Skip to content
GDPR and CCPA / CPRA Compliant

Privacy Policy

How Wexio, LLC collects, uses, and protects personal data, and the rights available to you.

Effective 15 July 2026

Wexio, LLC ("Wexio", "we", "us", or "our") respects your privacy and is committed to protecting personal data in connection with the Wexio platform available at wexio.io and its related applications and services (the "Service"). This Privacy Policy explains what personal data we process, why, on what legal basis, with whom we share it, and the rights available to you.

Wexio is a business-to-business platform that businesses use to communicate with their own end users through AI-powered agents. This distinction matters for privacy: for most personal data contained in the conversations our customers handle through the Service, our customer is the party that decides why and how the data is processed, and we act on that customer's behalf. Section 3 explains these roles in detail.

We may update this Policy from time to time. Material changes will be notified as described in Section 25. This document can be printed using your browser's print command.

1. Definitions

The following terms have the meanings given below.

  • "Personal Data": any information relating to an identified or identifiable natural person (Article 4(1) GDPR), and, for California residents, "personal information" as defined by the CCPA/CPRA.
  • "Processing": any operation performed on Personal Data, whether or not automated (Article 4(2) GDPR).
  • "Controller": the natural or legal person that determines the purposes and means of Processing (Article 4(7) GDPR).
  • "Processor": the natural or legal person that processes Personal Data on behalf of the Controller (Article 4(8) GDPR).
  • "Customer": a business that uses the Service to communicate with its own end users.
  • "End User": an individual who interacts with a Customer through a messaging channel connected to the Service.
  • "Conversation Data": the chats, messages, media, files, and contact records processed through the Service in connection with a Customer's communications with its End Users.
  • "Usage Data": information collected automatically, such as IP address, browser type, operating system, pages visited, and diagnostic data.

2. Who We Are and How to Contact Us

The entity responsible for the Service, and the Controller for the account and website data described in this Policy, is Wexio, LLC. For all privacy matters, including exercising your rights, contact us at privacy@wexio.io. Where we act as a Processor for a Customer, requests relating to End-User data should ordinarily be directed to that Customer as Controller, and we will assist the Customer as described in Section 3.

Wexio, LLC

Privacy contact: privacy@wexio.io

3. Our Roles: Controller and Processor

Because the Service is used by businesses to communicate with their own End Users, our role under data-protection law depends on the category of data.

  • Wexio as Processor. For the Personal Data of our Customers' End Users contained in Conversation Data (including messages, media, and contacts), the Customer is the Controller and Wexio acts as the Customer's Processor, processing that data only on the Customer's documented instructions. Our processing of that data is governed by our Data Processing Agreement. The Customer is responsible for the lawful basis, notices, and consents applicable to its End Users.
  • Wexio as Controller. For the Personal Data of the individuals who register and administer a Customer account, and for website visitors, Wexio is the Controller. This includes account and profile data, billing data, support communications, and website Usage Data. The remainder of this Policy describes that controller-level processing, except where stated.
  • End-User requests. If you are an End User and wish to exercise rights over your data, please contact the business you were communicating with, which is the Controller of that data. We will support that business in responding to your request.

4. Personal Data We Collect

Data you provide

  • Account and profile data received from your identity provider when you sign in (name, email address, and profile picture if available). Wexio does not offer password registration and never receives or stores your identity-provider password.
  • Contact and inquiry data you submit through forms, such as name, company name and size, work email, and phone number.
  • Billing data processed through our payment processor when you subscribe to a paid plan.
  • Support and communications data when you contact us.

Data processed on your behalf as a Customer

  • Conversation Data (chats, messages, media and files such as images, voice, and PDFs, and contact records) that flows through the Service in connection with your communications with End Users. We process this data as your Processor, as described in Section 3.
  • Knowledge Base content you upload to ground AI answers through retrieval-augmented generation.

Data collected automatically

  • Usage Data such as date and time of access, browser type and settings, operating system, referring URL, HTTP status, and IP address. Temporary storage of the IP address is necessary to deliver the Service and to secure our systems.

