Privacy Policy

Last updated: 26 May 2026

1. About This Policy

This Privacy Policy explains how Wavertech Ltd. ("Wavertech", "we", "us") handles personal data when you use WAVER+, the online account, billing, licensing, and optional service management system for WAVER Gateway devices.

Where Wavertech processes personal data on the Customer's behalf (for example, AI Service inputs and outputs or PMS integration data), the controller-to-processor terms in our Data Processing Addendum apply (Terms and Conditions, Section 23).

2. Who We Are

Wavertech Ltd., Vasil Mechkuevski 22, 2700 Blagoevgrad, Bulgaria. EU VAT: BG204530090.

For privacy questions and to exercise your data protection rights, contact our Privacy Contact at [email protected].

As Wavertech Ltd. is established in Bulgaria, our lead supervisory authority for matters under the EU General Data Protection Regulation (Regulation (EU) 2016/679, the "GDPR") is the Bulgarian Commission for Personal Data Protection (Комисия за защита на личните данни) - https://www.cpdp.bg. You also have the right to lodge a complaint with the supervisory authority of the EU member state in which you reside or work.

3. Data We Collect

The data WAVER+ collects falls into the categories described below.

3.1 Account data

Information you provide when creating and maintaining a WAVER+ account, such as full name, business email, company name, country, password (stored as a hash), and two-factor authentication settings.

3.2 Billing, subscription, and license data

Information about your subscriptions and licenses, including plan name, billing interval, start and end dates, subscription status, invoice references, and amounts charged. Payment card details are handled directly by our payment processor (Stripe). WAVER+ stores references such as customer and invoice IDs, not full card numbers.

Billing address, VAT identification number, and other invoice-relevant information are stored in our payment processor and may be cached locally in WAVER+ for display purposes.

3.3 Device and operational data

Information about WAVER Gateway devices that you link to your account, such as device name, device ID, model and firmware identifiers, cloud URL, pairing status, sync status, cloud access status, last sync time, and license assignment state.

3.4 Technical, security, and error logs

Records related to the operation of WAVER+, such as IP address, request metadata, authentication events, rate-limit counters, error logs, and security events. These logs are used for security, troubleshooting, abuse prevention, and reliability.

3.5 Support communications

Messages you send to our support channels, along with any information you choose to include in those messages.

3.6 AI service inputs and outputs (where applicable)

If you enable an AI Service License, the prompts you send and the generated outputs are transmitted to the AI provider for processing. WAVER+ retains limited metadata (request timestamp, model, token counts) for metering, abuse prevention, and quality monitoring. Provider-side retention of prompts and outputs is governed by the AI provider's terms.

3.7 PMS integration data (where enabled by the Customer)

If you enable a PMS Integration, configuration values, connection metadata, and the limited data fields necessary to operate the integration may be processed. The Customer remains responsible for configuring and authorizing the integration.

4. Guest WiFi and End-User Traffic

WAVER+ is designed so that guest WiFi traffic and End-User communications processed by a WAVER Gateway device normally remain on the device and are not transmitted to WAVER+. Traffic may be transmitted to WAVER+ or to a third-party provider only when a specific Optional Service or integration expressly requires it, and only after the Customer enables that service.

5. Controller and Processor Roles

For Customer account, billing, and operational data, Wavertech Ltd. acts as the data controller.

For data relating to End Users of a guest network operated by a WAVER Gateway device, the Customer (the operator of the device) is the data controller. Where an Optional Service processes such data on the Customer's behalf, Wavertech Ltd. acts as a data processor and processes that data on the Customer's instructions, as documented in the Data Processing Addendum (Terms and Conditions, Section 23).

6. Legal Bases (GDPR)

Where the GDPR or similar law applies, we process personal data on the following legal bases, depending on the activity:

  • Contract - to register your account, provide WAVER+, manage subscriptions and licenses, and deliver the Optional Services you request.
  • Legitimate interests - to secure our systems, prevent abuse, monitor service quality, and improve our products, where these interests are not overridden by your rights.
  • Legal obligation - to keep billing, tax, accounting, and security records as required by applicable law.
  • Consent - where we ask for your explicit consent for a specific purpose, for example enabling certain Optional Integrations.

7. How We Use Data

  • To create and manage WAVER+ accounts.
  • To process payments and manage subscriptions, licenses, and invoices.
  • To enable and operate the Optional Services you choose to use.
  • To communicate transactional information such as billing notifications, expiry warnings, and security notices.
  • To secure WAVER+ against fraud, abuse, and unauthorized access.
  • To meet legal, tax, accounting, and regulatory obligations.
  • To improve the reliability, performance, and security of WAVER+.

8. Data Sharing - Subprocessors

We do not sell personal data. We share data with the following named subprocessors and recipients to operate WAVER+. Our authority to engage these subprocessors is granted by the Customer in the Data Processing Addendum (Terms and Conditions, Section 23). New or replacement subprocessors will be announced with reasonable advance notice.

