Privacy Policy
Last Updated: September 11, 2026
Last Updated: September 11, 2026
Data Controller
Brehm, Osipovs & Zimmermann Software GbR Birkenstr. 111 40233 Düsseldorf Germany Email: contact@wavealign.app
Note on Children
Our services are not intended for individuals under the age of 16, and we do not knowingly collect personal data from minors.
1. Introduction
Welcome to WaveAlign. We are committed to protecting your privacy and handling your personal data in a transparent and secure manner. This Privacy Policy describes how we collect, use, and share your personal data when you:
- Visit our website (the "Site")
- Use our desktop application (the "App")
Please read this policy carefully. By using our services, you agree to the collection and use of information in accordance with this policy.
2. How Consent Works on Our Website
The rules we apply to analytics and advertising on the Site depend on the country you visit us from. There are two regimes, and which one applies to you determines whether anything is loaded before you have made a choice.
2.1 Opt-In Countries (Nothing Loads Until You Accept)
If you visit us from the European Economic Area (EEA), the United Kingdom, Switzerland, Brazil, South Korea, Thailand or Canada, we apply strict prior consent:
- No analytics is loaded, and no analytics data is collected
- No advertising or marketing technologies are loaded
- Nothing is shared with Meta or TikTok — neither from your browser nor from our servers
- Nothing is written to your device beyond the strictly necessary items described in Section 2.3 and Section 7
This stays the case until you make a choice in our consent banner. If you accept, the categories you accepted are activated. If you decline, nothing is activated.
Legal basis: Your consent (Art. 6(1)(a) GDPR, and the equivalent provisions of the national laws implementing ePrivacy, LGPD, PIPA, PDPA and PIPEDA/Law 25).
2.2 All Other Countries (Active on Arrival, Switchable Off)
If you visit us from anywhere else, analytics and advertising are active when you arrive, before you interact with any banner. You can switch them off at any time using the "Your Privacy Choices" link in the footer of every page. Your choice is stored and respected on subsequent visits.
Legal basis: Our legitimate interests in understanding how our Site is used and in measuring and optimising our advertising (Art. 6(1)(f) GDPR, where applicable, and the corresponding provisions of other applicable laws). You have the right to object to this processing at any time — using the "Your Privacy Choices" link, or by contacting us at contact@wavealign.app.
We do not claim that consent is obtained from every visitor before tracking begins. It is obtained first only in the countries listed in Section 2.1.
2.3 How We Determine Your Country
To apply the correct regime, we derive your country from the IP address your browser uses to connect to us. Specifically:
- Our hosting provider (Vercel) resolves the IP address to a two-letter country code at the edge
- That two-letter code — and nothing else — is stored in a first-party cookie named
wa-geofor 30 days - The IP address itself is not stored for this purpose
- The country code is used for one purpose only: deciding which consent rules apply to you. It is not used for analytics, advertising, personalisation, pricing, or any other purpose, and it is not shared with anyone
If your country cannot be determined, you are treated as if you were in an opt-in country: nothing loads until you accept.
The wa-geo cookie is strictly necessary — it exists solely to let us comply with the consent law that applies to you, and it is set regardless of your consent choice. Legal basis: Compliance with a legal obligation (Art. 6(1)(c) GDPR) and our legitimate interest in applying the correct legal regime (Art. 6(1)(f) GDPR).
2.4 Desktop Application Consent Is Separate
App analytics consent is managed independently from website consent — the two are not linked, and the country regimes above do not apply to the App. In the App, analytics is off by default everywhere and is only collected after you opt in. Accepting or rejecting cookies on our website has no effect on app analytics, and vice versa.
3. Data We Collect
3.1 Website Analytics (PostHog)
Subject to the consent regime that applies to you (Section 2), we use PostHog to understand how our Site is used.
