Our privacy policy & GDPR requirements are mentioned below
1 Overview and legal bases for processing
1.1. This privacy policy explains what personal data we process, and how, why, and on what legal basis we do so, across our online services — including our websites, the platform, the online shop, and all associated functions and content (together, our "online offer" or "website"). It applies no matter which domain, system, platform, or device (desktop or mobile) you use to access the online offer.
1.2. Where we use terms such as "personal data" or "processing", we use them as they are defined in Art. 4 of the General Data Protection Regulation (GDPR).
1.3. Depending on how you use our online offer, the personal data we process may include: inventory data (such as customers' names and addresses); contact data (such as email address and telephone number); contract data (such as the services used, the names of the people we deal with, and payment information); usage data (such as the pages you visit and the products you show interest in); meta and communication data (such as device IDs, IP addresses, and location data); content data (such as anything you enter in a contact form); and, where relevant, applicant data (name, contact details, qualifications, and application documents).
1.4. The term "user" covers every category of data subject — our business partners, customers, prospective customers, and any other visitor to our online offer. All such terms are meant in a gender-neutral sense.
1.5. We only process personal data in line with the applicable data protection rules, and only where we have a legal basis to do so. That basis exists where processing is necessary to provide our contractual services (for example, to process an order) or to run our online services, where the law requires it, where you have given your consent, or where we have a legitimate interest — for example in analysing, optimising, securing, and economically operating our services, measuring reach, building profiles for advertising and marketing, collecting access data, and using third-party services (Art. 6(1)(f) GDPR).
1.6. For clarity, the legal bases we rely on are: consent under Art. 6(1)(a) and Art. 7 GDPR; performance of a contract and pre-contractual measures under Art. 6(1)(b) GDPR; compliance with our legal obligations under Art. 6(1)(c) GDPR; and our legitimate interests under Art. 6(1)(f) GDPR.
2 Security measures
2.1. We take appropriate organisational, contractual, and technical security measures, in line with current best practice, to comply with data protection law and to protect the data we process against accidental or deliberate manipulation, loss, destruction, or access by unauthorised persons.
2.2. These measures include encrypting the data transmitted between your browser and our servers.
3 Sharing data with third parties and external providers
3.1. We only share data with third parties within the limits of the law. We do so where it is necessary to fulfil a contract under Art. 6(1)(b) GDPR, or where we have a legitimate interest in the economic and effective operation of our business under Art. 6(1)(f) GDPR.
3.2. Where we use subcontractors (processors) to deliver our services, we put appropriate contractual, technical, and organisational safeguards in place to protect personal data as required by law.
3.3. Where we use content, tools, or other services from external providers whose registered office is in a third country, it should be assumed that data is transferred to the country in which that provider is based. "Third countries" are countries where the GDPR does not apply directly — in principle, countries outside the EU or the European Economic Area. Such transfers only take place where there is an adequate level of data protection, your consent, or another legal permission.
4 Performance of contractual services
4.1. We process inventory data (such as users' names, addresses, and contact details) and contract data (such as the services used, the people we deal with, and payment information) in order to meet our contractual obligations and provide our services, under Art. 6(1)(b) GDPR.
4.2. You may optionally create a user account to view your orders. During registration, we tell you which information is required. User accounts are not public and cannot be indexed by search engines. If you close your account, the associated data is deleted — unless we are required to keep it for commercial or tax reasons under Art. 6(1)(c) GDPR. Where a software licence applies, it must be terminated beforehand, and all components of any downloaded software must be irretrievably deleted.
4.3. When you register, re-register, or use our online services, we store your IP address and the time of the action. We do this on the basis of our legitimate interests, and to protect you against misuse and other unauthorised use. As a rule, this data is not passed on to third parties, unless it is needed to pursue our legal claims or we are legally obliged to do so under Art. 6(1)(c) GDPR.
4.4. We process usage data (such as the pages of our online offer you visit and the products you show interest in) and content data (such as entries in a contact form or your user profile) to build a profile that lets us show you relevant information — for example, products related to services you have used before.
5 Getting in touch
5.1. When you contact us (by contact form or email), we process the details you provide in order to handle and respond to your request, under Art. 6(1)(b) GDPR.
5.2. We may store your information in our Customer Relationship Management (CRM) system or a comparable request-management tool.
6 Comments and contributions
6.1. If you leave a comment or other contribution, we store your IP address for 7 days on the basis of our legitimate interests under Art. 6(1)(f) GDPR.
