Privacy Policy

Last updated: 5 August 2026

1. Who We Are

Wava is a SaaS platform operated by Filova LTD, a company registered in England and Wales (Companies House No: 17263134), with registered office at 71-75 Shelton Street, Covent Garden, London WC2H 9JQ, United Kingdom. For privacy enquiries: privacy@wavaapp.com.

Controller / Processor distinction: Wava acts as a data controller in respect of Tenants (businesses using the platform), and as a data processoron behalf of Tenants in respect of their end-users' personal data. Tenants are the data controllers for their end-users' data.

2. Where Wava is offered

Wava is currently offered to businesses in Türkiye and the United Kingdom only. We do not actively offer the service to businesses in the European Union or the United States, and we therefore do not appoint a representative under GDPR Article 27 — that obligation arises from directing services at people in the EU, which we do not do. Should we begin offering Wava in the EU, a representative will be appointed before we do so and this policy will be updated.

This is separate from where our suppliers are located: some sub-processors are US-based, and those transfers are disclosed with their safeguards in the Sub-processors page and in section 7 below. If you are in the EU and have a question about your data, you can still contact us at privacy@wavaapp.com.

3. Data We Collect

CategoryExamples
Account dataName, email address, company name
Communication dataWhatsApp phone number, message content
Technical dataHashed IP address, session token
Billing dataCompany name, tax ID, billing address

4. Legal Basis for Processing

PurposeLegal basis (GDPR Art. 6)
Providing the WhatsApp AI serviceArt. 6(1)(b) — contract performance
Security, fraud prevention, abuse detectionArt. 6(1)(f) — legitimate interest
Marketing communicationsArt. 6(1)(a) — consent (freely given)
Billing and tax record-keepingArt. 6(1)(c) — legal obligation

5. Automated Decision-Making (GDPR Art. 22)

Wava uses AI (Anthropic Claude) to generate WhatsApp responses and to qualify leads on behalf of Tenants. These outputs may constitute automated decisions affecting end-users. You have the right to request human review of any AI-generated decision that significantly affects you. To exercise this right, contact privacy@wavaapp.com.

6. Sub-processors

We share personal data with a limited set of external providers to operate the Service. They fall into two groups: sub-processors, which access end-user data we process on our customers' behalf, and providers we engage for our own operations (billing, account notifications, bot protection), where Filova is the controller. Both groups, with the data categories processed and their locations, are listed on our Sub-processors page. We do not sell or share personal data for advertising purposes.

7. International Data Transfers

Some of our sub-processors are located outside the EEA/UK. We use the following mechanisms to safeguard transfers:

  • EU/UK to US (Anthropic): Standard Contractual Clauses (SCCs, 2021 EU SCC Decision), the UK Addendum to the EU SCCs (approved by ICO, March 2022), and/or EU-US Data Privacy Framework (DPF) certification where applicable.
  • WhatsApp (Meta): our contract is with WhatsApp Ireland Limited, an EU entity; its onward transfer to WhatsApp LLC (US) relies on the EU-US Data Privacy Framework. See Sub-processors for details.
  • Database (Supabase):data is hosted in the EU (eu-central-1, Frankfurt, Germany), but our contract is with Supabase Pte. Ltd. (Singapore); such transfers fall under Supabase's own Standard Contractual Clauses framework.
  • Other US-based providers: hosting (Vercel), error monitoring (Sentry), idempotency and rate limiting (Upstash — data itself hosted in the EU), transactional email (Resend) and bot protection (Cloudflare) are covered by the same mechanism as above: Standard Contractual Clauses with the UK Addendum, and/or EU-US Data Privacy Framework certification where the provider is certified. Payment processing (Paddle) is carried out in the United Kingdom, which benefits from an EU adequacy decision. Each provider's location and role is listed on the Sub-processors page.

8. Retention Periods

Data categoryRetentionBasis
Message content90 days (Turkey) / 365 days (other regions)Data minimisation
Account / profileActive + 90 daysContract performance
Billing records7 yearsUK tax law (HMRC)
IP address / access logs2 yearsLegitimate interest
Phone / emailWhile account activeContract performance

9. Your Rights

To request access to or deletion of your personal data, email privacy@wavaapp.com with your request. Response times depend on your region — see below.

This applies wherever you are: if you reached us through a business's WhatsApp line, that business is the controller for the conversation and Wava acts only as its processor. Send your request to us either way — we pass it on and help resolve it.

Türkiye — KVKK

Under KVKK Art. 11 you have the right to: learn whether your data is being processed, request information about it, request correction of incomplete or inaccurate data, request erasure once the grounds for processing no longer apply, and claim compensation for damages. Submit requests to privacy@wavaapp.com. We respond within 30 days (KVKK Art. 13). If unresolved, you may file a complaint with the Turkish Data Protection Authority (KVKK Kurumu).

EU / EEA — GDPR

Wava is not offered to businesses in the EU (section 2). If you are in the EU, your data most likely reached us through a customer's WhatsApp line — in which case that business is the controller and Wava acts only as its processor. Send us your request and we will pass it on and help resolve it.

To the extent GDPR applies, under Articles 15–21 you have the right to: access, rectification, erasure ("right to be forgotten"), restriction of processing, data portability, and to object to processing. You may also withdraw consent at any time without affecting prior lawful processing. To submit a request, contact privacy@wavaapp.com. We respond within one month of receipt (extendable by a further two months for complex or numerous requests, with notice). You may also lodge a complaint with the supervisory authority in your EU member state.

UK — UK GDPR

You have the same rights as under EU GDPR. Filova LTD is subject to UK GDPR and the Data Protection Act 2018. You may lodge a complaint with the Information Commissioner's Office (ICO) at ico.org.uk.

10. Cookies

We use three types of cookies/technologies: (1) the Supabase authentication session cookie, strictly necessary for login — Path=/, SameSite=Lax, retained in your browser for up to about 400 days, and never sent over an unencrypted connection because the site is served exclusively over HTTPS (HSTS preloaded); (2) wava_currency, a preference cookie that reflects your currency choice — written when you click the currency switcher in the UI — and never shared with third parties. Your language choice is not stored in a cookie; it is carried in the address itself (/tr, /en). Both are exempt from consent under the "appearance" exception added to PECR by the UK's Data (Use and Access) Act 2025 (in force since 5 February 2026) and under equivalent user-initiated preference-cookie treatment elsewhere. We do not use advertising, marketing, or analytics cookies. Our error-monitoring provider, Sentry, processes limited technical data (errors and performance) in the browser and does not set a persistent tracking cookie or use session replay — see the Sub-processors page for details. No cookie consent banner is required under GDPR / ePrivacy / PECR.

11. Contact

Filova LTD
Companies House No: 17263134
71-75 Shelton Street, Covent Garden
London WC2H 9JQ, United Kingdom
Phone: +44 7441 427697
(Registered in England and Wales)

Privacy requests: privacy@wavaapp.com

We aim to respond to all requests within 30 days (KVKK), or within one month under GDPR / UK GDPR. For identity verification we ask only for what is necessary and proportionate to the request — usually the WhatsApp number you messaged us from, or the email address on your account. We request an identity document only where there is reasonable doubt about who you are; it is used for verification only and deleted as soon as verification is complete.

12. Changes to This Policy

We will post any changes to this page and update the "last updated" date. For material changes (e.g. new data categories, new sub-processors), we will notify Tenant account holders by email.