Anonymous analytics: Operates without cookies or persistent browser storage and collects:
- Page views and navigation: Which pages you visit and how you navigate our Site
- Traffic sources: UTM parameters and referrer information to understand how you found us (e.g., from search engines, social media, or advertising campaigns)
- Device and browser information: Browser type, operating system, screen resolution, and user agent string
- Approximate location: City and country derived from your IP address
- Session data: A temporary, anonymous session identifier that changes daily and cannot identify you across different days or sessions
- Aggregate conversion events: When a purchase completes, an anonymous record of the sale (amount, currency, and campaign source) with no email, no persistent identifier, and no stored IP, used solely to measure marketing effectiveness in aggregate
How it works: PostHog generates a privacy-preserving hash on our servers using your IP address, user agent, and a daily salt that is deleted after processing. This hash cannot be reversed to identify you and changes every day, meaning each day you visit appears as a new anonymous user.
Persistent analytics: Where analytics is active under Section 2, we use persistent tracking, which additionally provides:
- Cross-session identification: Recognition of you across multiple visits to our Site
- User journey tracking: Understanding your behaviour over time
- Advanced analytics: Feature flag assignments, A/B testing, and detailed interaction tracking
- Persistent identifiers: PostHog distinct IDs stored in cookies/local storage
Legal basis: Consent in the countries listed in Section 2.1; legitimate interests, with a right to object, everywhere else.
Information You Provide:
- Email Address: When you contact us, purchase a licence, or sign up for communications
- Marketing Consent: Whether you have provided explicit consent to receive marketing communications
- Server Logs: Our hosting provider automatically collects standard server logs, which may include your IP address, browser type, page requests, and timestamps
3.2 Advertising and Marketing Technologies
We use advertising pixels and cookies from third-party platforms to measure the effectiveness of our marketing campaigns and deliver relevant advertising. These services may collect information about your visit to our website and your interactions with our ads.
When they are activated: In the countries listed in Section 2.1, only after you accept marketing cookies. Everywhere else, on arrival, until you switch them off via "Your Privacy Choices" in the footer.
Platforms we use:
- Meta Pixel & Conversions API (Facebook/Instagram advertising)
- TikTok Pixel & Events API (TikTok advertising)
- Google Tag Manager, which we use to deliver the tags above. Google Tag Manager is loaded only when marketing technologies are active under Section 2
What they collect:
- Your IP address
- A hashed (pseudonymised) version of your email address
- A hashed pseudonymous identifier and ad-platform cookie IDs
- Browser type and version
- Pages you visit on our website
- Whether you arrived from one of our advertisements
- Actions you take on our Site
- Device identifiers and advertising IDs
Campaign and click identifiers: When you arrive from an advertisement, the URL may carry campaign parameters (UTM values) and click identifiers (fbclid, ttclid, gclid, wbraid, gbraid). We capture these on the first page you view so that a later purchase can be attributed to the right campaign. Where the applicable regime does not yet permit storage on your device, the capture is held in memory only for that page session and is written to your device only if and when consent arrives. See the wavealign_attribution entry in Section 7.
