Privacy Policy
Last updated: September 22, 2026
Contents
1. Controller & Processor Roles
WhizzMS acts in two different capacities depending on the data in question:
- As a data controller, for account-level data about you and the users you invite to your Business (name, email, login activity, billing details) - we decide how this data is used to operate and improve the Service.
- As a data processor (or "service provider" under some regimes), for the catalog data you connect from your own data source and for the chat/search queries your website's End Users submit through your embedded widget - we process this data on your instructions, as your customer, to provide the Service. If you are subject to GDPR, CCPA, or similar law with respect to your End Users, you are the controller for that data and WhizzMS processes it on your behalf.
2. Data We Collect
| Category | Examples | Source |
|---|---|---|
| Account data | Name, email address, hashed password, role, account/business membership | You, when you register or invite a teammate |
| Business configuration | Data source connection details, field mappings, prompt templates, chat widget settings, AI provider selection and API credentials (stored encrypted at rest) | You, via the dashboard |
| Your Content (catalog data) | Product names, descriptions, prices, attributes, images, documents, and any other fields your data source exposes and you choose to make searchable | Fetched from your own data source, on your instruction |
| End-user interaction data | Chat messages and search queries submitted through your widget, session identifiers, conversation history, and derived vector embeddings of that content | Your website's End Users, via the embedded chat widget |
| Billing data | Plan selection, subscription status, payment method details (handled by our payment processor - WhizzMS does not store full card numbers) | You, via the billing page |
| Technical & usage data | IP address, browser/user agent, pages visited, API request logs, rate-limit counters | Automatically, when you or your End Users use the Service |
3. How We Use Data
- To provide the core Service: indexing Your Content, answering search queries, generating chat responses;
- To operate your account: authentication, authorization, role-based access control, billing;
- To secure the Service: rate limiting, abuse detection, audit logging;
- To communicate with you: service notices, security alerts, billing notices, and (only with consent where required) product updates;
- To improve the Service: aggregated, de-identified usage patterns - never Your Content itself used to train any model outside the AI provider call needed to answer a given query.
4. AI Processing of Your Content
When a search or chat query is answered, the relevant portion of Your Content and the query itself are sent to the AI provider your Business has configured (OpenAI, Google Gemini, Azure OpenAI, or AWS Bedrock) to generate an embedding vector and, in RAG/hybrid modes, a natural-language answer. This call is made using your own configured API credentials, under your own agreement with that provider. WhizzMS caches some of these calls (see Compliance & Security Policy) to reduce redundant provider calls and cost, with a bounded expiry, not indefinitely.
5. Who We Share Data With
We do not sell personal data. We share data only with:
- The AI provider you configure - to generate embeddings and responses, as described above;
- Infrastructure sub-processors that host the Service (hosting, vector database, caching, and queueing infrastructure) - see the full current list in our Compliance & Security Policy;
- Payment processors, to process your subscription billing;
- Law enforcement or regulators, only where required by valid legal process; and
- A successor entity, in the event of a merger, acquisition, or asset sale, subject to this policy continuing to apply to previously collected data.
6. Cookies & Similar Technologies
The WhizzMS dashboard uses a session cookie to keep you signed in and a small number of functional cookies (e.g. remembering that you've dismissed the cookie notice). We do not use third-party advertising cookies on the dashboard. If your embedded chat widget uses a browser-local session identifier to keep an End User's conversation continuous across messages, that identifier is scoped to your own website and is disclosed to your End Users through your own site's cookie/privacy notice, which you are responsible for maintaining.
7. Data Retention
- Account data is retained for as long as your account is active, and for a limited period afterward to comply with legal, tax, and dispute-resolution obligations;
- Your Content (indexed catalog data) is retained until you delete it, disconnect the data source, or close your account, at which point it is removed from the search index within a bounded period;
- Chat/conversation history is retained per the retention window configured for your Business (default window shown in your dashboard's Chat Widget settings), after which it is purged;
- Cached AI provider responses (Section 4) expire automatically, typically within 24 hours;
- Billing records are retained as required by applicable tax and accounting law.
8. Security
AI provider API credentials and other secrets are encrypted at rest. Access to a Business's data is restricted by account membership and role-based permissions. See our Compliance & Security Policy for full technical and organizational detail.
9. Your Rights
Depending on your jurisdiction, you may have rights to access, correct, export, or delete personal data we hold about you, and to object to or restrict certain processing. Account-level requests can be made from your dashboard's Settings page or by contacting us at [privacy contact email]. If you are an End User of a Business using WhizzMS's chat widget and wish to exercise a data right over your chat history, please contact that Business directly - WhizzMS processes that data on their instructions as described in Section 1.
10. International Data Transfers
The Service and the AI providers you may configure can involve processing and storing data in countries other than your own. Where required, we rely on appropriate safeguards (such as standard contractual clauses) for cross-border transfers. [Specific transfer mechanisms and hosting regions to be confirmed by the operating entity based on actual deployment infrastructure.]
11. Children's Privacy
The Service is intended for business use and is not directed at children. We do not knowingly collect personal data from children through the WhizzMS dashboard. If a Business's own website (and therefore its embedded chat widget) is directed at children, that Business is responsible for complying with applicable children's privacy law (e.g. COPPA) for its own End Users.
12. Changes to This Policy
We may update this policy from time to time; material changes will be notified through the dashboard or by email before they take effect.
13. Contact
Privacy questions or data-rights requests: [privacy contact email]. Registered entity: [Company Legal Name, Registered Address].
WhizzMS