WayConnect Portals
Workspace LoginHRMS Login

European data protection

GDPR Policy

This Policy explains how WayConnect approaches the EU General Data Protection Regulation and UK GDPR when personal data is processed through its websites, business platform, integrations, AI assistance, billing services, and workforce tools.

Last updated: 26 August 2026

1. Purpose and relationship to our Privacy Policy

This GDPR Policy provides additional information for individuals and organisations whose personal data is subject to Regulation (EU) 2016/679 (the “EU GDPR”) or the GDPR as incorporated into United Kingdom law (the “UK GDPR”). References to the “GDPR” mean the applicable regime. It should be read with the WayConnect Privacy Policy, Terms of Service, any Order Form, and any Data Processing Addendum (“DPA”).

The Privacy Policy describes WayConnect's broader processing practices. This Policy focuses on GDPR roles, principles, legal bases, individual rights, processor commitments, international transfers, accountability, and the responsibilities of Customers that use WayConnect to process personal data.

This public Policy does not itself certify that every Customer configuration or use case complies with the GDPR. Compliance depends on the facts, purposes, jurisdictions, data, integrations, settings, and instructions involved. A signed DPA or Order Form controls where it expressly provides different or additional data-protection terms.

2. Scope and territorial application

This Policy applies to personal data processed in connection with WayConnect where the EU GDPR or UK GDPR applies because of an establishment, an offering of goods or services to people in the EEA or United Kingdom, monitoring of their behaviour, or another applicable territorial rule.

The GDPR protects information relating to an identified or identifiable natural person. It does not generally regulate information relating only to a company or other legal entity, although business records may contain personal data about employees, directors, customers, suppliers, or other individuals.

A Customer must determine whether the GDPR applies to its activities before using WayConnect for contacts, marketing, messaging, employee administration, location-aware attendance, recruitment, payroll, AI assistance, or other processing. The Customer is also responsible for any national rules that supplement the GDPR, including employment, electronic-marketing, communications, monitoring, and special-category-data requirements.

3. Key GDPR terms

  • “Personal data” means information relating to an identified or identifiable natural person.
  • “Processing” includes collecting, recording, organising, structuring, storing, changing, retrieving, consulting, using, disclosing, transmitting, combining, restricting, erasing, or destroying personal data.
  • A “Controller” determines the purposes and essential means of processing; a “Processor” processes personal data for a Controller on documented instructions.
  • A “Data Subject” is the individual to whom personal data relates. In WayConnect, this may include an account user, message recipient, lead, customer contact, employee, candidate, visitor, supplier representative, or website visitor.
  • “Customer Content” means contacts, leads, messages, files, employee and candidate records, workflow data, prompts, and other information submitted to, received through, or generated in a Customer workspace.
  • A “Subprocessor” is another processor engaged by WayConnect to process Customer Content for the Customer.
  • “Special Category Data” includes personal data revealing racial or ethnic origin, political opinions, religious or philosophical beliefs, trade-union membership, genetic or biometric identifiers used for unique identification, health data, and data concerning a person's sex life or sexual orientation.

4. Controller and processor roles

WayConnect as Controller

WayConnect generally acts as Controller for account creation, authentication, website operation, direct billing relationships, product administration, security, fraud prevention, support, service communications, and information about how its own Services are used. For these activities, WayConnect determines the relevant purposes and means of processing.

WayConnect as Processor

WayConnect generally acts as Processor when it hosts or handles Customer Content on behalf of a Customer, including contacts, leads, messages, campaign audiences, chatbot sessions, employee data, attendance entries, payroll inputs, expense records, candidates, visitors, uploaded documents, and Customer-selected AI context.

For this data, the Customer normally acts as Controller and determines why the data is processed, which records are submitted, who receives communications, which users have access, which integrations are enabled, and when information should be exported, archived, or deleted.

Independent and joint Controllers

Meta, WhatsApp, Google, Microsoft, Razorpay, an AI provider, and other Connected Services may act as independent Controllers for some processing under their own notices and terms. A joint-controller arrangement applies only where the parties actually determine purposes and means together and document the allocation required by law; no joint controllership should be assumed merely because systems exchange data.

5. GDPR processing principles

WayConnect applies the GDPR principles to processing for which it is responsible and provides platform capabilities that help Customers apply them to Customer Content. Each Controller remains accountable for demonstrating compliance in its own context.

