Trust & Privacy

Privacy Policy

How Wizel collects, uses, shares, and protects information — both the account data of the brands and agencies who use the platform, and the data we process on their behalf from connected platforms like Klaviyo and Shopify.

Version
2.0
Effective
15 June 2026
Last updated
15 June 2026
Next review
15 June 2027

01

Who we are

Wizel (“Wizel”, “we”, “us”) operates an AI email marketing platform for Shopify DTC brands and the Klaviyo agencies that serve them. This Privacy Policy explains what we do with personal information and applies to our website, application, and related services (the “Services”).

We act in two distinct roles. For your own account information we are a data controller. For the data you bring in from connected platforms — your subscribers, campaigns, and analytics — we act as a data processor on your behalf, handling that data only to provide the Services under our agreement with you. Where you are an agency, the same applies between you and your own clients.

By using the Services you agree to the practices described here. If you do not agree, please do not use the Services.

02

Scope of this policy

This policy applies to:

  • Visitors to our marketing website.
  • Account holders and authorised users of the Wizel application.
  • Data we process from platforms you connect (Klaviyo, Shopify) to deliver the Services.

It does not cover third-party services that have their own privacy policies — including Klaviyo, Shopify, and any site we link to. Your use of those platforms is governed by their terms and policies.

03

Information we collect

We collect only what we need to run the Services. The categories below summarise what we hold and where it comes from.

CategoryExamplesSource
Account & contact dataName, email, password, company name, role, billing detailsYou, directly
Connected-platform dataCampaigns, flows, segments, templates, performance metrics, and subscriber/customer profiles from Klaviyo and ShopifyYour connected accounts, with your authorisation
Brand & content dataBrand voice, logos, product catalogue, generated copy and imagesYou and our generation pipeline
Usage & device dataIP address, browser and device type, pages viewed, log and error dataCollected automatically
Cookies & identifiersSession cookies, preferences, and analytics identifiersCollected automatically

We do not intentionally collect special-category data (such as health, biometric, or government-ID data). Please do not upload it to the Services.

04

How we use information

We use personal information for the purposes below. Where the GDPR or UK GDPR applies, the corresponding legal basis is shown.

PurposeLegal basis
Provide, maintain, and secure the ServicesPerformance of a contract
Process payments and send transactional noticesContract; legal obligation
Draft campaigns and generate AI insights and imageryContract; legitimate interests
Analyse performance across connected accountsLegitimate interests
Detect, prevent, and investigate fraud and abuseLegitimate interests; legal obligation
Send product and marketing updatesConsent; legitimate interests
Comply with law and respond to lawful requestsLegal obligation

We do not sell personal information, and we do not use the customer data you sync from connected platforms to train AI models or for our own advertising.

05

AI and automated processing

The Services use AI models to draft campaign copy, generate imagery, and surface analytics insights. To do this we send relevant brand, product, and campaign context to our AI providers strictly to produce the output you request.

  • We share only the data needed to generate the requested output, and we rely on provider terms that prohibit using your content to train their models.
  • Outputs are drafts. A person reviews and approves what is sent — we do not make decisions producing legal or similarly significant effects about individuals without human involvement.
  • We do not use your synced subscriber or customer data to train our own models.
06

Cookies and tracking

We use cookies and similar technologies to:

  • Keep you signed in and remember your preferences.
  • Understand how the Services are used so we can improve them.
  • Protect against fraud and abuse.

You can control cookies through your browser settings; disabling some cookies may affect functionality. Where required, we request consent for non-essential cookies. We honour Global Privacy Control (GPC) signals as a valid opt-out of targeted sharing where applicable.

07

How we share information

We do not sell your personal information. We share it only in these circumstances:

  • Sub-processors: vetted service providers who help us operate the Services under contract and on our instructions (see the table below).
  • Connected platforms: data flows to and from Klaviyo and Shopify as you direct and authorise.
  • Legal and safety: where required by law, or to protect the rights, property, or safety of Wizel, our customers, or the public.
  • Business transfers: in connection with a merger, acquisition, or sale of assets, subject to this policy.
  • With your consent: when you explicitly ask us to.

