> ## Documentation Index
> Fetch the complete documentation index at: https://help.wonka.chat/llms.txt
> Use this file to discover all available pages before exploring further.

# Privacy Policy

> Learn how WonkaChat collects, uses, and protects your personal data in compliance with GDPR and EU regulations.

# Privacy Policy

**WonkaChat**\
*(Last updated: November 28, 2025)*

## 1. About This Policy

This Privacy Policy (the "Policy") describes how we (as defined below) collect, share, and use any information that, used alone or in combination with other information, relates to you ("Personal Data") when you ("you" and "your", "User") create an account to access the AI conversational platform ("WonkaChat") made available to you through our platform.

The Policy also applies to account access management, collection of aggregated data for statistical or tracking purposes, and communication of information relating to WonkaChat's activities and operation.

For any questions about Personal Data collection outside of WonkaChat, please contact us at [support@meetwonka.com](mailto:support@meetwonka.com).

Please take the time to carefully read this Policy. If you have questions or comments, please contact our data protection officer at: **[support@meetwonka.com](mailto:support@meetwonka.com)**.

## Data Controller and Processor Roles

For the purposes of this Policy, **Wonka AI BV**, with its registered office at Luikersteenweg 165, 3500 Hasselt, registered with the Belgian Crossroads Bank for Enterprises under number 0800 787 953, ("Wonka AI", "we", "our") acts as data controller for Personal Data collected to offer its service, WonkaChat.

However, the User acts as data controller under applicable data protection legislation regarding the use of WonkaChat and all data they integrate into it. In this context, Wonka AI acts as data processor.

This Policy sets out Wonka AI's commitments regarding data protection and the measures implemented to guarantee the security and confidentiality of your personal data. It also specifies the rights you have in this regard and the practical procedures for exercising them with us.

## 2. Categories of Data Collected and Purposes

The types of Personal Data we collect and the reasons we process them include:

<div className="overflow-x-auto">
  <table className="min-w-full border border-gray-300">
    <thead>
      <tr className="bg-gray-100">
        <th className="border border-gray-300 px-4 py-2 text-left">Processing Purpose</th>
        <th className="border border-gray-300 px-4 py-2 text-left">Types of Data Processed</th>
        <th className="border border-gray-300 px-4 py-2 text-left">Legal Basis</th>
      </tr>
    </thead>

    <tbody>
      <tr>
        <td className="border border-gray-300 px-4 py-2">User account creation and management</td>
        <td className="border border-gray-300 px-4 py-2">Name, surname, professional email address, password, organization/profession</td>
        <td className="border border-gray-300 px-4 py-2">Contract execution</td>
      </tr>

      <tr>
        <td className="border border-gray-300 px-4 py-2">Secure access and WonkaChat maintenance</td>
        <td className="border border-gray-300 px-4 py-2">Technical and connection data (logs, identifiers)</td>
        <td className="border border-gray-300 px-4 py-2">Legitimate interest (security and operation)</td>
      </tr>

      <tr>
        <td className="border border-gray-300 px-4 py-2">Statistical analysis and growth measurement</td>
        <td className="border border-gray-300 px-4 py-2">Aggregated tracking and internet connection data</td>
        <td className="border border-gray-300 px-4 py-2">Consent</td>
      </tr>

      <tr>
        <td className="border border-gray-300 px-4 py-2">Communication of information or news</td>
        <td className="border border-gray-300 px-4 py-2">Name, surname, professional email</td>
        <td className="border border-gray-300 px-4 py-2">Consent, legitimate interest</td>
      </tr>
    </tbody>
  </table>
</div>

If we were to request other Personal Data not mentioned above, we will clearly indicate, at the time of collection, the nature of the information requested and the reasons for this request.

Some Personal Data may also be obtained indirectly, for example when a User associates you with their account to allow you access to their space.

### Automatically Collected Technical Information

We may automatically collect certain technical information related to your device, including:

* IP address
* Device type used
* Unique identifiers
* Browser type
* Approximate location (country or city)
* Other technical data

At this time, we do not collect any information about your interaction with WonkaChat, such as pages viewed or features used. If we choose to collect such data in the future, it will be solely for internal analysis and to enhance the relevance and overall experience of WonkaChat.

Some of this information may be collected through cookies or similar technologies, in accordance with our <a href="/en/legal/cookie-policy">Cookie Policy</a>.

