Legal
Privacy Policy
Widgo, Inc.
Effective date: 25 August 2026 · Last updated: 25 August 2026
This policy explains what personal data Widgo, Inc. ("Widgo", "we", "us") collects, why, and what you can do about it. It covers widgo.ai, app.widgo.ai, the Widgo widget served from cdn.widgo.ai, and our support and marketing channels.
Contact for any privacy matter: support@widgo.ai
1. The two roles, and why the difference matters
Widgo wears two hats, and your rights depend on which one applies.
We are the controller for our own customers and our own website. That means the account you open with us, the emails we send you, the invoices we raise, and the visitors to widgo.ai. We decide why and how that data is processed, and this policy governs it.
We are the processor for the data collected through the widget on a customer's website. When you chat with a Widgo widget on someone else's site, that company is the controller. It decided to install Widgo, it configured what the Agent does, and it decides how long to keep the conversation. We process that data on its instructions under our Data Processing Agreement.
If you are a website visitor and you want your data deleted, corrected or exported, contact the company whose website you were on. They control it. If you contact us instead, we will pass your request to that customer and support them in answering it, but we cannot act on it ourselves without their instruction.
2. Data we collect as controller (about our customers)
Account data. Name, work email address, password or federated identity from Google or Microsoft sign-in, company name, role, profile photo if you add one, workspace membership and role, and two-factor settings. Sign-in, verification and session management are handled for us by Stack Auth.
Onboarding data. The answers you give during setup: your website, your company details, what you sell, who you sell to, and your goals for the Agent.
Billing data. Plan, subscription status, invoice history, billing address and tax identifiers. We never see or store your full payment card number. Card details go directly to Stripe, which is a PCI DSS Level 1 service provider.
Product usage data. Pages and features you use in the dashboard, actions taken, settings changed, session and device information, IP address, browser and operating system, and error and performance data. Collected through PostHog and Datadog.
Support data. Messages you send us through the in-app widget, help centre activity, and anything you attach. Handled through Intercom.
Marketing and communications data. Email delivery, opens, clicks, unsubscribes, and your notification preferences. Handled through Customer.io.
Website data. Visits to widgo.ai, referrer, campaign parameters and aggregate analytics, through Google Analytics and Google Tag Manager, subject to the Cookie Policy and any consent choice you make.
3. Data we process as processor (about our customers' website visitors)
When one of our customers installs the widget, the Service processes, on their behalf:
Conversation content. Messages the visitor types or speaks, the Agent's replies, timestamps, and generated summaries, intents and outcomes.
Contact details the visitor chooses to give, such as name, email address, phone number, company name and meeting preferences, entered in conversation or in a booking flow.
Technical and session data. IP address, approximate location derived from it (country, region, city), browser and device information, referring URL, pages viewed on the customer's site, and time on site.
Company-level identification. We match the visitor's IP address against licensed IP intelligence data to identify the organisation the visit is likely to come from, and attach firmographic details such as industry, size and domain. This is deliberately limited:
Identification is at company level only. We do not attempt to identify an individual person from traffic.
A company is attached only when our matching layer is confident. Otherwise the visit is reported as unknown.
We do not track visitors across unrelated websites and we do not build cross-site visitor profiles.
A visitor who volunteers their email address in conversation confirms their own identity by doing so. That is the visitor's choice, not an inference we make.
Lead scores. Heuristic scores derived from the signals above. They are estimates and are described in section 9.
Session replay, where the customer has enabled it on a paid plan. This records page interactions on the customer's site. The customer decides whether to enable it, on which pages, and with what masking, and the customer is responsible for the notices and consents that recording requires.
Voice conversations, where the customer has enabled the voice agent, including audio and its transcript.
The customer chooses which of these are on. We do not decide to collect this data; they do.
4. Why we process data, and on what legal basis
Run your account and deliver the Service. Why: To perform our contract with you Legal basis (GDPR / UK GDPR): Contract
Bill you and collect payment. Why: To perform our contract, and to meet tax and accounting duties Legal basis (GDPR / UK GDPR): Contract, legal obligation
Send transactional and service emails. Why: To perform our contract Legal basis (GDPR / UK GDPR): Contract
Send product and marketing emails. Why: To promote the Service to business contacts Legal basis (GDPR / UK GDPR): Legitimate interests, or consent where required. Opt out any time
Secure the Service, prevent abuse and fraud, apply rate limits and bot filtering. Why: To keep the Service safe and available Legal basis (GDPR / UK GDPR): Legitimate interests
Measure and improve the product. Why: To understand what works and fix what does not Legal basis (GDPR / UK GDPR): Legitimate interests, or consent for non-essential cookies
Respond to support requests. Why: To help you Legal basis (GDPR / UK GDPR): Contract, legitimate interests
Comply with law and respond to lawful requests. Why: Because we must Legal basis (GDPR / UK GDPR): Legal obligation
Process visitor data through the widget. Why: On our customer's documented instructions Legal basis (GDPR / UK GDPR): The customer's legal basis, as controller
Where we rely on legitimate interests, we have balanced them against your rights, and you can object using the contact address above.
5. What we do not do
We do not sell personal data, and we do not share it for cross-context behavioural advertising, as those terms are defined under the CCPA and CPRA.
We do not use customer conversation content to train foundation models, and we require the same of the AI providers we use in delivering the Service.
We do not identify individual people from website traffic.
We do not track visitors across unrelated websites.
We do not knowingly collect data from children. The Service is for business use and is not directed at anyone under 18.
