PRIVACY POLICY
How we collect, use, and protect your personal data
Contents
INTRODUCTION AND SCOPE
1.1 About this Privacy Policy: This Privacy Policy (hereinafter referred to as the "Policy") describes how ReporaAI and its affiliates, subsidiaries, successors, and assigns (collectively, "ReporaAI", "we", "us", or "our") collect, use, process, store, share, and protect the personal data of individuals and organisations ("Users", "you", or "your") who access, register on, or use the ReporaAI software-as-a-service platform, including all associated websites, applications, APIs, connectors, tools, features, and services (the "Platform"). This Policy should be read in conjunction with the ReporaAI Terms and Conditions, which are available on the Platform and are incorporated herein by reference to the extent relevant.
1.2 Scope of Application: This Policy applies to all personal data collected, processed, or generated through the Platform, regardless of the User's geographic location. This includes personal data provided directly by Users, data collected automatically through the Platform's systems and third-party service providers, and data generated through the User's interaction with Platform features. This Policy applies to all Users, including individuals, organisations, and any persons accessing the Platform on behalf of an organisation.
1.3 Consent and Acceptance: By accessing, browsing, registering on, or using the Platform in any manner, you acknowledge that you have read, understood, and agree to the collection, use, processing, storage, and sharing of your personal data as described in this Policy. If you do not agree to this Policy, you must immediately cease all use of the Platform and must not create an Account. Where required by Applicable Data Protection Law, ReporaAI shall obtain your explicit consent prior to processing your personal data for specific purposes, including AI training and marketing communications.
DEFINITIONS
Unless otherwise defined in this Policy, capitalised terms used herein shall have the meanings ascribed to them in the ReporaAI Terms and Conditions. In addition, the following definitions apply to this Policy.
"Applicable Data Protection Law" means all applicable data protection and privacy legislation, regulations, directives, orders, codes, and guidance, including but not limited to the General Data Protection Regulation (EU) 2016/679 ("GDPR"), the UK General Data Protection Regulation and the UK Data Protection Act 2018 ("UK GDPR"), the California Consumer Privacy Act as amended by the California Privacy Rights Act ("CCPA/CPRA"), the Personal Information Protection and Electronic Documents Act (Canada) ("PIPEDA"), the Digital Personal Data Protection Act 2023 (India) ("DPDPA"), the Federal Data Protection Act (Germany) ("BDSG"), and any other applicable data protection laws.
"Data Controller" means the natural or legal person, public authority, agency, or other body which, alone or jointly with others, determines the purposes and means of the processing of personal data. For the purposes of this Policy, ReporaAI is the Data Controller in respect of the personal data described herein.
"Data Processor" means a natural or legal person, public authority, agency, or other body which processes personal data on behalf of the Data Controller.
"Personal Data" means any information relating to an identified or identifiable natural person, including but not limited to names, email addresses, phone numbers, IP addresses, device identifiers, location data, payment information, and any other information that can be used, directly or indirectly, to identify a natural person.
"Processing" means any operation or set of operations performed on personal data, whether or not by automated means, including collection, recording, organisation, structuring, storage, adaptation, alteration, retrieval, consultation, use, disclosure by transmission, dissemination, alignment, combination, restriction, erasure, and destruction.
"Special Category Data" means personal data revealing racial or ethnic origin, political opinions, religious or philosophical beliefs, trade union membership, genetic data, biometric data for the purpose of uniquely identifying a natural person, data concerning health, or data concerning a natural person's sex life or sexual orientation.
"Sub-Processor" means any third-party entity engaged by ReporaAI to process personal data on its behalf in connection with the provision of the Platform and Services.
DATA CONTROLLER
3.1 Identity of the Data Controller: For the purposes of Applicable Data Protection Law, ReporaAI is the Data Controller in respect of the personal data collected and processed through the Platform. ReporaAI determines the purposes and means of processing your personal data as described in this Policy.
