Wondder Privacy Policy

Version: 2.0

Effective date: 14 June 2026

1. Introduction

This Privacy Policy explains how Wondder, VaRc GmbH (“Wondder”, “we”, “us” or “our”) collects and processes personal data in connection with:

  • the Wondder website;
  • enquiries, demonstrations and business communications;
  • events and registration activities;
  • Wondder training services and learning experiences;
  • user accounts and technical support;
  • related operational, security and administrative activities.

We process personal data in accordance with the General Data Protection Regulation, Regulation (EU) 2016/679 (“GDPR”), and other applicable data protection laws.

This Policy applies to website visitors, prospective and existing clients, client representatives, platform users, training participants, event participants and other individuals who interact with Wondder.

2. Who is responsible for your personal data?

For processing activities for which Wondder determines the purposes and means, the data controller is:

Wondder, VaRc GmbH
Zähringerstr. 26
10707 Berlin
Germany

Email: privacy@wondder.io

This Policy primarily describes processing activities for which Wondder acts as a controller. Where Wondder processes personal data solely on behalf of a client organisation, that client acts as controller for the relevant processing and its privacy information also applies. Wondder then processes the data under the applicable data-processing agreement and documented client instructions.

For client-organised training, the client organisation generally determines participant selection and any independent use of training results for its internal purposes. The allocation of responsibilities may vary by service and contractual arrangement.

Questions about Wondder's processing activities may be sent to privacy@wondder.io.

3. Personal data we process

The personal data processed depends on how you interact with Wondder and which services are enabled.

3.1 Contact and business information

This may include:

  • first and last name;
  • business email address;
  • telephone number;
  • company or organisation;
  • job title or professional role;
  • country or location;
  • correspondence and enquiry content;
  • meeting, demonstration or event details;
  • communication preferences;
  • information relating to a business relationship.

3.2 Account information

Where an account is provided, we may process:

  • account identifier;
  • email address;
  • organisation or client affiliation;
  • user role and access permissions;
  • authentication and account-status information;
  • language and other service preferences.

3.3 Training and interaction data

Depending on the training service and configuration, we may process:

  • participation and session information;
  • scenario choices and interactions;
  • conversation turns and user responses;
  • response timing and scenario progression;
  • training results and feedback indicators;
  • completion information;
  • transcripts or other session records where enabled;
  • information voluntarily provided by a participant during a training interaction.

Training results and feedback indicators are designed to support learning and development. They are not intended by Wondder to determine employment, disciplinary or similarly significant decisions.

3.4 Voice and language-processing data

Some training experiences allow participants to interact using speech.

Depending on the service configuration, spoken input may be:

  • processed on a device;
  • transmitted temporarily for speech recognition;
  • converted into text;
  • used to generate a response or training feedback;
  • retained as a transcript where the relevant feature has been enabled.

The processing configuration may vary according to the service, client agreement and technical environment.

Customer training content is processed to provide, secure, support and maintain the relevant service. It is not used by Wondder for its own general-purpose artificial-intelligence model training. Any materially different use would require a separate assessment and prior transparent communication.

3.5 Technical and usage data

When you use our website or services, we may process technical information such as:

  • IP address;
  • browser and device information;
  • operating-system information;
  • timestamps and session duration;
  • pages, functions or content accessed;
  • application and device metadata;
  • diagnostic, security and error logs;
  • cookie or similar technology identifiers;
  • general interaction and performance information.

3.6 Support information

When you contact support, we may process:

  • your identity and contact details;
  • the organisation you represent;
  • the content of the support request;
  • technical and diagnostic information;
  • correspondence and resolution history;
  • files or screenshots voluntarily provided for troubleshooting.

Please avoid including unnecessary sensitive information in support requests.

4. How we obtain personal data

We may obtain personal data:

  • directly from you;
  • from your employer or another client organisation;
  • through our website, forms, scheduling services or communication channels;
  • through your use of a Wondder service or training experience;
  • from technical systems and devices used to access the service;
  • from event organisers or business partners;
  • from publicly accessible professional profiles and business directories for limited B2B relationship management, where permitted by law;
  • from service providers acting on our behalf.

