What Data Leaves Your Database
Wiz Asia does not receive a copy of your database. Only the records an agent actually reads to answer a question are sent, and they stay within that conversation. This page sets out what is sent, where it goes and how long it is kept.
What is sent, and how long it is kept
- Conversation messages. What a user or website visitor types, and the agent's replies. Sent to Wiz Asia AI services and on to a third-party language-model provider. Kept as conversation history on Wiz Asia infrastructure until you ask us to erase it. The copy in Odoo stays in your own database until you delete it.
- Odoo records the agent reads. For example a quotation total, a stock level or a contact's details. Sent to Wiz Asia AI services and on to the language-model provider. Held in that conversation's short-term memory, so they may be sent to the model again on later turns of the same conversation, and kept in the 7-day processing log. They are never carried into a different conversation and are not kept in the per-message usage record.
- Documents you add to an agent's knowledge base. Uploaded to Wiz Asia AI services and converted to text on Wiz Asia's own infrastructure. The text is then sent through OpenRouter to a third-party embedding model to be indexed. The indexed text is kept until you remove the document from the agent.
- Documents the agent opens for a user. The extracted text follows the same path as a conversation message and is kept in the 7-day processing log.
- Images, where image input is enabled. Sent to Wiz Asia AI services and on to a vision-capable model provider. The image and the text extracted from it are kept in the 7-day processing log.
- Registration and configuration. Company name, database URL, database name and UUID, deployment type, the administrator login, and the credentials created at installation: an Odoo API key and a webhook secret. Kept for the life of the subscription. The API key carries its Odoo user's access rights, so treat it like a password.
- Usage metrics. Message and token counts, the model used and the cost. Kept for the life of the subscription, and written back into your Odoo for the usage dashboard.
The agent's short-term memory. So the agent can answer “and what about the second one?”, each conversation keeps a short rolling memory: the recent messages and the results of the lookups the agent made. Only the most recent exchanges are kept, roughly the last ten, and anything older is deleted automatically every night. The memory belongs to one conversation and is never shared between conversations, users or databases.
The 7-day processing log. Wiz Asia keeps a technical record of each request so that failures can be diagnosed. It holds the full request and response, including record contents, the text of documents and images, and the files themselves. It is deleted automatically after 7 days, is used only to run and debug the service, and is not backed up.
Erasure and backups. Wiz Asia's databases are backed up nightly and each backup is kept for 14 days. When you ask for conversation history to be erased, it is removed from the live systems straight away and ages out of the backups within 14 days.
What is not sent
- Odoo user passwords.
- Records the agent has no permission to read. An agent's permission is what its Access Rights allow plus, when it serves a signed-in user, that user's own access. An agent serving someone with no Documents access of their own can read only the folders and files an administrator has explicitly allowed.
- Attachments and documents that are never added to a knowledge base and never opened in a conversation.
Who processes it
- Wiz Asia does not train or host the language models. Requests go through OpenRouter, and the provider that handles a request depends on the model configured for that agent and on Wiz Asia's routing at the time.
- Providers that may receive request content include OpenAI, Anthropic, Google, DeepSeek, Mistral, Moonshot (Kimi), Alibaba (Qwen), xAI and Z-AI.
- Indexing uses the same route: the text of a document, and of a question asked against it, goes through OpenRouter to an embedding model, currently Alibaba's Qwen.
- Converting PDF and Office files to text happens on Wiz Asia's own infrastructure, not at a third party.
- If you need a provider excluded, or processing kept within one jurisdiction, raise it before deployment. It is a configuration question, not a code change.
How it travels. All traffic between your Odoo and Wiz Asia is over HTTPS, and both directions are authenticated. Requests carry the credentials created at installation, and replies written back into your Odoo are signed and checked before they are accepted.
What you are responsible for
- Tell your users that conversations with the agent are processed by Wiz Asia and by third-party model providers. Get any consent your jurisdiction requires, especially where website visitors or customers can reach the agent.
- Choose deliberately what goes into a knowledge base. Anything added there is sent for indexing and can be given as an answer to anyone the agent serves.
- Review the Allowed Documents lists before exposing an agent to portal users or website visitors.
- Give the AI agent administration roles only to staff who are allowed to decide what the agent may read.
- Apply your own retention policy to the conversation records in Odoo, and email help@wiz.asia to have the matching history erased on Wiz Asia's side.
This page summarises the full disclosure, DATA_PRIVACY.md, which ships inside the Wiz AI Client Agent module. If the two ever differ, that file is authoritative. The Odoo Helper handles voice and screen content separately: see The Odoo Helper.