#Vatio Privacy Policy
Last updated: September 2, 2026
This Privacy Policy explains how Wolf Technology SpA ("Vatio," "we,"
"us," or "our"), the operator of the Vatio AI agent platform
(vatio.ai and related subdomains, the "Service"), collects, uses,
discloses, and protects personal data when you:
- visit or create an account on
vatio.aior use the Vatio CLI, Operator, or Super Admin tools ("Platform Users"); - interact with an AI agent built on Vatio through WhatsApp or an embedded web chat widget ("End Users" or "Contacts"); or
- otherwise communicate with us.
This policy is written to satisfy the requirements of the EU/UK General Data Protection Regulation ("GDPR") and the privacy-disclosure requirements Meta Platforms, Inc. imposes on businesses using the WhatsApp Business Platform (the "WhatsApp Business Messaging Policy" and Meta's Platform Terms). If your local law provides additional rights, those rights apply to you as well.
#1. Who we are — controller and processor roles
Vatio is a platform that lets Workspace Owners (our business customers) configure and deploy AI agents that talk to the Workspace Owner's own end users over WhatsApp and web chat.
Because of that structure, we act in two different legal capacities, and the role we play determines who you should contact with a request:
- As Data Controller — for account data of Platform Users (developers who sign up to build agents), for platform security and diagnostic logs (IP addresses, user-agent strings, API access logs), and for any data we collect through our own marketing site or our own WhatsApp number when we are the business you are messaging. For this data, Wolf Technology SpA is the controller and this policy applies directly.
- As Data Processor — for Contact data (name, phone number, email, message content, media) generated when an End User messages a Workspace Owner's AI agent. We process this data only on the Workspace Owner's documented instructions, under a Data Processing Agreement, to provide the Service. The Workspace Owner is the controller for this data and is responsible for its own privacy notice to its End Users; this policy describes, transparently, how we as processor handle that data on the Workspace Owner's behalf.
If you are an End User and are unsure who the Workspace Owner is for a conversation you had, ask the business you were messaging, or contact us at the address in Section 13 and we will direct your request appropriately.
#2. Data we collect
#2.1 Platform Users (developers, admins)
| Category | Examples | Source |
|---|---|---|
| Account identifiers | Email address, display name, role | You, or Google/GitHub OAuth |
| Authentication data | One-time-password codes, OAuth identifiers (provider + uid), CLI device-authorization tokens, API tokens |
You, Google, GitHub |
| Session & security logs | IP address, user-agent string, session timestamps | Automatically, on every request |
| API activity logs | Request parameters, response metadata, forwarded-for headers | Automatically, when you use our API |
#2.2 End Users / Contacts (people chatting with an agent)
| Category | Examples | Source |
|---|---|---|
| Identifiers | WhatsApp phone number and profile display name, or name/email/phone provided in web chat | You, via WhatsApp or the chat widget |
| Conversation content | Text messages, and any images, audio, video, or documents you send or receive | You, via WhatsApp or web chat |
| Message metadata | Message IDs, timestamps, delivery/read status, error codes | Automatically, from WhatsApp/Meta infrastructure |
| Authentication evidence | Where a Workspace Owner has connected its own login/identity system, profile attributes it supplies to authenticate you (e.g., verified account status) | The Workspace Owner's own systems |
| AI processing data | The model's response, and (where applicable) intermediate reasoning generated by the AI model to produce that response | Generated automatically when your message is processed |
#2.3 Everyone
| Category | Examples | Source |
|---|---|---|
| Error/diagnostic data | Stack traces, request context, and — in production — IP address and other request metadata | Automatically, via our error-monitoring tool |
| Cookies / local storage | Session identifiers needed to operate the web chat widget and the Platform | Automatically |
We do not intentionally collect special categories of data (health, biometric, religious, political, or similar data) about End Users. Because agents are configured by Workspace Owners, we ask Workspace Owners not to design agents that solicit special category data unless they have an independent, documented legal basis and appropriate safeguards for doing so.
