Zum Inhalt springen / Skip to content

Privacy Policy

Last updated: October 1, 2026, 16:02 UTC

Phiên bản đọc được dịch bằng AI

Ngôn ngữ này được dịch tự động. Các phiên bản đã được xem xét pháp lý nằm trên wavor.co.uk và wavor.de.

Tìm hiểu thêm

Submit a privacy request

Access, deletion, data export (GDPR Art. 15/17/20). Deadline: 30 days.

1. Data Controller

The data controller within the meaning of the General Data Protection Regulation (GDPR) and other data protection regulations is:

Wideys, operator of the Wavor platform. Full details of the controller can be found in the Thông tin liên hệ. Please direct data protection inquiries to us via the Platform's support function.

Data protection requests and authorities reach us through our contact form or at [email protected]. We recommend the form: it routes the request correctly at once.

This one contact applies worldwide: as the data protection contact under the EU GDPR and the UK GDPR, as the Encarregado under the Brazilian LGPD (Art. 41), and as the contact under the Indian DPDP Act.

2. Collection and Storage of Personal Data

We collect personal data when you use our Platform. The following data is processed:

a) Registration and User Account

  • First and last name
  • Email address
  • Password (stored encrypted using bcrypt)
  • Country and business type
  • Business address (street, city, ZIP, state)
  • Billing address (street, city, ZIP, state, country)
  • Company name (optional, for existing companies)

Legal basis: Art. 6(1)(b) GDPR (contract performance) and Art. 6(1)(a) GDPR (consent).

Required details: an account requires your email address, a password, a username, your first and last name and your country. They are required to enter into the user agreement; without them we cannot create an account. There is no legal obligation to provide them. Everything else asked at registration, such as a company name, addresses or a phone number, is optional. For a paid plan our payment provider also needs your payment details; without them no plan can be booked.

b) Company Management

  • Company label (internal identifier)
  • Desired company name
  • Country and business type per company
  • Progress data for each dashboard category

c) Tool-Specific Business Data

Depending on the tools used, the following additional data is processed and stored:

  • Invoices: invoice numbers, recipient data, line items, amounts, due dates, PDF documents
  • Customers: customer names, contact details, addresses, notes, communication history
  • Inventory: product names, SKUs, quantities, prices, warehouse locations, supplier information
  • Contracts: contracting parties, contract contents, terms, notice periods, document attachments
  • Employees: employee names, contact details, positions, working hours, salary data, social security data
  • Payroll: gross salaries, tax deductions, social security contributions, bank details
  • Projects: project names, tasks, assignments, time tracking data, comments
  • Time tracking: working hours, break times, project assignments
  • Accounting: accounts, journal entries, receipts, income, expenses
  • Tax: tax-relevant data, VAT calculations, input tax amounts
  • Documents: uploaded files, document metadata, versioning data
  • Calendar: appointments, reminders, participant information
  • Suppliers: supplier names, contact details, order history, terms
  • Orders: order numbers, product lists, quantities, prices, delivery status
  • Travel expenses: travel data, receipts, expense reports, mileage
  • Newsletter: recipient lists, email addresses, sending history, open rates
  • Fleet: vehicle data, license plates, maintenance schedules, mileage
  • Coupons: coupon codes, redemption history, validity periods
  • Dunning: outstanding claims, dunning levels, payment reminders
  • Digital signature: signatory data, timestamps, the signer's IP address and device details, document checksums. These details are the evidence that the signature is genuine and are kept together with the document.
  • Legal: legal cases, deadlines, document templates
  • Domain and email (Wavor Domains, Wavmail): domain names, DNS records, email inboxes, email content

Legal basis: Art. 6(1)(b) GDPR (contract performance). This data is processed exclusively to provide the respective tool function and is not used for other purposes.

d) Early Access Registration (Waitlist)

  • Name
  • Email address
  • Company name (optional)

e) Contact Form

  • Name
  • Email address
  • Subject and message content

Contact inquiries are forwarded to the Operator via email (through an email service provider).

f) Feedback

You can send us feedback through “Send feedback” in the dashboard and below every information page (“Was this information helpful?”). We store:

  • the kind of feedback, your text and an optional rating
  • the page on which you gave it
  • your browser's identifier (user agent) and the time
  • your account identifier if you are signed in; none without an account

Your IP address is not stored with the feedback. Without an account it is used only to limit the number of submissions per connection and is discarded one hour after the last submission.