3.2 Contact Details: If you have any questions, concerns, or requests regarding this Policy or the processing of your personal data, you may contact ReporaAI at [Privacy@Reporaai.uk], or through the support forum on the Platform. If ReporaAI appoints a Data Protection Officer, the relevant contact details shall be published on the Platform and updated in this Policy.
CATEGORIES OF PERSONAL DATA COLLECTED
4.1 Data Provided Directly by the User: ReporaAI collects the following categories of personal data that Users provide directly through the Platform: (a) email addresses, provided at the time of Account creation; (b) customer names (first name and surname), provided at the time of Account creation; (c) phone numbers, which are optional and provided at the User's discretion during Account creation; (d) organisation name, provided at the time of Account creation where the User registers on behalf of an organisation; (e) organisation email address, provided at the time of Account creation for organisational accounts; (f) organisation address, collected for invoicing and billing purposes and processed through Stripe; and (g) payment card details, which are collected and processed exclusively by Stripe and are not stored on ReporaAI's internal systems. Users have the option to save a payment card for future use through Stripe; however, the full card number is never displayed or stored by ReporaAI.
4.2 Data Generated Through Platform Use: ReporaAI collects the following categories of data generated through the User's interaction with Platform features: (a) uploaded data sets, which are stored for the purposes of providing the Services and, subject to the User's opt-out rights, for training ReporaAI's AI models; (b) Aura Pro chat history, including User queries, which is stored for AI training and internal review purposes; (c) project chats and project history, stored for internal purposes and monitored for security; (d) project names, project authors, project creation dates, project invited member IDs and email addresses, invite email addresses, and user type designations (Admin, Viewer, or Editor); (e) business view recommendations and their status (approved, archived, or rejected); (f) discussion types, discussion titles, content, and tags; (g) lists of business views, reports, Qlik Sense code, and Power BI code generated by the LLM, stored for internal system use; (h) natural language query history and prompts, stored for AI training and internal use; (i) discussion and vote logs, stored for security purposes; (j) token usage, token pool amounts, organisation IDs linked to token pools, user IDs, session IDs, AI credits, and time duration of use for rate limiting purposes; and (k) payment dates and payment amounts, tracked through ReporaAI's internal Wallet Management System.
4.3 Data Collected Automatically: ReporaAI and its third-party service providers automatically collect the following categories of data when Users access or use the Platform: (a) session activity, including session duration and feature-by-feature usage tracking; (b) duration of the User's engagement with each feature or page of the Platform; (c) IP addresses, collected through Clerk; (d) device type, collected through Clerk; (e) the User's last login activity, collected through Clerk; and (f) the geographic location of login, collected through Clerk. This data is collected through ReporaAI's internal administrative panel and through third-party analytics and authentication services, and is used solely for internal tracking, security, rate limiting, and Platform improvement purposes. This data is not sold to any third party.
4.4 No Collection of Special Category Data: ReporaAI does not intentionally collect or process Special Category Data. Users are advised not to upload, submit, or transmit any Special Category Data to the Platform.
POINTS AND METHODS OF DATA COLLECTION
5.1 Account Creation: Personal data including email addresses, customer names, phone numbers (where voluntarily provided), organisation names, organisation email addresses, and organisation addresses are collected at the point of Account creation. Users may register through standard email and password, through single sign-on ("SSO") authentication via Google or Apple (processed through Clerk), or through two-factor authentication ("2FA") with a one-time password or expiry token link sent to the User's registered email address.
5.2 Payment Processing: Payment card details and billing information, including organisation address for invoicing purposes, are collected at the point of payment processing. All payment card details are handled exclusively by Stripe, ReporaAI's third-party payment processor. ReporaAI does not collect, receive, or store payment card numbers or full card details on its internal systems. Payment dates and payment amounts are tracked internally through ReporaAI's Wallet Management System for transaction record-keeping and token management purposes.
