Wondeya Privacy Policy
Last updated: August 30, 2026 · Version: 1.0
This Privacy Policy explains how Woku SpA processes personal data when providing Wondeya. Wondeya is a product of Woku, operated by Woku SpA, that lets you create and publish sites, pages, and conversational agents with artificial intelligence, and integrate them through embeddable components, an SDK, and an API.
1. Who we are and how to contact us
The controller for Wondeya is Woku SpA, a company incorporated in Chile, domiciled at Calle 120 39 Dp 14 B, Hualpén, Chile 4600150 (in this Policy, "Woku", "we", or "our"). "Wondeya" refers to the product and the services described in this Policy, not to a separate company. Terms such as customer, Visitor, Workspace, Site, Page, and Plan are used here with the meaning given in the Terms of Service.
- General inquiries and support:
[email protected] - Privacy, data rights, and security:
[email protected]
When a customer uses Wondeya to publish its own site, page, or widget, that customer determines the purposes for which its visitors' data is collected and used. In that case, the customer is the controller and Woku processes that data on the customer's behalf as a processor, under the Data Processing Agreement. When we process data to administer accounts, security, support, billing, or our own site, Woku acts as controller.
2. To whom and to which services it applies
This Policy applies to:
- people who visit
wondeya.comor our own sites; - owners, members, and guests of a Wondeya workspace;
- people who request information, support, or a demonstration;
- visitors who interact with a Wondeya page or widget operated by one of our customers;
- buyers and billing contacts, for the portion of the data that Woku receives from Paddle.
Our customers' sites and businesses may have their own policies. If you interact with a customer's page or widget, also review that customer's privacy notice.
3. Personal data we process
3.1 Account, identity, and workspace
We may process:
- name, email address, language, and account preferences;
- verification status, sign-in method, and identity provider;
- memberships, roles, invitations, and active workspace;
- acceptance and version of the Terms;
- date of last sign-in and last authenticated activity of owners or administrators.
We do not store your password in Wondeya when authentication is managed by our identity provider.
3.2 Security and technical data
We may process IP address or a version pseudonymized through hashing, user agent, browser, device, approximate country, session identifiers, timestamps, access logs, administrative actions, errors, requests, and signals for the prevention of fraud, bots, or abuse.
Public conversations do not store the raw IP address within the conversation record. The IP address may be processed temporarily at the edge network, in security systems, in operational logs, or in rate limiting.
3.3 Business data and Customer Content
A customer may upload or create:
- name and description of its business, brand, domains, and settings;
- documents, text, files, images, video, audio, and other assets;
- pages, translations, metadata, links, and editorial content;
- extracted knowledge, chunks, summaries, and vector representations or embeddings;
- instructions and configuration of its agents.
The customer decides what content to include. It must not include personal or sensitive data that it is not authorized to process.
3.4 Visitor conversations
When a person converses with an agent, we may process:
- questions and other messages written by the person;
- generated responses and visual components displayed;
- conversation and session identifiers;
- the related agent, site, or page;
- approximate country, device type, and user agent;
- technical and usage metrics, such as tokens, model, cost, duration, and outcome, without needing to store the text in the cost metric.
To avoid hibernating a Free agent that does receive legitimate use, we may retain lastQualifiedVisitorTurnAt: only the date and time of the last turn that passed anti-bot and rate-limit controls and that was served from cache or reserved quota correctly. This signal does not contain the message and does not identify the Visitor; rejected attempts do not update it.
Free text may contain personal information or even sensitive categories that the person chooses to write. Our customers must configure the agent to minimize that collection and must not request sensitive data unless there is a specific need, legal basis, and agreement.
3.5 Leads and forms
Forms may request name, email address, phone, company, and message. Wondeya stores the submission as a lead and communicates it to the owner of the corresponding workspace. The customer is responsible for displaying its own notice, having a legal basis, and using the contact only for the purposes disclosed.
3.6 Purchase and billing
Paddle acts as merchant of record for subscriptions and purchases. Paddle directly collects and processes the data necessary for the checkout page, payment method, taxes, fraud, and billing under its own Privacy Policy. Woku's current record retains Paddle customer, subscription, transaction, and price identifiers, quantity, status, and dates necessary to enable the Service. It does not retain the original Paddle payload, name, address, country, amounts, or full card number within that record.