The purpose is to improve the Platform and our information. Legal basis: Art. 6(1)(f) GDPR (legitimate interest in improving our service). Feedback is deleted automatically after 24 months. Until then you can take back any feedback: when signed in at any time in the settings under “Privacy”, without an account on the information page itself, as long as your browser still holds the identifier stored for that purpose.

3. AI Data Processing

The Platform uses AI services to provide the following features:

  • AI assistant "Wavor Intelligence" - processes chat messages and user profile data (name, company, country, business type) in context
  • Company name check - processes the entered desired company name, country, and business type
  • Risk analysis - processes business description and company data
  • Logo generation - processes description, company name, country, and business type
  • Country information - processes country and business type
  • Drafts for dunning letters, invoices, contract renewals and support replies - process the name of the customer concerned along with invoice and contract data
  • Receipt recognition - processes the content of uploaded receipts, including supplier name and amounts
  • Email analysis - processes the subject and content of incoming email
  • Website generation - processes the description you enter

Text input goes to an AI service provider processing within the European Union, which does not use the data for training and does not retain it. If that service is unavailable, the same request is passed to a provider in the USA. Image generation runs exclusively through a provider in the USA.

Transfers to the USA are covered by Art. 49(1)(a) GDPR (consent) and the EU standard contractual clauses.

If a request contains data about your own customers - such as the name in a dunning or invoice draft - that data is sent along unchanged. It is not obscured beforehand.

AI usage is tracked (cost per request, endpoint, timestamp) to enforce per-user monthly usage limits.

4. Chat History

Conversations with the AI assistant 'Wavor Intelligence' are stored in our database to maintain the conversation history for the user. Stored data includes: message content, sender role (user/assistant), timestamp, and conversation title.

5. Cookies and Local Storage

The Platform uses the following cookies and local storage mechanisms:

  • Sign-in and security: session cookies and protection against requests from other sites. Without them the service does not work.
  • Convenience: language, light or dark appearance, staying on a country address. Only set when you choose something yourself.
  • No cookies for advertising, analytics or tracking, neither our own nor third-party ones. The reach measurement in section 6a works without cookies.

Full list of all cookies with purpose and retention

Legal basis for technically necessary cookies: Art. 6(1)(f) GDPR (legitimate interest). You can object to the use of cookies via our cookie banner or your browser settings.

6. Server Log Data

Each time the Platform is accessed, technical data is automatically collected: IP address, date and time of access, pages accessed, browser and operating system used, referrer URL. This data is processed to ensure technical operations and to defend against attacks.

Legal basis: Art. 6(1)(f) GDPR (legitimate interest in Platform security).

6a. Reach Measurement Without Cookies

Our websites run Cloudflare Web Analytics. It shows us how many visits a page gets and how fast it loads. The script is served by Cloudflare, sets no cookies, uses no local storage and builds no fingerprint from the IP address or browser string. Collected: the page visited, the referring page, browser, device type, operating system, the country derived from the IP address and the browser's load-time measurements. A visit is recognised by the referring page, not by an identifier; no visitor profile is built.

Legal basis: Art. 6(1)(f) GDPR (legitimate interest in knowing how the website is used and how fast it is). If you do not want the measurement, block the script (static.cloudflareinsights.com) in your browser; the website works fully without it.

7. Data Sharing with Third Parties

Personal data is only shared with third parties to the extent necessary for service provision. Categories of recipients are: hosting and infrastructure, payment processing, email sending and receiving, SMS delivery, AI services, domain registration, and CDN and security.

The specific sub-processors used, with name, location, and purpose, are listed in Section 13.