6. Cookies and similar technologies
The widget uses browser storage to keep a conversation continuous for a visitor and to enforce plan limits, and we use cookies on widgo.ai for analytics. Full detail, including names, purposes and durations, is in the Cookie Policy.
7. Who we share data with
Subprocessors. Vetted vendors that process data to help us run the Service. Each one is bound by a written contract with confidentiality and security terms, and each is listed with its purpose and location on our Subprocessors page.
Your integrations. When you connect a CRM, calendar or chat tool, we send data to it on your instruction. Once it arrives there, that vendor's privacy policy governs it, not ours.
Professional advisers, such as auditors, accountants and lawyers, under confidentiality.
Legal and safety. We may disclose data if required by law, court order or valid legal process, or where we reasonably believe disclosure is necessary to protect our rights, safety, or those of our users or the public. Where we are legally permitted to notify you of a request for your data, we will.
Corporate transactions. In a merger, acquisition, financing or sale of assets, data may transfer to the successor, subject to this policy or a policy no less protective. We will notify you.
We do not sell, rent or trade personal data.
8. International transfers
Widgo is a US company. We and our subprocessors process data in the United States, the European Union and other locations listed on the Subprocessors page. Our personnel and contractors are located in the United States, Canada and Türkiye.
For transfers of personal data out of the European Economic Area, the United Kingdom or Switzerland, we rely on the European Commission's Standard Contractual Clauses, together with the UK International Data Transfer Addendum where the UK GDPR applies, and we carry out transfer risk assessments where required. A copy of the clauses we use is available on request at support@widgo.ai.
9. Automated processing
The Agent generates replies automatically, and the Service assigns company matches and lead scores automatically. These are decision support outputs. They are probabilistic, they can be wrong, and they are not intended to produce legal or similarly significant effects on any individual. Neither we nor, under our Terms, our customers may use them as the sole basis for a decision producing such an effect. Where a person wants a human to look at an outcome, the controller of that data, which for widget data is the website operator, can and should provide one.
10. How long we keep data
Account and workspace data. Retention: While the account is open
Conversations, leads and bookings. Retention: While the workspace is open, or for the period the customer configures, whichever is shorter
Data over a plan's allowance. Retention: Held, not deleted. Shown blurred until the plan is upgraded
Billing records and invoices. Retention: Seven years, to meet tax and accounting obligations
Support conversations. Retention: Three years from last contact
Product analytics and logs. Retention: Up to 24 months, then aggregated or deleted
Security and audit logs. Retention: Up to 24 months
Backups. Retention: Deleted on a rolling cycle, no later than 90 days after deletion from live systems
On account deletion. When you delete your workspace, or within a reasonable period after termination, we delete or irreversibly anonymise Customer Data within 30 days from live systems, and remove it from backups on the cycle above. We keep only what we must for legal, tax, security or dispute purposes.
Dormant free accounts. We may deactivate a free workspace that has been inactive for six consecutive months and contains no saved conversation or lead data. A workspace holding conversation or lead data is not deleted for inactivity.
11. Security
We protect data with measures appropriate to the risk, including:
Encryption in transit using TLS on every connection, and encryption at rest for stored data.
Role-based access inside the product, with Owner, Admin, Member and Billing roles, and tenant isolation enforced at the database layer.
Two-factor authentication, federated sign-in with Google and Microsoft, and active session management.
Least-privilege internal access, granted on a need-to-know basis and reviewed periodically.
Edge protection including a web application firewall, DDoS mitigation, bot filtering and rate limiting.
Centralised logging and monitoring, with alerting on anomalies.
Written vendor review before a subprocessor is engaged.
No system is perfectly secure. If we become aware of a personal data breach affecting your data, we will notify you without undue delay and, where we act as processor, within the timeframe set out in the Data Processing Agreement, along with the information you need to meet your own notification duties.
Security documentation is available to customers on request at support@widgo.ai, and our current compliance status is published on our trust centre.
12. Your rights
If you are in the EEA, the UK or Switzerland, you have the right to access your data, correct it, delete it, restrict or object to processing, receive it in a portable format, withdraw consent at any time without affecting prior processing, and lodge a complaint with your supervisory authority. The Irish Data Protection Commission, the UK ICO and the Swiss FDPIC are examples; you may complain to the authority where you live or work.
If you are in California, you have the right to know what personal information we collect, use and disclose, to request deletion, to request correction, to opt out of sale or sharing (we do neither), to limit the use of sensitive personal information (we do not collect it), and not to be discriminated against for exercising these rights. You may use an authorised agent.
If you are in Canada, you have the right to access and correct your personal information and to complain to the Office of the Privacy Commissioner.
Other jurisdictions grant similar rights, and we honour them where they apply.
How to exercise them. Email support@widgo.ai. We will verify your identity and respond within the time the applicable law allows, normally within 30 days. There is no charge unless a request is manifestly unfounded or excessive.
Marketing opt out. Every marketing email has an unsubscribe link. Product notification settings live in your Widgo dashboard. You cannot opt out of transactional messages such as billing notices and security alerts while your account is open.
Again, for website visitors: if your data was collected by a Widgo widget on a company's website, that company holds your rights request. Contact them. We will help them respond.
13. Changes to this policy
We may update this policy. If a change is material we will notify customers by email or in-app at least 30 days before it takes effect, unless the change is required by law or addresses a security risk. The current version and its effective date are always at the top of this page.
14. Contact
Widgo, Inc.
Delaware, USA
support@widgo.ai
For data protection matters, address your message to the Privacy Team.