  • Lawfulness, fairness, and transparency: identify a lawful basis and explain processing in a clear, accessible notice.
  • Purpose limitation: collect data for specified, explicit, and legitimate purposes and assess compatibility before reusing it.
  • Data minimisation: process personal data that is adequate, relevant, and limited to what is necessary.
  • Accuracy: take reasonable steps to keep relevant personal data accurate and correct or erase inaccurate records.
  • Storage limitation: retain identifiable data only for as long as the applicable purpose, instruction, or legal requirement justifies it.
  • Integrity and confidentiality: use appropriate technical and organisational measures against unauthorised or unlawful processing and accidental loss, destruction, or damage.
  • Accountability: document decisions, responsibilities, safeguards, contracts, requests, incidents, and risk assessments where required.

6. Data Subjects and categories of personal data

The categories depend on the Customer's instructions, selected modules, and enabled integrations. The detailed Privacy Policy describes each category and source. Under the GDPR, WayConnect processing can concern account users, administrators, contacts, leads, message recipients, employees, family or emergency contacts, candidates, visitors, suppliers, and website users.

  • Identity, profile, contact, organisation, role, permission, authentication, session, device, usage, diagnostic, and security information.
  • Customer relationship data, lead sources, consent and opt-out status, tags, notes, assignments, activity history, message content, media, templates, campaigns, delivery events, and chatbot sessions.
  • Employee, attendance, shift, leave, location, device, salary, payroll, tax, expense, recruitment, visitor, asset, emergency-contact, and document information where a Customer uses workforce features.
  • Billing profiles, tax identifiers, invoices, subscription and mandate status, payment references, wallet balances, top-ups, usage debits, reversals, and refunds. Full payment credentials are intended to remain with the payment provider.
  • Integration identifiers, OAuth grants, API and webhook configuration, file metadata, event payloads, AI prompts, selected context, generated output, and associated usage records.

7. Purposes and lawful bases

A Controller must identify and document an Article 6 lawful basis before processing personal data. The appropriate basis depends on the specific relationship and purpose; a convenient basis cannot be selected after processing has already begun merely to justify it.

Contract and pre-contract steps

WayConnect may process account, requested-service, support, and direct billing data where necessary to enter into or perform a contract with the individual. A Customer should not rely on contract for processing that is useful but not objectively necessary to perform its contract with the Data Subject.

Legal obligations

WayConnect or a Customer may process data where EU, Member State, or UK law requires it, including applicable tax, accounting, employment, regulatory, and lawful-request obligations. The Controller must identify the relevant legal requirement and avoid retaining unrelated data under a general claim of legal necessity.

Legitimate interests

WayConnect may rely on legitimate interests for proportionate service security, fraud prevention, reliability, troubleshooting, business administration, and improvement where those interests are not overridden by the Data Subject's rights and freedoms. The responsible Controller should document the purpose, necessity, balancing assessment, safeguards, and right to object.

Consent

Where consent is relied upon, it must be freely given, specific, informed, unambiguous, recorded, and as easy to withdraw as to give. Consent is not valid where there is an inappropriate imbalance or access to a service is made conditional on unnecessary processing. Withdrawing consent does not make earlier lawful processing unlawful.

Other lawful bases

Vital interests and public-task grounds apply only in the limited circumstances defined by law. WayConnect does not ordinarily rely on these grounds for routine commercial Services. A public authority or other eligible Customer must make and document its own determination.

8. Special Category and criminal-offence data

Workforce, recruitment, health, emergency, background-check, and uploaded-document features can contain Special Category Data or information relating to criminal convictions and offences. Article 6 alone is not sufficient for Special Category Data: the Controller must also identify a valid Article 9 condition and any condition or safeguard required by Member State or UK law. Article 10 data must be processed only under official authority or where authorised by applicable law with appropriate safeguards.

Customers must avoid collecting sensitive fields by default, limit them to a defined lawful need, provide specific notices, apply restrictive permissions, establish a deletion schedule, and evaluate whether a DPIA, policy document, worker consultation, or other safeguard is required. WayConnect does not decide whether a Customer's employment, health, background-check, or monitoring purpose is lawful.

