Privacy Policy
How WRKZY handles personal data when you visit our website, create an account, use a workspace, connect communication providers, or contact us.
Scope and our role
This policy applies to website visitors, account and trial users, workspace users, business contacts, and people who submit sales, support, security, privacy, or deletion requests to WRKZY.
For account, website, signup, trial, billing, support, security, and business-contact data, AIRBRILS PRIVATE LIMITED determines why and how the data is processed. Depending on the applicable law, this is commonly described as acting as a data fiduciary or controller.
A client generally determines the purpose of processing customer data that it imports, creates, or receives in its WRKZY workspace. WRKZY processes that data on the client's instructions as its service provider or data processor. If your request concerns customer data controlled by a WRKZY client, that client may be the appropriate first contact.
Data we process
Information you give us
- Account and workspace information such as name, email, organization, role, authentication information, users, permissions, settings, assignments, notes, and audit history.
- Information submitted through signup, sales, support, security, privacy, and deletion requests.
- Trial, plan, entitlement, currency, invoice, tax, renewal, cancellation, and payment-status records. WRKZY does not collect or store complete payment-card details.
Customer operations data
- Contacts, companies, names, phone numbers, email addresses, conversations, CRM fields, notes, tasks, follow-ups, business-card images submitted for scanning and reviewed contact details, catalog items, deals, pipelines, quotes, and related commercial history.
- Connected-channel data, including WhatsApp Business and email account identifiers, participants, message content, subjects, threads, timestamps, templates, webhook and delivery events, and attachments or media where needed for the service.
- Campaign, audience, schedule, delivery, engagement, consent, unsubscribe, suppression, and template-snapshot information.
Technical and usage data
We process IP address, browser and device information, pages viewed, referrer, approximate location derived from network information, app events, security and error logs, and operational telemetry. Our website uses Vercel Web Analytics for aggregated traffic measurement and limited local or session storage for functions such as preferences, feedback state, authentication security, and required product functions.
Sources of data
We receive data directly from users and clients, from the communication and identity providers they choose to connect, from recipients interacting with client messages, from service and payment providers, and from normal use of the website and application.
How and why we use data
We process personal data for lawful purposes connected to providing and protecting WRKZY. Depending on the data and applicable law, we rely on your consent, a service or response you requested, our agreement with a client, the client's documented instructions, compliance with law, or the need to protect the service, users, and others from harm.
- Provide inboxes, CRM records, customer context, campaigns, pipelines, quotes, automations, dashboards, reporting, and AI-assisted features.
- Send client-approved messages through connected WhatsApp Business accounts and email providers, and display available delivery, reply, engagement, unsubscribe, and suppression information.
- Operate, secure, monitor, troubleshoot, and improve WRKZY; prevent spam, fraud, misuse, and security incidents; and enforce applicable terms and platform policies.
- Respond to access, sales, support, billing, privacy, security, and deletion requests, and meet legal, tax, regulatory, contractual, and provider obligations.
Where processing depends on consent, you may withdraw that consent. Withdrawal does not affect processing already carried out lawfully and may limit a feature that needs the data to operate.
AI-assisted processing
When a workspace enables an AI-assisted feature, WRKZY uses OpenAI's API to prepare summaries, drafts, rewrites, recommendations, and CRM suggestions. WRKZY sends only the selected conversation content, relevant customer or CRM context, user instructions, and technical fields needed for the requested result.
For business-card scanning, WRKZY sends the submitted front and optional back images to OpenAI for extraction. Users review and correct the extracted details before saving them as a new contact or applying them to an existing contact. Saved details, ownership, and event grouping become workspace CRM data.
The public pricing adviser may process an anonymous visitor's pricing question, a bounded session history, page context, and structured capacity requirements. Visible history remains in that browser tab unless the visitor clears it or closes the tab. WRKZY does not store the pricing-adviser transcript in its application database or submit it with a trial or sales enquiry. A visitor may separately choose to submit the validated configuration through the sales form.
People decide whether and how to use the output. A configured workflow may carry out its defined action, but current AI assistance does not independently execute autonomous, multi-step goals.
WRKZY does not persist raw AI prompts or raw provider responses in its application database. Operational metadata may be kept for audit, troubleshooting, cost, and security purposes; anonymous pricing-adviser metadata excludes the question, answer, full requirements, and network address and is deleted after 30 days. Content a user chooses to save, and source-cited customer memory prepared for team review, becomes workspace data and is retained under the rules in this policy.
OpenAI states that business and API data is not used to train its models by default. WRKZY requests that Responses API application state not be stored. OpenAI may still retain customer content in abuse-monitoring logs for up to 30 days by default, unless longer retention is legally required or a different approved data-control configuration applies.
Google Workspace API data
When a user connects a Google Workspace or Gmail account, WRKZY accesses only the Gmail data authorized for the selected email feature. Depending on the connection, this may include the connected account identity, message and thread metadata, message content, attachments when needed, Sent-mail history, and mailbox labels or state.
