WiiFlo
Request a Demo

Privacy Policy — WiiFlo

Effective: July 27, 2026 · Last updated: July 27, 2026

1. Overview

WiiFlo is an agentic analytics platform. When you use WiiFlo — through app.wiiflo.ai or wiiflo.ai — we process some of your personal data to make the service work.

This policy covers: GDPR (EU), CCPA/CPRA (US), UAE PDPL, Saudi PDPL, India DPDPA, Singapore PDPA, and the EU AI Act.

We act as the Data Controller for data you provide directly. For data you upload (files, databases, APIs), you are the Data Controller and we are the Data Processor on your behalf.

2. What We Collect

  • Account data — name, email, profile picture
  • Uploaded data — CSV/Excel files, API snapshots, database connections. May contain personal data depending on what you upload. You are responsible for having the right to upload it.
  • AI conversations — questions asked in Thinking Space, Flows, AI responses
  • Channel identities — Telegram/Slack/Teams user IDs if you connect those channels
  • Usage data — which features you use and when, stored in anonymised audit logs

We do NOT collect: payment card numbers, passwords, biometric data, or data from children under 16.

3. How We Use It

PurposeData usedLegal basis
Provide the analytics serviceUploaded data, AI conversationsContract performance
AI-generated insights & storiesUploaded data (anonymised sketches)Contract performance
Deliver results via channelsChannel identities, AI outputsContract performance
Improve the productAnonymised usage dataLegitimate interest
Security & fraud preventionUsage data, audit logsLegitimate interest
Comply with legal obligationsAccount data, audit logsLegal obligation
Send product updates (optional)Email addressConsent (opt-in only)

We never sell your personal data. We do not use your data for advertising.

4. How Long We Keep It

Data typeKept forDeleted when
Account profileWhile active + 30 daysYou delete your account
Uploaded dataWhile source is activeYou remove the source or delete your account
AI conversations & threads90 daysRolling expiry or account deletion
AI memory & document chunks90 daysRolling expiry or account deletion
Delivery logs90 daysRolling expiry or account deletion
Flows run history90 daysRolling expiry or account deletion
Audit logs12 monthsRolling expiry
Billing records7 yearsStatutory minimum
Waitlist emails12 monthsRolling expiry or opt-out

5. Who We Share It With

We share data only with companies needed to run WiiFlo (subprocessors). Each has signed a Data Processing Agreement with us.

  • Anthropic — AI analysis engine (Claude). US. Receives anonymised data sketches and user questions, never raw personal data.
  • OpenAI — Embeddings and suggestion prompts. US. Receives anonymised text snippets.
  • Supabase — Database and authentication. US/EU. Receives all structured data.
  • Railway — Application hosting. US. Receives all data passing through our backend.
  • Resend — Transactional email. US. Receives email address and content when sending reports.

We do not share data with advertisers, data brokers, or any third party for their own purposes.

6. Your Rights

Regardless of where you are, you can always: access your data, correct inaccuracies, download a copy, or delete your account — from your Profile settings or by emailing wiifloai@gmail.com. We respond within 30 days.

  • EU (GDPR): Access, rectification, erasure, restriction, portability, right to object, withdraw consent, lodge complaint with your national DPA.
  • US / California (CCPA/CPRA): Right to know, delete, correct, opt-out of sale (we don't sell data), non-discrimination.
  • UAE (PDPL): Access, correction, deletion, withdraw consent, breach notification within 72 hours.
  • Saudi Arabia (PDPL): Access, correction, deletion, withdraw consent, know purpose before consenting, breach notification.
  • India (DPDPA): Access, correction, erasure, grievance redressal (contact: wiifloai@gmail.com — we respond within 30 days), nominate a representative, withdraw consent. Grievance Officer: wiifloai@gmail.com
  • Singapore (PDPA): Access, correction, withdraw consent, data portability, breach notification within 3 business days.

7. International Data Transfers

WiiFlo is hosted in the United States. If you are in the EU, Middle East, India, or Singapore your data is transferred to the US. We protect these transfers using Standard Contractual Clauses (SCCs) and Data Processing Agreements with all subprocessors. All data is encrypted using AES-256 in transit and at rest.

8. Security

  • Encryption at rest (AES-256-GCM) for all credentials and tokens
  • HTTPS/TLS for all connections
  • Row-level security — users can only access their own data
  • PII detection on uploaded data
  • AI input/output guardrails to prevent PII leakage
  • Audit logging of all AI actions (EU AI Act compliance)
  • Rate limiting on all APIs

Breach notification timelines: 72 hours for EU, UAE, Saudi Arabia · 3 business days for Singapore · 6 hours for India (CERT-In).

9. Contact

Privacy requests (all regions): wiifloai@gmail.com
Grievance Officer (India — required by DPDPA): wiifloai@gmail.com
General support: wiifloai@gmail.com

Regulatory authorities:

  • EU: your national Data Protection Authority
  • UAE: TDRA
  • Saudi Arabia: SDAIA / PDPC
  • India: Data Protection Board of India
  • Singapore: PDPC (pdpc.gov.sg)
  • California: CPPA
WiiFlo© 2026 WiiFlo. All rights reserved.
TermsPrivacy Policieswiifloai@gmail.com