Privacy Policy
Last updated: 15 September 2026
1. Introduction
This privacy policy (Policy) relates to your personal information in connection with your use of and access to the Connector Central website (connectorcentral.com) and application (together, the Connector Central Platform) and any services provided by Connector Central (the Connector Central Platform and services together forming the Connector Central Services).
We are committed to protecting your information and your right to privacy. If you have any questions or concerns about our Policy, or our practices with regards to your personal information, please contact us via support@connectorcentral.com.
When you use the Connector Central Services, you trust us with your information and we take your privacy very seriously. We seek to explain to you in the clearest way possible what information we collect, how we use it and what rights you have in relation to it. We hope you take some time to read through it carefully, as it is important. If there are any terms in this Policy that you do not agree with, please discontinue your use of the Connector Central Services.
2. Changes to This Policy or Your Personal Information
We review this Policy regularly and reserve our right to amend it at any time. It is your responsibility to check regularly and determine whether you still agree to comply with the Policy. If you do not agree to any changes to this Policy then you must immediately stop using the Connector Central Services. In the event we make any significant changes to this Policy we will use our reasonable endeavours to inform you of such changes in advance in writing.
It is important that the personal information we hold about you is true, complete, accurate and current. Accordingly, you must notify us of any changes to your personal information (for example, if you change your email address).
3. About Us
The Connector Central Services are owned and operated by WLS Labs Ltd, a company registered in England and Wales with company number 15609221 and whose registered office is situated at 66 Paul Street, London, England, EC2A 4NA (WLS Labs/we/us/our).
WLS Labs is the controller (also known as a data controller) of, and is responsible for, your personal information. The term “you” refers to the user wishing to access and/or use the Connector Central Services.
The Connector Central Platform provides a governed gateway between our customers’ AI assistants (such as Claude) and the third-party platforms they choose to connect: workspaces enable connectors, hold the associated credentials, grant per-person access, and record an activity log of AI tool calls.
4. Information We May Collect About You
4.1 Personal information you disclose to us
In Short: We collect personal information that you provide to us, including information such as your name, address, contact information, date of birth, job title and social media handles/URLs (see paragraph (b) below for further details).
(a) Where and how we collect personal information
We collect personal information that you voluntarily provide to us when registering to use and actually using the Connector Central Services, or otherwise contacting us.
If you apply or are put forward for a role with us, or work for us (either directly or indirectly) for any period of time, we also collect your personal information, which may include your contact details, financial and payment details, details of your education, qualifications and skills, your marital status, your nationality, your NI number, your job title and your CV.
If you give us personal information on behalf of a third party, for example an employee, contractor or client, in providing that information to us you are confirming that you have sought and obtained, from that individual, permission for you to:
- Consent on their behalf to the processing of their personal data;
- Receive on their behalf any data protection notices; and
- If relevant, consent to the transfer of their personal data abroad,
and you shall indemnify us and hold us harmless against any claims, actions, proceedings, losses, damages, costs (including reasonable legal costs) and expenses (including taxation), in each case of any nature whatsoever, arising out of or in connection with your failure to obtain these permissions.
More particularly, the personal information that we collect depends on the context of your interactions with us, the choices you make and the products and features you use. For example:
- We collect personal information via the Connector Central Platform when you sign up to, participate in, use or receive a service from us, for example where you use the Connector Central Platform, contact us, request information online, report an issue, provide feedback or enter a live chat.
- Our website also uses cookies and collects IP addresses (for more information on this, see our Cookie Policy).
- We may monitor and record communications with you (such as telephone conversations and emails). We may do this for a number of reasons, such as to check the quality of our customer service, for training purposes, to prevent fraud or to make sure we are complying with legal requirements.
- If you visit our offices, some personal data may also be collected from monitoring devices and systems such as access cards.
Unless otherwise specified, all personal information requested by us is mandatory and failure to provide this information may make it impossible for us to provide our services. In cases where we specifically state that some personal information is not mandatory, you are free not to provide this personal information without consequences to the availability or the functioning of the Connector Central Services.
