Privacy Policy
Data controller: Plenvar Labs SRL
1. Who is responsible for your data (controller)
Plenvar Labs SRL ("Contwave", "we") operates the Contwave platform and is the data controller for the personal data described in §3 below, except where we act as a processor on behalf of a Client (see §2).
-
Registered office: Str. Anghelești nr. 5, Municipiul Curtea de Argeș, Județul Argeș, Romania
-
Trade Register no.: J2026042747008 · CUI: 55123337
-
Email (general): privacy@contwave.com
-
Privacy / data protection contact: privacy@contwave.com
Based on our current processing activities, we consider that the appointment of a Data Protection Officer (DPO) is not mandatory under Article 37 GDPR: our current processing does not consist of activities that require the mandatory designation of a DPO under applicable law. We will periodically review this assessment as our processing activities evolve (for example, if large-scale behavioural tracking is introduced). A privacy contact point — privacy@contwave.com — is provided regardless.
2. Controller vs processor — two different roles
Contwave processes personal data in two distinct capacities:
2.1. As controller — for data relating to: our Client account holders and their authorised users; visitors to contwave.com; prospects and leads who contact us; and our own business operations. For this data, this Privacy Policy applies.
2.2. As processor — where we process personal data on behalf of a Client (for example, the Client's own marketing contacts, audiences, or end-user data handled through the Platform). In that case the Client is the controller, the Client is responsible for providing any required privacy information notice to data subjects, and our processing is governed by a Data Processing Agreement (DPA) under Article 28 GDPR. This Privacy Policy describes our own controller processing, not the Client's.
3. What personal data we collect (as controller)
-
Account & identification data: name, business email, role, company, credentials/authentication data.
-
Usage & technical data: log data, IP address, device/browser information, actions in the Platform, diagnostics.
-
Communications: messages, support requests, and correspondence with us.
-
Prospect/marketing data: contact details of business prospects who engage with us, and (where consent is given) newsletter subscribers.
-
Billing data: information necessary to administer Subscriptions (processed largely by our payment processor; we do not store full card data).
-
Cookies and similar technologies: see §7.
Sources. Most personal data is collected directly from you. Some prospect data may be obtained from publicly available business sources or referrals, and — where Contwave acts as processor — audience or end-user data is provided by the Client (controller). Where we act as a processor on behalf of a Client, personal data relating to the Client's audiences, contacts or end users is provided by the Client acting as controller; such processing is governed by the Data Processing Agreement (DPA) and is not covered by this section except where expressly stated. Where we obtain personal data other than directly from you, we provide the information required by Article 14 GDPR.
We do not intentionally collect special categories of data, through our own controller activities the Platform is not directed at consumers or children (see §13).
4. Why we process it and our legal bases (Article 6 GDPR)
| Purpose | Legal basis |
|---|---|
| Providing and administering the Platform and accounts | Performance of a contract — Art. 6(1)(b) |
| Security, fraud prevention, service integrity, diagnostics | Legitimate interests — Art. 6(1)(f) |
| Billing, accounting, tax and legal record-keeping | Legal obligation — Art. 6(1)(c) / contract |
| Responding to enquiries and support | Contract where related to the provision of services/ legitimate interests |
| Direct marketing by electronic means (email, newsletters) | Prior consent (opt-in) — Art. 6(1)(a) GDPR and Art. 12(1) of Law no. 506/2004, which requires prior express consent for commercial communications unless a specific legal exception applies. A narrow "soft opt-in" exception (Art. 12(2)) allows emailing our own existing customers about similar products, with an easy free opt-out at collection and in every message |
| Product improvement using aggregated/anonymised data | Legitimate interests — Art. 6(1)(f) |
Where we rely on consent, you may withdraw it at any time (§12); withdrawal does not affect prior lawful processing.
5. AI processing and automated content generation
5.1. The Platform uses artificial intelligence to generate and assist in creating Content. AI processing for Content generation generally operates on Client-supplied briefs and brand inputs, not on the personal data of unrelated individuals. Where personal data is processed in connection with Client inputs or Content, such processing may be carried out on behalf of the Client in accordance with the Data Processing Agreement (DPA).