WRKZY uses this data to provide visible, user-facing email features: sending user-approved messages, syncing and displaying Private Mail, importing requested Sent history, and applying mailbox actions such as read, unread, archive, trash, or restore. Private Mail remains owner-scoped unless its owner deliberately shares approved context or moves future work into a team-managed inbox.
If a workspace user enables an applicable AI-assisted feature, WRKZY may send bounded Gmail and CRM context to OpenAI only to provide the visible summary, draft, recommendation, or other assistance the user requested. WRKZY does not use Google Workspace API data to develop, improve, or train generalized artificial-intelligence or machine-learning models.
The use of raw or derived user data received from Google Workspace APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements. WRKZY does not sell Google Workspace API data or use it for advertising, retargeting, credit-worthiness, or lending purposes.
Users can disconnect a Google email provider from WRKZY to stop future API access. Eligible data is then deleted under the retention and deletion controls described below and on our Data Deletion page.
Providers and transfers
We share data only as needed to provide WRKZY, follow a client's instructions, protect the service, or comply with law. Depending on the features used, recipients may include:
- Supabase for hosted database, authentication, storage, and platform services; Vercel for website and application hosting and aggregated Web Analytics; and Cloudflare Turnstile for bot and abuse prevention.
- OpenAI for AI-assisted processing when enabled, and configured email or support providers for transactional and service communications.
- Meta and WhatsApp APIs, connected email providers, and other communication providers a client chooses to connect.
- Professional advisers, authorities, or other parties when disclosure is required or permitted by law.
Trials and paid subscriptions
Chargebee provides subscription billing and payment-method management, and Razorpay is the configured payment gateway. They may process billing and payment information under their own terms and privacy notices. No payment method is required to start the 14-day Growth trial. If a client later chooses a paid plan, we use the resulting subscription and payment-status records to activate access, apply plan limits, reconcile billing, prevent fraud, and provide account support.
International processing
WRKZY is operated from India. Service providers and connected platforms may process data in India or other countries. Where required, we use an adequacy decision, approved standard contractual clauses, the UK Addendum or IDTA, ANPD-approved clauses, or another lawful transfer mechanism, together with technical and organizational safeguards. Current providers and known processing regions are described on our Subprocessors page.
WRKZY does not sell Meta Platform Data, WhatsApp customer data, client workspace data, or information submitted through signup, sales, support, privacy, or security requests.
Retention
We keep personal data only for as long as it is reasonably needed for the purpose described in this policy. Workspace, conversation, attachment, campaign, contact, and CRM data is generally retained while the client's workspace remains active or as directed by the client.
Trial, subscription, invoice, tax, payment-reconciliation, support, security, and dispute records may be kept for periods required by law or reasonably needed for accounting, fraud prevention, security, and dispute resolution.
We delete or anonymize eligible data after a verified request or when the relevant purpose ends, unless continued retention is required for legal compliance, security, fraud prevention, dispute resolution, backup integrity, or another lawful business record. Residual copies may remain in protected backups until the applicable backup cycle completes.
Your rights and requests
Depending on your location and relationship to the data, you may have rights to access a summary of your personal data, correct or update it, request erasure or export, withdraw consent, object to or restrict certain processing, seek grievance redressal, appeal a denied request where applicable, or nominate another person to exercise applicable rights in the event of death or incapacity. We do not discriminate against a person for exercising an applicable privacy right.
Send a privacy or data-rights request to privacy@wrkzy.com, or send a formal grievance to grievance@wrkzy.com. Workspace administrators can also use our Data Deletion page for workspace or customer-data deletion requests. We verify requests before acting and aim to acknowledge them within 7 business days and complete eligible deletion requests within 30 days after verification.
For customer conversation data controlled by a WRKZY client, we may direct the request to that client or verify it with the workspace administrator. Where applicable, after using our grievance process, you may make a complaint to the relevant data-protection authority, including the Data Protection Board of India when its complaint process applies.
Additional location-specific information is available in our Regional Privacy Rights notice. Clients that require controller-processor terms should review the Data Processing Addendum.
Security and safeguards
Security
We use technical and organizational safeguards designed to protect workspace and customer data. These include workspace-scoped access controls, role-based permissions, encrypted server-side handling of provider credentials, verified provider events, session controls, activity history, and operational monitoring. No service can guarantee absolute security. Read our Security overview.
Incident response
We investigate suspected personal-data breaches, take appropriate containment and remediation steps, and notify affected parties or authorities when required by applicable law.
Children
WRKZY is a business service and is not designed for child-directed use. Clients must not knowingly use WRKZY to process children's personal data unless they have a separately reviewed lawful basis, all required authority or consent, and controls appropriate to the applicable law.
Changes to this policy
We may update this policy as WRKZY, legal requirements, or connected-provider requirements change. We will post the revised version on this page, update the date above, and provide additional notice when required.