Legal

Privacy Policy

We collect what we need to run Wiiseto and nothing to sell. Your workspace lives in Switzerland, and everything else stays in the EU/EEA, except for the AI providers and the few US services listed in section 9. Analytics only run if you say yes. Where we fall short of an ideal, this policy says so.

Version 2026-10-01 · Effective 1 October 2026

https://wiiseto.com/legal/privacy

1. Who we are

1. Who we are

Wiiseto is operated by Wiiseto, LLC, a limited liability company registered in the State of Delaware, United States. The team works from Switzerland. The registered address and file number are available on request at [email protected].

Our role depends on the data:

  • Controller for your account, billing, security and analytics data, and for the marketing website. We decide why and how that data is used.
  • Processor for the content your company puts in its workspace (projects, tasks, employees, contacts, files, messages). Your company decides what goes in; we process it on its behalf, under the Data Processing Agreement.

Contact for anything in this policy: [email protected]. We answer within 30 days.

Swiss and EU representatives: not yet appointed. Because Wiiseto, LLC is a US company, Swiss law (Art. 14 revFADP) and EU law (Art. 27 GDPR) require us to name a representative in Switzerland and in the EU. We have not appointed them yet. Until we do, write to [email protected].

2. Which law applies

We apply the Swiss Federal Act on Data Protection (revFADP) and the EU General Data Protection Regulation (GDPR). Where they differ, you get the stronger protection. The rights in section 10 are available to everyone, wherever you live.

Wiiseto, LLC is a US company, so US authorities may in some cases require us to hand over data we hold, even data stored in Switzerland or the EU. Section 11 explains how we handle such requests.

3. What we collect

3.1 Your account

  • Name, email address, and optionally a phone number and profile picture. If you sign up with Google or Microsoft, we store the link to that account and the picture address it gives us.
  • Your password, stored only as a bcrypt hash. We never see it.
  • Two-factor secrets and backup codes, encrypted in our database.
  • Your preferences (language, theme, notifications), your answers during onboarding, your analytics and AI-prompt choices with the date you made them, the date you used a free trial, your AI credit balance, and your presence status.

3.2 Security and sign-in

  • For each session: IP address, browser, operating system and device type, and, when location lookup is on, an approximate location (country, region, city) computed on our own servers from a local database. Nothing is sent to an outside service for this.
  • A risk score for each sign-in, built from your earlier sessions (the last 180 days). A high score never blocks you on its own; it asks for an extra email code.
  • Trusted devices, failed and successful sign-in attempts (deleted after 24 hours), and a record of security events on your company (for example an ownership transfer).

3.3 Your company's workspace

Everything your company puts in Wiiseto: projects, tasks and comments, Kanban boards, planning and timelines, calendar events (including events imported read-only from Google or Outlook if you connect them), contacts and their details, employee records (name, contact details, birthday, start date, contract type, location, notes, photo, absences and availability), teams, fleet vehicles and their assignments, budgets, documents and files, text read from documents (OCR), audio notes, chat messages with their edit history, announcements, daily reports, and Wiibot conversations.

  • Photos you take or upload through Wiiseto have their location data (EXIF, including GPS) removed. Other files are stored exactly as uploaded.
  • Absences can be marked as sick leave. That can reveal health information. Please do not write medical details in absence notes.
  • Chat edit history. When a message is edited, we keep the earlier text. It is not shown anywhere in the app today; it is deleted 60 days after the message is deleted.

Wiiseto is not built for sensitive data (health, religion, political opinions, criminal records, biometrics). Please do not store it.

3.4 Billing

Your company's legal name, billing email, address and VAT or tax number, and the brand and last four digits of the card. The card itself goes straight to Stripe; we never see it.

3.5 Logs

  • Activity on projects and tasks, document access and changes, and a log of the emails we send (recipient, subject, status).
  • Notification emails (not sign-in or security emails) contain a small image that tells us when an email was opened. We keep open times for 90 days to diagnose delivery. Your company's admins do not see whether you opened an email.
  • Our web servers keep technical access logs (IP address, time, page requested) for 30 days.

3.6 Sharing and devices

  • Browser notifications: if you allow them, we store the address your browser gives us to deliver them.
  • Share links and upload links: when someone uploads a file through an upload link without an account, we store their IP address with the upload.
  • Link previews: when a share link is pasted in a chat app, the preview shows the task title, or for a day plan the employee's name and date, unless the link is password-protected.
  • Links you paste in Wiiseto: to show a preview, our server fetches the page. The website sees our server's address, not yours.

