Legal

Privacy Policy

This Privacy Policy explains how Wisdok (“Wisdok”, “we”, “us”, “our”) collect, use, disclose, retain and protect personal information when you visit the Wisdok website, use Wisdok, create or manage an account, request a demonstration, communicate with us, or otherwise interact with our services.

Wisdok is designed primarily for business and professional use.

Effective date: September 15, 2026

1. Information We Collect

Depending on how you interact with Wisdok, we may collect the following categories of information.

1.1 Account and business information

When you create an account or an organization account, we may collect information such as:

  • name;
  • business or organization name;
  • job title or role;
  • business email address;
  • telephone number;
  • account credentials and authentication information;
  • organization and user-role information; and
  • other information you provide when establishing or administering an account.

1.2 Communications and enquiries

If you contact us, request a demonstration, request information, or communicate with our team, we may collect the information contained in your communication and the contact details you provide.

1.3 Service and account activity

We may collect information relating to your use of Wisdok, including account configuration, organization membership, user roles, service activity, feature usage, support requests, and related technical records.

Customer administrators may be able to create, modify or remove user access and manage organization-level settings. The customer organization is responsible for determining which of its personnel are authorized to access its Wisdok account and Customer Content.

1.4 Customer Content

Customers may submit commercial documents and related information to Wisdok for analysis. This may include contracts, tenders and RFPs, proposals, statements of work, agreements, purchase orders, invoices, policies and other business documents.

For purposes of this Privacy Policy, this information is referred to as “Customer Content.”

Customer Content may contain personal information belonging to the customer's employees, customers, suppliers, contractors or other individuals.

Where Wisdok processes Customer Content on behalf of a customer, the customer generally determines the purposes and means of processing and Wisdok processes that information as a service provider or processor in accordance with the applicable Customer Agreement and, where applicable, Data Processing Addendum.

1.5 Billing and transaction information

For commercial transactions, we may collect and process the necessary information to issue invoices, confirm payments, maintain accounting records, reconcile transactions and comply with applicable legal, tax and financial requirements.

Wisdok currently uses business invoicing and bank-transfer payment arrangements. We do not require you to provide full payment-card details directly to Wisdok through the website.

1.6 Technical and security information

We may collect information necessary to operate, secure and maintain the service, including:

  • IP address;
  • browser and device information;
  • authentication and access records;
  • timestamps;
  • error and diagnostic information;
  • security logs; and
  • other technical information reasonably necessary to operate and protect the service.

2. How We Use Information

We use information for purposes including:

  • providing and operating Wisdok;
  • creating and administering accounts;
  • authenticating users and managing access;
  • processing and analyzing Customer Content as requested by customers;
  • generating analysis results and reports;
  • providing customer support;
  • responding to enquiries and demonstration requests;
  • issuing invoices and maintaining financial records;
  • maintaining service reliability, performance and security;
  • detecting, preventing and investigating misuse, fraud or security incidents;
  • complying with applicable legal, regulatory and accounting requirements; and
  • communicating with customers about the service, including important operational or contractual matters.

We do not sell personal information or Customer Content to third parties for advertising or data-broker purposes.

3. Customer Content and AI-Assisted Analysis

3.1 Customer responsibility and processing role

For Customer Content submitted by an organization, the customer generally determines what information is submitted to Wisdok, why it is processed and who within the organization is authorized to access it.

Wisdok processes Customer Content to provide the Wisdok service and in accordance with the customer's documented instructions and applicable contractual terms.

Customers remain responsible for ensuring that they have the necessary rights, permissions and lawful basis to submit Customer Content to Wisdok and to instruct Wisdok to process it.

The distinction between controller and processor depends on the particular processing activity and the parties' respective responsibilities. Wisdok may act as a controller for information it processes for its own business purposes and as a processor or service provider for Customer Content processed on behalf of a customer.

3.2 AI-assisted analysis

Wisdok uses AI-assisted processing to analyze commercial documents and generate structured findings, summaries and reports.

Depending on the service configuration, analysis may involve multiple processing stages designed to examine different aspects of a document, such as commercial, financial and legal considerations, followed by aggregation or review of the resulting findings.

Wisdok is designed as a decision-support system. Its outputs are intended to assist authorized users in reviewing documents and identifying relevant issues. They do not constitute legal, financial or other professional advice and should be reviewed by appropriately authorized human personnel before being relied upon for material business decisions.

Wisdok does not use Customer Content to train or fine-tune general-purpose AI models.

Where third-party AI or model providers process Customer Content on our behalf, we use providers and configurations intended to restrict such information from being used for general model training, subject to the applicable provider terms, technical configuration and contractual arrangements.

AI providers and technical configurations may change over time as we improve the service. Any such changes remain subject to applicable contractual, security and data-protection requirements.

3.3 Customer Content is not used for advertising

We do not use Customer Content for targeted advertising, behavioral advertising or the sale of advertising profiles.

4. Wisdok Deployment Models

Wisdok is primarily offered as a hosted software service.

We are also developing and supporting enterprise deployment capabilities in which Wisdok may be deployed or configured within a customer-controlled environment or under an architecture specifically agreed with the customer.

