Privacy policy
Last updated 2026-10-02
GroundedReply (NETBEARS TEAM SRL) processes personal data to run the service described here. GroundedReply drafts client email replies citing the client's own QuickBooks/Xero ledger line and the firm's written procedure, for the firm to read, edit and send.
1. Data controller
NETBEARS TEAM SRL, VAT ID RO37261366, Corneliu Baba 8, Iași, Romania, is the data controller for the personal data we collect to run GroundedReply (groundedreply.com) for you: your account, billing, support and technical data described below.
For personal data about other people contained in the content you submit for processing (for example names or contact details inside your documents), your organisation is the controller and we act as its processor, processing that data only on your instructions and only to provide the service. Our data processing agreement sets out those terms. Questions about it: hello@groundedreply.com.
2. What personal data we collect
- Account data: email address, and password (Amazon Cognito, our identity provider, stores a salted hash — we never see or store your password in plain text). If you sign in with a federated provider we configure, we also receive the identifier and verified-email status that provider sends us.
- Content you submit for processing: Client email question (pasted text); Firm's written procedures / engagement-letter text; Client QuickBooks Online / Xero ledger export or category totals.
- Billing data: purchases and credit balance are recorded in our own ledger. Card details are collected and processed by Creem, our payment processor and merchant of record — we never see or store your card number.
- Usage and support data: messages you send us through the contact form or by email (see inbound email), and API keys you create (we store only the last 4 characters and metadata; we never store the full key in our database).
- Connected apps: if you connect an AI app to your account, we store the details of that connection and the tokens we issue to it (see connected apps).
- Technical logs: the IP address and request details API Gateway, Lambda and Step Functions record for every request, for security and abuse investigation.
2b. Connected apps (MCP)
GroundedReply has an MCP server at /api/v1/mcp. It lets an AI app that you allow submit jobs, read results and spend your credits for you. You connect an app with OAuth 2.1: you sign in to GroundedReply and allow the app on a consent screen. Nothing is connected until you allow it. An AI assistant you connect (for example Claude) receives the data you ask it to fetch, such as units, job status, results and file contents, and processes it under its own terms.
When you allow an app, we issue it an access token and a refresh token. The access token is valid for 24 hours. The refresh token is valid for 30 days and is replaced each time the app uses it. We store the refresh token only as a SHA-256 hash, never in plain text. We also keep the name the app gave itself, the address it asked to be sent back to, and when it was connected.
The Connected apps table on the API keys page of your dashboard lists every app you have connected. You can revoke an app there at any time, and its tokens stop working. You can have up to 5 connected apps at once. The app you connect is your own tool, not our processor: what it does with your results is between you and its provider.
2c. Inbound email
Email sent to hello@groundedreply.com is received by Amazon SES. A raw copy of the message is stored in our AWS storage in Frankfurt for 30 days, and the message is forwarded to the mailbox we use to read and answer support mail. The raw copy is deleted after 30 days. The copy in our mailbox follows the contact-message retention in retention below.
3. Purposes of processing
- Providing the service described above.
- Account authentication and access control.
- Processing payments and maintaining the credit ledger.
- Sending you the notifications this product describes: Job finished email: the reply draft is ready, with the number of items to check, and replying to messages you send us.
- Keeping the service secure and investigating abuse.
4. Legal basis for processing
We process your data under the following legal bases (GDPR Article 6): performance of a contract (providing the service you signed up for and processing payment for it), legitimate interest (service security, abuse prevention), and legal obligation (retaining financial records, responding to lawful requests from ANSPDCP (the Romanian National Supervisory Authority for Personal Data Processing) or ANPC (the Romanian National Authority for Consumer Protection)).
5. Data sharing
We share personal data only with the processors needed to run the service, each under its own data processing terms:
- Amazon Web Services (AWS) — hosting and storage, all in the eu-central-1 (Frankfurt) region.
- Amazon Bedrock, an AWS service — runs the AI models that draft and review your results, on Bedrock's EU cross-region inference profiles, entirely within AWS's infrastructure; it processes your content only to produce the result. AWS is the processor for these calls; Anthropic, the models' developer, does not receive your data, and the calls are not used to train any model.
- Creem — our payment processor and merchant of record for credit-pack purchases. Creem is an independent data controller for the payment data it collects: it handles your card data, applicable sales tax/VAT, and issues your invoice/receipt under its own privacy policy.
