Last updated: April 25, 2026, 12:09
This Privacy and Data Processing Policy governs the way in which Wilki.ai, a platform operated by CV Software ("Wilki", "we", "us", "our platform"), accesses, collects, stores, processes, protects, and uses the data that its customers and users authorize to be processed through the platform.
Wilki is a data integration, processing, analytics, and intelligence platform that allows customers to connect different sources of information, including external platforms, proprietary systems, APIs, files, databases, legacy systems, or other authorized sources, with the purpose of transforming operational data into reports, alerts, analyses, indicators, recommendations, automations, and actionable insights.
Because Wilki may require access to data from third-party platforms or internal customer systems in order to fulfill its purpose, this Policy seeks to clearly and transparently state what data is processed, under what authorization, for what purpose, for how long, with what security measures, and what the rights and responsibilities of each party are.
1. General principle of express authorization
Wilki only accesses customer data, user data, or third-party platform data when the customer has previously granted express, valid, and sufficient authorization for such access.
Wilki accesses data only when the customer:
- Contracts, enables, or configures the use of the Wilki platform.
- Authorizes the connection between Wilki and one or more data sources.
- Provides credentials, tokens, API keys, OAuth authorizations, files, endpoints, permissions, or other access mechanisms.
- Represents that it has the necessary authority to allow Wilki to access, read, process, and store such data for the purposes of the service.
Wilki does not obtain data from customer platforms without authorization and does not perform hidden, non-consented, or out-of-scope connections.
2. Read-only access to source data
Unless the parties expressly agree in writing to a different feature, Wilki accesses the customer's data sources only in read mode.
This means that Wilki:
- Reads data from the platforms, systems, APIs, or files authorized by the customer.
- Processes such data within its own technology infrastructure.
- Generates reports, alerts, analyses, indicators, recommendations, and other derived results.
- Does not modify, edit, delete, replace, overwrite, or alter existing data in the customer's source platforms.
The customer must understand that Wilki does not act as the primary transactional system or as a replacement for the source platforms. Source platforms remain the responsibility of their respective providers or administrators.
3. Need for access and storage to provide the service
For Wilki to process, analyze, and generate value from the customer's data, the platform must be able to access that data and, in many cases, store a copy of it in its own infrastructure.
The customer acknowledges and accepts that Wilki cannot analyze, process, compare, enrich, interpret, generate reports, apply artificial intelligence, or produce recommendations on data to which it does not have access.
For this reason, by enabling an integration, uploading information, or authorizing a data source, the customer authorizes Wilki to:
- Read data from the authorized source.
- Extract a copy of such data.
- Store that copy in Wilki's infrastructure or that of its technology providers.
- Process, normalize, transform, structure, combine, and enrich the data.
- Generate derived information, such as metrics, dashboards, reports, alerts, historical comparisons, recommendations, and automated analyses.
- Apply statistical models, business rules, algorithms, or artificial intelligence tools when they are part of the contracted or enabled features.
4. Types of data Wilki may process
Depending on the integrations and features contracted, Wilki may process different categories of data, including, among others:
- Operational data from the customer's business.
- Sales, consumption, transaction, or commercial movement data.
- Inventory, stock, product, machine, location, route, store, or point-of-sale data.
- Data about customers, providers, users, operators, employees, or other persons related to the customer's operation, when such data is contained in authorized sources.
- Historical data needed for comparative analyses, trends, and prediction.
- Technical integration data, such as platform identifiers, endpoints, connection logs, synchronization statuses, processing errors, and metadata.
- Data derived or calculated by Wilki from the original data.
Wilki recommends that customers avoid connecting or uploading information that is not necessary for the contracted purposes, especially if it contains sensitive personal data, highly confidential financial data, health data, biometric data, credentials, identity documents, or other specially protected information, unless there is a legitimate need, sufficient authorization, and appropriate configuration.
5. Purposes of data processing
Wilki will process customer data exclusively for the following purposes:
- Provide, operate, maintain, and improve the Wilki platform.
- Execute integrations authorized by the customer.
- Read, copy, store, normalize, transform, and process data from authorized sources.
- Generate reports, dashboards, alerts, indicators, historical analyses, and recommendations.
- Allow data queries through web interfaces, APIs, connectors, artificial intelligence agents, or other mechanisms enabled by the customer.
- Detect anomalies, trends, opportunities, inconsistencies, operational errors, or relevant events in the customer's information.
- Provide technical support, maintenance, monitoring, and incident resolution.
- Audit the operation of integrations, processes, and data loads.
- Comply with legal, contractual, regulatory obligations, or valid requirements from competent authorities.
- Protect the security, availability, integrity, and operational continuity of the platform.
Wilki will not use customer data for purposes unrelated to the contracted service, unless expressly authorized by the customer or required by applicable law.
6. Storage of data copies
Wilki stores copies of data read from authorized sources in order to fulfill the purposes of the service.
These copies may be necessary for:
- Local processing of information.
- Consolidation of data from multiple platforms.
- Generation of historical indicators.
- Comparison between periods.
- Detection of changes, differences, or anomalies.
