1. Who is responsible for your data
Futuristic SRL is the data controller for JoyReply accounts and the service data described here. You can contact us at privacy@joyreply.com for privacy matters and contact@joyreply.com for product support.
When a creator connects a social Page, that creator remains responsible for the relationship with their audience. JoyReply processes Page and conversation data on the creator's instructions so the service can work.
2. Data we handle and where it comes from
We collect information you give us, information produced while you use JoyReply, and information received from services you choose to connect.
- Account and workspace details, language, role, settings, support messages, and security events.
- Connected Page or profile identifiers, encrypted access tokens, permissions, posts, comments, replies, reactions, media context, and available insights.
- Setter program profiles, qualification rules, saved booking links, conversation history, contact details a lead chooses to provide, stop or no-contact state, and booking-link handoff state.
- Knowledge sources, approved website pages, uploaded notes or documents, brand examples, and crawl records.
- Studio requests, clarifying answers, uploaded images or videos, generated or edited assets, review decisions, voice choices, project state, credit records, and provenance metadata.
- Calendar drafts, planned or scheduled posts, selected Page, publishing state, and growth or audience signals when the platform makes them available.
- Device, browser, session, request, audit, error, abuse-prevention, and diagnostic data needed to secure and operate the service.
3. Why we use it and our legal bases
We use only the data needed for the purpose at hand. The legal basis depends on the feature and your relationship with us.
| Purpose | Typical legal basis |
|---|---|
| Create and secure an account; provide connected-Page, Inbox, Setter, Studio, Calendar, Growth, and support functions | Contract or steps requested before a contract |
| Prevent abuse, investigate failures, protect accounts, keep audit records, and improve reliability | Our legitimate interests, balanced against your rights |
| Send optional product or marketing messages | Consent, or another basis allowed by applicable electronic-communications law |
| Keep accounting, legal, compliance, or dispute records | Legal obligation or legitimate interests |
| Use optional device access or non-essential storage in the future | Consent, where required |
5. Setter and automated conversations
A workspace owner can configure JoyReply to qualify people who ask about a specific programme and to share only the saved booking link when the conversation reaches the right point. JoyReply must not invent programme facts, discounts, availability, or a confirmed booking.
A request such as stop, do not contact me, or an equivalent clear refusal closes the automated conversation. When the system cannot continue safely, it should stop rather than keep pushing the person. We do not use Setter conversations to make decisions that produce legal or similarly significant effects about the person.
6. Studio, uploads, Calendar, and publishing
Studio can process prompts, answers, reference files, stock-media selections, generated material, edits, narration choices, and review notes to prepare content. Files stay private to the workspace unless the owner downloads, approves, schedules, or publishes them through an enabled capability.
Calendar stores plans, drafts, selected destinations, and platform status. A saved plan is not the same as a successful platform publication. JoyReply shows the state returned by the connected service and keeps restricted actions capability-gated.
7. AI assistance and automated analysis
JoyReply uses AI to understand post and conversation context, classify intent and safety signals, draft replies, guide Setter conversations, plan content, and help create or edit media. Outputs can be incomplete or wrong, so sensitive claims and public actions need the level of review shown in the workspace.
We do not sell customer content. Customer data is used to provide and protect that customer's workspace. We do not use it to train a shared JoyReply model unless we first provide a separate, valid choice that clearly explains the change.
9. International transfers
Some providers or connected platforms may process data outside Romania or the European Economic Area. Where data-protection law requires it, we rely on an adequacy decision, approved contractual safeguards such as standard contractual clauses, or another lawful transfer mechanism.
10. How long we keep data
We keep account and workspace data while the account is active. Connected data, drafts, assets, conversations, and plans remain only as long as needed to provide the feature, preserve an active workspace, resolve support or security issues, or meet legal obligations.
When an account or channel is deleted, we remove or anonymise eligible data after verification. Limited security, legal, accounting, dispute, and deletion-request records may remain for the period required by law or reasonably needed to establish what happened. Backups expire through their normal rotation.
11. Security
We use access controls, encrypted connection credentials, restricted administration, session protection, logs, and operational checks designed to reduce unauthorised access or loss. No online service can promise perfect security. Please use a strong password and tell us promptly if you suspect misuse.
12. Your rights
Depending on the situation, you can ask for access, correction, deletion, restriction, portability, or objection. You can withdraw consent at any time where consent is the basis, without affecting earlier lawful processing. You also have the right to complain to a data-protection authority.
Email privacy@joyreply.com from the account address when possible. We may ask for enough information to verify the request and protect the wrong account from being changed or deleted. We normally respond within one month; the law allows an extension for complex or numerous requests, in which case we will explain the delay.
13. Children and policy changes
JoyReply is a professional workspace and is not directed to children. Do not use it to collect unnecessary information about minors.
We update this policy when the product, providers, or law materially changes. The effective date at the top identifies the current version. If a change materially affects active users, we will use a reasonable in-product or email notice.
Need a copy of your data or want it deleted?
Use the signed-in Settings request when available, or email privacy@joyreply.com with your account email and the connected Page name.
4. Connected social Pages and audience data
JoyReply receives data only from Pages, profiles, or channels an authorised account connects. The exact fields and actions depend on the permissions granted by the platform and the capabilities enabled in JoyReply.
Comments and messages also contain data about people who have not opened a JoyReply account. We use that data only to show the authorised Page owner the conversation, understand the post context, prepare or send a permitted response, apply a stop request, and keep the Page-specific audit trail. Switching Pages must switch the data scope as well.