Privacy Policy
Effective Date: March 9, 2026
FastReply ("Company," "we," "us," or "our") respects your privacy and is committed to protecting your personal information. This Privacy Policy explains in detail how we collect, use, store, share, and protect your information when you use the FastReply website at fastreply.io, Chrome browser extension, APIs, and all related services, features, and applications (collectively, the "Service").
This Privacy Policy is incorporated into and forms part of our Terms of Service. Capitalized terms used but not defined in this Privacy Policy have the meanings given to them in the Terms of Service.
BY CREATING AN ACCOUNT, INSTALLING THE CHROME EXTENSION, OR OTHERWISE ACCESSING OR USING THE SERVICE, YOU ACKNOWLEDGE THAT YOU HAVE READ, UNDERSTOOD, AND AGREE TO THE COLLECTION, USE, AND SHARING OF YOUR INFORMATION AS DESCRIBED IN THIS PRIVACY POLICY. If you do not agree, you must not access or use the Service.
1. Information We Collect
We collect information in three categories: information you provide directly, information collected automatically, and information from the Chrome extension.
1.1 Information You Provide Directly
- Account registration information: Name, email address, and password when you create an account. If you register using a third-party authentication provider, we may receive your name and email from that provider.
- Profile and personalization information: Profession, target audience, keywords, services offered, writing style preferences, tone preferences, and other customization settings you provide to personalize AI-generated replies
- Memories and personal context: Personal notes, facts, background information, and contextual data you voluntarily add to improve reply personalization
- Social media content: The text of social media posts you submit for reply generation, and any edits or modifications you make to generated replies within the Service
- Payment and billing information: Payment method details (credit/debit card information), billing address, and transaction history. Payment card details are processed and stored securely by our payment processor, Stripe. We do not store your full credit card number, CVV, or full payment credentials on our servers. We retain only a tokenized reference, card type, last four digits, and expiration date for display and billing management purposes.
- Communications: The content and metadata of emails, support tickets, chat messages, or other communications you send to us or our support team
- Feedback and surveys: Cancellation reasons, satisfaction ratings, feature requests, bug reports, and other feedback you voluntarily provide
- Mailing list preferences: Your email communication preferences and mailing list opt-in status
1.2 Information Collected Automatically
When you access or use the Service, we automatically collect certain information, including:
- Usage and activity data: Features accessed, pages visited within the dashboard, number of replies generated, credit consumption history, button clicks, feature interactions, session duration, frequency of use, and interaction patterns
- Device and browser information: Browser type and version, operating system and version, screen resolution, device type (desktop/mobile), language settings, and time zone
- Network information: IP address, approximate geographic location derived from IP address, internet service provider, and connection type
- Log data: Server logs recording access times, pages viewed, referring URLs, HTTP response codes, request headers, and error logs
- Authentication data: Login timestamps, login IP addresses, session identifiers, and authentication method used
- Cookies and similar technologies: Session cookies, persistent cookies, and local storage data used to maintain your login state, remember preferences, and ensure security (see Section 9 for details)
1.3 Information from the Chrome Extension
When you install and use the FastReply Chrome extension, we collect the following information:
- The text content of social media posts you actively choose to generate replies for by clicking the FastReply button or invoking the extension
- Your interactions with the extension interface (e.g., clicking "Generate Reply," selecting a tone, copying a reply)
- Extension version information and installation/update events
- Error logs and crash reports from the extension
What the extension does NOT do:
- The extension does NOT passively monitor, scrape, or read web pages you visit
- The extension does NOT collect data from any page unless you actively invoke it
- The extension does NOT access information outside of the specific content element you interact with (e.g., a single post or comment)
- The extension does NOT read your browsing history, bookmarks, downloads, or other browser data
- The extension does NOT access your social media credentials, passwords, or direct messages
- The extension does NOT run or collect data in the background when you are not using it
- The extension does NOT inject advertisements or tracking pixels into web pages
The extension requires certain Chrome permissions to function (such as accessing the active tab when invoked). These permissions are used solely to provide the Service functionality and are requested in accordance with Google Chrome Web Store policies.
