#Vatio Privacy Policy

Last updated: September 2, 2026

This Privacy Policy explains how Wolf Technology SpA ("Vatio," "we," "us," or "our"), the operator of the Vatio AI agent platform (vatio.ai and related subdomains, the "Service"), collects, uses, discloses, and protects personal data when you:

This policy is written to satisfy the requirements of the EU/UK General Data Protection Regulation ("GDPR") and the privacy-disclosure requirements Meta Platforms, Inc. imposes on businesses using the WhatsApp Business Platform (the "WhatsApp Business Messaging Policy" and Meta's Platform Terms). If your local law provides additional rights, those rights apply to you as well.


#1. Who we are — controller and processor roles

Vatio is a platform that lets Workspace Owners (our business customers) configure and deploy AI agents that talk to the Workspace Owner's own end users over WhatsApp and web chat.

Because of that structure, we act in two different legal capacities, and the role we play determines who you should contact with a request:

If you are an End User and are unsure who the Workspace Owner is for a conversation you had, ask the business you were messaging, or contact us at the address in Section 13 and we will direct your request appropriately.


#2. Data we collect

#2.1 Platform Users (developers, admins)

Category Examples Source
Account identifiers Email address, display name, role You, or Google/GitHub OAuth
Authentication data One-time-password codes, OAuth identifiers (provider + uid), CLI device-authorization tokens, API tokens You, Google, GitHub
Session & security logs IP address, user-agent string, session timestamps Automatically, on every request
API activity logs Request parameters, response metadata, forwarded-for headers Automatically, when you use our API

#2.2 End Users / Contacts (people chatting with an agent)

Category Examples Source
Identifiers WhatsApp phone number and profile display name, or name/email/phone provided in web chat You, via WhatsApp or the chat widget
Conversation content Text messages, and any images, audio, video, or documents you send or receive You, via WhatsApp or web chat
Message metadata Message IDs, timestamps, delivery/read status, error codes Automatically, from WhatsApp/Meta infrastructure
Authentication evidence Where a Workspace Owner has connected its own login/identity system, profile attributes it supplies to authenticate you (e.g., verified account status) The Workspace Owner's own systems
AI processing data The model's response, and (where applicable) intermediate reasoning generated by the AI model to produce that response Generated automatically when your message is processed

#2.3 Everyone

Category Examples Source
Error/diagnostic data Stack traces, request context, and — in production — IP address and other request metadata Automatically, via our error-monitoring tool
Cookies / local storage Session identifiers needed to operate the web chat widget and the Platform Automatically

We do not intentionally collect special categories of data (health, biometric, religious, political, or similar data) about End Users. Because agents are configured by Workspace Owners, we ask Workspace Owners not to design agents that solicit special category data unless they have an independent, documented legal basis and appropriate safeguards for doing so.


Purpose Data used Legal basis
Create and administer Platform User accounts Account identifiers, authentication data Performance of a contract (Art. 6(1)(b))
Operate the AI agent runtime — receive, process, and respond to messages Conversation content, identifiers, message metadata Performance of a contract with the Workspace Owner (as processor) / contract or legitimate interest as controller where we are the business messaged
Route your message to an AI model to generate a response Conversation content Performance of a contract (Art. 6(1)(b))
Detect, prevent, and investigate fraud, abuse, and security incidents Session logs, API logs, error/diagnostic data Legitimate interests (Art. 6(1)(f)) — keeping the Service secure
Maintain and improve the Service (debugging, reliability) Error/diagnostic data, aggregated usage data Legitimate interests (Art. 6(1)(f))
Comply with legal obligations, respond to lawful requests Any of the above, as required Legal obligation (Art. 6(1)(c))
Send you service or transactional communications Email address Performance of a contract / legitimate interests
Where you have opted in to receive messages initiated by a business (e.g., WhatsApp template/marketing messages) Phone number, name Consent (Art. 6(1)(a)) — withdrawable at any time

We do not use End User conversation data to train AI models unless a Workspace Owner has separately and explicitly opted in to that use, and even then only after removing or with the End User's informed consent, as required by applicable law.

Automated decision-making. Your messages are processed by an AI system to generate a response, which is a form of automated processing. We do not use this processing to make decisions that produce legal effects or similarly significant effects concerning you without the possibility of human review. If a Workspace Owner configures an agent to take an automated action that does have such effects for you, you have the right to request human intervention, express your point of view, and contest that decision by contacting us or the Workspace Owner.


