Owned and operated by: UNITED INTEGRATED SOLUTIONS (Wyoming LLC, United States)
Privacy Policy
How WKIL — owned and operated by UNITED INTEGRATED SOLUTIONS, a Wyoming limited liability company in the United States — handles personal data across wkil.ai and app.wkil.ai.
1. Who we are
WKIL is owned and operated by UNITED INTEGRATED SOLUTIONS, a limited liability company formed in the State of Wyoming, United States. In this policy, "WKIL", "we", "us" and "our" refer to UNITED INTEGRATED SOLUTIONS operating the WKIL brand and platform. WKIL is not a separately incorporated company, and we have no establishment in the European Union, Saudi Arabia or Türkiye. For any privacy question, contact [email protected].
2. What this policy covers
Where an organisation uses WKIL as a customer, that organisation decides how the platform is used with its own data. In those cases the organisation is the controller and WKIL acts as its processor; this policy explains our own processing, and the organisation's privacy notice governs its use of the platform.
This policy applies to:
- wkil.ai — our public website, including the website assistant, contact, Enterprise, AI Readiness and Enterprise document / due-diligence request forms, blog and documentation pages.
- app.wkil.ai — the WKIL platform, where customers create accounts, build AI agents, connect systems and run conversations.
3. Our role
- Website visitors, leads, due-diligence requests and website assistant conversations — we are the controller.
- Account registration, authentication, billing, product analytics and support — we are the controller.
- Customer agent configurations, conversations, uploaded knowledge and connector data — we are a processor acting on the customer's instructions.
- Operational run logs and traces — mixed: a service record for the customer, and our own debugging and security purposes.
4. Information we process
Website (wkil.ai):
- Contact, Enterprise, AI Readiness and Enterprise document / due-diligence request details you submit (name, business email, company, role, country, company size, requested materials, message and timeline).
- Website assistant conversations.
- Analytics and product-usage measurement, and limited technical diagnostics (an allowlist of non-content error metadata).
- Cookies and similar technologies — see section 11.
- Accounts (app.wkil.ai): registration and authentication data (email address, authentication identifiers and, if you sign in with Google, the identity data that provider returns to us); workspace membership, roles and permissions; billing and subscription records and payment events from our payment provider; support correspondence.
- Customer content processed on our customers' instructions: agent configurations and instructions; conversations and messages between end users and agents; Company Knowledge (uploaded documents and files, and the text chunks and vector embeddings derived from them); data retrieved from or written to systems the customer connects; and agent run records, including tool calls with their inputs and results.
5. Why we process it
Where the GDPR applies, we rely on performance of a contract (accounts, subscriptions, providing the service), legitimate interests (security, product improvement, responding to business enquiries, business-to-business outreach where permitted), consent where it is required, and legal obligation (financial and compliance records).
- To provide, operate and secure the website and the platform.
- To create and administer accounts and workspaces.
- To execute AI agents as instructed by the customer.
- To respond to enquiries, Enterprise and due-diligence requests, and to provide support.
- To process payments and maintain financial records.
- To measure and improve our website and product.
- To detect, investigate and prevent abuse, fraud and security incidents.
- To comply with legal obligations.
6. AI processing
- Agent execution and embedding generation are performed through a single AI gateway provider, which routes requests to upstream model providers.
- Routing is not region-pinned, so inference may take place outside the region where your data is stored.
- We do not use customer content to train models. We enable the gateway's account-level training opt-out, and chat completion requests additionally carry a request-level restriction on data collection. Embedding requests do not currently carry that request-level restriction.
- Prompt caching exists at the provider layer; we therefore do not claim that nothing is retained by upstream providers.
- Model selection is configurable by the customer.
7. Connectors and integrations
- When a customer connects an external system, the authorisation credentials are custodied by the connector infrastructure provider we engage, not stored by WKIL itself.
- Data flows to and from the connected system according to the permissions the customer grants.
- The external services a customer connects are that customer's own vendors under their own contracts and privacy terms; they are not our subprocessors.
- Disconnecting a connection stops the agent from using it.
