Wfolio Privacy Policy
Welcome to Wfolio. Wfolio Limited (“Wfolio,” “we,” “us,” or “our”) is a Hong Kong-based SaaS provider of a no-code website platform (wfolio.com) serving users worldwide. We respect your privacy and are committed to protecting it. This Privacy Policy explains how we collect, use, and disclose personal information in our role as a data controller, and how you can exercise your privacy rights . We comply with Hong Kong’s Personal Data (Privacy) Ordinance (PDPO) and align our practices with international standards like the EU GDPR and California CCPA . Please read this Policy carefully to understand our practices.
Scope and Our Role in Data Processing
Wfolio as Data Controller vs Processor: This Policy covers personal data for which Wfolio is the data controller – for example, information you provide when you sign up for an account or use our platform. However, when you use Wfolio to build your own website and collect personal data from your site’s visitors or clients, you are the data controller for that data, and Wfolio acts only as a data processor on your behalf . In other words, Wfolio provides the infrastructure, but you determine the purpose and means of processing any personal data collected through your site. We are not responsible or liable for how you as a user handle your own site’s visitor data . Such data processing is governed by your agreement with those individuals and (if applicable) our Data Processing Addendum, not this Privacy Policy . If you are a visitor to a website built on Wfolio, you should refer to that site owner’s privacy policy, as Wfolio has no direct relationship with you in that context .
This Privacy Policy applies when you use Wfolio’s own website, dashboard, and services, or otherwise interact directly with Wfolio. It does not apply to third-party websites, services, or integrations that you may access through Wfolio, nor to personal data you collect on sites you build with Wfolio (as noted above). We encourage our users to publish their own privacy policies on sites they create, especially if they collect personal data from visitors.
Information We Collect
We collect various types of personal data in order to provide and improve our services. The categories of information we collect include:
- Account Information: When you register or use Wfolio, we collect information you provide such as your name, email address, login credentials, contact information, profile details, and any personal details in your account settings. We also collect business information like your company/name and payment details if you subscribe to a paid plan. This information helps us create and manage your account and communicate with you.
- User Content and Client Data: If you upload or create content on our platform (e.g. images, text, portfolio data) or use Wfolio to host websites and client galleries, we process that content and any personal data it contains on your behalf. For example, when a visitor submits a form on your Wfolio site (booking request, contact form, etc.), the submitted data is stored on our servers for you . Important: In such cases you are the data controller for the visitor’s personal data, and Wfolio only processes it under your instructions as a service provider .
- Usage and Device Data: We automatically collect technical data when you interact with our platform. This includes IP addresses, device identifiers, browser type, pages visited, date/time of access, and usage logs. We use this data to analyze performance, secure our services, and understand how users navigate our platform (for example, we may track what features are most used). This information may be collected via log files, analytics tools, and cookies (described below).
- Cookies and Similar Technologies: Like most websites, we use cookies, pixels, and local storage to collect information. Cookies are small text files stored on your browser to remember your preferences and enhance your experience . For instance, cookies help with things like keeping you logged in, measuring site traffic, or remembering your language settings. Some cookies may collect data that is considered personal (such as an IP address or unique ID) . For details, see Cookies below and our Cookie Notice.
- Communications: If you contact us for support or feedback, or subscribe to newsletters, we collect the information you choose to give us (such as your name, email, and the contents of your message). We may also keep records of our correspondence with you for training and quality assurance.
- Payment Information: When you make purchases (e.g. upgrading to a paid subscription), our payment processor (such as Stripe or other third-party) will collect your payment card details and billing information on our behalf . Wfolio itself generally does not store your full credit card number, but we may retain limited payment info (like the last four digits of your card, billing address, transaction IDs) and subscription history for invoicing, record-keeping, and fraud prevention.
Note: We do not knowingly collect personal information from children under the age required by applicable law (for example, 13 in the US, 16 in the EU). Our platform and services are intended for use by adults. If we learn that a child’s personal data has been provided to us without parental consent, we will take steps to delete it.
How We Use Personal Data
We use the collected information for the following purposes, relying on one or more lawful bases as appropriate (such as your consent, necessity to perform a contract, our legitimate interests, or legal obligations ):
- Provide and Maintain Our Services: We use data to create and secure your account, provide the functionality of our website builder and cloud services, host your content, process transactions, and enable features you request. This processing is generally necessary to perform our contract with you (i.e. our Terms of Service) or to take steps at your request before entering a contract . For example, we must use your registration and payment details to set up your account and keep your website online.
