WATTAIS

Privacy Policy

How Wattais LLC collects, uses, discloses, and protects your personal information

Effective: August 16, 2026 Version 2.4 GDPR · CCPA · LATAM Compliant

1 Introduction & Data Controller

Wattais LLC (referred to in this Policy as "Wattais", "we", "our", or "us") is a limited liability company duly organized and existing under the laws of the Republic of Costa Rica (Latin America), with its registered office located in San José, Costa Rica. Wattais operates the website available at wattais.com (the "Site") and the NeuroFlow artificial intelligence sales automation platform (the "Service" or "NeuroFlow").

For the purposes of the European Union's General Data Protection Regulation (Regulation (EU) 2016/679, "GDPR"), the United Kingdom's Data Protection Act 2018, the California Consumer Privacy Act of 2018 as amended by the CPRA ("CCPA"), Brazil's Lei Geral de Proteção de Dados ("LGPD"), and other applicable data protection laws, Wattais LLC acts as the Data Controller with respect to personal information collected through the Site and the Service. Where we process personal data on behalf of our enterprise clients (for example, lead lists, contact records, or message content they upload into NeuroFlow), Wattais acts as a Data Processor and the client is the Data Controller. In such cases, the client's privacy notice governs the underlying data, and our Data Processing Addendum (available on request) governs our processing activities.

This Privacy Policy (the "Policy") explains in clear and transparent language what personal data we collect, why we collect it, how we use it, who we share it with, how long we keep it, and what rights you have over your information. By accessing the Site, registering for an account, or otherwise using the Service, you acknowledge that you have read and understood this Policy. If you do not agree with any part of this Policy, you must discontinue use of the Site and the Service.

Data Protection Officer (DPO). Wattais has appointed a Data Protection Officer who can be contacted for any privacy-related inquiry, complaint, or to exercise your rights. The DPO can be reached at dpo@wattais.com or via our postal address listed in Section 13.

1.1 Scope of this Policy

This Policy applies to all personal information collected through: (a) the wattais.com website; (b) the NeuroFlow dashboard, web application, and any associated APIs; (c) email, chat, and other communications with Wattais; (d) sales, marketing, and customer support interactions; and (e) any third-party platform that links to or refers to this Policy. It does not apply to the practices of third-party companies that we do not own or control, including the AI infrastructure providers that we use to power NeuroFlow (see Section 4 and Section 6 for the full list).

2 Information We Collect

We collect personal information from several sources to operate, secure, and improve the Service. The categories below describe what we collect, the source, and the purpose.

2.1 Account & Identity Information

When you register for a NeuroFlow account, request a demo, or contact our sales team, we collect:

2.2 Payment & Billing Information

Wattais does not store full payment card numbers on its own servers. All payments are processed by Stripe Inc. (see Section 6). We collect and retain:

2.3 Usage, Telemetry & Device Information

When you interact with the Service, we automatically collect technical and usage data:

2.4 AI Prompts & Content You Submit

This is critical and is called out prominently in Section 4 below. When you use NeuroFlow to generate AI-driven sales messages, prospect lists, reply suggestions, or other content, we collect and transmit the following to our AI infrastructure provider:

2.5 Communications & Support

If you contact us via email, in-app chat, or support tickets, we collect the contents of those communications, including any attachments, screenshots, or diagnostic information you voluntarily share. We also retain records of consent, opt-out preferences, and account history.

2.6 Information from Third Parties

We may receive personal information about you from third-party services you have connected to NeuroFlow (e.g., Gmail, Outlook, HubSpot, Salesforce, LinkedIn Sales Navigator) and from public sources, advertising partners, and identity verification providers. We use this information only as described in this Policy and in accordance with your authorizations.

CategoryExamplesSource
IdentifiersName, email, IP, account IDDirectly from you
CommercialSubscription tier, billing historyDirectly from you / Stripe
Internet activityPages visited, clickstreamAutomatic / cookies
ProfessionalJob title, employer, industryDirectly from you / integrations
AI inference dataPrompts, lead lists, AI outputsDirectly from you
GeolocationCountry, approximate city (from IP)Automatic

3 How We Use Information

We process the personal information we collect for the following purposes, each grounded in a lawful basis under GDPR Article 6 (or equivalent grounds under CCPA, LGPD, and other applicable laws).

3.1 Service Delivery (Legal basis: Contract performance)

3.2 Service Improvement & Analytics (Legal basis: Legitimate interest; consent where required)

3.3 Customer Support (Legal basis: Contract performance; legitimate interest)

3.4 Communications & Marketing (Legal basis: Consent; legitimate interest)

3.5 Legal, Compliance & Security (Legal basis: Legal obligation; legitimate interest)

Aggregate & de-identified data. Wattais may aggregate or de-identify personal information such that it can no longer reasonably be used to identify you. We may use or share such data for any lawful purpose, including analytics, research, and product development, without further notice to you.

