1. Who we are
ReplyAid is an email marketing service operated by Minetta Capital Partners Ltd, a company registered in England and Wales under company number 14102287 ("ReplyAid", "we", "us", "our").
This policy explains what personal data we handle, why, and what you can do about it. It is written to meet our obligations under the UK General Data Protection Regulation (UK GDPR), the Data Protection Act 2018 and the Privacy and Electronic Communications Regulations 2003 (PECR).
2. We act in two different roles
The distinction matters, because it changes who is responsible for what.
| Situation | Our role | What that means |
|---|---|---|
| You visit our website, sign up for early access, or hold a ReplyAid account | Controller | We decide why and how your data is used. This policy governs it. |
| A ReplyAid customer uploads their subscriber list and sends email through us | Processor | The customer decides what happens to that list. We only act on their instructions, under a data processing agreement. Their own privacy policy applies to those subscribers. |
3. What personal data we collect
Website visitors
- Pages viewed, referring page, approximate location derived from IP address, browser and device type.
- Your IP address, held in our server logs.
Early access and newsletter signups
- Email address.
- The date and time you signed up, the IP address you signed up from, and the record of your confirmation click.
- Whether you opened or clicked our emails.
Account holders and customers
- Name, email address, business name, and the sending domain you connect.
- Authentication data: password hash, and passkey credentials if you use one. We never store your password in readable form.
- Billing information. Card details are handled by our payment provider and never reach our servers — we hold only the last four digits, card type, expiry, and billing address.
- Support correspondence.
- Usage records: emails sent, campaigns created, logins, and API activity.
Subscriber data belonging to our customers
When a customer uses ReplyAid, their subscribers' email addresses, names, custom fields, consent records and engagement data are stored on our systems. We hold this as a processor. We do not use it for our own purposes, we do not email those people on our own behalf, and we never sell, rent or share it.
4. Why we use it, and our lawful basis
| Purpose | Data used | Lawful basis |
|---|---|---|
| Providing the service, sending your campaigns, reporting on them | Account, usage, subscriber data | Performance of a contract |
| Taking payment and issuing invoices | Billing data | Performance of a contract; legal obligation (tax records) |
| Sending you our own product updates and marketing | Email address, engagement | Consent (you can withdraw it at any time) |
| Preventing abuse, spam and fraud on our platform | Usage, IP, sending metrics, list sources | Legitimate interests — protecting our infrastructure, our other customers, and the recipients of email sent through us |
| Keeping suppression records so people who unsubscribed are never emailed again | Email address (hashed where possible), suppression reason and date | Legal obligation under PECR; legitimate interests |
| Improving the product and understanding how it is used | Aggregated usage data | Legitimate interests |
| Responding to support requests | Correspondence, account data | Performance of a contract; legitimate interests |
| Meeting legal, tax and regulatory obligations | Account, billing, correspondence | Legal obligation |
Where we rely on legitimate interests, we have considered whether our interest is overridden by your rights, and concluded it is not. You can ask us to explain that assessment, and you can object — see Your rights.
5. Marketing emails from us
We only send you marketing email if you asked for it. Every signup form on our site uses double opt-in: we send one confirmation email, and your address is not added until you click the link in it. Unconfirmed addresses are deleted after 14 days.
Every marketing email we send includes a working unsubscribe link and a List-Unsubscribe header, so you can leave from inside your email client. Unsubscribing takes effect immediately. There is no confirmation step and we will not ask you why.
Once you unsubscribe we add your address to a suppression list. That entry exists purely so we do not email you again — it is not used for anything else. Asking us to delete your data entirely will remove the subscriber record but keep the suppression entry, unless you specifically ask us not to.
We will still send you service messages about your account — billing notices, security alerts, changes to these policies — because those are not marketing and you cannot opt out of them while you hold an account.
6. Cookies and similar technologies
Our marketing website uses only strictly necessary cookies, which do not require your consent. The application uses cookies to keep you signed in and to protect against cross-site request forgery.
If we introduce analytics or advertising cookies, we will ask for your consent through a banner first, and you will be able to refuse without losing access to anything.
7. Open and click tracking
Emails sent through ReplyAid can contain a tracking pixel and rewritten links, which record whether a message was opened and which links were clicked. This is standard for email marketing, and it is how senders judge whether their emails are worth sending.
For emails we send you, this is covered by the consent you gave when you subscribed. For emails our customers send, the customer is the controller and is responsible for disclosing this in their own privacy policy.
Customers can switch open and click tracking off per campaign. Many mail clients now pre-load images or route them through a proxy, so open figures should be treated as indicative rather than exact.
