Legal
Security
Last updated: 17 September 2026
This page explains how WI1 protects your data across the wi1.com website and the WI1 CRM application at crm.wi1.com. See also our Privacy Policy and Terms and Conditions.
Infrastructure
WI1 runs on a dedicated server in the United Kingdom, which stores the application database and files. We do not spread customer data across ad hoc third-party services beyond the providers named below.
- All traffic between your browser and WI1 is encrypted in transit with HTTPS (TLS).
- Credentials for connected services and mailboxes (Google, Microsoft 365, IMAP) are encrypted at rest.
- Data is backed up regularly.
Account isolation
Access is scoped per company account, so one customer’s data is never visible to another. Within an account, managers decide exactly what each user and each AI agent may see and do.
Authentication
WI1 accounts require a username and password to sign in. Passwords are hashed and are never stored in plain text. Keep your login details secure and never share them with a third party — we cannot resend a forgotten password, we can only reset it.
Connected services and AI processing
Connecting Google Calendar, Microsoft 365 or a mailbox is always optional. OAuth 2.0 is used for authentication with these providers, and access/refresh tokens are encrypted at rest. Disconnecting a service in WI1 deletes its stored credentials immediately and stops all further access.
WI1’s AI agents are powered by a number of models from leading AI harnesses. Content is sent to the harness via its API only to carry out the specific action you ask for, is processed under their commercial terms, and is not used to train their models. Agents act within your account only, and the CRM asks before taking consequential actions. See our Privacy Policy for the full details on what is shared with each provider.
Payments
We do not store credit card details. Payments are handled by our payment processing provider, Stripe (PCI DSS Level 1 certified) — at no point does WI1 have access to your card information.
Employee access
Access to production systems and customer data is limited to the people who operate the service, on the principle of least privilege, and is reviewed regularly. We only access individual customer data to provide support or investigate a system issue.
Data location
Data is stored and processed in the United Kingdom and, where you connect a third-party service, with that provider — in each case in line with UK data protection law. Where a provider is outside the UK, transfers are covered by the UK International Data Transfer Addendum or an adequacy decision.
Reporting a security issue
If you believe you’ve found a security issue, please tell us straight away at support[at]wi1.com. We will acknowledge your report (typically within one business day), investigate and assess impact, and keep you updated as appropriate. Where required by law, we will notify affected users and/or regulators of a data breach involving personal information.
Limitations
While we take reasonable steps to protect your data, no method of transmission or storage over the internet is completely secure.