(b) The types of personal information we may collect
When you use the Connector Central Services and/or when you otherwise deal with us, we may collect the following information about you (the Information):
- Identity Data, which includes your first name, last name, gender and profession.
- Contact Data, which means the data we use to contact you including your billing address, delivery address, email address and contact number.
- Commercial Data, which means information you provide when you contact sales, such as the plan you are interested in and the requirements you describe.
- Profile Data, which includes your username, email address and log-in data, details of any purchases or orders made by you, and your interests, preferences, feedback and survey or questionnaire responses and, in relation to job applicants, details of your next of kin, emergency/alternate contact(s) or referee(s).
- Connector Credential Data, which means the API keys or OAuth tokens for third-party platforms that you or your workspace owners choose to connect to your workspace. These are stored encrypted at rest and are used only to execute the tool calls that you or your authorised AI clients initiate.
- Activity Metadata, which means records of tool calls made through your workspace — which member or AI client invoked which tool, on which connector, when, and with what status and duration. We do not store the content of tool requests or responses in the activity log.
- Operational Evidence, which includes access decisions, execution timing and outcomes, and hashes of tool inputs or results. Platform usage facts retain workspace ID, tool identifiers and timestamps permanently, without member names or raw payloads, including after workspace deletion.
- Usage Data, which includes Information collected automatically through us, or via third-party service providers, about how you use the Connector Central Services. This includes your browsing patterns and Information such as how long you might spend on one of our webpages on the Connector Central Platform and what you look at and for, the page that referred you to the Connector Central Platform and the click stream during your visit to our website, page response times, and page interaction Information (for example, clicks you make on a page).
- Marketing and Communications Data, which includes your preferences with regards to receiving marketing from us and your other communication preferences.
- Other Information relevant to services, customer surveys, questionnaires and/or offers.
4.2 Sensitive personal information
In Short: Occasionally we may need to ask you to provide sensitive personal data. If we do, we will explain why we are requesting it and how we will use it.
We will not usually ask you to provide sensitive personal information. We will only ask you to provide sensitive personal information if we need to for a specific reason, for example, if we believe you are having difficulty dealing with your account due to illness. If we request such information, we will explain why we are requesting it and how we will use it.
4.3 Personal information from third parties
In Short: We may receive information about you from third parties, and we may use this information to provide, improve and personalise the Connector Central Services.
Occasionally we may receive information about you from other sources, which we will add to the information we already hold about you in order to help us provide, improve and personalise the Connector Central Services. If you apply for a job with us, we may also receive information from those who provide references relating to your prospective or actual engagement or employment.
In addition, when you or your authorised AI clients invoke tools on platforms you have connected to your workspace, data returned by those platforms passes through the Connector Central Services transiently in order to fulfil the tool call. This data may include personal information held in those platforms. We do not store this transiting data; operational metadata and hashes are retained as described in sections 4.1(b) and 9, without the raw inputs or results.
4.4 Information automatically collected
In Short: Some Information – such as IP addresses and/or browser and device characteristics – is collected automatically when you use the Connector Central Platform.
We automatically collect certain Information when you visit, use or navigate the Connector Central Platform. This Information does not reveal your specific identity (unless your device name is the same as your name) but may include device and usage Information, such as your IP address, browser and device characteristics, operating system, language preferences, referring URLs, device name, country, location, Information about how and when you use the Connector Central Platform and other technical Information. This Information is primarily needed to maintain the security and operation of the Connector Central Platform, and for our internal analytics and reporting purposes.
We use PostHog, an analytics platform hosted in the European Union, to collect page views, click events, and browser/device information across the Connector Central Platform, including both public pages and the authenticated application. PostHog is configured without cookies (memory-only persistence), so no tracking cookies are set on your device. When you are logged in, PostHog associates your activity with your user profile (email and name) to provide product analytics. We also capture server-side product analytics events (such as account creation and connector usage) to understand how the platform is used and improve our service.