7a. Identity Verification

The Platform uses a specialized payment and identity service provider (USA) for two purposes: to restore access when you no longer have access to your two-factor authentication, and for the voluntary identity verification in your account settings. The following is processed:

  • Photos of your identity document (ID card, passport, or driver's license), taken directly with the camera
  • A selfie that the provider compares with the photo on the document (biometric data)
  • Data read from the document: name, date of birth, address, document type, issuing country, expiry date and document number

The legal basis is your explicit consent (Art. 6(1)(a) GDPR, and for the biometric data Art. 9(2)(a) GDPR). Identity verification is performed solely at your initiative. You can withdraw your consent at any time; the withdrawal does not affect the lawfulness of the processing carried out until then.

The provider checks that the document is genuine and detects forged or manipulated documents. It processes the photos and the selfie according to its privacy policy; they are not stored on our servers.

We store the result of the verification (status and match result) and, from the document, first and last name, address, document type, issuing country and expiry date, the date of birth only in encrypted form. We do not store the document number, the photos or the selfie. We use this data to document the verification and to be able to match a later restoration of access to your account.

7b. Change History (Data History)

The Platform automatically logs changes to the following account data:

  • Email address and phone number
  • First and last name
  • Business and billing address
  • Two-factor authentication settings (email, SMS, TOTP)

Stored data includes: the changed field name, old and new value, timestamp of the change, and the initiator (user, admin, or system). This logging serves fraud prevention, compliance with anti-money laundering regulations (AML) under GwG, and protection of the user in case of unauthorized account changes.

Legal basis: Art. 6(1)(c) GDPR (legal obligation, in particular GwG) and Art. 6(1)(f) GDPR (legitimate interest in fraud prevention). The change history is stored in accordance with statutory retention periods (at least 5 years under Section 8 GwG, up to 10 years under Section 147 AO).

8. Your Rights (GDPR)

Under the GDPR, you have the following rights regarding your personal data:

  • Right of access (Art. 15 GDPR) - What data is stored about you
  • Right to rectification (Art. 16 GDPR) - Correction of inaccurate data
  • Right to erasure (Art. 17 GDPR) - Deletion of your data
  • Right to restriction of processing (Art. 18 GDPR)
  • Right to data portability (Art. 20 GDPR)
  • Right to object (Art. 21 GDPR) - Object to processing
  • Right to withdraw consent (Art. 7(3) GDPR)
  • Right to lodge a complaint with a supervisory authority (Art. 77 GDPR)

Your Right to Object (Art. 21 GDPR)

Where we process your data on the basis of our legitimate interest (Art. 6(1)(f) GDPR), you may object at any time on grounds relating to your particular situation. This concerns feedback (section 2 f), the technically necessary cookies (section 5), server log data (section 6), reach measurement (section 6a) and the change history insofar as it serves fraud prevention (section 7b).

After your objection we no longer process this data unless we can demonstrate compelling legitimate grounds which override your interests, rights and freedoms, or the processing serves the establishment, exercise or defence of legal claims.

Where we process your data to send you advertising, you may object at any time without giving reasons; we will then no longer use it for that purpose.

An objection needs no particular form. The quickest way is our privacy request form or [email protected].

To exercise your rights, please use our support page.

Competent supervisory authority: State Commissioner for Data Protection and Freedom of Information North Rhine-Westphalia, Kavalleriestraße 2-4, 40213 Düsseldorf, Germany.

8a. Automated Decisions

The Platform makes decisions based solely on automated processing which produce legal effects concerning you or similarly significantly affect you (Art. 22 GDPR) in only two cases:

  • Restoring access (section 7a): after the identity service provider's check, the Platform compares the first and last name, date of birth and address from the identity document with the accounts whose holders have already verified their identity successfully before. If the result matches exactly one such account, you automatically receive a link at the email address this account already has, with which you restore access; your existing second factor stays active until the new one is confirmed. If you name another address, a staff member decides, as in every other case. If you have switched off recovery through support in the security settings, access is not restored this way, not even by a staff member. The Platform never rejects a request automatically. If the provider cannot complete the check, for example because a photo is unreadable, you can start it again at any time.
  • Domains: if the email address of the domain holder is not confirmed within the deadline of the responsible registry (15 days for .com and other generic top-level domains), the domain is suspended automatically, as the registries' rules require (for generic top-level domains ICANN RAA § 3.7.7.1). As soon as the address is confirmed, the domain is released again.

