Legal · Last updated 24 September 2026

Privacy policy

What we collect on winsenrho.com and the Rho demo, where it goes, how long we keep it, and the rights you have over it.

1. Who we are

winsenrho.com is run by Winsen Labs (winsenlabs.com), which makes Winsen Rho ("we", "us"). Winsen Labs is based in India; its company details are on winsenlabs.com. For the personal data described here we are the controller under the EU and UK GDPR, the data fiduciary under India's Digital Personal Data Protection Act 2023, and the business under US state privacy laws, where those laws apply.

Write to us about anything in this policy, including a request or a grievance, at hello@winsenrho.com. Security issues go to security@winsenrho.com.

2. What this policy covers

This policy covers this website, its forms, and the Rho demo at demo.winsenrho.com, which section 12 describes. When a bank or financial institution uses Rho itself, we process its data on its instructions under our agreement with it, and its own privacy notice applies to the people whose data it holds.

3. What we collect

What you give us through a form

  • Contact form: your name, work email, designation, organisation, countries of operation, the topic and your message.
  • Security documentation form: your name, work email, designation, institution, its type if you give it, countries of operation, the documents you need, where you are in your review, and any note you add.
  • Security report form: your name, email, organisation if you give it, what you are reporting, how serious you think it is, what is affected, and your description and steps to reproduce. Security reports go to our security team's inbox, security@winsenrho.com, rather than our team's Slack channel.
  • Partner form: your name, work email, designation, organisation, its website if you give it, countries of operation, the type of partnership and your message.
  • Email: anything you send us at hello@winsenrho.com or another of our addresses.

Please don't include sensitive information, such as health, financial account or government ID details, in a message. We don't need it.

What is collected automatically

  • Server logs. Our host records requests to the site, including IP address, browser type and time, to keep the site running and secure.
  • Analytics, only if you allow them. Which pages you view, clicks on links and buttons, your browser and device type, the page that referred you, and an approximate location (country and city) worked out from your IP address. Analytics never capture what you type into a form, and we make no session recordings.

We don't buy personal data, and we don't combine what you give us with data from data brokers.

4. How we use it, and on what legal basis

PurposeDataLegal basis (EU and UK GDPR)
Replying to your enquiry and confirming we received itForm and email detailsSteps you asked us to take before a contract; our legitimate interest in answering enquiries
Assessing and managing a partnershipPartner form detailsSteps before a contract; legitimate interest
Telling our team about a new request (Slack and email)Form detailsLegitimate interest in handling requests quickly
Keeping the site secure and preventing abuseServer logs, form metadataLegitimate interest; legal obligation where one applies
Understanding how the site is usedAnalyticsYour consent, which you can withdraw at any time
Meeting legal obligations and defending legal claimsAny of the above, as neededLegal obligation; legitimate interest

Under India's DPDP Act we process what you submit for the purpose you gave it to us, which the Act treats as a legitimate use, and analytics only with your consent.

What we don't do. We don't sell your personal data or share it for cross-context behavioural advertising. We don't send marketing emails unless you ask for them. We don't use what you submit to train AI models, and we make no decisions about you by automated means that have legal or similarly significant effects.

5. Where your data is stored and how it flows

When you submit a form, what you enter goes to four places:

  • our database on Cloudflare D1, hosted in the Asia-Pacific region, which is the record of your request;
  • a notification to our team's Slack channel, so the right person picks it up;
  • a confirmation email to you, sent through Resend, whose replies arrive in our inbox at hello@winsenrho.com;
  • the authorised members of our team who handle it, who may work from India or other countries.

This means your data is stored and processed in several locations, including India, the United States and the Asia-Pacific region, and it may be accessed from wherever our team members and service providers work. Only people at Winsen Labs who need it to handle your request can see it.

All of it is encrypted in transit and at rest. Data travels between your browser, our servers and our providers over TLS, and each provider below encrypts the data it stores.

6. Who else processes it

These providers process personal data for us, under contracts that restrict them to our instructions:

ProviderWhat forWhere
VercelHosts this website and runs its server codeUnited States, with edge servers worldwide
Cloudflare (D1)Stores what you submit through our forms, and demo access requests with their visit logAsia-Pacific region
ResendSends the confirmation email to you, and the demo's sign-in codes and access emailsUnited States
Trigger.devRuns the demo's call audits, Ask Rho conversations and access-request jobsUnited States
OpenAIWrites Ask Rho's answers and scores audited calls in the demo, with response storage turned offUnited States
AssemblyAITranscribes and redacts calls audited in the demo, then deletes themUnited States
SlackDelivers a copy of each request to our team's channelUnited States
Our email providerHolds replies and correspondence at hello@winsenrho.comUnited States and other countries
PostHogCounts visits and clicks, only if you allow analyticsUnited States

We may also disclose personal data to professional advisers, to a buyer or successor if our business is reorganised or sold, or where the law requires it, such as a valid order from a court or regulator.

7. International transfers

Because of the flows above, your data may be transferred outside the country where you live, including from the European Economic Area, the United Kingdom or Switzerland to India, the United States and other countries whose laws may give less protection. Where the law requires it we rely on the European Commission's Standard Contractual Clauses, the UK International Data Transfer Addendum, the Swiss equivalents, or an adequacy decision, together with our providers' data processing terms. Ask us at hello@winsenrho.com for a copy of the relevant safeguards.

