Legal
Privacy Policy
This explains what we collect, why we hold it, who else touches it, and how to get it back or deleted. It describes the system as actually built — not an aspiration.
Last updated 29 July 2026
Who we are
AI Employees (“we”) provides automated workflow software at wflowprocess.app. When you use the platform to serve your own customers, you are the controller of their personal data and we are your processor — we handle it on your instructions, for the purpose of running the workflows you switched on.
What we collect
Account data. Your name, business name, email, phone number, business address, industry and chosen workflow. Needed to create and bill the workspace.
Workspace content you create or connect. Depending on which workflows and connectors you enable, this can include:
- Customer and contact records, including any address book you sync
- Job records, appointments, notes and calendar events
- Call metadata, call outcomes and — where you enable it — transcripts
- Messages sent and received on channels you connect (SMS, Telegram, email, web chat)
- Documents you upload for question-answering or e-signature
- For Credit Repair only: consumer credit information you enter — names, contact details, creditors and dispute history
Operational data. An immutable audit trail of actions taken in your workspace (who, what, when, outcome), rate-limit counters, and errors. This is how a disputed action can be reconstructed.
Payment data. On-chain transaction references and amounts. We do not collect or store card numbers or bank details, because we do not accept them.
What we deliberately do not hold
- Your vault master password. It never reaches our database. The encryption key for your connector credentials is derived from it for a single operation and discarded. If you lose it, we cannot recover it for you — that is the design, not a gap.
- Your funds. We are not a money transmitter. Payments move from you to the provider directly; we hold authorization only, and the wallet is owned by you.
- Card or bank details. Never taken, so never stored.
Why we process it
- To perform the contract — running the workflows you configured is the service you bought.
- Legitimate interests — securing the platform, preventing abuse, and keeping an audit trail that makes automated actions accountable.
- Consent — where you connect an optional data source such as an address book or health data, you can withdraw it by disconnecting that connector.
- Legal obligation — retaining records we are required to keep.
We do not sell personal data, and we do not use your workspace content to train models for anyone else.
Who else processes your data
We use these subprocessors. Which ones apply depends entirely on the connectors you enable — a workspace with no phone connector never touches a telephony provider.
- Supabase — the database and audit sink.
- Anthropic — the language models behind the assistant, classification and drafting.
- Retell / Vapi — voice agents, when you enable calling.
- Twilio — SMS and phone numbers, when enabled.
- Telegram — messaging, when enabled.
- Zoho, Gmail or Outlook — email, when you connect a mailbox.
- Google Calendar / Contacts / Maps, iCloud — scheduling and contacts, when connected.
- Duffel — flight and hotel booking, for the Personal Assistant.
- Documenso — e-signature, self-hosted by us.
- Coinbase and public blockchains — payment settlement. On-chain records are permanent and public by nature.
- QuickBooks, Xero, HubSpot, Stripe — only if you connect them.
How long we keep it
- Workspace content stays until you delete it or close the account.
- Audit records are retained for accountability and are intentionally immutable — they are not edited on request, though the account they belong to can be closed.
- On closure, workspace content is deleted within 30 days, except where we must retain records by law.
- On-chain payment records cannot be deleted by anyone, including us.
Your rights
Depending on where you live (GDPR in the UK/EU, CCPA/CPRA in California, and comparable laws elsewhere) you can request access, a copy, correction, deletion, restriction, or portability, and object to certain processing. We do not sell or share personal information as those laws define it, so there is nothing to opt out of on that front.
Email privacy@wflowprocess.app and we will respond within 30 days. If you are an end customer of a business that uses this platform, contact that business first — they control the data, and we act on their instruction.
Recorded calls and automated messages
If you enable voice or messaging workflows, you are responsible for the consent and disclosure that applies where you and your customers are. Recording laws differ by state and country, and automated calls and texts in the United States are regulated under the TCPA — including do-not-call handling and time-of-day limits. We give you DNC gating and audit tooling; we cannot give you permission to contact someone.
Credit repair data
The Credit Repair workflow processes consumer credit information, which is sensitive and separately regulated — in the United States under the Credit Repair Organizations Act and the Fair Credit Reporting Act. Those records are held under stricter access controls than the rest of the platform, and reachable only by your workspace. Using this workflow does not make us a credit repair organization, and nothing in the product is legal or financial advice to your clients.
Security
Connector credentials are encrypted with a key derived from your master password, which we never store. Every table holding customer data is protected by row-level security with the underlying grants revoked, so a single misconfiguration cannot expose it. Actions are written to an immutable audit trail. More detail is on our security page.
Children
The platform is for businesses and is not directed to anyone under 18. We do not knowingly collect data from children.
International transfers
Our infrastructure and subprocessors may process data outside your country, including in the United States. Where required we rely on appropriate safeguards such as the EU Standard Contractual Clauses.
Changes and contact
If we change this policy materially we will update the date above and notify account owners by email. Questions, requests or complaints: privacy@wflowprocess.app.