How we use this data:
- Measure conversion rates from our advertising campaigns
- Show you relevant ads on Facebook, Instagram, and TikTok
- Create audiences of similar users who might be interested in WaveAlign
- Optimise our advertising spend
Your choices:
- Use the "Your Privacy Choices" link in the footer of our Site
- Opt out of personalised advertising directly with the platforms: Meta (Facebook/Instagram) · TikTok
- Use your browser's tracking-protection settings
3.3 Desktop Application Data Collection
Application Metadata:
- App Version: Retrieved from application initialization
- App Lifecycle Events: When the app starts (
app_opened) and closes (app_closed)
User Interface Interactions:
- Button Clicks: Process button interactions (start/cancel actions), feedback button clicks, settings dialog openings
- Settings Changes: Target loudness adjustments with previous and new values
- Path Selections: Length (character count) of selected input paths, output paths, and backup paths (actual file paths are never collected)
- Dead Click Tracking: Clicks on disabled interface elements for user experience analysis, including element identifiers
Audio Processing Data (Per Track): For each processed audio file, we collect:
- File Extension: .mp3, .wav, .flac, .aiff, .aif — no other information about the processed file
- Loudness Measurements: Original and adjusted loudness values (LUFS), original and adjusted peak values (dB)
- Processing Status: Whether tracks were skipped due to clipping, caching, unsupported format, or processing errors
Technical Data Collected Automatically (via PostHog):
- System Information: Operating system and version, browser engine details, device type
- Network Data: approximate geographic location (city, country, timezone) derived from your IP address. We have configured PostHog to not retain IP addresses — the IP is used transiently at ingestion to derive the approximate location and is then discarded, so it is not stored with your events
- Display Information: Screen resolution and viewport/window dimensions
- Session Data: Pseudonymous session and device identifiers for analytics correlation
- Library Information: PostHog SDK version and configuration details
Privacy Safeguards in Desktop App:
- Only file extensions are collected, never full file paths or file names
- Only path lengths are collected, not actual directory structures
- Identifiers are pseudonymous (randomly generated, not personally identifiable)
- Geographic data is approximate (city-level, derived from IP address)
- Data collection is limited to supported audio formats only
- Analytics collection is optional and can be disabled at any time in the application settings
License Activation (Polar) — independent of analytics consent: To activate your license and enforce the per-device limit, the App transmits the following to Polar Software, Inc. (United States):
- License Key
- Device fingerprint: a pseudonymous SHA-256 hash derived from your device's hardware identifier. Where no hardware identifier is available, this value is left empty.
Purpose and legal basis: performance of the license contract (Art. 6(1)(b) GDPR). This processing occurs regardless of your analytics choice. For license enforcement Polar acts as our processor; for the purchase transaction Polar acts as Merchant of Record and as an independent controller (see Section 6). Transfers to the United States are based on the EU Standard Contractual Clauses (Art. 46 GDPR).
Update Check (Vercel): At launch, the App fetches a version manifest from Vercel Inc. (United States), which discloses your IP address to Vercel as a necessary consequence of the connection. No further data is transmitted, and no update is installed without your confirmation.
Purpose and legal basis: keeping the App functional and up to date (Art. 6(1)(b) GDPR). The transfer is covered by Vercel's certification under the EU-US Data Privacy Framework (Art. 45 GDPR) and, additionally, the Standard Contractual Clauses.
Data Stored Locally on Your Device (never uploaded to us):
- Settings (your preferences)
- License state (your license key and activation identifier, in obfuscated form)
- Processing cache — includes file paths and may contain your operating-system username; retained until you clear it in Settings
- Session log files — include file paths and error details; up to 100 files retained on a rolling basis, deletable in Settings
This data stays on your device and is not transmitted to us or any third party.
4. Server-Side Sharing With Advertising Platforms
Separately from the pixels in your browser, our server sends conversion data directly to Meta and TikTok after you complete a purchase. This is a server-to-server transmission. It does not involve your browser, and it is therefore not visible to, and not blocked by, browser-based ad blockers, tracking protection, or extensions. We describe it here in its own right so that you can see exactly what leaves our systems.
When it happens: after a completed purchase, triggered by the payment confirmation from Polar.
What we send to Meta and TikTok:
- Your email address, hashed (SHA-256; the platforms receive the hash, not the address)
- A hashed pseudonymous user identifier (our internal analytics identifier, hashed)
- Your IP address
- Your browser user agent
- Advertising click identifiers and ad-platform cookie values (e.g.
_fbc,_fbp,_ttp,ttclid) - The order value, the currency, and the page URL the checkout was started from
The purpose is conversion measurement and attribution: matching the purchase to the advertisement that led to it, deduplicated against the browser-side event for the same order.
Whether it happens depends on your consent regime (Section 2): in the countries listed in Section 2.1 this transmission occurs only if you accepted marketing; elsewhere it occurs unless you have switched marketing off via "Your Privacy Choices". Your choice is captured at checkout and applied to the transmission. See Section 8 for your opt-out rights under US state law, where this sharing constitutes a "sale"/"share".
Recipients: Meta Platforms Ireland Ltd. and Meta Platforms, Inc. (United States); TikTok Technology Limited and its affiliates (United States, see Section 13).
