This notice explains how Woyono handles personal data across its public website, account portal, help centre, web forms, browser demonstrations, mobile and desktop applications, and PC, console, cloud-streamed or browser-delivered video game services.
This is the main Woyono privacy notice. A short in-product notice may provide additional information at the point a specific permission, recording, organisation programme, research activity or new feature is enabled. Where the short notice and this notice differ, the more specific notice applies to that activity.
PRIVACY AT A GLANCE
| No legal name by default | Standard Woyono accounts use an email address, username or screen name, Woyono user ID and other non-name identifiers. |
|---|---|
| Transcript-first speech processing | Temporary audio used for transcription is ordinarily deleted within minutes or hours and no later than 24 hours unless you separately enable recording. |
| Human safeguards | Woyono does not itself make solely automated decisions with legal or similarly significant effects without a lawful basis and applicable safeguards. |
| No sale of personal data | Woyono does not sell personal data or identifiable interview content to advertisers, data brokers or unrelated organisations. |
| Privacy controls | You can manage optional permissions, analytics, recording, notifications and account deletion through product or device settings and by contacting Woyono. |
01Who we are, scope and data-protection roles
1.1 Data controller
For direct consumer use of the Services, the controller is:
| Entity | Woyono Limited |
|---|---|
| Company number | 17334114 |
| Registered office | Duncan Road, Manchester M13 0GU, United Kingdom |
| Jurisdiction | England and Wales |
| Privacy contact | privacy@woyono.com |
1.2 Services covered
This notice applies to the following Woyono services, together called the “Services”:
- the public website, marketing pages, help centre, browser-based account portal, web forms and browser demonstrations;
- the Woyono mobile and desktop application, including device permissions, offline storage, synchronisation, push notifications and app-store purchases;
- the Woyono PC, console, cloud-streamed or browser-delivered video game, including save data, progression, online services, in-game interviews, leaderboards and moderation features; and
- organisation or partner programmes that use Woyono interviews, simulations, dashboards or related services.
1.3 Nigerian operations and Modolos Studios Nigeria Limited
Woyono Limited is developing its Nigerian operations. Modolos Studios Nigeria Limited provides product-development, support, operational and local privacy-administration services under written agreements with Woyono Limited.
| Entity | Modolos Studios Nigeria Limited |
|---|---|
| RC number | RC1628188 |
| Registered Address | Mbonu Street, D/Line, Port Harcourt, Rivers State, Nigeria |
| Contact | dpo-ngr@woyono.com |
For direct consumer services, Modolos processes Woyono user information on Woyono’s documented instructions for assigned operational activities, except where Modolos must process information as an independent controller for its own legal obligations. Where Woyono acts as a processor for an organisation, Modolos may act as Woyono’s subprocessor. The relevant contracts must reflect the role that applies to each activity.
1.4 Organisation programmes
If a school, college, employer, training provider, government body, charity or other organisation enrols you in a programme, the organisation-specific notice or agreement explains the applicable roles. The organisation may be the controller and Woyono its processor, Woyono may be a separate controller, or the parties may have another lawful arrangement. The programme notice identifies who decides how results may be used and who handles rights requests.
1.5 Applicable law and EEA representative
This notice is designed to address the UK General Data Protection Regulation, the Data Protection Act 2018 as amended by the Data (Use and Access) Act 2025, the Nigeria Data Protection Act 2023 and related NDPC guidance. The EU GDPR applies where its territorial rules are met.
Where Woyono is required to appoint a representative in the European Economic Area under EU GDPR Article 27, the representative’s identity and contact details will be published in the relevant regional notice before the applicable EEA-targeted processing begins.
1.6 Related documents
This notice should be read with the Cookie and Technologies Policy, Data Use and Responsible AI Policy, Terms and Conditions, and any programme, recording, research or feature-specific notice shown to you.
02Personal data we collect
Account and contact information
Email address, username or screen name, Woyono user ID, authentication identifiers, account status, age band, country or region, language, organisation or programme ID, accessibility settings and communication preferences.