- Amazon SES — sends this product's own notifications to you (see purposes of processing above) and receives the email you send to hello@groundedreply.com (see inbound email).
We do not sell personal data, and we do not share it for advertising.
6. Data storage and security
Your data is stored in AWS's eu-central-1 (Frankfurt, Germany) region: encrypted at rest, encrypted in transit (TLS), with access limited to what the service needs to run.
6a. International data transfers
AWS processes your data exclusively in the EU for this service (eu-central-1 hosting, the EU Bedrock inference profile); Anthropic does not receive your data through our own processing (see data sharing above). Data you fetch into an AI app you connect (see connected apps) goes wherever that app's provider processes it, under its own terms. Creem, as an independent controller for payment data, may process billing data outside the EU under its own compliance framework (including Standard Contractual Clauses where applicable); see Creem's own privacy policy for details.
7. Retention
- Uploads never used in a job: deleted after 72 hours.
- Failed or unpaid jobs: their files are deleted after 14 days.
- Paid work: kept for 365 days from when the job started, so you can re-download results; you can delete a job at any time before that.
- Credit ledger: kept as a financial record, as long as the law requires — currently up to 10 years in Romania — a legal obligation, not deleted when a job or account is deleted.
- Contact form / email messages: kept 365 days, so we can find the history of a conversation with you.
- Inbound email, raw copy: the raw copy of mail sent to hello@groundedreply.com is deleted after 30 days.
- Connected apps: an access token is valid for 24 hours and a refresh token for 30 days. A connection ends when you revoke it or when its refresh token expires unused.
- Technical logs: API Gateway, Lambda and Step Functions logs are kept 30 days. The contact form's rate limiter keeps the submitting IP address for about 1 hour, purely to block bursts of spam.
- Email address and remaining balance after account deletion: if you delete your account while you still have credits, we keep only your email address and remaining balance, and only with your consent in the delete dialog. We keep them so the credits are still there if you sign in again with the same email. If you have no credits left, we keep neither. You can withdraw your consent by emailing hello@groundedreply.com, and we then erase both, except where the law requires us to keep a record. You can ask us at any time to erase the email address and balance we kept. The kept credits are then lost. This does not affect a refund of an unused pack within 14 days of purchase.
- You can delete a job, or your whole account, from the dashboard at any time; account deletion removes your sign-in identity, your stored content, your jobs and your API keys at once (the ledger is kept, per above).
8. How results are produced and checked
A second, stronger AI model reviews every result, fixes what it can, and lists what is left for you to decide. Results are model output checked by code and by a second model; they are not verified by a person. Your documents are sent to AI models running in EU regions only. No decision with legal or similarly significant effect on you is made by these models; you decide what to do with a result. Our staff do not read your documents except for support, security or legal reasons.
9. Your rights
Under the GDPR, you have the right to: access the personal data we hold about you; request correction of inaccurate data; request erasure ("right to be forgotten"); request restriction of processing; data portability; and object to processing based on legitimate interest. These rights apply to the email address and remaining balance we keep after account deletion too: you can ask for access to them, or for their erasure, and you can withdraw your consent at any time. To exercise any of these, email hello@groundedreply.com. You also have the right to lodge a complaint with ANSPDCP (the Romanian National Supervisory Authority for Personal Data Processing) (see complaints below).
9a. Minors
GroundedReply is for adults and businesses. It is not directed at, and we do not knowingly collect data from, individuals under 18.
9b. Data Protection Officer (DPO)
NETBEARS TEAM SRL has not appointed a statutory Data Protection Officer, as our processing does not meet the GDPR's mandatory-DPO thresholds. Data protection questions can be sent to hello@groundedreply.com.
10. Complaints
If you believe we have not handled your personal data properly, please contact us first at hello@groundedreply.com. You may also lodge a complaint with ANSPDCP (the Romanian National Supervisory Authority for Personal Data Processing): https://www.dataprotection.ro/.
11. Changes to this policy
We may update this policy as the service changes. The date at the top of this page is when it was last updated; material changes will also be noted on this page.
12. Contact
Company: NETBEARS TEAM SRL
Trade Register: J2017000687229
EUID: ROONRC.J2017000687229
VAT ID: RO37261366
Address: Corneliu Baba 8, Iași, Romania
Phone: +40 742 121 246
Email: hello@groundedreply.com