Privacy Notice
What personal data Wavn, Inc. processes, why, on what legal basis, who receives it, how long it is kept, and the rights you hold over it. Section 3 gives the legal basis for every purpose; section 6 gives the retention schedule; section 8 explains how to exercise your rights.
- Instrument
- Privacy Notice
- Version
- 2.3
- Effective
- 28 August 2026
- Last updated
- 16 September 2026
- Supersedes
- Version 2.2, updated 15 September 2026
1.Who we are and what this notice covers
Wavn, Inc., a Delaware corporation (Wavn, we, us), is the controller of the personal data described in this notice, except where clause 1.3 states otherwise. This notice explains what personal data we process, why, on what legal basis, who receives it, how long we keep it, and what rights you hold.
This notice covers the marketing site at wavn.ai, the Wavn platform at wavn.app and my.wavn.app, and all associated applications and interfaces (together, the Service). Capitalised terms not defined here have the meanings given in the Terms of Service.
Controller and processor roles. Wavn is a controller of account, billing, support and website data. Wavn is a processor of the personal data contained within Customer Content that a customer submits to the Service, acting on that customer’s instructions under the Data Processing Addendum. Where you are an individual whose personal data a Wavn customer has submitted, that customer is the controller and you should direct your request to them; we will assist them in responding.
Contact. Privacy enquiries and rights requests: privacy@wavn.ai. Enquiries under the EU or UK GDPR: gdpr@wavn.ai.
Data protection officer. Wavn has not appointed a data protection officer. Its processing does not meet the criteria in Article 37(1) of Regulation (EU) 2016/679: Wavn is not a public authority, and its core activities do not consist of large-scale regular and systematic monitoring of data subjects or large-scale processing of special categories of data. This assessment is reviewed as the Service grows, and this notice will be updated if an appointment becomes required.
EU and UK representatives. Where Article 27 of Regulation (EU) 2016/679 or of the UK GDPR requires the appointment of a representative, that appointment and its contact details will be published in this clause. Until then, enquiries from the EEA and the UK should be directed to gdpr@wavn.ai.
2.The personal data we process
We process the following categories. We do not purchase personal data from data brokers.
Data you provide directly.
- Account data: email address, display name, authentication identifiers, where your plan requires a verified mobile number, that number, and where you sign in through a third-party identity provider, the profile identifier that provider returns.
- Profile data: any name, role, organisation, language or locale preference you choose to add.
- Billing data: billing name, billing address, tax identifiers, plan and transaction history. Full payment card numbers are processed by our payment processor and never reach Wavn systems.
- Customer Content: the text, prompts, files, documents, images, audio and other material you submit, and the Output generated from it. This may contain personal data about you or about third parties, and you control what it contains.
- Support and communications data: the content of tickets, bug reports, feedback and correspondence with us.
Data collected automatically.
- Technical data: IP address, browser and device type, operating system, referring URL, request timestamps and language settings.
- Usage data: features used, sessions, actions taken in the Service, request and token volumes, and error events.
- Cookie and similar data: as described in the Cookie Notice.
Data from third parties. Where you connect a third-party service to your Account, we receive the data that integration returns, limited to the scopes you grant. Where you sign in through an identity provider, we receive the identifiers described above.
Data we ask you not to submit. The Service is not configured to receive special categories of personal data under Article 9, protected health information, payment card data, biometric identifiers, government identifiers, or children’s data. Clause 13.4 of the Terms and clause 5 of the Acceptable Use Policy prohibit submitting them without our prior written agreement. Where such data is submitted in breach of that prohibition, we process it only as necessary to operate the Service and to remediate.
3.Why we process it, and on what legal basis
Where the EU or UK GDPR applies, we rely on the legal bases in the table below. Where we rely on legitimate interests, we have carried out a balancing assessment and you may object under clause 8.
