Privacy Policy
This Privacy Policy explains how Wobidobi LLP (“Wobidobi,” “we,” “us,” or “our”) collects, uses, discloses, stores, and protects personal information when you visit wobidobi.com, create an account, use our form and survey software, contact support, or otherwise use our services (collectively, the “Service”). It also explains the choices and privacy rights available to you.
1. Who is responsible for your information
Wobidobi LLP, 1A Toporkova Street, room 4, Rudny, Republic of Kazakhstan, 111500, is the data controller for personal information used to operate accounts, provide the Service, manage our customer relationships, secure the platform, and communicate with you.
Customers can use the Service to create forms and collect responses. For personal information submitted to a customer-created form, the customer or workspace owner normally determines why and how that information is processed and acts as the controller or “business.” Wobidobi processes that information on the customer’s behalf as a processor or “service provider.” If you are a form respondent, please also contact the form owner about its privacy practices and your rights. This Policy does not replace the form owner’s privacy notice.
2. Personal information we collect
Depending on how you interact with the Service, we collect the following categories:
- Registration and account information. When you register directly, we collect your first name, last name, and email address. We also process your password in hashed form; we do not store the readable password.
- Social sign-in information. If you use an enabled social login provider, we may receive your provider identifier, name, email address, and other profile information that you authorize the provider to share. We do not store social-provider access tokens for ongoing use.
- Workspace and profile information. We collect workspace names, member roles, branding and domain settings, billing contacts, plan selections, and the preferences and settings you choose.
- User content and form data. We process the forms, questions, templates, files, invitations, respondent identifiers, responses, partial responses, and other content that users submit to or collect through the Service. The content of a customer-created form is determined by that customer and may include personal information not otherwise listed here.
- Transaction and subscription information. We receive transaction identifiers, customer and subscription identifiers, purchased plan, price, currency, status, invoice or receipt references, and refund or cancellation status from Paddle. We do not receive or store full payment-card numbers.
- Support and communications. We collect your name, email address, subject, message, and related correspondence when you contact us, together with information you choose to include.
- Device, log, and usage information. We may collect IP address, browser type, device and operating-system information, timestamps, requested URLs, referring pages, authentication and security events, cookie or session identifiers, form-visit events, and information about how features are used.
- Information from third parties. We may receive information from workspace administrators, identity providers, Paddle, integration providers, fraud-prevention services, and other users when necessary to provide the Service.
Please do not submit highly sensitive information to the Service unless it is necessary, permitted by your plan, and you have a lawful basis and appropriate safeguards. Customers are responsible for configuring their forms and deciding what information to request from respondents.
3. Sources of personal information
We collect personal information:
- directly from you when you register, configure the Service, submit a form, make a purchase, or contact us;
- automatically from your browser or device when you use the Service;
- from customers and workspace administrators who invite users or upload respondent information;
- from Paddle in connection with purchases and subscriptions; and
- from identity, integration, infrastructure, and security providers used at your request or to operate the Service.
4. How and why we use personal information
We use personal information to:
- create, verify, authenticate, and maintain accounts;
- provide forms, workspaces, templates, analytics, exports, billing features, and customer support;
- process customer instructions and host customer content and form responses;
- administer subscriptions, reconcile transactions, manage entitlements, and assist with cancellations and refunds;
- send service, verification, security, billing, and support communications;
- monitor reliability, troubleshoot errors, measure product usage, and improve the Service;
- detect, investigate, and prevent fraud, abuse, security incidents, and violations of our Terms;
- comply with legal obligations and valid requests from public authorities; and
- establish, exercise, or defend legal claims and protect the rights and safety of users, third parties, and Wobidobi.
Where the General Data Protection Regulation (“GDPR”), UK GDPR, or similar law applies, our legal bases are: performance of a contract or steps requested before entering a contract; compliance with legal obligations; our legitimate interests in operating, securing, and improving the Service and managing our business, balanced against your rights; consent where we specifically request it; and protection of vital interests in an emergency. When we process form data solely on a customer’s instructions, the customer determines the applicable legal basis.
5. Paddle and third-party payment processing
Paddle.com is our online reseller and Merchant of Record. Payment information, including card or other payment-method details entered at checkout, is collected and processed directly by Paddle, not by Wobidobi. Paddle acts as a third-party payment processor and, for buyer and transaction data it processes as Merchant of Record, may also act as an independent controller with its own legal obligations. Its processing is governed by the Paddle Privacy Notice. We receive only the transaction, customer, subscription, tax, and status information reasonably needed to provide access, maintain billing records, handle support, and reconcile refunds and cancellations.
6. How we disclose personal information
We disclose personal information only as reasonably necessary to:
- Service providers. Hosting, database, object-storage, backup, email-delivery, customer-support, security, anti-abuse, authentication, and infrastructure providers process information for us under contractual restrictions.