9. Customer responsibilities as Controller

  • Provide Articles 13 or 14 notices to Data Subjects at the required time and identify the Customer, purposes, lawful bases, recipients, transfers, retention, rights, and complaint route.
  • Obtain and preserve valid marketing or messaging consent where required; maintain suppression records; and honour objections, opt-outs, and withdrawals without undue delay.
  • Configure roles using least privilege, review workspace users, secure administrator accounts, and restrict sensitive workforce, payroll, recruitment, location, and document records.
  • Give WayConnect lawful, documented instructions; submit only necessary data; keep it accurate; and avoid using free-text fields, files, or AI prompts for unrelated secrets or excessive sensitive information.
  • Assess Connected Services before enabling them and ensure that each disclosure, international transfer, export, API, webhook, or automation has a lawful basis and appropriate safeguards.
  • Respond to Data Subject requests, perform DPIAs where required, maintain records of processing, manage incidents, and consult a supervisory authority where high residual risk cannot be reduced as required by law.

10. WayConnect commitments as Processor

Where the GDPR applies to Customer Content processed by WayConnect as Processor, the DPA, Order Form, product configuration, and Customer's authorised use provide the documented instructions. A Customer should request and execute the applicable DPA before submitting regulated personal data if Article 28 terms are not already incorporated into its agreement.

  • Process personal data only on documented Customer instructions, including for transfers, unless applicable law requires other processing; where legally permitted, inform the Customer of that requirement.
  • Ensure personnel authorised to process personal data are subject to appropriate confidentiality obligations and access restrictions.
  • Apply appropriate technical and organisational security measures and assist the Customer with security, Data Subject requests, DPIAs, prior consultation, and breach obligations as required by the DPA and GDPR.
  • Engage Subprocessors under written data-protection obligations and the authorisation mechanism stated in the DPA.
  • At the end of the Services, return or delete Customer personal data as provided by the DPA, Customer controls, backup cycles, and laws requiring continued retention.
  • Make information reasonably necessary to demonstrate Article 28 compliance available and support audits in the manner and subject to the safeguards defined by the DPA.

11. Transparency and data obtained indirectly

WayConnect provides privacy information for data it controls through its Privacy Policy, this GDPR Policy, contextual notices, and relevant account or billing interfaces. Customers must provide their own notice for Customer Content; linking only to WayConnect's Policy is not a substitute for identifying the Customer's purposes and practices.

Where personal data is obtained from an integration, lead source, employer, Customer, or another person rather than directly from the Data Subject, the Controller must provide the information required by Article 14 within the applicable period—generally within one month, at first communication, or before first disclosure—unless a lawful exception applies. The notice should identify the data source, including whether it was publicly accessible, where required.

12. Data protection by design and by default

WayConnect designs platform controls to support workspace separation, scoped permissions, restricted administrator functions, protected credentials, auditability, and configurable workflows. Customers must use those controls appropriately and choose privacy-protective defaults for their particular purpose.

  • Collect the minimum fields and audience data necessary for the stated purpose.
  • Limit default visibility, administrator access, exports, integrations, and public or shared links.
  • Separate brands, departments, or regulated workflows when broader access is not justified.
  • Test automation with non-production or minimised data where practicable and review workflow consequences before activation.
  • Define archive and deletion rules before collecting employee, candidate, message, location, and uploaded-document data.
  • Use pseudonymised or anonymised data where the purpose can reasonably be achieved without directly identifiable information.

13. AI assistance, profiling, and automated decisions

When an Authorised User requests an AI-assisted feature, WayConnect may provide the configured AI service with the prompt, selected workspace context, recent conversation content, or configured public knowledge extract needed to generate the requested result. The Customer determines whether and how Customer Content is submitted and must provide any required notice and lawful basis.

WayConnect's current AI features are designed to assist users with drafts, classification, qualification, insights, or workflow suggestions and are not intended to make a solely automated decision that produces legal or similarly significant effects on a Data Subject. Authorised users must review output and remain responsible for decisions and communications.

Customers must not configure WayConnect to make solely automated high-impact decisions about employment, credit, insurance, housing, health, education, legal rights, or comparable opportunities unless the processing is lawful under Article 22, required safeguards are implemented, meaningful information is provided, and applicable rights to human intervention and contest are available.

14. Recipients, Connected Services, and Subprocessors

Personal data may be disclosed to Customer-authorised users and recipients and to infrastructure, storage, database, email, notification, security, support, payment, messaging, integration, and AI providers that help deliver the Services. The Privacy Policy describes the main recipient categories and Connected Services reflected in the platform.

