SmartReply

Privacy Policy

Last updated: 11 July 2026  ·  SmartReply, a product of Made in Graphic Ltd  ·  Company No: 13094248 (England & Wales)

This Privacy Policy describes how Made in Graphic Ltd collects, uses, and protects your personal data when you use SmartReply, our AI-powered customer-messaging and appointment-booking automation service for WhatsApp, Facebook Messenger, Instagram and web chat.

1. Data We Collect

2. How We Use Your Data

To provide and improve SmartReply, manage your account, process payments, send service notifications, and respond to support requests. We never sell your data to third parties.

3. Customer Conversation Data (WhatsApp, Messenger, Instagram & Web Chat)

SmartReply connects to your messaging channels — your WhatsApp Business account and, where you enable them, your Facebook Page (Messenger), Instagram account and website web-chat widget — to receive and respond to your customers' messages. This includes text, media, voice notes and location messages, all of which are handled under the same rules. Conversation data is processed to generate replies, book appointments, and route conversations to your team, and is not used for any purpose beyond delivering the SmartReply service. Customer conversation data is not shared with third parties and is not used to train generalised AI models. Message content is sent to our AI providers (OpenAI / Anthropic) only at the moment a reply is generated — or when you actively use the in-panel AI assistant — in accordance with their data processing agreements, and is not retained by them beyond the operational need.

4. Email Marketing & Newsletters

When you opt in to receive marketing emails from us (for example, through our SmartReply WhatsApp ROI Calculator or product newsletters), we collect:

Legal basis: Consent (GDPR Article 6(1)(a)). We use a double opt-in flow: you must click a confirmation link in your email before we send any further messages.

All marketing emails include a visible unsubscribe link in the footer and a one-click unsubscribe header (RFC 8058) that Gmail and Outlook use to show a native unsubscribe button. You can also email unsubscribe@madeingraphic.co.uk to opt out.

Marketing email delivery is processed by Resend.com and bot protection by Cloudflare Turnstile (both included in the sub-processor list in our Data Processing Agreement).

Unsubscribed records are retained on a suppression list for up to 3 years to honour your opt-out. For full deletion, contact info@madeingraphic.co.uk.

5. Third-Party Processors

We share personal data only with service providers that help us deliver SmartReply, limited to the following categories: messaging platform providers, payment processors, AI model providers, calendar/scheduling providers, email delivery providers, bot-protection services, and hosting providers. Each operates under a data processing agreement and applicable data protection law; we never sell personal data.

The full, named list of our sub-processors — including each provider's purpose and region — is published in section 5 of our Data Processing Agreement and is kept up to date when a sub-processor is added or replaced.

6. Data Retention

Account and conversation data is retained while your account is active. When you request account deletion in the panel, your account is deactivated for a 90-day grace period during which you can cancel the request; at the end of this period all personal data is permanently removed. Billing records may be retained for up to 7 years for legal compliance. Marketing email subscribers who unsubscribe are kept on a suppression list for up to 3 years, then deleted; full deletion on request at any time.

Support ticket attachments (screenshots you optionally add to a support request; JPEG/PNG, up to 2 MB each) are stored to help us resolve your request. They are kept while the request is open and automatically deleted 90 days after the request is closed.

Media files (images, audio, video and documents) that your customers send to your connected channels are stored only to display them to you in the operator inbox. Per-file size limits apply (16 MB for images, audio and video; 50 MB for documents); files above these limits are not stored. Stored media is automatically and permanently deleted 90 days after receipt and cannot be recovered afterwards (WhatsApp's own download links also expire within minutes of delivery). Daily per-account media volume limits apply to protect service availability. These measures support the GDPR/KVKK principles of data minimisation (Art. 5(1)(c)) and storage limitation (Art. 5(1)(e)).

Conversation message content (the questions your customers send and the answers given, together with the customer’s display name and phone number) is retained while needed to operate your support inbox and, by default, anonymised after 24 months (configurable per account). Anonymisation permanently removes the message text and customer identifiers, keeping only non-identifying analytics (timestamps and AI quality metrics); it cannot be reversed. This supports the GDPR/KVKK principle of storage limitation (Art. 5(1)(e)).

7. Your Rights (GDPR / KVKK)

You have the right to access, correct, or delete your personal data, restrict or object to processing, and request data portability. To exercise your rights, contact us at info@madeingraphic.co.uk.

8. Cookies

We use essential session cookies to keep you logged in. We use localStorage to remember your language preference. We do not use advertising cookies, tracking pixels, or analytics cookies.

9. Security

All data is transmitted over HTTPS. Passwords are hashed. WhatsApp connection credentials and OAuth tokens are encrypted at rest. We follow industry-standard security practices to protect your data.

10. Contact

Made in Graphic Ltd · Company No: 13094248 · info@madeingraphic.co.uk · smart-reply.co.uk · Data Processing Agreement