- Paddle. We exchange buyer, transaction, subscription, and support information with Paddle for checkout, tax, fraud prevention, receipts, billing, cancellations, and refunds.
- Identity and integration providers. If you choose social sign-in or enable an integration, we share the information needed to complete your instruction with that provider.
- Customers and workspace administrators. A workspace owner and its authorized members can access information, content, and activity associated with that workspace. Form owners can access responses submitted to their forms.
- Professional advisers. Lawyers, accountants, auditors, insurers, and similar advisers may receive information subject to professional or contractual confidentiality duties.
- Legal and safety recipients. We may disclose information when reasonably necessary to comply with law or legal process, respond to lawful public-authority requests, enforce agreements, investigate abuse, or protect rights, safety, and security.
- Business transfers. Information may be disclosed in connection with due diligence, financing, a merger, acquisition, reorganization, bankruptcy, or sale of some or all assets, subject to appropriate confidentiality and notice where required.
We do not sell personal information for money. We do not share personal information for cross-context behavioral advertising, and we have not sold or shared personal information in that manner during the preceding 12 months. We do not use sensitive personal information to infer characteristics about individuals.
7. Cookies and similar technologies
We use cookies and similar technologies that are necessary to authenticate users, maintain sessions, protect forms against cross-site request forgery, remember settings, route requests, and secure the Service. These technologies may contain a random identifier but are not used by us to sell personal information or for cross-context behavioral advertising. Paddle, third-party identity providers, and optional anti-abuse services such as reCAPTCHA may set or read their own cookies when you use their features. Their practices are governed by their own privacy notices.
Most browsers let you remove or block cookies. Blocking cookies that are strictly necessary may prevent login, checkout, security controls, or other core features from working. Because we do not sell or share information for cross-context behavioral advertising, we do not currently provide a separate “Do Not Sell or Share” link. Where required, we recognize applicable browser-based opt-out preference signals, such as the Global Privacy Control, for processing to which such signals apply.
8. Consent to International Data Transfer
Wobidobi LLP is established in the Republic of Kazakhstan, while the Service’s servers and databases are physically located in the United States. When you use the Service, your personal information is therefore transferred to and stored on secure servers in the United States, meaning servers protected by technical and organizational security measures. We and our providers may also process information in other countries where personnel or service providers operate. Those countries may have privacy laws and government-access rules that differ from those in your country and may not provide an equivalent level of protection.
By choosing to register for and use the Service after being presented with this Policy, you expressly acknowledge this international processing and, where consent is the valid legal mechanism, explicitly consent to the transfer of your personal information to the United States. You may withdraw consent for future consent-based processing by contacting us, but withdrawal does not affect processing already performed and may mean that we can no longer provide an account where United States processing is necessary to operate the Service.
We do not rely on consent alone where another transfer mechanism is required. Where applicable, we use legally recognized safeguards for transfers, such as the European Commission’s Standard Contractual Clauses, the UK International Data Transfer Addendum, contractual data-protection commitments, transfer risk assessments, and supplementary technical and organizational measures. You may contact us for information about the safeguard relevant to your transfer and, where legally available, a copy of it subject to necessary redactions.
9. Data retention
We retain personal information only for as long as reasonably necessary for the purposes described in this Policy, including to provide the Service, comply with legal, tax, accounting, and reporting duties, resolve disputes, enforce agreements, maintain security, and preserve backups. Retention depends on the type of information and context:
- account and workspace information is generally retained while the account or workspace is active and for a limited period after closure;
- customer content and form responses are retained according to the workspace owner’s instructions and settings, subject to backup and legal-retention periods;
- pending email-registration records expire after the verification period, and sensitive verification material is cleared;
- transaction and subscription records may be retained for the period required by tax, accounting, fraud-prevention, and commercial laws;
- support records and security logs are retained for a period appropriate to support, audit, fraud-prevention, and security needs; and
- temporary export files and similar generated artifacts may be deleted on a shorter operational schedule.
When information is no longer needed, we delete or anonymize it, or isolate it until deletion is possible. Deletion from encrypted backups may occur through the normal backup-rotation cycle.
10. Information security
We use reasonable administrative, technical, and organizational measures designed to protect personal information, including access controls, password hashing, transport encryption, secure session controls, environment separation, logging, backups, and restrictions on service providers. No online service or storage system is completely secure, so we cannot guarantee absolute security. You are responsible for using a strong, unique password and keeping your credentials confidential. If you believe your account or information has been compromised, contact us promptly.
