ReReply trust centre
Privacy Policy
How ReReply protects and processes account, CRM and conversation data across separate customer organisations.
Scope and our role
This Privacy Policy explains how ReReply, provided by Medtech Healthcare Sdn Bhd, handles personal data through the ReReply website, applications, APIs and support services.
A clinic, pharmacy, wellness provider or other business using ReReply (a Customer Organisation) normally decides why and how its contact, patient, lead and conversation data is used. The Customer Organisation is the data controller and ReReply acts as its service provider or data processor. ReReply may act as controller for account administration, billing, platform security, service analytics and its own business communications.
Personal data we handle and why
ReReply uses this information to provide, secure and troubleshoot the service; route authorised messages; maintain conversation and CRM history; enforce organisation permissions and tenant isolation; administer subscriptions and support; prevent abuse; and comply with lawful obligations.
- Account identity, work contact details, roles, authentication records and organisation membership.
- Customer and CRM details such as names, telephone numbers, profile information, tags, notes, lead stages, appointments and service preferences.
- WhatsApp, Facebook Messenger, Instagram and email conversations, attachments, templates, delivery events and authorised agent notes.
- Connected-channel identifiers and settings, including Meta sender and message identifiers, Facebook Page and Instagram account identifiers, timestamps, technical and security logs, subscription and support records, and information submitted to optional automation or AI-assisted features.
Connected services and AI
When a Customer Organisation connects WhatsApp, Meta, Gmail, Google Search Console or another service, ReReply exchanges only the information needed for the authorised feature. Providers also process information under their own terms and privacy policies. Disconnecting ReReply does not automatically erase information independently held by a provider.
Search Console access is read-only. Gmail access is limited to reading new inbox conversations and sending a reply approved by an authorised user; it is not used to modify or delete Gmail content. Optional AI features may send relevant prompts or excerpts to the configured provider solely to perform the requested feature. ReReply does not sell personal data or use Google user data for advertising or to train general-purpose AI models.
Retention, deletion and your rights
Information is retained only as needed to provide and secure the service, follow lawful Customer Organisation instructions, and meet legal or contractual obligations. Data removed from active systems may remain temporarily in protected backups until normal rotation completes; limited security, billing, dispute and compliance records may be retained where necessary.
Depending on applicable law, you may request access, correction, deletion, restriction, portability or objection, or withdraw consent. Contact the Customer Organisation first when it controls the record. You may also follow ReReply's Data Deletion Instructions. Identity and authority may need to be verified before action is taken.
Privacy questions may be sent to Medtech Healthcare Sdn Bhd at [email protected].