waa

Privacy Policy

Last updated: July 2026

1. Data controller

WEB APPS ARTISAN S.R.L., with registered office at Ale. Socului nr. 2, București, România (tax ID 49809200), is the controller of personal data collected through the waa.events platform, in accordance with Regulation (EU) 2016/679 (GDPR).

Data protection contact: support@waa.events

2. What data we collect

We collect the following categories of data:

  • Account data: email address, name, phone number (optional)
  • Invitation data: event name, location, date, personalised messages, uploaded photos
  • RSVP data: names and responses of guests (attendance confirmations)
  • Technical data: IP address, browser type, operating system, pages visited, session duration
  • Payment data: processed securely through third-party providers — we do not store card details

3. Purpose and legal basis for processing

We process your data for:

  • Providing services — performance of contract (Art. 6(1)(b) GDPR)
  • Account management — performance of contract (Art. 6(1)(b) GDPR)
  • Service communications (confirmations, notifications) — performance of contract (Art. 6(1)(b) GDPR)
  • Marketing and newsletter — consent (Art. 6(1)(a) GDPR), which you may withdraw at any time
  • Legal obligations (invoicing, archiving) — legal obligation (Art. 6(1)(c) GDPR)
  • Platform improvement — legitimate interest (Art. 6(1)(f) GDPR)
  • Writing assistant (optional) — generating, rewriting and translating invitation text with an AI provider, at your request — performance of contract and legitimate interest (Art. 6(1)(b) and (f) GDPR)

4. Recipients of data

Your data may be shared with:

  • Cloud and infrastructure service providers (hosting, CDN)
  • Authorised payment processors
  • Transactional email services
  • Artificial-intelligence service providers — for the writing assistant, only when you use it (see below)
  • Public authorities, where required by law

We do not sell your personal data to third parties.

AI writing assistant (optional): when you use the feature to generate, rewrite or translate invitation text, the text of that field, the language code and a non-personal context hint (e.g. "the reception section") are sent to an artificial-intelligence service provider (for example Anthropic, OpenAI or Google, depending on the active configuration) to produce the suggestion. We do not send your account data or any personal data beyond the text you are editing. Under these providers' terms for API services, the text is not used to train their models, and retention at the provider is limited. The feature is optional: if you do not use it, no text is sent to these providers.

5. International transfers

Some service providers may be located outside the European Economic Area. Transfers are carried out with appropriate safeguards (standard contractual clauses approved by the European Commission or adequacy decisions).

The artificial-intelligence service providers used for the writing assistant may be located in the United States; transfers are carried out with the same appropriate safeguards.

6. Retention period

  • Account data: for the duration of the account + 30 days after deletion
  • Invitations and content: for the duration of the active subscription
  • Billing data: 10 years (legal obligation)
  • Technical data / logs: maximum 12 months

7. Your rights

Under GDPR, you have the right to:

  • Access — request a copy of the data being processed
  • Rectification — correction of inaccurate data
  • Erasure — the "right to be forgotten", under the conditions set by law
  • Restriction — limiting processing in certain situations
  • Portability — receiving your data in a structured format
  • Objection — to processing based on legitimate interest
  • Withdrawal of consent — without affecting the lawfulness of prior processing

To exercise your rights, contact us at support@waa.events. You also have the right to lodge a complaint with the National Supervisory Authority for Personal Data Processing (ANSPDCP)www.dataprotection.ro.

8. Data security

We implement appropriate technical and organisational measures to protect data: HTTPS encryption, restricted access, continuous monitoring. In the event of a security incident affecting your data, you will be notified in accordance with legal requirements.

9. Cookies

We use cookies and similar technologies. Details in the Cookie Policy.

10. Changes to this policy

We may update this policy periodically. The date of the last update is shown at the beginning of this document. Continued use of the platform after changes are published constitutes acceptance of those changes.