Privacy Policy of Happy Agents Pte. Ltd.
Last updated: June 18, 2026
This Privacy Policy explains how Happy Agents Pte. Ltd. ("Happy Agents", "we", "us", or "our") collects, uses, discloses, and protects personal data in connection with our websites, applications, and services, including Wimi (collectively, the "Services"). This Policy applies to data we process as a controller. Where we process personal data on behalf of a customer (for example, end-user data uploaded by a business that subscribes to Wimi), we act as a processor and our customer is the controller; this Policy describes that processing at a high level and is supplemented by a Data Processing Addendum where required.
By accessing or using the Services, you agree to the collection, use, and disclosure of personal data in accordance with this Policy and applicable law, including the Personal Data Protection Act 2012 of Singapore ("PDPA"), the EU and UK General Data Protection Regulation ("GDPR"), and the California Consumer Privacy Act as amended by the California Privacy Rights Act ("CCPA/CPRA"), where applicable.
1. Personal data we collect
Account and contact data: name, email, password (hashed), organization name, role, phone number, and other details you provide when creating or managing an account.
Billing and payment data: billing contact, billing address, plan, transaction history, and partial payment-card details. Full card numbers are collected and stored by our payment processor (Stripe) and are not stored on our systems.
Service usage and device data: features used, settings, configuration, log data, IP address, device and browser type, language, time zone, referring URLs, and timestamps.
Business data you connect: Google Business Profile information, location details, public reviews, review responses, posts, photos, hours, staff contacts, and other content you authorize us to access through connected platforms.
AI prompts and outputs: the review text, business context, and instructions we send to AI models on your behalf, and the AI-generated drafts and replies returned.
Support and communications: messages, attachments, recordings of voluntary calls (with notice), and other information you send us.
Marketing data: email engagement metrics where you have subscribed to marketing communications.
We do not knowingly collect personal data from children under 18. The Services are not directed to children.
2. Sources of personal data
We collect personal data (a) directly from you when you register, configure, or use the Services or communicate with us; (b) automatically from your device and use of the Services; and (c) from third parties you authorize us to connect to, such as Google Business Profile, Google OAuth, and our payment processor.
3. How we use personal data
We use personal data only to the extent reasonably necessary for the following purposes:
3.1 To provide and operate the Services, including creating and managing your account, authenticating you, connecting third-party platforms, generating and publishing AI replies and posts, and delivering the analytics dashboard.
3.2 To process payments, manage subscriptions, send invoices, and prevent fraud.
3.3 To provide customer support and respond to enquiries, requests, and complaints.
3.4 To maintain, secure, and improve the Services, including troubleshooting, abuse detection, testing, and analytics on an aggregated or de-identified basis.
3.5 To send service-related communications (for example, security alerts, billing notices, and changes to terms or policies).
3.6 With your consent or where otherwise permitted by law, to send marketing communications about products, features, and content we think may interest you. You can opt out at any time using the unsubscribe link or by contacting us.
3.7 To comply with applicable laws, regulations, legal processes, or enforceable governmental requests, and to enforce our Terms.
3.8 We do not sell personal data and we do not share personal data for cross-context behavioural advertising as those terms are defined under the CCPA/CPRA.
4. Legal bases (GDPR) and consent (PDPA)
Where GDPR applies, we rely on the following legal bases: (a) performance of a contract with you; (b) our legitimate interests in operating, securing, and improving the Services and growing our business, where not overridden by your interests or rights; (c) compliance with a legal obligation; and (d) your consent, where required (for example, certain marketing communications).
Where the PDPA applies, we collect, use, and disclose personal data with your consent or where an exception under the PDPA applies. You may withdraw consent at any time, subject to legal or contractual restrictions and reasonable notice, by contacting us as set out in Section 11. If you withdraw consent, we may not be able to continue providing some or all of the Services to you.
5. AI processing and subprocessors
To generate AI replies and posts, we send the relevant inputs (such as review text, business name, location context, and tone settings) to third-party large language model providers acting as our subprocessors. We have contractual commitments with these providers that prohibit them from using your inputs or outputs to train their general-purpose models, except for limited abuse monitoring and as required by law.
We engage the following categories of subprocessors to operate the Services: cloud hosting and database providers, authentication and identity providers, email and notification providers, customer-support tools, analytics providers (privacy-respecting only), error-monitoring tools, payment processors, and AI model providers. A current list of subprocessors is available on request to wimi@happyagents.io. We require subprocessors to provide a level of data protection consistent with this Policy and applicable law.
6. How we share personal data
Service providers and subprocessors: as described in Section 5, only for the purposes described in this Policy and under appropriate contractual obligations.
Connected platforms: when you authorize us to act on your behalf on a third-party platform (for example, publishing a reply on Google Business Profile), we share the relevant content with that platform; their handling of the content is governed by their own terms and policies.
