Privacy Policy

1. Introduction

This Privacy Policy describes how GridWyse ("we", "us", or "our service") collects, uses, discloses, and protects your personal data when you interact with our services. We are committed to ensuring the confidentiality, integrity, and security of your personal information and to fully complying with applicable data protection legislation, including the General Data Protection Regulation (GDPR) and other relevant regulations.

By using GridWyse, you agree to the practices described in this Privacy Policy.

2. Information We Collect

We collect the following categories of data:

2.1 Personal Information

  • Identification data: Full name, email address, phone number.
  • Profile data: Role in the organization, password (encrypted), optional profile photo.
  • Device information: IP address, device type, browser type, operating system, UUID or Cognito ID.
  • Usage data: Login time, pages viewed, dashboard interactions, session duration.

2.2 Business Information

  • Business profile: Company or branch name, description, category, working hours, address, social media links, uploaded media (photos, videos).
  • Review data: Customer reviews from integrated platforms (e.g., Google), review responses, timestamps, sources.
  • Publications and communications: Published posts, response history, internal comments, chat logs.

3. Legal Bases for Processing

We process your data on the following legal bases under Article 6 of the GDPR:

  • Consent – You have explicitly agreed to the use of your personal data.
  • Contractual necessity – Processing required to provide the services you have requested.
  • Legal obligations – To comply with regulatory or statutory requirements.
  • Legitimate interests – To maintain and improve our platform, provided this does not override your rights.

4. How We Use Your Data

We use the collected information for:

  • Service delivery: Account management, onboarding, subscription management, role-based access.
  • Performance monitoring: Tracking review metrics, activity logs, location quality indicators.
  • Security: Fraud detection, session monitoring, IP/device verification.
  • AI-based recommendations: Improving business profiles and customer satisfaction using AI-powered recommendations.
  • Communication: Transactional emails, platform updates, feedback requests.
  • Analytics: Aggregate data analysis to improve features and usability.

5. Data Retention

  • User accounts are retained indefinitely, unless a deletion request is submitted or required by law.
  • A full data deletion mechanism will be implemented in post-MVP releases.
  • Review data and analytics logs are retained as long as necessary for operational or legal purposes.
  • Aggregated and anonymized data may be retained for product development purposes.

6. Data Security

We implement strict security measures:

  • Hosting: All infrastructure is hosted in the AWS eu-north-1 region (Stockholm, EU).
  • Authentication: AWS Cognito with support for email verification and password reset.
  • Encryption:
    At rest: AES-256 encryption for data in Amazon RDS and S3.
    In transit: HTTPS/TLS encryption for all network requests.
  • Access control: Role-based access; restricted access for employees and vendors.
  • Audit logs: All sensitive actions and authentication attempts are logged via AWS CloudWatch.
  • Two-factor authentication: Not yet available in MVP.

7. Sharing Your Data with Third Parties

We do not sell or rent your personal data.
We may share information with the following third-party organizations:

  • WayForPay – for payment processing. We do not store card numbers, CVVs, or other sensitive financial data.
  • Amazon Web Services (AWS) – as our cloud infrastructure provider.
  • Telegram / Google – for authorized integrations (with user consent).
  • Authorities – in cases provided for by law (e.g., court order or fraud investigation).

8. Your Rights (GDPR)

As a data subject, you have the right to:

  • Access – Obtain a copy of your personal data.
  • Rectification – Correct inaccurate or incomplete data.
  • Erasure – Request deletion ("right to be forgotten").
  • Restriction – Request restriction of data processing.
  • Data portability – Receive your data in a structured format.
  • Objection – Object to marketing or automated processing.
  • Withdrawal of consent – At any time, without affecting the lawfulness of prior processing.

To exercise these rights, contact us: [email protected].

9. Cookies and Tracking Technologies

We use cookies and similar technologies for:

  • Maintaining user sessions and saving their preferences.
  • Tracking usage analytics (e.g., page views, session duration).
  • Improving platform performance.

For more information, please review our Cookie Policy.

10. International Data Transfers

All personal data is stored and processed within the European Union (AWS region in Stockholm). No transfer of data outside the EU takes place unless provided for and agreed upon in accordance with GDPR (e.g., through Standard Contractual Clauses (SCCs) or adequacy decisions).

11. Changes to This Policy

We reserve the right to update this Privacy Policy at any time. All changes will be published on this page with the effective date indicated. We recommend reviewing this policy regularly.

12. Contact Information

If you have questions, comments, or wish to exercise your rights, please contact:

Data Protection Officer (DPO)
GridWyse Platform
Email: [email protected]