Zum Inhalt springen / Skip to content

Privacy Policy

Last updated: October 2, 2026, 21:48 UTC

نسخة قراءة مترجمة بواسطة الذكاء الاصطناعي

تمت ترجمة هذه اللغة تلقائيًا. النسخ التي تمت مراجعتها قانونيًا موجودة على wavor.co.uk و wavor.de.

تعرف على المزيد

تقديم طلب الخصوصية

الوصول، الحذف، تصدير البيانات (المادة 15/17/20 من GDPR). الموعد النهائي: 30 يومًا.

1. المتحكم في البيانات

المتحكم في البيانات بمعنى اللائحة العامة لحماية البيانات (GDPR) وغيرها من لوائح حماية البيانات هو:

Wideys، مشغل منصة Wavor. يمكن العثور على التفاصيل الكاملة للمتحكم في البيانات في طباعة. يرجى توجيه استفسارات حماية البيانات إلينا عبر وظيفة الدعم في المنصة.

Data protection requests and authorities reach us through our نموذج الاتصال or at [email protected]. We recommend the form: it routes the request correctly at once.

This one contact applies worldwide: as the data protection contact under the EU GDPR and the UK GDPR, as the المسؤول under the Brazilian LGPD (Art. 41), and as the contact under the Indian DPDP Act.

2. جمع وتخزين البيانات الشخصية

نجمع البيانات الشخصية عندما تستخدم منصتنا. يتم معالجة البيانات التالية:

أ) التسجيل وحساب المستخدم

  • First and last name
  • Email address
  • Password (stored encrypted using bcrypt)
  • Country and business type
  • Business address (street, city, ZIP, state)
  • Billing address (street, city, ZIP, state, country)
  • Company name (optional, for existing companies)

الأساس القانوني: المادة 6(1)(ب) من GDPR (تنفيذ العقد) والمادة 6(1)(أ) من GDPR (الموافقة).

Required details: an account requires your email address, a password, a username, your first and last name and your country. They are required to enter into the user agreement; without them we cannot create an account. There is no legal obligation to provide them. Everything else asked at registration, such as a company name, addresses or a phone number, is optional. For a paid plan our payment provider also needs your payment details; without them no plan can be booked.

ب) إدارة الشركة

  • Company label (internal identifier)
  • Desired company name
  • Country and business type per company
  • Progress data for each dashboard category

ج) بيانات الأعمال الخاصة بالأداة

اعتمادًا على الأدوات المستخدمة، تتم معالجة وتخزين البيانات الإضافية التالية:

  • Invoices: invoice numbers, recipient data, line items, amounts, due dates, PDF documents
  • Customers: customer names, contact details, addresses, notes, communication history
  • Inventory: product names, SKUs, quantities, prices, warehouse locations, supplier information
  • Contracts: contracting parties, contract contents, terms, notice periods, document attachments
  • Employees: employee names, contact details, positions, working hours, salary data, social security data
  • Payroll: gross salaries, tax deductions, social security contributions, bank details
  • Projects: project names, tasks, assignments, time tracking data, comments
  • Time tracking: working hours, break times, project assignments
  • Accounting: accounts, journal entries, receipts, income, expenses
  • Tax: tax-relevant data, VAT calculations, input tax amounts
  • Documents: uploaded files, document metadata, versioning data
  • Calendar: appointments, reminders, participant information
  • Suppliers: supplier names, contact details, order history, terms
  • Orders: order numbers, product lists, quantities, prices, delivery status
  • Travel expenses: travel data, receipts, expense reports, mileage
  • Newsletter: recipient lists, email addresses, sending history, open rates
  • Fleet: vehicle data, license plates, maintenance schedules, mileage
  • Coupons: coupon codes, redemption history, validity periods
  • Dunning: outstanding claims, dunning levels, payment reminders
  • Digital signature: signatory data, timestamps, the signer's IP address and device details, document checksums. These details are the evidence that the signature is genuine and are kept together with the document.
  • Legal: legal cases, deadlines, document templates
  • Domain and email (Wavor Domains, Wavmail): domain names, DNS records, email inboxes, email content

الأساس القانوني: المادة 6(1)(ب) من GDPR (تنفيذ العقد). تتم معالجة هذه البيانات حصريًا لتوفير وظيفة الأداة المعنية ولا تستخدم لأغراض أخرى.