8. Where data is stored and processed
Storage and processing are different. Persistent data is stored on European-region managed services: application runtime in Belgium; database, knowledge chunks, embeddings, conversations and run data in Ireland; files in the provider's Eastern-Europe region; cache and queues in Ireland; application logs in an EU logging project; AI traces in the provider's EU region; and backups in Ireland. Processing nonetheless takes place outside those regions for AI inference and embeddings, connector execution, global content delivery, product analytics, payment processing and transactional email. Because UNITED INTEGRATED SOLUTIONS is a United States company, our personnel may access data for support and operations. Where transfers are subject to the GDPR, the Saudi PDPL or the KVKK, we apply the safeguards required by the applicable law, including standard contractual clauses where they apply. Saudi in-country data residency is a target enterprise capability under engineering work; it is not a current production offering.
9. Who we share it with
We also disclose information where required by law, to protect our rights or the safety of users, or in connection with a corporate transaction. Enterprise customers can request our current subprocessor list, with roles and regions, through their account contact. We do not sell personal data.
We use service providers acting on our behalf, in these categories:
- Cloud hosting and runtime; managed database, authentication and storage; cache and queues.
- Content delivery and edge services.
- AI gateway and, through it, model providers; AI tracing.
- Connector infrastructure.
- Product analytics, payment processing, transactional email and logging.
10. How long we keep it
Automated retention purges are not yet in place across every store, so we do not claim zero retention anywhere.
- Account and workspace data: for the life of the account, and afterwards as needed for legal, financial and security purposes.
- Customer content: for as long as the customer keeps it in the platform, subject to the customer's own instructions.
- Billing and financial records: as required by applicable law.
- Website leads, due-diligence requests and assistant conversations: for as long as needed for the enquiry, the commercial relationship and our records.
- Backups: managed daily database backups on a seven-day rotation; data in backups is removed by rotation rather than by selective deletion.
- Logs and traces: retained for operational and security purposes.
11. Cookies and analytics
We use cookies and similar technologies that are strictly necessary for the site to work, and analytics technologies — currently Google Analytics 4 and Microsoft Clarity — that help us measure and improve the site. Under our current configuration these analytics technologies load automatically when you visit the public website; they are not consent-gated today. You can block or delete cookies through your browser settings. Details of each cookie, its purpose and its duration are maintained in our cookie inventory and reflected in our cookie notice, and we will update this section if the configuration changes.
12. Your rights
Contact [email protected]. We verify requests before acting on them. Export and deletion requests are handled by our team manually today; self-service tooling is not yet available. We respond within the period required by applicable law. Where the data relates to a customer's use of the platform, that customer is the controller and we will refer you to them or assist them in responding.
Depending on where you are, you may have rights to:
- Access the personal data we hold about you.
- Correct or update it.
- Delete it, or restrict or object to certain processing.
- Receive it in a portable format.
- Withdraw consent where processing is based on consent.
- Complain to your local supervisory authority.
13. Security
We apply technical and organisational measures including transport encryption, managed encryption at rest, database-level tenant isolation, role-based access control, managed secret storage, separated environments, restricted production access under confidentiality obligations, and logging. We do not currently hold, and do not claim, any security certification or third-party audit report. Enterprise customers can request a detailed description of these measures through the Enterprise document request on our Trust Center.
14. Enterprise document and due-diligence requests
If you submit an Enterprise document or due-diligence request, we record the details you provide (name, business email, company, role, country, company size, the materials you requested, your question and any timeline) so that our team can review the request, respond, and record which documents and versions were shared with you. This information is used only for that purpose and for managing the resulting commercial relationship, and is accessible internally to the WKIL team. Documents are never released automatically; each request is reviewed individually.
15. Children
The Services are intended for business use and are not directed at children. We do not knowingly collect personal data from children; if we learn that we have, we will delete it.
16. Changes and contact
We will update this policy as our services change and will indicate the date of the latest version at the top of this page. For any question about this policy or your data, contact UNITED INTEGRATED SOLUTIONS at [email protected].