1.4 Information We Do NOT Collect
For clarity, we do not collect:
- Social Security numbers, government-issued identification numbers, or national ID numbers
- Biometric data (fingerprints, facial recognition, voice prints)
- Health, medical, or genetic information
- Precise geolocation data (GPS coordinates)
- Financial account numbers (bank accounts, routing numbers) -- payment processing is handled entirely by Stripe
- Information about your religious beliefs, political opinions, sexual orientation, racial or ethnic origin, or trade union membership
2. How We Use Your Information
We use the information we collect for the following purposes:
2.1 Providing and Operating the Service
- Generate personalized AI replies based on your profile, preferences, memories, and the content you submit
- Process your requests and deliver generated content
- Authenticate your identity and manage your account
- Process payments, manage subscriptions, and track credit usage
- Provide customer support and respond to your inquiries
2.2 Improving and Developing the Service
- Analyze aggregated usage patterns and trends to enhance existing features and develop new ones
- Identify and fix bugs, errors, and performance issues
- Conduct internal research and analytics to improve AI output quality
- Test new features, designs, and user experiences
2.3 Communication
- Send transactional emails (account confirmations, password resets, billing receipts, subscription changes, credit alerts)
- Send service-related announcements (planned maintenance, security notices, terms updates, new features)
- With your explicit consent, send marketing and promotional communications
2.4 Security and Fraud Prevention
- Detect, investigate, and prevent fraud, abuse, unauthorized access, and other harmful activities
- Monitor for violations of our Terms of Service and Acceptable Use Policy
- Protect the security and integrity of the Service, our users, and the public
- Log authentication events for audit and security purposes
2.5 Legal and Compliance
- Comply with applicable laws, regulations, legal processes, and governmental requests
- Enforce our Terms of Service and other agreements
- Protect our legal rights, property, and safety and those of our users
- Respond to subpoenas, court orders, or other legal processes
2.6 Aggregate and Anonymized Analysis
- Create aggregated, de-identified, or anonymized data sets that do not identify any individual user
- Use such data for any lawful purpose, including business analytics, benchmarking, research, and improving the Service
3. AI Processing and Generated Content
3.1 How AI Processing Works
When you use the Service to generate a reply, the following data is transmitted to our servers and then to our third-party AI provider (currently Google Gemini):
- The text content of the social media post you are replying to
- Your profile information and personalization settings (profession, audience, writing style, etc.)
- Your stored memories/context (if applicable)
- Your selected tone and any other generation parameters
3.2 AI Provider Data Handling
Our current AI provider (Google Gemini API) processes this data in real time to generate reply suggestions. Based on our agreement with and the published policies of our AI provider:
- Data sent via the API is used solely to generate the requested response
- The AI provider does not use API data to train, improve, or fine-tune its general-purpose models
- Data is not retained by the AI provider beyond the immediate processing session, except as may be required for safety monitoring, abuse prevention, and legal compliance
We do not control our AI provider's internal practices beyond our contractual agreements. We encourage you to review Google's AI data handling policies for additional detail.
3.3 Our Use of AI Data
We do not use your individual inputs or generated outputs to train, fine-tune, or improve AI models. We may use aggregated, anonymized usage statistics (e.g., average response length, feature popularity, error rates) to improve the Service, but this data does not contain personally identifiable information or specific content you submitted.
3.4 Changes to AI Providers
We may change our AI provider(s) at any time. If we switch to a different AI provider, the data transmitted for processing will be subject to the new provider's data handling practices. We will update this Privacy Policy to reflect any such changes and will ensure that any new provider offers data protection standards at least comparable to our current provider.
4. How We Share Your Information
We do not sell, rent, or trade your personal information to third parties for their marketing purposes. We share your information only in the following limited circumstances:
4.1 Service Providers and Processors
We share information with third-party service providers who process data on our behalf to help us operate and deliver the Service. These providers are contractually obligated to use your data only for the purposes we specify and to maintain appropriate security measures. Our current service providers include:
- Stripe: Payment processing, subscription management, invoicing, and fraud detection. Stripe receives your payment method details, billing address, email address, and transaction history. Stripe's privacy policy: stripe.com/privacy
- Google (Gemini API): AI content generation. Google receives the text content submitted for processing (post text, profile context, memories). Google's privacy policy: policies.google.com/privacy
- DigitalOcean: Cloud hosting, infrastructure, database hosting, and content delivery. DigitalOcean stores all Service data on its servers. DigitalOcean's privacy policy: digitalocean.com/legal/privacy-policy
- Mailchimp (Intuit): Email marketing communications (only if you opt in to our mailing list). Mailchimp receives your email address and name. Mailchimp's privacy policy: mailchimp.com/legal/privacy
We may engage additional service providers from time to time. We will update this list when we add material new providers that process personal information.