5.2. We do not use your personal data to make decisions producing legal or similarly significant effects on you by solely automated means within the meaning of Article 22 GDPR. Where any such processing were introduced, we would provide the required information and safeguards.
5.3. AI-generated Content including synthetic media where applicable, may be subject to transparency obligations under applicable law, including Article 50 of the EU AI Act. Contwave provides software functionality and information intended to support applicable transparency requirements; however, the Client remains responsible for reviewing, approving and using AI-generated Content in compliance with applicable legal and regulatory requirements.
6. Who we share data with (recipients and sub-processors)
We share personal data only as necessary, with the following categories of recipients and sub-processors:
| Sub-processor | Function | Status |
|---|---|---|
| Supabase | Hosting, database and authentication (core infrastructure) | In use |
| Railway | Application/back-end hosting (processes data in transit) | In use |
| Vercel | Front-end / dashboard hosting and serverless functions | In use |
| Anthropic | AI text/copy generation | In use |
| OpenAI | AI text generation | In use |
| HeyGen | AI video / avatar generation | In use |
| ElevenLabs | AI voice / narration | In use |
| Resend | Transactional and email delivery (processes email addresses) | In use |
| DataForSEO | Trend/keyword data (operates on non-personal query data) | In use |
| Fal.ai | AI video generation (processes images and other content provided by the client) | In use |
| Google / Gemini | AI image generation (processes images and other content provided by the client) | In use |
| Calendly | Meeting scheduling and appointment booking (processes contact details of individuals who book a meeting) | In use |
Where these providers process Client Personal Data on behalf of a Client, they act as sub-processors under the applicable Data Processing Agreement. Where they process Contwave's own data, they act as processors or service providers engaged by Contwave as controller, as applicable.
In addition, advertising and social platforms (including Meta, Google/YouTube, TikTok, LinkedIn and X) act as recipients where the Client connects its own accounts — those accounts are controlled by the Client, not by Contwave. We may also share data with professional advisers and competent authorities where required by law.
The Client remains responsible for its own accounts, audiences and compliance with the terms and policies applicable to such third-party platforms.
Each sub-processor acting on behalf of Contwave is engaged under written terms imposing appropriate data-protection obligations consistent with Article 28 GDPR. An up-to-date list of sub-processors is available on request at privacy@contwave.com. We may update our sub-processors as the Platform evolves; material changes to the sub-processor list will be notified by reasonable means, and you may raise an objection, in accordance with the applicable Data Processing Agreement.
To reduce third-party data exposure, the Platform self-hosts web fonts and avoids unnecessary third-party calls in published outputs where feasible.
YouTube API Services
Where a Client connects a YouTube channel, the Platform uses YouTube API Services. By connecting a channel you agree to the YouTube Terms of Service; Google's handling of your data is described in the Google Privacy Policy. Through the connection the Platform obtains an OAuth refresh token, the channel's name, and — for videos published through the Platform — daily performance statistics (views, likes, comments, shares, watch time) and the channel's subscriber count. This data is stored on our servers (see sections 6 and 8 for hosting and transfers), is refreshed daily for 30 days after publication, is shown only to members of the Client's organisation, and is not shared with any other party. You can revoke the Platform's access at any time from Settings → Integrations (which also deletes the stored token and the collected statistics) or via the Google security settings page.
7. Cookies and similar technologies
7.1. We use cookies and similar technologies in two categories: - Strictly necessary cookies — required for the Platform to function (e.g. authentication, session, security, load balancing). These are exempt from the consent requirement under the ePrivacy regime, because they are strictly necessary to provide the service you request. - Optional cookies (analytics and preferences) — set only with your prior consent, to understand usage and improve the Platform.
7.2. This reflects the ePrivacy regime and Law no. 506/2004. Today we set no optional cookies: our website uses only strictly necessary cookies together with a cookieless traffic measurement, so no consent banner is presented. If we introduce optional cookies or similar technologies, we will ask for your prior consent beforehand, and you will be able to give, refuse or withdraw it at any time. Refusing optional cookies does not affect access to the core Platform.
7.3. Some cookies may be provided by third-party service providers used by the platform, where necessary for the functionality of the relevant service (for example, authentication or payment-related services). Such providers do not use these cookies for their own purposes on behalf of Contwave unless otherwise disclosed.