- Communicate with You: We use contact information (like your email or phone) to send service-related communications, such as confirmations, invoices, technical notices, updates, security alerts, and administrative messages. We may also send you marketing or promotional emails about new features or content if you have opted-in or if otherwise permitted. The legal basis for communications may be contract necessity (for service messages) or your consent (for marketing, where required) . You can opt out of marketing emails at any time. We will not send you marketing communications if you tell us you don’t want them.
- Improve and Personalize the Service: We analyze usage and feedback to understand how our users interact with Wfolio, so we can troubleshoot issues, make improvements, and develop new features. This analysis may include reviewing aggregated usage logs, cookie data, and user feedback. We may also personalize your experience, for example by remembering your preferences or suggesting relevant features. We rely on our legitimate interests in running and improving our business for this processing, ensuring that our interests are balanced against your privacy rights .
- Security and Fraud Prevention: We process data (such as IP addresses, device information, and account activity) to secure our platform, verify accounts, detect and prevent fraudulent activity, abuse, and other harmful behavior . This is in our legitimate interests to protect the security of our services and users. We also may process data as necessary to comply with legal obligations related to security (e.g., maintaining records of consents or logging accesses for security audits).
- Legal Compliance: We will use or disclose personal information where necessary to comply with legal obligations. For instance, we may keep transaction records for tax and accounting purposes, or disclose data in response to lawful requests by public authorities (such as court orders or to meet national security or law enforcement requirements). If we process your data to comply with a law (e.g. GDPR or PDPO requirements), that legal requirement is our basis.
- Other Purposes with Consent: If we ever need to process your personal data for a purpose that is not covered above, we will obtain your consent if required by law. Where consent is our legal basis, you have the right to withdraw it at any time .
We do not use personal data for any purposes that are incompatible with the above. In particular, we do not sell your personal information to data brokers or third parties for monetary gain or share it for targeted advertising purposes . If this policy changes in the future, we will update this Policy and provide any required notices or opt-out options.
Cookies and Tracking Technologies
Wfolio uses cookies and similar tracking technologies to provide and optimize our services:
- Types of Cookies: We employ both essential cookies (necessary for our site to function, e.g. for login security or user input preferences) and non-essential cookies (used for analytics, performance, and personalization). For example, we use analytics cookies to collect statistical information about how visitors use our site, which helps us improve the user experience. Cookies help remember your settings and improve site loading speed .
- Cookie Consent: Where required by law (such as in the EU/UK), we will obtain your consent before using non-essential cookies on your device . You will see a cookie banner or similar mechanism when you first visit our site, allowing you to accept or manage your cookie preferences. You can change your cookie settings at any time via our Cookie Notice/Consent Manager or by adjusting your browser settings to delete or block cookies. Please note that if you disable certain cookies, some features of our service may not function properly.
- Other Tracking: We may use local storage, pixels, or similar technologies for the purposes described in this Policy . For instance, pixels or script integrations from third-party analytics or advertising partners (like Google Analytics, etc.) may be present, which can set their own cookies. Such third-party technologies are subject to those providers’ privacy policies, and we will inform you of these in our Cookie Notice. We do not allow third parties to collect your personal data from our site for their own marketing purposes without your consent.
For more details, please see our Cookie Notice, which provides a detailed list of cookies and your choices. By continuing to use our site with cookies enabled, you agree to our use of cookies as described in that notice. You can always withdraw or modify your consent using the cookie settings tool on our website.
How We Share and Disclose Information
We understand the importance of your personal data and only share it in a few circumstances, each with appropriate safeguards. We do not disclose your personal data to third parties for their independent marketing or advertising purposes without your consent. Situations in which we may share data include:
- Service Providers: We use trusted third-party companies to perform certain business-related functions necessary for our service (“processors” or service providers). Examples include cloud hosting providers (to store data and keep Wfolio running), email delivery services, analytics providers, payment processors, customer support tools, and other IT or business consultants. These parties will have access to or process personal data only as needed to perform tasks on our behalf and in compliance with this Privacy Policy and applicable law. We contractually require service providers to safeguard personal data and prohibit them from using it for any unrelated purposes.
- Legal Requirements and Safety: We may disclose personal information when required to do so by law or in a good-faith belief that such action is necessary to comply with a legal obligation, regulation, or governmental request . We may also share information in order to enforce our Terms of Service or other agreements, or investigate potential violations . This includes exchanging information with law enforcement or other companies and organizations for fraud prevention and credit risk reduction. Additionally, if we believe disclosure is appropriate to protect the rights, property, or safety of Wfolio, our users, or the public, we may share data (for example, reporting suspected misuse of our platform or addressing security threats) .
