Skip to content
Skip to content

Wennov Connect

Privacy policy

Last updated: August 2026. How we collect, use, and protect personal data in Wennov Connect.

1. WHO WE ARE AND OUR TWO ROLES

Glo Wennov SRL, headquartered in Bucharest, Romania, is the company operating the Wennov Connect platform. "Wennov Connect" is the platform’s commercial name, not a separate company: every obligation described in this document rests with Glo Wennov SRL. Contact: office@wennov.ro.

We process personal data in two distinct roles, and your rights differ depending on which one applies:

  • As CONTROLLER – for data about our own customers and website visitors: account holders, their users, billing contacts and visitors. We decide the purposes and means of this processing.
  • As PROCESSOR – for the contact data our customers upload and the messages they send through the platform (phone numbers, email addresses, names, custom fields, message content, delivery results). Here our customer is the controller and we act only on their documented instructions under a Data Processing Agreement (see /dpa).

IF YOU RECEIVED A MESSAGE sent through Wennov Connect and want your data erased or corrected, or want the communications to stop: your request goes to the business that contacted you, because that business is the controller of your data. You may write to us at office@wennov.ro and we will forward the request to our customer and assist them in handling it, but we cannot decide on that data ourselves. To stop SMS immediately, reply STOP.

2. DATA WE PROCESS AS CONTROLLER

- Identification data: name, work email address, phone number. - Account and security data: password stored as a hash, two-factor authentication status, active sessions, login records (IP address, approximate country/city derived from IP, browser, device). - Billing data: company details, VAT ID, address, payment history, invoices. - Usage data: features used, campaigns created, volumes sent, API usage. - Correspondence with our support team.

3. DATA WE PROCESS ON BEHALF OF CUSTOMERS (AS PROCESSOR)

- Contact records: phone number, email, name, tags, custom fields, consent and opt-out status. - Message content and metadata: message body, sender, recipient, timestamps, delivery status, error codes, replies received. - Engagement data: opens, clicks, replies, and scores computed for the customer.

We do not use this data for our own purposes, do not sell it, and never use it to build our own marketing lists.

4. PURPOSES AND LEGAL BASIS (CONTROLLER ROLE)

- Contractual service delivery: performance of contract (Art. 6(1)(b) GDPR) - Billing and fiscal compliance: legal obligation (Art. 6(1)(c) GDPR) - Operational security, fraud and abuse prevention: legitimate interest (Art. 6(1)(f) GDPR) - Marketing to prospects and analytics/marketing cookies: consent (Art. 6(1)(a) GDPR, withdrawable at any time)

5. SUBPROCESSORS AND RECIPIENTS

Depending on the channels and integrations a customer enables, data may be processed by:

- Cloud infrastructure providers (EU/EEA) – hosting, databases, backups - SMPP aggregators and CPaaS providers (for example Infobip, Twilio) – SMS and Voice delivery - Meta Platforms – WhatsApp, Messenger and Instagram messaging - Telegram, Viber, Google (RCS) – where those channels are enabled - Amazon SES / SMTP providers – email delivery - Stripe, Netopia – payment processing; FGO – invoicing - Anthropic PBC (USA) – AI-assisted features (see section 9) - Sentry – error monitoring; MaxMind – approximate IP-based location for login security - Google Analytics and Meta Pixel – on the public website only, and only with cookie consent - Competent authorities, where legally required

We do not sell data to third parties. We give advance notice before adding a new subprocessor that handles customer data, and customers may object under the terms of the DPA.

6. INTERNATIONAL TRANSFERS

Some of the providers above – in particular Anthropic, Stripe, Twilio, Sentry, MaxMind, Google and Meta – process data in the United States or other countries outside the EEA. These transfers rely on the European Commission Standard Contractual Clauses, on EU-US Data Privacy Framework certification where applicable, and on supplementary safeguards (encryption in transit, minimisation of the data transmitted).

7. RETENTION PERIODS

The periods below reflect how the platform is actually configured:

- Campaign messages: 60 days after sending - Individual/direct messages: 30 days - Send tracking records: 60 days - Message composer history: 180 days - Delivery events: up to 90 days - Security audit logs: 365 days - Sign-in records (IP, browser, approximate country/city): 365 days - Routing logs: 60 days; API key usage logs: 30 days - Application technical logs: 30 days - Contact records: until the customer deletes them or closes the account - Account data: contract duration + 3 years (limitation period) - Billing documents: 10 years (Romanian fiscal/accounting obligation)

If you need longer periods for your own compliance obligations, export the data from the platform before the periods above expire.

8. SECURITY

We apply: encryptio

Contact

Tell us your use case and we will recommend the best setup.

Email: office@wennov.ro

Phone: +40 731 177 744

Location: București, România