د) تسجيل الوصول المبكر (قائمة الانتظار)

  • Name
  • Email address
  • Company name (optional)

هـ) نموذج الاتصال

  • Name
  • Email address
  • Subject and message content

يتم تحويل استفسارات الاتصال إلى المشغل عبر البريد الإلكتروني (من خلال مزود خدمة البريد الإلكتروني).

f) Feedback

You can send us feedback through “Send feedback” in the dashboard and below every information page (“Was this information helpful?”). We store:

  • the kind of feedback, your text and an optional rating
  • the page on which you gave it
  • your browser's identifier (user agent) and the time
  • your account identifier if you are signed in; none without an account

Your IP address is not stored with the feedback. Without an account it is used only to limit the number of submissions per connection and is discarded one hour after the last submission.

The purpose is to improve the Platform and our information. Legal basis: Art. 6(1)(f) GDPR (legitimate interest in improving our service). Feedback is deleted automatically after 24 months. Until then you can take back any feedback: when signed in at any time in the settings under “Privacy”, without an account on the information page itself, as long as your browser still holds the identifier stored for that purpose.

3. معالجة بيانات الذكاء الاصطناعي

تستخدم المنصة خدمات الذكاء الاصطناعي لتوفير الميزات التالية:

  • AI assistant "Wavor Intelligence" - processes chat messages and user profile data (name, company, country, business type) in context
  • Company name check - processes the entered desired company name, country, and business type
  • Risk analysis - processes business description and company data
  • Logo generation - processes description, company name, country, and business type
  • Country information - processes country and business type
  • Drafts for dunning letters, invoices, contract renewals and support replies - process the name of the customer concerned along with invoice and contract data
  • Receipt recognition - processes the content of uploaded receipts, including supplier name and amounts
  • Email analysis - processes the subject and content of incoming email
  • Website generation - processes the description you enter

Text input goes to an AI service provider processing within the European Union, which does not use the data for training and does not retain it. If that service is unavailable, the same request is passed to a provider in the USA. Image generation runs exclusively through a provider in the USA.

Transfers to the USA are covered by Art. 49(1)(a) GDPR (consent) and the EU standard contractual clauses.

If a request contains data about your own customers - such as the name in a dunning or invoice draft - that data is sent along unchanged. It is not obscured beforehand.

يتم تتبع استخدام الذكاء الاصطناعي (التكلفة لكل طلب، نقطة النهاية، الطابع الزمني) لفرض حدود الاستخدام الشهرية لكل مستخدم.

4. سجل الدردشة

يتم تخزين المحادثات مع مساعد الذكاء الاصطناعي 'Wavor Intelligence' في قاعدة بياناتنا للحفاظ على سجل المحادثة للمستخدم. تشمل البيانات المخزنة: محتوى الرسالة، دور المرسل (مستخدم/مساعد)، الطابع الزمني، وعنوان المحادثة.

5. الكوكيز والتخزين المحلي

تستخدم المنصة الكوكيز وآليات التخزين المحلي التالية:

  • Sign-in and security: session cookies and protection against requests from other sites. Without them the service does not work.
  • Convenience: language, light or dark appearance, staying on a country address. Only set when you choose something yourself.
  • No cookies for advertising, analytics or tracking, neither our own nor third-party ones. The reach measurement in section 6a works without cookies.

Full list of all cookies with purpose and retention

الأساس القانوني للكوكيز الضرورية تقنيًا: المادة 6(1)(ف) من اللائحة العامة لحماية البيانات (المصلحة المشروعة). يمكنك الاعتراض على استخدام الكوكيز عبر لافتة الكوكيز الخاصة بنا أو إعدادات المتصفح لديك.

6. بيانات سجلات الخادم

في كل مرة يتم فيها الوصول إلى المنصة، يتم جمع بيانات تقنية تلقائيًا: عنوان IP، تاريخ ووقت الوصول، الصفحات التي تم الوصول إليها، المتصفح ونظام التشغيل المستخدم، عنوان URL المحيل. تتم معالجة هذه البيانات لضمان العمليات التقنية والدفاع ضد الهجمات.

