Privacy Policy

How Waivern Limited collects, uses, and protects your personal data, and the rights you have over it.

Effective date:
17 July 2026
Last reviewed:
28 July 2026

1. Who we are and how to contact us

Waivern Limited (Waivern, we, us, our) is a company registered in England and Wales (company number 16375372). Our registered address is 14 Eastbury Road, Petts Wood, Orpington, England, BR5 1JW.

We are registered with the Information Commissioner’s Office (ICO) as a data controller (registration reference: ZB920277).

We are the controller of the personal data described in this policy - meaning we decide why and how that data is processed.

If you have any questions about how we handle your personal data, or if you wish to exercise any of your rights, please contact us:

2. Our Data Protection Officer

We have appointed a Data Protection Officer (DPO). You can contact our DPO directly at:

3. The law that applies to this policy

This policy is written to satisfy our transparency obligations under:

  • the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018 (DPA 2018), as amended by the Data (Use and Access) Act 2025 (DUAA);
  • the Privacy and Electronic Communications Regulations 2003 (PECR), as amended by the DUAA; and
  • the EU General Data Protection Regulation (EU GDPR) - which applies because we have an establishment under formation in Norway and serve individuals in EU member states including the Netherlands and Norway.

Where we refer to “GDPR” without a prefix, the obligation applies equally under both the UK GDPR and the EU GDPR. Where the two regimes differ, we say so explicitly.

4. About us and who this policy covers

Waivern provides privacy, AI and cybersecurity compliance-readiness services for startups and scale-ups. We combine automated evidence-gathering tooling with review and guidance from human legal and technical experts, helping clients achieve audit-ready compliance outcomes.

This policy applies to:

  • visitors to our website at https://www.waivern.com;
  • existing and prospective customers and business contacts; and
  • job applicants.

We do not knowingly collect personal data from children under 13. Our services and website are directed at business professionals and organisations.

This policy does not cover personal data that our customers upload into the Waivern compliance platform. When you use our platform to process data that belongs to your own users or employees, you are the controller of that data and we act as your processor. That relationship is governed by the Data Processing Agreement between us.

5. What personal data we collect and why

The table below sets out each purpose for which we process personal data as controller, the categories of data involved, the lawful basis we rely on under Article 6 UK GDPR (and, where relevant, EU GDPR), and how long we keep the data.

