Realfy Data Protection Policy
Last updated: 27 April 2026
1. Scope and Purpose
This Data Protection and Privacy Policy describes how Realfy Inc. (“we,” “our,” or “us”) collects, uses, shares, and protects personal and business data when individuals and entities use our software-as-a-service (SaaS) platform and related services. It applies to all products, APIs, and deployments operated by Realfy and covers data concerning visitors, Account holders (Businesses, Agencies, Individuals), and Customers. Because Realfy serves clients globally, including in the European Union/European Economic Area (EEA) and the United States, this policy is strictly aligned with the General Data Protection Regulation (GDPR), the EU Artificial Intelligence Act (AI Act), and comprehensive U.S. state privacy frameworks (including the CCPA, CPA, VCDPA, CTDPA, and UCPA). Sector-specific U.S. laws are incorporated where relevant.
1.1 Service Description and Roles
Realfy provides the infrastructure for Account holders to build, train, and deploy advanced AI agents across third-party communication channels (such as Meta, Instagram, WhatsApp, Telegram, and custom websites).
- Account Holders (Businesses, Agencies, Individuals): These users configure AI models to emulate a brand (AI SDR/AI Agent) or a specific person (AI SDR Agent). Account holders provide proprietary training data. Realfy acts strictly as a data processor regarding this training data; we process it solely upon the Account holder's instructions to operate their AI agent. Account holders are the data controllers for the training data and are responsible for ensuring they have a lawful basis to supply it.
- Customers: Individuals who purchase subscription packs to interact with deployed AI agents on external channels. For Customer data (e.g., identifiers, payment information, and platform usage data), Realfy acts as a data controller to provide the SaaS infrastructure, ensure platform safety, and process billing.
- Other Roles: Realfy engages third-party infrastructure providers (e.g., AWS, Stripe, Runpod) who act as sub-processors, bound by strict contractual obligations to process data solely according to our instructions.
2. Definitions
- Personal Data / Personal Information: Any information that identifies or can reasonably be linked to an individual. Under the GDPR, this includes names, contact details, identification numbers, and online identifiers. Under U.S. laws, it also covers persistent identifiers, biometric information, and other statutory data elements.
- Sensitive Personal Data: Data revealing racial or ethnic origin, political opinions, religious beliefs, genetic or biometric data (used for our identity verification), or health data.
- Controller: The entity that determines the purposes and means of processing personal data.
- Processor: A natural or legal person that processes personal data on behalf of a controller.
- Customer: A user who possesses an active subscription pack to interact with deployed AI agents.
- Minor (Prohibited User): Any individual under the age of 18. Realfy is strictly an adult-only, B2B/commercial platform.
3. What Information Realfy Collects
We adhere strictly to the principle of data minimization, collecting only what is necessary to deliver our SaaS platform and deploy your AI agents.
- Account and Contact Information: Legal names, company details, email addresses, telephone numbers, and account credentials.
- Usage, API, and Device Data: IP addresses, browser types, session data, webhook payloads, routing logs, and API transmission data necessary to connect AI agents to third-party networks (e.g., Meta, Telegram).
- Transaction and Payment Data: Billing addresses and secure payment tokens (e.g., the last four digits of a card). All primary financial data is handled securely by processors like Stripe.
- Proprietary Training Data: Documents, brand guidelines, audio files, videos, and text uploaded by Account holders to train their AI agents.
- Communications and AI Outputs: Interaction logs, audio recordings, and text transcripts generated between Customers and AI agents across deployed channels. We process this to facilitate the service, provide audience analytics to the Account holder, and monitor for safety.
- Biometric Data (For Authentication Only): For Individual Accounts creating an AI SDR Agent, we process biometric data via a secure third-party provider solely to verify the user is genuine, over 18, and consenting to their digital likeness.
4. Legal Bases for Processing (GDPR)
For individuals in the EEA and UK, we process data based on the following legal foundations:
- Contractual Necessity: Processing necessary to provide our SaaS platform, route API calls, and process payments.
- Legitimate Interests: Processing to secure the platform, prevent fraud, maintain third-party integrations, and provide aggregated audience insights, provided these interests do not override your fundamental rights.
- Consent: Where required by law, such as for Biometric Verification, sending marketing communications, or dropping non-essential cookies. Consent can be withdrawn at any time.
- Legal Obligations: Processing required to comply with the EU AI Act, tax laws, accounting standards, and lawful enforcement requests.
5. How Realfy Uses Personal Data
We use data strictly for the purposes outlined below. Crucially, Realfy guarantees that your proprietary training data and Customer interaction logs will NEVER be used to train, fine-tune, or improve our own foundational AI models.
- Service Delivery & Deployment: To host AI agents, route messages to/from third-party platforms (e.g., WhatsApp, Instagram), and process SaaS subscriptions.
- Identity & Likeness Protection: To process Biometric Verification, ensuring no unauthorized deepfakes or impersonations occur on the Platform.
- Audience Insights: To provide Account holders with de-identified, aggregated analytics regarding how Customers interact with their AI agents.
- Platform Security & Moderation: To enforce our Acceptable Use Policy, block NSFW or illegal content, and detect API abuse or fraudulent transactions.