4 AI Processing Disclosure Important

ALL data you submit to NeuroFlow (prompts, lead lists, message content, response data) is processed by MiniMax AI (minimax.io). MiniMax's privacy policy applies to data processed by their systems: https://minimax.io/privacy. By using NeuroFlow, you consent to your data being processed by MiniMax's AI infrastructure.

You acknowledge that Minimax processes this data on its own servers, under its own terms, and may use it in accordance with its own privacy policy and product agreements. Wattais does not control Minimax's processing activities.

4.1 What is sent to MiniMax

Every interaction with NeuroFlow's core AI features transmits data to Minimax. Specifically, the following categories are transmitted:

4.2 Where Minimax processes data

Minimax operates AI inference infrastructure in multiple regions. Depending on your account configuration and our routing decisions, your data may be processed in the United States, the European Union, or other regions where Minimax maintains servers. By using NeuroFlow, you consent to this processing in any region where Minimax operates its infrastructure.

4.3 Minimax's privacy policy

Minimax's privacy practices are described in their own privacy policy, available at https://minimax.io/privacy. We encourage you to review that policy before submitting sensitive personal data to NeuroFlow. Wattais is not responsible for Minimax's privacy practices, retention policies, security measures, or any modification of the Minimax service.

4.4 Your consent

By clicking "I agree," creating an account, or otherwise using NeuroFlow's AI features, you confirm that:

4.5 Data minimization

Where feasible, we pseudonymize lead identifiers before transmission to Minimax, and we strip non-essential metadata. However, because Minimax's API requires the full prompt and context to produce accurate outputs, some personal data will necessarily be transmitted. You can and should review your prompts and lead lists before triggering AI generation.

5 Cookies & Tracking Technologies

Wattais uses cookies and similar tracking technologies to operate the Site, remember your preferences, and analyze traffic. We categorize cookies as follows:

5.1 Strictly Necessary Cookies

These cookies are required for the Site to function and cannot be disabled. They include authentication session cookies (e.g., wattais_session), CSRF protection tokens, and load-balancing identifiers.

5.2 Preference Cookies

These cookies remember choices you make (e.g., language, theme, timezone) to provide a personalized experience and avoid asking you to re-enter them on every visit.

5.3 Analytics Cookies

We use first-party analytics and privacy-respecting analytics tools to understand how visitors use the Site. These cookies collect information in aggregate form. We do not use Google Analytics by default; if we do in the future, we will display a consent banner.

5.4 Marketing Cookies

Wattais does not currently use third-party advertising cookies on the Site. If you arrive from a marketing campaign, we may use UTM parameters (stored in your browser via first-party cookies) to attribute the conversion correctly.

5.5 Local Storage & Similar

We use the localStorage and sessionStorage Web APIs to remember UI state, draft content, and authentication state. You can clear local storage at any time via your browser settings.

Your choices. You can block or delete cookies via your browser settings. The Site will continue to work, but some features (e.g., staying logged in) may be impaired. European Economic Area ("EEA") and UK users will see a consent banner on their first visit and may opt in to non-essential cookies.

6 Third-Party Services

To deliver NeuroFlow, we rely on the following categories of third-party service providers. Each provider processes personal data only on our documented instructions and under data processing agreements that comply with GDPR Article 28, CCPA service provider requirements, and equivalent obligations under other applicable laws.

6.1 Payment Processing — Stripe

All payments are processed by Stripe Inc., a U.S.-based payment service provider. Stripe collects payment card data, billing addresses, and authentication information as needed to process transactions, perform fraud screening, and meet regulatory obligations (e.g., PCI-DSS, PSD2 SCA). Stripe's privacy policy is available at stripe.com/privacy. Stripe is independently certified as a PCI-DSS Level 1 service provider.

6.2 Hosting, CDN & Edge Computing — Cloudflare

Our Site and API endpoints are served from Cloudflare's global edge network. Cloudflare processes IP addresses, request headers, and TLS metadata for security, DDoS protection, caching, and content delivery. Cloudflare's privacy policy is available at cloudflare.com/privacypolicy. Where Cloudflare acts as our sub-processor, it is bound by a Data Processing Addendum that restricts processing to our documented purposes.

6.3 Transactional & Marketing Email

We use transactional email providers to deliver account notifications, security alerts, billing receipts, and (with consent) marketing communications. Depending on your region and account type, we use one of:

Both providers process email addresses and message content strictly to deliver the messages you request. They do not use your content for advertising or model training.

