Privacy Policy
Version 2026-11-02
1. Who we are
V.P. Labs (trading as wawesome.io) is registered in the Netherlands with the Chamber of Commerce (Kamer van Koophandel) under number 76655180, based in Almere, the Netherlands.
For the personal data described in this Privacy Policy, V.P. Labs is the Data Controller under the General Data Protection Regulation (GDPR).
Questions about this policy or your personal data can be sent to privacy@wawesome.io.
2. If you came here from a site hosted on wawesome
The apps on this platform are built and run by our customers. We run the code they deployed and nothing else with it.
For personal data a customer’s app holds about you, that customer decides what is collected and why, so they are the Data Controller and we are their Data Processor. Ask them, not us. If you write to us instead, we will point you to them and tell them you asked. What we may and may not do with that data is set out in our Data Processing Agreement.
The rest of this policy is about data we decide the use of ourselves, which is the data of the people who hold workspaces with us.
3. The data we collect and why
We collect only the personal data needed to run the platform, provide customer support, comply with tax laws, and protect platform security.
Account information
When you create a workspace or sign in, we receive your name, email address, and user identifier from the identity provider you selected. We use this data to identify you, manage your workspace memberships, and provide access to your deployed apps.
Signing in from the command-line tool or from an MCP client opens a session record holding your account identifier, the client that opened it, and when it was last renewed. Signing out ends it.
The lawful basis for this processing is the performance of our contract with you (GDPR Article 6(1)(b)), based on the terms of service you accepted.
The record of what you accepted
Creating a workspace records which version of each legal document you accepted, the moment you accepted it, the IP address the acceptance arrived from, and the client that sent it. It is the evidence that a contract exists and what its terms were, which is the whole reason we keep it. Nothing else reads it.
We keep it while your workspace is open and for five years after it closes, matching the limitation period for a contract claim under Dutch law. When it closes and you belong to no other workspace, we delete the IP address and the client from it. The document, its version and the date are enough to show what was agreed.
Closing a workspace and erasing your account are two different things. A workspace can close while your account stays, and the five years run from that closure. If you ask us to erase your account, the record is erased with it, because we cannot keep evidence about a person we have erased.
The lawful basis is our legitimate interest in being able to show what was agreed (GDPR Article 6(1)(f)).
Billing and payment records
When you choose a paid plan, payment is handled by Stripe Managed Payments, who acts as Merchant of Record. Stripe collects your billing details, payment card information, and tax address. We receive transactional confirmation records, subscription identifiers, billing statuses, and transaction receipts. We do not store raw credit card numbers on our servers.
The lawful basis for holding transaction records is compliance with our legal obligations under Dutch tax and commercial law (GDPR Article 6(1)(c)), which requires retaining accounting records for seven years.
Operational notifications
We send platform notifications regarding your resources, such as deployment confirmations, credential revocations, plan status changes, and payment retry updates. Platform mail is sent from send.wawesome.io via our email delivery provider.
A notification row in our database identifies the recipient user and event, and resolves the email address at the time of sending. Sent notification records are retained for 35 days for delivery verification and then deleted. If an address produces a hard bounce, we suppress the address for 30 days to avoid repeated delivery failures, after which the suppression record expires automatically.
The lawful basis for sending platform mail is the performance of our contract with you (GDPR Article 6(1)(b)). We do not send marketing newsletters or unsolicited promotions through this system.
Correspondence
When you write to one of our published addresses, we keep your message and our reply so we can answer it and account for what was said. Notices about illegal content and moderation appeals are kept for as long as the restriction they concern, because we may have to justify that decision later.
The lawful basis is the performance of our contract with you where you are a customer (GDPR Article 6(1)(b)), and our legitimate interest in handling reports and appeals properly (GDPR Article 6(1)(f)).
The record of what happens in a workspace
When somebody in a workspace deploys code, makes a version live, sets or deletes an environment variable, invites somebody, joins, changes a role, removes somebody, leaves, or pauses or resumes a schedule, we record who did it, what it was about and when. If a deploy credential did it, we record the credential and the person who created it. We never record the value of an environment variable.