Where WayConnect acts as Processor, Subprocessors are engaged under contracts requiring appropriate data-protection and security obligations. The applicable DPA may provide the Subprocessor-list and notice or objection mechanism. Customers may request current relevant Subprocessor information at the contact address below before enabling a feature or submitting affected data.

A Connected Service may be a separate Controller for its own account, platform-security, billing, policy-enforcement, or product-improvement processing. Customers must review that provider's notice and permissions and should not enable a connection unless the resulting disclosure is lawful.

15. International data transfers

WayConnect, its providers, and Customer-selected recipients may process personal data outside the EEA or United Kingdom. A restricted transfer must use a mechanism permitted by the applicable GDPR unless a specific lawful derogation applies.

  • For EU GDPR transfers, the mechanism may include an adequacy decision, the European Commission's approved Standard Contractual Clauses (“EU SCCs”), or another safeguard permitted by Articles 45–49.
  • For UK GDPR transfers, the mechanism may include UK adequacy regulations, the International Data Transfer Agreement (“IDTA”), the UK Addendum to the EU SCCs, or another safeguard permitted by UK law.
  • Where required, the responsible exporter should assess the destination law and practical risks and apply supplementary contractual, technical, or organisational measures.
  • A Customer requiring a specific transfer mechanism, processing location, or data-residency commitment must ensure that it is documented in the applicable DPA or Order Form before submitting the affected data.

16. Security of processing

WayConnect uses measures designed for the nature and risk of the Services, including workspace- and role-scoped permissions, password hashing, encrypted connections, protection for supported credential and message fields, rotating sessions, rate limits, signed temporary file access, webhook-signature checks, audit and security events, and restricted support access.

Security is a shared responsibility. Customers must manage authorised users, authentication, devices, integrations, exports, secrets, and endpoints; train relevant personnel; and promptly revoke access that is no longer required. No online service can guarantee absolute security, availability, or prevention of every incident.

The specific measures applicable to processor services may be described in the DPA or security schedule. Security measures may evolve as threats, technology, and Services change, provided the overall protection is not materially reduced during an applicable commitment without appropriate notice or agreement.

17. Personal data breach response

WayConnect maintains processes to identify, contain, investigate, document, remediate, and learn from suspected security incidents. An event is a GDPR personal data breach only if it results in accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to personal data.

When WayConnect acts as Processor and becomes aware of a confirmed personal data breach affecting Customer Content, it will notify the affected Customer without undue delay as required by the DPA and provide available information reasonably needed for the Customer's assessment. The Customer, as Controller, remains responsible for deciding whether it must notify a supervisory authority or Data Subjects unless the agreement or law assigns a different obligation.

When WayConnect acts as Controller, it will assess the likely risk to individuals and notify the competent supervisory authority without undue delay and, where feasible, within 72 hours after becoming aware when the GDPR requires notification. Affected individuals will also be informed without undue delay where the breach is likely to create a high risk and no applicable exception removes that requirement.

18. Retention, return, and deletion

Personal data is retained only for the applicable purpose, Customer instruction, active service relationship, security, dispute resolution, and legal, tax, accounting, or regulatory need. The Privacy Policy provides current operational examples, including short-lived authentication records, default 30-day Meta webhook and developer log periods, short-lived idempotency records, and workspace activity logs that may be retained for up to 730 days.

Customer Content is subject to the Customer's settings, product controls, and DPA. When Services end, access may stop before all data is removed. Deleted data can remain temporarily in protected backups or provider systems until standard overwrite or deletion cycles complete. Billing, tax, fraud, security, opt-out, request, and legal-claim records may be preserved where continued retention is justified.

Customers should export required records and submit deletion instructions before access ends. A Customer must not retain data in WayConnect merely because storage remains technically available after the original lawful purpose has ended.

19. Data Subject rights

Subject to conditions and exceptions in the applicable GDPR, a Data Subject may exercise the following rights against the relevant Controller. Rights are not absolute, and the Controller may need to preserve information to comply with law, protect another person's rights, prevent fraud, secure the Services, or establish, exercise, or defend legal claims.