5.3 Platform and Feature Use: Data is generated and collected continuously throughout the User's interaction with Platform features, including but not limited to the upload of data sets, the submission of natural language queries and prompts, the generation of business views, reports, and code outputs through the LLM, participation in project chats and discussions, voting on business view recommendations, and the consumption of Tokens and Credits. This data is collected at the point of system use and is processed for the purposes of providing the Services, AI training (subject to opt-out), internal review, and security monitoring.
5.4 Automated Collection: Session activity, page and feature duration metrics, IP addresses, device types, last login activity, and login locations are collected automatically through Clerk (for authentication data) and ReporaAI's internal administrative panel each time a User accesses or interacts with the Platform. Analytics data is additionally collected through Google Analytics, HubSpot, and Google Tag Manager when Users visit the website or Platform.
PURPOSES OF PROCESSING
6.1 Service Delivery and Account Management: ReporaAI processes your personal data for the following purposes related to service delivery and Account management: (a) to create, authenticate, and manage your Account; (b) to verify your identity through SSO and 2FA mechanisms via Clerk; (c) to provide, operate, maintain, and deliver the Services and Platform features, including AI Data Analyst Agent, Report Architect Agent, Teams and Projects, Code Craft Studios, and Aura Pro; (d) to process payments and manage your Wallet, Tokens, and Credits; (e) to track and manage subscription plans, billing, and invoicing; and (f) to communicate with you regarding your Account, transactions, and the Services.
6.2 Platform Improvement and AI Training: ReporaAI processes your personal data for the purposes of improving, developing, and enhancing the Platform and Services, including: (a) analysing usage patterns, feature engagement, and session metrics to optimise Platform performance and user experience; (b) training and improving ReporaAI's proprietary AI knowledge base and LLM models using uploaded data sets, natural language query histories, prompts, and chat histories, subject to your right to opt out through your Profile settings; and (c) conducting internal reviews of Aura Pro chat history, project chats, and discussion logs to improve service quality and AI accuracy. Unless and until you exercise your opt-out right, your continued use of the Platform constitutes consent to the use of your data for AI training purposes.
6.3 Security, Fraud Prevention, and Compliance: ReporaAI processes your personal data for the purposes of: (a) monitoring, detecting, and preventing unauthorised access, credential sharing, fraudulent activity, and misuse of the Platform; (b) enforcing the Terms and Conditions and this Policy; (c) monitoring and reviewing discussion and vote logs for security purposes; (d) tracking IP addresses, login locations, and device information to detect anomalous activity and enforce the prohibition on multiple Accounts; (e) operating the Data Masking Algorithm to review and prohibit the upload of unlawful or restricted data; (f) operating the PII Algorithm to hash personally identifiable information; and (g) complying with legal obligations, responding to lawful requests from public authorities, and cooperating with law enforcement and regulatory bodies where required by Applicable Law.
6.4 Marketing and Communications: ReporaAI processes your personal data for the purposes of: (a) sending you notifications via email and push notifications within the Platform regarding service updates, maintenance schedules, and Account-related matters; (b) sending you marketing communications, newsletters, and promotional messages, including promotional code offers for Tokens displayed in the Wallet section of the Platform; and (c) analysing user engagement with marketing communications to improve the effectiveness of ReporaAI's communications. You may opt out of marketing newsletters through your Account settings and opt out of push notifications through the Settings section of the Platform. Opting out of marketing communications shall not affect the delivery of transactional or service-related communications that are necessary for the operation of your Account.
6.5 Analytics and Tracking: ReporaAI uses Google Analytics, HubSpot, and Google Tag Manager to track User durations, page events, and other analytics data on the website and Platform. This data is used for internal analytical purposes to understand User behaviour, improve Platform performance, and inform product development decisions. This data is not sold externally to any third party.
LEGAL BASES FOR PROCESSING
7.1 Contractual Necessity: ReporaAI processes your personal data where processing is necessary for the performance of the contract between you and ReporaAI (the Terms and Conditions), including the creation and management of your Account, the provision of the Services, payment processing, and service-related communications. This legal basis applies under Article 6(1)(b) of the GDPR and UK GDPR, and equivalent provisions under other Applicable Data Protection Laws.