Where personal data is provided by a client organisation, that organisation is responsible for ensuring that it has an appropriate legal basis for providing the data and for informing the relevant individuals where required.

5. Why we process personal data

We process personal data for the following purposes.

5.1 Providing training and related services

This includes:

  • delivering training sessions and learning experiences;
  • enabling interactive and AI-supported functionality;
  • processing speech and text where required by a training scenario;
  • generating training responses and feedback;
  • administering users and service access;
  • providing client-requested reporting or session records;
  • supporting service delivery across different devices and environments.

5.2 Responding to enquiries and managing business relationships

This includes:

  • responding to contact requests;
  • arranging demonstrations and meetings;
  • preparing proposals and contracts;
  • communicating with prospective and existing clients;
  • maintaining relevant business-contact records;
  • managing sales and customer relationships.

5.3 Events and communications

This includes:

  • managing event and roundtable registrations;
  • sending organisational information;
  • communicating about events or requested materials;
  • following up on participation or an expressed business interest;
  • sending electronic marketing communications where the required consent has been provided or another specific legal exception applies; each communication includes a simple opt-out method.

5.4 Operating and improving our services

This includes:

  • troubleshooting and technical support;
  • maintaining service availability;
  • analysing performance and reliability;
  • developing and improving service functionality;
  • understanding how the website and services are used;
  • preventing misuse, fraud and security incidents;
  • protecting Wondder, its users and client organisations.

5.5 Compliance and legal purposes

This includes:

  • complying with legal and regulatory obligations;
  • maintaining business and compliance records;
  • establishing, exercising or defending legal claims;
  • responding to lawful requests from authorities;
  • enforcing contractual terms.

6. Legal bases for processing

The principal legal bases are mapped as follows: contact and demonstration requests — Article 6(1)(b) GDPR; ongoing B2B relationship management, service operation and security — Article 6(1)(f) GDPR; non-essential cookies and marketing where consent is required — Article 6(1)(a) GDPR; legal and accounting records — Article 6(1)(c) GDPR; and client-organised participant processing — the legal basis determined by the relevant controller under the applicable contractual arrangement. Further details are set out below.

6.1 Performance of a contract or steps before entering a contract

Article 6(1)(b) GDPR applies where the individual is a party to a contract with Wondder or has requested steps before entering into such a contract, including where processing is necessary to:

  • provide a requested service;
  • administer an account;
  • respond to a request for a proposal or demonstration;
  • organise participation where the individual is party to, or has requested, the relevant service;
  • provide technical or contractual support.

6.2 Legitimate interests

Article 6(1)(f) GDPR may apply where processing is necessary for legitimate interests such as:

  • operating and securing our website and services;
  • maintaining business relationships;
  • responding to business enquiries;
  • improving the reliability and usability of our services;
  • preventing fraud, misuse and security incidents;
  • maintaining appropriate business and compliance records;
  • protecting or defending legal rights.

Where we rely on legitimate interests, we consider the nature of the data, the reasonable expectations of the individuals concerned and the potential impact on their rights and freedoms.

You may object to processing based on legitimate interests as explained in Section 12.

6.3 Consent

Article 6(1)(a) GDPR may apply where you have consented to:

  • non-essential cookies or similar technologies;
  • particular marketing communications;
  • optional recordings or service features;
  • other processing activities for which consent is required.

You may withdraw consent at any time. Withdrawal does not affect the lawfulness of processing carried out before withdrawal.

6.4 Legal obligations

Article 6(1)(c) GDPR may apply where processing is necessary to comply with legal, accounting, regulatory or reporting requirements.

6.5 Processing on behalf of a client

Where Wondder acts solely as a processor, the relevant client organisation determines the purposes, legal basis and essential means of the processing. Wondder processes the data only under the applicable data-processing agreement and documented client instructions.

