Last updated: 2026-09-06
1. Roles and Contact
Wisprs is the controller for personal data used to run your account and the service. When a business customer uses Wisprs to process its team’s content, that customer may be the controller and Wisprs may act as its processor under a separate agreement. Our privacy contact is tosh@getwisprs.com. We have not appointed a data-protection officer.
2. Processing Purposes and Legal Bases
We process account and authentication data, content, usage and billing data, support messages, integration records, technical logs, security signals, and analytics data to perform the service contract, protect the service, provide support, measure reliability, improve the product, process payments, send service communications, and comply with law. For GDPR and UK GDPR users, we rely on contract, legitimate interests, consent where required, and legal obligation as described in the Privacy Policy.
3. Categories of Data and Recipients
Categories include identifiers and contact details; account and session data; commercial and subscription information; IP, device, browser, and usage data; audio, video, transcripts, translations, summaries, generated speech, and other user content; support and integration data; and approximate location derived from an IP address. Recipients include authentication, billing, email, speech, AI, hosting, storage, queue, cache, security, monitoring, support, and analytics providers. The current provider categories and purposes are listed in the Privacy Policy.
4. Retention and Deletion
We keep each category only as long as needed for the service, security, support, accounting, legal, and dispute purposes described in the Privacy Policy. Active content remains until the user deletes it or starts an account deletion request. Active-system deletion is followed by normal backup expiry; legal, billing, security, and support records may remain when required. A deletion request is verified and reviewed before permanent action so we can handle subscriptions, legal holds, and third-party limits safely.
5. Data Subject Rights
EEA, UK, and Swiss users may request access, rectification, erasure, restriction, portability, or objection, and may withdraw consent where consent is the basis. You may complain to a supervisory authority. Email tosh@getwisprs.com from your account email, or use the export and deletion controls in Account Settings. We may verify identity and normally respond within one month, subject to lawful extensions. US state rights are described in the Privacy Policy.
6. International Transfers
Wisprs and its providers may process data in the United States and other countries. For transfers from the EEA, UK, or Switzerland, we use an adequacy decision, standard contractual clauses, or another valid safeguard when required. Ask tosh@getwisprs.com for information about the safeguard relevant to a transfer.
7. Security and Subprocessors
We use access controls, encryption in transit, encryption at rest where supported, scoped credentials, rate limiting, logging, backups, and monitoring appropriate to the risk. A current provider list can change as the service changes; the Privacy Policy describes provider categories and we will update it when a change materially affects processing.
8. Enterprise Processing
Enterprise customers may request a data-processing addendum, security schedule, subprocessor information, transfer terms, or other compliance documentation before enabling regulated workflows. Do not upload regulated or highly sensitive data until the required agreement is in place.