6.4 AI Infrastructure — MiniMax

As described in Section 4, NeuroFlow uses Minimax AI (minimax.io) for prompt processing and response generation. Minimax's privacy policy is available at minimax.io/privacy.

6.5 Other Service Providers

We may share data with additional subprocessors (e.g., error tracking, customer support platforms, internal analytics). A current list of subprocessors is published at wattais.com/subprocessors and is updated at least 30 days before any new subprocessor begins processing your data. You may subscribe to receive notification of changes.

7 Data Retention

We retain personal data only for as long as necessary to fulfill the purposes for which it was collected, including to satisfy legal, accounting, or reporting obligations.

7.1 Account Data

We retain your account information for the duration of your subscription and for an additional period of ninety (90) days after termination to allow you to reactivate, export, or recover your data. During this 90-day window, your data is stored in a "deletion queue" and is not actively processed.

7.2 Billing & Tax Records

Invoices, receipts, and related tax records are retained for a minimum of five (5) years after the transaction date, in accordance with Costa Rican tax law (Ley del Impuesto sobre la Renta, Article 28) and equivalent international provisions.

7.3 AI Prompts, Lead Lists & Generated Content

Prompts, lead lists, and AI-generated content are retained for the duration of your account and for the same 90-day post-termination window as account data. After the 90-day window, all content is permanently deleted from production systems and active backups within an additional 30 days. Backups are purged on a rolling 12-month cycle.

7.4 Logs & Telemetry

Server access logs, application logs, and security logs are retained for a maximum of 12 months for security and operational purposes, except where a longer retention period is required to investigate an incident.

7.5 Support Communications

Support tickets and email correspondence are retained for 24 months to provide continuity of service and to comply with documented retention rules.

7.6 Marketing Data

If you have unsubscribed from marketing communications, we retain your email address on a "suppression list" indefinitely to ensure we do not contact you again.

7.7 Deletion Exceptions

We may retain data beyond the periods above where retention is necessary to: (a) comply with a legal obligation; (b) respond to a lawful government request; (c) defend a legal claim; or (d) investigate a security incident. Where data is retained for these reasons, it is isolated from production systems and access is restricted.

8 Your Rights (GDPR, CCPA, LGPD & Other Jurisdictions)

You have a number of rights with respect to your personal data. These rights vary by jurisdiction but are summarized below. We will honor all rights granted to you under applicable law.

8.1 Right of Access

You have the right to request confirmation of whether we process personal data about you and to request a copy of that data in a portable format. To exercise this right, email dpo@wattais.com. We will respond within 30 days (or as required by your jurisdiction).

8.2 Right to Rectification

If any personal data we hold about you is inaccurate or incomplete, you have the right to have it corrected. You can correct most account data directly from the NeuroFlow dashboard under Settings → Profile.

8.3 Right to Deletion ("Right to be Forgotten")

You have the right to request deletion of your personal data, subject to the retention exceptions in Section 7.7. We will respond within 30 days. In some cases, deletion will require termination of your account.

8.4 Right to Restrict Processing

You may ask us to stop processing your data while we investigate a complaint or verify the accuracy of the data.

8.5 Right to Data Portability

You may request a machine-readable export of your personal data. You can download a JSON export of your account data at any time from Settings → Export.

8.6 Right to Object

You may object to processing based on our legitimate interests, including profiling. If you object, we will cease processing unless we have a compelling legitimate ground that overrides your interests.

8.7 Right to Opt-Out of Sale or Sharing (CCPA)

Wattais does not sell personal information for monetary or other valuable consideration. We also do not share personal information for cross-context behavioral advertising. California residents may, however, request that we do not sell or share their personal information at any time. To exercise this right, email privacy@wattais.com with the subject line "Do Not Sell or Share My Personal Information."

8.8 Right to Non-Discrimination

If you exercise any of your rights under CCPA, we will not deny you service, charge different prices, or provide a different level of quality.

8.9 Right to Withdraw Consent

Where we rely on your consent (e.g., for marketing emails or non-essential cookies), you may withdraw consent at any time. Withdrawal does not affect the lawfulness of processing carried out before withdrawal.

8.10 Right to Lodge a Complaint

You have the right to lodge a complaint with a supervisory authority. If you are in the EEA, you may contact your local Data Protection Authority. If you are in the UK, you may contact the Information Commissioner's Office (ICO). If you are in California, you may contact the California Privacy Protection Agency. If you are in Brazil, you may contact the Autoridade Nacional de Proteção de Dados (ANPD). For other jurisdictions, please contact your local data protection regulator.

8.11 How to Exercise Your Rights

To exercise any of these rights, send a verifiable request to dpo@wattais.com. We may need to verify your identity before fulfilling the request. We will respond within 30 days (45 days under CCPA, extendable by an additional 45 days with notice). Authorized agents may submit requests on your behalf with proof of authorization.