3.7 Legal acceptance

When you accept the Terms and this Policy, we record which version, when, how (signup, invitation, social sign-up or a later update), your IP address and browser. We keep this as proof, also after your account is closed. The IP address and browser are removed after 24 months.

3.8 What we never do

No advertising or marketing cookies. No selling or renting of your data. No data brokers or enrichment. No use of your content to train AI models, by us or by our AI providers (section 6). No analytics unless you say yes.

5. Product analytics

We use PostHog, on its EU cloud in Frankfurt, to understand which features are used and where the app breaks.

In the app:

  • Nothing is loaded until you say yes, in the first-run question or in Account > Legal & privacy. If your browser sends "Do Not Track", we treat it as no. If you are signed in and never answered, we treat it as no.
  • What is sent when you say yes: a random id for you and your company id, the page pattern (for example /projects/$projectId, never the real id), clicks with all text masked, named events (for example "task created"), your browser, and your IP address (used by PostHog for an approximate country). No names, no email, nothing you type.
  • Session recording is off.
  • Events go through an address on our own domain (r.wiiseto.com), so content blockers do not break the app.
  • Share AI prompts is a second switch, off by default, available only when analytics is on. It lets us see the text of your Wiibot prompts in PostHog to improve answers. It does not control whether AI features send data to AI providers; that is section 6.

On the website (wiiseto.com): see section 12.

PostHog is a US-owned company. We keep analytics events for as long as the PostHog project exists. Server error reports can be sent to PostHog without your analytics consent, but only without anything that identifies you.

6. AI features

Wiiseto includes AI features: the Wiibot assistant, summaries, writing help, form autofill, estimates, daily and morning reports, and text recognition in documents (OCR).

  • On by default for a new company. The founder or an admin can switch AI off for the whole company, or feature by feature, in Company > AI & Credits. Each member can also switch off features for themselves.
  • What is sent to the AI provider: your request, plus the workspace data needed to answer it. For Wiibot, that can include tasks, comments, contacts, employee details (including email, phone and notes), vehicles, budgets, calendar events and the text of documents you attach, but only what you are allowed to see.
  • Two features run on their own when enabled: the morning summary email, and automatic text recognition of new files.
  • We cannot let you choose the provider; we route each feature to one of the providers below.
ProviderUsed forWhereTrains on your data?
OpenAI, L.L.C.Assistant, summaries, writingUnited StatesNo (API terms)
Anthropic, PBCAssistantUnited StatesNo (API terms)
Mistral AI SASText recognition (OCR)FranceNo (API terms)

Data sent to the United States. OpenAI and Anthropic process requests in the United States. If this is not acceptable for your company, switch AI off in Company > AI & Credits; nothing is sent to any AI provider from then on.

  • AI answers can be wrong. Review them before relying on them. AI-generated content is marked as such in the app.
  • Moderation: we can flag requests that match a list of abuse terms, and send a short excerpt (up to 240 characters) to your company's founder.
  • Wiibot conversations are stored in Wiiseto so you can come back to them. We keep your most recent conversations up to a fixed number, and you can delete any of them.

7. What stays on your device

To work offline, the app keeps a copy of your company's data in your browser (IndexedDB), including employee birthdays and email logs you are allowed to see, and up to 300 MB of recently viewed files. This copy is not separately encrypted; your device's own protection applies.

  • Signing out deletes this copy, your sign-in tokens and your analytics answer.
  • After your session expires, cached data stays readable offline for up to 7 days.
  • If an admin removes you or signs you out remotely, the copy is deleted the next time your device connects.

The full list of what is stored is in the Cookies and local storage policy.

8. How long we keep it

DataHow long
AccountUntil you ask us to delete it (section 10)
Workspace contentAs long as the company exists
Deleted company100 days (you can restore it), then deleted from our database
Files of a deleted companyNot yet deleted automatically. Deleted on request to [email protected]. We are fixing this.
Trash30 days, then deleted, file included
Unfinished uploads24 hours
Unpaid signup (checkout never completed)About 48 hours
Document access and activity logs365 days
Project activity and company audit logsAs long as the company exists
Deleted chat messages and their earlier versions60 days after deletion
Chat attachmentsYour company's setting (by default, kept)
Wiibot conversationsUntil you delete them, or they fall past the per-person limit
AI actions waiting for confirmation90 days after they are confirmed or cancelled
Email log365 days; open times 90 days
Failed and successful sign-in attempts24 hours
Sessions (IP, device, approximate location)12 months after the session expires
Legal acceptance recordsKept after the account is closed, as proof; IP and browser removed after 24 months
Payment dispute evidenceUntil the dispute and any claim about it are settled
InvoicesAt Stripe, for as long as tax law requires
Web server access logs30 days
Analytics eventsAs long as the PostHog project exists
Database backups7 days on the server, 30 days in our EU storage

Deleted data can remain in backups until they rotate out, as above.