8. How long we keep it

  • Form submissions, with their Slack and email copies: up to 24 months after our last contact with you, unless they become part of a customer or partner relationship, when the terms of that relationship apply.
  • Server logs: for the short periods our host keeps them, normally no more than 30 days.
  • Analytics: up to 24 months, and deleted from your browser as soon as you turn analytics off.
  • Demo access requests and the demo visit log: as for form submissions, and deleted sooner if you ask.
  • Calls audited in the demo: audio and transcripts are deleted at AssemblyAI at the end of each audit run. We keep no copy.

We keep data longer only where the law requires it or to establish or defend a legal claim.

9. How we protect it

Beyond encryption in transit and at rest, access to the database, Slack channel and inbox is limited to named team members, and credentials for our providers are kept out of our code. No system is perfectly secure; if a breach affects your data, we will notify you and the authorities as the law requires. To report a vulnerability, write to security@winsenrho.com.

10. Your rights

Depending on where you live, you can ask us to:

  • tell you what personal data we hold about you and give you a copy;
  • correct or complete it;
  • delete it;
  • restrict or object to how we use it, including anything based on our legitimate interests;
  • give it to you, or to someone else, in a portable format;
  • withdraw your consent to analytics, at any time, without affecting what happened before.

Write to hello@winsenrho.com from the address you used, or tell us how to reach you. We may need to confirm your identity first. We reply within one month, or sooner where your local law requires, and we won't treat you differently for using your rights. You can also complain to your data protection authority.

11. Where you live

European Economic Area, United Kingdom and Switzerland

You have the rights in section 10 under the GDPR, the UK GDPR and the Swiss Federal Act on Data Protection, and the right to complain to your local supervisory authority, the UK Information Commissioner's Office, or the Swiss Federal Data Protection and Information Commissioner.

United States

If you live in California, Colorado, Connecticut, Virginia or another state with a consumer privacy law, you have the right to know what we collect and how we use it, to access, correct and delete it, and to opt out of its sale, sharing for targeted advertising, and profiling. In the last 12 months we have collected identifiers (name, email address, IP address), professional information (organisation and designation), and, with consent, internet activity (analytics), for the purposes in section 4, from you and your browser. We have not sold or shared personal data for cross-context behavioural advertising, and we don't collect sensitive personal information. We honour the Global Privacy Control signal as a refusal of analytics. An authorised agent may make a request for you with your signed permission. If we decline a request you may appeal by replying to our decision, and if we uphold it you may contact your state attorney general.

India

Under the Digital Personal Data Protection Act 2023 you can ask for a summary of your data and how it is processed, have it corrected, completed, updated or erased, nominate someone to exercise your rights if you die or become incapacitated, and have a grievance addressed by writing to us at hello@winsenrho.com. If you are not satisfied with our answer, you can complain to the Data Protection Board of India.

Other countries

If you live in the United Arab Emirates, Singapore, Canada, Australia or elsewhere, you have the rights your local law gives you, such as access and correction under Singapore's PDPA, Canada's PIPEDA and Australia's Privacy Act, and the right to complain to your local regulator. Write to hello@winsenrho.com and we will help.

12. The Rho demo

The Rho demo at demo.winsenrho.com shows Rho working on a fictional bank. Access is by approval. Nothing you upload, record or type in the demo is written to a database we run: call audio and transcripts are processed and discarded. The one exception is access: to decide who can use the demo, we keep your request and a log of your visits.

You give the demoWhat happens to it
Your work emailChecked against approved requests, used to send your sign-in code through Resend, and carried in your signed session cookie. Each time you enter it we record that it was entered and whether a code was sent. It is not sent to analytics.
Your access requestWhat you told us in the form, kept in our Cloudflare D1 database with a log of your visits: which pages you opened and when, the market and seat you chose, your browser, and a one-way hash of your network address, never the address itself. Read only by the Winsen team. The emails we send you about it are recorded too.
A call you upload or recordSent to AssemblyAI to be transcribed, with names, phone, account and ID numbers redacted. The redacted transcript is sent to OpenAI to be scored, with response storage at OpenAI turned off. As its last step the audit run deletes the transcript and any audio you uploaded at AssemblyAI. The run's record at Trigger.dev holds the steps and the result you see, and expires with its logs.
What you ask RhoSent to OpenAI to write the answer, and held by the chat session at Trigger.dev so you can continue the conversation later. Your browser keeps only the list of your conversations.
Reports and briefs you downloadMade when you ask for them and handed to you. We keep no copy.
Rate limitsShort-lived counters keyed by a one-way hash of your address and network, never the address itself. They expire within a day.

Please use made-up calls in the demo, never a real customer's. The demo's cookies and browser storage are listed in our cookie policy, and its analytics are off unless you turn them on.

13. Children

This site is for professionals. It isn't directed at anyone under 18, and we don't knowingly collect their data. If you think we have, write to us and we will delete it.

14. Changes to this policy

We update this policy when what we do changes. The date at the top shows the latest version, and we will point out significant changes on this site.

15. Contact

Winsen Labs · winsenlabs.com · hello@winsenrho.com