الأساس القانوني: المادة 6(1)(ف) من اللائحة العامة لحماية البيانات (المصلحة المشروعة في أمان المنصة).

6a. Reach Measurement Without Cookies

Our websites run Cloudflare Web Analytics. It shows us how many visits a page gets and how fast it loads. The script is served by Cloudflare, sets no cookies, uses no local storage and builds no fingerprint from the IP address or browser string. Collected: the page visited, the referring page, browser, device type, operating system, the country derived from the IP address and the browser's load-time measurements. A visit is recognised by the referring page, not by an identifier; no visitor profile is built.

Legal basis: Art. 6(1)(f) GDPR (legitimate interest in knowing how the website is used and how fast it is). If you do not want the measurement, block the script (static.cloudflareinsights.com) in your browser; the website works fully without it.

7. مشاركة البيانات مع أطراف ثالثة

لا تتم مشاركة البيانات الشخصية مع أطراف ثالثة إلا بالقدر اللازم لتقديم الخدمة. فئات المستلمين هي: الاستضافة والبنية التحتية، معالجة المدفوعات، إرسال واستقبال البريد الإلكتروني، تسليم الرسائل القصيرة، خدمات الذكاء الاصطناعي، تسجيل النطاق، وشبكة توصيل المحتوى والأمان.

يتم سرد المعالجات الفرعية المحددة المستخدمة، مع الاسم، الموقع، والغرض، في القسم 13.

7أ. التحقق من الهوية

The Platform uses a specialized payment and identity service provider (USA) for two purposes: to restore access when you no longer have access to your two-factor authentication, and for the voluntary identity verification in your account settings. The following is processed:

  • Photos of your identity document (ID card, passport, or driver's license), taken directly with the camera
  • A selfie that the provider compares with the photo on the document (biometric data)
  • Data read from the document: name, date of birth, address, document type, issuing country, expiry date and document number

The legal basis is your explicit consent (Art. 6(1)(a) GDPR, and for the biometric data Art. 9(2)(a) GDPR). Identity verification is performed solely at your initiative. You can withdraw your consent at any time; the withdrawal does not affect the lawfulness of the processing carried out until then.

The provider checks that the document is genuine and detects forged or manipulated documents. It processes the photos and the selfie according to its privacy policy; they are not stored on our servers.

We store the result of the verification (status and match result) and, from the document, first and last name, address, document type, issuing country and expiry date, the date of birth only in encrypted form. We do not store the document number, the photos or the selfie. We use this data to document the verification and to be able to match a later restoration of access to your account.

7ب. تاريخ التغيير (تاريخ البيانات)

تقوم المنصة بتسجيل التغييرات تلقائيًا على بيانات الحساب التالية:

  • Email address and phone number
  • First and last name
  • Business and billing address
  • Two-factor authentication settings (email, SMS, TOTP)

تشمل البيانات المخزنة: اسم الحقل الذي تم تغييره، القيمة القديمة والجديدة، الطابع الزمني للتغيير، والمبادر (مستخدم، مسؤول، أو نظام). يساعد هذا التسجيل في منع الاحتيال، والامتثال للوائح مكافحة غسل الأموال (AML) بموجب GwG، وحماية المستخدم في حالة حدوث تغييرات غير مصرح بها في الحساب.

الأساس القانوني: المادة 6(1)(ج) من اللائحة العامة لحماية البيانات (الالتزام القانوني، ولا سيما قانون غفغ) والمادة 6(1)(و) من اللائحة العامة لحماية البيانات (المصلحة المشروعة في منع الاحتيال). يتم تخزين تاريخ التغيير وفقًا لفترات الاحتفاظ القانونية (على الأقل 5 سنوات بموجب القسم 8 من قانون غفغ، حتى 10 سنوات بموجب القسم 147 من قانون AO).

