WenOXLegal
General

Privacy Policy

How WenOX processes account, usage, content, payment, and technical data.

1. Scope and controller

This notice covers personal data processed through WenOX websites, accounts, API services, and CLI connections. The intended controller following restoration is ATSIZ YAZILIM LTD, company no. 16324501, at 71-75 Shelton Street, Covent Garden, London, United Kingdom, WC2H 9JQ. For enterprise content, WenOX may be a processor under a separate data processing agreement while remaining controller for account administration and billing.

2. Data we process

  • Account data: name, email, optional profile information, protected credentials, linked Google/GitHub identifiers, verification, and agreement records, received from you or your selected identity provider.
  • Usage and transactions: model identifiers, request/session references, token counts, Credit usage, limits, wallet entries, orders, gifts, referrals, and payment/refund status.
  • Content: prompts, selected code/files, tool results, and outputs transmitted to fulfil AI requests, plus material you deliberately attach to support cases.
  • Technical and security data: IP address, browser/device information, cookies, sessions, error details, anti-abuse signals, and security events.
  • Payment data: transaction reference, amount/currency, billing details, and status received from the provider chosen at checkout. Full card credentials are handled by the payment provider.

3. Purposes and lawful bases

  • Contract: create/authenticate accounts, deliver requests and purchases, calculate usage, manage limits, and provide support.
  • Legitimate interests, balanced against your rights: prevent fraud/abuse, protect accounts and infrastructure, investigate faults, and improve reliability.
  • Legal obligation: accounting/tax records, valid disclosures, and regulatory compliance.
  • Consent: optional marketing or non-essential tracking where required. You may withdraw consent without affecting earlier lawful processing. Reading this policy is not blanket consent.

Necessary account and transaction information is required for paid access; refusing it may prevent service. Optional profile fields are voluntary. Automated usage/security controls may restrict access; you may ask support to review a disputed restriction, including any legally protected automated-decision rights.

4. AI content and CLI

Selected content is sent to the model infrastructure needed to answer your request. Do not submit unnecessary personal data, secrets, or content you cannot lawfully share. CLI features may read project files, generate tool results, and run authorised actions depending on the feature and permissions you enable. Local session files are distinct from server usage records.

Request metadata supports metering and limits. This notice does not guarantee zero retention by all upstream providers or identical data practices across every model. Provider retention, processing, and any training permissions depend on the applicable service and written enterprise commitments. A new processing purpose needs an appropriate lawful basis and updated notice; this policy does not grant blanket permission to train on customer content.

5. Sharing and transfers

Necessary recipients may include hosting/infrastructure and database providers, AI model providers, your selected authentication provider, email/support tools, security services, and the payment provider shown at checkout. Google/GitHub provide the account data you authorise. Payment providers may be independent controllers for their own duties. Data may be disclosed to professional advisers, authorities when lawfully required, or a business successor with appropriate safeguards. We do not sell personal data.

Providers may process outside your country. Where required by UK law, transfers need a recognised adequacy decision or appropriate safeguards, such as the UK International Data Transfer Agreement or UK Addendum, with necessary assessments. Applicable EU and other local requirements must also be met. Ask us for information about the safeguards relevant to your data.

6. Retention and security

Account data is kept while needed to supply the account. Usage/security records are kept as needed for billing, fraud prevention, administration, and disputes; financial records follow statutory periods. After closure, data needed for legal duties or claims may remain; other data is deleted or anonymised under the operational retention schedule. Backups can remain until their normal rotation. The exact retention schedule and upstream content settings must be verified before this review draft is published.

We use proportionate technical and organisational safeguards, including access controls and credential protection. Absolute internet security cannot be guaranteed. Protect your credentials and report suspected incidents; reportable breaches are handled and notified as required by law.

7. Rights and complaints

Subject to law and its exceptions, you may request access, correction, deletion, restriction, portability, object to processing, withdraw consent, and request review of qualifying automated decisions. Use dashboard support or the company contact page, mark it as a privacy request, and supply proportionate identity information rather than passwords/API keys. We respond within the legal deadline and explain any lawful restriction. Controller identity and a monitored privacy contact must be verified before publication.

You may complain to the UK Information Commissioner's Office at ico.org.uk or another competent supervisory authority. Local rights, including applicable Turkish data-protection rights, apply where their legal conditions are met. Services are intended for adults; contact us if a child may have supplied data. Material policy changes are communicated as required.

Have a legal question?

Contact us with your account or order reference.

Contact