Who we are and what this document covers.
Wavly (“we”, “us”, “our”) operates the Wavly Agentic Revenue Operating System at thewavly.com. This Privacy Policy explains how we collect, use, disclose, and safeguard information when you use our service, websites, and related APIs.
Controller vs Processor — depends on the data path.
- Account & billing contacts — Wavly is typically the controller for your login identity, subscription records, and support correspondence.
- Workspace Revenue Graph data — For CRM sync, product events, agent drafts, and attributed outcomes you instruct us to process, Wavly acts as a processor on your documented instructions (see DPA).
- This policy covers thewavly.com, the authenticated app, conversion webhooks, and transactional email. It does not cover third-party sites you connect via OAuth.
Section 03
Information we collect
#Account, Graph, usage, payments, and logs — nothing hidden.
- Account information — name, email, authentication credentials via Supabase Auth; workspace membership and roles.
- Revenue Graph data — accounts, opportunities, product/usage events, integration metadata, agent handoffs, and attributed outcomes you create or sync.
- Configuration — ICP definitions, governance tiers, brand voice, playbooks, and Customer Revenue DNA™ cluster settings.
- Usage data — feature usage, operator actions, performance metrics needed to run and improve the OS.
- Payment information — processed by Stripe and/or Razorpay. We do not store card numbers on Wavly servers.
- Device & log data — IP address, user agent, timestamps, security events (signature failures, rate limits) for abuse prevention and audit.
Section 04
How we use information
#Operate the OS, draft under governance, bill, notify, improve.
- Provide, operate, secure, and maintain the Agentic Revenue Operating System.
- Run Scout · Closer · Keeper · Grower with governed autonomy — drafts, elevations, and plays with provenance.
- Call model APIs (currently OpenAI) to generate drafts and analysis. Campaign / Graph context may be sent for processing; it is not used to train their foundation models under our provider terms.
- Process payments and manage subscriptions via Stripe / Razorpay.
- Send transactional email, digests, and operational alerts (opt-out for non-essential marketing).
- Detect abuse, debug incidents, and improve reliability and UX.
- Comply with law and enforce our Terms.
Section 05
Graph, Memory & DNA
#Compounding intelligence stays in your tenant.
Revenue Memory stores attributed outcomes so agents improve within your workspace. Customer Revenue DNA™ profiles are learned from your top customers and used to score new visitors/accounts — with match rationale shown to operators.
Memory and DNA are not sold, not used to train cross-tenant models for other customers, and remain subject to workspace isolation (RLS). Aggregated, anonymized product analytics may be used to improve the platform without identifying your accounts.
Section 06
Processors & sharing
#Only processors required to run Wavly. We do not sell data.
We share data with subprocessors necessary to operate the service, including:
- Supabase — authentication and Postgres (RLS).
- Vercel — application hosting.
- OpenAI — model API for drafts and analysis.
- Stripe / Razorpay — payment processing.
- Resend — transactional email.
CRM / product connectors you authorize (e.g. HubSpot, Salesforce, Zoho, Slack, PostHog) receive or provide data under your OAuth instructions — they are your processors or controllers for that path, not Wavly marketing partners.
We do not sell personal data. We may disclose information if required by law or to protect rights, safety, and security.
See Security for architecture detail and DPA for processor terms.
Section 07
Cookies & tracking
#Session cookies + attribution links. No ad networks.
We use essential cookies to maintain authenticated sessions. We may use first-party attribution links to measure click-through on Closer-attributed pages. We do not run third-party advertising trackers on the app.
TLS, RLS, secrets, audit — same posture as /security.
We implement industry-standard measures including TLS, database row-level security, encrypted secrets, HMAC webhook verification, and governance audit trails. No system is 100% secure; we take reasonable precautions and improve continuously. Full detail: Security page.
Section 09
Retention & deletion
#Active while your workspace runs; deletion on request / cancel.
- Account and Graph data retained while your workspace is active.
- Workspace deletion: in-app workflow with approximately 30 days grace before hard delete of Graph rows (backups may persist for a limited recovery window per infrastructure provider).
- Security logs retained for abuse prevention and audit as reasonably necessary (typically up to 12 months unless law requires longer).
- Billing records retained as required for tax and accounting.
Access, correct, delete, export, opt out — where law allows.
Depending on your jurisdiction, you may have the right to:
- Access, correct, or delete personal data.
- Opt out of non-essential marketing email.
- Request a portable copy of your data.
- Withdraw consent where processing is consent-based.
- Lodge a complaint with a supervisory authority.
Exercise rights via privacy@thewavly.com. We may need to verify identity before fulfilling requests.
Section 11
GDPR & DPDP Act
#EEA: GDPR bases. India: DPDP Act, 2023.
For individuals in the EEA / UK, we process personal data under contractual necessity, legitimate interests (securing and improving the service), and consent where required. Enterprise Graph processing is typically on documented controller instructions under a DPA.
For individuals in India, we comply with the Digital Personal Data Protection (DPDP) Act, 2023. You may exercise rights under applicable law by contacting privacy@thewavly.com.
Section 12
International transfers
#Infrastructure may process outside your country.
Wavly and its subprocessors may process data in regions where those providers operate (default Graph/Auth primary: United States). Dedicated EU residency is sales-led infrastructure when provisioned — not a self-serve toggle. Where required, we use appropriate safeguards (such as contractual clauses with processors). Operators can view the current deployment disclosure in Settings → Team → Security.
Not directed to children under 18.
The service is directed to business users 18+. We do not knowingly collect personal data from children. Contact us if you believe we have — we will delete promptly.
Section 14
Changes to this policy
#Material updates by email or in-app.
We may update this policy from time to time. Material changes will be communicated via email or in-app notice. Continued use after the effective date constitutes acceptance where permitted by law.
privacy@thewavly.com for privacy and data-rights requests.