Version: 2.0
Effective date: 14 June 2026
This Privacy Policy explains how Wondder, VaRc GmbH (“Wondder”, “we”, “us” or “our”) collects and processes personal data in connection with:
We process personal data in accordance with the General Data Protection Regulation, Regulation (EU) 2016/679 (“GDPR”), and other applicable data protection laws.
This Policy applies to website visitors, prospective and existing clients, client representatives, platform users, training participants, event participants and other individuals who interact with Wondder.
For processing activities for which Wondder determines the purposes and means, the data controller is:
Wondder, VaRc GmbH
Zähringerstr. 26
10707 Berlin
Germany
Email: privacy@wondder.io
This Policy primarily describes processing activities for which Wondder acts as a controller. Where Wondder processes personal data solely on behalf of a client organisation, that client acts as controller for the relevant processing and its privacy information also applies. Wondder then processes the data under the applicable data-processing agreement and documented client instructions.
For client-organised training, the client organisation generally determines participant selection and any independent use of training results for its internal purposes. The allocation of responsibilities may vary by service and contractual arrangement.
Questions about Wondder's processing activities may be sent to privacy@wondder.io.
The personal data processed depends on how you interact with Wondder and which services are enabled.
This may include:
Where an account is provided, we may process:
Depending on the training service and configuration, we may process:
Training results and feedback indicators are designed to support learning and development. They are not intended by Wondder to determine employment, disciplinary or similarly significant decisions.
Some training experiences allow participants to interact using speech.
Depending on the service configuration, spoken input may be:
The processing configuration may vary according to the service, client agreement and technical environment.
Customer training content is processed to provide, secure, support and maintain the relevant service. It is not used by Wondder for its own general-purpose artificial-intelligence model training. Any materially different use would require a separate assessment and prior transparent communication.
When you use our website or services, we may process technical information such as:
When you contact support, we may process:
Please avoid including unnecessary sensitive information in support requests.
We may obtain personal data:
Where personal data is provided by a client organisation, that organisation is responsible for ensuring that it has an appropriate legal basis for providing the data and for informing the relevant individuals where required.
We process personal data for the following purposes.
This includes:
This includes:
This includes:
This includes:
This includes:
The principal legal bases are mapped as follows: contact and demonstration requests — Article 6(1)(b) GDPR; ongoing B2B relationship management, service operation and security — Article 6(1)(f) GDPR; non-essential cookies and marketing where consent is required — Article 6(1)(a) GDPR; legal and accounting records — Article 6(1)(c) GDPR; and client-organised participant processing — the legal basis determined by the relevant controller under the applicable contractual arrangement. Further details are set out below.
Article 6(1)(b) GDPR applies where the individual is a party to a contract with Wondder or has requested steps before entering into such a contract, including where processing is necessary to:
Article 6(1)(f) GDPR may apply where processing is necessary for legitimate interests such as:
Where we rely on legitimate interests, we consider the nature of the data, the reasonable expectations of the individuals concerned and the potential impact on their rights and freedoms.
You may object to processing based on legitimate interests as explained in Section 12.
Article 6(1)(a) GDPR may apply where you have consented to:
You may withdraw consent at any time. Withdrawal does not affect the lawfulness of processing carried out before withdrawal.
Article 6(1)(c) GDPR may apply where processing is necessary to comply with legal, accounting, regulatory or reporting requirements.
Where Wondder acts solely as a processor, the relevant client organisation determines the purposes, legal basis and essential means of the processing. Wondder processes the data only under the applicable data-processing agreement and documented client instructions.
Wondder does not request special categories of personal data unless this is necessary for a specifically identified service and an applicable condition under Article 9 GDPR has been established.
Because some training interactions permit free-form speech or text, a participant may incidentally disclose information concerning health, racial or ethnic origin, political opinions, religious beliefs, trade-union membership, sexual orientation or other special-category data.
If continued processing of such information is necessary, Wondder or the relevant client will identify and document an applicable condition under Article 9 GDPR before that processing continues. Otherwise, access is restricted and the information is deleted, anonymised or securely isolated as appropriate.