5. How and Why We Use Personal Data

As Controller, we use Personal Data to: provide and administer accounts and the Service; process payments and manage subscriptions; provide support; secure the Service and prevent abuse; analyze and improve the Service; send service and, with consent where required, marketing communications; and comply with law. As Processor, we process Conversation Data and Knowledge Base content only to provide the Service on the Customer's instructions, including operating AI Features and Agent Actions the Customer configures.

7. AI Features and Automated Processing

The Service uses AI to generate responses, summaries, classifications, and Agent Actions from Conversation Data and Knowledge Base content that a Customer configures. Two paths exist for AI processing.

  • Managed AI. AI processing is performed through Wexio's AI Subprocessors (listed at wexio.io/subprocessors) under DPAs that restrict use of the data to providing the service and, per those providers' terms, do not use it to train their models.
  • Bring-Your-Own-Key. Where a Customer connects its own AI provider credentials, AI processing occurs under the Customer's own agreement with that provider, and that provider's privacy terms govern. Wexio encrypts supplied credentials at rest but is not responsible for the provider's data handling on that path.

AI output may be inaccurate or incomplete and should be reviewed by the Customer before it is relied upon. Where automated processing produces legal or similarly significant effects on an End User, the Customer, as Controller, is responsible for any measures required under Article 22 GDPR.

8. Where Data Is Stored: Managed and Bring-Your-Own-Storage Modes

The Service offers two storage models for Conversation Data. In both models, organization and account data and billing data are always stored in Wexio-controlled infrastructure and its Subprocessors.

  • Managed storage. Conversation Data is stored in Wexio-controlled infrastructure through the Subprocessors listed at wexio.io/subprocessors, with the security and retention controls described in this Policy and on our Security page.
  • Bring-Your-Own-Storage. Conversation Data is stored in the Customer's own database and cache infrastructure. Wexio processes but does not host that data, and the Customer is responsible for its storage, backups, and security. Personal Data held in Customer-controlled storage is subject to the Customer's own retention and security arrangements.

9. Authentication and Account Security

Authentication is handled exclusively by third-party identity providers (Google, GitHub, or Microsoft). When you sign in, we receive only your name, email address, and profile picture if available; we never receive or store your password. You can manage permissions through your provider's account settings. Review your provider's privacy policy for details of its processing.

10. Sharing and Disclosure of Personal Data

We share Personal Data only as necessary and as described below.

  • Subprocessors: with Subprocessors that provide infrastructure, AI, communications, payment, CRM, and analytics services, bound by DPAs and acting on our documented instructions (see Section 12 and wexio.io/subprocessors);
  • Connected services: with the connected channels, CRM systems, scheduling tools, and payment processor that a Customer chooses to integrate, to provide the requested functionality;
  • Corporate and advisers: with professional advisers, or in connection with a merger, acquisition, or sale of assets, subject to confidentiality;
  • Legal and safety: where required by law, or to protect the rights, safety, and security of Wexio, our Customers, or others.

We do not sell Personal Data, and we do not "sell" or "share" it as those terms are defined under the CCPA/CPRA (see Section 16).

11. CRM Synchronization and Connected Integrations

Where a Customer enables an integration, relevant Personal Data may be synchronized with that service. For example, contact details and conversation summaries may be synced to HubSpot, Salesforce, or Google BigQuery; scheduling data may be exchanged with Google Calendar, Calendly, or Cal.com; and billing data is processed by Stripe. Each integration is activated by the Customer and, once data reaches the third-party service, is additionally governed by that service's own terms and privacy policy.

12. Subprocessors

We engage third-party Subprocessors to provide the Service, including for infrastructure and hosting, AI, email, payments, messaging channels, CRM, and analytics. Each Subprocessor undergoes a security and privacy review and is bound by a DPA consistent with Article 28 GDPR. The current list, including purpose, data processed, and location, is maintained at wexio.io/subprocessors. We provide at least 30 days' notice before adding a new Subprocessor that processes Personal Data, and Customers may object as described in the Data Processing Agreement.

