1. Scope and roles
Workora is operated by Avtax Integration Systems. Contact us at support@avtax.net for privacy questions or requests. This policy applies to the Workora application and its connected services. A company using Workora controls its company configuration and the business data it connects. Workora processes that data to provide the service. The connected provider's own privacy policy also applies when a user approves access on that provider's screen.
2. Information we process
- Account information: name, email address, authentication and company membership.
- Company configuration: departments, agents, instructions, workflows, tasks, approvals, permissions and schedules.
- Connected-service data: account identifiers, granted scopes, commerce, finance and business conversations requested through connected providers.
- Conversation content: messages, attachments and agent responses needed to provide the customer inbox and assigned Agent Jobs.
- Operational records: audit events, activity and automation status, model usage, costs, errors and security signals.
- Technical information: browser and request information normally recorded to operate, secure and diagnose a web service.
For a connected Shopify store, permitted features can process product and inventory information, customer names, email addresses and phone numbers, order history, and delivery addresses. Workora uses these details for product questions, order lookup, and preparing or updating draft orders according to the company's permissions and approval settings. Relevant details can also appear in conversations, tool results and order records.
3. How information is used
Information is used to:
- provide the company workspace, agents, workflows, inbox and integrations;
- perform actions a user requests or approves;
- enforce tenant isolation, permissions, limits and human approvals;
- secure the service, investigate failures and maintain an audit trail; and
- measure usage and the cost of services used on the company's behalf.
Workora does not sell personal information or use connected business data for advertising.
4. Connected providers and service partners
Workora sends information to a provider only when needed for a requested feature. This can include Meta for WhatsApp, Facebook and Instagram messaging, Telegram for conversations, Shopify for commerce data, Zoho Books for finance workflows, configured HTTPS services, and model providers for agent execution. Hosting, database and monitoring providers may process limited data while operating the platform. Access is limited to the scopes approved by the company and the permissions granted to each agent.
When a business enables an AI assistant, Workora sends the customer message and relevant conversation context to the OpenAI API to generate a reply. This can include attachments the business permits the assistant to use. OpenAI acts as a service provider for that processing. Workora does not submit connected-service data to train shared AI models. Customer content may be processed internationally; OpenAI publishes its processing providers and locations. A business using its own provider account controls that account's data settings.
5. OAuth credentials and security
Provider consent occurs on the provider's own website. Workora stores issued access credentials encrypted, never displays them back to users, and never includes them in audit records or model prompts. Tenant-aware database rules, authorization checks, approval policies and immutable audit events are used to reduce unauthorized access. No security measure can guarantee absolute security.
6. Retention
Information is retained while it is needed to provide the service, satisfy the company's configured history, resolve disputes, prevent abuse or meet legal duties. Disconnecting an app removes its saved credentials and stops future access. Message content and derived customer context follow the workspace's history period. Successfully handled webhook bodies are normally cleared after seven days; failed or unprocessed bodies are retired after the configured retry horizon (30 days by default), once they are no longer being processed. Deletion confirmation records remain available for 90 days after completion by default. Security, billing, and backup records may have separate retention periods. OpenAI's provider-side retention is governed by its own agreement and account settings; requesting an unstored response does not mean that no provider logs exist.
7. Choices and rights
Shopify can forward customer access, customer deletion and store deletion requests to Workora. Verified requests are recorded for the connected company's administrators, with a 30-day fulfillment deadline. Administrators review the covered information and record completion after providing or erasing it. Disconnecting a store stops access; fulfillment also requires reviewing information already retained by Workora and its processors.
Company administrators can disconnect an app and remove agent access from Workora at any time. People may request access, correction, export or deletion of personal information through the company that controls their workspace. Account holders can follow the data-deletion instructions. Rights can vary by location.
8. Children's data
Workora is a business service and is not directed to children. Companies must not use it to intentionally collect children's personal information without an appropriate lawful basis and safeguards.
9. Changes to this policy
This policy may be updated as the product, providers or legal requirements change. The effective date at the top identifies the current version. Material changes will be communicated through the service or the company that provides access to it.
Privacy questions
Email support@avtax.net with privacy or deletion requests. You may also contact the business whose account you messaged. The data-deletion page explains what to include so the request can be verified and completed safely.