5. How We Use Your Data (Purpose and Legal Basis)
5.1 Website Data Usage
To Analyse Site Usage, Measure Marketing Effectiveness, and Improve the Site:
- Purpose: Understand website traffic patterns, measure effectiveness of marketing campaigns (including UTM parameters from advertising sources), identify popular content, and optimise website performance, including measuring completed-purchase conversions.
- Legal Basis: Consent (Art. 6(1)(a) GDPR) for visitors in the countries listed in Section 2.1; legitimate interests, with a right to object, for all other visitors.
To Deliver and Measure Advertising:
- Purpose: Conversion tracking, remarketing, audience building, and optimisation of our advertising spend on Meta and TikTok.
- Legal Basis: Consent (Art. 6(1)(a) GDPR) for visitors in the countries listed in Section 2.1; legitimate interests, with a right to object, for all other visitors. For visitors in US states with applicable privacy laws, see Section 8.
To Apply the Correct Consent Rules:
- Purpose: Determine, from your IP-derived country code, which consent regime applies to you (Section 2.3).
- Legal Basis: Compliance with a legal obligation (Art. 6(1)(c) GDPR) and legitimate interests (Art. 6(1)(f) GDPR).
To Send You Marketing Communications:
- Purpose: Inform you about WaveAlign updates and send marketing information
- Legal Basis: Your explicit consent, obtained through the signup form.
To Inform Purchasers About the Product They Bought:
- Purpose: When you purchase a licence, we add your email address to our customer list at Brevo so that we can send you product information, updates and offers relating to WaveAlign. This happens for every purchase, including where you did not give marketing consent.
- Legal Basis: Our legitimate interest in direct marketing to existing customers for our own similar products, as permitted for existing customers under § 7(3) UWG (Germany) and the equivalent "soft opt-in" provisions of Art. 13(2) of the ePrivacy Directive as implemented in other EEA states and the UK.
- Your right to object: You can object to this at any time, at no cost beyond basic transmission rates, by using the unsubscribe link in any email or by contacting contact@wavealign.app. We tell you about this right when we collect your address and in every message we send.
5.2 Desktop Application Data Usage
To Improve Application Performance and User Experience:
- Purpose: Understand how users interact with the application, identify usability issues, measure feature effectiveness, and optimise the user interface
- Legal Basis: Your explicit Consent (Art. 6(1)(a) GDPR), obtained through the in-application analytics consent prompt. Analytics is off by default and the App is fully functional without it
To Enhance Audio Processing Features:
- Purpose: Analyse processing patterns, identify common issues, improve audio processing algorithms, and ensure compatibility with various audio formats
- Legal Basis: Your explicit Consent, obtained through the in-application analytics consent prompt
To Provide Technical Support:
- Purpose: Diagnose technical problems, understand error patterns, and improve application stability
- Legal Basis: Your explicit Consent (Art. 6(1)(a) GDPR), obtained through the in-application analytics consent prompt
5.3 Shared Purposes (Website and Desktop App)
For Security and Troubleshooting:
- Purpose: Monitor for and prevent fraudulent or malicious activity, diagnose technical problems, and maintain security
- Legal Basis: Our Legitimate Interest in protecting our services and business operations
To Comply with Legal Obligations:
- Purpose: Comply with applicable laws, regulations, and legal processes
- Legal Basis: Compliance with a legal obligation
6. How We Share Your Data (Recipients)
We share your personal data with the third parties below. Processors are bound by data processing agreements and act only on our instructions.
- PostHog, Inc. — PostHog Cloud EU (Frankfurt, Germany). Role: processor. Receives: website and app usage data, identifiers, event information.
- Meta Platforms Ireland Ltd. / Meta Platforms, Inc. — Ireland / United States. Role: independent controller (joint controller with us for the collection via the pixel). Receives: pixel data and server-side conversion data (Section 4).
- TikTok Technology Ltd. and affiliates — Ireland / United States. Role: independent controller (joint controller with us for the collection via the pixel). Receives: pixel data and server-side conversion data (Section 4).