PurposeCategories of personal dataLawful basisRetention
Managing your customer account and delivering our servicesName, email address, billing address, phone numberPerformance of a contract with you - Art. 6(1)(b) UK GDPR / EU GDPR6 years after account closure (UK Limitation Act 1980 contract-claim window)
Processing paymentsBilling address, payment card details (held by our payment processor - we do not store card data ourselves)Performance of a contract with you - Art. 6(1)(b) UK GDPR / EU GDPR6 years after account closure
Electronic direct marketing to existing customers (newsletters, product updates, and offers relating to our own similar services)Name, email address, engagement historyLegitimate interests - Art. 6(1)(f) UK GDPR / EU GDPR. Our interest is maintaining a commercial relationship by keeping existing customers informed of relevant updates and services. We rely on the soft opt-in under PECR Regulation 22 (existing-customer rule). A Legitimate Interests Assessment is on file.24 months from last engagement (last open, click, or visit), then deleted or re-confirmed
Electronic direct marketing and advertising to prospects (people who have not yet purchased from us)Name, email address, employer, engagement historyConsent - Art. 6(1)(a) UK GDPR / EU GDPR. You must opt in before we contact you for marketing. You may withdraw consent at any time (see Section 10).24 months from last engagement, or until consent is withdrawn
Website analytics - understanding how visitors use our website and improving our servicesIP address, device identifiers, language settings, screen resolution, device type, operating system, session start and end times, click-event behaviour, non-precise location (city/country)Consent - Art. 6(1)(a) UK GDPR / EU GDPR. We use Google Analytics, which must be loaded only after you have given consent via our consent management platform (Cookiebot). You may withdraw consent at any time (see Section 10 and our Cookie Policy).14 months from the date of the event
Advertising performance and conversion trackingIP address, device identifiers, language settings, screen resolution, device type, operating system, session start and end times, click-event behaviour, non-precise location (city/country), conversion behaviour, user engagement dataConsent - Art. 6(1)(a) UK GDPR / EU GDPR. Advertising and conversion-tracking cookies (Google Ads, DoubleClick, LinkedIn Insight Tag) must be loaded only after you have given consent. You may withdraw consent at any time (see Section 10 and our Cookie Policy).24 months from collection, or until consent is withdrawn
Security logging and fraud preventionIP addresses, access logs, authentication eventsLegitimate interests - Art. 6(1)(f) UK GDPR / EU GDPR. Our interest is protecting our systems, our customers, and the integrity of our services against unauthorised access and fraud. A Legitimate Interests Assessment is on file.12 months from the date of the event, then deleted by log rotation
Responding to your direct enquiries (via contact form or email)Name, email address, message content, and any other information you choose to includeLegitimate interests - Art. 6(1)(f) UK GDPR / EU GDPR. Our interest is responding to people who contact us. A Legitimate Interests Assessment is on file.24 months from last contact with you
Processing job applicationsName, contact details, CV/résumé, work history, qualifications, referencesLegitimate interests - Art. 6(1)(f) UK GDPR / EU GDPR, for the purpose of evaluating and selecting candidates. A Legitimate Interests Assessment is on file.If unsuccessful: 12 months from decision date (Equality Act 2010 claim window), then deleted. If successful: merged into your employee record.
Employee payroll and HR administrationName, contact details, national insurance number, payroll data, employment contract details, performance recordsLegal obligation - Art. 6(1)(c) UK GDPR / EU GDPR (HMRC reporting and employment law obligations)HR file: 6 years after end of employment. Payroll records: 7 years after end of the relevant tax year.
Maintaining cookie consent recordsConsent timestamp, preferences selected, anonymised identifierLegal obligation - Art. 6(1)(c) UK GDPR / PECR (demonstrating that consent was validly obtained)24 months from the date consent was collected, then auto-purged by our consent platform
Handling data subject access and other rights requestsName, contact details, request correspondence, verification informationLegal obligation - Art. 6(1)(c) UK GDPR / EU GDPR (Art. 12-22 compliance)3 years from response date
Recording and managing personal data breach incidentsDetails of affected individuals (categories and approximate numbers), incident correspondence, regulatory notificationsLegal obligation - Art. 6(1)(c) UK GDPR / EU GDPR (Art. 33-34 breach notification and demonstrating compliance to regulators)5 years from incident close date

6. Special-category personal data

Our compliance platform and general business operations do not involve the routine processing of special-category personal data (as defined in Art. 9 UK GDPR / EU GDPR) about our customers, website visitors, or job applicants.

Where we act as your Data Protection Officer and you bring individual cases, complaints, or data subject access matters to our attention, we may occasionally encounter special-category data in that context. We do not retain such data beyond the resolution of the matter for which it was shared with us, and we do not use it for any other purpose.

7. Cookies and similar technologies

We use cookies and similar technologies on our website. Full details - including the specific cookies in use, their purposes, and your consent choices - are set out in our Cookie Policy.

In summary, our cookies fall into the following categories under the post-DUAA PECR framework:

CategoryCookies observedConsent required?Basis
Strictly necessaryCookieConsent (Cookiebot - records your consent preference)NoEssential for recording your consent choices and for the website to function correctly. Exempt from prior consent under PECR.
AnalyticsGoogle Analytics (_ga and related cookies, property G-SNNESL7MGP)Yes - prior opt-in consent requiredGoogle Analytics is connected to Google’s advertising infrastructure and cannot be treated as a single-purpose analytics cookie exempt from consent under PECR. These cookies must be loaded only after you have given consent via our consent management platform (Cookiebot).
Advertising and conversion trackingGoogle Ads conversion linker (_gcl_au), Google DoubleClick (test_cookie on doubleclick.net), LinkedIn Insight TagYes - prior opt-in consent requiredUsed for advertising performance, retargeting, and LinkedIn audience matching. Consent is required under PECR. These must be loaded only after you have given consent.

