Account, privacy & your data

Where Wavrr stores your data

Where your client records live, who can reach them, and which side of the GDPR line you are on.

Clients ask this, and health inspectors sometimes do too. Here is the short version, with the authoritative detail in our privacy policy.

Where it lives

Wavrr is operated by Blink B.V., established in Amsterdam, the Netherlands.

Your database, your signed waivers, your PDFs and any uploaded ID photographs are hosted with Supabase inside the European Union. Personal data is encrypted in transit with TLS, and at rest where supported.

Some supporting services — email delivery, billing, support messaging, analytics — may process limited personal data outside the EEA, including in the United States. Where that happens it is covered by the safeguards required under Chapter V of the GDPR. The privacy policy names each sub-processor, what it does and which region it operates in.

Who is the controller — you or us

This is the part worth getting right.

Practically, that means a client's request to see or erase their data comes to you, not to us, and you are the one who has to answer it.

Who can reach it

Your account's sign-in credentials are the boundary. Anyone with your email and password can read every client record you hold.

How long it is kept

Signed waivers, PDFs and ink passport records are kept for as long as your account is open, and after closure for as long as is needed to defend or assert legal claims about the underlying service. Under Dutch law, limitation periods for personal-injury claims can run up to 20 years — which is a long retention, and deliberately so: a consent record you threw away is a defence you no longer have.

ID photographs are different. You are responsible for setting an appropriate retention period for those and for removing them once the purpose they were collected for is over. GDPR data-minimisation applies to you as controller, which is a good reason not to collect them unless you need to — see Ask a client for photo ID.

What to tell a client who asks

That their consent form is stored digitally on EU-hosted infrastructure, encrypted, accessible only to your studio, and kept because you are required to be able to evidence consent. Then point them at your own privacy notice — as controller, you should have one.

Related

Still stuck?

If this did not answer your question, get in touch and a human will reply.

Contact support

Last updated