Scope and roles
This policy applies to Wonkka’s public website, accounts, and workspaces, including WhatsApp conversations, AI-assisted operations, bookings, classes, orders, memberships, access, payments, billing, and analytics.
When a business uses Wonkka to communicate with its customers, that business decides why and how customer data is used, and Wonkka processes it to provide the service. Wonkka determines the processing needed to manage accounts, billing, security, support, and its own compliance obligations.
Data we collect
Depending on the features used, we may process the following categories:
- Account and identity data, such as name, email, password hash, protected verification codes, sessions, invitations, membership, and workspace role.
- Workspace and operational data, such as location, modules, schedules, availability, services, products, professionals, resources, customers, bookings, classes, orders, memberships, access checks, check-ins, and notifications.
- Content and metadata needed to operate WhatsApp, the AI assistant, and operational notifications, including text, audio, images, PDFs, derived transcripts and visual summaries, phone numbers, business-scoped user identifiers, profile names, delivery status, opt-outs, and human handoffs.
- Wonkka billing and business-payment data, such as plan, usage, amounts, references, deadlines, status, refunds, connected-account identifiers, and CBUs, CVUs, or aliases used in configuration or assigned to memberships. Integration credentials are encrypted; Wonkka does not store full card details or payer banking credentials.
- Technical, operational, and security data, such as IP address, device, browser, sessions, access dates, logs, traces, API and webhook events, errors, and signals used to prevent abuse or fraud.
Where data comes from
We receive data from people who create an account; authorized workspace members; customers who interact with the business; and connected integrations, including Kapso, Meta, WhatsApp, Mercado Pago, and Cresium. We also receive API and webhook events to synchronize messages, assets, subscriptions, and payments.
How we use data
We use data only when needed for purposes such as:
- Creating and managing accounts, workspaces, locations, teams, customers, and operations.
- Sending and receiving messages; transcribing audio; interpreting images and PDFs in context; running AI-assisted responses; executing authorized actions; and handing conversations to the team.
- Managing plans and trials, measuring usage, creating payment requests, reconciling charges and refunds, and maintaining recurring subscriptions.
- Answering questions, resolving incidents, and communicating important service changes.
- Authenticating users, protecting the platform, and detecting fraud, abuse, or policy violations.
- Analyzing performance and improving Wonkka, preferably with aggregated or deidentified information. Wonkka does not use conversation content to train AI models.
Legal bases and responsibilities
Depending on the jurisdiction and context, we process data to perform a contract, comply with legal obligations, protect legitimate operational and security interests, or based on consent when required.
Each business is responsible for having a valid legal basis, notices, and consents to collect data, send messages, and charge its customers, and for following the rules of WhatsApp, Meta, Kapso, Mercado Pago, Cresium, and any other provider it connects.
Retention
We retain data while an account is active and for as long as reasonably necessary to provide the service, maintain operational records, resolve disputes, prevent fraud, and meet legal, tax, or accounting obligations.
Encrypted WhatsApp webhooks expire after 30 days, and their content is removed sooner when successfully processed. The assistant’s working state expires after 7 days of inactivity. Wonkka processes audio, images and PDFs without keeping its own permanent copy of those files; message content and derived transcripts or summaries are purged after 90 days. Technical payloads expire after 7 days. Purging runs through periodic tasks; minimal operational, security and compliance records and provider retention may follow other timelines.
Security and international transfers
We apply reasonable technical and organizational measures, including role-based controls, workspace isolation, protected access codes, webhook validation, and encryption of sensitive tokens and credentials. No system can guarantee absolute security.
Our providers may process data in other countries. Where required, we use available contracts and safeguards to protect those transfers under applicable law.
Your rights
Depending on applicable law, you may request:
- Access to your personal data and an explanation of its processing.
- Correction or updating of inaccurate information.
- Deletion when there is no valid reason to retain the data.
- Objection to or restriction of certain processing.
- A portable copy where this right applies.
- Withdrawal of consent without affecting processing before withdrawal.
Children
Wonkka is intended for businesses and people with legal capacity to contract. We do not knowingly collect children's data through their own accounts. Businesses using Wonkka for services aimed at minors must obtain the authorizations required by law.
Changes to this policy
We may update this policy to reflect legal, technical, or service changes. We will publish the current version on this page and, when a change is material, provide notice through a reasonable channel.
Privacy questions
Write from the email associated with your account and identify your workspace and the right you want to exercise. If you are a customer of a business using Wonkka, include its name and the WhatsApp number, email, or identifier you used in the interaction.
Contact Wonkka