- Sendinblue GmbH / Brevo — Germany / France. Role: processor. Receives: email address, marketing consent status, campaign attributes.
- Polar Software, Inc. — United States. Role: processor for licence activation; Merchant of Record and independent controller for purchases. Receives: licence key, pseudonymous device fingerprint; purchase and payment data.
- Vercel Inc. — United States. Role: processor (hosting). Receives: website requests, server logs, IP address; App update-check requests.
- Google (Google Tag Manager) — Ireland / United States. Role: processor (tag delivery). Receives: the loading of the Meta and TikTok tags, and the data those tags read, where marketing technologies are active.
PostHog: All analytics data is hosted on PostHog Cloud EU (AWS data centre, Frankfurt, Germany), and we have disabled IP-address retention, so events are stripped of IP-derived personal data on ingestion. PostHog performs website analytics, A/B testing and feature-flag management, and application usage analytics (desktop app data only if you have consented in the application settings).
Brevo: We share your email address, marketing consent status and campaign attributes with Brevo to manage our email contact list and send communications (website only). See Section 5.1 for the two grounds on which addresses reach this list.
Polar: Polar serves two roles. (1) Licence activation/enforcement — the desktop App transmits your licence key and pseudonymous device fingerprint to Polar to enforce the per-device limit; here Polar acts as our processor under a data processing agreement (Art. 28 GDPR). (2) Purchases — licence purchases are processed by Polar as Merchant of Record and independent controller; we do not directly handle or store your payment information, and Polar (with its payment subprocessor Stripe) processes payment data under its own privacy policy. Privacy Policy
Vercel: Our Site is hosted on Vercel, which processes and stores server logs as necessary to operate the Site, and which resolves your IP address to a country code at the edge (Section 2.3). The desktop App's update check also reaches Vercel.
Meta and TikTok: See Section 3.2 (browser pixels) and Section 4 (server-side sharing). Meta Privacy Policy · TikTok Privacy Policy
Except as described in Section 8 for US state privacy law — under which our sharing with Meta and TikTok for targeted advertising counts as a "sale"/"share" — we do not sell your personal data. We may also disclose your data if required by law or in response to valid requests by public authorities.
7. Cookies and Storage
7.1 What We Store on Your Device
wa-geo— Cookie. Purpose: determines which consent rules apply. Retention: 30 days.user-consent— localStorage. Purpose: stores the visitor's choice. Retention: until cleared.wavealign_attribution— localStorage. Purpose: campaign and click identifiers — written only after consent; held in memory until then. Retention: 90 days._fbc,_fbp,_ttp— Cookies. Purpose: Meta/TikTok attribution, loaded via Google Tag Manager after marketing consent. Retention: per vendor.
wa-geo and user-consent are strictly necessary: the first tells us which law to apply, the second remembers what you chose. They are set regardless of your consent choice and are used for nothing else.
PostHog's persistent analytics identifiers are stored in cookies/local storage only where analytics is active under Section 2. Anonymous analytics operates without cookies or persistent browser storage.
7.2 Managing Your Choices
- "Your Privacy Choices" in the footer of every page re-opens your consent settings. This is the single place to grant, change or withdraw analytics and marketing permissions, and it is the opt-out mechanism referred to in Section 8
- Your browser settings can block or clear cookies and site data (this may limit functionality)
- Clearing your browser storage removes
user-consent, which resets you to the default state for your country under Section 2
Withdrawing consent does not affect the lawfulness of processing carried out before the withdrawal.
7.3 Desktop Application Analytics
The desktop application uses PostHog for optional analytics. Analytics collection is disabled by default and requires your explicit consent through the in-application consent prompt on first launch. You can change your analytics preference at any time in the application settings.
This consent is entirely separate from the website — accepting cookies on the website does not enable app analytics, and enabling app analytics does not affect your website preferences.
When analytics are enabled:
- capture_pageview: Disabled (no automatic page view tracking)
- Data Collected: System information, usage events, and geographic data as described in Section 3.3
- Identifiers: Pseudonymous session and device identifiers for analytics correlation
When analytics are disabled, no usage data is transmitted from the application.