No fees. We will not charge you a fee to exercise your rights, unless your request is manifestly unfounded, excessive, or repetitive.

9 Data Security

Wattais takes the security of your personal data seriously. We have implemented technical and organizational measures ("TOMs") commensurate with the risks involved in processing and the nature of the personal data.

9.1 Encryption

9.2 Access Controls

9.3 Network Security

9.4 Operational Security

9.5 Organizational Measures

9.6 Breach Notification

In the event of a personal data breach that is likely to result in a high risk to your rights and freedoms, we will notify you and the relevant supervisory authority without undue delay and, where feasible, within 72 hours of becoming aware of the breach, in accordance with GDPR Article 33–34 and equivalent laws.

No system is 100% secure. Despite our efforts, no security measure is perfect. We cannot guarantee absolute security of your data. You are responsible for maintaining the confidentiality of your account credentials and for using a strong, unique password.

10 International Data Transfers

Wattais is headquartered in Costa Rica, but we serve a global customer base. As a result, your personal data may be transferred to, stored, and processed in countries other than your country of residence. These countries may have data protection laws that differ from your home jurisdiction.

10.1 Primary Hosting Locations

Our primary infrastructure is hosted in the United States and the European Union (via Cloudflare and our hosting providers). We use regional data residency where technically feasible.

10.2 EU & UK Data Transfers

For transfers of personal data from the European Economic Area, the United Kingdom, or Switzerland to countries that have not been deemed adequate by the European Commission (or the relevant UK authority), we rely on:

10.3 LATAM Data Transfers

For transfers between Latin American jurisdictions (e.g., between Costa Rica, Brazil, Mexico, Argentina, Chile, Colombia), we comply with regional frameworks including the Convenio Marco de Protección de Datos Personales and applicable local statutes.

10.4 US Data Transfers

For transfers of personal data from the EU, UK, or Switzerland to the United States, we additionally rely on providers that participate in the EU-U.S. Data Privacy Framework and the UK Extension, where applicable.

10.5 Your Rights in Relation to Transfers

You may request a copy of the safeguards we use for international transfers by contacting dpo@wattais.com. We may redact sensitive commercial information for confidentiality reasons.

11 Children's Privacy

NeuroFlow is a business-to-business service designed for professional sales and marketing use. It is not intended for, and may not be used by, individuals under the age of 18.

We do not knowingly collect personal information from children under 18 (or the equivalent age of digital consent in your jurisdiction). If we learn that we have inadvertently collected personal information from a child under 18, we will delete it as soon as possible. If you believe we have collected information from a child, please contact us immediately at dpo@wattais.com.

You are also responsible for ensuring that, when you upload prospect data or lead lists to NeuroFlow, you do not include personal data of individuals under 18 without appropriate legal grounds.

12 Changes to this Policy

We may update this Policy from time to time to reflect changes in our practices, our Service, or applicable law. The most current version will always be posted at wattais.com/privacy.html with the "Effective" date at the top.

For material changes — meaning changes that meaningfully affect the way we collect, use, or share your personal data — we will provide at least thirty (30) days' prior notice by:

For non-material changes (e.g., clarifications, typo corrections, updated service-provider URLs), we will update the "Effective" date and post the revised Policy without prior notice.

Your continued use of the Service after the effective date of the revised Policy constitutes acceptance of the changes. If you do not agree to the changes, you may terminate your account within the notice period and request deletion of your data.

Previous versions of this Policy are archived and available on request from dpo@wattais.com.

13 Contact & Data Protection Officer

If you have any questions, comments, or complaints about this Policy or our privacy practices, please contact us using the methods below. We will respond as soon as possible and in any event within the deadlines required by applicable law.

13.1 Data Protection Officer

Email: dpo@wattais.com

Privacy team (general): privacy@wattais.com

Postal address:

Wattais LLC — Office of the Data Protection Officer
P.O. Box 11381-1000
San José, Costa Rica
Central America

13.2 EU Representative

For users in the European Economic Area, our appointed EU representative under GDPR Article 27 can be contacted at eu-rep@wattais.com.

13.3 UK Representative

For users in the United Kingdom, our appointed UK representative can be contacted at uk-rep@wattais.com.

13.4 Supervisory Authority

If you are unsatisfied with our response, you have the right to lodge a complaint with your local data protection authority. For Costa Rica, the relevant authority is the Agencia de Protección de Datos de los Habitantes (PRODHAB). For EU users, the lead supervisory authority is the Agencia Española de Protección de Datos (AEPD) or your local DPA.

Effective Date: August 16, 2026 · Version: 2.4 · Supersedes: all prior versions.