- Training or execution of internal analytical models for the customer, when applicable.
- Availability of reports and dashboards without depending in real time on source platforms.
- Operational continuity in the face of outages, limits, or restrictions of external APIs or systems.
The customer acknowledges that storing copies of data is an essential part of Wilki's architecture and operation.
7. Retention period and deletion of data
Data will be retained for the period defined in the account configuration, contract, service order, applicable retention policy, or instructions agreed with the customer.
When no specific period has been agreed, Wilki may retain data for as long as reasonably necessary to provide the service, comply with contractual obligations, resolve incidents, maintain operational backups, comply with legal obligations, or protect its rights.
Wilki may apply retention policies based on age, volume, type of data, contracted plan, customer configuration, or technical needs of the platform.
Upon expiration of the applicable retention period, Wilki may delete, anonymize, aggregate, or stop processing the data, as technically and contractually appropriate.
The customer may request data deletion, subject to:
- Current legal or contractual obligations.
- The need to retain minimum records for audit, security, billing, or compliance.
- Reasonable technical times required to delete data from active systems, backups, logs, or distributed storage.
8. Credentials, tokens, and authentication methods
Wilki will use the authentication methods supported by each platform, system, or data source, such as API keys, OAuth, technical users, tokens, certificates, integration keys, secure files, or other mechanisms.
The customer is responsible for:
- Providing valid and sufficient credentials.
- Keeping them updated.
- Revoking them when appropriate.
- Configuring minimum necessary permissions when the source platform allows it.
- Reporting any suspicion of compromise, leakage, or unauthorized use.
Wilki will seek to protect integration credentials through reasonable security measures and restrict internal access.
9. Secure credentials and scope of permissions granted by the customer
The customer is responsible for generating, configuring, managing, and providing Wilki with the credentials, tokens, API keys, technical users, permissions, or access mechanisms needed to connect the authorized data sources.
Wilki strongly recommends that such credentials be configured under the principle of least privilege and, whenever the external platform allows it, with read-only permissions.
Wilki does not require administrative credentials, write permissions, modification permissions, deletion permissions, or access that allows alteration of the customer's source data. The purpose of the credentials provided to Wilki is to allow reading, extraction, and retrieval of data for subsequent storage, processing, and analysis within the Wilki platform.
It is the customer's sole responsibility to define the type of role, scope, permissions, and level of access associated with the credentials that it provides or enables for Wilki. If the customer provides credentials with permissions beyond what is necessary, including administrative, modification, write, or deletion permissions, that will be the customer's responsibility.
CV Software and the Wilki platform expressly recommend that customers provide only secure, controlled, traceable credentials with read-only access.
10. Information security
Wilki will implement reasonable technical, organizational, and administrative measures to protect customer data against unauthorized access, loss, destruction, alteration, improper disclosure, or malicious use.
These measures may include, as applicable:
- Internal access controls.
- User authentication and authorization.
- Permission management by account, role, or profile.
- Encryption in transit through secure protocols.
- Encryption or protection mechanisms at rest when applicable.
- Monitoring of systems and integrations.
- Logging of events, errors, and technical activity.
- Logical separation of data between customers.
- Use of trusted technology providers.
- Backups and operational continuity measures.
- Secure development best practices.
- Restriction of personnel access to customer data under operational need criteria.
Notwithstanding the above, the customer acknowledges that no computer system, cloud platform, integration, API, or internet-connected network can guarantee absolute security. Wilki will make reasonable and commercially appropriate efforts to protect data, but cannot ensure that a security incident will never occur.
11. Confidentiality
Wilki will treat customer data as confidential information.
Wilki will not sell, lease, assign, commercialize, or share customer data with third parties for its own or others' commercial purposes.
Internal access to customer data will be limited to persons who reasonably need such access to operate, maintain, improve, audit, or provide support for the platform, and will be subject to confidentiality obligations.
12. No sharing of data with third parties
Wilki will not share customer data with third parties, except in the following cases:
- When necessary to provide the contracted service, for example through cloud infrastructure, storage, communications, monitoring, technical analytics, support, or other essential technology providers.
- When the customer expressly authorizes it.
- When required by a competent authority, court, legal rule, or valid procedure.
- When necessary to protect rights, security, operational continuity, or prevent fraud, abuse, or incidents.
- When the data has been anonymized or aggregated so that it does not allow identification of the customer or specific or identifiable natural persons.
- When the customer expressly enables integrations with external artificial intelligence tools, agents, or platforms, in which case the information necessary to provide the requested feature may be made available to those tools, in accordance with this Policy and the configuration authorized by the customer.
Technology providers that may participate in the provision of the service must act under Wilki's instructions and under reasonable confidentiality and security conditions.
13. Use of artificial intelligence and automated analysis
Wilki may use automated analysis techniques, statistical models, business rules, algorithms, and artificial intelligence to process customer data and generate reports, recommendations, alerts, summaries, classifications, predictions, or other results.
Artificial intelligence will be used only on data that Wilki has been authorized to access and always for purposes linked to the service contracted or enabled by the customer.
Unless expressly authorized by the customer, Wilki will not use individualized customer data to train public, general, or third-party models that may benefit other customers or reveal customer information.