Browser PostHog events pass through a Cloudflare proxy. Google Ads and Google Analytics, where configured, collect website and conversion events as explained in the Cookie Policy. These services have their own processing locations, listed on our Sub-Processors page.
Like many businesses, we also collect Information through cookies and similar technologies. You can find out more about this in our Cookie Policy.
5. How We Use Your Information
In Short: We process your personal information to provide and improve the Connector Central Services, to administer your account and sales inquiries, to keep the platform secure, and to communicate with you. We only process your personal information where we have a valid lawful basis to do so.
We use the Information we collect for the following purposes and on the following lawful bases:
- To provide the Connector Central Services — creating and administering your account and workspaces, storing connector credentials you provide, executing the tool calls you or your authorised AI clients initiate, enforcing access grants, and maintaining the activity log. Lawful basis: performance of a contract.
- To respond to sales inquiries and administer commercial agreements — understanding your requirements, preparing an offer and keeping the invoicing and accounting records required to perform a contract and meet our legal obligations. Lawful basis: steps taken at your request before entering a contract, performance of a contract and compliance with our legal obligations.
- To secure the Connector Central Services — authenticating users, preventing fraud, abuse and unauthorised access, rate limiting, monitoring for errors, and maintaining audit and activity records. Lawful basis: our legitimate interests in keeping the Services and our customers’ data secure.
- To communicate with you — sending service communications such as account verification, password reset, team invitations, and material changes to the Services or our terms. Lawful basis: performance of a contract and our legitimate interests.
- To improve our products — analysing how the Connector Central Platform is used (see section 4.4) so we can fix problems and improve features. Lawful basis: our legitimate interests. Our analytics platform is EU-hosted and configured without tracking cookies.
- To send marketing communications — only as described in section 13. Lawful basis: consent, or the soft opt-in for our own similar products and services.
- To consider job applicants — assessing applications and engagements as described in section 4.1(a). Lawful basis: our legitimate interests and steps taken prior to entering a contract.
- To comply with the law — keeping records we are legally required to keep and responding to lawful requests from authorities. Lawful basis: compliance with our legal obligations.
Where we rely on our legitimate interests, we have considered and balanced those interests against your rights and freedoms. We do not use your personal information for automated decision-making that produces legal or similarly significant effects about you. For clarity, decisions made or actions taken by AI clients that you or your organisation connect to the Services are made on your instructions and under your control, not ours.
6. How We Share Your Information
In Short: We do not sell your personal information. We share it only with the service providers who help us run the Connector Central Services, with platforms you instruct us to connect to, with our professional advisers, and where the law requires it.
We may share your Information with:
- Our sub-processors — the hosting, email, analytics, security and monitoring providers listed on our Sub-Processors page, in each case only to the extent necessary for them to perform their services for us.
- Platforms you connect — when you or your authorised AI clients invoke a tool, the request (and the credentials required to authenticate it) is transmitted to the relevant connected platform on your instruction. Those platforms process data under your own agreements with them, as described in section 4.3 and our Data Processing Agreement.
- Professional advisers — our lawyers, accountants, auditors and insurers where reasonably necessary.
- Authorities and other parties where required by law — courts, regulators, law enforcement or other authorities where we are under a legal obligation to do so, or where disclosure is necessary to establish, exercise or defend legal claims, or to protect the rights, property or safety of WLS Labs, our customers or others.
- A purchaser or prospective purchaser of our business — if we sell, transfer or merge parts of our business or assets, in which case the new owner may use your personal information in the same way as set out in this Policy.
7. International Transfers
In Short: The Connector Central Platform is hosted in the European Union (Germany). Where our service providers process personal data outside the UK, we ensure appropriate safeguards are in place.
Our application and databases are hosted on Hetzner infrastructure in Nuremberg, Germany. This location does not describe every service that processes data: email, monitoring, analytics proxying, and object storage have their own processing locations. The Sub-Processors page lists these providers and their processing locations.