#3. How we use personal data, and our legal bases (GDPR Art. 6)
| Purpose | Data used | Legal basis |
|---|---|---|
| Create and administer Platform User accounts | Account identifiers, authentication data | Performance of a contract (Art. 6(1)(b)) |
| Operate the AI agent runtime — receive, process, and respond to messages | Conversation content, identifiers, message metadata | Performance of a contract with the Workspace Owner (as processor) / contract or legitimate interest as controller where we are the business messaged |
| Route your message to an AI model to generate a response | Conversation content | Performance of a contract (Art. 6(1)(b)) |
| Detect, prevent, and investigate fraud, abuse, and security incidents | Session logs, API logs, error/diagnostic data | Legitimate interests (Art. 6(1)(f)) — keeping the Service secure |
| Maintain and improve the Service (debugging, reliability) | Error/diagnostic data, aggregated usage data | Legitimate interests (Art. 6(1)(f)) |
| Comply with legal obligations, respond to lawful requests | Any of the above, as required | Legal obligation (Art. 6(1)(c)) |
| Send you service or transactional communications | Email address | Performance of a contract / legitimate interests |
| Where you have opted in to receive messages initiated by a business (e.g., WhatsApp template/marketing messages) | Phone number, name | Consent (Art. 6(1)(a)) — withdrawable at any time |
We do not use End User conversation data to train AI models unless a Workspace Owner has separately and explicitly opted in to that use, and even then only after removing or with the End User's informed consent, as required by applicable law.
Automated decision-making. Your messages are processed by an AI system to generate a response, which is a form of automated processing. We do not use this processing to make decisions that produce legal effects or similarly significant effects concerning you without the possibility of human review. If a Workspace Owner configures an agent to take an automated action that does have such effects for you, you have the right to request human intervention, express your point of view, and contest that decision by contacting us or the Workspace Owner.
#4. The WhatsApp Business Platform and Meta
We use the WhatsApp Business Platform, operated by Meta Platforms, Inc. and its affiliates ("Meta"), to send and receive messages with End Users. By messaging an agent on WhatsApp, you should be aware that:
- Your phone number, profile name, message content, and any media you send are transmitted through Meta's infrastructure and are processed by Meta as well as by us, as necessary to deliver, secure, and improve the messaging service.
- Messages exchanged with a business on the WhatsApp Business Platform are not end-to-end encrypted between you and the business in the same way personal WhatsApp chats between two individuals are. Meta and the business (and its service providers, including us) may access message content to provide the service, ensure safety and compliance, and — where a Workspace Owner has enabled it — to generate AI responses.
- Meta's own Privacy Policy and WhatsApp Business Privacy Policy also apply to Meta's handling of your data and are independent of, and in addition to, this policy.
- We only message you on WhatsApp because you contacted us first, or because you (or the Workspace Owner, with your consent) opted in to receive messages. You may opt out at any time by replying UNSUBSCRIBE (in capital letters) to any message, blocking the WhatsApp Business number, or contacting us using Section 13 — we will honor opt-outs promptly and stop further messaging. Reply SUBSCRIBE (in capital letters) to opt back in.
- We use a WhatsApp "preview" number for testing during development. If you interact with the preview, the same protections in this policy apply; test data is deleted on a shorter schedule (see Section 6).
#5. Who we share data with (sub-processors)
We share personal data only as necessary to operate the Service, and always under contractual confidentiality and data-protection obligations. Our current sub-processors are:
| Sub-processor | Purpose | Location (data processed) |
|---|---|---|
| Meta Platforms, Inc. | WhatsApp Business Platform messaging | United States / global (Meta infrastructure) |
| OpenRouter, Inc. (and the underlying AI model providers it routes requests to, e.g. Google, OpenAI, Anthropic, Meta, depending on the model a Workspace configures) | Generating AI responses to messages | United States and other countries, depending on the selected model provider |
| Amazon Web Services (AWS) | Cloud file storage (Amazon S3) for message media and attachments; transactional email delivery (Amazon SES) | United States, South America (see Section 7) |
| DigitalOcean, LLC | Application hosting and managed database hosting | United States (New York City datacenter) |
| Cloudflare, Inc. | CDN, TLS termination, DDoS protection | Global network |
| Sentry (Functional Software, Inc.) | Error monitoring and diagnostics | United States |
| Google LLC | OAuth sign-in for Platform Users | United States |
| GitHub, Inc. (Microsoft) | OAuth sign-in for Platform Users | United States |
We do not sell personal data, and we do not share personal data with third parties for their own independent marketing purposes.
We may also disclose personal data: to comply with a legal obligation, court order, or lawful government request; to enforce our terms; to protect the rights, property, or safety of Vatio, our users, or the public; or in connection with a merger, acquisition, or sale of assets, subject to continued protection of your data under this policy or a substantially similar one.