| Purpose | Data used | Legal basis |
|---|---|---|
| Creating and administering your Account and providing the Service | Account, profile, Customer Content, technical | Performance of a contract (Art. 6(1)(b)) |
| Executing the operations you request, including generating Output | Customer Content, usage | Performance of a contract (Art. 6(1)(b)) |
| Billing, invoicing and collections | Billing, account | Performance of a contract (Art. 6(1)(b)); legal obligation (Art. 6(1)(c)) for tax and accounting records |
| Providing support and responding to enquiries | Support, account, technical | Performance of a contract (Art. 6(1)(b)); legitimate interests (Art. 6(1)(f)) in assisting users |
| Securing the Service, preventing fraud and abuse, enforcing the Acceptable Use Policy | Technical, usage, account, Customer Content where necessary to investigate | Legitimate interests (Art. 6(1)(f)) in protecting the Service, our users and third parties |
| Verifying a mobile number on plans that require one, so that one number stands behind one Account | Account (mobile number) | Legitimate interests (Art. 6(1)(f)) in preventing abuse of plans offered without charge |
| Maintaining and improving the Service, diagnosing faults, capacity planning | Usage, technical, aggregated and de-identified data | Legitimate interests (Art. 6(1)(f)) in operating a functioning service |
| Training Wavn’s own models on Free Plan chat text | Chat text on Free Plan accounts where the setting is enabled | Consent (Art. 6(1)(a)), withdrawable at any time |
| Sending service and security notices | Account | Performance of a contract (Art. 6(1)(b)); legal obligation (Art. 6(1)(c)) for breach notification |
| Sending marketing communications | Account, contact | Consent (Art. 6(1)(a)) where required; otherwise legitimate interests (Art. 6(1)(f)), with opt-out in every message |
| Complying with law and responding to lawful requests | Any category, as required | Legal obligation (Art. 6(1)(c)) |
| Establishing, exercising or defending legal claims | Any category, as necessary | Legitimate interests (Art. 6(1)(f)); legal claims (Art. 9(2)(f)) where special categories are involved |
| Corporate transactions | Account, billing, usage | Legitimate interests (Art. 6(1)(f)) in the conduct of the business |
Model training, stated exactly. Only Wavn’s own models are ever trained on Customer Content. Every third-party engine that processes Customer Content is contractually prohibited from training on it. Training by Wavn happens on two kinds of account only. On a Free Plan account it is limited to chat text and is on unless the Account holder turns it off in Settings under Privacy; our basis is legitimate interests, and that setting is how you object to it at any time, with effect from that moment. A Founding account is granted by invitation at no charge on the express term that both its chat text and the work it builds are used to train Wavn’s own models; our basis there is performance of that agreement, the term is stated in the invitation and accepted before the account is used, and there is accordingly no setting for it. A Founding Account holder who does not wish this may relinquish or close the account. Files, uploaded documents and mail are never used for training on any plan, and neither is any work built from files you supplied. Paid Plan accounts are never used for training. Closing the Account erases what was retained, on any plan, and you may ask us to erase it without closing the account.
No sale, no behavioural advertising. We do not sell personal data. We do not share personal data for cross-context behavioural advertising. We do not use personal data to build advertising profiles, and we run no advertising on the Service.
4.Who receives it
Sub-processors. We use third-party providers to host, operate and secure the Service and to process Customer Content. Every one of them is named, with what it does, where it sits and what reaches it, on the Sub-processor List. That page is the current and authoritative list; it is maintained in preference to naming providers here, because a list in two places drifts. Each operates under a written data processing agreement that restricts it to our documented instructions and prohibits training on Customer Content.
Text messages. Where your plan requires a verified mobile number, we send a one-time code to that number by SMS, through the provider named for it on the Sub-processor List. One message is sent per code you request, and a code is sent only when you ask for one on the verification screen; we send no marketing by text. Message and data rates may apply according to your carrier’s plan. We do not share, sell, or provide your mobile phone number or messaging consent data to third parties or affiliates for marketing or promotional purposes. Text-messaging opt-in data and consent are not shared with any third party, and all other disclosures in this notice exclude that information. Reply STOP to any code message to opt out and HELP for help; a number that has opted out cannot receive a code until it opts back in by replying START.
Advance notice of change. A new sub-processor is published on that page before it begins processing, not after. Customers who require notice by email may request it at privacy@wavn.ai, and may object on reasonable data-protection grounds under the Data Processing Addendum.
Professional advisers. Lawyers, accountants, auditors and insurers, bound by professional duties of confidence, where necessary.
Authorities. We disclose personal data to a court, regulator or law-enforcement authority only where we are legally compelled, or where disclosure is necessary to establish, exercise or defend a legal claim, or to prevent imminent harm to a person. We assess each request for validity, disclose only what the request compels, and notify the affected user unless legally prohibited from doing so or unless notice would create a risk to life or an investigation.