3.7 Support and communications
We process the content of emails, requests, meetings, survey responses, and other messages you send us, together with the data necessary to respond and keep a record of the request.
We may also send you account and quota notices related to your use of the Service. For the 80% and 100% notices of the Free quota, we process the User's email, role, preference, and language; workspace identifiers and name; Plan; responses used and limit; threshold reached; period and reset date; and preparation, delivery, or retry status. We do not include conversation content or Visitor data in those emails. If we measure the call to action, we record the click associated with the notice, recipient, and workspace, without advertising pixels or tracking of browsing outside Wondeya.
The 100% notice explains an effective degradation of the Service and is treated as an operational communication. Where the preference exists, each recipient may disable the early 80% notice through a direct link or from the console. Both may include a link to manage the quota or upgrade to Pro, but they are not used for discounts, campaigns, cross-selling, or behavioral advertising. Promotional communications not tied to an operational event require a separate legal basis and preferences.
3.8 Analytics
In the console we may process product events associated with an internal user, workspace, and plan identifier. We do not intentionally send the content of documents, conversations, or emails to analytics.
On public pages, optional analytics loads only after the applicable consent. It may include anonymous or pseudonymous identifiers, page, referrer, campaign, language, and interaction events. A customer may also configure its own tools; that customer is responsible for disclosing their use and obtaining the appropriate consent.
4. Where we obtain the data
We obtain data:
- directly from you or from the customer that administers the workspace;
- from visitors who write or complete forms;
- automatically from browsers, devices, security systems, and technical logs;
- automatically from the usage meter when a workspace crosses a quota threshold;
- from identity providers when you choose to sign in with them;
- from Paddle to enable and administer a purchase;
- from sources that a customer instructs us to process and for which it declares that it has authorization.
5. For what purposes and why we process data
The exact legal basis depends on the country and the relationship. When applicable law requires identifying it, we use the following:
| Purpose | Typical data | Typical legal basis |
|---|---|---|
| Create and administer accounts, workspaces, and access | Account, identity, membership, session | Performance of the contract and pre-contractual measures |
| Provide sites, agents, chat, knowledge, leads, SDK, and API | Customer Content, conversations, configuration, usage | Performance of the contract; customer instructions when we act as processor |
| Process purchase, plan entitlements, and billing | Paddle identifiers, price, quantity, status, and dates | Performance of the contract and legal obligations |
| Protect the Service and prevent abuse, fraud, or bots | IP, hash values, session, device, logs, audit | Legitimate interest in security; legal obligations |
| Operate, diagnose, and improve reliability and experience | Errors, technical metrics, product events | Legitimate interest, minimized and subject to objection where applicable |
| Respond to support, privacy, and incidents | Contact and communications | Performance of the contract, legitimate interest, and legal obligations |
| Administer quotas and send 80%/100% notices | Email, role, preference, language, workspace, Plan, consumption, threshold, period, reset, delivery, and click | Performance of the contract and legitimate interest in the continuity and administration of the Service |
| Administer, hibernate, and reactivate inactive Free AI | Owner/administrator last authenticated activity and lastQualifiedVisitorTurnAt, without Visitor content or identity | Performance of the contract and legitimate interest in administering resources and costs, subject to the published criteria and the right to reactivation |
| Comply with the law and defend rights | Data relevant to the obligation or claim | Legal obligation and the establishment, exercise, or defense of legal claims |
When we rely on consent, you may withdraw it at any time without affecting the lawfulness of processing carried out beforehand.
6. How we use artificial intelligence
Wondeya uses OpenAI models for tasks that may include conversation, vector representations (embeddings), knowledge extraction and enrichment, translation, generation of marketing text, image analysis, and audio transcription.
- We do not use Customer Content to train or fine-tune Woku models.
- We do not authorize OpenAI to use Customer Content to train its models, and we do not voluntarily participate in data sharing programs. OpenAI states that data sent to its API is not used for training by default.
- OpenAI's standard services may temporarily retain prompts and responses in abuse-monitoring logs for up to 30 days, except for legal or security exceptions. Some endpoints may also retain application state depending on the configuration.