4.2 Legal Requirements and Protection
We may disclose your information when we believe in good faith that disclosure is necessary to:
- Comply with applicable laws, regulations, legal processes, subpoenas, court orders, or governmental requests
- Enforce our Terms of Service, Privacy Policy, or other agreements
- Investigate, prevent, or take action regarding suspected fraud, abuse, security incidents, or technical issues
- Protect the rights, property, safety, or security of FastReply, our users, or the public as required or permitted by law
- Respond to an emergency involving danger of death or serious physical injury
4.3 Business Transfers
If FastReply is involved in a merger, acquisition, reorganization, bankruptcy, dissolution, sale of all or a portion of its assets, or similar transaction, your personal information may be transferred, sold, or disclosed as part of that transaction. In such an event:
- We will notify you by email and/or prominent notice on the Service before your information is transferred and becomes subject to a different privacy policy
- We will use reasonable efforts to ensure the acquiring entity honors the commitments in this Privacy Policy
- You will have the opportunity to delete your account before the transfer takes effect
4.4 With Your Consent
We may share your information with third parties when you have given us your explicit consent to do so.
4.5 Aggregated and Anonymized Data
We may share aggregated, de-identified, or anonymized data that cannot reasonably be used to identify you with third parties for any lawful purpose, including research, analytics, benchmarking, and marketing.
5. Data Retention
We retain your information for as long as necessary to fulfill the purposes described in this Privacy Policy, unless a longer retention period is required or permitted by law.
5.1 Retention Periods
- Account data (name, email, profile): Retained for the lifetime of your account plus 30 days after deletion request
- Authentication and login logs: Retained for up to 24 months for security and fraud detection
- Usage and analytics data: Retained for up to 24 months in identifiable form; retained indefinitely in aggregated/anonymized form
- Payment and billing records: Retained for 7 years as required by tax, accounting, and financial regulations
- Support communications: Retained for up to 36 months after resolution for quality assurance and legal purposes
- Cancellation feedback: Retained indefinitely in anonymized form for product improvement
- Generated replies: Not stored persistently. Replies are generated in real time, delivered to you, and not maintained in a history. We do not keep a record of specific replies generated for your account.
- Social media post text (input): Processed in real time for reply generation and not stored after the request is complete, except temporarily in server logs (retained up to 30 days)
- Memories: Retained until you delete them or your account is deleted
- Mailing list data: Retained until you unsubscribe or request deletion
5.2 Deletion Process
When you request account deletion or your account is terminated:
- We will begin the deletion process within 7 days of receiving the request
- Your personal data will be permanently removed from active systems within 30 days
- Data in backups and disaster recovery systems will be overwritten within 90 days through our regular backup rotation cycle
- Some data may be retained beyond these periods where required by law (e.g., tax records, legal hold obligations)
6. Data Security
We take the security of your information seriously and implement industry-standard technical, administrative, and physical safeguards to protect it.
6.1 Technical Measures
- Encryption in transit: All data transmitted between your device and our servers is encrypted using TLS 1.2 or higher (SSL/HTTPS)
- Encryption at rest: Sensitive data stored in our databases is encrypted at rest using AES-256 encryption
- Password security: All passwords are hashed using bcrypt with per-user salts. We never store plaintext passwords.
- CSRF protection: All forms and state-changing requests are protected against cross-site request forgery attacks
- Secure headers: We implement security headers including HSTS, X-Content-Type-Options, X-Frame-Options, and Content-Security-Policy
- API security: API access is authenticated and rate-limited to prevent abuse
6.2 Administrative Measures
- Access to personal data is restricted to authorized personnel on a need-to-know basis
- All team members with data access undergo security awareness training
- We conduct regular security reviews and vulnerability assessments
- Third-party service providers are vetted for their security practices before engagement
6.3 Infrastructure Security
- Our infrastructure is hosted on DigitalOcean, which maintains SOC 2 Type II and ISO 27001 certifications
- Database access is restricted to application servers only (no public internet access)
- We maintain regular automated backups with encryption
- We use firewalls and network segmentation to isolate sensitive systems
6.4 Limitations
While we take reasonable precautions to protect your information, no method of transmission over the internet or method of electronic storage is 100% secure. We cannot guarantee absolute security against all threats. In the event of a security incident, we will follow our incident response procedures as described in Section 7.
