Zum Inhalt springen / Skip to content

Privacy Policy

Last updated: October 2, 2026, 21:48 UTC

Versión de lectura traducida por IA

Este idioma se traduce automáticamente. Las versiones revisadas legalmente están en wavor.co.uk y wavor.de.

Aprender más

Enviar una solicitud de privacidad

Acceso, eliminación, exportación de datos (GDPR Art. 15/17/20). Plazo: 30 días.

1. Controlador de Datos

El responsable del tratamiento en el sentido del Reglamento General de Protección de Datos (GDPR) y otras regulaciones de protección de datos es:

Wideys, operador de la plataforma Wavor. Los detalles completos del controlador se pueden encontrar en el Imprenta. Por favor, dirija las consultas sobre protección de datos a nosotros a través de la función de soporte de la Plataforma.

Data protection requests and authorities reach us through our formulario de contacto or at [email protected]. We recommend the form: it routes the request correctly at once.

This one contact applies worldwide: as the data protection contact under the EU GDPR and the UK GDPR, as the Encarregado under the Brazilian LGPD (Art. 41), and as the contact under the Indian DPDP Act.

2. Recopilación y Almacenamiento de Datos Personales

Recopilamos datos personales cuando utiliza nuestra Plataforma. Los siguientes datos son procesados:

a) Registro y Cuenta de Usuario

  • First and last name
  • Email address
  • Password (stored encrypted using bcrypt)
  • Country and business type
  • Business address (street, city, ZIP, state)
  • Billing address (street, city, ZIP, state, country)
  • Company name (optional, for existing companies)

Base legal: Art. 6(1)(b) GDPR (ejecución del contrato) y Art. 6(1)(a) GDPR (consentimiento).

Required details: an account requires your email address, a password, a username, your first and last name and your country. They are required to enter into the user agreement; without them we cannot create an account. There is no legal obligation to provide them. Everything else asked at registration, such as a company name, addresses or a phone number, is optional. For a paid plan our payment provider also needs your payment details; without them no plan can be booked.

b) Gestión de la Empresa

  • Company label (internal identifier)
  • Desired company name
  • Country and business type per company
  • Progress data for each dashboard category

c) Datos Comerciales Específicos de la Herramienta

Dependiendo de las herramientas utilizadas, se procesan y almacenan los siguientes datos adicionales:

  • Invoices: invoice numbers, recipient data, line items, amounts, due dates, PDF documents
  • Customers: customer names, contact details, addresses, notes, communication history
  • Inventory: product names, SKUs, quantities, prices, warehouse locations, supplier information
  • Contracts: contracting parties, contract contents, terms, notice periods, document attachments
  • Employees: employee names, contact details, positions, working hours, salary data, social security data
  • Payroll: gross salaries, tax deductions, social security contributions, bank details
  • Projects: project names, tasks, assignments, time tracking data, comments
  • Time tracking: working hours, break times, project assignments
  • Accounting: accounts, journal entries, receipts, income, expenses
  • Tax: tax-relevant data, VAT calculations, input tax amounts
  • Documents: uploaded files, document metadata, versioning data
  • Calendar: appointments, reminders, participant information
  • Suppliers: supplier names, contact details, order history, terms
  • Orders: order numbers, product lists, quantities, prices, delivery status
  • Travel expenses: travel data, receipts, expense reports, mileage
  • Newsletter: recipient lists, email addresses, sending history, open rates
  • Fleet: vehicle data, license plates, maintenance schedules, mileage
  • Coupons: coupon codes, redemption history, validity periods
  • Dunning: outstanding claims, dunning levels, payment reminders
  • Digital signature: signatory data, timestamps, the signer's IP address and device details, document checksums. These details are the evidence that the signature is genuine and are kept together with the document.
  • Legal: legal cases, deadlines, document templates
  • Domain and email (Wavor Domains, Wavmail): domain names, DNS records, email inboxes, email content

Base legal: Art. 6(1)(b) GDPR (ejecución del contrato). Estos datos se procesan exclusivamente para proporcionar la función de la herramienta respectiva y no se utilizan para otros fines.

d) Registro de Acceso Anticipado (Lista de Espera)

  • Name
  • Email address
  • Company name (optional)

e) Formulario de Contacto

  • Name
  • Email address
  • Subject and message content

Las consultas de contacto se envían al Operador por correo electrónico (a través de un proveedor de servicios de correo electrónico).

f) Feedback

You can send us feedback through “Send feedback” in the dashboard and below every information page (“Was this information helpful?”). We store:

  • the kind of feedback, your text and an optional rating
  • the page on which you gave it
  • your browser's identifier (user agent) and the time
  • your account identifier if you are signed in; none without an account

Your IP address is not stored with the feedback. Without an account it is used only to limit the number of submissions per connection and is discarded one hour after the last submission.

