OpenWaya legal
Privacy Notice
How OpenWaya handles account, billing, usage, support, security, and optional request-content data.
Version 1.1 · Effective 2026-09-13
Who this notice covers
This Privacy Notice explains how OpenWaya, a DruxAI company, handles personal information for visitors, account holders, organization members, API users, support contacts, and other people whose information is processed through the service. It does not replace a customer's own notice for data that customer submits.
Questions, privacy requests, or complaints can be sent to support@openwaya.africa. Until a separate OpenWaya legal entity is registered and identified here, DruxAI operates the service and is responsible for the processing described in this notice, subject to any executed customer agreement.
Information we collect
We collect account and organization details; verified email and authentication identifiers; profile and preference data; API-key metadata; billing, credit, invoice, payment, tax, refund, and dispute evidence; model, token, cost, latency, route, error, and request metadata; security events; device, browser, IP-derived location, cookie, consent, and session data; and support communications.
We receive information from you, organization administrators, Clerk, payment processors, model providers, infrastructure and security services, and your use of OpenWaya. We do not sell personal information or build cross-site advertising profiles.
Google sign-in data
If you choose Sign in with Google, Google sends authentication data to Clerk, OpenWaya's identity provider. For basic sign-in, this can include your Google account identifier, name, profile image, email address, email-verification status, and authentication event information. OpenWaya uses this information only to create or link your account, authenticate you, prevent abuse, provide account features, and communicate about the service.
OpenWaya does not request Gmail, Drive, Calendar, contacts, advertising, or other sensitive Google API scopes for basic sign-in, and does not receive or store your Google password. OpenWaya does not use Google user data for advertising, sell it, or permit human access except when necessary for security, support you request, legal compliance, or service operation under access controls.
Clerk handles the Google OAuth exchange and may retain provider tokens as needed to maintain the connection. OpenWaya does not persist Google access or refresh tokens in its application database for basic sign-in. You can disconnect the connection in your account settings or Google Account permissions; you may also request account deletion or assistance at support@openwaya.africa.
How we use information
We use information to provide and secure accounts; authenticate users; route and deliver model requests; enforce preferences, limits, and policies; calculate usage and cost; process payments; issue invoices; detect fraud and abuse; provide support; send requested operational communications; maintain audit evidence; comply with law; and improve reliability through privacy-safe aggregate measurement.
Where applicable, processing relies on performing our contract, legitimate interests in operating and securing the service, consent for optional activities, and compliance with legal obligations. Customers are responsible for establishing an appropriate basis and notice for personal information they submit through the API.
Prompts, responses, and model providers
Prompts and request data are transmitted to the model provider or hosted route selected under the applicable routing policy. Provider processing locations, retention, training terms, and controls vary; review the catalog, subprocessors page, provider terms, and your organization configuration before sending sensitive data.
OpenWaya does not use prompt or response content for advertising. Content is not retained by default as ordinary request-log data. Optional diagnostic content capture is separately disclosed, purpose-bound, encrypted, access-controlled, consent- or administrator-authorized, and time-limited.
When we share information
We share only information reasonably needed with infrastructure, identity, model, payment, communication, support, analytics, and professional-service providers; with your organization and authorized members; when you direct us; during a properly structured business transaction; or where reasonably required by law, safety, fraud prevention, or rights protection.
Current service categories are listed on the Subprocessors page. Service providers are expected to process information for defined purposes and under appropriate safeguards. Provider credentials alone do not make an integration production-approved.
International processing
OpenWaya's primary AWS environment is in Canada. Identity, model, payment, messaging, security, and support providers may process information in other countries according to the selected route and provider. Privacy protections and government-access rules differ between jurisdictions.
Where required, OpenWaya uses contractual, organizational, and technical safeguards for cross-border processing. Enterprise customers can request available processing-location and transfer information through support@openwaya.africa.
Retention and deletion
We retain account, authentication, request metadata, security, support, billing, payment, and audit information only for configured operational, contractual, dispute, tax, security, and legal periods. Retention varies by category; short-lived operational data is deleted or reviewed sooner, while financial and audit evidence may be retained for up to seven years where required.
Account deletion removes or de-identifies eligible account data and propagates supported deletion actions. Some records may remain where needed for legal holds, fraud prevention, security integrity, payment disputes, tax, audit, or enforcement. Backups expire through controlled lifecycle schedules rather than immediate selective deletion.
Security
OpenWaya uses measures designed for the service risk, including encryption in transit and at rest, tenant isolation, least-privilege access, scoped credentials, secrets management, audit trails, rate and spend limits, provider governance, monitoring, vulnerability checks, incident response, backup, and recovery testing.
No system is completely secure. Protect your credentials, avoid sending secrets in prompts or support email, and report suspected compromise promptly to support@openwaya.africa.
Your rights and choices
Depending on applicable law, you may request access, correction, portability, deletion, restriction, or objection; withdraw consent for optional processing; manage cookies and communications; disconnect Google; or complain to a privacy regulator. We may verify identity and authority before acting and may retain information where law permits or requires.
Use available dashboard controls for profile, export, session, notification, and deletion actions, or contact support@openwaya.africa. Organization-controlled data may require coordination with the relevant organization administrator. We do not discriminate for exercising applicable privacy rights.
Children and changes
OpenWaya is intended for developers and organizations able to enter a binding agreement and is not directed to children. Do not use the service to process children's personal information unless you have all required authority, safeguards, notices, and agreements.
We may update this notice as the service, providers, or law changes. The published version and effective date identify the current notice, and material changes will be communicated through reasonable channels when required.
