Reprise Software GDPR Policy
Updated May 27, 2026
GDPR Policy Overview
The General Data Protection Regulation (“GDPR”) and the UK GDPR establish legal requirements governing the collection, processing, storage, transfer, and protection of personal data relating to individuals located in the European Economic Area (“EEA”) and the United Kingdom.
Reprise Software, Inc. (“Reprise,” “we,” “our,” or “us”) is committed to respecting the privacy rights of customers, prospective customers, partners, employees, website visitors, and other individuals whose personal data we process. We strive to implement privacy and security practices that align with GDPR principles and industry best practices.
This GDPR Policy supplements the Reprise Software Privacy Policy and describes our general approach to data protection, privacy governance, security, and GDPR compliance.
Our Privacy and Security Principles
Reprise strives to adhere to the following principles in the design and operation of our systems, products, services, and business processes:
- Privacy by design and privacy by default
- Defense in depth security architecture
- Data minimization and purpose limitation
- Confidentiality, integrity, and availability (“CIA”)
- Accountability and transparency
- Continuous security and privacy improvement
We evaluate our information systems, operational practices, and vendors against these principles on an ongoing basis.
Personal Data We Process
Reprise may process personal data including:
- Contact and account information
- Business relationship information
- Customer support and communication records
- Marketing and subscription preferences
- Technical, analytics, attribution, and campaign interaction data
- Security and audit log information
Attribution and campaign interaction data may include referral URLs, UTM parameters, advertising click identifiers, pages viewed, session activity, device and browser information, IP address, and related analytics information associated with website or marketing interactions.
Legal Bases for Processing
Where applicable under GDPR or UK GDPR, Reprise processes personal data based on one or more of the following legal bases:
- Performance of a contract or taking requested pre-contractual steps
- Legitimate interests, including operating and improving our business, supporting customers, securing systems, understanding website usage, measuring campaign effectiveness, and responding to business inquiries
- Consent, including where required for marketing communications or certain cookies and tracking technologies
- Compliance with legal obligations
Where processing is based on consent, individuals may withdraw consent at any time.
Security Measures
Reprise maintains administrative, technical, and organizational safeguards designed to protect personal data against unauthorized access, loss, misuse, alteration, disclosure, or destruction.
Security measures may include:
- Role-based access control
- Multi-factor authentication and strong password policies
- Encryption of personal data in transit and at rest where appropriate
- Vulnerability management and remediation processes
- Security awareness and privacy training
- Security monitoring and incident response procedures
- Endpoint, workstation, server, and mobile device protections
- Periodic internal reviews and risk assessments
An Information Security Policy containing additional detail may be made available to certain enterprise customers under appropriate confidentiality protections.
Cookies, Analytics, and Attribution Data
Reprise uses cookies, analytics tools, and similar technologies to understand how visitors interact with our websites and communications.
These technologies may collect information including:
- IP address
- Browser and device information
- Pages visited
- Referring URLs
- Session activity
- UTM parameters
- Advertising click identifiers
- Website interaction and campaign attribution data
This information helps us:
- Analyze website usage
- Improve website functionality and communications
- Measure campaign and marketing effectiveness
- Support customer relationship management activities
- Maintain website security and performance
Where required by applicable law, Reprise obtains consent for certain cookies or tracking technologies.
Marketing Communications and Consent
Reprise allows individuals to opt in to receive newsletters, webinar invitations, product updates, event invitations, and related marketing communications.
Marketing consent mechanisms are designed to:
- Provide clear and affirmative opt-in choices
- Allow consent withdrawal at any time
- Provide unsubscribe functionality in all marketing emails
- Maintain records of consent where required by law
Operational, transactional, support, or service-related communications may still be sent where necessary.
Data Minimization, Accuracy, and Retention
Reprise seeks to collect only the personal data reasonably necessary for legitimate business purposes.
We maintain data retention and deletion practices designed to ensure that personal data:
- Remains accurate and current where appropriate
- Is retained only as long as reasonably necessary
- Is securely deleted or anonymized when no longer required
Retention periods may vary depending on legal, contractual, operational, security, accounting, and regulatory requirements.
International Data Transfers
Reprise is headquartered in the United States and may process or store personal data in the United States or other countries where Reprise or its service providers operate.
Where required by applicable law, Reprise implements safeguards for international transfers of personal data, including contractual protections and recognized transfer mechanisms.
Data Subject Rights
Subject to applicable law, individuals may have rights regarding their personal data, including the right to:
- Access personal data
- Correct inaccurate data
- Delete personal data
- Restrict or object to certain processing
- Withdraw consent
- Request portability of certain data
- Lodge complaints with applicable supervisory authorities
Requests may be submitted to privacy@reprisesoftware.com. Reprise may request identity verification before processing certain requests.
Security Incidents and Breach Response
Reprise maintains incident response procedures designed to identify, investigate, contain, remediate, and document security incidents involving personal data.
We are committed to providing affected customers and individuals with information required under applicable law in the event of a reportable personal data breach.
Third-Party Processors and Vendors
Reprise may engage third-party service providers, vendors, contractors, and subprocessors to support our business operations.
Where such providers process personal data on behalf of Reprise, we seek to implement contractual and operational measures designed to ensure appropriate data protection obligations are maintained.
These providers may include:
- Hosting and cloud providers
- CRM and marketing automation providers
- Analytics providers
- Webinar and communication platforms
- Customer support providers
- Security service providers
Privacy Governance
Reprise maintains cross-functional privacy and security governance processes intended to support compliance with applicable data protection laws and internal policies.
Responsibilities may include:
- Reviewing privacy and security practices
- Evaluating risks and vulnerabilities
- Overseeing incident response activities
- Reviewing third-party access
- Supporting compliance initiatives
- Maintaining security and privacy awareness programs
Automated Decision-Making
Reprise does not use personal data to make solely automated decisions that produce legal or similarly significant effects on individuals.
How To Contact Us
For questions regarding this GDPR Policy, privacy rights, or data protection matters, please contact:
Reprise Software, Inc.
Email: privacy@reprisesoftware.com
General inquiries: info@reprisesoftware.com
This GDPR Policy is intended to supplement the Reprise Software Privacy Policy and is reviewed periodically to reflect evolving legal, regulatory, operational, and technical requirements.