8. International transfers
Where personal data is transferred outside the EEA (for example, to a US-based processor), we rely on an appropriate safeguard under Chapter V GDPR: - for providers certified under the EU-US Data Privacy Framework (DPF), the European Commission's adequacy decision of July 2023; and/or - the European Commission's Standard Contractual Clauses (SCCs), which we also maintain as a fallback safeguard, together with supplementary measures where needed.
Details of the safeguard applicable to a given transfer are available on request.
Where we process Client Personal Data as a processor, the applicable transfer mechanism is addressed in the Data Processing Agreement (DPA), including the relevant sub-processors and safeguards.
9. How long we keep data (retention)
We keep personal data only as long as necessary for the purposes above. Our standard periods are:
-
Account and contract data — for the duration of the contract and for up to 3 years thereafter (the general limitation period for civil claims under Article 2517 of the Romanian Civil Code), so that we can establish, exercise or defend legal claims;
-
Invoices and supporting accounting documents (documente justificative, registre de contabilitate) — 5 years, calculated from 1 July of the year following the financial year in which they were drawn up, as required by Article 25 of the Romanian Accounting Law no. 82/1991 (as amended by Law no. 36/2023); this also aligns with the 5-year fiscal limitation period;
-
Annual financial statements — 10 years, as required by the Accounting Law (entity-level records);
-
Marketing data — until consent is withdrawn or the data is no longer relevant, reviewed periodically;
-
Compliance and content audit trail (content generation, compliance flags and warnings, approvals, overrides and publication decisions) — retained for the duration of the contract and up to 3 years thereafter, to preserve evidence of the parties' decisions for the applicable limitation period (see Terms of Service §6.6);
-
Logs and technical diagnostics — typically 6 to 12 months, retained on the basis of our legitimate interest in security and service integrity.
Where we process Client Personal Data as a processor, retention and deletion are governed by the Data Processing Agreement (DPA) and the Client's instructions.
After the applicable period, data is deleted or anonymised. These periods are based on our current legal and operational requirements and may be updated where required by applicable law or changes to our processing activities.
10. Security
We apply appropriate technical and organisational measures to protect personal data, including access controls, encryption in transit, credential management and least-privilege practices. Further details of the technical and organisational measures applicable to Client Personal Data processed on behalf of Clients are described in the Data Processing Agreement (DPA). No system is perfectly secure; we work to continuously improve our safeguards and to handle any breach in accordance with Articles 33–34 GDPR.
11. Your rights under the GDPR
Subject to the conditions set out in the GDPR, you have the right to: access your data (Art. 15); rectification (Art. 16); erasure (Art. 17); restriction of processing (Art. 18); data portability (Art. 20); object to processing based on legitimate interests or to direct marketing (Art. 21); and not to be subject to solely automated decisions producing legal/significant effects (Art. 22). Where processing is based on consent, you may withdraw consent at any time, without affecting the lawfulness of processing carried out before withdrawal.
To exercise your rights, contact us at privacy@contwave.com. We respond within the time limits set by the GDPR (generally one month).
12. Right to lodge a complaint
If you believe your data protection rights have been infringed, you may lodge a complaint with the Romanian supervisory authority:
Autoritatea Națională de Supraveghere a Prelucrării Datelor cu Caracter Personal (ANSPDCP) - Address: B-dul G-ral Gheorghe Magheru nr. 28-30, Sector 1, 010336 București, Romania - Phone: +40 31 805 9211 - Email: anspdcp@dataprotection.ro · Website: www.dataprotection.ro
You may also seek a judicial remedy in accordance with applicable law. If you are located in another EEA country, you may contact your local supervisory authority.
13. Children
The Platform is a business-to-business service, is not directed at children, and we do not intentionally collect or knowingly process the personal data of minors.
14. Changes to this policy
We may update this Privacy Policy from time to time to reflect changes in our processing activities, legal requirements or the Platform. Material changes will be notified by reasonable means, and the "last updated" date will be revised. Continued use after the effective date constitutes acknowledgement of the updated Privacy Policy.
15. Contact
Questions about this policy or your data: privacy@contwave.com.