Privacy Policy
This Policy explains what personal data Whisone handles, why we use it, when it may be shared, how long it is kept, and the choices and rights available to you.
Scope and who is responsible
This Policy applies to Whisone websites, applications, accounts, research products, learning tools, communications, and support services that link to it. “Whisone,” “we,” “us,” and “our” refer to the operator of those services and the controller responsible for deciding how personal data is processed.
External websites, data providers, payment services, and sign-in providers have their own privacy notices. This Policy does not control their independent processing.
Personal data we collect
- Account and identity data: name, username, email address, authentication details, account status, and profile image where provided.
- Investor profile and preferences: goals, experience, risk tolerance, time horizon, sectors of interest, display currency, theme, and communication settings.
- Product content: watchlists, alerts, portfolio holdings and transactions, goals, saved research, comments, learning progress, AI prompts, and feedback.
- Subscription and transaction data: plan, payment status, billing references, renewal and cancellation information. Payment providers process card or bank details; Whisone does not need to store complete payment-card numbers.
- Support and communications: messages, ticket history, replies, email interactions, and files or screenshots you attach.
- Usage and technical data: pages and features used, searches, clicks, session events, approximate location derived from IP address, device and browser information, identifiers, error logs, and diagnostic data.
- Public and third-party information: information received from sign-in providers and information you choose to make public through a shared research report or comment.
How we receive data
We receive data directly from you when you register, configure your profile, use tools, purchase a plan, submit content, or contact support. We collect some technical and usage data automatically through cookies, local storage, logs, and analytics tools. We may also receive limited account, payment, delivery, or authentication information from service providers you choose to use.
Why we use personal data
- create and secure accounts, authenticate users, and provide requested features;
- save watchlists, alerts, portfolios, preferences, learning progress, and research activity;
- process subscriptions, maintain billing records, and prevent fraud;
- deliver alerts, verification messages, password resets, reports, support replies, and service notices;
- personalise research presentation and AI-assisted responses using the context you provide;
- measure product use, diagnose errors, monitor reliability, and improve features;
- moderate content, enforce our Terms, protect users, and respond to misuse or security incidents; and
- comply with legal obligations, resolve disputes, and establish or defend legal claims.
Legal bases for processing
Depending on the activity and applicable law, we process personal data because it is necessary to perform our contract with you, comply with a legal obligation, protect vital interests, pursue legitimate interests that are not overridden by your rights, or because you have given consent.
Our legitimate interests include operating and securing the Service, understanding product performance, preventing fraud, improving research tools, and communicating about related features. Where processing relies on consent, you may withdraw it at any time without affecting earlier lawful processing.
AI and automated processing
When you use AI-assisted features, we process your prompt and relevant product context to generate a response. We may also process interaction data to evaluate safety, quality, and usefulness. Do not include sensitive or confidential personal information that is not needed for your question.
Research scores, alerts, and AI outputs may be generated automatically, but they are informational product features and do not execute trades or make legally binding decisions about you. Where applicable law gives you rights concerning solely automated decisions with legal or similarly significant effects, you may request information or human review.
Cookies, analytics, and device storage
Whisone uses cookies and browser storage that are necessary for sign-in, security, session continuity, display currency, theme, saved preferences, and device-local learning or interface state. Removing them may sign you out or reset preferences.
We also use product analytics and measurement services, including PostHog and Google Analytics where configured, to understand visits, feature use, and reliability. These tools may use device identifiers, cookies, or similar technologies. Browser settings and available consent controls can be used to limit optional storage, although some essential functions cannot operate without necessary storage.
When we share data
We do not sell personal data. We may share only what is reasonably necessary with:
- hosting, infrastructure, database, security, and error-monitoring providers;
- authentication and account-verification providers;
- payment processors and billing providers;
- email, notification, customer-support, and file-storage providers;
- analytics and product-improvement providers;
- professional advisers, auditors, insurers, or potential transaction partners under appropriate confidentiality obligations; and
- regulators, courts, law enforcement, or other parties when required by law or necessary to protect rights, safety, and the integrity of the Service.
Content you deliberately publish or share, such as a public research link or comment, may be visible to others according to the controls shown when you share it.
International data transfers
Some service providers may process data outside Nigeria or the country where you live. Where required, we use recognised safeguards for international transfers and assess whether the destination, recipient, or contractual arrangement provides appropriate protection.
How long we keep data
We keep personal data only for as long as reasonably necessary for the purposes described here. Retention depends on the type of data, your account status, operational needs, legal or accounting requirements, security considerations, and dispute limitation periods.
Account and product data is generally retained while your account is active. After deletion or closure, some data may remain temporarily in backups or be retained where required for billing, fraud prevention, security, legal compliance, or claims. Data that has been irreversibly anonymised may be kept because it no longer identifies you.
Security
We use administrative, technical, and organisational measures designed to protect personal data, including access controls, authentication safeguards, monitoring, and restricted staff access. No internet service can guarantee absolute security. Use a strong, unique password and contact us immediately if you believe your account or personal data has been compromised.
Your rights and choices
Subject to applicable law, including the Nigeria Data Protection Act 2023, you may have the right to be informed; request access, correction, deletion, restriction, or portability; object to processing; withdraw consent; and seek human review of qualifying automated decisions. You may also lodge a complaint with the Nigeria Data Protection Commission or another competent authority.
You can update some information and notification choices in your account. For other requests, email hello@whisone.app or use Whisone Support. We may need to verify your identity before completing a request. Some rights are subject to lawful exceptions.
Children's privacy
Whisone is not directed to children under 18, and we do not knowingly collect their personal data. If you believe a child has provided personal data, contact us so we can investigate and take appropriate action.
Changes and contact
We may update this Policy when our practices, products, providers, or legal obligations change. We will update the date above and provide additional notice where a change is material or required by law.
Questions, complaints, or privacy requests can be sent to hello@whisone.app or through Whisone Support. Please do not send identity documents until we ask for the specific information needed to verify a request securely.