7.2 Legitimate Interests: ReporaAI processes your personal data where processing is necessary for the legitimate interests pursued by ReporaAI, provided that such interests are not overridden by your fundamental rights and freedoms. ReporaAI's legitimate interests include: (a) the security, integrity, and proper functioning of the Platform; (b) the detection and prevention of fraud, misuse, and unauthorised access; (c) the improvement, development, and optimisation of the Platform and Services; (d) internal analytics and business intelligence; and (e) the enforcement of the Terms and Conditions. This legal basis applies under Article 6(1)(f) of the GDPR and UK GDPR, and equivalent provisions under other Applicable Data Protection Laws.
7.3 Consent: ReporaAI processes your personal data on the basis of your consent where required by Applicable Data Protection Law, including: (a) the use of your data for AI training purposes, which you may withdraw by opting out through your Profile settings; (b) the sending of marketing communications, which you may withdraw by opting out through your Account settings or the Settings section of the Platform; and (c) the use of non-essential cookies and tracking technologies. Where consent is the legal basis for processing, you have the right to withdraw your consent at any time. Withdrawal of consent shall not affect the lawfulness of processing carried out prior to withdrawal. This legal basis applies under Article 6(1)(a) of the GDPR and UK GDPR, and equivalent provisions under other Applicable Data Protection Laws.
7.4 Legal Obligation: ReporaAI processes your personal data where processing is necessary for compliance with a legal obligation to which ReporaAI is subject, including but not limited to tax and accounting obligations, regulatory reporting requirements, and responses to lawful requests from law enforcement or regulatory authorities. This legal basis applies under Article 6(1)(c) of the GDPR and UK GDPR, and equivalent provisions under other Applicable Data Protection Laws.
DATA STORAGE AND INFRASTRUCTURE
8.1 Storage Locations and Systems: ReporaAI stores and processes personal data using the following infrastructure and systems: (a) Amazon Web Services ("AWS") EC2 instances located in the European Union (Ireland) and/or London, United Kingdom, protected by two-factor authentication, which serve as the primary storage infrastructure for Platform data; (b) Stripe, located in the United States, which processes and stores payment card details and billing information exclusively on its own infrastructure; (c) Qdrant, a vector knowledge base located in the United States, used for AI model knowledge storage; (d) Clerk, located in the United States, which handles user authentication and stores authentication-related data including IP addresses, device types, last login activity, and login locations; (e) Vercel, located in the United States, which provides hosting infrastructure for the Platform; and (f) MongoDB Atlas, which provides database services for the Platform. ReporaAI does not utilise any third-party open AI systems, including but not limited to ChatGPT, Gemini, or similar models, for its AI services.
8.2 Internal Wallet Management System: Payment dates, payment amounts, token usage, token pool amounts, AI credits, organisation IDs, user IDs, and session IDs are stored within ReporaAI's internal Wallet Management System and administrative panel. This system is maintained on ReporaAI's secure infrastructure and is subject to the security measures described in Clause 10 of this Policy.
DATA SHARING AND THIRD-PARTY PROCESSORS
9.1 Categories of Recipients: ReporaAI shares personal data with the following categories of third-party service providers (Sub-Processors) solely for the purposes described in this Policy and subject to appropriate contractual safeguards: (a) Stripe (United States), which receives payment card details, billing addresses, and transaction data for the purpose of processing payments; (b) Clerk (United States), which receives email addresses, names, IP addresses, device types, login activity data, and login location data for the purpose of user authentication and session management; (c) Qdrant (United States), which receives anonymised and vectorised data for AI knowledge base storage; (d) Vercel (United States), which provides hosting services and receives data necessary for Platform delivery; (e) MongoDB Atlas, which provides database services and stores Platform data; (f) Google Analytics, which receives analytics and tracking data including session activity, page durations, and user engagement metrics; (g) HubSpot, which receives analytics data and may receive contact information for marketing and customer relationship management; and (h) Google Tag Manager, which facilitates the deployment of tracking tags and receives associated tracking data.