The purpose is to improve the Platform and our information. Legal basis: Art. 6(1)(f) GDPR (legitimate interest in improving our service). Feedback is deleted automatically after 24 months. Until then you can take back any feedback: when signed in at any time in the settings under “Privacy”, without an account on the information page itself, as long as your browser still holds the identifier stored for that purpose.

3. Procesamiento de Datos de IA

La Plataforma utiliza servicios de IA para proporcionar las siguientes características:

  • AI assistant "Wavor Intelligence" - processes chat messages and user profile data (name, company, country, business type) in context
  • Company name check - processes the entered desired company name, country, and business type
  • Risk analysis - processes business description and company data
  • Logo generation - processes description, company name, country, and business type
  • Country information - processes country and business type
  • Drafts for dunning letters, invoices, contract renewals and support replies - process the name of the customer concerned along with invoice and contract data
  • Receipt recognition - processes the content of uploaded receipts, including supplier name and amounts
  • Email analysis - processes the subject and content of incoming email
  • Website generation - processes the description you enter

Text input goes to an AI service provider processing within the European Union, which does not use the data for training and does not retain it. If that service is unavailable, the same request is passed to a provider in the USA. Image generation runs exclusively through a provider in the USA.

Transfers to the USA are covered by Art. 49(1)(a) GDPR (consent) and the EU standard contractual clauses.

If a request contains data about your own customers - such as the name in a dunning or invoice draft - that data is sent along unchanged. It is not obscured beforehand.

El uso de IA se rastrea (costo por solicitud, punto final, marca de tiempo) para hacer cumplir los límites de uso mensual por usuario.

4. Historial de Chat

Las conversaciones con el asistente de IA 'Wavor Intelligence' se almacenan en nuestra base de datos para mantener el historial de conversaciones del usuario. Los datos almacenados incluyen: contenido del mensaje, rol del remitente (usuario/asistente), marca de tiempo y título de la conversación.

5. Cookies y Almacenamiento Local

La Plataforma utiliza las siguientes cookies y mecanismos de almacenamiento local:

  • Sign-in and security: session cookies and protection against requests from other sites. Without them the service does not work.
  • Convenience: language, light or dark appearance, staying on a country address. Only set when you choose something yourself.
  • No cookies for advertising, analytics or tracking, neither our own nor third-party ones. The reach measurement in section 6a works without cookies.

Full list of all cookies with purpose and retention

Base legal para cookies técnicamente necesarias: Art. 6(1)(f) GDPR (interés legítimo). Puede oponerse al uso de cookies a través de nuestro banner de cookies o la configuración de su navegador.

6. Datos de Registro del Servidor

Cada vez que se accede a la Plataforma, se recopilan automáticamente datos técnicos: dirección IP, fecha y hora de acceso, páginas accedidas, navegador y sistema operativo utilizados, URL de referencia. Estos datos se procesan para garantizar operaciones técnicas y defenderse contra ataques.

Base legal: Art. 6(1)(f) GDPR (interés legítimo en la seguridad de la Plataforma).

6a. Reach Measurement Without Cookies

Our websites run Cloudflare Web Analytics. It shows us how many visits a page gets and how fast it loads. The script is served by Cloudflare, sets no cookies, uses no local storage and builds no fingerprint from the IP address or browser string. Collected: the page visited, the referring page, browser, device type, operating system, the country derived from the IP address and the browser's load-time measurements. A visit is recognised by the referring page, not by an identifier; no visitor profile is built.

Legal basis: Art. 6(1)(f) GDPR (legitimate interest in knowing how the website is used and how fast it is). If you do not want the measurement, block the script (static.cloudflareinsights.com) in your browser; the website works fully without it.

7. Compartición de Datos con Terceros

Los datos personales solo se comparten con terceros en la medida necesaria para la prestación del servicio. Las categorías de destinatarios son: alojamiento e infraestructura, procesamiento de pagos, envío y recepción de correos electrónicos, entrega de SMS, servicios de IA, registro de dominios y CDN y seguridad.

Los subprocesadores específicos utilizados, con nombre, ubicación y propósito, se enumeran en la Sección 13.

7a. Verificación de Identidad

The Platform uses a specialized payment and identity service provider (USA) for two purposes: to restore access when you no longer have access to your two-factor authentication, and for the voluntary identity verification in your account settings. The following is processed:

  • Photos of your identity document (ID card, passport, or driver's license), taken directly with the camera
  • A selfie that the provider compares with the photo on the document (biometric data)
  • Data read from the document: name, date of birth, address, document type, issuing country, expiry date and document number

The legal basis is your explicit consent (Art. 6(1)(a) GDPR, and for the biometric data Art. 9(2)(a) GDPR). Identity verification is performed solely at your initiative. You can withdraw your consent at any time; the withdrawal does not affect the lawfulness of the processing carried out until then.