11. GDPR and UK privacy rights
If the GDPR, UK GDPR, or a similar law applies to our processing of your personal information, you may have the right to:
- request access to your personal information and information about its processing;
- request correction of inaccurate or incomplete personal information;
- request deletion of personal information in circumstances provided by law;
- request restriction of processing in circumstances provided by law;
- receive personal information you provided in a structured, commonly used, machine-readable format and transmit it to another controller where the right to portability applies;
- object to processing based on legitimate interests and object at any time to direct marketing;
- withdraw consent at any time for future processing that relies on consent; and
- lodge a complaint with the data-protection supervisory authority in the country where you live or work or where you believe a violation occurred.
These rights are not absolute and may be subject to lawful exceptions. We do not make decisions based solely on automated processing that produce legal or similarly significant effects about account users. When Wobidobi processes form responses only for a customer, we may direct your request to that customer or assist the customer in responding.
12. California Privacy Notice
This section supplements the rest of the Policy for California residents. It applies to the extent Wobidobi is subject to the California Consumer Privacy Act, as amended (“CCPA”). In the preceding 12 months, we have collected the categories described below for the business and commercial purposes stated in Sections 4 and 6:
- Identifiers, such as name, email address, account identifiers, IP address, and transaction identifiers;
- California customer-record information, such as name and contact information;
- Commercial information, such as plan, subscription, purchase, cancellation, and refund records;
- Internet or electronic-network activity, such as browser, session, security, form-visit, and Service-usage information;
- Approximate geolocation, which may be inferred from an IP address;
- Professional or employment-related information, if you provide it in a workspace, support request, or form response;
- Inferences, such as plan needs or usage patterns derived from Service activity; and
- Sensitive personal information, such as account login credentials and any sensitive information a customer chooses to collect through a form.
We collect these categories from the sources in Section 3. During the preceding 12 months, we have disclosed the categories below for the business purposes described in this Policy to the following categories of recipients, as relevant to the interaction:
- Identifiers and customer-record information: infrastructure, email, authentication, security, and support service providers; Paddle; identity and integration providers; workspace administrators; professional advisers; and legal or safety recipients.
- Commercial information: infrastructure and support service providers; Paddle; workspace owners and billing administrators; professional advisers; and legal or safety recipients.
- Internet or electronic-network activity and approximate geolocation: hosting, logging, security, anti-abuse, and support service providers; workspace administrators for activity within their workspace; and legal or safety recipients.
- Professional or employment-related information: service providers; the relevant customer and workspace administrators; professional advisers; and legal or safety recipients.
- Inferences: infrastructure and support service providers and the relevant customer or workspace administrator where the inference relates to its workspace.
- Sensitive personal information: infrastructure and security service providers and the relevant customer or workspace administrators when a customer has chosen to collect that information through a form.
Information may also be disclosed to parties involved in a business transfer as described in Section 6. We do not sell or share personal information, including any of these categories, for cross-context behavioral advertising. We have not done so in the preceding 12 months. We do not knowingly sell or share the personal information of people under 16.
Subject to the CCPA’s scope and exceptions, California residents may have the right to:
- know the categories and specific pieces of personal information we have collected, used, disclosed, sold, or shared;
- delete personal information we collected from them;
- correct inaccurate personal information;
- opt out of the sale or sharing of personal information;
- limit certain uses and disclosures of sensitive personal information; and
- receive equal service and pricing and not be retaliated against for exercising a CCPA right.
Because we do not sell or share personal information or use sensitive personal information for purposes that trigger a right to limit, there is currently no such processing to opt out of or limit. If our practices change, we will provide the legally required methods before beginning that processing.
13. How to exercise privacy rights
To exercise an applicable privacy right, email info@wobidobi.com with the subject “Privacy Request” or contact us by telephone using the number at the bottom of this page. Describe your request and identify the account or interaction involved. We may request information reasonably necessary to verify your identity and authority. We will use verification information only for that purpose and will respond within the period required by applicable law.
An authorized agent may submit a California request on your behalf. We may require proof of the agent’s authority and may ask you to verify your identity or confirm the authorization directly, as permitted by law. You may appeal a refusal where applicable law provides an appeal right by replying to our decision with the subject “Privacy Appeal.”
14. Children
The Service is not directed to children under 18, and children may not create Wobidobi accounts. We do not knowingly collect personal information directly from children for our own purposes. A customer must not use the Service to collect children’s personal information unless it has all legally required authority, parental consent, notices, and safeguards. If you believe a child has provided personal information unlawfully, contact us so we can investigate.
15. Changes to this Policy
We may update this Policy to reflect changes in the Service, law, or our processing practices. We will post the revised version and update the “Last updated” date. If a change materially affects your rights or how we use personal information, we will provide additional notice where required, such as by email or through the Service. We will request consent before applying a material change where applicable law requires consent.
16. Contact us
For questions, complaints, or privacy requests, contact:
Wobidobi LLP
1A Toporkova Street, room 4
Rudny, Republic of Kazakhstan, 111500
Email: info@wobidobi.com