1. Scope
This Privacy Policy applies to the Weavlin website at weavlin.co.in and to the Weavlin workflow automation platform (together, the "Services"). In this policy, "Weavlin", "we", "us", and "our" refer to the provider of the Services.
By using the Services, you acknowledge that you have read this policy. If you use Weavlin on behalf of an organisation, that organisation's agreement with us also governs how its data is handled.
2. Information we collect
Information you provide
- Account information: your name, work email address, organisation, workspace membership, and role.
- Invitations: the email address of a person an administrator invites to an organisation or workspace.
- Workflow content: workflow definitions, node configurations, test cases, and prompts you enter into our AI features.
- Connected-service credentials: API keys, database connection details, and cloud access keys you store so that workflows can reach your services.
- Communications: messages you send to us, for example by email.
Information generated when you use the Services
- Execution records: the history of each workflow run, including node-level inputs, outputs, logs, status, and timing.
- Audit logs: records of administrative and security-relevant actions within your organisation.
- Technical data: IP address, browser and device type, and request logs collected by our servers for security and reliability.
Passwords. Sign-in, passwords, and multi-factor authentication are managed by Amazon Cognito. Weavlin does not receive or store your password.
3. How we use information
We use information to:
- create and manage accounts, organisations, workspaces, and permissions;
- run the workflows you build and show you their results in real time;
- provide AI features, such as generating a workflow or a test payload from your description;
- secure the Services, prevent abuse, and investigate incidents;
- provide support and respond to your requests;
- maintain and improve the reliability and performance of the Services; and
- meet our legal and regulatory obligations.
We do not sell personal information, and we do not use the content of your workflows or execution data for advertising.
4. Legal bases
Where data protection laws such as India's Digital Personal Data Protection Act, 2023 or the EU and UK General Data Protection Regulation (GDPR) apply, we process personal information on the following bases:
- Contract: to provide the Services you or your organisation have signed up for.
- Legitimate interests: to secure, maintain, and improve the Services, where those interests are not overridden by your rights.
- Consent: where we ask for it. You may withdraw consent at any time.
- Legal obligation: where the law requires us to process or retain information.
5. Customer workflow data
Organisations use Weavlin to process their own data, which may include personal information about their customers or employees. For that data, the organisation decides what is processed and why, and Weavlin processes it on the organisation's behalf and according to its instructions.
If your personal information is processed through a workflow run by an organisation that uses Weavlin, please contact that organisation directly to exercise your rights. We will support them in responding.
Customers are responsible for ensuring they have a lawful basis to process data through their workflows. Sensitive categories of data, such as health or financial records, should only be processed where the customer has the appropriate agreements and safeguards in place.
6. Sharing and sub-processors
We share information only as described below:
| Recipient | Purpose |
|---|---|
| Amazon Web Services | Hosting, database storage, identity management (Amazon Cognito), and compute infrastructure. |
| AI model providers via Amazon Bedrock | Processing prompts and data when you use AI features or the AWS Bedrock node. |
| Services you connect | Data sent by your workflows to the APIs, databases, and services you configure, such as Postmark or your own endpoints. |
| Professional advisers and authorities | Where required by law, to protect rights and safety, or in connection with a merger or acquisition. |
When a workflow sends data to a third-party service, that service's own privacy policy governs how it handles the data.
7. International transfers
Our infrastructure providers may store or process information in countries other than your own. Where we transfer personal information across borders, we do so in line with applicable law and use appropriate safeguards, such as contractual protections.
8. Security
We design Weavlin to be secure by default. Our safeguards include:
- identity and multi-factor authentication through Amazon Cognito;
- AES-256-GCM encryption of stored credentials, which are write-only and never returned by our API;
- organisation-level data isolation applied automatically to database queries;
- custom code run in an isolated V8 sandbox with no file system or process access, and strict time and memory limits;
- single-use invitation links that expire after 15 minutes;
- role-based access control and organisation-level audit logs.
No system is completely secure. If you believe you have found a security issue, please contact us at info@weavlin.co.in.
9. Data retention
We keep personal information only for as long as needed for the purposes described in this policy:
- Account and workflow data is kept while your organisation's account is active, and deleted or anonymised within a reasonable period after the account is closed.
- Execution records and audit logs are kept for the period configured for, or agreed with, your organisation.
- Information we must keep by law is retained for the period the law requires.
10. Your rights
Depending on where you live, you may have the right to:
- access the personal information we hold about you;
- correct inaccurate or incomplete information;
- request erasure of your information;
- object to or restrict certain processing;
- receive your information in a portable format;
- withdraw consent where processing is based on consent;
- nominate another person to exercise your rights on your behalf; and
- lodge a complaint with a data protection authority.
To exercise these rights, email info@weavlin.co.in. We may need to verify your identity before responding. Please do not include sensitive personal information in your email.
11. Cookies and similar technologies
This website does not use advertising or analytics cookies. The website loads fonts from Google Fonts, which means your browser connects to Google's servers and shares your IP address with Google.
The Weavlin platform uses strictly necessary storage and authentication tokens to keep you signed in and secure. These cannot be switched off without affecting how the platform works.
12. Children
The Services are intended for business use and are not directed at anyone under 18. We do not knowingly collect personal information from children. If you believe a child has provided us with information, please contact us and we will delete it.
13. Changes to this policy
We may update this policy from time to time. When we do, we will change the "Last updated" date above, and for significant changes we will notify organisation administrators through the Services or by email.
14. Contact us
For privacy questions, requests, or grievances, contact us at info@weavlin.co.in. We aim to acknowledge requests promptly and to respond within the time required by applicable law.