9.2 No Sale of Personal Data: ReporaAI does not sell, rent, lease, trade, or otherwise commercially distribute your personal data to third parties. For the purposes of the CCPA/CPRA, ReporaAI does not "sell" or "share" (as those terms are defined under the CCPA/CPRA) your personal information. The data shared with the third-party service providers identified in Clause 9.1 is shared solely for the purposes of operating the Platform and providing the Services.
9.3 Legal and Regulatory Disclosures: ReporaAI may disclose your personal data to law enforcement agencies, regulatory authorities, courts, or other governmental bodies where: (a) disclosure is required by Applicable Law, regulation, or legal process; (b) disclosure is necessary to comply with a lawful request, subpoena, court order, or regulatory investigation; (c) disclosure is necessary to protect the rights, property, or safety of ReporaAI, its Users, or the public; or (d) disclosure is necessary in connection with the detection, prevention, or investigation of fraud, security incidents, or violations of the Terms and Conditions. ReporaAI shall use commercially reasonable efforts to notify you of any such disclosure, unless notification is prohibited by law or court order.
9.4 Business Transfers: In the event of a merger, acquisition, reorganisation, sale of assets, bankruptcy, or other corporate transaction involving ReporaAI, your personal data may be transferred to the acquiring entity or successor, subject to compliance with Applicable Data Protection Law.
DATA SECURITY
10.1 Technical Safeguards: ReporaAI implements the following technical security measures to protect your personal data: (a) a proprietary PII Algorithm that securely hashes all personally identifiable information, including names, addresses, and credit card information, ensuring that such data cannot be viewed in readable form within ReporaAI's systems; (b) SSL/TLS encryption and HTTPS protocols for all data in transit between Users and the Platform; (c) encryption at rest for data stored on AWS infrastructure; (d) two-factor authentication ("2FA") for both Users and internal ReporaAI personnel accessing systems; and (e) the proprietary Data Masking Algorithm, which monitors and prohibits the upload of unlawful or restricted data sets.
10.2 Organisational Safeguards: ReporaAI implements the following organisational security measures: (a) internal security audits conducted on a quarterly basis; (b) access controls that restrict access to personal data to authorised personnel on a need-to-know basis, with role-based access permissions; (c) internal password policies requiring password changes at least every six (6) months for all internal personnel; and (d) contractual obligations imposed on all Sub-Processors requiring compliance with equivalent security standards.
10.3 Data Breach Notification: In the event of a personal data breach that is likely to result in a risk to your rights and freedoms, ReporaAI shall notify the relevant supervisory authority without undue delay and, where feasible, within seventy-two (72) hours of becoming aware of the breach, in accordance with Article 33 of the GDPR and UK GDPR. Where the breach is likely to result in a high risk to your rights and freedoms, ReporaAI shall communicate the breach to you without undue delay in accordance with Article 34 of the GDPR and UK GDPR, unless one of the exceptions in that Article applies. ReporaAI shall also comply with any additional breach notification obligations under other Applicable Data Protection Laws, including the CCPA/CPRA, PIPEDA, and the DPDPA.
10.4 Limitation of Security Guarantee: While ReporaAI implements commercially reasonable technical and organisational measures to protect your personal data, no method of electronic transmission or storage is completely secure. ReporaAI cannot guarantee the absolute security of your personal data and shall not be liable for any unauthorised access, disclosure, alteration, or destruction of personal data resulting from circumstances beyond ReporaAI's reasonable control, including but not limited to cyber-attacks, system failures, or User negligence in maintaining Account credentials.