Participants should avoid disclosing sensitive personal information unless the relevant service specifically requires it and the applicable privacy information explains how it will be handled.
Wondder services may use automated systems to:
These functions are intended to support learning and service delivery. Analysis of responses or interaction patterns may constitute profiling under the GDPR where it evaluates aspects of a participant's behaviour or performance. The resulting feedback or indicators are intended for the training context and do not, by themselves, determine employment or disciplinary outcomes.
Wondder does not use solely automated processing to make decisions about individuals that produce legal effects or similarly significant effects within the meaning of Article 22 GDPR.
Client organisations remain responsible for any independent employment, disciplinary, performance-management or human-resources decisions they make using their own processes.
Wondder services are primarily intended for organisational and professional training and are not directed to children as consumer services. If a client organisation plans to include a person under 18, the client and Wondder must confirm the applicable legal basis, authorisation and age-appropriate transparency before the service is used.
Our website may use cookies, local storage, pixels and similar technologies to:
Where consent is required by law, non-essential technologies are activated only after the relevant consent has been provided.
You may accept, reject or manage non-essential technologies through the cookie settings available on the website. You may change or withdraw your consent at any time.
Further details about the technologies used, their purposes, providers and durations are available through our cookie settings or Cookie Declaration.
We may disclose personal data to carefully selected recipients where necessary for the purposes described in this Policy.
These recipients may include:
Service providers are contractually authorised to process personal data for the relevant service functions and any legally permitted security, compliance or support activities described in their agreements with Wondder.
An up-to-date list of relevant service providers or subprocessors may be made available to business clients or data subjects where appropriate.
We do not sell personal data.
Wondder aims to process personal data within the European Economic Area where reasonably possible.
Some service providers or their group companies may process data in countries outside the European Economic Area.
Where an international transfer requires additional safeguards, we use an appropriate transfer mechanism, which may include:
Information about applicable transfer safeguards may be requested by contacting privacy@wondder.io. Certain information may be redacted where necessary to protect confidential or security-related information.
We retain personal data only for as long as necessary for the relevant purpose.
The applicable period depends on factors such as:
Unless a shorter period applies under a client configuration or legal requirement, the following maximum periods generally apply:
Raw voice audio is not retained by Wondder as part of the standard training configuration. If a separate recording feature is enabled, the applicable retention and access rules are communicated before use.
When personal data is no longer required, it is deleted, anonymised or securely restricted. Residual copies may remain temporarily in protected backups until they are overwritten through the applicable backup cycle.
Subject to the conditions and limitations of applicable law, you may have the following rights:
Where we process personal data for direct-marketing purposes, you may object to that processing at any time.
To exercise your rights, contact:
We may need to verify your identity before responding. Where Wondder processes data solely on behalf of a client organisation, we may direct the request to, or coordinate the response with, that client.
You may lodge a complaint with the data-protection authority responsible for your place of residence, place of work or the location of the alleged infringement.
Wondder's competent supervisory authority is:
Berliner Beauftragte für Datenschutz und Informationsfreiheit
Alt-Moabit 59–61
10555 Berlin
Germany
Website: https://www.datenschutz-berlin.de
We encourage you to contact us first at privacy@wondder.io so that we have an opportunity to address your concern.
We use appropriate technical and organisational measures designed to protect personal data.
Depending on the service and risk, these measures may include:
No system can guarantee absolute security. Users should also take reasonable precautions to protect their accounts, devices and authentication information.
Our website and services may contain links to or embedded content from external providers.
Those external providers may process personal data under their own privacy policies. Depending on the integration, Wondder may be responsible for the initial disclosure or other aspects of the processing, while the external provider may act as a processor or an independent controller. Further information is provided through the relevant cookie or service notice.
Where required, external content that uses non-essential technologies will be subject to the cookie choices made through the website.
We may update this Privacy Policy where necessary to reflect:
The current version and effective date will be published at the top of this page.
Where a change materially affects how personal data is processed, we will take appropriate steps to inform affected individuals.
For privacy questions, requests or complaints, contact:
Wondder, VaRc GmbH
Zähringerstr. 26
10707 Berlin
Germany
Email: privacy@wondder.io