Trust & Privacy
Privacy Policy
How Wizel collects, uses, shares, and protects information — both the account data of the brands and agencies who use the platform, and the data we process on their behalf from connected platforms like Klaviyo and Shopify.
- Version
- 3.0
- Effective
- 4 August 2026
- Last updated
- 4 August 2026
- Next review
- 4 August 2027
Who we are
Wizel (“Wizel”, “we”, “us”) is Doan Than trading as Wizel, based in Australia. We operate an AI email marketing platform for Shopify DTC brands and the Klaviyo agencies that serve them. This Privacy Policy explains what we do with personal information and applies to our website, application, and related services (the “Services”).
We act in two distinct roles. For your own account information we are a data controller. For the data you bring in from connected platforms — your subscribers, campaigns, and analytics — we act as a data processor on your behalf, handling that data only to provide the Services under our agreement with you. Where you are an agency, the same applies between you and your own clients.
That processor relationship is governed by our Data Processing Addendum, which takes effect automatically when you accept our Terms and sets out our obligations, our named sub-processors, the security measures we apply, and how we support your obligations to data subjects and regulators. Where this policy and that Addendum differ on data we process for you, the Addendum governs.
By using the Services you agree to the practices described here. If you do not agree, please do not use the Services.
Scope of this policy
This policy applies to:
- Visitors to our marketing website.
- Account holders and authorised users of the Wizel application.
- Data we process from platforms you connect (Klaviyo, Shopify) to deliver the Services.
It does not cover third-party services that have their own privacy policies — including Klaviyo, Shopify, and any site we link to. Your use of those platforms is governed by their terms and policies.
Information we collect
We collect only what we need to run the Services. The categories below summarise what we hold and where it comes from.
| Category | Examples | Source |
|---|---|---|
| Account & contact data | Name, email, password, company name, role, billing details | You, directly |
| Connected-platform data | Campaigns, flows, segments, templates, performance metrics, and subscriber/customer profiles from Klaviyo and Shopify | Your connected accounts, with your authorisation |
| Brand & content data | Brand voice, logos, product catalogue, generated copy and images | You and our generation pipeline |
| Usage & device data | IP address, browser and device type, pages viewed, log and error data | Collected automatically |
| Cookies & identifiers | Session cookies, preferences, and analytics identifiers | Collected automatically |
We do not intentionally collect special-category data (such as health, biometric, or government-ID data). Please do not upload it to the Services.
How we use information
We use personal information for the purposes below. Where the GDPR or UK GDPR applies, the corresponding legal basis is shown.
| Purpose | Legal basis |
|---|---|
| Provide, maintain, and secure the Services | Performance of a contract |
| Process payments and send transactional notices | Contract; legal obligation |
| Draft campaigns and generate AI insights and imagery | Contract; legitimate interests |
| Analyse performance across connected accounts | Legitimate interests |
| Detect, prevent, and investigate fraud and abuse | Legitimate interests; legal obligation |
| Send product and marketing updates | Consent; legitimate interests |
| Comply with law and respond to lawful requests | Legal obligation |
We do not sell personal information, and we do not use the customer data you sync from connected platforms to train AI models or for our own advertising.
AI and automated processing
The Services use AI models to draft campaign copy, generate imagery, and surface analytics insights. To do this we send relevant brand, product, and campaign context to our AI providers strictly to produce the output you request.
- We send only the brand, product, and campaign context needed to generate the output you asked for. We do not route subscriber contact records to AI providers as part of normal content generation.
- We select AI providers and configure our accounts with the intent that your content is not used to train their models, and we rely on their published terms to that effect. Those terms are the provider's, not ours — the current provider list is in Annex III of our Data Processing Addendum so you can verify them yourself.
- Outputs are drafts. A person reviews and approves what is sent — we do not make decisions producing legal or similarly significant effects about individuals without human involvement.
- We do not use your content, brand assets, or synced subscriber data to train our own models. We do use aggregated, de-identified operational data — feature usage, error rates, latency — to improve the Services.