CROSS-BORDER DATA TRANSFERS
11.1 International Transfers: By using the Platform, you acknowledge and consent to the transfer of your personal data to countries outside your country of residence, including to the United States, where certain Sub-Processors (Stripe, Clerk, Qdrant, and Vercel) are located, and to the European Union (Ireland) and the United Kingdom, where AWS infrastructure is located.
11.2 Safeguards for International Transfers: Where personal data is transferred to countries that have not been deemed to provide an adequate level of data protection by the European Commission, the UK Secretary of State, or any other relevant authority, ReporaAI shall ensure that appropriate safeguards are in place, including: (a) Standard Contractual Clauses ("SCCs") approved by the European Commission and/or the UK Information Commissioner's Office ("ICO"), as applicable; (b) binding corporate rules, where applicable; (c) reliance on adequacy decisions, where available; and (d) any other transfer mechanism recognised under Applicable Data Protection Law. For transfers of personal data to the United States, ReporaAI shall rely on the EU-U.S. Data Privacy Framework, UK Extension to the EU-U.S. Data Privacy Framework, or SCCs, as appropriate.
DATA RETENTION
12.1 General Retention Principles: ReporaAI retains personal data only for as long as is necessary to fulfil the purposes for which it was collected, as described in this Policy, unless a longer retention period is required or permitted by Applicable Law. The specific retention periods applicable to each category of personal data are set forth below.
12.2 Retention of Account Data: Account registration data, including names, email addresses, phone numbers, and organisation details, is retained for the duration of the User's active Account. Upon termination or cancellation of the User's Account, Account data shall be retained for a period of up to twelve (12) months from the date of termination, after which it shall be permanently deleted, unless a longer retention period is required by Applicable Law. ReporaAI shall provide the User with a notification approximately three (3) months prior to the scheduled deletion of data following Account termination.
12.3 Retention of Uploaded Data and Content: Uploaded data sets and Content are retained for a period of three (3) months from the date of upload, unless the User elects to extend retention through available settings. In the event that a User's Account becomes inactive for a continuous period of six (6) to twelve (12) months, ReporaAI shall delete the inactive data in accordance with its data deletion timelines.
12.4 Retention of Payment Data: Payment card details are not stored by ReporaAI; they are retained by Stripe in accordance with Stripe's own privacy policy and data retention practices. Internal transaction records, including payment dates and payment amounts recorded in the Wallet Management System, are retained for such period as is required to comply with tax, accounting, and regulatory obligations under Applicable Law, which may extend beyond the termination of the User's Account.
12.5 Retention of Usage and Analytics Data: Session activity data, feature duration metrics, IP addresses, device types, login activity, and login location data are retained for the period necessary to fulfil the internal tracking, security, and analytics purposes described in this Policy. ReporaAI reserves the right to retain anonymised and aggregated analytics data that does not identify any individual User for an indefinite period for analytical, research, and service improvement purposes.
12.6 Retention Following Cancellation: Where a User cancels their Account and requests immediate deletion of data, ReporaAI shall delete the User's personal data from its internal systems within a commercially reasonable timeframe, subject to: (a) any legal, regulatory, or contractual obligations requiring longer retention; (b) the retention of anonymised and aggregated data that does not identify the User; and (c) the retention of data that is reasonably necessary to resolve disputes, enforce the Terms and Conditions, or protect the legitimate interests of ReporaAI. Notwithstanding the foregoing, ReporaAI reserves the right to retain purchased Tokens in the User's Account for a period of up to twelve (12) months from the date of cancellation, as set forth in the Terms and Conditions.
12.7 Inactivity: Where a User's Account remains inactive for a continuous period of six (6) to twelve (12) months, ReporaAI may, at its discretion, delete inactive data associated with the Account in accordance with its data deletion timelines. ReporaAI may provide notice to the User prior to such deletion, but shall not be obligated to do so.