7. Special categories of personal data

Wondder does not request special categories of personal data unless this is necessary for a specifically identified service and an applicable condition under Article 9 GDPR has been established.

Because some training interactions permit free-form speech or text, a participant may incidentally disclose information concerning health, racial or ethnic origin, political opinions, religious beliefs, trade-union membership, sexual orientation or other special-category data.

If continued processing of such information is necessary, Wondder or the relevant client will identify and document an applicable condition under Article 9 GDPR before that processing continues. Otherwise, access is restricted and the information is deleted, anonymised or securely isolated as appropriate.

Participants should avoid disclosing sensitive personal information unless the relevant service specifically requires it and the applicable privacy information explains how it will be handled.

8. Automated processing and training feedback

Wondder services may use automated systems to:

  • recognise or transcribe speech;
  • generate conversational responses;
  • analyse interaction patterns;
  • produce training feedback or qualitative indicators;
  • adapt a training scenario to a participant's responses.

These functions are intended to support learning and service delivery. Analysis of responses or interaction patterns may constitute profiling under the GDPR where it evaluates aspects of a participant's behaviour or performance. The resulting feedback or indicators are intended for the training context and do not, by themselves, determine employment or disciplinary outcomes.

Wondder does not use solely automated processing to make decisions about individuals that produce legal effects or similarly significant effects within the meaning of Article 22 GDPR.

Client organisations remain responsible for any independent employment, disciplinary, performance-management or human-resources decisions they make using their own processes.

8.1 Children and young participants

Wondder services are primarily intended for organisational and professional training and are not directed to children as consumer services. If a client organisation plans to include a person under 18, the client and Wondder must confirm the applicable legal basis, authorisation and age-appropriate transparency before the service is used.

9. Cookies and similar technologies

Our website may use cookies, local storage, pixels and similar technologies to:

  • provide essential website functions;
  • maintain security;
  • remember user preferences;
  • understand website usage and performance;
  • improve content and user experience;
  • support business analytics and marketing activities;
  • display externally hosted content, forms, scheduling tools or videos.

Where consent is required by law, non-essential technologies are activated only after the relevant consent has been provided.

You may accept, reject or manage non-essential technologies through the cookie settings available on the website. You may change or withdraw your consent at any time.

Further details about the technologies used, their purposes, providers and durations are available through our cookie settings or Cookie Declaration.

10. Who may receive personal data?

We may disclose personal data to carefully selected recipients where necessary for the purposes described in this Policy.

These recipients may include:

  • cloud-hosting and infrastructure providers;
  • security, monitoring and technical-support providers;
  • speech-recognition and language-processing providers;
  • generative-AI and conversational-processing providers;
  • speech-synthesis providers;
  • customer-relationship and business-communication providers;
  • form, scheduling and event-management providers;
  • website analytics and user-experience providers;
  • video-hosting and embedded-content providers;
  • professional advisers, including legal, tax and compliance advisers;
  • client organisations where the processing relates to their users or participants;
  • public authorities where disclosure is required by law.

Service providers are contractually authorised to process personal data for the relevant service functions and any legally permitted security, compliance or support activities described in their agreements with Wondder.

An up-to-date list of relevant service providers or subprocessors may be made available to business clients or data subjects where appropriate.

We do not sell personal data.

11. International data transfers

Wondder aims to process personal data within the European Economic Area where reasonably possible.

Some service providers or their group companies may process data in countries outside the European Economic Area.

Where an international transfer requires additional safeguards, we use an appropriate transfer mechanism, which may include:

  • an adequacy decision adopted by the European Commission;
  • the European Commission's Standard Contractual Clauses;
  • supplementary technical, contractual or organisational safeguards;
  • another legally recognised transfer mechanism.

Information about applicable transfer safeguards may be requested by contacting privacy@wondder.io. Certain information may be redacted where necessary to protect confidential or security-related information.

12. How long we retain personal data

We retain personal data only for as long as necessary for the relevant purpose.