8. Notice to US Residents (California, Colorado, Connecticut, Virginia, Texas and Other States)
Notice at collection. When you visit our Site, we collect the categories of personal information described in Section 3 — identifiers (including IP address, hashed email address, and pseudonymous and advertising identifiers), internet and network activity (pages viewed, referrer, interactions), approximate geolocation derived from IP address, device and browser characteristics, and commercial information (purchase value and currency). We collect it for the purposes set out in Section 5 and retain it as described in Section 9. We do not collect sensitive personal information for the purpose of inferring characteristics, and we do not knowingly collect personal information from anyone under 16.
Sale and sharing. Our disclosure of personal information to Meta and TikTok for targeted advertising — both through the browser pixels (Section 3.2) and through the server-side transmission after a purchase (Section 4) — constitutes a "sale" and a "share" for cross-context behavioural advertising under the California Consumer Privacy Act as amended by the CPRA, and targeted advertising / a sale of personal data under the Colorado Privacy Act, the Connecticut Data Privacy Act, the Virginia Consumer Data Protection Act and the Texas Data Privacy and Security Act. We do not sell personal information for money.
Your right to opt out. You have the right to opt out of this sale/sharing and of targeted advertising. To exercise it:
- Use the "Your Privacy Choices" link in the footer of every page on our Site and switch marketing off. This is our designated opt-out mechanism; no account and no verification is required
- Or email us at contact@wavealign.app
Other rights. Depending on your state, you also have the right to know/access the personal information we hold about you, the right to correct it, the right to delete it, the right to a portable copy, the right to limit the use of sensitive personal information (we do not use it for purposes requiring this right), and the right to appeal a refusal of a request. Contact us at contact@wavealign.app; see Section 12 for how requests are handled. You may use an authorised agent, and we may ask for confirmation of their authority.
Non-discrimination. We will not discriminate against you for exercising any of these rights. We will not deny you our products or services, charge you a different price, impose penalties, or provide a different level or quality of service because you opted out or made a privacy request.
9. Data Retention
Email Address and Marketing Consent: Retained in Brevo while you remain on our contact list — that is, until you unsubscribe, object, or ask us to delete your address — unless a longer retention period is required by law. Records of purchases are additionally retained for the statutory commercial and tax retention periods (up to 10 years under German law).
Website and Desktop Application Analytics Data: Retained by PostHog for up to one (1) year, after which it is deleted. Because IP addresses are not retained (see Section 6), the stored analytics data does not identify you. You can request deletion of your application analytics data at any time by contacting us, subject to the limitation noted in Section 12.2.
Consent and Country Signals: wa-geo expires after 30 days; user-consent remains until you clear it; wavealign_attribution expires after 90 days (see Section 7.1).
Audio Processing Data: Aggregated and anonymised processing statistics may be retained to improve our algorithms. Individual track data is not linked to personal identifiers.
Payment Records: Transaction records are retained by Polar.sh in accordance with their privacy policy and applicable legal retention requirements.
10. Data Security
We have implemented appropriate technical and organizational security measures designed to protect your personal data from accidental loss and unauthorized access, use, alteration, and disclosure. However, no method of transmission over the Internet or electronic storage is 100% secure.
Desktop Application Security: Analytics data from the desktop application is transmitted using secure protocols and encrypted in transit.
In the event of a personal data breach, we will notify affected individuals and regulators as required by applicable law.
