Legal
Privacy Policy
We collect what we need to run Wopie for your business and nothing more. Customer Data is never used to train foundation models. Inside your Workspace we act on your instructions and your own privacy policy governs; for our relationship with you, this policy does.
- Effective
- 6 September 2026
- Version
- 1.0
- Provider
- The Trustee for The Wink Group, trading as Wopie
Use your browser's print function to save this page as a PDF.
1. Who we are and what this policy covers
This Privacy Policy explains how The Trustee for The Wink Group (ABN 69 794 946 307), trading as Wopie (we, us, our), handles Personal Information. We are an Australian business, based in Victoria, and we contract as trustee of The Wink Group. The Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs) are the primary frame for this policy: we handle Personal Information in accordance with the APPs, and we commit to doing so whether or not the Privacy Act applies to us by operation of law. Where we handle information about individuals in the European Economic Area or the United Kingdom, the GDPR and UK GDPR sections of this policy also apply.
This policy covers our website at https://www.wopie.ai, the web application at https://app.wopie.ai, the Wopie apps for Slack and Microsoft Teams, and our support and sales communications. Capitalised terms have the meanings given in our Definitions.
Wopie is built for businesses and we do not offer the Service to consumers. When a Customer connects a Workspace and its Authorised Users delegate work to Wopie, we handle the Personal Information inside that Workspace and its Connected Tools on the Customer's behalf and on its instructions. In that role we act as a processor (or service provider) and the Customer is the controller or APP entity responsible for the information. The Customer's own privacy policy governs that information, our Data Processing Agreement sets out our obligations to the Customer, and we may redirect requests about Workspace data to the Customer.
We are the controller of the Personal Information that relates to our own relationship with you: Account holders, billing contacts, website visitors, prospects, and people who contact us.
2. Information we collect
| Category | Examples | Source |
|---|---|---|
| Account and contact data | Name, work email, job title, company name, password hash or single sign-on identifier, plan and Account settings. | You, or the colleague who invites you. |
| Workspace and user identifiers | Slack or Teams user IDs, display names, email addresses, Workspace or tenant IDs, and membership of Channels Wopie has been added to. | The Chat Platform, under the permissions granted at install. |
| Chat content | Messages in Channels Wopie has been added to, limited to what a request needs; direct messages only when a user messages Wopie directly; files shared into those Channels. | Authorised Users, through the Chat Platform. |
| Connected Tool data | Records Wopie reads from HubSpot, Stripe, Notion, Zendesk, Xero, Google Sheets, Gmail, Outlook or other Connected Tools under the authorising user's permissions, and the OAuth tokens that allow that access. | Connected Tools, when an Authorised User authorises them. |
| Outputs and approval records | Deliverables, drafts and proposed actions Wopie generates; who requested, approved or declined each Gated Action and when; the audit trail. | Generated by the Service. |
| Usage, device and log data | Features used, Credits consumed, IP address, browser and operating system, timestamps, error and security logs. | Collected automatically. |
| Billing data | Billing contact, company details, ABN or tax ID, invoices, payment method type and last four digits. Payments are processed by Stripe; we do not store full card numbers. | You, and Stripe. |
| Support communications | Emails, chat transcripts, screenshots and files you send us when asking for help. | You. |
| Website data | Cookies, pages visited, approximate location from IP address, referral source and UTM parameters, product analytics events (PostHog, once enabled), and advertising pixel events only if enabled and, where the law requires, only with your consent. | Your browser. |
3. How we use information
We use Personal Information only for the following purposes.
- Providing and securing the Service — creating Accounts, connecting Workspaces and Connected Tools, running requests, delivering Outputs, and keeping the Service available and safe.
- Generating Outputs — sending the context a request needs to our Model Providers so they can return the text or proposed action that becomes an Output.
- Approvals and the audit trail — recording who asked for what, what Wopie did, and who approved or declined each Gated Action.
- Billing — metering Credits, issuing invoices, collecting payment and managing subscriptions.
- Support — answering questions and investigating problems.
- Service communications — sending the account, security, billing and product notices you need to use the Service.
- Product analytics and improvement — understanding how the Service is used and making it better, using Aggregated Data wherever possible.
- Security, fraud and abuse prevention — detecting suspicious activity and enforcing the Acceptable Use Policy.
- Legal compliance — meeting our obligations under tax, corporate, privacy and other laws, and responding to lawful requests.
- Marketing — with your consent where the law requires it, telling you about features and offers. You can opt out at any time.
We do not use Customer Data to train foundation models. Our Model Providers are contractually restricted from using Customer Data to train or improve their models. Aggregated Data used to improve the Service does not identify you, your Customer or any individual.
4. Legal bases (GDPR and UK GDPR)
If you are in the European Economic Area or the United Kingdom, we rely on the following legal bases to process your personal data.
- Performance of a contract — to provide the Service under the Agreement, manage your Account, bill you and give you support.
- Legitimate interests — to secure the Service and prevent fraud and abuse; to understand how the Service is used and improve it; to communicate with business contacts about our products; to enforce our rights; and to run our business. We balance each interest against your rights before relying on it.
- Consent — for non-essential cookies, advertising pixels and marketing communications where the law requires consent. You can withdraw consent at any time.
- Legal obligation — to keep tax and accounting records, respond to lawful requests, and notify data breaches where required.
Under Australian law we collect Personal Information only where it is reasonably necessary for our functions or activities.
5. Who we disclose information to
We disclose Personal Information only in these ways.
- Sub-processors — the hosting, database, Model Provider, payment, messaging and analytics providers that process data on our behalf under written contracts. The current list is at /legal/sub-processors.
- Your Customer's Workspace administrators — they can see the audit trail, Outputs, approval records and configuration for their Workspace, because the Customer is responsible for that data.
- Connected Tool providers — when an Authorised User instructs Wopie to read from or write to a Connected Tool, data is exchanged with that provider under the Customer's own agreement with it.
- Professional advisers — our lawyers, accountants, auditors and insurers, under confidentiality.
- Legal compulsion — courts, regulators and law enforcement, where the law or a binding order requires. Where the law allows, we tell the affected Customer first and disclose no more than we must.
- Business transfers — a buyer or successor in a merger, acquisition, financing or sale of assets, on terms that keep this policy in force.
- With your consent — in any other case where you have agreed.
We do not sell Personal Information, and we do not share it with third parties for their own advertising.
6. Slack and Microsoft platform commitments
When you install Wopie in Slack or Microsoft Teams, we access Workspace data only under the permissions the Chat Platform grants. We make these commitments for data received through those platforms.
- Data accessed through Slack or Teams is used only to provide the Service to that Workspace.
- It is not used for advertising, for profiling, or to train general-purpose models.
- Uninstalling Wopie revokes our access tokens and stops all new access immediately.
- Data is deleted when the Account is closed, on the timetable in the How long we keep information section.
- We comply with the Slack API Terms of Service and Slack App Directory requirements, and with the Microsoft commercial marketplace policies that apply to Teams apps.
Workspace administrators decide which Channels Wopie joins, which Approval Rules apply and which Connected Tools are authorised. The permission scopes we request are described at /security.
7. International transfers
Our primary database and file storage are hosted in United States. Our Model Providers and some other Sub-processors process data in the United States, and the Chat Platforms run their own global infrastructure. The location of each Sub-processor is listed at /legal/sub-processors.
When Personal Information leaves the country it was collected in, we protect it with these safeguards.
- Written contracts with every Sub-processor requiring at least the level of protection in this policy.
- For EEA and UK personal data, the European Commission's Standard Contractual Clauses and the UK International Data Transfer Addendum, incorporated into our Data Processing Agreement.
- For Personal Information collected in Australia, the reasonable steps required by APP 8 to ensure overseas recipients do not breach the APPs. We remain accountable for it while it is overseas.
- For personal information collected in Canada, contractual protection consistent with PIPEDA's accountability principle; you may contact us to learn how it is handled abroad.
- For personal information collected in New Zealand, the safeguards required by Information Privacy Principle 12 of the Privacy Act 2020.
- Encryption in transit and at rest, and the access controls in the Security section.
8. Security
We protect Personal Information with technical and organisational measures appropriate to the data and the risks involved, including:
- Encryption in transit using TLS 1.2 or higher, and at rest using AES-256 or an equivalent standard.
- Encrypted storage of OAuth tokens and other credentials, separated from application data and never exposed in logs or Outputs.
- Role-based, least-privilege access to production systems.
- Multi-factor authentication for all staff access to production, code and administrative systems.
- Centralised logging and monitoring of access to Customer Data, with alerts for unusual activity.
- A documented incident response process with defined roles, escalation paths and notification timelines.
- Secure development practices, including code review, dependency scanning and separate production and testing environments.
- Confidentiality obligations for everyone with access to Customer Data.
Our controls are mapped to the SOC 2 Trust Services Criteria (SOC 2-ready) and our policies are aligned to ISO 27001. Current attestation status for Wopie itself: controls are mapped and documented; our own SOC 2 examination has not yet started and is planned for the coming months. We say ready or aligned, not certified, until an audit report for Wopie exists. The infrastructure and platform providers we build on hold their own independent attestations (including SOC 2 Type II and ISO/IEC 27001); those are listed, attributed to each provider, in the Sub-processor List. They cover the layers those providers operate and are not certifications of Wopie. More detail is published at /security. No system is completely secure; please report suspected vulnerabilities or incidents to security@wopie.ai.
9. How long we keep information
We keep Personal Information only as long as we need it for the purposes above, then delete or de-identify it.
| Data | Retention period | Reason |
|---|---|---|
| Account and contact data | For the life of the Account, then deleted within 30 days of closure. | To run the Account and complete closure. |
| Chat content and Connected Tool data | Only as long as needed to complete the request and produce the audit trail, then according to the Customer's retention settings. Default: 90 days after the request completes, or sooner if the Customer configures a shorter period or deletes the request. | Wopie is a worker, not an archive. The Customer controls how long working data stays. |
| Outputs and audit trail | For the life of the Account, then deleted 30 days after closure. | So the Customer has a complete record of what was requested, done and approved. |
| Encrypted backups | Rotated within 35 days. Deleted data leaves backups on that cycle. | Disaster recovery. |
| Billing records | 7 years from the end of the financial year to which they relate. | Australian tax and corporate record-keeping law. |
| Usage and security logs | 12 months. | Security investigation, abuse prevention and service reliability. |
| Marketing data | Until you unsubscribe, then a suppression record so we do not contact you again. | To honour your preferences. |
Model Providers process request context to generate an Output. Their retention of that data is governed by our contracts with them: our Model Provider retains request inputs and outputs for no more than 30 days for abuse and safety monitoring, then deletes them. Model Providers do not use Customer Data to train their models.
10. Your rights and how to exercise them
If you are in Australia, you may ask for access to the Personal Information we hold about you and ask us to correct it if it is inaccurate, out of date, incomplete, irrelevant or misleading. If you believe we have breached the APPs, complain to us first and we will investigate and respond in writing. If you are not satisfied, you may complain to the Office of the Australian Information Commissioner at oaic.gov.au.
If you are in the EEA or the UK, you have these rights, subject to the conditions in the GDPR or UK GDPR.
- Access to your personal data and information about how we process it.
- Rectification of inaccurate or incomplete personal data.
- Erasure of your personal data in certain circumstances.
- Restriction of processing in certain circumstances.
- Portability of the personal data you provided to us, in a structured, machine-readable format.
- Objection to processing based on legitimate interests, and to direct marketing at any time.
- Withdrawal of consent at any time, where processing is based on consent.