8. حقوقك (GDPR)

بموجب اللائحة العامة لحماية البيانات، لديك الحقوق التالية المتعلقة ببياناتك الشخصية:

  • Right of access (Art. 15 GDPR) - What data is stored about you
  • Right to rectification (Art. 16 GDPR) - Correction of inaccurate data
  • Right to erasure (Art. 17 GDPR) - Deletion of your data
  • Right to restriction of processing (Art. 18 GDPR)
  • Right to data portability (Art. 20 GDPR)
  • Right to object (Art. 21 GDPR) - Object to processing
  • Right to withdraw consent (Art. 7(3) GDPR)
  • Right to lodge a complaint with a supervisory authority (Art. 77 GDPR)

Your Right to Object (Art. 21 GDPR)

Where we process your data on the basis of our legitimate interest (Art. 6(1)(f) GDPR), you may object at any time on grounds relating to your particular situation. This concerns feedback (section 2 f), the technically necessary cookies (section 5), server log data (section 6), reach measurement (section 6a) and the change history insofar as it serves fraud prevention (section 7b).

After your objection we no longer process this data unless we can demonstrate compelling legitimate grounds which override your interests, rights and freedoms, or the processing serves the establishment, exercise or defence of legal claims.

Where we process your data to send you advertising, you may object at any time without giving reasons; we will then no longer use it for that purpose.

An objection needs no particular form. The quickest way is our privacy request form أو [email protected].

To exercise your rights, please use our support page.

Competent supervisory authority: State Commissioner for Data Protection and Freedom of Information North Rhine-Westphalia, Kavalleriestraße 2-4, 40213 Düsseldorf, Germany.

8a. Automated Decisions

The Platform makes decisions based solely on automated processing which produce legal effects concerning you or similarly significantly affect you (Art. 22 GDPR) in only two cases:

  • Restoring access (section 7a): after the identity service provider's check, the Platform compares the first and last name, date of birth and address from the identity document with the accounts whose holders have already verified their identity successfully before. If the result matches exactly one such account, you automatically receive a link at the email address this account already has, with which you restore access; your existing second factor stays active until the new one is confirmed. If you name another address, a staff member decides, as in every other case. If you have switched off recovery through support in the security settings, access is not restored this way, not even by a staff member. The Platform never rejects a request automatically. If the provider cannot complete the check, for example because a photo is unreadable, you can start it again at any time.
  • Domains: if the email address of the domain holder is not confirmed within the deadline of the responsible registry (15 days for .com and other generic top-level domains), the domain is suspended automatically, as the registries' rules require (for generic top-level domains ICANN RAA § 3.7.7.1). As soon as the address is confirmed, the domain is released again.

In both cases you can ask for a staff member to review the decision, state your point of view and contest the decision. Please contact our support for this.

9. أمان البيانات

نستخدم تدابير الأمان التقنية والتنظيمية لحماية بياناتك: يتم تشفير كلمات المرور باستخدام bcrypt، وتتم إدارة الجلسات عبر كوكيز httpOnly الآمنة، ويتم تشفير نقل البيانات عبر HTTPS/TLS، ويتم تقييد الوصول إلى قاعدة البيانات على الخدمات المصرح بها.

10. الاحتفاظ بالبيانات

يتم الاحتفاظ بالبيانات الشخصية وفقًا للفترات التالية:

  • Account data (name, email, address): until account deletion by the user
  • Company data and progress data: until account deletion
  • Tool-specific business data (invoices, contracts, employees, accounting, etc.): until account deletion, unless statutory retention obligations apply (e.g., invoices 10 years per Section 147 AO)
  • Chat histories with the AI assistant: until account deletion
  • Early access registrations: until official platform launch or until withdrawal
  • Contact inquiries: 6 months after completion of the inquiry
  • Feedback: 24 months
  • AI usage data (cost tracking): until account deletion
  • Server log data: 90 days
  • Sign-in history (the basis for the new-device alert): 365 days
  • Sign-in attempts (protection against automated attacks): 90 days
  • Session cookies: 7 days or until logout
  • Change history (Data History): at least 5 years (GwG), up to 10 years (AO)
  • Identity verification results: until account deletion or per statutory retention periods

عند حذف حسابك، سيتم حذف جميع البيانات الشخصية، بيانات الشركة، بيانات التقدم، وسجلات الدردشة بشكل لا يمكن التراجع عنه خلال 28 يومًا، ما لم تنطبق التزامات الاحتفاظ القانونية (مثل فترات الاحتفاظ المتعلقة بالضرائب التي تبلغ 6 أو 10 سنوات).