9. Who else sees it, and where it goes

We do not sell or share your data for anyone's marketing. We use service providers (sub-processors) to run Wiiseto; the full, current list is on the Sub-processors page. In short:

  • Switzerland: our application servers and database (Amazon Web Services, Zurich), and the website (Infomaniak, Geneva).
  • European Union: files and backups (Cloudflare R2, EU jurisdiction), analytics (PostHog, Frankfurt), and any AWS service not yet available in Zurich (Frankfurt).
  • Email is sent through Amazon SES in Zurich, or Frankfurt where needed.

Outside Switzerland and the EU:

  • Cloudflare, Inc. (US) carries all traffic to our sites and servers, through its global network, so it sees your IP address and the data in transit.
  • Stripe (EU and US) for payments.
  • The AI providers in section 6, in the United States.
  • Email recipients' own providers, wherever they are.

For transfers to the United States we rely on the EU-US Data Privacy Framework and its Swiss extension where the provider is certified, and on the European Commission's standard contractual clauses (with the Swiss addendum) otherwise.

Keeping data in Switzerland or the EU does not put it out of reach of foreign law, in particular US law, because Wiiseto, LLC and some of our providers are US companies.

10. Your rights

You can ask us to:

  • tell you what data we hold about you and give you a copy (access),
  • correct it (rectification),
  • delete it (erasure),
  • limit how we use it (restriction),
  • give it to you in a machine-readable format (portability),
  • stop processing based on our legitimate interest (objection),
  • have a person review a decision made automatically (for example a sign-in risk check).

Write to [email protected]. It is free. We may ask you to prove who you are.

Today, export and account deletion are done by hand: there is no button for them yet. We answer within 30 days. You can already download your documents, export budgets as CSV or Excel, download invoices, and subscribe to calendars through iCal.

If you are an employee or contact recorded by one of our customers, your request is handled by that company, since it decides what it stores. Ask them first; if you write to us, we pass your request on to them.

If you are not satisfied with our answer, you also have the right to complain to a data protection authority.

11. Government requests and payment disputes

We hand over data only when a valid legal order requires it. We tell the affected customer unless the law forbids it, and we challenge requests that are too broad. There is no backdoor.

If a card payment is disputed, we send the card issuer, through Stripe, evidence that the service was ordered and used: the account email, acceptance records (date, version, IP), invoices and usage counts. We do this on the basis of our legitimate interest.

12. The marketing website (wiiseto.com)

  • The website has no accounts and no forms. If you write to us through an email link, we receive your email like any other.
  • Before you answer the cookie question, and if you decline: we count page views (page address, referring site, language) and whether you answered the question, without any cookie or storage, in memory only, with no click tracking. The random id disappears when you close the tab.
  • If you accept: PostHog stores a random id in a cookie on .wiiseto.com and in your browser storage, and records the pages you visit and your clicks with all text masked. The website and the app ask you separately: your answer on one does not apply to the other. Screens are never recorded.
  • The website is hosted in Switzerland (Infomaniak) and delivered through Cloudflare. Fonts are served from our own domain.
  • You can change your answer at any time on the Cookies page.

13. How we protect it

Connections are encrypted (TLS). Passwords are hashed with bcrypt. Two-factor secrets, calendar connections and single sign-on secrets are encrypted in our database. Access to data is checked on the server for every request, and denied by default. Sign-in is rate limited and supports two-factor authentication. More detail on the Security page.

If a breach puts your data at risk, we act as soon as possible. We inform the competent authorities within the deadlines the law sets, and the affected customers as described in the DPA: a first notice within 72 hours, and a detailed report within 31 days.

14. Children

Wiiseto is a work tool. You must be at least 16 to use it. We do not knowingly create accounts for anyone younger.

15. Changes to this policy

When we change this policy in a way that matters, we email account holders at least 30 days before the change takes effect, and ask you to accept the new version in the app. Each version shows what changed at the top. Earlier versions stay available.

Other documents

Wiiseto, LLC · wiiseto.com/legal/privacy · Version 2026-10-01

Wiiseto