Interview, simulation and performance information
Interview questions, typed or spoken responses, transcripts, timing, scores, rubric evidence, skill indicators, developmental feedback, recommendations, progress history and human-review outcomes.
Gameplay and progression information
Save data, quests, achievements, experience points, virtual items, role selections, game economy records, gameplay events, multiplayer or leaderboard data, moderation records and other progression information.
App, device and technical information
App-instance and platform identifiers, device or console type, operating system, app or game version, permission status, push-notification token, local cache and synchronisation status, IP address, browser data, network quality, security logs, crash reports and diagnostic data.
Audio, video and acoustic information
Temporary audio streams for transcription; optional audio or video recordings where enabled; and an optional encrypted acoustic profile used only for speech-recognition quality as described in section 7.
Website and analytics information
Cookie and similar-technology identifiers, session and interaction events, approximate location derived from IP address, referral information, browser or device data and consent records.
Transaction and entitlement information
Purchase and subscription status, app-store receipt or transaction reference, entitlement history, refund status and limited billing or tax records. Apple, Google or another payment platform may process full payment-account information under its own privacy terms.
Communications and support information
Waitlist, newsletter, event-registration, customer-support and privacy-request messages, attachments, complaint records and correspondence.
Organisation and programme information
Programme eligibility, assigned roles, cohort or organisation identifiers, attendance or completion information and dashboard access records where an organisation programme applies.
2.1 Legal names and identity information
Woyono does not request or require a legal name for a standard consumer account. Woyono integrations are configured to request only the scopes needed for authentication or service delivery and should not import a legal-name field into the standard Woyono profile. Independent platforms, payment providers or programme organisations may hold legal-name information under their own notices, but Woyono does not instruct processors to enrich standard account records with it.
2.2 Sensitive or special-category information
Woyono does not ask users to include health, disability, race or ethnicity, religion, political opinions, trade-union membership, sexual-orientation information or other sensitive information in interview answers unless a specific programme lawfully requires and clearly explains it. Users may nevertheless reveal sensitive information in free-text, audio, video or support messages. Woyono minimises access to incidental sensitive information, does not use it to infer protected characteristics, and processes it only where an applicable legal condition and safeguards exist.
03How we obtain personal data
- directly from you when you register, speak, type, upload, purchase, play, contact support, submit a form or change settings;
- from an authorised organisation that enrols you, assigns a programme or reviews results under the programme notice;
- automatically through the website, app, game, local storage, SDKs, platform identifiers, cookies, security logs, crash reporting and service operation; and
- from approved authentication, app-store, payment, platform, communications, support, infrastructure, speech and AI providers.
04Required and optional information
Information marked as required is needed to create an account, secure the Services, provide a requested interview or simulation, restore purchases or meet legal obligations. If you do not provide required information, the relevant feature may not work.
Microphone, camera, media-library, notifications, optional analytics, recording, acoustic-profile, marketing and research features are optional unless a separately described organisation programme lawfully requires a feature. Refusing or withdrawing an optional permission does not prevent access to unrelated core features.
05Purposes and lawful bases
The lawful basis depends on the activity and your jurisdiction. Where Woyono relies on legitimate interests, it considers necessity, reasonable expectations and the effect on your rights. The following table describes the main activities.