11. Your Data Protection Rights
For Users in the European Economic Area (EEA), UK, and Switzerland: Under the General Data Protection Regulation (GDPR), you have the following rights regarding your personal data:
- Right to Be Informed — Know what data we collect and how we use it
- Right to Access — Request a copy of the personal data we hold about you
- Right to Rectification — Ask us to correct inaccurate data
- Right to Erasure — Request deletion of your data ("right to be forgotten")
- Right to Restrict Processing — Ask us to limit how we use your data
- Right to Data Portability — Receive your data in a portable format
- Right to Object — Object to processing based on legitimate interest or direct marketing. Where we rely on legitimate interests (Section 2.2 and Section 5.1), you may object at any time, and for direct marketing we will always stop
- Right to Withdraw Consent — Withdraw consent for marketing or analytics at any time without affecting the lawfulness of prior processing
- Right to Lodge a Complaint: If you believe your data protection rights have been violated, you have the right to lodge a complaint with a data protection authority. Our competent supervisory authority is:
- Germany (our authority): Landesbeauftragte für Datenschutz und Informationsfreiheit Nordrhein-Westfalen (LDI NRW)
- Other EU countries: you may also complain to the authority in your country of residence — find your local authority
For users in Brazil, South Korea, Thailand and Canada: you have comparable rights under the LGPD, PIPA, the PDPA and PIPEDA (and, in Quebec, Law 25), including access, correction, deletion, and withdrawal of consent. Contact us at contact@wavealign.app.
For users in the United States: see Section 8.
Automated decision-making: We do not carry out any automated decision-making producing legal or similarly significant effects within the meaning of Art. 22 GDPR.
12. How to Exercise Your Rights
To exercise your rights or withdraw consent, contact us at contact@wavealign.app.
12.1 Website Consent Management
Change or withdraw analytics and advertising permissions: Click "Your Privacy Choices" in the footer of any page. This works in every country: in opt-in countries it re-opens the banner, and in opt-out countries it is how you switch tracking off.
You can also:
- Clear your browser cookies and site data and refresh the page
- Contact us at contact@wavealign.app and we will action your choice manually
- Opt out directly with the advertising platforms: Meta · TikTok
Withdraw Marketing Consent / object to customer emails: Click the "unsubscribe" link in any marketing email or contact us directly.
12.2 Desktop Application Consent Management
You can enable or disable analytics collection at any time through the application settings. When you disable analytics, data collection stops immediately and no further usage data is transmitted.
To request access to, correction of, or deletion of any personal data already collected through the application, contact us at contact@wavealign.app.
Please note: the application analytics data is pseudonymous and contains no identifier we can link back to you (Art. 11 GDPR). We may therefore be unable to locate your specific records in response to an access or erasure request, although we will assist where you can provide information that enables identification.
13. International Data Transfers
Some of our service providers are located outside the EU/EEA (primarily in the United States). Where that is the case, we ensure an appropriate safeguard under Chapter V GDPR for each transfer:
- PostHog (analytics): hosted on PostHog Cloud EU (Frankfurt, Germany) — analytics data is not transferred to a third country.
- Brevo (email): hosted in the EU (Germany/France) — no third-country transfer.
- Meta, United States (browser pixels and server-side Conversions API, see Sections 3.2 and 4): EU-US Data Privacy Framework certification (Art. 45 GDPR) and, additionally, the EU Standard Contractual Clauses.
- TikTok, United States (browser pixels and server-side Events API, see Sections 3.2 and 4): EU Standard Contractual Clauses (Art. 46 GDPR), supplemented by the transfer measures described in TikTok's privacy policy.
- Google (Tag Manager), United States: EU-US Data Privacy Framework certification (Art. 45 GDPR) and Standard Contractual Clauses.
- Polar (licence activation and payment), United States: EU Standard Contractual Clauses (Art. 46 GDPR).
- Vercel (hosting and update service), United States: EU-US Data Privacy Framework certification (Art. 45 GDPR) and Standard Contractual Clauses.
You may request a copy of the relevant Standard Contractual Clauses by contacting us at contact@wavealign.app.
14. Changes to This Policy
We may update this Privacy Policy periodically. Changes will be published on this page with a revised "Last Updated" date. For significant changes, we will also notify desktop application users through the application itself. We encourage you to review this page regularly.
15. Contact Us
If you have questions about this policy or want to exercise your data rights, contact us:
Brehm, Osipovs & Zimmermann Software GbR Birkenstr. 111 40233 Düsseldorf Germany
Email: contact@wavealign.app
If you want to change your cookie preferences or see the consent banner again, you can do so here: