Privacy Policy
Last updated: August 4, 2026
Protecting your personal data matters to us. This privacy policy explains how we process personal data when you visit this website and when you use the Antwortio service.
1. Data controller
The controller within the meaning of the General Data Protection Regulation (GDPR) is:
Muhammad Shuaib Aslam, Antwortio, Wilhelmstraße 27, 90439 Nuremberg, Germany, email:
datenschutz@antwortio.de
A data protection officer is not legally required and none has been appointed.
2. Principles
We process personal data only to the extent necessary to provide our website and our service. All data is stored on servers in Germany (Hetzner Online GmbH, data centers in Germany). We do not sell data and do not use it for third-party advertising.
3. Data processing when visiting this website
Server log files
When you access the website, our server automatically processes: IP address (truncated), date and time, page accessed, browser type, and operating system. Purpose: technical operation and security. Legal basis: Art. 6(1)(f) GDPR (legitimate interest). Retention period: 14 days, after which it is automatically deleted.
Web analytics
We do not currently use any web analytics or tracking tools. Should we introduce one in the future, we will update this section and obtain your consent where required.
Contact and waitlist
If you contact us by email or via a form, or join the waitlist, we process the data you provide (name, business name, email address, optional phone number, industry) to handle your inquiry. Legal basis: Art. 6(1)(b) GDPR (pre-contractual measures) or Art. 6(1)(a) (consent). Data is deleted once your inquiry has been resolved, and at the latest after 12 months if no contract is concluded.
4. Data processing when using the Antwortio service
Antwortio helps businesses reply to Google reviews. In doing so, we process the following categories of data:
a) Customer data (contract data)
Name, business name, address, email, phone number (WhatsApp), billing data. Purpose: contract performance, billing, support. Legal basis: Art. 6(1)(b) GDPR. Retention period: duration of the contract; invoice data additionally subject to statutory retention obligations (up to 10 years).
b) Google account connection
To connect your Google Business Profile, we store the access tokens issued by Google as part of your authorization (OAuth). These are stored encrypted and used exclusively to retrieve your reviews and publish your replies. You can revoke this connection at any time in your Google account.
c) Review data (third-party data)
We retrieve the reviews of your business profile that are publicly visible on Google: reviewer display name, review text, star rating, timestamp. Purpose: generating reply drafts and publishing your replies. Legal basis: Art. 6(1)(f) GDPR; the legitimate interest lies in the reviewed business's ability to respond to public customer reviews. We process this data exclusively for this purpose, do not build profiles of reviewers, and do not pass the data on for other purposes. Retention period: deleted at the latest 90 days after the contract ends.
d) WhatsApp communication
Notifications about new reviews and the approval of replies take place via the WhatsApp Business platform. Your WhatsApp number and the message content of the approval process are processed. The WhatsApp Business platform is provided by Meta Platforms Ireland Ltd.; The connection is provided via a certified WhatsApp Business Solution Provider based in the European Union. Voice messages are deleted immediately after being converted to text. Legal basis: Art. 6(1)(b) GDPR. Retention period for message history: 90 days.
e) AI-generated reply drafts
To generate reply drafts, we transmit the review text and your stored tone-of-voice profile to our AI provider Mistral AI (France). Processing takes place exclusively within the European Union. Use of your data to train AI models is contractually excluded. Legal basis: Art. 6(1)(b) GDPR.
f) Payment processing
Payments are processed via Stripe Payments Europe Ltd. (Ireland). Credit card data is processed exclusively by Stripe and is never stored by us. Legal basis: Art. 6(1)(b) GDPR.
5. Data processing on behalf of customers
To the extent we process review data and communication data on behalf of our business customers, we act as a processor under Art. 28 GDPR. A data processing agreement (DPA) is concluded with every customer when the contract is signed. We make our current list of subprocessors (including Hetzner, Meta, our WhatsApp BSP, our AI provider, Stripe, and Sentry) available on request, and will publish it on a dedicated page shortly.
6. International data transfers
Our servers are located in Germany. Where individual service providers (Meta, Stripe) use group companies in the US, the transfer is based on the EU-US Data Privacy Framework and the EU Standard Contractual Clauses.
7. Your rights
You have the right to access (Art. 15 GDPR), rectification (Art. 16), erasure (Art. 17), restriction of processing (Art. 18), data portability (Art. 20), and objection to processing based on legitimate interests (Art. 21). Contact us at datenschutz@antwortio.de. You also have the right to lodge a complaint with a supervisory authority; the competent authority is the Bavarian State Office for Data Protection Supervision (BayLDA), Ansbach.
Note for reviewers: If you have left a Google review for a business that uses Antwortio, we process your publicly visible review data on behalf of that business solely to respond to your review. For requests regarding your rights, you may contact either the reviewed business or us directly.
8. Data security
We employ technical and organizational measures, in particular: TLS encryption for all connections, encrypted storage of access tokens, access restrictions on a need-to-know basis, daily encrypted backups in German data centers, and logging without personal content.
9. Changes
We update this privacy policy whenever our service or the applicable law changes. The version published on this page is always the current one.