Home Pricing Docs About Live Demo Contact Sign In

GDPR & UK GDPR

Last updated: August 26, 2026

Where you or the visitors to your website are in the European Economic Area, the United Kingdom, or Switzerland, the GDPR (and its UK equivalent) applies to how WhizzTalk handles personal data. This page sets out how WhizzAct Private Limited meets it.

1. Controller and processor

  • We are the controller of the personal data of our own account holders: registration details, business profile, support correspondence, and billing records.
  • We are a processor of the personal data your widget collects from your site's visitors. You are the controller: you decide what your flow asks, why, and how long to keep it. We process it only on your documented instructions — which, for most customers, are the settings you configure in the dashboard plus our Terms of Service.

2. Lawful bases we rely on

  • Contract (Art. 6(1)(b)) — creating and running your account, providing the platform, taking payment.
  • Legitimate interests (Art. 6(1)(f)) — keeping the service secure, preventing abuse of shared AI and messaging quotas, and improving the product, balanced against your rights.
  • Legal obligation (Art. 6(1)(c)) — retaining invoices and tax records.
  • Consent (Art. 6(1)(a)) — where we ask for it separately, such as optional product emails. You can withdraw it at any time.

For visitor data collected through your widget, choosing and documenting the lawful basis is your responsibility as controller.

3. Our commitments as your processor (Art. 28)

  • We process personal data only on your instructions, and tell you if we believe an instruction breaches data protection law.
  • Everyone with access is bound by confidentiality obligations, and access is limited to what their role requires.
  • We apply the technical and organisational measures described on our Compliance page (Art. 32).
  • We engage sub-processors only under written terms no less protective than these, and we publish the current list so you can object before a new one is added.
  • We help you respond to data-subject requests, and assist with impact assessments and breach notification.
  • On termination we delete or return the personal data we hold for you, except where law requires us to keep it.
  • We make available the information you need to demonstrate compliance, and allow audits on reasonable notice.

A Data Processing Addendum incorporating these terms, with the Standard Contractual Clauses attached, is available on request from privacy@whizzact.com.

4. Data-subject rights

Where we are the controller, you can exercise the rights of access, rectification, erasure, restriction, portability, and objection, and the right not to be subject to solely automated decisions with legal or similarly significant effects. We respond within one month, extendable by two months for complex requests, and we don't charge for it unless a request is manifestly unfounded or excessive.

To exercise a right, write to privacy@whizzact.com. If your data was collected by a chat widget on someone else's website, that business is the controller — please contact them, and we will act on their instruction.

5. Automated processing

Parts of the platform are AI-driven: an assistant asks follow-up questions, matches answers to recommendations, and drafts a summary when a support ticket is opened. These outputs are suggestions and ticket content — they do not produce legal or similarly significant decisions about a person, and a human at the business always handles the resulting lead or ticket.

6. International transfers

WhizzAct is established in India, and data is hosted in India. Personal data transferred out of the EEA or UK is protected by the European Commission's Standard Contractual Clauses (with the UK Addendum where relevant), together with the technical measures described on our Compliance page. The sub-processors involved are listed there.

7. Retention

We keep personal data only as long as it serves the purpose it was collected for. Chat sessions with no contact detail are deleted automatically after 24 hours of inactivity; your account data is kept while your account is active and deleted within 30 days of a deletion request, apart from records we must retain by law.

8. Breach notification

Where we are the controller, we notify the competent supervisory authority within 72 hours of becoming aware of a personal data breach that is likely to result in a risk to individuals, and we notify affected individuals where the risk is high. Where we are your processor, we notify you without undue delay so that you can meet your own 72-hour obligation.

9. Contact and complaints

Data-protection contact: privacy@whizzact.com. You also have the right to lodge a complaint with your local supervisory authority — or, in the UK, the Information Commissioner's Office — though we'd ask you to raise it with us first.