You can change your cookie preferences at any time by using the cookie settings link on our website, or by clearing your browser cookies and revisiting us.

8. Who we share your data with

We share personal data only where necessary and with appropriate safeguards in place. The categories of recipients are:

  • Hosting and infrastructure providers (processors): Vercel (primary hosting) and Railway Corporation (backend infrastructure), both located in the USA, who host our website and application.
  • Payment processor (processor): Stripe, located in the USA, who processes card payments on our behalf.
  • AI / language-model providers (processors): Anthropic (primary) and OpenAI (fallback), both located in the USA, whose large language models underpin our compliance tooling.
  • Transactional email provider (processor): Postmark (ActiveCampaign), located in the USA, who delivers system emails and notifications.
  • Email marketing platform (processor): Mailchimp (Intuit), located in the USA, who manages our marketing and newsletter communications.
  • Analytics provider (processor): Google (Google Analytics), located in the USA, who provides website analytics where you have consented.
  • Advertising platforms (processors): Google (Google Ads, DoubleClick) and LinkedIn, located in the USA, who process advertising and conversion-tracking data where you have consented.
  • Marketing platform (processor): Gojiberry AI (Superfruits SAS), located in France, who provides LinkedIn and email marketing services.
  • Authentication and productivity providers (processors): Google (Google OAuth) and Microsoft (Microsoft Entra ID / Microsoft 365), located in the USA, who manage sign-in, identity, and staff productivity.
  • Team communications (processor): Salesforce / Slack, located in the USA, who provide our internal messaging and collaboration platform.
  • Collaboration and design tools (processors): Canva and Miro, who provide design and whiteboarding tools used by our team.
  • Source code and engineering tools (processor): GitHub, located in the USA, who hosts our source code.
  • Regulators and law enforcement: We may share data with the ICO, the Norwegian Data Protection Authority (Datatilsynet), or other public authorities where we are legally required to do so.
  • Professional advisers: Lawyers, accountants, and insurers, under duties of confidentiality, where necessary for legitimate business purposes.

We do not sell your personal data to third parties.

9. International transfers of personal data

Several of our service providers are based outside the UK and the European Economic Area (EEA). Where we transfer personal data internationally, we put in place appropriate safeguards as set out below.

Transfer routeRecipients / examplesSafeguard / mechanism
UK → EU/EEA (including France)Gojiberry AI (Superfruits SAS)UK adequacy regulations - the EU/EEA benefits from a UK adequacy finding; no additional safeguard is required for UK-to-EEA transfers.
UK → USAVercel (UK IDTA); Anthropic, GitHub, LinkedIn, Mailchimp, Meta, Microsoft, Miro, OpenAI, Railway Corporation, Salesforce/Slack (UK Addendum to EU SCCs); Postmark / ActiveCampaign (UK Extension to EU-US Data Privacy Framework)International Data Transfer Agreement (IDTA) or Standard Contractual Clauses with the UK Addendum to EU SCCs, or - where applicable - the UK Extension to the EU-US Data Privacy Framework, incorporated into data processing agreements with each provider. Copies of the relevant safeguards are available on request.
UK → USA (transfer mechanism under confirmation)Stripe, WhatsApp, Google AnalyticsWe are in the process of confirming the specific transfer mechanism for these providers. We will update this policy once confirmed. In the interim, we are satisfied that appropriate contractual arrangements are in place with each provider.
EU → USA (where EU GDPR applies to our EU-based users)Same US providers as aboveEU Standard Contractual Clauses (EU SCCs 2021) incorporated into data processing agreements. Copies available on request.

To request a copy of the transfer safeguards in place for any specific recipient, please contact us at info@waivern.com.

10. Your rights

Under UK GDPR and EU GDPR, you have the following rights in relation to your personal data. To exercise any of these rights, please contact us at info@waivern.com or write to us at our registered address.