- Business Transfers: If Wfolio undergoes a business transaction such as a merger, acquisition, corporate reorganization, or sale of some or all assets, personal data may be transferred to the acquiring or successor entity as part of that deal . If such a transfer occurs, we will ensure that your personal data remains subject to confidentiality obligations and we will provide notice (e.g., via email or prominent notice on our site) before any personal data is transferred or becomes subject to a different privacy policy .
- Your Own Use and Instructions: If you integrate third-party services with Wfolio (for example, adding a third-party plugin, or connecting an email marketing service), or if you direct us to share data (e.g., when you export your data or use our API to send data to another service), we will share information at your direction. Note: Any personal data that you choose to make publicly available on your Wfolio-built site (such as in a public portfolio or blog) will, by nature, be visible to others; please exercise caution when posting personal content publicly.
- With Your Consent: In cases other than the above, if we want to share your information with third parties, we will obtain your explicit consent. For example, if we ever contemplate sharing data with a partner for their own purposes, we would let you know and give you the choice to opt-in or opt-out.
Except for the circumstances above, Wfolio will not disclose your personal data to third parties without your consent or unless permitted/required by law . We do not sell personal data to third parties. We also do not share your personal information for targeted advertising or profiling in a way that constitutes a “sale” or “sharing” under the CCPA; thus, we do not provide a “Do Not Sell My Info” link (because we don’t engage in those practices) .
International Data Transfers
Wfolio is a global service – as such, your personal data may be transferred to or stored on servers in multiple countries, including outside of your home jurisdiction. Primarily, data we collect will be stored in Hong Kong (where we are based) and/or in other locations where our service providers operate data centers (for example, United States, European Union, or other regions). This means your information could be processed outside of your country and outside of the European Economic Area (EEA) if you are an EU user.
Whenever we transfer personal data across borders, we take steps to ensure appropriate safeguards are in place to protect it. If you are in the EU/UK or another region with data transfer restrictions, we rely on approved transfer mechanisms to legally transfer data to countries that may not have the same level of data protection. These can include:
- Standard Contractual Clauses: We incorporate the European Commission’s Standard Contractual Clauses (SCCs) for data transfers, which are legal contracts that require recipients in non-EU countries to protect European personal data to EU standards . For example, when we use a U.S.-based cloud provider to store EU data, we have an SCC in place with them to safeguard that data.
- Adequacy and Frameworks: Where applicable, we may transfer data to jurisdictions that the European Commission or relevant authority has deemed to have an “adequate” level of data protection. In some cases, we may also rely on certifications or frameworks (for instance, the EU-U.S. Data Privacy Framework for transfers to the United States, if our service providers are certified under it ).
- Hong Kong and Other Laws: Transfers of personal data from Hong Kong are handled in compliance with the PDPO and any guidelines from Hong Kong’s Privacy Commissioner. We also comply with other local transfer requirements as needed.
Regardless of where your data is processed, we will protect it with appropriate technical, organizational, and contractual measures. We understand that privacy laws in some countries may not be as strict as those in your own country; in all cases, we will treat your personal information in line with this Privacy Policy. If you have questions about international data transfers or need more information about the safeguards we use, please contact us.
Data Retention
We retain personal data only for as long as necessary to fulfill the purposes outlined in this Policy, unless a longer retention period is required or permitted by law. In general:
- If you have a Wfolio account, we keep your personal information for as long as your account is active. This allows us to provide the service to you. If you delete your account or it becomes inactive, we will initiate deletion of or anonymize your personal data within a reasonable period, except as noted below.
- We may retain certain data for a longer period as needed to comply with legal obligations or protect our legitimate interests. For example, we might retain transactional records and invoices for accounting/tax purposes, or logs and backup copies for security, fraud prevention, and dispute resolution. Similarly, if you asked us to delete something, we may keep a record of your request and our response. We will also retain information as necessary to resolve disputes, enforce our agreements, or comply with regulatory requirements.
- Some usage data and analytics may be retained in aggregate form (after removing personal identifiers) for internal analysis. We strive to set retention and deletion schedules that meet business needs while respecting privacy. For instance, basic web logs and analytics might be kept for a set period (e.g. 12–24 months) before automatic deletion , unless we need to preserve them for security audits.