Corporate transactions. In connection with a merger, acquisition, financing, reorganisation or sale of assets, personal data may be disclosed to counterparties and their advisers under confidentiality obligations, and may transfer as part of the transaction. Any acquirer remains bound by this notice in respect of data transferred until it gives affected individuals notice of a change and, where required, obtains consent.
At your direction. Where you connect an integration or publish material through the Service, data flows to that destination because you instructed it.
5.International transfers
Wavn is established in the United States and its sub-processors are located in several countries, identified on the Sub-processor List with the country each sits in. Using the Service therefore involves transferring personal data across borders, including to countries that have not received an adequacy decision from the European Commission or the UK government.
Transfer mechanisms. For transfers of personal data out of the EEA, the United Kingdom or Switzerland, we rely on:
- the Standard Contractual Clauses approved by the European Commission in Implementing Decision (EU) 2021/914, incorporated into the Data Processing Addendum;
- the UK International Data Transfer Addendum to those clauses, for UK transfers;
- the Swiss addendum recognised by the Federal Data Protection and Information Commissioner, for Swiss transfers; and
- an adequacy decision, where one covers the destination.
Transfer impact. We assess the law and practice of each destination for its effect on the protection the clauses provide, and apply supplementary measures where the assessment requires them, including encryption in transit and at rest, access minimisation, and a commitment to challenge overbroad government access requests. A copy of the clauses and of the current assessment is available on request at privacy@wavn.ai.
6.How long we keep it
We keep personal data only as long as necessary for the purpose it was collected for, then delete it or irreversibly de-identify it. Where a period below is expressed as a criterion rather than a fixed term, that is because the period genuinely depends on the criterion.
| Category | Retention | Why |
|---|---|---|
| Account and profile data | For the life of the Account, then deleted on closure | Needed to provide the Service |
| Customer Content | Until you delete it, or 30 days after Account closure | Yours to control; the 30-day window is the export period in clause 18.5 of the Terms |
| Decision Records | For the life of the Account, then with the Account | A record whose value is that it survives the meeting |
| Guest conversations (no Account) | Thirty days from the conversation, then deleted | There is no Account to keep them against; they are never used to train our models |
| Training corpus entries | Until the setting is disabled or the Account is closed, then erased | Consent-based and withdrawable |
| Billing and transaction records | Seven years from the transaction | Tax, accounting and audit obligations |
| Support correspondence | Three years from closure of the ticket | Service history and dispute defence |
| Security and access logs | Twelve months, or longer where an incident or investigation is live | Detecting and investigating abuse |
| Marketing contact data | Until you unsubscribe, then a suppression record indefinitely | A suppression list must outlive the consent to honour the opt-out |
| Records relating to a legal claim | Until the claim and any appeal or limitation period ends | Establishing, exercising or defending claims |
| Backups | Purged on the ordinary backup cycle after deletion from live systems | Deletion from live systems cannot instantly rewrite historical backups |
Backups. When data is deleted from live systems, residual copies may persist in backups until those backups expire on their ordinary cycle. Data in backups is not returned to live systems, is not processed for any other purpose, and is deleted when the backup expires.
7.Security
We maintain technical and organisational measures appropriate to the risk, including encryption of data in transit and at rest, row-level access controls in the database, least-privilege access for personnel, authentication through a managed identity provider, segregation of environments, logging of administrative access, and vendor review before a sub-processor is engaged. Further detail is on the security page, including what is not yet done.
No certification claimed. Wavn does not currently hold SOC 2, ISO/IEC 27001 or any comparable third-party certification, and this notice makes no such claim. Where a certification is obtained, it will be stated on the security page with its date and scope.
Breach notification. Where a personal data breach is likely to result in a risk to your rights and freedoms, we will notify the competent supervisory authority within 72 hours of becoming aware of it where required by Article 33, and will notify you without undue delay where Article 34 or comparable law requires. Where Wavn acts as a processor, it will notify the controller without undue delay so that the controller can meet its own deadlines.
No absolute guarantee. No method of transmission or storage is completely secure. We do not warrant that our measures will prevent every unauthorised access.
8.Your rights
Subject to the conditions and exemptions of the law that applies to you, you hold the following rights. We do not charge for exercising them, and we do not discriminate against you for doing so.