| Activity | Information used | Purpose | Main lawful basis |
|---|---|---|---|
| Create and manage an account | Account identifiers, authentication data, age band, region, language and settings | Provide registration, sign-in, account recovery and cross-device access | Contract or pre-contractual steps; legitimate interests in account administration and security |
| Provide interviews, simulations and feedback | Questions, responses, transcripts, timing, rubric evidence, scores, feedback and progress | Deliver requested interview practice, simulations, scoring and developmental recommendations | Contract; in organisation programmes, the organisation’s lawful basis and Woyono’s documented processor instructions |
| Operate the app and game | App-instance and platform identifiers, save data, progression, quests, achievements, entitlements, local-sync status and gameplay events | Provide gameplay, progression, synchronisation, feature access and service continuity | Contract; legitimate interests in reliable service operation |
| Process purchases and entitlements | Transaction references, receipts, subscription status and entitlement information | Complete purchases, restore entitlements, prevent duplicate access and keep accounting records | Contract; legal obligation; legitimate interests in fraud prevention |
| Provide support and communications | Contact details, support messages, attachments and service communications | Respond to enquiries, deliver notices and resolve technical or account issues | Contract; legitimate interests; legal obligation where applicable |
| Protect Woyono and users | IP addresses, device and network information, logs, moderation records, fraud or cheating indicators and security events | Authenticate users, prevent abuse, cheating, fraud and unauthorised access; investigate incidents | Legitimate interests in security and service integrity; legal obligation where applicable |
| Optional audio/video recording and acoustic profile | Audio, video, recording metadata and encrypted acoustic profile | Provide an optional recording, improve speech-recognition quality or support a specifically described feature | Consent, unless a separate programme notice identifies another lawful basis permitted by law |
| Analytics and service improvement | Pseudonymous usage events, device information, feature interactions, diagnostics and aggregate performance information | Understand feature use, improve reliability and measure service effectiveness | Consent for non-essential analytics and similar technologies where required; legitimate interests for strictly necessary operational measurement |
| Marketing and research participation | Email address, preferences, campaign engagement and information submitted for a research activity | Send opted-in communications or conduct a separately described study | Consent; legitimate interests for permitted business-to-business communications, subject to an effective opt-out |
| Comply with law and establish claims | Information relevant to tax, consumer, safeguarding, regulatory, dispute and legal matters | Meet legal duties, respond to lawful requests and establish, exercise or defend legal claims | Legal obligation; legitimate interests; substantial public interest or other condition where special-category data is involved |
06AI, profiling and automated decisions
6.1 How Woyono uses AI
Woyono uses AI and rules-based systems to generate or adapt interview questions, transcribe speech, compare responses with role-relevant rubrics, identify evidence of skills, produce developmental feedback and personalise progression or recommendations. The systems may profile performance, skill evidence and progress for these purposes.
6.2 Main factors and limitations
Depending on the feature, an assessment may consider the role requirements, the rubric, evidence contained in the response, relevance, completeness, clarity, timing where relevant and consistency across responses. AI output is probabilistic and may be incomplete or incorrect. Users can report an AI result, request correction and ask for human review where applicable.
6.3 Significant decisions and safeguards
Woyono does not itself make a decision based solely on automated processing that produces legal or similarly significant effects unless the processing is legally permitted and appropriate safeguards apply. These may include clear information, an opportunity to make representations, meaningful human intervention and a right to contest the decision, in accordance with UK GDPR Articles 22A to 22C, EU GDPR Article 22 where applicable, and NDPA section 37.
If a partner organisation may use a result for recruitment, education, funding, disciplinary action or another significant decision, the organisation-specific notice must explain that use, identify the decision-maker, provide meaningful human review and explain how to challenge the outcome.
6.4 Prohibited inferences and model training
Woyono does not infer protected characteristics, emotion, honesty, personality or mental state from a person’s voice, face or behaviour. Woyono does not authorise identifiable interview content to be used to train a provider’s general-purpose models unless a separate notice identifies the purpose and a valid lawful basis. De-identified or aggregate information may be used to test and improve Woyono features where permitted.
07Audio, video and acoustic data
7.1 Transcript-first design
The standard speech workflow is transcript-first. Temporary audio buffers are used to create a transcript and for limited quality or security checks. They are ordinarily deleted within minutes or hours and no later than 24 hours unless you separately enable recording or a shorter notice applies.
7.2 Optional recording
If audio or video recording is enabled, Woyono provides an on-screen notice explaining the purpose, recipients and retention period before recording begins. Optional recordings are normally kept for 30 to 90 days unless a longer period is specifically justified and disclosed.
7.3 Microphone and camera connections
Woyono opens the microphone or camera only for the feature you activate and closes the application connection when the interview, call, recording or related feature ends. Your operating system may continue to remember the permission until you revoke it in device settings; a retained operating-system permission does not mean Woyono continues capturing audio or video.