SubprocessorRoleLocation
Stripe Payments Europe, Ltd.Payment processing, subscription billing, customer portal, invoicing, VAT calculationIreland (EU)
Amazon Web Services EMEA SARLHosting and storage of WAVER+ application dataEU region (Frankfurt)
Cloudflare, Inc.Edge CDN, DDoS protection, TLS termination, and Turnstile bot/CAPTCHA challenge on login and signupGlobal, EU edge POPs; corporate seat in the United States
OpenAI Ireland LimitedAI text processing for the Customer's AI Service prompts. Engaged only when the Customer enables an AI Service License using an OpenAI-supported model.Ireland; provider may process in the United States under Standard Contractual Clauses
Anthropic, PBCAI text processing for the Customer's AI Service prompts. Engaged only when the Customer enables an AI Service License using an Anthropic-supported model.United States, under Standard Contractual Clauses

Transactional email (account verification, password reset, billing notifications) is sent from Wavertech's own mail server using our own infrastructure; no third-party email provider is engaged for outbound email.

In addition to the subprocessors above, we may disclose data to authorities, regulators, or other parties where required by law.

9. International Transfers

The primary storage location for WAVER+ application data is in the European Union (Frankfurt region). Two categories of processing involve potential transfers outside the EEA:

  • Edge / CDN traffic handled by Cloudflare - requests are typically terminated at an EU edge POP, but Cloudflare is a US-headquartered company. We rely on Standard Contractual Clauses with Cloudflare.
  • AI provider traffic - when the Customer enables an AI Service License, prompts and outputs are transmitted to the relevant AI provider (OpenAI or Anthropic), which may process them in the United States. We rely on Standard Contractual Clauses with these providers.

Where personal data is transferred to a country that is not subject to an adequacy decision, we rely on appropriate safeguards such as Standard Contractual Clauses or equivalent measures recognized under applicable law.

10. Retention

We keep account and operational data for as long as your WAVER+ account is active. After the account is closed, some categories of data are retained for the periods required by law and by our payment processor, including billing records, tax records, and security records.

Logs and operational records are retained only for as long as needed for the purposes described in this Policy, after which they are deleted or anonymized.

11. Security

We apply appropriate technical and organizational measures to protect personal data, including encrypted transport, authenticated and authorized access, application-level rate limiting, logging of security-relevant events, and periodic review of provider configurations. No system is completely secure; we work to reduce risk and to respond to security events when they occur.

12. Your Rights

Depending on your country, you may have rights under data protection law, including:

  • The right to access personal data we hold about you.
  • The right to request correction of inaccurate data.
  • The right to request deletion of personal data, subject to legal retention requirements.
  • The right to restrict or object to certain processing.
  • The right to data portability for data you provided to us.
  • The right to withdraw consent, where processing is based on consent.
  • The right to lodge a complaint with your local supervisory authority (see Section 2 for our lead authority).

Most actions can be performed from your WAVER+ account settings. For other requests, contact [email protected]. We may need to verify your identity before acting on a request.

13. Cookie Notice

WAVER+ uses cookies and similar technologies only to the extent necessary for the service to function. We do not use advertising cookies, behavioral tracking cookies, or third-party analytics cookies.

13.1 Strictly necessary cookies set by WAVER+

  • auth_token - HTTP-only session cookie that keeps you signed in. Required for the dashboard to function after login. Expires according to the configured session lifetime.
  • csrftoken - Cross-site request forgery protection. Set by Django, required for state-changing requests.
  • sessionid - Server session cookie used by the Django admin and Swagger UI for staff accounts. Not set for regular Customer accounts.

13.2 Cookies set by Cloudflare Turnstile (anti-bot challenge)

On the login and signup pages we embed Cloudflare Turnstile, which may set its own challenge tokens or cookies to verify that the visitor is not an automated bot. These are managed by Cloudflare; consult Cloudflare's documentation for the current list and behavior.

13.3 Cookies set by Stripe on Stripe-hosted pages

When you proceed to checkout or open the Stripe Customer Portal, you are temporarily on a Stripe-hosted page. Stripe may set its own cookies for fraud prevention and session continuity while you are on that page. These are governed by Stripe's own privacy and cookie notices.

13.4 Refusing or deleting cookies

You can clear or block cookies in your browser settings. Blocking the strictly necessary cookies listed above will break sign-in and the dashboard. We do not provide an in-app cookie consent banner because we do not use any cookies that require GDPR consent (no advertising, no behavioral tracking, no third-party analytics).

14. Children and Minors

WAVER+ is intended for business customers and is not directed at children. We do not knowingly collect personal data from children. If you believe a minor has provided data to WAVER+, contact [email protected] so we can investigate and take appropriate action.

15. Changes to This Policy

We may update this Privacy Policy from time to time. The "Last updated" date at the top of this page shows when the latest version took effect. Material changes will be communicated by email or in-app notice before they take effect.

16. Contact

Wavertech Ltd., Vasil Mechkuevski 22, 2700 Blagoevgrad, Bulgaria. EU VAT: BG204530090.

For privacy questions, data subject requests, or to contact our Privacy Contact, email [email protected].

For general or sales enquiries, email [email protected]. For technical support, email [email protected].