#6. Data retention
We retain personal data only as long as necessary for the purposes described in this policy, then delete or anonymize it.
| Data | Retention |
|---|---|
| Platform User account data | Until account deletion, plus 30 days |
| Conversation content (messages, media) | For the duration of the Workspace Owner's active relationship with us; if the Workspace Owner's account is closed, retained for 30 days and then purged, unless the Workspace Owner requests earlier deletion |
| WhatsApp preview test data (unverified numbers and OTPs) | Automatically deleted 24 hours after an abandoned/expired verification attempt |
| Session, API access, and security logs | 90 days |
| Error-monitoring data (Sentry) | Per Sentry's default retention, currently up to 90 days; as of this version we no longer send IP addresses, cookies, or request headers to Sentry by default |
| Backups | Rolling 30-day backup window |
We will delete or anonymize data sooner where an End User or Platform User validly exercises a deletion right under Section 8, unless we are required or permitted by law to retain it longer (e.g., for legal claims or regulatory obligations).
#7. International data transfers
We and our sub-processors are located in multiple countries, including the United States. If you are located in the European Economic Area, the United Kingdom, or Switzerland, your personal data may be transferred to and processed in countries that have not been recognized by the European Commission as providing an adequate level of data protection.
Where this occurs, we rely on appropriate safeguards recognized under GDPR, such as the European Commission's Standard Contractual Clauses, or on our sub-processors' own certified compliance mechanisms (e.g., Meta's and AWS's Standard Contractual Clauses with their customers). You can request a copy of the relevant safeguard by contacting us at the address in Section 13.
[ACTION ITEM]: Confirm Standard Contractual Clauses (or equivalent) are executed with every sub-processor in the table in Section 5 before relying on this section.
#8. Your rights
If GDPR or another applicable data-protection law grants you rights over your personal data, you have the right to:
- Access — obtain a copy of the personal data we hold about you.
- Rectification — correct inaccurate or incomplete data.
- Erasure — request deletion of your data ("right to be forgotten"), subject to legal retention requirements.
- Restriction — ask us to limit how we process your data.
- Portability — receive your data in a structured, commonly used, machine-readable format, or ask us to transmit it to another controller.
- Object — object to processing based on legitimate interests, or to direct marketing at any time.
- Withdraw consent — where processing is based on consent (e.g., opted-in WhatsApp messaging), withdraw it at any time without affecting the lawfulness of prior processing.
- Lodge a complaint with your local data protection supervisory authority. If you are in the EU, you can find your authority via the European Data Protection Board. Wolf Technology SpA has no establishment in the EU, UK, or Switzerland, so it has no designated lead supervisory authority there at this time; in Chile, complaints may be directed to the Agencia de Protección de Datos Personales.
To exercise any of these rights, contact us using Section 13. If your request concerns a conversation with a specific business's AI agent, we may need to verify your identity and may direct part of the request to the relevant Workspace Owner where they are the controller, per Section 1.
We will respond within the timeframe required by applicable law (generally one month under GDPR, extendable by two further months for complex requests).
#9. Security
We use technical and organizational measures designed to protect personal data against unauthorized access, alteration, disclosure, or destruction, including encryption of data in transit (TLS), access controls, and monitoring for security incidents. No method of transmission or storage is completely secure, and we cannot guarantee absolute security.
If we become aware of a personal data breach that poses a risk to your rights and freedoms, we will notify the competent supervisory authority and, where required, affected individuals, in accordance with applicable law.
#10. Children's privacy
The Service is not directed to, and we do not knowingly collect personal data from, children under 16 (or the minimum age required by your local law and by WhatsApp's own Terms of Service, if higher). Workspace Owners are responsible for ensuring their own use of the Service complies with applicable children's privacy laws (e.g., not deploying agents targeted at children without appropriate safeguards). If you believe a child has provided us with personal data, contact us and we will delete it.
#11. Cookies and similar technologies
Our website and embedded web chat widget use strictly necessary cookies or local storage to maintain your session and enable the chat to function. We do not currently use non-essential advertising or analytics cookies.
#12. Changes to this policy
We may update this policy from time to time. We will post the updated version at this URL with a new "Last updated" date, and where changes are material, we will provide additional notice (e.g., by email to Platform Users or a notice on the Service).
#13. Contact us
Wolf Technology SpA Antonio Bellet 193, Of. 1210, Providencia, Región Metropolitana, Chile Privacy inquiries: [email protected]
As of this version, Vatio's users and End Users are located across North, Central, and South America, with no operations or users in the EU, UK, or Switzerland — so an Art. 27 GDPR representative is not currently required.
Wolf Technology SpA has not appointed a Data Protection Officer, as none is currently required under applicable law given the scale and nature of our processing. Privacy inquiries, including any that would otherwise go to a DPO, should be directed to the contact above.