7.4 Optional acoustic profile
Where you choose to enable this feature, Woyono may create an encrypted acoustic profile to improve how accurately the service recognises your speech, including in noisy environments or where your accent, pronunciation or speaking pattern affects transcription quality.
The profile is used only to improve speech recognition. It is not used to identify or authenticate you, compare your voice with another person’s voice, infer emotion, honesty, personality, health or protected characteristics, or provide advertising.
You can disable the feature and delete the acoustic profile separately from your account through the relevant privacy settings. Deleting the profile does not require you to delete your Woyono account.
Woyono will not use the profile for unique identification or authentication unless it first updates this notice, completes the required data-protection assessment, identifies the applicable lawful basis and sensitive or special-category data condition, and obtains explicit consent where required.
08App, game and device features
8.1 Device permissions
The app or game may request microphone, camera, media or file access, notifications, local-network access or other permissions only when needed for a feature. The permission prompt and any preceding in-product explanation identify the purpose. You can change permissions in the product or device settings, although disabling a permission may prevent the related feature from working.
8.2 Local saves, offline storage and synchronisation
The app or game may store encrypted or access-controlled local saves, caches, configuration and offline progress on your device. When synchronisation is enabled, relevant data is transmitted to Woyono’s systems. Local data may remain until you sign out, clear app data or uninstall the product. Device, console or platform backups are controlled by the relevant platform provider.
8.3 Push notifications
Woyono uses a platform-issued push token to deliver account, interview, event, security or progression notifications. Notification content is minimised on lock screens where practicable. You can disable notifications in Woyono or device settings.
8.4 Purchases and platform accounts
Apple, Google, console platforms or other payment providers may process account and payment information as independent controllers. Woyono normally receives a transaction reference, receipt status, entitlement and limited fraud or refund information rather than full card details.
09Children and young people
9.1 Consumer eligibility
The direct consumer service is intended for people aged 16 or over. This is Woyono’s service eligibility rule and is not a statement that 16 is the statutory digital-consent age in every country. In the United Kingdom, a child aged 13 or over may generally consent for an online service where consent is the lawful basis. Nigerian consent requirements are assessed under NDPA section 31, the Child Rights Act and applicable NDPC guidance.
9.2 High-privacy defaults
Users under 18 receive high-privacy defaults, age-appropriate explanations and restrictions on marketing, public-profile visibility, precise location, social interaction and unnecessary data collection. Woyono considers the best interests and differing needs of children when designing online services likely to be accessed by them.
9.3 Younger users in supervised programmes
A programme involving users below the normal consumer age requires a separate assessment and programme notice, appropriate authority, age and consent mechanisms, safeguarding controls, restricted access and parental or guardian involvement where required by law. Educational or social-care exceptions are used only where their legal conditions are met.
12International transfers
Personal data may be processed in the United Kingdom, Nigeria, the EEA, the United States and other locations used by the providers in Schedule 1. Woyono records and reviews the legal basis for relevant transfers.
For restricted transfers from the United Kingdom, Woyono uses adequacy regulations or appropriate safeguards such as the UK International Data Transfer Agreement or the UK Addendum to EU Standard Contractual Clauses, together with the UK data protection test and supplementary measures where required. For EEA transfers, Woyono uses adequacy decisions or EU Standard Contractual Clauses and applicable transfer assessments. Transfers from Nigeria are made under NDPA sections 41 to 43, using adequacy, binding rules, contractual clauses, codes, certification or another lawful basis as applicable.
