Privacy Policy

Last updated: 14 September 2026

Privogrid is operated by WaveLinker OÜ, a company registered in the Estonian Commercial Register (Äriregister) under registry code 17450210, with its registered address at Tartu mnt 67/1-13b, Kesklinna linnaosa, 10115 Tallinn, Estonia (VAT number EE102974542) — the "controller", "we", "us". This policy explains what we collect, why, where it goes and how you can control it. By using Privogrid you agree to this policy.

You must be at least 13 years old (Estonia's digital-consent age under the GDPR and the Estonian Personal Data Protection Act, Isikuandmete kaitse seadus) to use Privogrid. We do not knowingly collect data from children below that age.

1. What we collect

We do not knowingly collect any special category data (such as health, religion or political opinions). Please do not send us such data.

2. What we do NOT collect

3. Why we use it (legal basis)

We do not sell your data and we do not use it for advertising. We do not carry out automated decision-making or profiling that produces legal or similarly significant effects on you.

4. Who processes it for us

Each processor only receives what it needs for its job.

5. International data transfers

Some of these processors operate outside the European Economic Area (EEA), for example in the United States. Where your data is transferred outside the EEA it is protected by an adequacy decision of the European Commission or by the EU Standard Contractual Clauses (SCCs), together with additional technical measures such as encryption. You can request a copy of the relevant safeguards by writing to [email protected].

6. How long we keep it

7. Security

Passwords are salted and hashed (PBKDF2). Synced data is encrypted with AES-256-GCM before it leaves your device. All traffic uses HTTPS (HSTS). Accounts are protected with rate-limiting, automatic blocking of abusive traffic and session-token expiry. Access to personal data is limited to staff who need it.

If a personal data breach occurs that is likely to result in a risk to your rights, we will notify the Estonian supervisory authority within 72 hours, and affected users without undue delay, as required by the GDPR (Art. 33–34).

Found a vulnerability? See our security page or write to [email protected].

8. Your rights (GDPR)

You can ask us to access, correct, export (data portability) or erase your personal data, to restrict or object to processing, and — where we rely on your consent — to withdraw that consent. You also have the right to lodge a complaint with your supervisory authority — in Estonia, the Estonian Data Protection Inspectorate (Andmekaitse Inspektsioon), www.aki.ee, [email protected].

9. Cookies

The website sets no advertising or tracking cookies. The dashboard keeps your login token in your browser's local storage so you stay signed in; Stripe sets its own cookies on its checkout pages. Cloudflare may set a strictly necessary security cookie to protect against bots. Because we use only strictly necessary storage and cookieless analytics, no cookie-consent banner is required — if we ever add non-essential cookies, we will ask for your consent first.

10. Changes

We may update this policy. Material changes will be posted on this page with a new "Last updated" date, and announced in the dashboard or by email if they affect how your data is used.

11. Contact

WaveLinker OÜ · registry code 17450210 · Tartu mnt 67/1-13b, 10115 Tallinn, Estonia · VAT EE102974542 · [email protected] (privacy requests) · [email protected] (security reports).

← Back to home