AI TRAINING AND AUTOMATED DECISION-MAKING
14.1 Use of Data for AI Training: ReporaAI may use anonymised and aggregated User data, including uploaded data sets, natural language query histories, prompts, Aura Pro chat histories, and LLM-generated outputs, to train, improve, and develop its proprietary AI knowledge base and LLM models. Users have the right to opt out of data training at any time through their Profile settings on the Platform. Unless and until a User exercises this opt-out right, the User's continued use of the Platform constitutes consent to the use of their data for AI training purposes. Upon receipt of a valid opt-out request, ReporaAI shall cease using the relevant User's data for training purposes within a commercially reasonable timeframe.
14.2 Automated Processing: The Platform employs automated processing to generate Suggestions, narratives, code, reports, and other outputs through its proprietary LLM. The Platform also employs automated processing through its Data Masking Algorithm to detect and prohibit the upload of unlawful or restricted data, and through its PII Algorithm to hash personally identifiable information. These automated processes do not produce legal or similarly significant effects on Users within the meaning of Article 22 of the GDPR. To the extent that any automated processing constitutes automated decision-making with legal or similarly significant effects under Applicable Data Protection Law, Users shall have the right to obtain human intervention, express their point of view, and contest the decision by contacting ReporaAI through the channels specified in Clause 3.2 of this Policy.
DATA SUBJECT RIGHTS
15.1 Your Rights Under Applicable Data Protection Law: Subject to the conditions and exceptions set out in Applicable Data Protection Law, you may have the following rights in relation to your personal data: (a) the right of access, being the right to obtain confirmation as to whether your personal data is being processed and, where that is the case, to obtain a copy of such data; (b) the right to rectification, being the right to require the correction of inaccurate personal data and the completion of incomplete personal data; (c) the right to erasure (the "right to be forgotten"), being the right to require the deletion of your personal data in certain circumstances; (d) the right to restriction of processing, being the right to require the restriction of processing of your personal data in certain circumstances; (e) the right to data portability, being the right to receive your personal data in a structured, commonly used, and machine-readable format and to transmit such data to another Data Controller; (f) the right to object, being the right to object to the processing of your personal data on grounds relating to your particular situation; and (g) the right to withdraw consent, where consent is the legal basis for processing.
15.2 Additional Rights Under Specific Jurisdictions: Users located in specific jurisdictions may have additional rights, including: (a) under the CCPA/CPRA, the right to know what personal information is collected, the right to delete personal information, the right to opt out of the sale or sharing of personal information, and the right to non-discrimination for exercising privacy rights; (b) under PIPEDA, the right to access, challenge the accuracy of, and withdraw consent for the processing of personal information; (c) under the DPDPA (India), the rights of a Data Principal including the right to information about processing, the right to correction and erasure, the right of grievance redressal, and the right to nominate; and (d) under the BDSG (Germany), the right to information, the right to object, and the right to compensation for unlawful processing.
15.3 How to Exercise Your Rights: You may exercise your data subject rights through any of the following channels: (a) your Profile settings on the Platform, where you can access, update, and manage your personal data and opt-out preferences; (b) the customer service data information service; (c) by submitting a request via email or through the online form provided by ReporaAI; or (d) by adjusting your opt-out preferences in the Settings section of the Platform. ReporaAI shall respond to valid data subject requests within the timeframes required under Applicable Data Protection Law, which is generally within one (1) month of receipt under the GDPR and UK GDPR, subject to a possible extension of two (2) further months for complex or numerous requests. ReporaAI may require you to verify your identity before processing your request.
15.4 Right to Lodge a Complaint: If you believe that ReporaAI has processed your personal data in a manner inconsistent with your data protection rights, you have the right to lodge a complaint with the relevant supervisory authority. For Users in the United Kingdom, this is the ICO. For Users in the European Union, this is the Data Protection Authority of the EU Member State in which you reside or work, or in which the alleged infringement occurred. For Users in other jurisdictions, this is the competent data protection authority in your country of residence.