  • The right to be informed about the collection and use of personal data.
  • The right of access to personal data and relevant processing information.
  • The right to rectify inaccurate data and complete incomplete data.
  • The right to erasure where a legal ground for continued processing does not apply.
  • The right to restrict processing in the circumstances defined by law.
  • The right to receive eligible data in a structured, commonly used, machine-readable format and transmit it to another Controller.
  • The right to object to processing based on public task or legitimate interests, including related profiling, and an absolute right to object to direct marketing.
  • The right to withdraw consent at any time where consent is the basis, without affecting processing that was lawful before withdrawal.
  • Rights relating to decisions based solely on automated processing that produce legal or similarly significant effects.
  • The right to lodge a complaint with the competent supervisory authority and seek a judicial remedy where available.

20. Exercising GDPR rights

Where to submit a request

For personal data controlled directly by WayConnect, email support@wayconnect.co from the account-associated address and identify the right, relevant account or workspace, relationship to WayConnect, and data involved. Do not provide passwords, one-time passcodes, full payment credentials, API secrets, or unnecessary identity documents.

If the request concerns a message, contact, employee, candidate, visitor, or other Customer Content, contact the relevant Customer first. WayConnect will refer or transmit a request to the Customer and assist it as required when WayConnect acts only as Processor.

Verification, timing, and fees

The Controller may request proportionate information to verify identity, authority, and the records involved. A valid request will be answered without undue delay and normally within one month. Where permitted for a complex request or multiple requests, the response period may be extended by up to two further months if the requester is informed of the extension and reasons within the first month.

Requests are normally handled without charge. Where permitted, a reasonable administrative fee may be charged or a request may be refused if it is manifestly unfounded or excessive, particularly because it is repetitive. Any refusal will be explained together with available complaint and remedy information.

21. DPIAs, records, and accountability

A Controller must conduct a Data Protection Impact Assessment (“DPIA”) before processing that is likely to result in a high risk to individuals. Depending on scope and context, this can include large-scale sensitive data, systematic monitoring, precise or repeated employee location tracking, innovative technology, vulnerable people, or systematic and extensive profiling with significant effects.

Customers should screen proposed workforce monitoring, geofence attendance, AI qualification, recruitment assessment, message profiling, large-scale campaign, and integration workflows before activation. A DPIA should document the processing and purposes, necessity and proportionality, risks to individuals, safeguards, security controls, consultation, residual risk, approvals, and review schedule.

If high residual risk cannot be mitigated, the responsible Controller must consult the competent supervisory authority before processing where the GDPR requires it. WayConnect will provide reasonable processor information and assistance as described in the DPA but does not perform the Customer's legal assessment or approve its processing purpose.

22. Data-protection contacts and supervisory authorities

A Data Protection Officer (“DPO”) is appointed where the applicable legal test requires one. WayConnect does not represent through this public page that a DPO is legally required or appointed for every service relationship. Requests for the applicable privacy, DPO, grievance, or representative contact can be sent to the address below and will be routed according to the relevant WayConnect contracting entity and processing context.

EEA Data Subjects may complain to the data-protection authority in the Member State of habitual residence, place of work, or alleged infringement. UK Data Subjects may complain to the UK Information Commissioner's Office. We encourage individuals to contact the relevant Controller first so the concern can be investigated, but doing so does not remove a statutory right to complain.

Questions about this GDPR Policy, DPA requests, and verified rights requests may be sent to support@wayconnect.co. Include enough information to identify the relevant account or Customer, but do not send credentials, secrets, or unrelated sensitive personal data.

23. Children and policy changes

WayConnect is intended for business and organisational use and is not directed to children. A Customer must not process children's data through WayConnect unless the processing is lawful, necessary, transparently explained, supported by the required parental or guardian authorisation where applicable, and protected by measures appropriate to the child's interests and vulnerability.

We may update this Policy as the Services, processing, providers, regulatory guidance, or legal requirements change. The current effective date will remain visible on this page. Material changes affecting existing processing will receive additional notice through the website, workspace, email, DPA notice process, or another appropriate channel where required.

Questions about this document?

Contact WayConnect from an authorised account email and include the relevant workspace, invoice, or request details. Never include a password, one-time passcode, full payment credential, or API secret.

support@wayconnect.co
WayConnect AI
Online
Type a message

Stay connected

Subscribe to our newsletter for the latest updates and insights.

No spam—just useful product updates, insights, and events.

GDPR Policy | WayConnect