## 3. Recipients of Your Personal Data

We may transmit your Personal Data to the following categories of recipients:

<CardGroup cols={2}>
  <Card title="Technical Providers & Subcontractors" icon="wrench">
    Developers, hosts, analytics tool providers, or support providers acting under strict Wonka AI instructions. We require these subcontractors to process Personal Data strictly according to our instructions and take appropriate measures to ensure Personal Data remains protected.
  </Card>

  <Card title="Authorities or Public Bodies" icon="shield-check">
    Any competent law enforcement body, regulator, government agency, court, or other third party when we believe disclosure is necessary under applicable laws or regulations, or to establish or defend our rights, or to protect your vital interests or those of any other person.
  </Card>
</CardGroup>

<CardGroup cols={2}>
  <Card title="External Advisors" icon="users">
    Auditors, advisors, legal representatives, and similar agents in the context of advisory services they provide to us and subject to confidentiality commitments.
  </Card>

  <Card title="Authorized Third Parties" icon="user-check">
    Any other person provided you have given prior consent to disclosure.
  </Card>
</CardGroup>

## 4. Protection Principles

In accordance with this Policy, we will process Personal Data as follows:

<AccordionGroup>
  <Accordion title="Fairness" icon="balance-scale">
    Personal Data will be processed fairly and transparently. We commit to clearly inform about processing methods and act in compliance with applicable legislation.
  </Accordion>

  <Accordion title="Lawfulness" icon="gavel">
    No processing will be carried out without a valid legal basis; any use of Personal Data will rest on a legal foundation.
  </Accordion>

  <Accordion title="Purpose Limitation" icon="tools">
    Personal Data will only be collected and processed for specific, explicit, and legitimate purposes. They will not be subject to any subsequent use incompatible with these initial purposes.
  </Accordion>

  <Accordion title="Data Minimisation" icon="minimize">
    Data is adequate, relevant, and limited to what is necessary for the purposes for which it is processed.
  </Accordion>

  <Accordion title="Accuracy" icon="check-circle">
    We implement reasonable measures to ensure Personal Data is accurate, complete, and regularly updated when needed. However, you remain obliged to notify us without delay of any changes or inaccuracies to maintain the accuracy of your information.
  </Accordion>

  <Accordion title="Integrity and Confidentiality" icon="shield">
    Personal Data is processed to ensure its security, including protection against unauthorized access, unlawful processing, loss, destruction, or accidental damage, through appropriate technical and organizational measures.
  </Accordion>

  <Accordion title="Accountability" icon="clipboard-list">
    Wonka AI assumes responsibility for compliance with these principles and is able to demonstrate, at any time, the compliance of implemented processing, notably through maintaining adequate documentation, establishing internal procedures, and conducting impact analyses or compliance audits when required.
  </Accordion>
</AccordionGroup>

## 5. Security

We use appropriate technical and organizational measures to protect the Personal Data we collect and process about you. The measures we use are designed to provide a level of security appropriate to the risk of processing your Personal Data.

### Security Measures Include:

<CardGroup cols={2}>
  <Card title="Data Encryption" icon="lock">
    **In Transit & At Rest**

    All communications protected by HTTPS/TLS (TLS 1.3, with TLS 1.2 support if necessary). Data encrypted at rest.
  </Card>

  <Card title="Environment Isolation" icon="server">
    **Strict Tenant Isolation**

    Each user's data (conversations, configurations, user accounts, audit logs, connections) is logically separated and protected against unauthorized access.
  </Card>
</CardGroup>

<CardGroup cols={2}>
  <Card title="Secure Credential Management" icon="key">
    **Protected Authentication**

    Passwords are hashed (bcrypt), access tokens (JWT) are cryptographically signed, and sensitive keys/APIs are never stored in plain text.
  </Card>

  <Card title="Enhanced Authentication" icon="user-shield">
    **Limited Session Duration**

    Short-duration access tokens and rotating refresh tokens limit risks. We support local authentication, Google Authentication, and Azure AD/Entra ID.
  </Card>
</CardGroup>

### Additional Security Features

<Tabs>
  <Tab title="Access Controls">
    **Principle of Least Privilege**

    Each user, agent, or tool can only operate within the limits of permissions explicitly assigned to them. No internal mechanism allows AI to bypass authorizations.
  </Tab>

  <Tab title="Audit & Monitoring">
    **Structured Logging**

    We record security-relevant events: authentication attempts, permission changes, suspicious activity, data access, agent/tool executions, and migrations. All sensitive data is automatically masked.
  </Tab>

  <Tab title="Abuse Prevention">
    **Operational Protection**

    Rate limiting mechanisms protect against abusive automated usage or attacks.
  </Tab>

  <Tab title="External Testing">
    **Penetration Testing**

    Independent penetration testing was conducted in November 2025, and all identified critical vulnerabilities have been corrected.
  </Tab>
</Tabs>

<Note>
  **Ephemeral Data Processing by Model Providers:** When an external model (Azure, AWS Bedrock, Google) is used, data is processed only in memory and is never retained or reused for training.
</Note>

## 6. International Data Transfers

Your Personal Data may be transferred to and processed in countries other than where you reside. These countries may have data protection laws that differ from your own country's laws and, in some cases, may be less protective.

