Pricing
Products
Files and document managementFilesAutomation and workflowsAutomationSearch across everythingSearch
Start now

Repora Privacy Policy

Effective date: 5 September 2026

Contents
  1. About Repora and This Notice
  2. Who We Are
  3. How to Contact Us About Your Data
  4. What This Notice Covers
  5. Lawful Bases and Your Choices
  6. What We Collect, Why, and How Long We Keep It
  7. How We Use Your Information
  8. Your Rights Over Your Personal Data
  9. Who We Share Personal Data With
  10. Children
  11. Links to Other Websites
  12. Where Your Data Is Stored, and How It Is Protected
  13. Deleting Your Data
  14. Cookies and Local Storage
  15. Other Terms

About Repora and This Notice

Repora is a business platform for file management, document collaboration, search, automation and workflows. This notice explains how Velvet Software Limited handles personal data on the repora.com website, in the forms published on it, and in the Repora service itself. It is written to be read in full, and every statement in it describes something we actually do.

Who We Are

Velvet Software Limited (the "Company", "we", "us"), registered in Dublin, Ireland (company registration no. 633270), develops and operates the Repora website and services (together, the "Services"), and is the data controller for the personal data described in this notice.

How to Contact Us About Your Data

Write to privacy@repora.com for anything covered by this notice, including access, correction and deletion requests; support@repora.com reaches the same team. We have not appointed a Data Protection Officer; requests under this notice are handled directly by the Company. If you are not satisfied with our answer, you may complain to the Irish Data Protection Commission, which is our supervisory authority, or to the authority in the country where you live.

What This Notice Covers

This notice covers the personal data we handle as a controller: visitors to repora.com, people who submit one of our forms, subscribers to our product-update email, and the people who administer and use a Repora account.

It does not cover the contents of documents a customer uploads into Repora. For that content we act on the customer's instructions as a processor: the customer decides what is stored, who is admitted to a shared space, and when material is removed. If your organisation needs a written data processing agreement before uploading personal data, contact us and we will tell you what we are able to sign.

We are an Irish company and we handle personal data under the EU General Data Protection Regulation. We do not claim any certification we do not hold: there is no SOC 2 report, no ISO 27001 certification and no published penetration-test report. What we do have is set out below and on our security page, and we will answer specific procurement questions in writing.

Lawful Bases and Your Choices

We do not rely on a single blanket consent for everything we do. Each row of the table below names its own lawful basis: performing a contract or taking steps at your request before entering one, our legitimate interest in running and securing the Services, a legal obligation, or your consent. Product-update email is the only thing we do on the basis of consent, and you can withdraw that consent at any time using the unsubscribe link in every message or by writing to privacy@repora.com; withdrawing it does not affect anything done beforehand. Marketing email is a separate, optional choice and is never a condition of requesting or receiving access to Repora.

What We Collect, Why, and How Long We Keep It

Each row below is one thing we do with personal data. Fields described as optional can be left blank without affecting your request. Where a row gives a criterion rather than a fixed number of months, that is deliberate: we would rather publish the rule we actually apply than a retention period we have not set. You can ask us to delete your data at any time, and the section on deletion explains how.