International data transfers
Wizel is based in Australia and uses infrastructure and providers that may process data in other countries. Where we transfer personal data across borders — including out of the EEA, UK, or your home country — we put appropriate safeguards in place, such as the European Commission’s Standard Contractual Clauses (and the UK Addendum) or transfers to jurisdictions recognised as providing adequate protection.
You can request more detail about the safeguards that apply to a specific transfer using the contact details below.
How we protect your data
We apply organisational and technical controls appropriate to the risk, including encryption in transit and at rest, least-privilege access, MFA on administrative systems, vulnerability management, and logging and monitoring.
Full detail of our controls — access management, encryption, vulnerability remediation timeframes, incident response, and breach notification — is published in our Information Security Program. No method of transmission or storage is perfectly secure, but we work continuously to protect your data.
Breach notification
If a breach affects data we process on your behalf, we notify you without undue delay and in any case within 48 hours of becoming aware, so you can meet your own 72-hour regulator deadline. Where we are the controller, we assess the breach promptly and notify the relevant regulators and individuals where required — under the Australian Notifiable Data Breaches scheme and, where applicable, within 72 hours under the GDPR. Full breach commitments are in section 9 of our Data Processing Addendum.
Your privacy rights
Depending on where you live — including under the GDPR/UK GDPR, the Australian Privacy Act 1988, and US state laws such as the California CCPA/CPRA — you may have the following rights over your personal data.
| Right | What it means |
|---|---|
| Access | Request a copy of the personal data we hold about you |
| Correction | Update or correct inaccurate or incomplete information |
| Deletion | Request erasure of your personal data |
| Portability | Receive your data in a structured, machine-readable format |
| Objection & restriction | Object to or restrict certain processing |
| Withdraw consent | Withdraw consent at any time, without affecting prior processing |
| Opt out of sale/sharing | We do not sell personal data; opt out of targeted sharing |
| Non-discrimination | Exercise your rights without penalty or degraded service |
To exercise any of these rights, email privacy@wizel.ai. We will verify your request and respond within the timeframe required by applicable law (generally within 30 days). You may use an authorised agent where the law allows. If we process data on behalf of one of our customers, we will refer your request to that customer as the controller.
Data retention
We retain personal information only as long as necessary to:
- Provide the Services to you.
- Comply with our legal, tax, and accounting obligations.
- Resolve disputes and enforce our agreements.
- Maintain backups and business continuity.
When you close your account we keep your content available for export for 30 days. After that — or sooner if you ask us in writing — we delete or anonymise your personal data from our production systems within a further 30 days. Copies persist in encrypted backups until they age out on our rolling backup cycle, which does not exceed 90 days, and are not restored to production except as part of a full disaster recovery.
We may retain data for longer where the law requires it, and we may keep aggregated, de-identified data that cannot be linked back to you or any individual. Retention of the data we process on your behalf is governed by our Data Processing Addendum.
Children's privacy
The Services are intended for businesses and are not directed to children under 18. We do not knowingly collect personal information from children. If you believe a child has provided us personal information, contact us and we will delete it.
Changes to this policy
We may update this policy from time to time. When we make material changes, we will update the “Last updated” date above and, where appropriate, notify you by email or within the Services. Your continued use of the Services after an update means you accept the revised policy.
Contact and complaints
Questions about this policy or how we handle your data? We are happy to help — and you have the right to complain to a regulator if you are not satisfied with our response.
Privacy contact
For privacy questions, data requests, a signed copy of our Data Processing Addendum, or to be notified of sub-processor changes, contact our privacy team at privacy@wizel.ai. For general enquiries, email info@wizel.ai.
If you are in the EEA or UK you may also lodge a complaint with your local data protection authority. In Australia, you may contact the Office of the Australian Information Commissioner (OAIC).
See also our Terms of Service, Data Processing Addendum, and Information Security Program.