The record lets the people in a workspace, and us, answer for what was done in it: after a mistake, after a security incident, or when members disagree about what happened.
We keep each entry for 12 months, including after the workspace closes. If you erase your account, the entries keep the identifier your account had, which no longer points to anyone.
The lawful basis is our legitimate interest in being able to show who did what in a workspace (GDPR Article 6(1)(f)).
Conversations with the assistant
The dashboard has an assistant that answers questions about your workspace. When you ask it something, we keep the conversation: your messages, its answers, and what it read to answer. To produce the answer, we send your question, and what the assistant reads from the workspace, to a language model provider listed in section 6.
Your messages and the assistant’s answers are covered by this policy. What the assistant reads from the workspace, such as function code and execution logs, is the workspace’s data and can hold personal data about the people who use its apps. For that data we act for the workspace, as section 2 describes, and our Data Processing Agreement covers it.
The assistant cannot read the values of secrets. Anything you write in the chat is sent as you wrote it. Do not write passwords, keys or other secrets there, or personal data about other people, such as the names, email addresses or health details of your app’s users.
Only you can read your conversations. Other members of the workspace cannot, owners included. A change the assistant makes with your approval is different: like any change you make yourself, it goes in the record of what happens in the workspace, under your name.
We delete a conversation 30 days after its last message, or earlier when you delete it, leave the workspace, the workspace closes, or you erase your account. What the assistant read from execution logs is removed from the conversation after 14 days. If you are an owner, a workspace export you ask for includes your own conversations.
The providers do not keep your conversations after answering. The one exception is Scaleway, which may keep a request that causes errors for up to 14 days to investigate it. Neither provider uses them to train models.
The lawful basis for answering your questions is the performance of our contract with you (GDPR Article 6(1)(b)): the assistant is part of the service, and it only runs when you ask it something. Keeping a conversation afterwards, so you can come back to it, rests on our legitimate interest in giving you a useful assistant (GDPR Article 6(1)(f)).
Security and rate limiting
To protect the platform against denial-of-service attacks, brute-force attempts, and abuse, our gateway records the caller socket address of incoming HTTP requests. For IPv6 connections, rate limiting is applied to the /64 subnet prefix.
The lawful basis for processing network addresses for rate limiting is our legitimate interest in securing our infrastructure (GDPR Article 6(1)(f)) and our statutory obligation to maintain security of processing (GDPR Article 32).
Workspace names and domain labels
A workspace name and app name become part of the public domain name minted for your apps. Because domain names and DNS records are public and remain resolvable to avoid dangling routes, you must not include personal data in your workspace slug, app name, or function URLs.
4. Cookies and tracking
The wawesome website and dashboard use strictly necessary cookies only, which are required to authenticate sessions and keep you signed in.
We count visits to the pages of wawesome.io, the documentation included, with Cloudflare Web Analytics. A small script on each page reports the page’s address, the page that linked to it, your browser, device type and country, and how long the page took to load. It sets no cookie, stores nothing on your device and does not fingerprint you. We see totals per page, never who visited. The dashboard does not carry this script.
The lawful basis is our legitimate interest in knowing which pages people read (GDPR Article 6(1)(f)).
We do not use advertising cookies or fingerprinting scripts. Because we set only strictly necessary cookies, no cookie consent banner is shown. If we ever introduce optional cookies, we will present a consent banner before setting them.
Cloudflare, which sits in front of our network, may set a bot-management cookie (__cf_bm) on requests it protects. It tells automated traffic from human traffic and carries no advertising identifier.
5. How long we keep your data
We keep account records until you erase your account. Closing a workspace and erasing your account are both done from the dashboard. If you cannot sign in, write to privacy@wawesome.io from the address on your account and we do it for you.
A workspace closes fourteen days after its owner asks, and the owner can cancel until then. When it closes, its custom domains are detached and its apps, credentials, sessions and memberships are deleted. Its code and files are deleted too. Our storage keeps an older copy for recovery, in backups too, and the last of those copies is gone about 31 days after the workspace closes, so about 45 days after the owner asks. Your account stays until you erase it.