8. Where your data is held
ReplyAid runs on servers located in the United Kingdom. Email is sent through Amazon Simple Email Service in the eu-west-2 (London) region. Subscriber lists, campaign content and engagement data are stored in the UK and are not copied to a US region for processing.
Some of our suppliers are established outside the UK. Where personal data is transferred internationally, we rely on the UK International Data Transfer Addendum to the EU Standard Contractual Clauses, or on UK adequacy regulations where they apply. You can ask us for a copy of the relevant safeguards.
9. Sub-processors
We use a small number of suppliers who may handle personal data on our behalf. Each is bound by a written contract that limits what they can do with it.
| Supplier | What it does | Where |
|---|---|---|
| Amazon Web Services | Email delivery (SES), infrastructure | United Kingdom (eu-west-2) |
| [HOSTING PROVIDER] | Application and database hosting | United Kingdom |
| [PAYMENT PROVIDER] | Payment processing and invoicing | [REGION] — safeguards in place |
| [SUPPORT / EMAIL TOOL] | Support correspondence | [REGION] |
We will publish an updated list here before adding a new sub-processor that handles customer data, and customers on a signed data processing agreement will be notified in advance and may object.
10. How long we keep it
| Data | Kept for |
|---|---|
| Account and profile data | While your account is open, then 30 days after closure |
| Customer subscriber lists | While your account is open. Deleted within 30 days of closure |
| Campaign reports and engagement data | 24 months, then aggregated |
| Suppression records (unsubscribes, complaints, hard bounces) | Indefinitely — this is what stops someone being emailed again |
| Consent records (date, IP, list, confirmation) | While the subscriber is active, plus 24 months, so consent can be evidenced |
| Billing records and invoices | 6 years, as required by UK tax law |
| Server and access logs | 90 days |
| Support correspondence | 24 months from last contact |
11. Security
We take the following measures, among others:
- All traffic to and from ReplyAid is encrypted in transit using TLS. Data is encrypted at rest.
- Passwords are hashed. We support passkeys so you can sign in without one.
- Access to production systems is limited to people who need it, protected by multi-factor authentication, and logged.
- Backups are encrypted and held in the UK.
- Sending domains must pass SPF, DKIM and DMARC checks before a campaign can go out.
No system is perfectly secure. If a personal data breach occurs that is likely to cause a risk to people's rights, we will report it to the Information Commissioner's Office within 72 hours and tell affected customers without undue delay.
12. Your rights
Under UK GDPR you can ask us to:
- Give you a copy of the personal data we hold about you.
- Correct anything that is wrong or incomplete.
- Delete your data, where we have no continuing reason to keep it.
- Restrict how we use it while a dispute is resolved.
- Object to processing based on legitimate interests, and to direct marketing at any time — for marketing this is absolute, and we will always stop.
- Port your data to another provider in a machine-readable format.
- Withdraw consent where we relied on it. This does not affect anything done before you withdrew it.
Email privacy@replyaid.com and we will respond within one month. There is no charge. We may ask you to confirm your identity first.
If you are unhappy with how we handled your request, you can complain to the Information Commissioner's Office at ico.org.uk, or by calling 0303 123 1113. We would rather you came to us first so we can put it right.
13. If you received an email sent through ReplyAid
If a business emailed you using ReplyAid and you want to stop, use the unsubscribe link in that email. It works immediately, and it also stops any automated series that business has running.
For anything beyond unsubscribing — a copy of your data, deletion, or a complaint about how you ended up on that list — you need to contact the business that sent the email, because they are the controller and we cannot act on their data without their instruction.
If they do not respond, or you believe the email was unsolicited, tell us at abuse@replyaid.com. We investigate every report, and we suspend accounts that send email people did not ask for.
14. Children
ReplyAid is a business tool and is not directed at children. We do not knowingly collect personal data from anyone under 13. If you believe a child's data has been given to us, tell us and we will delete it.
15. Changes to this policy
We will update this page when our practices change. The version number and date at the top will change with it. If a change materially affects how we handle your data, we will email account holders at least 30 days before it takes effect.
16. Contact us
Company number 14102287, England and Wales
Registered office: 31 Elderdale Road, Liverpool, Merseyside, L4 2ST, United Kingdom
ICO registration: [ADD ICO REGISTRATION NUMBER]
Email: privacy@replyaid.com
Abuse reports: abuse@replyaid.com
We have not appointed a Data Protection Officer, as we are not required to. Data protection enquiries go to the address above and are handled by a named person internally.