How Waivern Limited collects, uses, and protects your personal data, and the rights you have over it.
Waivern Limited (Waivern, we, us, our) is a company registered in England and Wales (company number 16375372). Our registered address is 14 Eastbury Road, Petts Wood, Orpington, England, BR5 1JW.
We are registered with the Information Commissioner’s Office (ICO) as a data controller (registration reference: ZB920277).
We are the controller of the personal data described in this policy - meaning we decide why and how that data is processed.
If you have any questions about how we handle your personal data, or if you wish to exercise any of your rights, please contact us:
We have appointed a Data Protection Officer (DPO). You can contact our DPO directly at:
This policy is written to satisfy our transparency obligations under:
Where we refer to “GDPR” without a prefix, the obligation applies equally under both the UK GDPR and the EU GDPR. Where the two regimes differ, we say so explicitly.
Waivern provides privacy, AI and cybersecurity compliance-readiness services for startups and scale-ups. We combine automated evidence-gathering tooling with review and guidance from human legal and technical experts, helping clients achieve audit-ready compliance outcomes.
This policy applies to:
We do not knowingly collect personal data from children under 13. Our services and website are directed at business professionals and organisations.
This policy does not cover personal data that our customers upload into the Waivern compliance platform. When you use our platform to process data that belongs to your own users or employees, you are the controller of that data and we act as your processor. That relationship is governed by the Data Processing Agreement between us.
The table below sets out each purpose for which we process personal data as controller, the categories of data involved, the lawful basis we rely on under Article 6 UK GDPR (and, where relevant, EU GDPR), and how long we keep the data.
| Purpose | Categories of personal data | Lawful basis | Retention |
|---|---|---|---|
| Managing your customer account and delivering our services | Name, email address, billing address, phone number | Performance of a contract with you - Art. 6(1)(b) UK GDPR / EU GDPR | 6 years after account closure (UK Limitation Act 1980 contract-claim window) |
| Processing payments | Billing address, payment card details (held by our payment processor - we do not store card data ourselves) | Performance of a contract with you - Art. 6(1)(b) UK GDPR / EU GDPR | 6 years after account closure |
| Electronic direct marketing to existing customers (newsletters, product updates, and offers relating to our own similar services) | Name, email address, engagement history | Legitimate interests - Art. 6(1)(f) UK GDPR / EU GDPR. Our interest is maintaining a commercial relationship by keeping existing customers informed of relevant updates and services. We rely on the soft opt-in under PECR Regulation 22 (existing-customer rule). A Legitimate Interests Assessment is on file. | 24 months from last engagement (last open, click, or visit), then deleted or re-confirmed |
| Electronic direct marketing and advertising to prospects (people who have not yet purchased from us) | Name, email address, employer, engagement history | Consent - Art. 6(1)(a) UK GDPR / EU GDPR. You must opt in before we contact you for marketing. You may withdraw consent at any time (see Section 10). | 24 months from last engagement, or until consent is withdrawn |
| Website analytics - understanding how visitors use our website and improving our services | IP address, device identifiers, language settings, screen resolution, device type, operating system, session start and end times, click-event behaviour, non-precise location (city/country) | Consent - Art. 6(1)(a) UK GDPR / EU GDPR. We use Google Analytics, which must be loaded only after you have given consent via our consent management platform (Cookiebot). You may withdraw consent at any time (see Section 10 and our Cookie Policy). | 14 months from the date of the event |
| Advertising performance and conversion tracking | IP address, device identifiers, language settings, screen resolution, device type, operating system, session start and end times, click-event behaviour, non-precise location (city/country), conversion behaviour, user engagement data | Consent - Art. 6(1)(a) UK GDPR / EU GDPR. Advertising and conversion-tracking cookies (Google Ads, DoubleClick, LinkedIn Insight Tag) must be loaded only after you have given consent. You may withdraw consent at any time (see Section 10 and our Cookie Policy). | 24 months from collection, or until consent is withdrawn |
| Security logging and fraud prevention | IP addresses, access logs, authentication events | Legitimate interests - Art. 6(1)(f) UK GDPR / EU GDPR. Our interest is protecting our systems, our customers, and the integrity of our services against unauthorised access and fraud. A Legitimate Interests Assessment is on file. | 12 months from the date of the event, then deleted by log rotation |
| Responding to your direct enquiries (via contact form or email) | Name, email address, message content, and any other information you choose to include | Legitimate interests - Art. 6(1)(f) UK GDPR / EU GDPR. Our interest is responding to people who contact us. A Legitimate Interests Assessment is on file. | 24 months from last contact with you |
| Processing job applications | Name, contact details, CV/résumé, work history, qualifications, references | Legitimate interests - Art. 6(1)(f) UK GDPR / EU GDPR, for the purpose of evaluating and selecting candidates. A Legitimate Interests Assessment is on file. | If unsuccessful: 12 months from decision date (Equality Act 2010 claim window), then deleted. If successful: merged into your employee record. |
| Employee payroll and HR administration | Name, contact details, national insurance number, payroll data, employment contract details, performance records | Legal obligation - Art. 6(1)(c) UK GDPR / EU GDPR (HMRC reporting and employment law obligations) | HR file: 6 years after end of employment. Payroll records: 7 years after end of the relevant tax year. |
| Maintaining cookie consent records | Consent timestamp, preferences selected, anonymised identifier | Legal obligation - Art. 6(1)(c) UK GDPR / PECR (demonstrating that consent was validly obtained) | 24 months from the date consent was collected, then auto-purged by our consent platform |
| Handling data subject access and other rights requests | Name, contact details, request correspondence, verification information | Legal obligation - Art. 6(1)(c) UK GDPR / EU GDPR (Art. 12-22 compliance) | 3 years from response date |
| Recording and managing personal data breach incidents | Details of affected individuals (categories and approximate numbers), incident correspondence, regulatory notifications | Legal obligation - Art. 6(1)(c) UK GDPR / EU GDPR (Art. 33-34 breach notification and demonstrating compliance to regulators) | 5 years from incident close date |
Our compliance platform and general business operations do not involve the routine processing of special-category personal data (as defined in Art. 9 UK GDPR / EU GDPR) about our customers, website visitors, or job applicants.
