Privacy Policy

How Wextfy handles personal data of account holders, company representatives and site visitors.

Draft outline. Each section below describes the content that belongs there. The binding wording must be drafted and reviewed by a qualified lawyer before launch.

Operator

Legal entity
SIA "G 78"
Registered address
Mehanizācijas iela 4a, Limbaži, Latvia, LV-4001
Registration number
40203775379
VAT number
Not VAT-registered
Contact
support@wextfy.com

1. Controller and contact

The data controller is SIA "G 78", registration number 40203775379, registered at Mehanizācijas iela 4a, Limbaži, Latvia, LV-4001. Privacy enquiries and data-subject requests can be sent to support@wextfy.com. A data protection officer or EU representative will be named here if one becomes required.

2. Data we collect

Account data (name, business email, phone, preferred language, password hash, 2FA secrets), company data (public profile, private contact and registration details, uploaded documents and images), messaging content and translations, billing data held with Stripe, affiliate payout details, and technical data such as IP address, device fingerprint and login history.

3. Why we use it and on what legal basis

Map each purpose to a GDPR Article 6 basis: contract performance for account, profile and messaging; legitimate interests for fraud prevention, moderation, security logging and product analytics; legal obligation for invoicing and tax records; consent for marketing email and non-essential cookies.

4. Automated processing

Describe AI-assisted chat translation and AI image/text moderation, what data is sent to the model provider, the fact that borderline cases are reviewed by a human, and that no decision with legal effect is made solely by automated means.

5. Sharing and processors

List categories of recipients: hosting and database infrastructure, payment processing, transactional email delivery, AI translation and moderation providers, and analytics. State that public profile content is intentionally visible to anyone and indexed by search engines.

6. International transfers

Identify transfers outside the EEA and the safeguards relied on, such as standard contractual clauses or adequacy decisions.

7. Retention

Retention periods per data category: active account data, the 30-day soft-delete window before permanent erasure, invoices retained for statutory accounting periods, login history and security logs, and moderation records.

8. Your rights

Access, rectification, erasure, restriction, portability, objection and withdrawal of consent, how to exercise them in account settings or by email, response timelines, and the right to lodge a complaint with a supervisory authority.

9. Security

Encryption in transit, row-level access controls, separation of public and private company data, mandatory two-factor authentication, trusted-device expiry, and the breach-notification approach.

10. Children

The service is not directed at children; accounts require business capacity.

11. Changes to this policy

How updates are published and how material changes are notified to account holders.