The provider checks that the document is genuine and detects forged or manipulated documents. It processes the photos and the selfie according to its privacy policy; they are not stored on our servers.

We store the result of the verification (status and match result) and, from the document, first and last name, address, document type, issuing country and expiry date, the date of birth only in encrypted form. We do not store the document number, the photos or the selfie. We use this data to document the verification and to be able to match a later restoration of access to your account.

7b. Historial de Cambios (Historial de Datos)

La Plataforma registra automáticamente los cambios en los siguientes datos de la cuenta:

  • Email address and phone number
  • First and last name
  • Business and billing address
  • Two-factor authentication settings (email, SMS, TOTP)

Los datos almacenados incluyen: el nombre del campo cambiado, el valor antiguo y nuevo, la marca de tiempo del cambio y el iniciador (usuario, administrador o sistema). Este registro sirve para la prevención del fraude, el cumplimiento de las regulaciones contra el lavado de dinero (AML) bajo GwG, y la protección del usuario en caso de cambios no autorizados en la cuenta.

Base legal: Art. 6(1)(c) GDPR (obligación legal, en particular GwG) y Art. 6(1)(f) GDPR (interés legítimo en la prevención del fraude). El historial de cambios se almacena de acuerdo con los períodos de retención legales (al menos 5 años bajo la Sección 8 GwG, hasta 10 años bajo la Sección 147 AO).

8. Tus Derechos (GDPR)

Bajo el GDPR, usted tiene los siguientes derechos respecto a sus datos personales:

  • Right of access (Art. 15 GDPR) - What data is stored about you
  • Right to rectification (Art. 16 GDPR) - Correction of inaccurate data
  • Right to erasure (Art. 17 GDPR) - Deletion of your data
  • Right to restriction of processing (Art. 18 GDPR)
  • Right to data portability (Art. 20 GDPR)
  • Right to object (Art. 21 GDPR) - Object to processing
  • Right to withdraw consent (Art. 7(3) GDPR)
  • Right to lodge a complaint with a supervisory authority (Art. 77 GDPR)

Your Right to Object (Art. 21 GDPR)

Where we process your data on the basis of our legitimate interest (Art. 6(1)(f) GDPR), you may object at any time on grounds relating to your particular situation. This concerns feedback (section 2 f), the technically necessary cookies (section 5), server log data (section 6), reach measurement (section 6a) and the change history insofar as it serves fraud prevention (section 7b).

After your objection we no longer process this data unless we can demonstrate compelling legitimate grounds which override your interests, rights and freedoms, or the processing serves the establishment, exercise or defence of legal claims.

Where we process your data to send you advertising, you may object at any time without giving reasons; we will then no longer use it for that purpose.

An objection needs no particular form. The quickest way is our privacy request form o [email protected].

To exercise your rights, please use our support page.

Competent supervisory authority: State Commissioner for Data Protection and Freedom of Information North Rhine-Westphalia, Kavalleriestraße 2-4, 40213 Düsseldorf, Germany.

8a. Automated Decisions

The Platform makes decisions based solely on automated processing which produce legal effects concerning you or similarly significantly affect you (Art. 22 GDPR) in only two cases:

  • Restoring access (section 7a): after the identity service provider's check, the Platform compares the first and last name, date of birth and address from the identity document with the accounts whose holders have already verified their identity successfully before. If the result matches exactly one such account, you automatically receive a link at the email address this account already has, with which you restore access; your existing second factor stays active until the new one is confirmed. If you name another address, a staff member decides, as in every other case. If you have switched off recovery through support in the security settings, access is not restored this way, not even by a staff member. The Platform never rejects a request automatically. If the provider cannot complete the check, for example because a photo is unreadable, you can start it again at any time.
  • Domains: if the email address of the domain holder is not confirmed within the deadline of the responsible registry (15 days for .com and other generic top-level domains), the domain is suspended automatically, as the registries' rules require (for generic top-level domains ICANN RAA § 3.7.7.1). As soon as the address is confirmed, the domain is released again.

In both cases you can ask for a staff member to review the decision, state your point of view and contest the decision. Please contact our support for this.

9. Seguridad de Datos

Utilizamos medidas de seguridad técnicas y organizativas para proteger tus datos: las contraseñas se almacenan con bcrypt, las sesiones se gestionan a través de cookies httpOnly seguras, la transmisión de datos está encriptada a través de HTTPS/TLS y el acceso a la base de datos está restringido a servicios autorizados.

