Effective date: August 2, 2026 Last updated: August 2, 2026
1. Who we are
Reppic is a product of The Sales Studios B.V., based in the Netherlands (Chamber of Commerce no. 97393142).
For privacy questions: privacy@reppic.ai
2. Scope of this policy
This policy covers the entire Reppic platform: the mobile app, the web application (app.reppic.ai), all dashboards (salesperson, sales manager, CCO/executive), and the associated integrations (calendar, CRM, call recording).
3. When we are a processor vs. a controller
Which of the two situations below applies to you depends on how your account was created, it is not a choice Reppic makes for the platform as a whole. Both situations occur at the same time, for different users.
- You use Reppic through an employer or client (you work at a Reppic customer and your account was created or required by your employer). In this case, your employer is the data controller for your conversation data, scores, and performance insights. The Sales Studios B.V. acts as processor, under a data processing agreement with your employer. Rights requests in this case can also go through your employer; we support them in handling these.
- You hold a direct individual account (trial, individual subscription) without an employer-customer involved. In this case, The Sales Studios B.V. is the controller.
4. What data we collect
Account information
- Email address, name, role (salesperson / manager / CCO)
- Authentication token (JWT), 2FA status
Conversation data
- Audio recordings you start yourself (app) or that come in via a connected calling service (Zoom, Microsoft Teams, Google Meet, Recall)
- Transcripts (via AssemblyAI or a comparable service)
- AI-generated analysis: PICA scores (Propositie, Inventarisatie, Overtuiging, Afsluiting), DMU analysis, rubric scores, summaries
Calendar and CRM data (pre-call brief)
- Calendar data from connected Google Calendar/Outlook accounts, within a 48-hour window before a scheduled call
- Contact and deal data from connected CRMs (HubSpot, Salesforce, Pipedrive)
Strategic and team data
- Uploaded strategic plans (executive/CCO level)
- Aggregated team and organizational data in manager and CCO dashboards
Technical data
- IP address, device type, operating system, log files
Local storage on your device
- Drafts, language preference, settings (expo-secure-store / AsyncStorage)
5. Data of conversation participants (non-users)
Reppic processes conversations where the other party (your customer or prospect) has no Reppic account and may not have seen this policy. We address this separately because it requires a different legal basis and disclosure approach than processing our own users’ account data.
- Legal basis: legitimate interest of the organization conducting the call (quality assurance, coaching, customer insight), provided it does not disproportionately affect the interests of the conversation participant.
- Disclosure obligation: Reppic customers are responsible for informing their conversation participants that the call is being recorded and analyzed (e.g., via a notice at the start of the call).
- Retention and rights: see section 8. Conversation participants can submit access or deletion requests to privacy@reppic.ai; we route the request to the relevant customer organization where they are the controller.
6. Purposes and legal bases
| Purpose | Legal basis |
|---|---|
| Authentication and account management | Performance of a contract |
| Processing recordings into transcript and analysis | Performance of a contract (or: controller’s instructions, where we act as processor) |
| Generating coaching feedback for the individual salesperson | Performance of a contract |
| Generating team and performance insights for managers/CCO | Employer’s legitimate interest, subject to proportionality — see section 7 on the AI Act |
| Pre-call brief (calendar/CRM integration) | Performance of a contract, after active connection by the user |
| Improving the service | Legitimate interest |
| Technical support | Legitimate interest |
7. Use of AI transparency and your rights
Reppic uses AI models to transcribe, score, and analyze conversations. Because these analyses are used to assess employee performance and behavior, this system may fall under the EU AI Act as a high-risk AI system (Annex III, category 4(b): monitoring and evaluation of the performance and behavior of workers).
Where applicable, this means:
- Human oversight: AI-generated scores are intended solely as a tool for coaching and personal development. Reppic scores must never be used as a control mechanism and must never be used directly in promotion or termination decisions. Customer organizations using Reppic commit to this, and it is also set out contractually in customer terms. Where a score does inform a formal HR assessment, human review is required and the individual has the right to request human re-evaluation (see also GDPR Art. 22 and the AI Act’s requirements for high-risk AI systems).
- Disclosure: employees whose conversations are analyzed are informed by their employer when Reppic is introduced, and via this policy.
- Conformity status: We continuously assess whether and to what extent our AI systems qualify as high-risk under the EU AI Act, and what obligations follow from that. The current status of this assessment is available on request via privacy@reppic.ai.
- Models we use: Anthropic Claude (analysis), AssemblyAI (transcription)
We recommend that customer organizations (employers) involve their works council when introducing Reppic, given the potential applicability of consent rights for systems that can monitor employee behavior or performance.
8. Retention periods
| Data type | Retention period |
|---|---|
| Account information | As long as the account is active, +30 days after termination |
| Audio recordings | 7 days after processing, then automatically deleted |
| Transcripts (raw conversation text) | 7 days after processing, then automatically deleted |
| AI analysis, PICA scores, and reports | Remain available in the dashboard as long as the account is active (see also “Account information” above) |
| Calendar/CRM data via pre-call brief | Deleted after 30 days or when the connected time window expires |
| Local drafts | On device, until deleted by the user |
| Log files | Up to 90 days |
9. Sharing data – subprocessors
We never sell personal data to third parties. We share data with:
| Subprocessor | Function | Location |
|---|---|---|
| AssemblyAI | Transcription | EU processing (Dublin, Ireland). DPF-certified. |
| Recall | Capturing/relaying meeting recordings (Zoom, Teams, Google Meet) | US (Hyperdoc Inc.) – per Recall’s own privacy policy, data is stored on US servers; we found no Recall-confirmed EU storage option |
| Anthropic | AI analysis (Claude) | US. Transfers rely on EU Standard Contractual Clauses (SCCs) – no DPF certification claimed. |
| Own infrastructure (The Sales Studios B.V.) | Hosting | Amsterdam, the Netherlands |
| HubSpot | CRM integration | EU (Frankfurt), DPF-certified |
| Salesforce | CRM integration | EU (Hyperforce EU zone, incl. Frankfurt/Paris), DPF-certified |
| Pipedrive | CRM integration | EU (Frankfurt/Dublin/Stockholm; EU contracting entity in Estonia), DPF-certified |
All subprocessors are bound by a data processing agreement and may use data solely for the agreed purposes.
10. International transfers
Where data is processed outside the EEA, we apply appropriate safeguards under the GDPR. HubSpot, Salesforce, Pipedrive, and AssemblyAI use EU hosting or EU processing respectively (see section 9), backed by their DPF certification. For Recall and Anthropic, which do process data outside the EEA, we rely on EU Standard Contractual Clauses (SCCs) as the transfer mechanism.
11. Security
- HTTPS encryption for all data transfers
- Secure token storage on device (expo-secure-store)
- Access security on our servers
- Automatic deletion of audio files after the retention period (section 8)
12. Your rights
As a data subject in the EU/EEA, you have the right to: access, correction, deletion, restriction, portability, objection to processing based on legitimate interest, and — where applicable to AI-driven assessment — the right to request human review of an AI-generated score before it is used in a formal judgment.
Send your request to privacy@reppic.ai. Where your employer is the controller, we route your request to them and support the handling of it. We respond within 30 days.
You may file a complaint with the Dutch Data Protection Authority: autoriteitpersoonsgegevens.nl
13. Changes
We will notify users of material changes via the app, by email, or where the employer is the controller, via the customer organization.
14. Contact
The Sales Studios B.V. St. Geradushof 1, 4744 BC Bosschenhoofd, the Netherlands Email: privacy@reppic.ai Website: https://reppic.ai