13. International Data Transfers

Our primary infrastructure is hosted in the EU (Ireland). Some Subprocessors are located in, or transfer data to, the United States and other countries. Where we transfer Personal Data outside the EU, EEA, or United Kingdom, we rely on an appropriate transfer mechanism.

  • an adequacy decision under Article 45 GDPR, including reliance on the EU-US Data Privacy Framework for certified US providers such as Google and Stripe; or
  • Standard Contractual Clauses under Article 46(2)(c) GDPR (and the UK International Data Transfer Addendum where relevant) for providers not covered by an adequacy decision, including our AI, database, cache, and certain messaging Subprocessors, together with supplementary measures such as encryption where appropriate.

You may request further information about the safeguards applicable to a given transfer by contacting privacy@wexio.io.

14. Data Retention

We retain Personal Data only as long as necessary for the purposes described in this Policy or as required by law.

  • Conversation Data. Conversation Data and associated media are subject to configurable retention enforced by plan tier and applied through an automated daily cleanup process, after which expired messages and media are permanently deleted. Customers may configure retention within the limits of their plan and may trigger manual deletion to meet erasure requests.
  • Account data is retained for the duration of the active subscription and deleted on account deletion, subject to legal retention periods.
  • Server log files are deleted after 30 days, and backups are retained for up to 90 days after deletion from production systems.
  • Where Bring-Your-Own-Storage is used, retention of Conversation Data in the Customer's own infrastructure is controlled by the Customer.

15. Your Rights Under the GDPR (EU/EEA/UK)

If you are in the EU, EEA, or United Kingdom, you have the following rights, free of charge, in respect of Personal Data for which we are Controller.

  • to withdraw consent at any time where processing is based on consent (Article 7(3));
  • to access your Personal Data (Article 15);
  • to rectification and erasure (Articles 16 and 17);
  • to restriction of processing (Article 18);
  • to data portability (Article 20);
  • to object to processing based on legitimate interests or for direct marketing (Article 21); and
  • to lodge a complaint with a supervisory authority (Article 77).

To exercise these rights, contact privacy@wexio.io using an email associated with your account so we can verify your identity. We will respond within one month, extendable where permitted. If your request concerns data we process as Processor for a Customer, we will refer you to, and assist, that Customer.

16. Your Rights Under the CCPA/CPRA (California)

This Section applies to California residents whose Personal Data we process as a business under the California Consumer Privacy Act, as amended by the California Privacy Rights Act ("CCPA/CPRA"). Where we process Personal Data on a Customer's behalf, we act as that Customer's service provider and process the data only for the business purposes set out in our agreement.

Categories of personal information

In the preceding 12 months we may have collected the following categories of personal information: identifiers (such as name, email, IP address); commercial information (such as subscription and transaction records); internet or network activity (such as Usage Data); and, where provided through the Service, the contents of communications. We collect this information for the business purposes described in Section 5, disclose it to the Subprocessors and connected services described in Sections 10 to 12, and retain it as described in Section 14.

California rights

  • to know the categories and specific pieces of personal information we have collected, the sources, the purposes, and the categories of recipients;
  • to delete personal information we have collected, subject to exceptions;
  • to correct inaccurate personal information;
  • to opt out of the sale or sharing of personal information; and
  • to non-discrimination for exercising your rights.

We do not sell personal information and do not share it for cross-context behavioral advertising as those terms are defined by the CCPA/CPRA. We do not use or disclose sensitive personal information beyond the purposes permitted by the CCPA/CPRA. To exercise your rights, contact privacy@wexio.io; you may use an authorized agent, and we will verify requests before responding.

17. Your Rights Under the LGPD (Brazil)

This Section applies to personal data of individuals in Brazil processed under the Lei Geral de Proteção de Dados (Law No. 13,709/2018, "LGPD"). Consistent with Section 3, where we determine the purposes and means of processing (for example, account, billing, and website data) we act as controller, and where we process personal data on a Customer's behalf we act as operator (operador) under the Customer's instructions, with the Customer acting as controller.