- Legal Compliance: To meet regulatory requirements across global jurisdictions, including strict age-gating and AI transparency laws.
6. Data Sharing and Disclosure
6.1 Service Providers and Sub-Processors
We share data with trusted infrastructure partners to operate the platform (e.g., AWS for secure cloud hosting, Stripe for payments, Runpod for AI compute, and specialized biometric verification partners). These providers are legally bound to protect your data and cannot use it for their own purposes. We do not and will never sell personal or business data for monetary consideration.
6.2 External Deployment Channels
Because our platform deploys AI agents to external networks, interaction data must be transmitted through the APIs of third parties (e.g., Meta, Telegram). This data sharing is technically necessary to provide the Service, and such transmissions are governed by the respective privacy policies of those external networks.
6.3 International Transfers
Realfy operates globally. When transferring personal data from the EEA, UK, or Switzerland to the United States or other jurisdictions, we rely on legally recognized mechanisms, including the EU–U.S. Data Privacy Framework (DPF) and Standard Contractual Clauses (SCCs), ensuring uninterrupted GDPR compliance.
6.4 Legal and Corporate Disclosures
We may disclose data to comply with valid legal processes, protect the safety of the public, or during corporate transactions (e.g., mergers), provided the receiving entity adheres to these privacy standards.
7. Cookies and Similar Technologies
Realfy uses cookies and session tokens primarily to secure your dashboard access, maintain API connections, and analyze platform performance. Users can customize their cookie preferences via our consent management center. Under U.S. state laws, you have the right to opt out of non-essential tracking and targeted advertising.
8. Strict Age Restriction (18+ Platform)
Realfy is strictly an adult-only platform. We do not knowingly collect, process, or store personal data from anyone under the age of 18. Because our platform involves commercial SaaS agreements, advanced AI deployment, and biometric identity verification, minors are categorically prohibited from using the Services.
- If we discover that an Account holder or Customer is under 18, we will immediately terminate the account, disconnect all deployed AI agents, and securely delete all associated data.
- By enforcing a strict 18+ policy, Realfy operates outside the scope of the Children’s Online Privacy Protection Act (COPPA).
9. Individual Rights and Choices
9.1 EU/EEA and UK Rights (GDPR & AI Act)
You have the right to:
- Access & Portability: Request a copy of your data in a machine-readable format.
- Rectification & Erasure: Request corrections or the deletion of your data (the "right to be forgotten").
- Restriction & Objection: Object to certain processing, including marketing.
- Human Intervention: Request human review of automated decisions or AI enforcement actions.
9.2 U.S. State Privacy Rights (CCPA, CPA, VCDPA, etc.)
Depending on your state, you have the right to:
- Know & Access: Request details about the categories of data we process.
- Delete: Request the deletion of your personal information.
- Opt-Out: Opt out of targeted advertising. (Note: Realfy does not "sell" data).
- Non-Discrimination: Receive equal service regardless of exercising your privacy rights.
9.3 How to Exercise Your Rights
To exercise any of these rights, contact us via the methods in Section 13 or use the privacy controls within your Account dashboard. We will verify your identity before processing requests to ensure data security.
10. Data Security
Realfy utilizes enterprise-grade security protocols designed to protect your training data, API keys, and interaction logs. Measures include:
- Technical Safeguards: Encryption at rest, encryption in transit, strict API rate limiting, and multi-factor authentication (MFA) for dashboard access.
- Organizational Safeguards: Routine security audits, role-based access control (RBAC) for Realfy employees, and comprehensive vendor security assessments.
- Incident Response: Maintained protocols to detect, mitigate, and report data breaches to relevant authorities within legally mandated timeframes (e.g., 72 hours under GDPR).
11. Data Retention
We retain personal and proprietary data only for as long as your Account or SaaS subscription is active, or as necessary to comply with legal/tax obligations. If you deactivate your Account, we instantly revoke external API connections and systematically delete your proprietary training data and Customer interaction logs from our active servers.
12. Third-Party Websites and Services
Realfy’s core functionality relies on deploying AI agents to third-party communication networks (e.g., Instagram, WhatsApp, Telegram, custom websites) and utilizing backend infrastructure (e.g., AWS, Stripe). When an AI agent operates on an external channel, or when you interact with those channels, the data processed there is subject to that specific third party’s terms and privacy policies. Realfy is not responsible for the data collection, content moderation, or privacy practices of Meta, Telegram, AWS, Stripe, or any other external platform.
13. Contact Information and Complaints
If you have questions about this policy, wish to exercise your data rights, or need to contact our Data Protection Officer, please reach out:
Data Protection Officer (DPO)
Realfy Inc.
Coastal Highway 16192, Lewes, Delaware 19958, USA
Email: hello@realfy.ai
- EU/EEA Residents: You have the right to lodge a complaint with your national Data Protection Authority (DPA).
- U.S. Residents: You may file a complaint with your state’s attorney general regarding local privacy law compliance.
14. Changes to this Policy
We may update this policy periodically to reflect advancements in our AI architecture, third-party API changes, or evolving global regulations (such as the EU AI Act). We will revise the “Last Updated” date and provide prominent notice (e.g., a dashboard alert or email) for any material changes. Your continued use of the Services post-update constitutes your acceptance of the revised policy.