11. اتفاقيات معالجة البيانات

لتقديم خدماتنا، نستخدم معالجات فرعية. يتم دمج ميزات الذكاء الاصطناعي والبنية التحتية للاستضافة من خلال مزودين خارجيين متخصصين كمعالجات فرعية. لا يعمل مزود خدمة الذكاء الاصطناعي كجهة تحكم بيانات مستقلة ولكنه يعالج البيانات حصريًا ضمن نطاق اتفاقيات معالجة البيانات. توجد اتفاقيات معالجة البيانات وفقًا للمادة 28 من اللائحة العامة لحماية البيانات مع جميع المزودين.

تُقدم القائمة الكاملة للمعالجات الفرعية المستخدمة، مع الاسم، الموقع، والغرض، في القسم 13.

12. نقل البيانات الدولية

من خلال استخدام مزودينا الخارجيين في الولايات المتحدة، قد يتم نقل البيانات الشخصية إلى دول ثالثة. يعتمد النقل على الأسس القانونية التالية:

  • EU-US Data Privacy Framework (EU Commission adequacy decision)
  • Standard Contractual Clauses (SCC) pursuant to Art. 46(2)(c) GDPR
  • Additionally, Transfer Impact Assessments (TIA) to evaluate the level of protection

تضمن مزودو CDN ومزودو الأمان ومزودو الاستضافة، بصفتهم مزودي بنية تحتية، أسسهم القانونية الخاصة لنقل البيانات الدولية، بما في ذلك إطار خصوصية البيانات بين الاتحاد الأوروبي والولايات المتحدة و/أو البنود التعاقدية القياسية (SCC).

13. المعالجات الفرعية وخدمات الأطراف الثالثة

نستخدم المعالجات الفرعية التالية:

Hetzner Online GmbH·ألمانيا (الاتحاد الأوروبي)·استضافة الخادم والبنية التحتية
Cloudflare, Inc.·الولايات المتحدة الأمريكية/الاتحاد الأوروبي (DPF)·CDN, DNS, DDoS protection, bot detection (Turnstile), cookieless reach measurement (Web Analytics)
Stripe Payments Europe Ltd.·أيرلندا (الاتحاد الأوروبي) + الولايات المتحدة الأمريكية·معالجة المدفوعات، الاشتراكات، التحقق من الهوية
Amazon Web Services, Inc. (AWS)·الولايات المتحدة الأمريكية (DPF) + منطقة الاتحاد الأوروبي (فرانكفورت)·Email sending and receiving (SES), short-term storage of inbound emails (S3, Frankfurt)
OVH SAS (OVHcloud)·ألمانيا (الاتحاد الأوروبي)·Object storage for uploaded customer files (receipts, documents, images)
Backblaze, Inc.·USA (DPF) + EU region (Amsterdam)·Offsite backups: database dumps (encrypted with our own key before transfer) and a mirror copy of customer files
Twilio, Inc.·الولايات المتحدة الأمريكية (DPF)·التحقق من الرسائل القصيرة (2FA)، إشعارات الطوارئ
OpenAI LLC·الولايات المتحدة الأمريكية (DPF)·AI features (chat, risk analysis, OCR, text generation). Inputs are not used to train the AI models (API usage).
OpenProvider B.V.·هولندا (الاتحاد الأوروبي)·تسجيل وإدارة النطاقات (ICANN/DENIC بيانات WHOIS الإلزامية)

Standard Contractual Clauses (SCC) per Art. 46(2)(c) GDPR are in place with all US-based sub-processors. Data Processing Agreements per Art. 28 GDPR are in place with EU-based providers.

14. التغييرات على سياسة الخصوصية هذه

نحتفظ بالحق في تحديث سياسة الخصوصية هذه في أي وقت. سيتم إبلاغ التغييرات الكبيرة للمستخدمين المسجلين عبر البريد الإلكتروني أو من خلال المنصة. النسخة الحالية متاحة دائمًا على المنصة.