What we doWhat we collectWhy, and on what lawful basisWho can see it, and how long we keep it
Sales enquiries and meeting requests submitted from the siteYour work email address, full name and company; and, if you choose to give them, your role, your team size and a description of your use case. We also record the time of submission and the IP address the request came from.To assess your request, reply to it and arrange access. Lawful basis: steps taken at your request before entering a contract, together with our legitimate interest in preventing abuse of a public form.Written as a single record to a log file on our server that sits outside the public web root and cannot be reached from a browser. Readable by the people who operate the site and answer sales enquiries. Kept while your enquiry is open and while we are still in contact about it, then deleted once it is closed and no longer needed for that purpose, or sooner if you ask.
Messages and attachments sent through the contact formYour email address, the subject line, the message you write, and up to five attached files of up to 5 MB each in the formats the form accepts. Job enquiries sent to us by email are handled in the same way, including any CV attached to them.To read your message, answer it and keep a record of the exchange. Lawful basis: our legitimate interest in responding to people who contact us, and performance of a contract where you are already a customer.The message is written to the same server-side log file, outside the public web root. Attachments are written to a separate directory that is also outside the web root and is never served to the internet. A notification is emailed to our support address so that a person sees the request. Both are readable only by the people who operate the site and answer support. Kept while the matter is open and while we may still need it to answer a related question, then deleted; deleted sooner if you ask.
Product-update emailYour email address, and your name if you give one.To send product news and release notes. Lawful basis: your consent, given when you subscribe.Held in the same server-side log file and in the system we use to send the email. Kept until you unsubscribe or ask to be removed, after which we keep only the minimum needed to make sure we do not email you again.
Website analyticsPages viewed, the page that referred you, an approximate location derived from your IP address, your browser and device type, and an identifier held in first-party cookies.To understand which pages are used, so that we can improve them. Lawful basis: our legitimate interest in maintaining and improving the site.Collected by a Matomo instance we host ourselves at stat.repora.com; the data is not passed to an advertising network. Visible to the people who operate the site. Retained for the period configured on that instance — ask us and we will tell you what it currently is. You can stop the collection by blocking the tracker in your browser.
Administering a Repora accountThe name, email address and role of each person an administrator adds to the account, together with sign-in records and the activity record showing what changed in a shared space and when.To operate the account, apply permissions and give administrators an activity record. Lawful basis: performance of our contract with the customer.Visible to the administrators of that account and to the people who operate the service. Kept for the life of the account and deleted when the account is deleted, except for anything we must retain for accounting or legal reasons.
Taking paymentYour name, billing contact details and the record of a payment: who paid, for which plan, when, and how much. Card details are entered with the regulated payment provider that handles a card payment and never reach our servers; a bank transfer reaches us as a bank reference.To take payment and to meet our accounting and tax obligations. Lawful basis: performance of our contract with you, and a legal obligation.Card details never reach our servers. The transaction record is visible to the people who run our finances and is kept for the period Irish tax and accounting law requires.

How We Use Your Information

  1. The purposes in the table, and nothing else
    We use personal data only for the purposes set out in the table above. In practice that comes down to four things:
    1. Responding to you: Reading and answering sales enquiries, meeting requests, contact messages and support questions, arranging the time of a meeting you asked for, and contacting you about a request you made.
    2. Running and securing the Services: Operating accounts and shared spaces, applying permissions, keeping activity records, investigating abuse of our forms or of the service, and fixing faults.
    3. Sending the product-update email you asked for: Sending release notes and product news to the people who subscribed, with an unsubscribe link in every message.
    4. Meeting legal and financial obligations: Keeping the accounting and tax records Irish law requires, and responding to lawful requests from a court, regulator or other competent authority.
  2. What we do not do
    We do not sell personal data. We do not disclose it to third parties for their own marketing. We do not run third-party advertising or social-media trackers on this site. We do not make marketing consent a condition of requesting or receiving access to Repora. And we do not make decisions about you by automated means that produce a legal effect or a similarly significant one.
  3. Document content processed by product features
    Some Repora features act on the contents of a document: converting it, indexing it so that it can be found by search, or producing a summary in response to a command written in ordinary language. Those features run on our servers as part of providing the service to the customer who uploaded the document. If your organisation needs written detail about which features read document content, and on whose infrastructure they run, ask us before you move regulated or sensitive material into Repora and we will answer directly rather than point you at a general statement.

Your Rights Over Your Personal Data

You have the right to ask us for a copy of the personal data we hold about you; to have it corrected if it is wrong; to have it erased; to restrict how we use it, or object to our using it; to receive it in a portable form; and, where we rely on your consent, to withdraw that consent. Exercising any of these rights is free.

Write to privacy@repora.com or support@repora.com. We will answer within one month of receiving the request, as the GDPR requires, and will tell you if we need longer because the request is complex. We may first need to confirm who you are, so that we do not hand your data to somebody else.

If we cannot do what you asked, we will tell you why. If you are not satisfied with our answer, you may complain to the Irish Data Protection Commission, which supervises us, or to the supervisory authority in the country where you live.

Who We Share Personal Data With

We do not sell personal data, and we share it only with the recipients listed here, for the purposes set out in the table above.