  • Right of access (subject access request): You can ask us for a copy of the personal data we hold about you. We will respond within one calendar month of receiving your request. Where your request is broad or relates to a large volume of data, we may contact you to ask for clarification before we begin our search - this pauses the one-month clock until you respond (Art. 12A UK GDPR, as amended by the DUAA). We may also need to verify your identity before we can respond; we will let you know promptly if so. Our search will be reasonable and proportionate to the scope of your request.
  • Right to rectification: You can ask us to correct inaccurate data or complete incomplete data we hold about you.
  • Right to erasure (right to be forgotten): You can ask us to delete your personal data where there is no compelling reason for us to continue processing it. Where data is held in backup copies, those copies will be deleted when the relevant backup cycle expires rather than immediately; we record this at the time of your request.
  • Right to restriction of processing: You can ask us to restrict how we use your data in certain circumstances - for example, while you contest its accuracy.
  • Right to data portability: Where we process your data on the basis of your consent or to perform a contract, you can ask us to provide it to you in a structured, commonly used, machine-readable format, or to transfer it directly to another organisation where technically feasible.
  • Right to object: You can object at any time to our processing of your data where we rely on legitimate interests as our lawful basis. We will stop processing unless we can show compelling legitimate grounds that override your interests, rights, and freedoms. You have an unconditional right to object to your data being used for direct marketing - if you object, we will stop immediately.
  • Right to withdraw consent: Where we rely on your consent to process your data (for example, for marketing communications or analytics cookies), you can withdraw that consent at any time. Withdrawal does not affect the lawfulness of processing carried out before withdrawal. To opt out of marketing emails, use the unsubscribe link in any email we send. To change cookie preferences, use the cookie settings link on our website.
  • Rights relating to automated decision-making: We do not make solely automated decisions that produce a legal or similarly significant effect on you. If this changes, we will update this policy and give you the appropriate rights and safeguards under Arts. 22A-22D UK GDPR (as amended by the DUAA).

We will not charge a fee for handling your request unless it is manifestly unfounded or excessive. We aim to respond within one month, though we may extend this by a further two months for complex or numerous requests, in which case we will notify you promptly.

11. How to raise a concern or make a complaint

Step 1 - Contact us first

If you are unhappy with how we have handled your personal data, please contact us first so we have the opportunity to put things right:

  • Email: info@waivern.com
  • Post: Waivern Limited, 14 Eastbury Road, Petts Wood, Orpington, England, BR5 1JW

We will acknowledge your complaint within 30 days and will respond without undue delay, in accordance with our obligations under the DPA 2018 as amended by the DUAA (s.164A, in force from 19 June 2026). We will also provide an electronic route for submitting your complaint - you may use the email address above.

Step 2 - Escalate to the ICO

If you remain dissatisfied after contacting us, or if you prefer to contact the regulator directly, you have the right to lodge a complaint with the Information Commissioner’s Office (ICO):

If you are based in Norway or another EU member state, you also have the right to lodge a complaint with your local supervisory authority. In Norway, this is the Norwegian Data Protection Authority (Datatilsynet): https://www.datatilsynet.no/en/.

12. How we protect your data

We take appropriate technical and organisational measures to protect your personal data against unauthorised access, loss, or disclosure. These include:

  • encryption in transit for all data transmitted to and from our platform;
  • access controls using Microsoft Entra ID and Google OAuth, with role-based access management;
  • read-only access to client environments for our compliance tooling, working only against development or staging data rather than production;
  • immediate revocation of system access on employee departure, with device wiping on the same day; and
  • open-source code that is publicly auditable and subject to automated security checks including static analysis and pre-commit controls.

13. Changes to this policy

We review this policy regularly. When we make significant changes, we will notify you by email (if you are a customer or have subscribed to our communications) and/or by displaying a prominent notice on our website. The effective date at the top of this policy will always reflect when it was last updated.

We encourage you to review this policy periodically.

14. Version and review

  • Effective date: 17 July 2026
  • Last reviewed: 28 July 2026
  • Next review due: 11 June 2027
  • Policy owner: Vincent Nunan, CEO and Data Protection Officer