Some of our sub-processors are located in the United States or process data globally. For those transfers we rely on the UK-US Data Bridge (the UK Extension to the EU-US Data Privacy Framework) where the provider is certified, or on the UK International Data Transfer Agreement (IDTA) or the UK Addendum to the EU Standard Contractual Clauses. Our current sub-processors and their locations are listed on our Sub-Processors page.
If you connect a platform whose servers are located outside the UK, data transmitted to that platform when you or your authorised AI clients invoke tools is transferred under your own relationship with that platform.
8. Third Party Websites
The Connector Central Services may contain links to third-party websites and services that are not operated by us, and connected platforms are operated by third parties under their own policies. If you follow a link to a third-party website or use a connected platform, that third party’s privacy policy — not this Policy — governs their processing of your personal information. We encourage you to read the privacy policy of every website you visit and every platform you connect.
9. Data Retention
In Short: Retention depends on the category of information. The workspace Activity retention setting does not apply to every record, third-party service, or backup.
- Account and workspace data is kept while the account or workspace exists. Workspace deletion removes its live records and logo. Account deletion also deletes owned workspaces, removes memberships elsewhere, and deletes the personal profile and profile image. Other workspaces and their audit history remain.
- Connector credentials remain encrypted in the connection record when you disconnect a provider; disconnection stops use of that connection but does not erase it. Workspace deletion removes its connection records. Ask support about an earlier removal, and revoke credentials directly with the connected provider where needed.
- Activity log records are retained for the period configured for your workspace (30 days by default) and then removed by daily automatic cleanup.
- Audit and execution evidence has no automatic time-based deletion. Workspace evidence remains until workspace deletion. Removing a member does not erase audit history or the actor name recorded in it.
- Platform usage facts retain workspace ID, tool identifiers and timestamps permanently, including after workspace deletion. These records contain no member names or raw tool inputs or results.
- Data transiting the Services during tool calls is processed transiently to fulfil the call. Raw inputs and results are not stored; operational metadata and hashes are separate records.
- Analytics and error reports are handled by their respective services, separately from Activity. Contact us about access or erasure requests.
- Backups may retain copies after live deletion. Contact us about data-return and deletion requests.
- Billing and transaction records are retained for as long as required by law (typically six years for UK tax and accounting purposes).
- Support correspondence is retained for as long as necessary to deal with your enquiry and for a reasonable period afterwards.
- Job applicant information is retained for the duration of the recruitment process and a reasonable period thereafter, unless you ask us to delete it sooner or agree that we may keep it for future opportunities.
Contact support@connectorcentral.com to request access, data return, correction or erasure. We verify your identity and authority and explain which information is available and which retention limits apply. There is no self-service workspace export. Our obligations under the Data Processing Agreement continue to apply.
10. Security
In Short: We implement technical and organisational measures designed to protect your personal information, including HTTPS, application-level encryption for connector credentials, and workspace access controls.
Measures we implement include:
- HTTPS enforced across the Connector Central Platform;
- Application-level encryption at rest for connector credentials and two-factor authentication secrets;
- Tenant isolation enforced at both the application layer and the database layer (row-level security), so each workspace’s data is segregated;
- Per-member access grants, so AI clients can only reach the connectors their user has been granted;
- Optional two-factor authentication for all user accounts, session expiry, and rate limiting on authentication and API surfaces;
- An append-only audit log and a retention-managed Activity log of security-relevant events and tool calls (metadata only); and
- Error monitoring and access controls limiting administrative access on a need-to-know basis.
No method of transmission over the internet or method of electronic storage is completely secure, so we cannot guarantee absolute security. If we become aware of a personal data breach affecting your personal information, we will notify you and the relevant supervisory authority where and when required by Data Protection Laws.
11. Minors
The Connector Central Services are business tools intended for users aged 18 or over. We do not knowingly collect personal information from anyone under 18. If you believe a person under 18 has provided us with personal information, please contact us at support@connectorcentral.com and we will delete it.