Business transfers: in connection with a merger, acquisition, financing, reorganization, or sale of all or part of our business, in which case continued use of the data will be subject to this Policy or a successor notice.
Legal, safety, and rights: where we reasonably believe it is necessary to comply with law, legal process, or government request, to enforce our Terms, or to protect the rights, property, or safety of Happy Agents, our users, or others.
With your direction: with other recipients you direct or authorize.
We may also use and share aggregated or de-identified data that does not identify any individual for analytics, research, model improvement, and business purposes.
7. Cookies and tracking
We use strictly necessary cookies and similar technologies to operate the Services (for example, to keep you logged in and maintain session security). We do not use cookies for cross-site advertising or behavioural profiling.
For product analytics we use PostHog, a first-party-configured analytics tool, to understand aggregate usage such as which pages are viewed and which buttons are clicked. By default this runs in a cookieless mode: no analytics identifier is stored on your device, and each visit is measured in isolation. If you choose "Allow cookies" in our consent banner, PostHog stores a first-party analytics identifier so we can recognise return visits and measure conversion over time. You can withdraw or change that choice at any time by clearing your browser storage for this site, or by contacting us at wimi@happyagents.io.
If you select "Reject", analytics capture is switched off entirely for your browser. We do not sell analytics data, and we do not use it for advertising.
8. Data retention
We retain personal data only for as long as is reasonably necessary to fulfil the purposes for which it was collected, including to provide the Services, comply with legal, tax, and accounting obligations, resolve disputes, prevent abuse, and enforce our agreements. Indicative retention periods:
Account and billing records: for the duration of the account and up to seven (7) years after closure, to meet legal and tax obligations.
Connected business data, generated replies, and analytics: for the duration of the account and up to thirty (30) days after termination, after which we delete or de-identify it, except as required by law.
Backups: rolling backups are retained for up to ninety (90) days.
Support and communications: up to three (3) years from the last interaction.
De-identified or aggregated data may be retained indefinitely.
9. Data security and incidents
We implement reasonable technical and organisational measures designed to protect personal data, including encryption in transit, access controls, least-privilege access, logging, vendor due diligence, and regular review of security practices. No method of transmission or storage is completely secure, and we cannot guarantee absolute security. In the event of a personal data breach affecting your data, we will notify affected customers and, where required, regulators in accordance with applicable law.
10. Your rights and choices
Subject to applicable law, you may have the following rights in relation to your personal data:
Access: request a copy of personal data we hold about you.
Correction: request correction of inaccurate or incomplete personal data.
Deletion: request deletion of personal data, where required by law.
Portability: request a copy of personal data in a structured, commonly used, machine-readable format.
Restriction and objection: request that we restrict or object to certain processing, including processing based on legitimate interests or for direct marketing.
Withdrawal of consent: withdraw consent at any time, subject to legal or contractual restrictions.
Automated decisions: we do not make decisions producing legal or similarly significant effects about you based solely on automated processing.
Complaint: lodge a complaint with your local supervisory authority (for example, the Personal Data Protection Commission of Singapore, your EU/UK Data Protection Authority, or the California Privacy Protection Agency).
California residents: you have the right to know what personal information we collect and how we use it, to request deletion or correction, to opt out of any "sale" or "sharing" of personal information (we do neither), and to non-discrimination for exercising your rights. We do not use or disclose sensitive personal information for purposes that would require an opt-out under the CCPA/CPRA.
To exercise any of these rights, contact us using the details in Section 11. We may need to verify your identity before processing your request. We will respond within the time required by applicable law.
11. Contact and Data Protection Officer
If you have any questions about this Policy or our data protection practices, or wish to exercise your rights, please contact:
Happy Agents Pte. Ltd.
Attn: Data Protection Officer
Address: 20A Tanjong Pagar Road, Singapore 088443
Email: wimi@happyagents.io
12. International transfers
Our servers and subprocessors may be located in Singapore, the United States, the European Economic Area, the United Kingdom, and other countries. Where personal data is transferred across borders, we use appropriate safeguards required by applicable law, including the PDPA's transfer requirements and, for transfers from the EEA, UK, or Switzerland, the European Commission's Standard Contractual Clauses (and the UK International Data Transfer Addendum where applicable), together with supplementary measures where required.
13. Third-party sites and platforms
The Services may link to or interoperate with third-party websites and platforms (for example, Google Business Profile). We are not responsible for the privacy practices of those third parties. Please review their privacy notices separately.
14. Changes to this Policy
We may update this Policy from time to time. Material changes will be notified through the Services or by email before they take effect, where required by law. The "Last updated" date at the top reflects the latest version. Your continued use of the Services after a change takes effect constitutes acceptance of the updated Policy.