- We do not claim that Zero Data Retention exists for an account or plan unless it is expressly agreed and the configuration is verified.
- Responses are probabilistic and may be incomplete or incorrect. They must not be used as the sole source for decisions that may cause physical, medical, legal, financial, or other high-impact harm.
- The interface informs visitors that they are interacting with AI. Our customers may not hide, contradict, or disable that notice.
7. With whom we share data
We may share data only when necessary with:
- Infrastructure and operations providers. These include, depending on the active service and the applicable role, Amazon Web Services (including Amazon SES for outbound account, quota, and lead email), MongoDB Atlas, Cloudflare, Stytch, OpenAI, LangSmith, Sentry, and PostHog. Annex III of the DPA identifies which of these act as subprocessors of Customer Data and their roles.
- Social sign-in providers. If you choose to sign in with Google, Microsoft, or GitHub, the chosen provider receives the authentication request and may share with Stytch and Woku the identifiers and profile data that you authorize.
- Paddle. Paddle processes purchase data as an independent controller and merchant of record. It does not receive conversation records for that function.
- The responsible customer. The messages and leads from a page or widget are processed to deliver the service to the customer that published it. A contact may be emailed to the authorized owners of the workspace.
- Tools configured for the customer. If a customer chooses and configures Google Tag Manager, Microsoft Clarity, Meta Pixel, PostHog, or another supported tool, it normally determines their purpose and its relationship with the provider. If Woku engages a tool to process data on the customer's behalf, we will treat it as a subprocessor and include it in the corresponding list.
- Authorities and advisors. When reasonably necessary to comply with a legal obligation, protect rights, investigate abuse, or establish, exercise, or defend legal claims.
- Corporate transactions. In a merger, acquisition, financing, reorganization, or sale, subject to confidentiality and applicable law.
Woku does not sell personal data. Nor does it use the content of customer conversations for its own behavioral advertising.
8. Cookies, local storage, and similar technologies
We use different technologies depending on the surface:
- Console: cookies strictly necessary for an opaque session and CSRF protection, plus temporary storage required by OAuth. The session expires after 30 minutes of inactivity and has an absolute maximum of 30 days.
- Public pages: the analytics choice is remembered in
localStorageunder the keywdy_consent. Optional tools load only after the corresponding acceptance. - Chat on a page: when the conversation starts, an identifier may be created in
sessionStorageto keep the thread during that tab. Public requests do not send console cookies. - Embedded widget: it keeps the identifier in memory when the host site sends
storage: 'denied'and uses session storage when it receivesstorage: 'granted'. In the current compatibility mode, if the host sends no signal, the widget usessessionStoragewhen the first message is sent. The integrator must connect its CMP before the interaction when the law or its policy requires consent. - Security: Cloudflare Turnstile and equivalent controls may process technical signals necessary to distinguish human traffic from abuse. They are not classified as optional analytics.
This section is our cookie information; there is no separate cookie policy. Tools configured by a customer must also appear in that customer's policy. You may change or withdraw your analytics choice at any time from the page's cookie controls or by clearing site data in your browser.
9. International transfers
Woku is located in Chile and uses providers that operate in the United States and other jurisdictions. As a result, data may be processed outside the country where you reside.
When applicable law requires it, we use recognized mechanisms, such as adequacy decisions, standard contractual clauses, transfer addenda, and technical or organizational supplementary measures. The public list of providers in Annex III of the DPA identifies the relevant locations for each service; network and security services may process traffic on a global network.
10. How long we retain data
We retain data only for as long as necessary for the purposes described, to comply with the law, resolve disputes, and enforce our agreements.