Legal bases (Art. 7 LGPD)

Where we act as controller and the LGPD applies, we process personal data on one or more of the legal bases in Article 7 LGPD, including: the consent of the data subject; compliance with a legal or regulatory obligation; the performance of a contract or preliminary procedures at the data subject's request; the legitimate interests of the controller or a third party, balanced against the data subject's rights and freedoms; and the regular exercise of rights in proceedings. Where we act as operator, the Customer is responsible for establishing the legal basis for the processing of its end users' personal data.

Data subject rights (Art. 18 LGPD)

Subject to the conditions of the LGPD, data subjects in Brazil have the right to obtain from the controller: confirmation of the existence of processing; access to their data; correction of incomplete, inaccurate, or outdated data; anonymization, blocking, or deletion of unnecessary or excessive data or data processed unlawfully; portability to another provider; deletion of data processed with consent; information about entities with which the data has been shared; information about the possibility of refusing consent and its consequences; and revocation of consent. To exercise these rights, contact privacy@wexio.io. Where a request concerns data we process as operator for a Customer, we will refer the request to, and assist, that Customer as controller.

National Data Protection Authority (ANPD)

Processing of personal data in Brazil is overseen by the Autoridade Nacional de Proteção de Dados (ANPD). Data subjects have the right to petition the ANPD in relation to the processing of their personal data. We cooperate with the ANPD in the exercise of its functions as required by law.

International transfers

Personal data of Brazilian data subjects may be transferred to and processed in countries outside Brazil, including through the infrastructure and Subprocessors described in this Policy. We rely on a transfer mechanism recognized under Articles 33 to 35 LGPD, which may include the data subject's specific consent, the necessity of the transfer for the performance of a contract, compliance with a legal obligation, or appropriate contractual safeguards such as standard contractual clauses, together with the technical and organizational measures described in this Policy.

18. Cookies and Tracking Technologies

We use cookies and similar technologies for authentication, preferences, security, analytics, and functionality. Optional cookies are set only with your consent through our consent banner. For full details, including categories, purposes, durations, and how to manage your choices, see our Cookie Policy.

19. Analytics and Website Measurement

We use Google Analytics 4 with IP anonymization enabled and personalized-advertising features disabled, and Vercel Analytics for performance monitoring. These services process limited Usage Data to help us understand and improve the Service. Google LLC is certified under the EU-US Data Privacy Framework. See the Cookie Policy for details and opt-out options.

20. Marketing and Communications

We send service-related messages necessary to operate your account. If you subscribe to our newsletter, we use a double opt-in process and process your email on the basis of consent; you can unsubscribe at any time. We may measure campaign engagement to improve communications. Transactional and notification email is delivered through our email Subprocessor.

21. Payment Processing

Payments are processed by Stripe, a PCI DSS Level 1 service provider. When you make a payment, Stripe may collect your name, email, billing address, and payment-method details. We do not store card numbers, CVV codes, or full payment details; payment data is handled directly by Stripe under its own privacy terms.

22. Data Security

We implement technical and organizational measures appropriate to the risk, including TLS 1.2+ in transit with HSTS, AES-256 encryption at rest with per-organization key derivation, role-based access controls, malware scanning of uploaded files, network segmentation, continuous monitoring, and encrypted backups. No method of transmission or storage is completely secure, and we cannot guarantee absolute security. Our current security practices are described on our Security page.

23. Children's Privacy

The Service is a business tool and is not directed to children. We do not knowingly collect Personal Data from children under 16 through account registration. Where we act as Processor, the Customer is responsible for any processing of minors' data through its own communications and for the additional protections that apply, including CCPA/CPRA rules for consumers under 16. If you believe a child has provided Personal Data to us as Controller, contact privacy@wexio.io and we will take appropriate steps to delete it.

25. Changes to This Policy

We may update this Policy to reflect changes in our practices, technology, or legal requirements. Material changes will be communicated by a prominent notice on the Service or by email at least 30 days before they take effect. The date at the top indicates the last update. Continued use after changes take effect constitutes acceptance of the revised Policy.

26. Contact Us

For questions about this Policy or to exercise your rights, contact us.

Wexio, LLC

Privacy and data protection: privacy@wexio.io

Security: security@wexio.io