6.2. We do this for safety: if someone posts unlawful content in a comment or contribution (such as insults or prohibited political propaganda), we could be held responsible for it, and therefore have a legitimate interest in being able to identify the author.
7 Access data and log files
7.1. On the basis of our legitimate interests under Art. 6(1)(f) GDPR, we record data each time our server is accessed (so-called server log files). This access data includes the name of the page or file requested, the date and time of access, the volume of data transferred, a note of whether the request succeeded, the browser type and version, your operating system, the referrer URL (the page you visited previously), your IP address, and the requesting provider.
7.2. For security reasons — for example, to investigate misuse or fraud — log file data is kept for a maximum of seven days and then deleted. Data that needs to be retained as evidence is exempt from deletion until the relevant incident has been fully resolved.
8 Cookies and reach measurement
8.1. Cookies are pieces of information that our web server, or a third-party server, transfers to your browser and stores there for later retrieval. Cookies may be small files or other forms of information storage.
8.2. We use cookies, for example, to remember your login status or the contents of your shopping cart, so that our online offer is convenient to use.
8.3. Where we use cookies for pseudonymous reach measurement, we explain this within this privacy policy.
8.4. If you do not want cookies stored on your device, you can disable them in your browser settings, and delete any stored cookies there as well. Please note that blocking cookies may limit some functions of our online offer.
8.5. You can opt out of the use of cookies for reach measurement and advertising via the deactivation page of the Network Advertising Initiative (http://optout.networkadvertising.org/), and also via the US page (http://www.aboutads.info/choices) and the European page (http://www.youronlinechoices.com/uk/your-ad-choices/).
9 Google Analytics
9.1. On the basis of our legitimate interests (in analysing, optimising, and economically operating our online offer under Art. 6(1)(f) GDPR), we use Google Analytics, a web analytics service provided by Google Inc. ("Google"). Google uses cookies, and the information the cookie generates about how you use our online offer is generally transferred to, and stored on, a Google server in the USA.
9.2. Google is certified under the EU-U.S. Data Privacy Framework, which provides a safeguard for complying with European data protection law when data is transferred to the USA.
9.3. Google uses this information on our behalf to evaluate how our online offer is used, to compile reports on activity within it, and to provide us with further services connected to its use and to internet usage generally. Pseudonymous user profiles may be created from this data.
9.4. We use Google Analytics to show ads placed by Google and its partners only to users who have shown an interest in our online offer or who share certain characteristics (such as interests in particular topics or products, inferred from the pages they visit) that we pass to Google — a practice known as "remarketing" or "Google Analytics Audiences". Through remarketing audiences, we aim to show ads that match your likely interests and are not intrusive.
9.5. We only use Google Analytics with IP anonymisation enabled. This means Google truncates your IP address within the member states of the European Union or other parties to the Agreement on the European Economic Area. Only in exceptional cases is the full IP address transferred to a Google server in the USA and truncated there.
9.6. The IP address transmitted by your browser is not combined with other data held by Google. You can prevent cookies from being stored by adjusting your browser settings, and you can also prevent Google from collecting and processing the data generated by the cookie about your use of the online offer by downloading and installing the browser plug-in available at http://tools.google.com/dlpage/gaoptout?hl=en.
9.7. You can find more information about how Google uses data, along with the available settings and objection options, on Google's own pages: https://www.google.com/intl/de/policies/privacy/partners ("How Google uses data when you use our partners' sites or apps"), http://www.google.com/policies/technologies/ads ("How Google uses data for advertising"), and http://www.google.de/settings/ads ("Manage the information Google uses to show you ads").
10 Newsletter
10.1. In this section we explain what our newsletter contains, how sign-up and dispatch work, how we evaluate it statistically, and your right to object. By subscribing, you agree to receive the newsletter and to the procedures described here.
10.2. We only send newsletters, emails, and other electronic notifications containing promotional information ("newsletters") with the recipient's consent or where the law permits it. If the content of a newsletter is described specifically during sign-up, that description is decisive for your consent. Our newsletters also contain information about our products, offers, promotions, and our company.
10.3. Sign-up uses a "double opt-in" procedure: after registering, you receive an email asking you to confirm your subscription. This confirmation prevents anyone from signing up with someone else's email address. We log subscriptions so we can demonstrate that the sign-up process complied with the law; this includes storing the sign-up and confirmation times and your IP address.
10.4. To subscribe, you only need to provide your email address.
10.5. You can cancel the newsletter — and withdraw your consent to receiving it — at any time. Every newsletter contains an unsubscribe link. If you subscribed only to the newsletter and then cancel, we delete your personal data.