7. Data Breach Notification
In the event of a data breach that affects your personal information, we will:
- Investigate the breach promptly and take immediate steps to contain it and mitigate harm
- Notify affected users by email within 72 hours of becoming aware of a breach that is likely to result in a risk to your rights and freedoms, or as otherwise required by applicable law
- Notify relevant regulatory authorities as required by applicable law (including data protection authorities under GDPR)
- Provide details about the nature of the breach, the types of data affected, the likely consequences, and the measures we are taking to address it
- Offer guidance on steps you can take to protect yourself (e.g., changing passwords)
8. Your Rights and Choices
We respect your rights over your personal information. Depending on your location and applicable law, you may have the following rights:
8.1 Access and Portability
You have the right to request a copy of the personal data we hold about you in a structured, commonly used, and machine-readable format (e.g., JSON or CSV). You may also request that we transfer your data directly to another service provider where technically feasible.
8.2 Correction and Rectification
You can update your profile and account information at any time through the Service dashboard. If you cannot correct information through the dashboard, contact us and we will update it promptly.
8.3 Deletion (Right to be Forgotten)
You can request deletion of your account and all associated personal data by contacting us at support@fastreply.io. We will process your request in accordance with our data retention policy (Section 5.2). Note that certain data may be retained as required by law.
8.4 Restriction of Processing
You may request that we restrict the processing of your personal data in certain circumstances, such as when you contest the accuracy of the data or object to our processing.
8.5 Objection to Processing
Where we process your data based on legitimate interest, you have the right to object to such processing. We will cease processing unless we demonstrate compelling legitimate grounds that override your interests.
8.6 Withdrawal of Consent
Where we process your data based on your consent (such as marketing emails), you may withdraw your consent at any time. Withdrawal does not affect the lawfulness of processing based on consent before its withdrawal.
8.7 Marketing Opt-Out
You can unsubscribe from marketing emails at any time by:
- Clicking the "unsubscribe" link at the bottom of any marketing email
- Updating your communication preferences in your account settings
- Contacting us at support@fastreply.io
Please note that even if you opt out of marketing emails, we will still send you transactional and service-related communications (e.g., billing receipts, security notices, terms updates).
8.8 Cookie Preferences
You can control cookies through your browser settings. See Section 9 for detailed information about our cookie practices.
8.9 How to Exercise Your Rights
To exercise any of these rights, contact us at support@fastreply.io with the subject line "Privacy Rights Request." Please include:
- Your full name and email address associated with your account
- The specific right(s) you wish to exercise
- Any additional information that will help us locate your data
We will verify your identity before processing your request. We will respond to all valid requests within 30 days (or sooner if required by applicable law). If we need additional time, we will notify you of the extension and the reasons for it. We do not charge a fee for processing reasonable requests, but we reserve the right to charge a reasonable fee or refuse manifestly unfounded or excessive requests.
8.10 Authorized Agents
You may designate an authorized agent to submit privacy rights requests on your behalf. We may require the agent to provide proof of authorization and we may contact you directly to verify the request.
9. Cookies and Tracking Technologies
9.1 Types of Cookies We Use
- Strictly necessary cookies: Required for core functionality including authentication, session management, CSRF protection, and security. These cookies are essential for the Service to function and cannot be disabled. They are set in response to actions you take (logging in, filling forms, setting preferences).
- Functional cookies: Remember your preferences, settings, and choices to provide a more personalized experience. These include language preferences, display settings, and recently viewed items.
9.2 What We Do NOT Use
- We do NOT use third-party advertising cookies or ad trackers
- We do NOT use cross-site tracking technologies
- We do NOT participate in retargeting or behavioral advertising networks
- We do NOT use social media tracking pixels or widgets that collect data
- We do NOT use fingerprinting or any other covert tracking technologies
9.3 Managing Cookies
You can manage cookies through your browser settings. Most browsers allow you to block or delete cookies. However, if you block essential cookies, the Service may not function properly (e.g., you may not be able to log in). Instructions for managing cookies can typically be found in your browser's "Help," "Settings," or "Preferences" menu.
