Appearance
Privacy & compliance
This page covers how VWAM handles data-subject requests, the state of our GDPR program, and the sub-processors behind the service.
Data-subject requests
VWAM includes automated tooling for the two most operationally significant data-subject requests.
- Erasure — removal of a shopper's personal data on request. VWAM removes personal content and identifiers across the conversation, lead, analytics, and file-storage paths. VWAM preserves the anonymized aggregate records that keep a merchant's analytics intact.
- Export — delivery of a shopper's data on request.
This tooling is in place today. For the exact scope and mechanics of erasure for a compliance sign-off, contact us for a direct walkthrough.
Data minimization
- VWAM operates no third-party analytics service for its own purposes. Our behavioral analytics are first-party. VWAM salts and hashes the identifiers in the analytics stream, and does not store them as raw personal data.
- Lead analytics record only which form fields a shopper submits, never the values. Lead personal data therefore does not enter the analytics store.
- VWAM purges raw analytics events on a short rolling window.
A merchant can connect its own analytics service as an integration, for example Google Analytics. That service is the merchant's own property and configuration. VWAM does not operate it.
GDPR program
Automated data-subject request tooling and time-based retention limits are in place. See Data storage & geo-residency. We are completing the remaining elements:
- Documented, contractual retention schedules on top of those limits.
- Full EU geo-residency. See Data storage & geo-residency.
- Granular EU consent controls, with a privacy-preserving default mode until a shopper consents.
- Our data processing agreement (DPA) and a complete sub-processor register.
We target completion of this work in the near term. For the current status, for our DPA, or for a geo-residency or retention commitment for your contract, contact us.
Sub-processors
VWAM depends on a small set of sub-processors. They are the AI providers behind the assistant, which are OpenAI and Anthropic; AWS for hosting; and the integrations that a merchant chooses to connect. We maintain a complete, current sub-processor register in our DPA pack, and we provide it on request.