In both cases you can ask for a staff member to review the decision, state your point of view and contest the decision. Please contact our support for this.

9. Data Security

We use technical and organizational security measures to protect your data: passwords are hashed with bcrypt, sessions are managed via secure httpOnly cookies, data transmission is encrypted via HTTPS/TLS, and database access is restricted to authorized services.

10. Data Retention

Personal data is retained according to the following periods:

  • Account data (name, email, address): until account deletion by the user
  • Company data and progress data: until account deletion
  • Tool-specific business data (invoices, contracts, employees, accounting, etc.): until account deletion, unless statutory retention obligations apply (e.g., invoices 10 years per Section 147 AO)
  • Chat histories with the AI assistant: until account deletion
  • Early access registrations: until official platform launch or until withdrawal
  • Contact inquiries: 6 months after completion of the inquiry
  • Feedback: 24 months
  • AI usage data (cost tracking): until account deletion
  • Server log data: 90 days
  • Sign-in history (the basis for the new-device alert): 365 days
  • Sign-in attempts (protection against automated attacks): 90 days
  • Session cookies: 7 days or until logout
  • Change history (Data History): at least 5 years (GwG), up to 10 years (AO)
  • Identity verification results: until account deletion or per statutory retention periods

When you delete your account, all personal data, company data, progress data, and chat histories will be irrevocably deleted within 28 days, unless legal retention obligations (e.g., tax-related retention periods of 6 or 10 years) apply.

11. Data Processing Agreements

To provide our services, we use sub-processors. AI features and hosting infrastructure are integrated through specialized third-party providers as sub-processors. The AI service provider does not act as an independent data controller but processes data exclusively within the scope of data processing agreements. Data Processing Agreements pursuant to Art. 28 GDPR exist with all providers.

The complete list of sub-processors used, with name, location, and purpose, is provided in Section 13.

12. International Data Transfer

Through the use of our third-party providers in the USA, personal data may be transferred to third countries. The transfer is based on the following legal bases:

  • EU-US Data Privacy Framework (EU Commission adequacy decision)
  • Standard Contractual Clauses (SCC) pursuant to Art. 46(2)(c) GDPR
  • Additionally, Transfer Impact Assessments (TIA) to evaluate the level of protection

CDN and security providers as well as hosting providers, as infrastructure providers, ensure their own legal bases for international data transfers, including the EU-US Data Privacy Framework and/or Standard Contractual Clauses (SCC).

13. Sub-Processors and Third-Party Services

We use the following sub-processors:

Hetzner Online GmbH·Germany (EU)·Server hosting and infrastructure
Cloudflare, Inc.·USA/EU (DPF)·CDN, DNS, DDoS protection, bot detection (Turnstile), cookieless reach measurement (Web Analytics)
Stripe Payments Europe Ltd.·Ireland (EU) + USA·Payment processing, subscriptions, identity verification
Amazon Web Services, Inc. (AWS)·USA (DPF) + EU region (Frankfurt)·Email sending and receiving (SES), short-term storage of inbound emails (S3, Frankfurt)
OVH SAS (OVHcloud)·Germany (EU)·Object storage for uploaded customer files (receipts, documents, images)
Backblaze, Inc.·USA (DPF) + EU region (Amsterdam)·Offsite backups: database dumps (encrypted with our own key before transfer) and a mirror copy of customer files
Twilio, Inc.·USA (DPF)·SMS verification (2FA), emergency notifications
OpenAI LLC·USA (DPF)·AI features (chat, risk analysis, OCR, text generation). Inputs are not used to train the AI models (API usage).
OpenProvider B.V.·Netherlands (EU)·Domain registration and management (ICANN/DENIC mandatory WHOIS data)

Standard Contractual Clauses (SCC) per Art. 46(2)(c) GDPR are in place with all US-based sub-processors. Data Processing Agreements per Art. 28 GDPR are in place with EU-based providers.

14. Changes to this Privacy Policy

We reserve the right to update this Privacy Policy at any time. Significant changes will be communicated to registered users via email or through the Platform. The current version is always available on the Platform.