11 Integrating third-party services and content
11.1. On the basis of our legitimate interests (in analysing, optimising, and economically operating our online offer under Art. 6(1)(f) GDPR), we include content and services from third parties — such as videos or fonts ("content"). This always requires that the third-party provider is aware of your IP address, since without it they could not send the content to your browser; the IP address is therefore necessary to display this content. Third-party providers may also use "pixel tags" (invisible graphics, also called "web beacons"), which can be used for statistical or marketing purposes — for example, to analyse visitor traffic on this website. This pseudonymous information may also be stored in cookies on your device and may include technical details about your browser and operating system, referring websites, the time of your visit, and other information about how you use our online offer, and it may be linked with such information from other sources.
11.2. The following is an overview of the third-party providers we use and their content, together with links to their privacy policies, which contain further information and, in some cases, opt-out options:
Where our customers use third-party payment services (for example, Stripe), the terms and privacy notices of those providers apply, as available within their respective websites or transaction flows.
Live chat by "Tawk.to", provided by tawk.to inc. — Privacy policy: https://www.tawk.to/privacy-policy/ and GDPR information: https://www.tawk.to/data-protection/gdpr/
External fonts from Google Inc., https://www.google.com/fonts ("Google Fonts"). Google Fonts are loaded via a server request to Google (usually in the USA). Privacy policy: https://www.google.com/policies/privacy/, opt-out: https://www.google.com/settings/ads/.
Maps from the "Google Maps" service provided by Google Inc., 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA. Privacy policy: https://www.google.com/policies/privacy/, opt-out: https://www.google.com/settings/ads/.
External code from the JavaScript framework "jQuery", provided by the jQuery Foundation, https://jquery.org.
12 Your rights
12.1. You have the right, on request and free of charge, to obtain information about the personal data we hold about you.
12.2. You also have the right to have inaccurate data corrected, to have the processing of your data restricted, to have your personal data deleted where applicable, to exercise your right to data portability, and — where you consider processing to be unlawful — to lodge a complaint with the competent supervisory authority.
12.3. Where processing is based on your consent, you may withdraw that consent at any time, in principle with effect for the future.
13 Deletion of data
13.1. We delete the data we hold as soon as it is no longer needed for its intended purpose, unless a legal retention obligation prevents deletion. Where data is not deleted because it is still needed for other lawful purposes, we restrict its processing instead — meaning the data is blocked and not used for any other purpose. This applies, for example, to data that must be retained for commercial or tax reasons.
13.2. In line with statutory requirements, records are retained for 6 years under § 257(1) of the German Commercial Code (HGB) — covering trading books, inventories, opening balance sheets, annual financial statements, business letters, and accounting documents — and for 10 years under § 147(1) of the German Fiscal Code (AO) — covering books, records, management reports, accounting documents, commercial and business letters, and documents relevant to taxation.
13.3. You can request deletion directly from your account at client.youwaves.cloud, while logged in to your client account. We then confirm the deletion by email within the statutory deadlines. Where a software licence applies, this also irreversibly terminates it; before making the request, all components of any downloaded software must be irretrievably deleted, and access cannot be granted afterwards.
13.4. Even after a deletion request, data is only fully deleted where we are not required to keep it for commercial or tax reasons under Art. 6(1)(c) GDPR.
14 Right to object
You may object to the future processing of your personal data at any time, as provided for by law. In particular, you may object to processing for direct marketing purposes.
15 Changes to this privacy policy
15.1. We may update this privacy policy to reflect changes in the law or changes to our services or data processing. This applies only to statements about data processing. Where your consent is required, or where parts of this policy form part of our contractual relationship with you, we will only make changes with your consent.
15.2. Please review this privacy policy regularly to stay informed of its contents.
16 How to request deletion of your data
16.1. You can ask us to delete the personal data we hold about you at any time. The quickest way is to sign in to your account at client.youwaves.cloud and submit a deletion request there; we then confirm the deletion by email within the statutory deadlines (see section 13). Alternatively, email us at contact@youwaves.cloud from the address associated with your account and we will process your request.
16.2. If you signed in or registered using a social login such as Facebook, Google, or Apple, you can also remove our app's access from that provider at any time — for example, in Facebook under Settings → Apps and Websites. Revoking access stops future data sharing; to have the data we already hold deleted, please also send us a deletion request as described in section 16.1.
16.3. Once we receive your request, we delete your personal data unless we are legally required to retain part of it for commercial or tax reasons under Art. 6(1)(c) GDPR (see section 13). We will tell you if any such retention applies.
For more details, email us at contact@youwaves.cloud