9.4 Do Not Track
Some browsers transmit "Do Not Track" (DNT) signals. Since there is no industry-standard interpretation for DNT signals, we do not currently respond to them. However, because we do not use third-party advertising trackers, our data collection practices are consistent regardless of your DNT setting.
10. International Data Transfers
FastReply is operated from the United States. If you access the Service from outside the United States, please be aware that your information will be transferred to, stored, and processed in the United States, where data protection laws may differ from those in your jurisdiction.
10.1 European Users (GDPR)
If you are located in the European Economic Area (EEA), United Kingdom, or Switzerland:
Legal Bases for Processing: We process your personal data under the following legal bases as defined by the GDPR:
- Performance of contract (Art. 6(1)(b)): Processing necessary to provide the Service you signed up for, including account management, payment processing, and reply generation
- Legitimate interest (Art. 6(1)(f)): Processing for analytics, security monitoring, fraud prevention, service improvement, and direct marketing to existing customers (subject to your right to object)
- Consent (Art. 6(1)(a)): Marketing communications to non-customers, optional data collection, and mailing list enrollment. You may withdraw consent at any time.
- Legal obligation (Art. 6(1)(c)): Processing necessary to comply with tax, accounting, and other legal obligations
International Transfer Mechanisms: Where we transfer your personal data outside the EEA/UK, we rely on:
- Standard Contractual Clauses (SCCs) approved by the European Commission
- Adequacy decisions by the European Commission where applicable
- Other lawful transfer mechanisms as recognized under GDPR
Additional GDPR Rights: In addition to the rights listed in Section 8, you have the right to:
- Lodge a complaint with your local data protection authority (supervisory authority)
- Restrict processing of your data in certain circumstances
- Object to processing based on legitimate interest
- Not be subject to solely automated decision-making (see Section 11)
- Receive your data in a portable format
10.2 California Users (CCPA/CPRA)
If you are a California resident, the California Consumer Privacy Act (CCPA) as amended by the California Privacy Rights Act (CPRA) provides you with specific rights:
Right to Know: You have the right to request that we disclose:
- The categories and specific pieces of personal information we have collected about you
- The categories of sources from which we collected that information
- The business or commercial purpose for collecting that information
- The categories of third parties with whom we share that information
Right to Delete: You can request that we delete personal information we collected from you, subject to certain exceptions required by law.
Right to Correct: You can request that we correct inaccurate personal information we hold about you.
Right to Opt Out of Sale/Sharing: We do not sell your personal information. We do not share your personal information for cross-context behavioral advertising. Therefore, there is no need to opt out, but you have the right to request confirmation of this practice.
Right to Limit Use of Sensitive Personal Information: We do not use sensitive personal information for purposes beyond what is necessary to provide the Service.
Right to Non-Discrimination: We will not discriminate against you for exercising any of your CCPA/CPRA rights. We will not deny you goods or services, charge you different prices, or provide a different level of service for exercising your privacy rights.
Categories of Information Collected (Last 12 Months):
- Identifiers (name, email address, IP address, account ID)
- Commercial information (subscription history, transaction records, credit usage)
- Internet or electronic network activity (usage logs, browsing activity within the Service, extension interactions)
- Professional information (profession, audience, services offered -- as voluntarily provided)
- Inferences (personalization preferences derived from your profile data)
You may submit CCPA/CPRA requests by emailing support@fastreply.io with the subject line "CCPA Privacy Request." We will verify your identity before processing your request.
10.3 Other U.S. State Privacy Laws
If you are a resident of Virginia (VCDPA), Colorado (CPA), Connecticut (CTDPA), Utah (UCPA), Texas (TDPSA), Oregon (OCPA), Montana (MCDPA), or other states with comprehensive privacy legislation, you may have similar rights to those described above, including:
- Right to access, correct, and delete your personal data
- Right to data portability
- Right to opt out of targeted advertising (we do not engage in targeted advertising)
- Right to opt out of the sale of personal data (we do not sell personal data)
- Right to opt out of profiling in furtherance of decisions that produce legal or similarly significant effects (we do not engage in such profiling)
- Right to appeal a denial of a privacy request
To exercise these rights, contact us at support@fastreply.io. If we deny your request, you may appeal by emailing us with the subject line "Privacy Rights Appeal."
