Privacy Policy
WAVHZ SYSTEMS PRIVATE LIMITED · Last updated 5 October 2026
This policy explains what personal data WAVHZ SYSTEMS PRIVATE LIMITED (“WavHz”, “we”) handles through Waveform, why, who else sees it, and the rights you have. We are the data fiduciary (controller) for the account details of the people who sign up. For the information an organisation puts into Waveform about its own customers and work, the organisation decides what goes in and we process it on its behalf.
1. What we collect
- Your account: name, email address, country, your role in the organisation, and the organisation’s name and type. Passwords are handled by our sign-in provider; we never see them in readable form.
- What you put in: customers and their contact details, forms and the answers submitted through them (including through public links, by people who have no account), workflow items, tasks, comments, files you upload, and the settings and integrations you set up.
- Payments: the plan, amount, dates, and the order and payment references from Razorpay. We do not receive or store your card, UPI or bank details.
- The AI assistant: what you ask it, the information it reads or changes in your account to answer, and how much of your allowance you use.
- API keys: a name, the role it acts as, when it was used and from which address. The secret itself is kept only as a one-way hash.
- Technical data: IP address, browser and device information, and timestamps in our logs, used to keep the service secure and working.
2. Why we use it
- to provide Waveform to you: sign you in, store and show your data, send the messages that sign-in needs (such as a temporary password), and take payments;
- to keep it secure: prevent abuse, limit repeated failed sign-ins, investigate problems;
- to support you and to tell you about changes that affect you;
- to meet legal obligations (tax, accounting, responding to lawful requests) and to establish or defend legal claims;
- to improve the service, using anonymous figures about how it is used.
We do not sell personal data, and we do not use it for advertising.
3. Who else handles it
We use these providers to run the service, each only for that purpose:
- Amazon Web Services: hosting, file storage, email delivery of sign-in messages, and the sign-in service itself (Amazon Cognito). Our data is hosted in Ireland (EU).
- Our managed database provider (Timescale), which stores your records.
- Razorpay, which processes payments and has its own privacy policy.
- A third-party AI model provider (Anthropic), only when the AI assistant is used, and only with what the assistant needs to answer.
- Authorities and advisers, where the law requires it or to protect our legal rights.
If our business is sold or reorganised, personal data may transfer to the new owner on the same terms.
4. Where it goes
WavHz is based in India, our data is hosted in Ireland, and some providers (such as the AI model provider) process data in other countries, including the United States. Where personal data leaves its home country we rely on the safeguards the law provides, such as contractual protections and the providers’ own compliance commitments.
5. How long we keep it
- Your account and your organisation’s data: while the account is active, and until you ask us to delete it.
- Payment records: for 8 years, as tax and company law require.
- Security logs: for a limited period needed to keep the service safe.
- Anything we must keep to meet a legal obligation or defend a claim, for as long as that lasts.
6. Cookies and similar storage
We use only what the service needs: cookies that keep you signed in and complete a sign-in, and your browser’s local storage for your own preferences (such as theme, text size, the sidebar and which dashboard cards you show). We do not use advertising or tracking cookies. When you pay, Razorpay’s payment window may set its own cookies, under its own policy.
7. Security
We protect data in transit with encryption, keep the secrets behind integrations encrypted and API key secrets only as hashes, limit what each person can see by their role, and restrict who at WavHz can reach systems. No system is perfectly secure; if a breach affects your personal data we will tell you and the authorities as the law requires.
8. Your rights
Under India’s Digital Personal Data Protection Act, 2023 you may ask to access the personal data we hold about you, have it corrected or erased, nominate someone to exercise your rights, and have a grievance addressed. Where the UK or EU GDPR applies you also have the rights to restrict or object to processing, to portability, and to complain to a supervisory authority. To exercise a right, write to legal@wavhz.com. We respond within 30 days, and may need to confirm who you are first.
If you are a customer or contact of an organisation that uses Waveform, the organisation decides what is held about you; ask it first, and we will help it respond.
9. Children
Waveform is for businesses and is not directed at anyone under 18. We do not knowingly collect children’s data; if we learn we have, we delete it.
10. Grievances and changes
Complaints about how we handle personal data go to our Grievance Officer at legal@wavhz.com (put “Grievance” in the subject). We acknowledge and aim to resolve them within 30 days; if you are not satisfied you may approach the Data Protection Board of India or the regulator in your country. If we change this policy in a way that matters, we will tell you in the product or by email, and the date at the top will change.
WAVHZ SYSTEMS PRIVATE LIMITED, 1-179/P3/443/APR Nagar, APR Nature, Patancheru, Patancheru, Medak - 502319, Telangana, India.