Trust & Privacy
How Wizer Email Security handles customer data, and the artifacts your security and legal teams can request.
Headline commitments
- No email content centralized. Email message data stays inside your tenant’s dedicated database. Wizer’s central management surface has no access to your per-row data.
- Wizer staff cannot read your message metadata. Architectural, not a policy promise. Internal access to production data is gated and logged.
- All AI usage runs under Zero-Data-Retention. Both the inline detection second-opinion and the optional admin agent route through Anthropic via the Vercel AI Gateway under a ZDR contract. Prompts and responses are not stored or used for model training. Per-row tenant data is structurally anonymized (placeholders for domains and addresses; message bodies not transmitted) before any AI call.
- Per-tenant isolation. Dedicated database, isolated credentials, separate serverless deployment, separate inbound Pub/Sub subscription. Compromise of one customer’s tenant cannot reach another.
Artifacts your security/legal team can use
Privacy Policy
Public, plain-language description of what data we handle and how.
Terms of Service
Public terms covering use, billing, termination.
Data Processing Agreement (DPA) ↓ PDF
Article-28 GDPR DPA with Annexes I/II/III. v0 draft — counter-signed copy available on request.
Security Overview ↓ PDF
One-pager designed for vendor-security questionnaires. Architecture, sub-processors, retention, controls.
Sub-processors
A sub-processor is a third party that may process personal data on our behalf to deliver Wizer Email Security. We list them below by function. The list is authoritative; we notify customers thirty (30) days in advance of any addition or replacement.
Infrastructure
| Sub-processor | Purpose | Personal data processed | Location |
|---|---|---|---|
| Vercel, Inc. | Application hosting, AI Gateway routing, encrypted file storage | Email content and metadata (encrypted at rest) | USA |
| Neon, Inc. | Per-tenant database hosting | Email metadata, encrypted message bodies, mailbox addresses | USA |
Product functionality
| Sub-processor | Purpose | Personal data processed | Location |
|---|---|---|---|
| Google LLC | Google Workspace API access to monitored mail (via customer-granted Domain-Wide Delegation) and Google Cloud Pub/Sub for inbound delivery | Mail metadata and content of monitored mailboxes | USA |
Customer management & support
| Sub-processor | Purpose | Personal data processed | Location |
|---|---|---|---|
| HubSpot, Inc. | Customer support, customer success, CRM, and sales operations | Customer and prospect account and contact data | USA |
| Twilio Inc. (SendGrid) | Transactional and customer communication emails | Customer contact email addresses | USA |
| Stripe, LLC | Payment processing and billing | Billing and payment data | USA |
Not sub-processors (no personal data). The following services support the product but never receive personal data, so they are not sub-processors:
- Anthropic PBC — AI second-opinion detection and the optional admin agent. Receives only structurally anonymized inputs (placeholders for domains and addresses; message bodies not transmitted) under a Zero-Data-Retention contract.
- Third-party web search — invoked only by the optional admin agent; anonymized queries, no personal data.
- Google Safe Browsing — URL reputation; URLs only, no message content.
- GitLab, Inc. — source-code hosting; no customer data.
Last updated: July 27, 2026.
Questions
For DPA counter-signature requests or security questions, reach out:
- Legal / DPA: legal@wizer-training.com
- Security: security@wizer-training.com