1. Who this policy covers
This Policy explains how Webinku processes personal data when people visit our website, create an account, operate a workspace, configure an agent, upload knowledge, contact support, or interact with a Webinku-powered agent. A business using Webinku may separately control customer data processed by its agents and must provide its own notices where required.
2. Data we collect
- Account data: email address, authentication records, consent versions, profile details, and workspace role.
- Workspace data: optional company name, industry, website, support contacts, timezone, business hours, agent settings, and safety rules.
- Knowledge data: uploaded price lists, catalogues, policies, URLs, and instructions.
- Conversation data: customer names or references, messages, channel, timestamps, agent and human replies, and handoff status.
- Voice and call data: selected provider and voice ID, voice notes, call metadata, and recordings or transcripts only when the connected feature and lawful configuration require them.
- Technical data: device, browser, IP-derived security signals, logs, cookies, errors, and usage events needed to operate and protect the service.
- Support and payment data: communications with us and, when paid plans launch, billing status and provider references. Payment-card details should be handled by the payment provider rather than stored by Webinku.
3. Why we use data
We process data to create and secure accounts, provide workspaces and agents, store private knowledge, route conversations, enforce human takeover, generate authorized responses, provide support, prevent abuse, maintain reliability, comply with law, and improve the service. We use data only for purposes compatible with the notice and permissions presented to you.
4. Legal grounds and consent
Depending on the context, processing may be necessary to perform our contract, comply with legal duties, protect legitimate security and operational interests, or act on consent. Where consent is required, it must be informed and may be withdrawn, although withdrawal does not affect earlier lawful processing. Workspace owners are responsible for establishing an appropriate basis for customer data they submit.
5. AI processing and owner control
Agent instructions and conversation content may be sent to configured AI providers to generate responses and perform authorized tasks. Webinku records configuration boundaries such as human handoff, discount limits, voice and call permissions, and safety rules. AI output is probabilistic; workspace owners must supervise their agents and avoid providing data that is unnecessary for the task.
6. Sharing and service providers
We may share data with infrastructure, authentication, database, AI, analytics, communications, payment, voice, and support providers that help deliver the service. Current core infrastructure includes Supabase and Vercel; AI or voice providers are used only when their features are configured. We may also disclose data to comply with law, protect rights and safety, investigate abuse, or support a corporate transaction with appropriate safeguards. We do not sell personal data.
7. International processing
Providers may process data outside Kuwait. Where required, Webinku and workspace owners should use appropriate contractual, organizational, or legal safeguards for international transfers. The location and terms of an optional third-party provider may differ from Webinku’s core infrastructure.
8. Storage, security, and access
Private agent files are stored in non-public storage and access is restricted to authenticated members of the relevant workspace. Database row-level policies separate workspaces. We use authentication, access controls, transport encryption, logging, and provider safeguards designed to protect data. You must keep credentials secure and grant workspace access carefully.
9. Retention
We keep data for as long as needed to provide the service, meet legal and accounting obligations, resolve disputes, enforce agreements, and protect security. Retention depends on the data type, sensitivity, workspace settings, and legal requirements. When an agent is deleted, its document metadata and stored files are scheduled for deletion; backups and security logs may persist for a limited period.
10. Your choices and rights
Subject to applicable law and verification, you may ask to access, correct, delete, restrict, or obtain information about personal data, and may withdraw consent where processing relies on it. Workspace customers should first contact the business whose agent they used; Webinku will assist that business when appropriate. Requests may be sent to hello@webinku.com.
11. Cookies and local storage
Webinku uses essential session cookies for secure authentication and local storage for theme preference. If optional analytics or advertising technologies are added, we will update this Policy and provide controls where required.
12. Children
Webinku is not directed to children and should not be used to knowingly collect children’s personal data without appropriate authorization, consent, and safeguards required by law.
13. Security incidents
We investigate suspected incidents and notify affected parties or authorities when required. Workspace owners must promptly tell us about suspected unauthorized access affecting the service and cooperate with reasonable containment steps.
14. Kuwait privacy framework
This Policy describes Webinku's privacy practices for this service and should be read together with Kuwait's current Data Privacy Protection Regulation. Workspace owners remain responsible for privacy notices and obligations that apply to their own business, sector, and customer data.
15. Updates and contact
We may update this Policy as features, providers, and legal requirements change. Material changes will be communicated appropriately. The version and effective date appear at the top. Privacy questions may be sent to hello@webinku.com. Use of the service is also subject to the Terms of Service.