CHILDREN'S PRIVACY
16.1 Age Restrictions: The Platform is not directed at, and is not intended for use by, individuals who have not attained the age of consent in their applicable jurisdiction. ReporaAI does not knowingly collect personal data from individuals below the age of consent. If ReporaAI becomes aware that it has collected personal data from an individual below the applicable age of consent without verified parental or guardian consent, ReporaAI shall take steps to delete such data as soon as practicable. If you believe that ReporaAI has collected personal data from an individual below the applicable age of consent, please contact ReporaAI through the channels specified in Clause 3.2 of this Policy.
MARKETING COMMUNICATIONS
17.1 Types of Communications: ReporaAI may send you the following types of communications: (a) transactional and service-related notifications via email and in-app push notifications, including Account confirmations, payment receipts, token expiry notifications, and maintenance alerts, which are necessary for the operation of your Account and cannot be opted out of; (b) marketing newsletters and promotional messages via email, which you may opt out of at any time through your Account settings; (c) push notifications within the Platform application, which you may opt out of through the Settings section of the Platform; and (d) promotional code offers for Tokens displayed in the Wallet section of the Platform.
17.2 Opt-Out Mechanisms: You may opt out of receiving marketing newsletters by adjusting your preferences in your Account settings or by following the unsubscribe instructions included in each marketing email. You may opt out of push notifications by adjusting your preferences in the Settings section of the Platform. Promotional code offers displayed within the Wallet section of the Platform are part of the Platform's functionality and are not subject to opt-out. Opting out of marketing communications shall not affect the delivery of transactional or service-related communications.
USER FEEDBACK
18.1 Feedback Data: ReporaAI periodically collects and analyses user review feedback data from all social channels and stores such data in its database for the purpose of improving the Platform, adding new features, or amending existing features. Any User-identifying information associated with feedback, including the name of the User, shall be hashed and rendered anonymous prior to storage and analysis. User feedback is prioritised for review and implementation, and shall be deleted after implementation is complete. ReporaAI conducts comprehensive feedback reviews at least every six (6) months. By submitting feedback to ReporaAI, you grant ReporaAI the licence described in the Terms and Conditions to use such feedback without restriction.
THIRD-PARTY LINKS AND SERVICES
19.1 Third-Party Websites: The Platform may contain links to third-party websites, services, or applications that are not owned or controlled by ReporaAI. This Policy does not apply to any third-party websites, services, or applications. ReporaAI is not responsible for the privacy practices, content, or data processing activities of any third-party websites, services, or applications. You are encouraged to review the privacy policies of any third-party websites, services, or applications that you access through or in connection with the Platform.
CHANGES TO THIS PRIVACY POLICY
20.1 Amendments: ReporaAI reserves the right, in its sole and absolute discretion, to modify, amend, supplement, or replace this Policy at any time. Any changes to this Policy shall be effective immediately upon posting on the Platform, unless otherwise specified. Your continued use of the Platform after the posting of any changes shall constitute your acceptance of and agreement to be bound by the amended Policy. It is your sole responsibility to review this Policy periodically for changes.
GOVERNING LAW
21.1 Applicable Law: This Policy, and any disputes or claims arising out of or in connection with it, its subject matter, or its formation (including non-contractual disputes or claims), shall be governed by and construed in accordance with the laws of England and Wales. The parties irrevocably submit to the exclusive jurisdiction of the courts of London, United Kingdom, for the resolution of any disputes arising out of or in connection with this Policy, without prejudice to ReporaAI's right to bring proceedings in any court of competent jurisdiction for the purpose of seeking injunctive or other equitable relief.
CONTACT INFORMATION
22.1 Contact Details: For any questions, concerns, complaints, or requests relating to this Policy or the processing of your personal data, including the exercise of your data subject rights, you may contact ReporaAI through the following channels: (a) the support forum on the Platform; (b) the customer service data information service; or (c) by email at support@reporaai.uk. ReporaAI shall endeavour to respond to all enquiries and data subject requests within the timeframes required under Applicable Data Protection Law.
© 2026 ReporaAI. All rights reserved.