10. Retención de Datos

Los datos personales se retienen de acuerdo con los siguientes períodos:

  • Account data (name, email, address): until account deletion by the user
  • Company data and progress data: until account deletion
  • Tool-specific business data (invoices, contracts, employees, accounting, etc.): until account deletion, unless statutory retention obligations apply (e.g., invoices 10 years per Section 147 AO)
  • Chat histories with the AI assistant: until account deletion
  • Early access registrations: until official platform launch or until withdrawal
  • Contact inquiries: 6 months after completion of the inquiry
  • Feedback: 24 months
  • AI usage data (cost tracking): until account deletion
  • Server log data: 90 days
  • Sign-in history (the basis for the new-device alert): 365 days
  • Sign-in attempts (protection against automated attacks): 90 days
  • Session cookies: 7 days or until logout
  • Change history (Data History): at least 5 years (GwG), up to 10 years (AO)
  • Identity verification results: until account deletion or per statutory retention periods

Cuando eliminas tu cuenta, todos los datos personales, datos de la empresa, datos de progreso e historiales de chat se eliminarán de forma irrevocable en un plazo de 28 días, a menos que se apliquen obligaciones legales de retención (por ejemplo, períodos de retención relacionados con impuestos de 6 o 10 años).

11. Acuerdos de Procesamiento de Datos

Para proporcionar nuestros servicios, utilizamos subprocesadores. Las características de IA y la infraestructura de alojamiento están integradas a través de proveedores externos especializados como subprocesadores. El proveedor de servicios de IA no actúa como un controlador de datos independiente, sino que procesa datos exclusivamente dentro del alcance de los acuerdos de procesamiento de datos. Existen Acuerdos de Procesamiento de Datos conforme al Art. 28 GDPR con todos los proveedores.

La lista completa de subprocesadores utilizados, con nombre, ubicación y propósito, se proporciona en la Sección 13.

12. Transferencia Internacional de Datos

A través del uso de nuestros proveedores externos en EE. UU., los datos personales pueden ser transferidos a terceros países. La transferencia se basa en las siguientes bases legales:

  • EU-US Data Privacy Framework (EU Commission adequacy decision)
  • Standard Contractual Clauses (SCC) pursuant to Art. 46(2)(c) GDPR
  • Additionally, Transfer Impact Assessments (TIA) to evaluate the level of protection

Los proveedores de CDN y seguridad, así como los proveedores de alojamiento, como proveedores de infraestructura, aseguran sus propias bases legales para transferencias internacionales de datos, incluido el Marco de Privacidad de Datos UE-EE. UU. y/o Cláusulas Contractuales Estándar (SCC).

13. Subprocesadores y Servicios de Terceros

Utilizamos los siguientes subprocesadores:

Hetzner Online GmbH·Alemania (UE)·Alojamiento de servidores e infraestructura
Cloudflare, Inc.·EE. UU./UE (DPF)·CDN, DNS, DDoS protection, bot detection (Turnstile), cookieless reach measurement (Web Analytics)
Stripe Payments Europe Ltd.·Irlanda (UE) + EE. UU.·Procesamiento de pagos, suscripciones, verificación de identidad
Amazon Web Services, Inc. (AWS)·EE. UU. (DPF) + región de la UE (Fráncfort)·Email sending and receiving (SES), short-term storage of inbound emails (S3, Frankfurt)
OVH SAS (OVHcloud)·Alemania (UE)·Object storage for uploaded customer files (receipts, documents, images)
Backblaze, Inc.·USA (DPF) + EU region (Amsterdam)·Offsite backups: database dumps (encrypted with our own key before transfer) and a mirror copy of customer files
Twilio, Inc.·EE. UU. (DPF)·Verificación por SMS (2FA), notificaciones de emergencia
OpenAI LLC·EE. UU. (DPF)·AI features (chat, risk analysis, OCR, text generation). Inputs are not used to train the AI models (API usage).
OpenProvider B.V.·Países Bajos (UE)·Registro y gestión de dominios (datos WHOIS obligatorios de ICANN/DENIC)

Standard Contractual Clauses (SCC) per Art. 46(2)(c) GDPR are in place with all US-based sub-processors. Data Processing Agreements per Art. 28 GDPR are in place with EU-based providers.

14. Cambios a esta Política de Privacidad

Nos reservamos el derecho de actualizar esta Política de Privacidad en cualquier momento. Los cambios significativos se comunicarán a los usuarios registrados por correo electrónico o a través de la Plataforma. La versión actual siempre está disponible en la Plataforma.