When we have no ongoing legitimate need or legal requirement to keep your personal data, we will either delete it or anonymize it so that it can no longer be associated with you. If deletion or anonymization is not immediately possible (for example, because the data is stored in backups), we will securely store the data and isolate it from any further use until deletion is feasible.
Your Choices: If you wish to close your account or request deletion of certain data, you can do so through your account settings or by contacting us (see Contact Us below). We will make good faith efforts to honor your request within the timelines required by law. Note that we may ask you to verify your identity before deleting your data, and certain information may be retained as explained above.
Security Measures
We take security seriously and have implemented administrative, technical, and physical safeguards to protect your personal information from unauthorized access, loss, misuse, or alteration . These measures include, for example:
- Encryption of data in transit (e.g., using HTTPS/TLS protocols for our website) and, where applicable, encryption of data at rest.
- Secure server infrastructure and firewalls to prevent external attacks. Our servers are maintained in controlled facilities, and we limit access to personal data to authorized personnel who need it to operate our services.
- Regular security assessments and updates. We monitor for potential vulnerabilities and attacks, and we update our software and protocols to address emerging threats. We may also employ third-party security tools or conduct penetration testing to strengthen our defenses.
- Access Controls: Wfolio staff and contractors are bound by confidentiality obligations. We restrict internal access to personal data on a need-to-know basis, ensuring that employees or service providers only access the data necessary for their role. All staff are trained on data protection best practices.
- Incident Response: We have an incident response plan for managing suspected data breaches. In the event of a security incident affecting your personal data, we will notify you and/or the relevant authorities as required by law.
While we strive to protect your information, no method of transmission over the Internet or electronic storage is 100% secure. Therefore, we cannot guarantee absolute security of your information . For example, emails or other communications you send us may not be fully secure if your own security measures are compromised. You are responsible for keeping your account credentials safe and for any activity using your login. Please choose a unique, strong password and do not share it with others. If you believe your account or data may have been compromised, contact us immediately.
By using Wfolio, you acknowledge that you understand these security risks and limitations. We will continue to update and improve our security practices over time. For more information on our security measures, you can visit our Security page or contact us with specific questions.
Your Rights and Choices
Depending on your location and applicable data protection laws, you have certain rights regarding your personal data. Wfolio is committed to honoring these rights and providing you control over your information, as summarized below:
- Access and Portability: You have the right to request a copy of the personal data we hold about you , and to obtain it in a structured, commonly used format (where required by law) . This allows you to see what data we have and to transfer it to another provider if needed.
- Rectification: If any of your personal information is inaccurate or incomplete, you have the right to ask us to correct or update it . You can also review and update most of your account information directly by logging into your Wfolio account.
- Erasure: You can request that we delete your personal data under certain circumstances – for example, if the data is no longer necessary for the purposes it was collected, or if you withdraw consent (where we relied on consent) and we have no other legal basis to continue processing. We will honor valid deletion requests to the extent required by law (“right to be forgotten”). Keep in mind there are exceptions – we might retain data if needed for legal obligations or legitimate interests (we will inform you if so).
- Restriction of Processing: You have the right to ask us to restrict or pause the processing of your data in certain situations . For instance, if you contest the accuracy of your data, you can request we restrict processing until the issue is resolved; or if you object to our processing, we may need to verify whether our grounds override yours.
- Objection to Processing: You may object to our processing of your personal data when we base it on legitimate interests . If you object, and the processing is for non-marketing purposes, we will evaluate whether our legitimate grounds for processing outweigh your rights; if not, we will cease the processing. You also have an absolute right to object to direct marketing – if we send marketing emails, you can opt out at any time and we will stop.
- Withdraw Consent: Where we rely on your consent to process personal data (e.g. for optional marketing or certain cookie uses), you can withdraw that consent at any time . This will not affect the lawfulness of processing that occurred before your withdrawal. If you withdraw consent for a specific feature or service, we may not be able to provide that feature, but we will continue to offer our core services as applicable.
- Non-Discrimination: Wfolio will not discriminate against you for exercising any of these rights . For example, we won’t deny you service or charge different prices just because you made a privacy request. Our service offerings to you remain the same whether or not you choose to exercise your privacy rights.
These rights may have certain conditions or limitations under law. For example, we might not be able to delete data that we are legally required to keep, or we may decline to comply with a request if it adversely affects the rights and freedoms of others. If we refuse any request, we will explain our reasons in our response.