13Retention and deletion
Woyono keeps personal data only for as long as reasonably necessary for the purpose, account or programme, security, legal obligations and claims. The following periods are indicative maxima unless a specific notice states a shorter period or law requires otherwise.
| Data category | Typical retention |
|---|---|
| Account and profile data | While the account is active and normally up to 24 months after closure, unless earlier deletion is required or a longer period is needed for a legal claim, fraud prevention or another documented legal reason. |
| Interview transcripts, scores and developmental results | While the account or programme is active and normally up to 24 months afterwards. |
| Game save, progression and entitlement records | While the account is active and normally up to 24 months afterwards; transaction evidence may be retained for the statutory accounting period. |
| Temporary transcription audio | Minutes or hours, and no later than 24 hours, unless you separately enable recording or a shorter in-product notice applies. |
| Optional audio or video recordings | The period shown when recording is enabled, normally 30 to 90 days unless a longer period is specifically justified and disclosed. |
| Optional acoustic profile | Until you disable the feature, delete the profile or close the account, subject to secure deletion cycles and backup rotation. |
| Push-notification tokens and app-instance identifiers | Until notifications are disabled, the app instance becomes inactive or the account is closed, followed by a reasonable deletion cycle. |
| Local saves, caches and offline data | Until you sign out, clear local data or uninstall the app or game. Device, platform or cloud backups may follow the retention settings of the relevant platform provider. |
| Analytics data | Normally up to 14 months where analytics is enabled, unless a shorter configuration applies. |
| Support records | Normally up to 36 months after resolution. |
| Security, crash and diagnostic logs | Normally 6 to 18 months, depending on the event, risk and investigation requirements. |
| Financial and tax records | The period required by applicable accounting and tax law, ordinarily six years in the United Kingdom and the period required by Nigerian law. |
| Privacy requests and complaints | As long as reasonably necessary to fulfil the request, demonstrate compliance and manage related claims, normally up to six years after closure. |
13.1 Account deletion
Where account creation is available, you may initiate deletion through the app or game account/privacy settings where provided, or request deletion outside the product by contacting privacy@woyono.com from the email associated with the account. Woyono removes or de-identifies information from active systems and instructs processors as required, subject to legal retention and documented exceptions.
13.2 Backups and derived information
Deletion is propagated to active systems, relevant derived profiles, scores, embeddings, indexes and instructed processors where required. Information remaining in securely isolated backups expires through the applicable backup-rotation cycle and is not returned to routine active use. If a backup is restored, relevant deletion or suppression instructions are reapplied.
14Security
Woyono applies risk-based technical and organisational measures appropriate to the information and processing. Measures may include encryption in transit and at rest, tenant or programme separation, least-privilege access, administrator multi-factor authentication, secure development and testing, logging and monitoring, incident response, resilient backups, vendor due diligence and staff confidentiality and training.
No system is completely secure. Users should protect account credentials, use supported devices and report suspected unauthorised access promptly. Woyono targets alignment with ISO/IEC 27001, ISO/IEC 27701 and ISO/IEC 42001; this describes a target and is not a certification claim.
15Your rights and choices
15.1 UK and EEA rights
Depending on the circumstances, you may have rights to access personal data, correct inaccurate information, request erasure, restrict processing, object to legitimate-interest or direct-marketing processing, receive portable data, withdraw consent and obtain safeguards relating to significant automated decisions. EU GDPR rights apply where the EU GDPR governs the processing.
15.2 Nigerian rights
Under the NDPA, Nigerian data subjects may request access, information, rectification, erasure or restriction under section 34; withdraw consent under section 35; object under section 36; request safeguards for qualifying automated decisions under section 37; and exercise portability rights under section 38.
15.3 How to exercise rights
Contact privacy@woyono.com, dpo@woyono.com or, for Nigerian matters, dpo-ngr@woyono.com. We normally verify a request through a logged-in account, a code sent to the registered email, username, Woyono user ID, session reference, platform identifier or organisation/programme ID. If we reasonably doubt identity, we may request proportionate additional information. Formal identification is requested only where reasonably necessary and is not retained longer than needed for verification.
15.4 Product and device choices
Permissions, optional analytics, recording, acoustic profile, marketing and notifications can be managed through relevant Woyono, browser, operating-system, app-store or console settings. Withdrawing consent does not affect processing that was lawful before withdrawal.
