Data protection

Data Processing Agreement

The Article 28 terms that apply when Wilph handles your customers' personal data on your instructions. It is part of your contract — accepting the Terms of Service accepts this too.

Last updated:

Who is who

For the support conversations you run through Wilph — your customers’ emails, chats and direct messages, their names, addresses and order details — you are the controller and Wilph is the processor. You decide why that data is collected; we handle it only to give you the service.

For your own account data — the names and email addresses of your team, your billing details, and the security logs behind them — Wilph is the controller. That is covered by the Privacy Policy instead.

What we process, and for how long

Details
Subject matterProviding an AI-assisted customer-support helpdesk to you.
DurationFor as long as your workspace exists, plus the short period it takes deletion to work through backups.
Categories of data subjectYour customers and website visitors, and the members of your own team who use Wilph.
Categories of personal dataNames, email addresses, the content of support messages, social media handles for direct messages, order and delivery details retrieved from systems you connect, and technical data such as timestamps and message identifiers.
Special category dataNot intended, not asked for, and not something the product is built to handle. Customers do sometimes volunteer health or similar details in a support message; where that happens it is processed only as part of the message it sits in.

Our instructions from you

We process your customer data only on your documented instructions. Your instructions are: this agreement, the Terms of Service, and what you do in the product — connecting a mailbox, crawling your website, enabling a skill, switching an agent on. We will tell you if we think an instruction breaks data-protection law.

Everyone at Wilph with access to your data is bound by confidentiality.

What the AI does with it, specifically

This is the part most worth reading, because it is where a support message leaves our systems.

  • When a draft or an answer is generated, the message being answered is sent to the model provider named in the sub-processor list, together with passages from your own crawled website, your enabled skills, and a bounded amount of recent conversation history.
  • Nothing else is sent. Crawling your website, searching it, and matching your skills all happen without any AI call at all.
  • A question your website and skills do not cover is not sent to the model. It is handed to a person instead.
  • We do not use your customers’ support conversations to train models, and we contract for the model provider not to train on them either.
  • The Replay lab is an evaluation tool. It generates a draft for one historical conversation you chose, shows it beside what your team actually replied, and never sends anything or touches a live ticket.

Security measures

The measures we take under Article 32 are described in full on the security page. In summary: every workspace’s data is separated by an organization identifier applied on every read and write and covered by automated tests; connection credentials and OAuth tokens are encrypted with AES-256-GCM before storage; traffic is served over TLS; access to production is limited to those who need it; public endpoints are rate limited in the database; and visitor IP addresses are stored only as a salted hash, never in the clear.

Sub-processors

You give us general authorisation to use the sub-processors listed on the sub-processor page. We will give you at least 30 days’ notice before adding or replacing one, and you may object on reasonable data-protection grounds; if we cannot resolve your objection you may cancel without penalty. Each sub-processor is bound by terms no less protective than these, and we remain responsible to you for what they do.

International transfers

Wilph’s infrastructure is in the United States, so your customers’ data is transferred outside the EEA. Those transfers rely on the European Commission’s standard contractual clauses together with the technical measures described above. The sub-processor page says exactly where each vendor holds data.

Helping you answer your customers

If one of your customers exercises a right — access, correction, deletion, objection — you answer them; it is your relationship. Wilph gives you the tools to do it: search across every ticket and message, the contact view that gathers one person’s conversations, and delete controls for tickets and for imported Replay samples. Where a request needs something the product does not expose, ask us and we will help within a reasonable time and at no charge.

If something goes wrong

If we become aware of a personal data breach affecting your data we will tell you without undue delay, and in any case within 72 hours of becoming aware, with what we know: what happened, which data and roughly how many people are affected, what we are doing, and what we suggest you do. You make the notification to your supervisory authority; we give you what you need to make it.

Deletion and return

You can export or delete data from the product while your workspace is open. When it closes, we delete your data; deleting a workspace cascades to its tickets, messages, contacts, crawled pages, skills, imported Replay samples and stored credentials. Backups and provider logs expire on their own ordinary schedules rather than being purged on the day, and are not used for anything else in the meantime.

Audit

On reasonable notice, and no more than once a year unless a regulator or an incident requires otherwise, we will give you the information you need to show that we are meeting these obligations, and answer a security questionnaire. Wilph is a small company and does not hold a SOC 2 report or an ISO 27001 certificate — we would rather say so than imply an assurance we do not have.

Precedence and law

Where this agreement and the Terms of Service conflict on the processing of personal data, this agreement wins. It is governed by the laws of Denmark. For a signed copy, or to use your own DPA, write to info@wilph.com.

How to reach us

Questions about this document, or any request about your data, go to info@wilph.com. We answer in English or Danish.