Data Processing Agreement (DPA)
This agreement governs how Wavor processes personal data on your behalf. It is part of the Masharti ya Huduma and is concluded together with them.
This language is translated automatically. The legally reviewed versions are under wavor.co.uk and wavor.de.
Learn moreWhat we process and why
We process the data you enter into your Wavor tools solely to run those tools for you. Which tools these are is listed in the Terms. We store, display, transmit on your behalf, and delete this data for as long as you use Wavor.
Whose data
The data of the people you manage in Wavor: your customers, prospects, employees, applicants, and business contacts. That means names and addresses, contact details, contract and billing data, HR data if you use HR tools, and anything you enter yourself. You ensure you are allowed to process this data.
Only on your instruction
We use this data only to provide the tools you use, never for our own purposes. Your use of the platform is your instruction; beyond that you can give us instructions via support.
Confidentiality
Everyone at Wavor with access to this data is bound to confidentiality. Access to sensitive data is logged.
Usalama
Your data sits on servers in Germany, protected with encryption, access control, and tamper-proof logs. For sending email and SMS and for processing payments we use vetted service providers; where this involves data outside the EU, we secure the transfer with the EU Standard Contractual Clauses.
More on securitySub-processors
To run the service we use a few vetted providers. The complete and current list is at wavor.io/subprocessors, with location, purpose and assurance for each provider. Before we add a new one, we tell you at least 28 days in advance. If you object within that time on reasonable grounds, we will not use that provider for your data; if the service cannot be delivered without it, you may terminate as of the effective date and receive a pro-rata refund of amounts paid in advance. If a provider is located outside the EU, we secure the transfer with the EU Standard Contractual Clauses. If a provider fails unexpectedly, we may temporarily switch to a substitute, provided the outage is outside our reasonable control and the immediate switch is necessary to keep the service running or to protect the security of your data. Any such substitute is likewise bound by contract in advance to the same level of protection (Art. 28(4) GDPR), and outside the EU additionally via the EU Standard Contractual Clauses. We inform you without undue delay after the switch; your right to object is unaffected.
To the sub-processor listExport and deletion
You can export or delete your data anytime directly in the platform. Deleted accounts have a 28-day recovery window. After that we delete the data. Where a statutory retention period stands against deletion, we destroy the key instead: the data stays as an encrypted block with no key left for it - we cannot read it either. Only what must be kept is kept. When the contract ends, you decide whether we delete your data or return it to you.
When someone contacts you
If a person whose data you manage in Wavor asks for access, correction, or deletion, they turn to you, not to us. Export and deletion for that are available to you in the platform. If someone contacts us directly, we pass the request on to you and do not answer it ourselves. If we become aware of a data breach affecting your data, we inform you without undue delay, with everything you need for your own notification.