The applicable period depends on factors such as:

  • the nature of the data;
  • the service or feature being used;
  • the duration of the client or business relationship;
  • the configuration agreed with a client organisation;
  • whether an account remains active;
  • the time needed to answer an enquiry or resolve a support case;
  • security, fraud-prevention and troubleshooting requirements;
  • statutory retention obligations;
  • applicable limitation periods;
  • the need to establish, exercise or defend legal claims.

Unless a shorter period applies under a client configuration or legal requirement, the following maximum periods generally apply:

  • training transcripts and performance data: up to 24 months where enabled;
  • account data: for the account lifetime and normally deleted or anonymised within 30 days after a valid deletion request, subject to legal retention requirements;
  • technical logs: up to 90 days;
  • support-case data: up to 12 months after closure;
  • CRM and event data: for the duration of the business relationship or until a valid objection or deletion request, subject to legal retention requirements;
  • protected backups: until overwritten in the ordinary backup cycle, generally within 30 days.

Raw voice audio is not retained by Wondder as part of the standard training configuration. If a separate recording feature is enabled, the applicable retention and access rules are communicated before use.

When personal data is no longer required, it is deleted, anonymised or securely restricted. Residual copies may remain temporarily in protected backups until they are overwritten through the applicable backup cycle.

13. Your data-protection rights

Subject to the conditions and limitations of applicable law, you may have the following rights:

  • the right to obtain information about the processing of your personal data;
  • the right of access to your personal data;
  • the right to correct inaccurate or incomplete data;
  • the right to request deletion;
  • the right to request restriction of processing;
  • the right to object to processing based on legitimate interests;
  • the right to data portability;
  • the right to withdraw consent at any time;
  • the right not to be subject to qualifying solely automated decisions;
  • the right to lodge a complaint with a data-protection authority.

Where we process personal data for direct-marketing purposes, you may object to that processing at any time.

To exercise your rights, contact:

privacy@wondder.io

We may need to verify your identity before responding. Where Wondder processes data solely on behalf of a client organisation, we may direct the request to, or coordinate the response with, that client.

14. Right to lodge a complaint

You may lodge a complaint with the data-protection authority responsible for your place of residence, place of work or the location of the alleged infringement.

Wondder's competent supervisory authority is:

Berliner Beauftragte für Datenschutz und Informationsfreiheit
Alt-Moabit 59–61
10555 Berlin
Germany

Website: https://www.datenschutz-berlin.de

We encourage you to contact us first at privacy@wondder.io so that we have an opportunity to address your concern.

15. Security

We use appropriate technical and organisational measures designed to protect personal data.

Depending on the service and risk, these measures may include:

  • access controls;
  • encryption during transmission;
  • separation of environments;
  • secure development and deployment practices;
  • logging and monitoring;
  • data minimisation;
  • backup and recovery procedures;
  • incident-management processes;
  • contractual controls for service providers.

No system can guarantee absolute security. Users should also take reasonable precautions to protect their accounts, devices and authentication information.

16. External websites and services

Our website and services may contain links to or embedded content from external providers.

Those external providers may process personal data under their own privacy policies. Depending on the integration, Wondder may be responsible for the initial disclosure or other aspects of the processing, while the external provider may act as a processor or an independent controller. Further information is provided through the relevant cookie or service notice.

Where required, external content that uses non-essential technologies will be subject to the cookie choices made through the website.

17. Changes to this Privacy Policy

We may update this Privacy Policy where necessary to reflect:

  • changes to our services;
  • changes to processing activities;
  • legal or regulatory developments;
  • changes to relevant service-provider categories;
  • improvements to our privacy and security practices.

The current version and effective date will be published at the top of this page.

Where a change materially affects how personal data is processed, we will take appropriate steps to inform affected individuals.

18. Contact

For privacy questions, requests or complaints, contact:

Wondder, VaRc GmbH
Zähringerstr. 26
10707 Berlin
Germany

Email: privacy@wondder.io

Copyright © VaRc GmbH All Rights Reserved

Privacy PolicyImpressum