16Data-protection complaints, regulators and breaches
16.1 Complaining to Woyono
You may make a data-protection complaint by emailing privacy@woyono.com. Woyono accepts complaints made through other reasonable channels, acknowledges a UK data-protection complaint within 30 days, makes appropriate enquiries, keeps you informed and communicates the outcome without undue delay. A complaint may be made separately from a rights request.
16.2 Supervisory authorities
- United Kingdom: Information Commissioner’s Office — ico.org.uk;
- Nigeria: Nigeria Data Protection Commission — ndpc.gov.ng; or
- European Economic Area: the supervisory authority in the country where you live, work or consider the infringement occurred.
16.3 Personal-data breaches
Where a qualifying personal-data breach occurs, Woyono notifies the relevant regulator within the applicable statutory period, including within 72 hours where required under UK GDPR Article 33 or NDPA section 40. Woyono notifies affected individuals without undue delay where the applicable high-risk threshold is met.
17Governance and regulatory registration
Woyono maintains records of processing, vendor assessments, transfer assessments, legitimate-interest assessments and data-protection impact assessments where required. Woyono Limited and Modolos Studios Nigeria Limited separately assess and maintain any registration, data-protection-officer and compliance obligations that apply to them, including obligations for data controllers or processors of major importance under NDPA sections 32 and 44. One entity’s registration does not automatically satisfy another entity’s separate legal obligation.
18Changes and contact
Woyono may update this notice when services, law, providers or data practices change. Material changes are notified through the website, app, game, account dashboard or associated email address where appropriate. The “last updated” date shows when the notice was most recently revised.
| Privacy requests and complaints | privacy@woyono.com |
|---|---|
| Privacy Lead / data-protection contact | dpo@woyono.com |
| Nigeria privacy contact | dpo-ngr@woyono.com |
| Controller | Woyono Limited, Company No. 17334114, Duncan Road, Manchester M13 0GU, United Kingdom |
19Schedule 1: Service providers and platform operators
This schedule covers providers that may process personal data across the Services. Each product uses only the providers needed for its live configuration. Processors are subject to appropriate data-processing terms; independent platform controllers process information under their own privacy notices and platform agreements. Woyono reviews this list when providers or material processing arrangements change.
| Provider | Role | Purpose | Data processed | Country / region | Transfer mechanism and safeguards |
|---|---|---|---|---|---|
| Hetzner Online GmbH | Processor / service provider | Primary computing, application hosting, storage and backups | Account identifiers, user content, application records, uploaded files, database content, IP addresses and logs | Germany and/or Finland, depending on the selected data centre | Article 28 processing terms; UK adequacy for the EEA; appropriate contractual safeguards for authorised third-country processing. |
| Microsoft Corporation and applicable Microsoft affiliate (Azure) | Processor / service provider | Hybrid infrastructure, identity and access management, security, configuration, backup and regional failover | Account and administrator identifiers, email addresses, authentication records, access tokens, IP/device data, configuration and diagnostic logs | Selected UK and/or EU regions; limited global operational access may occur depending on the service | Microsoft Data Protection Addendum; adequacy where applicable; SCCs and applicable UK transfer terms for restricted transfers. |
| Cloudflare, Inc. | Processor / service provider | DNS, content delivery, web application firewall, DDoS protection, routing and edge caching | IP addresses, request URLs, HTTP headers, cookies, security-event information, network metadata and temporary cached content | Global edge network, including UK, EEA, United States and other points of presence | Cloudflare DPA; adequacy where applicable; SCCs and UK Addendum/IDTA; supplementary security measures. |
| Supabase, Inc. | Processor / service provider when Supabase Cloud is used | Managed PostgreSQL, authentication, storage, edge functions and real-time services | Account, authentication and session data, application records, uploaded files, user content, logs and service metadata | Customer-selected region; limited support and subprocessor processing may occur internationally | DPA; adequacy where applicable; SCCs and applicable UK transfer terms. If Supabase is fully self-hosted without vendor access, Supabase may not process production personal data. |
