Whowell: Privacy Policy
Effective 2026-10-05. Great Work LLC, 651 N Broad St Suite 206, Middletown, DE 19709, USA. Contact: hello@greatwork.company.
This policy explains what information the Whowell app for Zendesk Support (the "App") processes, why, and where it goes. It does not cover Zendesk's, Persona's or Onfido's products, which are governed by their own policies and your contracts with them. Identity verification itself (the documents, selfies and checks your customer submits) happens entirely on Persona's or Onfido's pages under your agreement with that vendor.
In short
- The App runs entirely in your agents' browsers inside Zendesk. It talks only to your Zendesk account (as the signed-in agent), your Persona account (api.withpersona.com) and your Onfido account (your region's api.eu, api.us or api.ca.onfido.com), with the API key and token you entered, through Zendesk's app proxy. The key and token are Zendesk secure settings: Zendesk inserts them into the Authorization header on the way to those hosts; they are never sent to agents' browsers and Great Work never sees them.
- No identity documents, images, selfies, ID numbers, dates of birth or addresses enter Zendesk. The App asks Persona only for statuses and check names (sparse fieldsets), never downloads files, and discards anything else a vendor answer carries before it's shown or saved.
- What the App stores is in your Zendesk account only: per verification, the vendor, the inquiry or workflow run id, the Onfido applicant id, the flow name, the status, who sent it and when, and when the link expires, in a hidden ticket field; the result as an internal note; a whowell_* tag; and, on approval, the date in the requester's "Whowell: identity verified on" user field.
- The App keeps nothing outside Zendesk and the vendors: no copies, archives, caches or indexes, no browser storage, no export, no background processing, no analytics, nothing used to train AI.
- Great Work LLC receives no data from the App. We see only what you send us in a support email and the billing information Zendesk shares with app developers.
What the App processes
| Data | Why | Where it goes |
|---|---|---|
| The ticket's id, status and requester (id, name, email) | To know who to verify and to address the reply | Read from Zendesk into browser memory while the App is open |
| The signed-in agent's id, name, role, groups and time zone | Permissions, and naming the agent in notes | Read from Zendesk into browser memory |
| The verifications field, tags and status of the ticket | To show and update the verifications sent from this ticket | Read from and written to Zendesk |
Persona: the chosen inquiry template id, a reference zendesk-user-<requester id>, a note Zendesk ticket #<id>, the link lifetime | To create an inquiry and its one-time link. No name, email, phone or other personal data is sent to Persona by the App | Sent to Persona |
| Persona: the inquiry's status, expiry and redaction time; the ids and types of its verifications; each verification's status and check names and results | To show the status and write the result note. Requested with sparse fieldsets so Persona does not return the inquiry's collected fields (name, birthdate, address, ID number, email). Check metadata Persona includes with checks is discarded in memory | Read from Persona into browser memory; check names and results go into the internal note |
Onfido: the requester's first and last name (from their Zendesk name), and their email only if an admin turns on "Send the requester's email to Onfido"; the workflow id, link expiry, a reference zendesk-user-<requester id> and the tag zendesk | Onfido requires a first and last name to create an applicant and a workflow run | Sent to Onfido |
| Onfido: the workflow run's status, reasons, error type, link, link expiry and dashboard address; the names of the tasks that ran | To show the status and write the result note. The run answer can also carry an output object (whatever your team mapped in Onfido Studio) and an SDK token; the App discards both on arrival, never shows, logs or stores them | Read from Onfido into browser memory; status, reasons and task names go into the internal note |
| The verification link | So the customer can verify | Placed only in the agent's reply draft. Never written to a note, field or tag |
Retention
The App itself retains nothing. Data read for the sidebar disappears when the sidebar closes. The hidden ticket field keeps at most the 20 newest verifications per ticket. Fields, notes and tags in Zendesk, and inquiries, applicants and workflow runs at Persona and Onfido, stay in those systems under your control and their retention settings. Uninstalling the App removes the hidden ticket field and the user field (with their values); notes and tags stay on past tickets.
Sharing and subprocessors
None. The App sends data only between your browser, your Zendesk account and your Persona and Onfido accounts. We have no subprocessors for the App itself. Zendesk bills the subscription and shares billing details with us as described in Zendesk's Marketplace terms.
Security
The App has no server or database to breach. It loads the Zendesk Apps framework from Zendesk's CDN. Vendor requests go through Zendesk's proxy over HTTPS, with the key inserted by Zendesk into the Authorization header only, and only for the four whitelisted hosts. Persona API keys can be limited to inquiry.read, inquiry.write and verification.read (and to specific templates); we recommend exactly that. Onfido API tokens cannot be limited, so we recommend a token used only for Zendesk, narrowing who may send links in the App, and revoking the token if you uninstall.
Your choices
- Admins decide who sees verifications and who may send links, the link lifetime and reply text, whether the requester's email goes to Onfido, and whether the approval date is written on the user.
- Uninstalling the App deletes the stored key and token; you can also revoke them at Persona and Onfido.
- Requests about personal data in your Zendesk, Persona or Onfido account go to your organization, which controls that data. We can help you answer them.
- You can ask us for any information we hold about you (in practice, support emails and billing records). Write to hello@greatwork.company.
Changes
We will post changes here with a new effective date, and email account owners about material changes.