Rights under the EU and UK GDPR.
- Access: to be told whether we process your personal data and to receive a copy (Art. 15).
- Rectification: to have inaccurate data corrected and incomplete data completed (Art. 16).
- Erasure: to have data deleted where one of the grounds in Art. 17 applies.
- Restriction: to have processing restricted in the circumstances in Art. 18.
- Portability: to receive data you provided in a structured, commonly used, machine-readable format and to have it transmitted to another controller where technically feasible (Art. 20).
- Objection: to object at any time to processing based on legitimate interests, on grounds relating to your particular situation, and to object absolutely to processing for direct marketing (Art. 21).
- Withdrawal of consent: to withdraw consent at any time, without affecting the lawfulness of processing before withdrawal (Art. 7(3)).
- Complaint: to lodge a complaint with a supervisory authority in your habitual residence, place of work or the place of the alleged infringement (Art. 77), or with the UK Information Commissioner’s Office.
Rights under United States state privacy laws. Where a state law such as the California Consumer Privacy Act as amended, or the comparable laws of Colorado, Connecticut, Virginia, Utah, Texas, Oregon, Montana and other states, applies to you, you hold rights to know, access, correct, delete and obtain a portable copy of your personal information, to opt out of sale, sharing for cross-context behavioural advertising, and profiling with legal or similarly significant effects, and to limit the use of sensitive personal information. As stated in clause 3.3, we do not sell or share personal information and do not conduct behavioural advertising, so there is nothing to opt out of; we honour Global Privacy Control signals regardless. You may appeal a refused request under clause 8.5.
Authorised agents. You may use an authorised agent to make a request. We will require written proof of authorisation and may require you to verify your identity directly.
How to exercise a right, and our response. Write to privacy@wavn.ai. We will verify your identity before acting, using information already associated with your Account, and will respond within one month under the GDPR or forty-five days under applicable US state law, each extendable once where the request is complex, with notice to you of the extension and its reasons. Where we refuse, we will say why and tell you how to complain or appeal.
Appeal. If we refuse a request, you may appeal by replying to our decision with the word “appeal” and your grounds. An appeal is reviewed by someone other than the person who made the original decision, and we will notify you of the outcome and its reasons within forty-five days. If the appeal is refused, we will tell you how to contact your supervisory authority or state attorney general.
Deletion, self-service. You may delete Customer Content in the Service at any time, and may close your Account, which erases the Account, its Customer Content and any training corpus entries associated with it, subject to the backup and legal-claim exceptions in clause 6.
9.Automated decision-making and profiling
Wavn does not make decisions producing legal effects concerning you, or similarly significantly affecting you, based solely on automated processing within the meaning of Article 22 of Regulation (EU) 2016/679.
The Service generates Output by automated means at your direction. That Output is a work product delivered to you, not a decision Wavn takes about you.
Automated systems are used to detect abuse and to enforce usage limits. Where such a system results in a restriction of your Account, clause 8 of the Acceptable Use Policy gives you notice, reasons and an appeal that is not decided solely by the automated process that produced the measure.
10.Cookies and similar technologies
Our use of cookies, local storage and similar technologies, the categories used, their purposes and duration, and how to control them, are set out in the Cookie Notice, which forms part of this notice.
11.Children
The Service is offered only for business and professional use and only to persons aged eighteen (18) or over. It is not directed to children, and we do not knowingly collect personal data from anyone under eighteen.
If we learn that we hold personal data of a person under eighteen collected through an Account held in breach of clause 3.2 of the Terms, we will delete it and close the Account. If you believe we hold such data, write to privacy@wavn.ai and we will act without undue delay.
12.Changes to this notice
We may update this notice. The updated version is posted on this page with a new version number and effective date in the masthead, and recorded on the changelog.
Where a change materially affects how we process your personal data, we will give at least thirty (30) days’ notice before it takes effect, by email to the address on your Account or by prominent notice in the Service. Where a change requires your consent, we will obtain it before the change applies to you rather than treating continued use as agreement.
Previous versions are available on request at privacy@wavn.ai.
Wavn, Inc. Questions about this document go to legal@wavn.ai. The other instruments that bind alongside it are the Terms of Service, Acceptable Use Policy, Privacy Notice, Cookie Notice, Data Processing Addendum, the Sub-processor List and the Refund Policy.