Results generated by artificial intelligence or automated analysis must be understood as decision-support tools. The customer is responsible for reviewing, validating, and deciding whether to use such results in its operation.
14. Integration with external artificial intelligence tools and agents
Wilki may allow integration with external artificial intelligence tools, assistants, models, or agents, such as ChatGPT, Claude, or other similar platforms, including mechanisms such as MCP or other interoperability protocols that allow querying, analyzing, or interpreting data available in Wilki.
When the customer enables, configures, or uses these integrations, the customer authorizes Wilki to make certain information, data, queries, results, metadata, or responses generated by the platform available to such external tools or agents, exclusively to the extent necessary to allow the analysis, interpretation, generation of insights, executive summaries, recommendations, or decision-support requested by the customer or its authorized users.
Wilki will seek to ensure that such access is limited to the scope authorized by the customer, the corresponding permission configuration, and the service's own purposes. However, the customer acknowledges that external artificial intelligence tools or agents may be operated by third parties other than CV Software and Wilki, and that their use may be subject to terms, conditions, privacy policies, technical configurations, and data processing rules of those third parties.
The customer is responsible for deciding which external artificial intelligence tools it enables, which users it authorizes to use them, what data it allows to be queried through them, and under what conditions it uses them.
Unless expressly authorized by the customer, Wilki will not use individualized customer data to train public, general, or third-party models that may benefit other customers or reveal customer information.
15. Customer responsibility for authorizations
The customer represents and warrants that:
- It has the necessary authority to authorize Wilki to access, read, copy, store, and process data from connected sources.
- It has the right to provide or enable credentials, tokens, API keys, users, files, or integration mechanisms.
- It has obtained, when applicable, the necessary consents, authorizations, or legal bases regarding personal data or third-party information included in connected sources.
- The information provided to Wilki does not infringe third-party rights, confidentiality obligations, contracts, laws, regulations, or external platform policies.
- It will keep permissions, credentials, and configurations needed for the operation of integrations updated.
- It will promptly inform Wilki if an authorization must be revoked, modified, or limited.
Wilki will not be responsible for accesses or processing carried out in accordance with permissions, credentials, or authorizations provided by the customer, except in the event of Wilki's direct breach of its legal or contractual obligations.
16. Personal data
When the data processed by Wilki includes personal data, Wilki and the customer must comply with the applicable regulations on personal data protection, including current Chilean law and any law that enters into force in the future.
In general terms, the customer is responsible for determining the lawfulness, purpose, scope, and legal basis for the processing of personal data that it authorizes Wilki to process.
Wilki will act, as applicable, as technology provider, data processor, agent, processor, or equivalent figure, to the extent that it processes personal data on behalf of the customer and under the customer's instructions.
If Wilki determines its own processing purposes for certain data, it may assume the legally applicable role with respect to that specific processing.
17. Rights of personal data subjects
When legally applicable, personal data subjects may exercise the rights recognized by applicable regulations, such as access, rectification, cancellation, objection, erasure, portability, blocking, or other rights that may apply.
Because many personal data processed by Wilki come from sources controlled by the customer, data subject requests may be referred to the customer when the customer is the main controller of the processing.
Wilki will reasonably cooperate with the customer to respond to data subject requests, to the extent that such cooperation is technically possible and within the scope of the contracted service.
18. Security incidents
If Wilki detects a security incident that significantly affects the confidentiality, integrity, or availability of customer data, Wilki will adopt reasonable measures to:
- Assess the nature and scope of the incident.
- Mitigate its effects.
- Protect operational continuity.
- Inform the customer when legally or contractually required.
- Cooperate with reasonable investigation, containment, and remediation actions.
The customer must cooperate promptly when the incident originates from or relates to credentials, configurations, systems, or decisions under its control.
19. International transfers
Wilki may use infrastructure, storage, processing, communications, monitoring, or other technology providers located in Chile or abroad.
Accordingly, customer data may be processed or stored in jurisdictions other than the customer's jurisdiction, always under reasonable security, confidentiality, and compliance measures.
When applicable regulations require specific requirements for international transfers of personal data, Wilki will seek to adopt the corresponding contractual, technical, or organizational mechanisms.
20. Aggregated, anonymized, or statistical data
Wilki may generate aggregated, anonymized, or statistical information about platform use, technical performance, general trends, operating metrics, or integration operation.
Such information must not allow direct identification of the customer, its end users, or specific or identifiable natural persons.
Wilki may use this information to improve its services, develop new features, measure performance, prevent errors, optimize costs, train non-individualized internal models, or communicate general platform metrics.
21. Changes to this Privacy Policy
Wilki may modify this Privacy Policy to reflect legal, technical, commercial, operational, or security changes.
When changes are relevant, Wilki will seek to inform the customer through the platform, email, or another reasonable means.
Continued use of the platform after the changes have been communicated will constitute acceptance of the updated version, unless applicable law requires a different mechanism.
22. Contact
For questions, requests, or matters related to privacy, security, or data processing, the customer may contact Wilki through:
Contact email: [email protected]