Legal
Wisayo — General Data Protection Regulation (GDPR)
1. Lawful Basis for Processing
We process your data based on:
- Contractual necessity — To provide the Wisayo service
- Legitimate interest — To improve security and prevent fraud
- Consent — For optional analytics (you can withdraw anytime)
2. Your Rights
- Right to access — Get a copy of your data
- Right to rectification — Correct inaccurate data
- Right to erasure — Delete your data (with exceptions)
- Right to restrict — Limit how we use your data
- Right to portability — Get your data in portable format
- Right to object — Object to certain processing
- Right to withdraw consent — Stop optional data sharing
3. Submitting Requests
Email: security@wisayo.com
Include: Name, email, account ID, request type. Respond within 30 days. Complex requests may take 60 days.
4. Data Protection Officer
Contact our DPO: security@wisayo.com
5. Transfers Outside EU
We use Standard Contractual Clauses (SCCs) for data transfers. SCCs available on request: security@wisayo.com
6. Sensitive Data
We do NOT knowingly collect:
- Racial or ethnic origin
- Political opinions
- Religious beliefs
- Genetic data
- Biometric data
- Health data (unless you voluntarily share in chat)
7. Automated Decision-Making
Wisayo forecasts are NOT used for:
- Hiring decisions
- Credit decisions
- Legal decisions
- Discrimination
Forecasts are personal guidance only.
8. Data Retention (GDPR)
We keep your data only as long as needed:
- Active accounts: Data retained
- Deleted accounts: Data removed within 30 days
- Inactive accounts (12+ months): Deletion notice sent
Your vault data on your device: Retained until you delete it.
9. Supervisory Authority
If you believe we're violating GDPR, contact your local data protection authority: edpb.ec.europa.eu
