Privacy

WOWL ensures GDPR compliance with robust data protection practices, secure processing, and privacy safeguards. Learn about our encryption standards, Data Protection Officer role, and commitment to safeguarding EU and EEA personal data.

GDPR Compliance Policy

Policy Owner: Senior Systems Architect

Effective Date: February 1, 2025

Application

This policy applies to all employees, contractors, and vendors doing business with wowl.io and others who access European Union (EU) and European Economic Area (EEA) data subject information (“personal data”) in connection with wowl.io’s operating activities.

Policy

wowl.io is committed to protecting the security, confidentiality, and privacy of its information resources, including EU and EEA personal data, in accordance with the General Data Protection Regulation (GDPR).

Key principles include:

1. Legal Basis: Personal data will only be processed when legally justified.

2. Data Security: Ensuring confidentiality, integrity, and security of personal data.

3. Responsible Use: Data is only used for authorized purposes.

Roles and Responsibilities

Policy Adoption

wowl.io, in collaboration with stakeholders, adopts GDPR Policies that define safeguards and ensure compliance. These include technical, physical, and administrative controls.

Responsible Persons

Overall Oversight: Jonathan Chuang, Senior Systems Architect (jonathan@wowl.io)

Data Protection Officer (DPO): Oversees daily GDPR compliance, provides guidance, and acts as the contact for supervisory authorities.

Article 27 Representative

EU Representative: Isaac Fung, Director of Global Strategy (isaac@wowl.io, UK)

UK Representative: Isaac Fung, Director of Global Strategy

Implementation

Data Protection

• Legal basis required for all processing.

• Encryption for data storage and transmission.

• Secure disposal of paper and electronic media.

Training

Personnel will receive training on GDPR responsibilities, including handling data subject access requests (DSAR).

Third-Party Data Transmission

Data transmission to third parties requires a fully executed Data Protection Addendum.

Breach Notification

Reportable incidents will follow GDPR notification requirements and wowl.io’s Incident Response Policy.

Data Subject Access Requests (DSAR)

Data subjects have rights under GDPR, including access, rectification, erasure, and more. Requests can be made via:

Privacy Page

• Email: privacy@wowl.io

Requests will be logged, and responses provided within 25 days.

Enforcement


Failure to comply may result in disciplinary action. Report violations to privacy@wowl.io.

Version History

Version 1.0 (February 1, 2025): Initial Policy by Jonathan Chuang

img

The WOWL Newsletter