  1. Service providers who operate parts of the service on our behalf: hosting and infrastructure, email delivery, and the analytics instance we host at stat.repora.com. They act on our instructions and may not use the data for their own purposes.
  2. Where you pay by card, the regulated payment provider that handles that payment, and our bank where you pay by transfer. They receive what they need to take or receive the payment; card details never reach our servers.
  3. Legal and regulatory disclosure, where we are required to disclose by law or by an order of a court or other competent authority. We do not disclose personal data voluntarily.
  4. Investigating fraud, abuse of the Services or a security incident, where disclosure is necessary to deal with it. If we receive a copyright notice about material held in an account, we forward it to the account holder, and it is for them to answer it.
  5. A buyer, if the Company or its assets are sold, merged or reorganised. Personal data may pass to the buyer, who remains bound by this notice. We will tell you before that happens and give you the opportunity to have your data deleted first.
  6. Aggregate figures describing use of the site and the service. These contain nothing that identifies a person and may be shared or published.
  7. Nobody else. If we ever need to share personal data with a recipient not listed here, we will update this notice and, where the law requires it, tell you before we do so.

Children

Repora is a business product. It is not directed at children, and we do not knowingly collect personal data from anyone under 16. If you believe a child has given us personal data, write to privacy@repora.com and we will delete it.

Links to Other Websites

The Services contain links to other websites, and a customer may connect third-party services such as Google Drive or OneDrive. We are not responsible for how those sites and services handle personal data, and we suggest you read their privacy notices before connecting them.

Where Your Data Is Stored, and How It Is Protected

Documents and account data are stored on servers in the European Union. Connections between your browser and Repora are encrypted, access to a shared space is governed by the permissions set on that space, and access by our own staff is limited to the people who need it to operate the service and answer support.

Submissions from the forms on this site are written to a log file that sits outside the public web root, and attachments to a separate directory that is also outside the web root and is never served to the internet. Neither can be reached from a browser.

We hold no SOC 2 report and no ISO 27001 certification, we publish no penetration-test report, and we give no contractual uptime commitment. We would rather say so plainly than imply otherwise. If your procurement process needs assurances of that kind, contact us before you commit and we will tell you exactly what we can and cannot provide. If you find a security problem, report it to support@repora.com and we will act on it.

Deleting Your Data

You can ask us to delete your personal data at any time by writing to privacy@repora.com or support@repora.com, or by using the contact form. We confirm the request by email before anything is removed, and we act within one month.

For a meeting request, a contact message or a newsletter subscription, deletion means the record is removed from our log file and any attachments sent with it are deleted. For a Repora account, deletion removes the account and the documents stored in it; an administrator should export whatever the organisation needs first, because deletion cannot be undone.

We keep only what we have to: the records Irish tax and accounting law requires us to hold, and anything we need in order to establish or defend a legal claim. If that applies to your request, we will tell you what we are keeping and why.

Cookies and Local Storage

We use no advertising cookies, and no third-party advertising or social-media trackers run on this site. Three things are stored in your browser.

  1. Analytics cookies set by the Matomo instance we host ourselves at stat.repora.com. They record which pages are visited so that we can improve them. They are first-party cookies, and the data is not passed to an advertising network.
  2. A language preference stored under the key repora-locale in your browser's local storage. It records the language you chose, stays in your browser and is never sent to us.
  3. Cookies that are strictly necessary to keep you signed in to a Repora account and to keep the service working.

You can block or clear any of these from your browser settings. Blocking the analytics tracker does not affect how the site works, and clearing the language preference simply returns the site to English.

Other Terms

  1. Changes to This Notice
    We update this notice when the Services or our practices change. The effective date at the top of the page always shows when it last changed, and we will describe a material change on the site rather than rely on the date alone. Please read it again before you send us personal data. Continuing to use the Services after a change takes effect means you accept the updated notice; if you do not accept it, stop using the Services and ask us to delete your data.
  2. Governing Law and Disputes
    Irish law governs this notice, and the courts of Dublin, Ireland have exclusive jurisdiction over any dispute arising out of it. This does not affect your right to complain to the Irish Data Protection Commission or to the supervisory authority in the country where you live.
Support
ProductPricingSecurityAboutCareersFAQUpdatesContact usTerms of UsePrivacy PolicyBilling and refundsCopyright policy

© 2026 repora.com
All rights reserved
Repora is operated by Velvet Software Limited, Dublin, Ireland. Company registration number 633270.
Registered office: 29 Earlsfort Terrace, Dublin 2, D02 AY28, Ireland.
support@repora.com