Policies

Data processing agreement

How we handle the personal data you put into Waving, as the UK GDPR says a processor's contract must set out. Part of the terms of service.

This agreement is part of the Waving terms of service. It applies when Fully Coded Solutions Limited (“we”) processes personal data for the business that holds a Waving account (“you”).

1. Roles

For personal data about the people you email, you are the controller and we are the processor.

2. What we process

Subject matter Sending, pacing and following up business outreach email, and handling replies
Duration While your account is open, plus up to 30 days to delete
Nature Storing, sending, receiving, matching replies, drafting with AI, suppressing
Purpose Providing Waving to you
People Contacts at the businesses you choose to email
Data Name, work email address, job title, company, the reason you are writing, emails sent and received, delivery events

You must not load special category data or data about criminal convictions.

3. Your instructions

We process the data only on your documented instructions, which are the terms of service, this agreement and the settings you choose in the app. That includes any transfer outside the UK. If we think an instruction breaks data protection law, we will tell you. If the law requires us to process data in another way, we will tell you first unless the law forbids it.

4. Confidentiality

Everyone at Fully Coded Solutions Limited who can access the data is bound by confidentiality.

5. Security

We keep appropriate technical and organisational measures in place, including encryption in transit, access limited to the people who need it, a code sent by email on every sign-in to the app, and 14 days of backups.

6. Sub-processors

You give general permission for us to use the sub-processors listed in our privacy policy. We will email you at least 30 days before adding or replacing one, and you can object. If we cannot resolve your objection, you can close your account and we will refund any fees paid for the period after it closes. Each sub-processor is bound by data protection terms at least as protective as these, and we remain responsible to you for them.

7. Helping you

We will help you answer requests from the people you email, including giving you what we hold on a person within two working days. We will also help you with security, breach notifications, data protection impact assessments and any consultation with the ICO, as far as our role allows.

8. Breaches

If we become aware of a personal data breach affecting your data, we will tell you without undue delay, and give you what we know so you can decide whether to report it.

9. When your account closes

Within 30 days we delete your data, or return it first if you ask, unless the law requires us to keep it. Backups expire within a further 14 days.

The only data we keep is an email address that its owner has asked us directly to add to the Waving-wide do-not-send list. We hold that as controller, as our privacy policy explains.

10. Audits

We will give you the information you reasonably need to show we meet this agreement. We will allow an audit by you or an auditor you appoint, with at least 30 days’ notice, no more than once a year unless a breach or a regulator requires it, at your cost.

11. Transfers

We will only transfer your data outside the UK where a lawful transfer mechanism is in place, as listed in our privacy policy.

Questions

If anything here is unclear, ask. A person answers.

hello@waving.co.uk