When you erase your account, we delete it within 30 days of the request. If you own a workspace, erasing your account closes it first, and your account is erased once it has closed. Erasure takes your name and email address, your memberships, your conversations with the assistant, notifications addressed to you, your sign-in sessions, and your identity at our authentication provider. Stripe keeps billing invoices and payment receipts for seven years as Merchant of Record, to satisfy Dutch tax authority requirements. Data under a legal preservation order is kept until the order is released.
Records of what you accepted are kept for five years after your workspace closes, unless you ask us to erase your account, as described above. Operational security logs and raw network connection records are deleted within 35 days. The record of what happens in a workspace is not one of these logs: it is kept for 12 months, as section 3 describes. Assistant conversations are deleted 30 days after their last message, as section 3 describes. Aggregated usage counts are kept in monthly summary records, which contain no personal data or individual IP addresses. They are deleted with the workspace when it closes.
6. Who else receives your data
We share account data only with third-party service providers who help us run the platform:
- Hosting and infrastructure: DigitalOcean, LLC (primarily Frankfurt, Germany, and facilities within the European Union) for server compute, database hosting, and file storage.
- Content delivery and edge security: Cloudflare, Inc. (global edge network) for DNS routing, TLS encryption, and DDoS mitigation.
- Authentication: Supabase, Inc. for identity management and sign-in verification. Our project is hosted in Stockholm, Sweden (AWS
eu-north-1). - Payment processing: Stripe Payments Europe, Ltd. and Stripe, Inc. for subscription checkout and billing management.
- Transactional email: Resend, Inc. for delivering platform notices from send.wawesome.io.
- Operational logs: Raintank, Inc. (Grafana Labs) for storing and searching our gateway’s logs. A log line can include the IP address a request came from. Our logs are held in Frankfurt, Germany (AWS
eu-central-1). - Error reports: Functional Software, Inc. (Sentry) for errors raised in the dashboard. A report carries your workspace identifier, never your name, email address or the contents of a request. Reports are held in Sentry’s EU data region.
- Assistant: Mistral AI SAS (France) and Scaleway SAS (Paris, France) provide the language models behind the dashboard assistant. They receive your questions and what the assistant reads to answer them, and process them in the European Union.
Every supplier processes data under written data protection terms and confidentiality obligations. We do not sell personal data to anyone.
7. International data transfers
Our primary servers, databases, and file stores are located within the European Union (initially Frankfurt, Germany).
Where suppliers transfer personal data to the United States or other countries outside the European Economic Area (EEA), transfers are protected by:
- The EU-US Data Privacy Framework adequacy decision, where the supplier is certified.
- European Commission Standard Contractual Clauses (SCCs), incorporated into our agreement with the supplier to provide enforceable safeguards.
Supabase, Inc. is not certified under the Data Privacy Framework, so transfers to it rest on Standard Contractual Clauses alone. Our data sits in Sweden; access from the United States by Supabase staff supporting the service is covered by those clauses.
8. Your statutory rights
Under Chapter III of the GDPR, you have the right to:
- Request access to the personal data we hold about you.
- Request correction of inaccurate personal data.
- Request erasure of your personal data when it is no longer necessary for the purposes collected.
- Object to processing based on legitimate interests.
- Request restriction of processing while a dispute is resolved.
- Request data portability in a structured, machine-readable format.
To exercise any of these rights, email privacy@wawesome.io. We will verify your identity and respond within one month.
You also have the right to lodge a complaint with the Dutch Data Protection Authority (Autoriteit Persoonsgegevens) at https://autoriteitpersoonsgegevens.nl.
9. Changes to this policy
We update this policy when what we do with personal data changes. Every version carries the date it took effect, at the top of this page.
Where a change materially affects you, such as a new supplier receiving your data, we give workspace owners at least 30 days’ notice by email before it takes effect. Earlier versions are available on request.