- Lodging a complaint with the supervisory authority in the country where you live or work, or where you believe a breach occurred.
How to exercise your rights. Email privacy@wopie.ai and tell us what you need. We may need to verify your identity first, and will ask for no more than that requires. We respond within 30 days, or sooner where the law requires, and will tell you if we need more time and why.
Requests about Workspace data. If your request concerns information inside a Customer's Workspace or Connected Tools, the Customer controls that data. We will pass your request to the Customer, or ask you to contact your Workspace administrator, and we will help the Customer respond as our Data Processing Agreement requires.
11. Additional rights for residents of United States states
If you live in a US state with a comprehensive privacy law (including California, Colorado, Connecticut, Oregon, Texas, Utah and Virginia), you may have the following rights in relation to Personal Information we hold as a business or controller. Where we process Workspace data as a service provider or processor for a Customer, please direct your request to that Customer; we will help them respond.
- Know and access. The categories and specific pieces of Personal Information we have collected about you, the sources, our purposes, and the categories of third parties we disclose it to.
- Delete. Deletion of Personal Information we collected from you, subject to the exceptions the law allows.
- Correct. Correction of inaccurate Personal Information.
- Opt out of sale or sharing and of targeted advertising. We do not sell Personal Information and we do not share it for cross-context behavioural advertising. If we ever enable advertising pixels on our website, we will honour opt-out preference signals, including the Global Privacy Control, and provide a Do Not Sell or Share control.
- Limit use of sensitive Personal Information. We do not use sensitive Personal Information for purposes other than providing the Service.
- Non-discrimination. We will not deny you the Service, charge a different price, or provide a different level of quality because you exercised a right.
To exercise these rights, email privacy@wopie.ai. We will verify your request using the email address associated with your Account or Workspace and respond within 45 days, extending once by a further 45 days where the law permits and we tell you why. You may use an authorised agent where the law allows; we may ask the agent for proof of authority. If we decline a request you may appeal by replying to our decision, and we will respond to the appeal within the period the applicable law requires.
13. Children
The Service is for businesses and their staff. It is not directed at anyone under 18, and we do not knowingly collect Personal Information from anyone under 18. Information about children is Regulated Data, which the Acceptable Use Policy prohibits from the Service. If you believe a person under 18 has provided us with Personal Information, contact us and we will delete it.
Because the Service is not directed at children and is not a general-audience site or app, the United States Children's Online Privacy Protection Act (COPPA) does not apply to it. We do not knowingly collect Personal Information from children under 13 in any case.
14. Notifiable data breaches
If we become aware of unauthorised access to, disclosure of, or loss of Personal Information, we contain the incident and assess whether it is likely to result in serious harm to any individual. Where it is, and the Notifiable Data Breaches scheme applies, we notify the Office of the Australian Information Commissioner and the affected individuals as soon as practicable, explaining what happened, what information was involved and what people can do in response.
Where a breach affects Customer Data, we notify the Customer on the timetable in our Data Processing Agreement so that it can meet its own obligations, including under the GDPR or UK GDPR where those apply. Report suspected incidents to security@wopie.ai.
15. Changes to this policy and how to contact us
We review this policy at least once a year, and update it whenever the Service, the law or our practices change. New versions are published here with a new effective date. If a change materially reduces your rights or expands what we collect, we give Account owners at least 30 days' notice before it takes effect.
Privacy questions and requests: privacy@wopie.ai. Security incidents: security@wopie.ai. Post: The Trustee for The Wink Group, 1/10 Langton Street, Glenroy VIC 3046, Australia. Our representative in the European Union and the United Kingdom for the purposes of Article 27 of the GDPR and UK GDPR is being appointed. Until the appointment is published here, EU and UK individuals and authorities can reach us directly at privacy@wopie.ai and we will respond as if the representative had received the request. The representative's name and address will be added to this section and to the Legal notice on appointment, as a logged change.
Version 1.0. Effective 6 September 2026.