WAVESTORE DATA PRIVACY POLICY

1. Purpose

The purpose of this policy is to ensure that Wavestore handles personal data in a manner that complies with the UK GDPR, the EU GDPR (where applicable), and all relevant data protection legislation. This policy outlines how Wavestore collects, uses, stores, protects, and shares personal data belonging to customers, partners, employees, and other stakeholders.

2. Scope

This policy applies to:

  • All employees, contractors, and temporary staff of Wavestore
  • All systems, processes, and activities where personal data is collected or processed
  • All personal data processed by Wavestore in the UK or internationally

3. GDPR Principles

Wavestore processes personal data in accordance with Article 5 of the GDPR. Personal data must be:

  1. Lawful, fair & transparent
  2. Collected for specific, explicit purposes
  3. Adequate, relevant & limited
  4. Accurate and kept up to date
  5. Kept no longer than necessary
  6. Processed securely

4. Employee Awareness & Training

  • All new employees receive GDPR and Data Privacy training during induction.
  • Employees must sign a Confidentiality Agreement before accessing any personal data.
  • Annual refresher training is mandatory for staff handling personal data.
  • This policy is available to all employees and reviewed annually.

5. Personal Data Wavestore Collects

5.1 Types of Data Collected

Wavestore collects only the personal data necessary for normal business operations. This may include: Name, Email address, Telephone number, Business contact information, notes related to business interactions, and support logs that may contain usernames or IP addresses.

Financial information is never stored by Wavestore. Payments are processed securely through third-party providers in accordance with the Information Security Policy.

5.2 How Data Is Collected

Data is collected through website sign-ups, CRM entries, emails or written correspondence, telephone communications, in-person meetings, and support cases.

5.3 Where Data Is Stored

Personal data may be stored on Wavestore’s CRM, website systems, or secure Outlook accounts and mobile device contacts. All systems are password-protected and access-controlled.

5.4 Online Academy Registration

Wavestore provides training for Value Added Resellers (V.A.R.s) and end users through our Online Academy. To access materials, individuals must create an account providing their name, email, company, and job title. This data is used to track progress and provide certificates. Records are retained for the duration of the training and business relationship.

6. Legal Basis for Processing

Wavestore processes personal data based on contractual necessity, legitimate interests (such as CRM management and support), legal obligations, or explicit consent for marketing communications.

7. How Personal Data Is Used

Personal data is used for managing accounts, processing orders, administering contracts, providing technical support, personalising service experiences, and sending authorized marketing emails.

8. Who Personal Data Is Shared With

Wavestore may share data with technology partners, distributors, service providers, or legal authorities. All third parties are bound by Data Processing Agreements (DPAs). Wavestore never sells personal data.

9. International Data Transfers

If personal data is transferred outside the UK or EEA, Standard Contractual Clauses (SCCs) or equivalent safeguards are implemented to ensure continued protection.

10. Retention Periods

  • CRM contact data: 3 years after last interaction
  • Support logs: 12 months unless required longer for an investigation
  • CCTV footage: 31 days unless part of an incident

11. CCTV at Wavestore Offices

Visitors and employees may be recorded for safety. Footage is retained for 31 days. Access is strictly restricted to authorized staff and used only for security purposes.

12. Data Handling on Customer Sites

12.1 Live CCTV

Viewed only for troubleshooting and only for the duration needed to complete support tasks.

12.2 Recorded Footage

Extracted only with customer authorization and deleted when no longer needed.

12.3 Log Files

Used only by relevant support staff and retained securely until the case is resolved.

12.4 Passwords

Temporary accounts are requested where possible; passwords are treated as confidential and deleted after use.

12.5 Confidentiality

All other non-public customer data is treated as confidential and deleted after use.

13. Data Subject Rights

Individuals have the right to access, correct, delete, or restrict the processing of their data. They also have the right to data portability and to lodge a complaint with the ICO.

14. Data Breaches

Wavestore will investigate all suspected breaches immediately. The ICO will be notified within 72 hours where a breach risks harm to individuals, and affected parties will be informed as required.

15. Data Protection Lead

For questions, requests, or complaints regarding personal data, please contact:
Email: help@wavestore.com