Where an enterprise or customer-controlled deployment is provided, the applicable deployment architecture, hosting responsibilities, data locations, integrations, security responsibilities and support arrangements will be defined in the relevant agreement, statement of work or technical documentation.

The privacy and processing arrangements for a particular deployment therefore depend on the service and architecture agreed with the customer.

5. Google Drive and Other Knowledge-Source Connections

In certain enterprise configurations, Wisdok may be connected to customer-authorized knowledge sources, including services such as Google Drive, to support retrieval-augmented analysis (“RAG”) or related knowledge-retrieval functionality.

Where such a connection is enabled:

  • the customer or an appropriately authorized user must grant the relevant permissions through the applicable service's authorization process;
  • Wisdok accesses information within the permissions granted to it;
  • customer-authorized sources may be used to retrieve information relevant to an analysis requested by the customer;
  • the information is used to provide the corresponding Wisdok functionality and is not used for advertising or unrelated purposes; and
  • access and processing remain subject to the applicable customer agreement, deployment configuration and data-protection requirements.

Wisdok will request only permissions reasonably necessary for the relevant functionality and will use connected-service data in accordance with the applicable service policies.

For Google Workspace and Google Drive integrations, Wisdok follows the applicable Google API Services User Data Policy and Limited Use requirements. Google requires applications using its APIs to clearly disclose the data accessed, how it is used and how it is shared, and to limit use of Google user data to the purposes disclosed to users.

Where Google Drive connectivity involves restricted scopes, additional Google verification and security requirements may apply. The specific permissions requested by Wisdok will depend on the functionality being implemented.

6. Service Providers and Subprocessors

We may use third-party service providers to operate or support aspects of Wisdok, including providers for:

  • cloud hosting and infrastructure;
  • authentication and identity services;
  • AI or model processing;
  • storage and databases;
  • communications and customer support;
  • security and monitoring; and
  • other technical services necessary to provide the service.

Where required by applicable data-protection law, such providers may act as subprocessors.

We require relevant service providers to process information only for authorized purposes and to maintain appropriate contractual, technical and organizational safeguards.

A current list of relevant subprocessors may be provided to customers upon request or made available through the applicable contractual documentation.

7. International Processing and Transfers

Depending on the service configuration and the location of our service providers, information may be processed or stored in countries other than the country in which you or your organization is located.

Where applicable data-protection law requires safeguards for international transfers, we will use appropriate mechanisms, which may include contractual safeguards such as Standard Contractual Clauses or other legally recognized transfer mechanisms.

Specific data-location and transfer arrangements for enterprise deployments may be defined in the applicable agreement or statement of work.

8. Data Retention

We retain information only for as long as reasonably necessary for the purposes described in this Privacy Policy, the applicable customer agreement, or as required by law.

For Customer Content, retention and deletion are primarily governed by the applicable Customer Agreement and, where applicable, Data Processing Addendum.

Following termination of a customer's service, Customer Content will generally be deleted or returned in accordance with the applicable contractual terms, subject to legal, regulatory, security, backup or other legitimate retention requirements.

Information required for accounting, tax, legal, dispute-resolution or compliance purposes may be retained for the period required by applicable law.

9. Security

We use reasonable technical and organizational measures designed to protect information against unauthorized access, loss, alteration, disclosure or destruction.

Security measures may include access controls, authentication controls, encryption in transit, appropriate protection of stored information, logging, monitoring and other measures appropriate to the nature of the service and information processed.

No internet-based service can guarantee absolute security. Customers are also responsible for maintaining appropriate security over their own accounts, credentials, users and connected systems.

10. Your Privacy Rights

Depending on your location and the applicable law, you may have rights relating to your personal information, which may include rights to:

  • access your personal information;
  • request correction of inaccurate information;
  • request deletion of information;
  • object to or restrict certain processing;
  • request portability of certain information; and
  • withdraw consent where processing is based on consent.

Where Wisdok processes personal information on behalf of a customer, requests concerning that processing may need to be directed to the customer as the relevant controller. We will reasonably assist customers with applicable data-subject requests in accordance with the applicable agreement and data-protection requirements.

11. Automated Decision-Making

Wisdok provides AI-assisted analysis and decision-support.

Wisdok is not intended to make decisions that produce legal effects or similarly significant effects concerning individuals without appropriate human involvement.

Wisdok's findings and recommendations should be reviewed by authorized users before being relied upon for significant commercial, legal, financial or operational decisions.

12. Children's Information

Wisdok is a business service and is not directed to children.

We do not knowingly seek to collect personal information from children through the service.

13. Changes to This Privacy Policy

We may update this Privacy Policy from time to time to reflect changes to the service, technology, legal requirements or our information-handling practices.

When material changes are made, we will update the “Last Updated” date and, where appropriate, provide additional notice.

Where changes affect the way we access or use Google user data, we will update our disclosures and obtain any consent required by applicable Google policies before using such data for a newly disclosed purpose.

14. Contact

If you have questions about this Privacy Policy or our handling of personal information, please contact:

Email: legal@wisdok.com

For customer-specific data-processing matters, please refer to the applicable Customer Agreement and Data Processing Addendum.

Last updated: September 15, 2026