| Unity Technologies and applicable affiliates | Processor / service provider; some platform services may have separate roles | Game engine cloud services, builds, analytics, diagnostics and crash reporting where enabled | Player or user identifiers, device and hardware information, IP address, gameplay events, build data, crash reports and diagnostics | United States, EU and other locations used by Unity and its subprocessors | Unity processing terms; adequacy where applicable; SCCs and applicable UK transfer terms. |
| Apple Inc. and Apple Distribution International Ltd. | Independent platform controller for App Store accounts and purchases; processor / service provider for certain developer services | iOS/macOS distribution, App Store administration, in-app purchases, receipt validation and push notifications | Apple account, transaction and subscription data, receipts, device identifiers, push tokens and notification payloads | Ireland, United States and other Apple operating locations | Apple platform agreements and privacy terms; processor terms for relevant developer services; Apple determines purposes for its independent-controller activities. |
| Google LLC, Google Ireland Ltd. and Google Commerce Ltd. | Independent platform controller for Google Play accounts and purchases; processor / service provider for Firebase services | Android distribution, Google Play billing, purchase validation and Firebase Cloud Messaging | Google account, transaction and subscription records, purchase tokens, app-instance identifiers, device information, push tokens and message metadata | Ireland, United States and other Google operating locations | Google Play controller terms; Firebase Data Processing and Security Terms; adequacy where applicable; SCCs and applicable UK transfer terms. |
| Deepgram, Inc. | Processor / service provider | Streaming speech-to-text transcription | Live or recorded audio, transcript, language, timestamps, confidence data, speaker information where enabled, request identifiers and technical metadata | United States by default or EU where an EU endpoint has been contracted and configured | DPA; adequacy where applicable; SCCs and applicable UK transfer terms. Retention follows Woyono’s contracted endpoint and configuration. |
| OpenAI OpCo, LLC and applicable OpenAI affiliate | Processor / service provider | AI-assisted question generation, follow-ups, response analysis and rubric-based scoring | Interview prompts and responses, transcripts, role descriptions, rubrics, scoring criteria, generated outputs and request metadata | United States and other locations in OpenAI’s current subprocessor list; regional processing depends on contract and configuration | OpenAI DPA; SCCs and UK Addendum where applicable; business/API data controls. Woyono does not authorise identifiable interview content for general model training unless separately disclosed. |
| Plus Five Five, Inc., trading as Resend | Processor / service provider | Transactional email, account verification, password resets, security alerts and service notices | Recipient email, sender information, message subject/body, verification or reset tokens, delivery status, timestamps, IP information and delivery metadata | United States and authorised subprocessor locations | Resend DPA; SCCs and applicable UK transfer terms; Data Privacy Framework participation where relied upon. |
| Burke Software and Consulting LLC, trading as GlitchTip | Processor / service provider where hosted GlitchTip or vendor access is used | Error monitoring, crash reporting, performance and uptime monitoring | Error messages, stack traces, application logs, request metadata, session identifiers, IP address, browser, device and operating-system information | Germany for the EU-hosted service; United States for the US-hosted service | DPA; UK adequacy for Germany; SCCs and UK transfer terms for relevant third-country access. Fully self-hosted use without vendor access may not involve vendor processing. |
| Google Ireland Ltd. / Google LLC (Google Analytics 4) | Processor / service provider for configured analytics services | Website and application analytics and service-usage reporting where enabled | Pseudonymous client or app-instance identifiers, sessions, events, approximate location, browser/device information and interactions | Initial regional collection with processing through Google’s global infrastructure | Google data-processing terms; adequacy where applicable; SCCs and UK transfer terms. Non-essential analytics is controlled through consent and product settings. |
| Modolos Studios Nigeria Limited | Operational service provider / processor; subprocessor where Woyono acts for an organisation; separate controller for its own legal obligations | Nigerian product development, support, operations, safeguarding and local privacy administration | Only the account, programme, support, technical and compliance information needed for the assigned activity | Nigeria | Written management and data-processing terms, confidentiality, access controls and NDPA safeguards. Controller roles are separately documented where Modolos determines its own purposes. |