Sub-processors

We engage the following categories of sub-processor. A current list of named sub-processors is available to customers on request.

CategoryPurpose
Cloud hosting & computeApplication hosting and infrastructure
Database & analytics storesOperational data and campaign analytics
Content delivery / WAFTraffic delivery, TLS, and edge security
AI model providersContent and image generation
Object / image storageGenerated and uploaded assets
Payment processorBilling and subscription management
Connected platforms (Klaviyo, Shopify)Data sync you authorise and control
08

International data transfers

Wizel is based in Australia and uses infrastructure and providers that may process data in other countries. Where we transfer personal data across borders — including out of the EEA, UK, or your home country — we put appropriate safeguards in place, such as the European Commission’s Standard Contractual Clauses (and the UK Addendum) or transfers to jurisdictions recognised as providing adequate protection.

You can request more detail about the safeguards that apply to a specific transfer using the contact details below.

09

How we protect your data

We apply organisational and technical controls appropriate to the risk, including encryption in transit and at rest, least-privilege access, MFA on administrative systems, vulnerability management, and logging and monitoring.

Full detail of our controls — access management, encryption, vulnerability remediation timeframes, incident response, and breach notification — is published in our Information Security Program. No method of transmission or storage is perfectly secure, but we work continuously to protect your data.

Breach notification

If a breach is likely to result in serious harm, we assess it promptly and notify affected customers and, where required, the relevant regulators and individuals — under the Australian Notifiable Data Breaches scheme and, where applicable, within 72 hours under the GDPR.

10

Your privacy rights

Depending on where you live — including under the GDPR/UK GDPR, the Australian Privacy Act 1988, and US state laws such as the California CCPA/CPRA — you may have the following rights over your personal data.

RightWhat it means
AccessRequest a copy of the personal data we hold about you
CorrectionUpdate or correct inaccurate or incomplete information
DeletionRequest erasure of your personal data
PortabilityReceive your data in a structured, machine-readable format
Objection & restrictionObject to or restrict certain processing
Withdraw consentWithdraw consent at any time, without affecting prior processing
Opt out of sale/sharingWe do not sell personal data; opt out of targeted sharing
Non-discriminationExercise your rights without penalty or degraded service

To exercise any of these rights, email privacy@wizel.ai. We will verify your request and respond within the timeframe required by applicable law (generally within 30 days). You may use an authorised agent where the law allows. If we process data on behalf of one of our customers, we will refer your request to that customer as the controller.

11

Data retention

We retain personal information only as long as necessary to:

  • Provide the Services to you.
  • Comply with our legal, tax, and accounting obligations.
  • Resolve disputes and enforce our agreements.
  • Maintain backups and business continuity.

When you close your account, we delete or anonymise your personal data within 30 days, unless we are required to retain it by law. Synced customer data is deleted or returned at the end of the engagement, subject to legal retention requirements. Backups are purged on a rolling schedule.

12

Children's privacy

The Services are intended for businesses and are not directed to children under 18. We do not knowingly collect personal information from children. If you believe a child has provided us personal information, contact us and we will delete it.

13

Changes to this policy

We may update this policy from time to time. When we make material changes, we will update the “Last updated” date above and, where appropriate, notify you by email or within the Services. Your continued use of the Services after an update means you accept the revised policy.

14

Contact and complaints

Questions about this policy or how we handle your data? We are happy to help — and you have the right to complain to a regulator if you are not satisfied with our response.


Privacy contact

For privacy questions, data requests, or to ask for our current sub-processor list, contact our privacy team at privacy@wizel.ai. For general enquiries, email info@wizel.ai.

If you are in the EEA or UK you may also lodge a complaint with your local data protection authority. In Australia, you may contact the Office of the Australian Information Commissioner (OAIC).

See also our Information Security Program and Terms of Service.