<CardGroup cols={2}>
  <Card title="EU Hosting" icon="globe-europe">
    **Primary Location**

    Our servers are located within the European Economic Area (EEA).
  </Card>

  <Card title="Third Country Transfers" icon="plane">
    **Protected Transfers**

    Some service providers may be established outside the EEA. We ensure these transfers comply with GDPR Chapter V and guarantee adequate protection.
  </Card>
</CardGroup>

### Transfer Safeguards

We use one or more of the following mechanisms:

* European Commission adequacy decision
* Standard contractual clauses adopted by the European Commission, with additional measures if necessary
* Any other appropriate safeguards provided by GDPR

<Warning>
  We do not transfer any data outside the EEA without implementing these safeguards and ensuring data subjects have enforceable rights and effective remedies.
</Warning>

## 7. Data Retention

We retain Personal Data we collect from you when we have a legitimate business need (for example, to provide a service you requested or to comply with applicable legal requirements).

### Retention Periods:

<CardGroup cols={2}>
  <Card title="Account Management" icon="user">
    **1 year** from last activity
  </Card>

  <Card title="Support Requests" icon="headset">
    **1 year** after last contact date
  </Card>
</CardGroup>

<CardGroup cols={2}>
  <Card title="User Experience Improvement" icon="lightbulb">
    **1 year** from last activity
  </Card>

  <Card title="Statistical Analysis" icon="chart-bar">
    **1 year** from last activity
  </Card>
</CardGroup>

When we no longer have a legitimate business need to process your Personal Data, we anonymize it, delete it, or if deletion is not possible (for example, your Personal Data has been stored in backup archives), we securely store and isolate it from any other processing until deletion becomes possible.

## 8. Your Data Protection Rights

You have the following data protection rights, which you can exercise by contacting us at **[support@meetwonka.com](mailto:support@meetwonka.com)**:

<AccordionGroup>
  <Accordion title="Access, Rectification, Update & Erasure" icon="edit">
    You may request access to your Data, correct it if inaccurate, update it, or request its deletion.
  </Accordion>

  <Accordion title="Objection, Limitation & Portability" icon="arrows-alt">
    In certain circumstances, you may object to processing of your Data, request limitation of their use, or seek portability of your Data to yourself or a third party.
  </Accordion>

  <Accordion title="Consent Withdrawal" icon="undo">
    When processing is based on your consent, you may withdraw it at any time. This withdrawal will not affect the lawfulness of processing carried out before withdrawal, nor processing based on other legal bases (such as contract or legal obligation).
  </Accordion>

  <Accordion title="Lodge a Complaint" icon="exclamation-triangle">
    If you have concerns about how we process your Data, we invite you to contact us first. If you feel your request has not been sufficiently addressed, you have the right to lodge a complaint with the competent supervisory authority.
  </Accordion>
</AccordionGroup>

### Contact the Data Protection Authority

**Belgian Data Protection Authority**\
Rue de la Presse 35\
1000 Brussels\
Phone: +32 (0)2 274 48 00\
Email: [contact@apd-gba.be](mailto:contact@apd-gba.be)\
Website: [www.autoriteprotectiondonnees.be](http://www.autoriteprotectiondonnees.be)

We respond to all requests we receive from individuals wishing to exercise their Personal Data protection rights in accordance with applicable data protection laws.

## 9. Policy Updates

We may revise this Policy from time to time to account for evolving legal, technical, or organizational requirements. In case of substantial changes, we will take appropriate measures to inform you, depending on the nature and impact of the changes.

The date of the last update appears at the top of this Policy and allows you to verify the most recent version.

## 10. Contact

If you have questions about the processing of your Personal Data or wish to exercise your rights, please contact us by email at **[support@meetwonka.com](mailto:support@meetwonka.com)**.

<Card title="Data Protection Officer" icon="shield-check">
  **Email:** [support@meetwonka.com](mailto:support@meetwonka.com)\
  **Subject:** Data Protection Inquiry - WonkaChat
</Card>