#4. The WhatsApp Business Platform and Meta

We use the WhatsApp Business Platform, operated by Meta Platforms, Inc. and its affiliates ("Meta"), to send and receive messages with End Users. By messaging an agent on WhatsApp, you should be aware that:


#5. Who we share data with (sub-processors)

We share personal data only as necessary to operate the Service, and always under contractual confidentiality and data-protection obligations. Our current sub-processors are:

Sub-processor Purpose Location (data processed)
Meta Platforms, Inc. WhatsApp Business Platform messaging United States / global (Meta infrastructure)
OpenRouter, Inc. (and the underlying AI model providers it routes requests to, e.g. Google, OpenAI, Anthropic, Meta, depending on the model a Workspace configures) Generating AI responses to messages United States and other countries, depending on the selected model provider
Amazon Web Services (AWS) Cloud file storage (Amazon S3) for message media and attachments; transactional email delivery (Amazon SES) United States, South America (see Section 7)
DigitalOcean, LLC Application hosting and managed database hosting United States (New York City datacenter)
Cloudflare, Inc. CDN, TLS termination, DDoS protection Global network
Sentry (Functional Software, Inc.) Error monitoring and diagnostics United States
Google LLC OAuth sign-in for Platform Users United States
GitHub, Inc. (Microsoft) OAuth sign-in for Platform Users United States

We do not sell personal data, and we do not share personal data with third parties for their own independent marketing purposes.

We may also disclose personal data: to comply with a legal obligation, court order, or lawful government request; to enforce our terms; to protect the rights, property, or safety of Vatio, our users, or the public; or in connection with a merger, acquisition, or sale of assets, subject to continued protection of your data under this policy or a substantially similar one.


#6. Data retention

We retain personal data only as long as necessary for the purposes described in this policy, then delete or anonymize it.

Data Retention
Platform User account data Until account deletion, plus 30 days
Conversation content (messages, media) For the duration of the Workspace Owner's active relationship with us; if the Workspace Owner's account is closed, retained for 30 days and then purged, unless the Workspace Owner requests earlier deletion
WhatsApp preview test data (unverified numbers and OTPs) Automatically deleted 24 hours after an abandoned/expired verification attempt
Session, API access, and security logs 90 days
Error-monitoring data (Sentry) Per Sentry's default retention, currently up to 90 days; as of this version we no longer send IP addresses, cookies, or request headers to Sentry by default
Backups Rolling 30-day backup window

We will delete or anonymize data sooner where an End User or Platform User validly exercises a deletion right under Section 8, unless we are required or permitted by law to retain it longer (e.g., for legal claims or regulatory obligations).


#7. International data transfers

We and our sub-processors are located in multiple countries, including the United States. If you are located in the European Economic Area, the United Kingdom, or Switzerland, your personal data may be transferred to and processed in countries that have not been recognized by the European Commission as providing an adequate level of data protection.

Where this occurs, we rely on appropriate safeguards recognized under GDPR, such as the European Commission's Standard Contractual Clauses, or on our sub-processors' own certified compliance mechanisms (e.g., Meta's and AWS's Standard Contractual Clauses with their customers). You can request a copy of the relevant safeguard by contacting us at the address in Section 13.

[ACTION ITEM]: Confirm Standard Contractual Clauses (or equivalent) are executed with every sub-processor in the table in Section 5 before relying on this section.


#8. Your rights

If GDPR or another applicable data-protection law grants you rights over your personal data, you have the right to:

To exercise any of these rights, contact us using Section 13. If your request concerns a conversation with a specific business's AI agent, we may need to verify your identity and may direct part of the request to the relevant Workspace Owner where they are the controller, per Section 1.

We will respond within the timeframe required by applicable law (generally one month under GDPR, extendable by two further months for complex requests).


#9. Security

We use technical and organizational measures designed to protect personal data against unauthorized access, alteration, disclosure, or destruction, including encryption of data in transit (TLS), access controls, and monitoring for security incidents. No method of transmission or storage is completely secure, and we cannot guarantee absolute security.

If we become aware of a personal data breach that poses a risk to your rights and freedoms, we will notify the competent supervisory authority and, where required, affected individuals, in accordance with applicable law.


#10. Children's privacy

The Service is not directed to, and we do not knowingly collect personal data from, children under 16 (or the minimum age required by your local law and by WhatsApp's own Terms of Service, if higher). Workspace Owners are responsible for ensuring their own use of the Service complies with applicable children's privacy laws (e.g., not deploying agents targeted at children without appropriate safeguards). If you believe a child has provided us with personal data, contact us and we will delete it.


#11. Cookies and similar technologies

Our website and embedded web chat widget use strictly necessary cookies or local storage to maintain your session and enable the chat to function. We do not currently use non-essential advertising or analytics cookies.


#12. Changes to this policy

We may update this policy from time to time. We will post the updated version at this URL with a new "Last updated" date, and where changes are material, we will provide additional notice (e.g., by email to Platform Users or a notice on the Service).


#13. Contact us

Wolf Technology SpA Antonio Bellet 193, Of. 1210, Providencia, Región Metropolitana, Chile Privacy inquiries: [email protected]

As of this version, Vatio's users and End Users are located across North, Central, and South America, with no operations or users in the EU, UK, or Switzerland — so an Art. 27 GDPR representative is not currently required.

Wolf Technology SpA has not appointed a Data Protection Officer, as none is currently required under applicable law given the scale and nature of our processing. Privacy inquiries, including any that would otherwise go to a DPO, should be directed to the contact above.