12. Consent
Where we rely on your consent to process your personal information (for example, for certain marketing communications), you may withdraw that consent at any time by using the unsubscribe link in the relevant communication, adjusting your notification preferences in your account settings, or contacting us at support@connectorcentral.com. Withdrawing consent does not affect the lawfulness of processing carried out before the withdrawal, and it does not affect processing carried out on other lawful bases.
13. Marketing
In Short: We send marketing about our own products and services only where we are permitted to, and you can opt out at any time.
We may send you information about our own products, features and services where you have consented to receive it or where the “soft opt-in” applies (because you are a customer and the communication concerns our similar products and services). Every marketing email we send includes an unsubscribe link. We do not share your personal information with third parties for their own marketing purposes, and opting out of marketing does not stop service communications (such as password resets, invitations or material service notices), which we need to send to operate your account.
14. Account Information
You can review and change the personal information associated with your account at any time by signing in and visiting your account settings, where you can update your profile details, change your password, manage two-factor authentication, manage notification preferences, and delete your account or individual workspaces. If you delete your account, your data is handled as described in section 9. If you need help with any of these actions, contact us at support@connectorcentral.com.
15. Your Privacy Rights
In Short: Under UK data protection law you have rights over your personal information, and you can exercise them by contacting us.
Subject to the conditions and exemptions in Data Protection Laws, you have the right to:
- Access the personal information we hold about you and receive a copy of it;
- Rectify inaccurate or incomplete personal information;
- Erase your personal information in certain circumstances;
- Restrict our processing of your personal information in certain circumstances;
- Data portability — receive personal information you provided to us in a structured, commonly used, machine-readable format and have it transmitted to another controller where technically feasible;
- Object to processing based on our legitimate interests, and to direct marketing at any time; and
- Withdraw consent as described in section 12.
To exercise any of these rights, contact us at support@connectorcentral.com. We will respond within one month of receiving your request (extendable where permitted for complex requests). We will not usually charge a fee unless a request is manifestly unfounded or excessive. If you are a member of a customer’s workspace, note that the customer (your organisation) is the controller of the data it processes through the Services; we may refer your request to them where they are best placed to deal with it.
You also have the right to lodge a complaint with the UK supervisory authority, the Information Commissioner’s Office (ico.org.uk). We would appreciate the chance to address your concerns first, so please consider contacting us before you do.
16. AI Clients and Connected Platforms
In Short: You control which AI clients can access your workspace and what they can reach. AI clients never see your connector credentials, and we log only metadata about their activity.
The Connector Central Platform is designed so that:
- AI clients access your workspace only after an explicit authorisation flow in which you choose the workspace and approve the access;
- An AI client can only see and invoke the connectors and tools that have been granted to the authorising user, and those grants can be revoked at any time, taking effect on the next agent request;
- Connector credentials are never disclosed to AI clients — the platform injects them server-side when executing a tool call; and
- The activity log records metadata about each tool call (who, which connector and tool, when, and the outcome) but not the content of requests or responses.
The AI clients you use (for example, Claude) are third-party services operated under their own terms and privacy policies, and data they receive from tool calls is processed by them on your behalf. Please review your AI provider’s processing locations, retention policies, and settings governing whether your data may be used for model training. Connector Central does not control those settings or verify membership of your firm’s organisation at the AI provider.
17. Vulnerability Disclosure
We welcome reports from security researchers acting in good faith. If you believe you have found a security vulnerability in the Connector Central Services, please email support@connectorcentral.com with the subject line “Security”, including enough detail for us to reproduce the issue. Please do not access, modify or delete data belonging to others, and do not publicly disclose the issue before we have had a reasonable opportunity to address it. We will acknowledge your report promptly, keep you informed of our progress, and will not pursue legal action against good-faith research conducted in accordance with this section.
18. Contact Details
If you have any questions about this Policy or our privacy practices, or wish to exercise any of your rights, please contact us:
WLS Labs Ltd
Email: support@connectorcentral.com
Post: 66 Paul Street, London, England, EC2A 4NA
WLS Labs Ltd
Company Number: 15609221
Registered Office: 66 Paul Street, London, England, EC2A 4NA
Email: support@connectorcentral.com