Where we act as your Data Protection Officer and you bring individual cases, complaints, or data subject access matters to our attention, we may occasionally encounter special-category data in that context. We do not retain such data beyond the resolution of the matter for which it was shared with us, and we do not use it for any other purpose.
We use cookies and similar technologies on our website. Full details - including the specific cookies in use, their purposes, and your consent choices - are set out in our Cookie Policy.
In summary, our cookies fall into the following categories under the post-DUAA PECR framework:
| Category | Cookies observed | Consent required? | Basis |
|---|---|---|---|
| Strictly necessary | CookieConsent (Cookiebot - records your consent preference) | No | Essential for recording your consent choices and for the website to function correctly. Exempt from prior consent under PECR. |
| Analytics | Google Analytics (_ga and related cookies, property G-SNNESL7MGP) | Yes - prior opt-in consent required | Google Analytics is connected to Google’s advertising infrastructure and cannot be treated as a single-purpose analytics cookie exempt from consent under PECR. These cookies must be loaded only after you have given consent via our consent management platform (Cookiebot). |
| Advertising and conversion tracking | Google Ads conversion linker (_gcl_au), Google DoubleClick (test_cookie on doubleclick.net), LinkedIn Insight Tag | Yes - prior opt-in consent required | Used for advertising performance, retargeting, and LinkedIn audience matching. Consent is required under PECR. These must be loaded only after you have given consent. |
You can change your cookie preferences at any time by using the cookie settings link on our website, or by clearing your browser cookies and revisiting us.
We share personal data only where necessary and with appropriate safeguards in place. The categories of recipients are:
We do not sell your personal data to third parties.
Several of our service providers are based outside the UK and the European Economic Area (EEA). Where we transfer personal data internationally, we put in place appropriate safeguards as set out below.
| Transfer route | Recipients / examples | Safeguard / mechanism |
|---|---|---|
| UK → EU/EEA (including France) | Gojiberry AI (Superfruits SAS) | UK adequacy regulations - the EU/EEA benefits from a UK adequacy finding; no additional safeguard is required for UK-to-EEA transfers. |
| UK → USA | Vercel (UK IDTA); Anthropic, GitHub, LinkedIn, Mailchimp, Meta, Microsoft, Miro, OpenAI, Railway Corporation, Salesforce/Slack (UK Addendum to EU SCCs); Postmark / ActiveCampaign (UK Extension to EU-US Data Privacy Framework) | International Data Transfer Agreement (IDTA) or Standard Contractual Clauses with the UK Addendum to EU SCCs, or - where applicable - the UK Extension to the EU-US Data Privacy Framework, incorporated into data processing agreements with each provider. Copies of the relevant safeguards are available on request. |
| UK → USA (transfer mechanism under confirmation) | Stripe, WhatsApp, Google Analytics | We are in the process of confirming the specific transfer mechanism for these providers. We will update this policy once confirmed. In the interim, we are satisfied that appropriate contractual arrangements are in place with each provider. |
| EU → USA (where EU GDPR applies to our EU-based users) | Same US providers as above | EU Standard Contractual Clauses (EU SCCs 2021) incorporated into data processing agreements. Copies available on request. |
To request a copy of the transfer safeguards in place for any specific recipient, please contact us at info@waivern.com.
Under UK GDPR and EU GDPR, you have the following rights in relation to your personal data. To exercise any of these rights, please contact us at info@waivern.com or write to us at our registered address.
We will not charge a fee for handling your request unless it is manifestly unfounded or excessive. We aim to respond within one month, though we may extend this by a further two months for complex or numerous requests, in which case we will notify you promptly.
If you are unhappy with how we have handled your personal data, please contact us first so we have the opportunity to put things right:
We will acknowledge your complaint within 30 days and will respond without undue delay, in accordance with our obligations under the DPA 2018 as amended by the DUAA (s.164A, in force from 19 June 2026). We will also provide an electronic route for submitting your complaint - you may use the email address above.
If you remain dissatisfied after contacting us, or if you prefer to contact the regulator directly, you have the right to lodge a complaint with the Information Commissioner’s Office (ICO):
If you are based in Norway or another EU member state, you also have the right to lodge a complaint with your local supervisory authority. In Norway, this is the Norwegian Data Protection Authority (Datatilsynet): https://www.datatilsynet.no/en/.
We take appropriate technical and organisational measures to protect your personal data against unauthorised access, loss, or disclosure. These include:
We review this policy regularly. When we make significant changes, we will notify you by email (if you are a customer or have subscribed to our communications) and/or by displaying a prominent notice on our website. The effective date at the top of this policy will always reflect when it was last updated.
We encourage you to review this policy periodically.