How to Exercise Your Rights: You can exercise your rights at any time by contacting us (see Contact Us below). We may need to verify your identity (to protect your privacy) before fulfilling certain requests, such as access or deletion requests . Verification might involve confirming information we already have on file or asking for additional identification. We will respond to your request within the timeframe required by the applicable law (for example, under GDPR, typically within 1 month; under CCPA, within 45 days with possible extension). There is no fee for making a request, unless it is manifestly unfounded or excessive, in which case we may charge a reasonable fee or decline the request as allowed by law.
Additional Rights for California Residents: If you are a California resident, the California Consumer Privacy Act (CCPA), as amended by the CPRA, provides some additional rights: the right to know what personal information we collect and how we use/disclose it, the right to delete personal information (with certain exceptions), the right to correctinaccurate personal information, the right to opt-out of the “sale” or “sharing” of personal information, and the right to non-discrimination for exercising these rights . We have outlined many of these above. Notably, as stated, Wfolio does not sell or share personal data in the manner defined by CCPA, so the opt-out right may not be applicable in practice . If you have any questions about your California privacy rights or want to exercise them, you can contact us through the methods below. We may provide a designated web form or a toll-free number for CCPA requests, as required by law, and will need to verify your California residency and identity. You may also designate an authorized agent to make requests on your behalf in accordance with CCPA.
Finally, if you believe we have handled your personal data in violation of applicable law, you have the right to lodge a complaint with a supervisory authority (such as an EU Data Protection Authority, or the Hong Kong Privacy Commissioner, or your local regulatory agency) . We would, however, appreciate the chance to address your concerns first. We commit to resolve privacy complaints directly and efficiently. Please feel free to reach out to us with any concerns, and we will do our best to assist you.
Limited Liability and Compliance
Limited Liability for User-Controlled Data: As noted, Wfolio’s role for data your end-users provide on your sites is that of a processor. We are not responsible for and will not be held liable for your own data protection obligations towards your customers or site visitors . You are responsible for complying with privacy laws as a data controller in those circumstances, including providing appropriate notices and obtaining any necessary consents from your site’s users. Wfolio provides tools (like the ability to add a custom Privacy Policy or Cookie Banner to your site) to help you in this regard , but the content and lawfulness of those notices are up to you. We encourage you to consult a legal advisor to ensure your use of our platform is compliant with all applicable laws in your jurisdiction.
Compliance with Laws: Wfolio Limited is governed by the laws of Hong Kong, and we operate in accordance with the PDPO and other Hong Kong regulations. However, we recognize the importance of global privacy standards and strive to meet or exceed them. In practice, we align our data practices with key principles from laws like the GDPR (Europe), CCPA (California), and similar frameworks . This means we aim to offer strong privacy protections for all our users, regardless of location, and adjust our policies as needed to remain compliant when laws change. If any provision of this Policy conflicts with a legal requirement applicable to you, we will follow the law and revise our practices accordingly.
This Privacy Policy is not a contract and does not create any direct rights or obligations beyond those in applicable privacy laws. Rather, it is a transparency document that we provide in good faith. Our liability for any issues arising from this Policy or our handling of personal data is limited and governed by our Terms of Service and applicable law. By using Wfolio, you agree that any dispute over privacy or the terms of this Policy will be subject to the Governing Law and dispute resolution clauses in our Terms (which generally designate Hong Kong law and jurisdiction) , to the extent permitted by law.
Updates to this Privacy Policy
We may update or revise this Privacy Policy from time to time to reflect changes in our practices, technologies, legal requirements, or for other operational reasons. If we make material changes to how we handle your personal data, we will provide prominent notice – for example, by posting the updated policy on our website and updating the “Last Updated” date at the top, or by emailing you if appropriate . We encourage you to review this page periodically for the latest information on our privacy practices.
Your continued use of Wfolio after any changes to this Privacy Policy constitutes your acknowledgment of the changes and your agreement (to the extent allowed by law) to be bound by the updated Policy . If you do not agree with any changes, you should discontinue use of our services and you may request that we delete your data.
Contact Us
If you have any questions, concerns, or requests regarding this Privacy Policy or about how Wfolio handles your personal data, please do not hesitate to contact us. We are here to help.
Wfolio Limited (Hong Kong) – Privacy Team
Address: Unit 1603, 16th Floor, The L. Plaza, 367-375 Queen’s Road Central, Sheung Wan, Hong Kong
Email: privacy@wfolio.com
WhatsApp: +1 (585) 866-1000
We will respond to your inquiries as soon as possible, and at most within any timeline required by law.
Thank you for trusting Wfolio with your personal data. We value your privacy and are committed to safeguarding it in all aspects of our service.