| Data | Period or criterion |
|---|---|
| Content of a public conversation | Retained while the workspace is active, so the Customer can review what its Visitors asked; deleted when the workspace is deleted or upon a valid deletion instruction, subject to the deletion process and backups |
| Usage and cost metrics without message content | 90 days by default |
| Status and metadata of delivery, retries, and clicks of quota notices | Up to 12 months for idempotency and support, then deleted; conversation content is not included |
| Last activity timestamps used for Free hibernation | Only the most recent value is retained while the workspace is active; it is deleted with the workspace, subject to the deletion process and backups |
| Sign-in attempts and equivalent anti-abuse signals | 24 hours, normally pseudonymized through hashing |
| Console session | 30 minutes of inactivity, with an absolute maximum of 30 days |
| Security audit events | 400 days; they deliberately do not include conversation content |
| Application logs in AWS CloudWatch | 30 days |
| Account, membership, and settings | While the account or workspace remains active and for the period necessary for closure, security, and legal obligations |
| Knowledge, pages, files, assets, and vectors | While the workspace remains active or until a valid deletion instruction, subject to the deletion process and backups |
| Leads | While the workspace remains active or until a valid deletion instruction, subject to the deletion process and backups |
| Purchase and accounting data | For the periods required by tax, accounting, fraud, and claim-defense law; Paddle keeps its own copy according to its policy |
| OpenAI | Abuse-monitoring logs retained for up to 30 days under OpenAI's own configuration; data sent to the API is not used for training by default |
| Sampled LangSmith traces | Up to 14 days when the integration is active |
| MongoDB Atlas backups | Encrypted backups retained on a rolling basis and deleted upon rotation, no later than 30 days |
When a piece of data must be retained due to a legal obligation or the defense of claims, it will be restricted to that purpose. Canceling a subscription normally downgrades the workspace to the Free plan; it is not equivalent to requesting its deletion.
11. Security
We apply technical and organizational measures proportionate to the risk. These measures include:
- modern encryption in transit on interfaces controlled by Woku and encryption at rest managed by the providers;
- opaque, revocable sessions stored as a hash;
- role-based access control and isolation between workspaces;
- private objects and signed or validated access to assets;
- secrets managed outside the code;
- rate limits, anti-bot controls, and budget circuit breakers;
- server-side validation of AI output against a closed catalog;
- logging, error monitoring, and an incident response procedure;
- minimization and redaction of common personal-data formats in traces.
No system is infallible. If you detect a vulnerability or possible incident, write to [email protected] and avoid including unnecessary personal data in the first message.
When Woku acts as controller and a security breach represents a risk that must be communicated, we will notify the affected people and the relevant authorities without undue delay and within the deadlines of applicable law. The communication will describe the known nature, the likely consequences, the measures taken, and the contact channel, and it may be delivered in phases if the investigation continues.
12. Your rights
Depending on your jurisdiction, you may have the right to:
- know whether we process your data and access it;
- correct inaccurate or incomplete data;
- request deletion, blocking, or restriction;
- object to certain processing;
- withdraw consent;
- receive data in a portable format where applicable;
- not be subject to a decision based solely on automated processing with legal or similar effects where the law limits it;
- file a complaint with the competent authority.
To exercise a right regarding your account or wondeya.com, write to [email protected]. We may request reasonable information to verify your identity and protect other people. We will acknowledge receipt and communicate the expected timeframe without undue delay; we will respond within the period that applies to your jurisdiction.
If your request concerns a customer's page or widget, contact that customer first. If you write to us, we will forward or assist with the request according to the instructions and obligations of the responsible customer, without disclosing data from another workspace.
Chile's Law No. 19.628 currently governs. The amendments of Law No. 21.719, including new rules and rights, take effect on December 1, 2026; we have drafted this Policy with a view to that strengthened framework.
13. Minors and high-risk data
Wondeya is a business service and is not directed at minors under 18. Our customers must not target agents at minors or deliberately collect data from minors or sensitive categories without an appropriate legal basis, controls, and specific agreement. If you believe we received a minor's data without authorization, write to [email protected].
14. Third-party links and services
A page may contain links or integrations configured by the customer. Their policies and practices belong to those third parties. Review their information before giving them data.
15. Changes to this Policy
We may modify this Policy to reflect changes in the Service, providers, or legislation. We will publish the updated version and date. When a material change adversely affects your rights, we will give at least 30 days' notice by email or within the Service, unless a legal, security, or emergency obligation requires acting sooner. We will request additional consent when the law requires it.
16. Contact and complaints
- Privacy and exercise of rights:
[email protected] - General inquiries:
[email protected] - Postal mail: Woku SpA, Calle 120 39 Dp 14 B, Hualpén, Chile 4600150
If you are not satisfied with our response, you may turn to the data protection authority or competent court of your jurisdiction.