10.4 Canadian Users (PIPEDA)
If you are a Canadian resident, you have rights under the Personal Information Protection and Electronic Documents Act (PIPEDA), including the right to access, correct, and challenge the handling of your personal information. To exercise these rights or file a complaint, contact us at support@fastreply.io or contact the Office of the Privacy Commissioner of Canada.
10.5 Australian Users
If you are an Australian resident, you have rights under the Privacy Act 1988 (Cth) and the Australian Privacy Principles. You can access and correct your personal information and lodge complaints regarding our handling of your data. To exercise your rights or lodge a complaint, contact us at support@fastreply.io. If your complaint is not resolved to your satisfaction, you may contact the Office of the Australian Information Commissioner (OAIC).
10.6 Brazilian Users (LGPD)
If you are a Brazilian resident, you have rights under the Lei Geral de Protecao de Dados (LGPD), including the right to access, correct, delete, and port your personal data, and to obtain information about shared data. To exercise your rights, contact us at support@fastreply.io.
11. Automated Decision-Making
We do not use your personal data for automated decision-making that produces legal or similarly significant effects on you. Our credit system, subscription management, and account operations follow predetermined rules that apply equally to all users.
The AI-generated replies produced by the Service are suggestions for your review and are not automated decisions about you. You retain full control over whether to use, modify, or discard any generated content.
We may use automated systems for fraud detection and abuse prevention. If automated systems flag your account, a human will review the situation before any adverse action is taken against your account.
12. Third-Party Links and Services
The Service may contain links to third-party websites, platforms, or services that are not operated by us. This Privacy Policy does not apply to third-party sites. We are not responsible for the privacy practices, content, or data collection policies of any third-party sites. We encourage you to review the privacy policies of any third-party services you visit.
Specific third-party interactions include:
- Social media platforms (LinkedIn, X/Twitter): When you use generated replies on these platforms, your interactions are governed by those platforms' privacy policies
- Chrome Web Store: The installation and update of our extension is governed by Google's privacy policy and Chrome Web Store terms
- Payment processing: When you enter payment details, you interact directly with Stripe's secure payment interface, governed by Stripe's privacy policy
13. Children's Privacy
The Service is not intended for or directed at individuals under the age of 18 (or the age of majority in your jurisdiction, whichever is greater). We do not knowingly collect, solicit, or maintain personal information from anyone under 18.
If we learn that we have inadvertently collected personal information from a user under 18, we will take steps to promptly delete that information and terminate the associated account. If you believe we have collected information from a minor, please contact us immediately at support@fastreply.io.
Parents or legal guardians who become aware that their child has provided personal information to us without their consent should contact us, and we will delete such information.
14. Data Processing Agreements
Where required by applicable law (such as GDPR), we enter into Data Processing Agreements (DPAs) with our service providers that process personal data on our behalf. These agreements ensure that our providers:
- Process personal data only on our documented instructions
- Maintain appropriate technical and organizational security measures
- Notify us of data breaches without undue delay
- Assist us in responding to data subject requests
- Delete or return personal data at the end of the service relationship
- Submit to audits and inspections to demonstrate compliance
If you require a copy of our Data Processing Agreement for your records, please contact us at support@fastreply.io.
15. Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or for other operational reasons. When we make changes:
- Material changes: We will notify you by email to the address associated with your account and/or by posting a prominent notice on the Service at least 30 days before the changes take effect
- Non-material changes: We will post the updated policy on our website. The "Effective Date" at the top indicates when the policy was last updated.
Your continued use of the Service after the effective date of any changes constitutes your acceptance of the updated Privacy Policy. If you do not agree to the updated policy, you should stop using the Service and request account deletion.
We encourage you to review this Privacy Policy periodically to stay informed about how we protect your information.
16. Contact Us
If you have any questions, concerns, or complaints about this Privacy Policy, our data practices, or your privacy rights, please contact us at:
FastReply
Email: support@fastreply.io
Website: fastreply.io
Subject line for privacy inquiries: "Privacy Inquiry"
We aim to respond to all privacy-related inquiries within 30 days. For urgent matters (such as reporting a data breach), please indicate "URGENT" in your subject line.
If you are not satisfied with our response, you may have the right to lodge a complaint with your local data protection authority or seek other legal remedies.