1. Who we are and how to contact us
This Policy explains how WCODE SOLUTIONS, LDA, with registered office at Av. do Atlântico, no. 16, Office 2.01, 1990-019 Lisbon, Portugal, legal person identification number 518656284, trading under the Wisiex brand ("Wisiex"), processes personal data in connection with the wisiex.com website ("Site"), professional contacts and the services described here.
For privacy matters and the exercise of rights, email [email protected], call +351 21 781 6010 or write to our registered office for the attention of the privacy team. Wisiex has not appointed a data protection officer because it has not concluded that an appointment is mandatory in its current circumstances. The stated contact receives all data protection requests.
Processing complies with Regulation (EU) 2016/679 (General Data Protection Regulation or GDPR), Portuguese Law no. 58/2019 of 8 August and other applicable legislation, including Law no. 41/2004 of 18 August, as amended, regarding cookies and electronic communications.
2. Who this Policy applies to and our role
This Policy applies to Site visitors, people who contact Wisiex and representatives, contacts and users of clients, prospective clients, partners and suppliers in relation to the processing described here.
Wisiex is the controller of data used to manage professional contacts, administer contractual relationships, comply with billing obligations and protect its systems as described in this Policy.
Where Wisiex processes data on behalf of an institutional client and under its instructions, Wisiex acts as a processor. That processing is governed by the agreement with the client and the relevant privacy notice, as explained in section 6.
If an operation involves joint controllership, data subjects will receive information about the entities involved and the essence of the arrangement allocating their responsibilities.
Employees, job applicants and services involving distinct processing receive specific notices. Reading this Policy does not amount to consent.
3. Data we may process
The data processed depends on your relationship with Wisiex and the functions you use. We limit collection to what is appropriate and necessary for the applicable purposes.
3.1. Identity and professional contact details
First and last name, professional email address, company, role, telephone number and other contact details you provide. Forms may also collect the type of request, services of interest, the country or market indicated and your message.
3.2. Commercial and contractual relationship
Identity of representatives and contacts, evidence of authority where necessary, communications, proposals, contracts, support requests, complaints, and billing and payment information to the extent it relates to individuals.
3.3. Access and security
User identifiers, profiles and permissions, authentication logs, IP address, access date and time, technical browser or device information, requests made to systems and security events, to the extent actually collected to operate and protect those systems.
3.4. Preferences and consents
Communication preferences, subscriptions, proof of consent and records of withdrawal or objection. The Site does not currently use optional cookies, behavioural advertising or optional audience analytics tools.
3.5. Data processed on behalf of clients
Depending on the contracted service, systems may process user and end-client data, account and wallet identifiers, blockchain addresses, transaction information, counterparties, permissions, audit logs, and verification or risk results. This processing follows the client's instructions and does not arise merely because someone submits a commercial contact form.
Do not send passwords, private keys, wallet recovery phrases, full bank details, special-category data or other sensitive information through general contact forms.
4. Where data comes from
We may receive data directly from you through forms, email, meetings and support channels. We may also receive your professional data from the organisation you represent or from a client that gave you access to the services.
Technical data is generated through use of the systems. Data processed on behalf of clients may come from their systems, authorised integrations and, where the service provides for it, blockchain networks or contracted verification sources.
When we receive data indirectly and act as controller, we provide information about the categories, source and other matters required by Article 14 GDPR. Unless a legal exception applies, that information is provided within one month of collection or earlier, at the first contact or first disclosure to another recipient.
5. Purposes and legal bases for our own processing
5.1. Responding to contacts and assessing requests
We process identity details, contact details and communication content to answer requests, arrange demonstrations and discuss projects or partnerships. When you contact us on behalf of an organisation, the legal basis is our legitimate interest in managing that professional relationship under Article 6(1)(f) GDPR.
If the individual is the prospective contracting party, requested pre-contractual steps rely on Article 6(1)(b) GDPR. A contact request does not, by itself, add the person to a commercial communications list.
5.2. Administering contracts and professional access
We use representatives' and contacts' data to manage contracts, operational communications, support and relationships with clients and suppliers. The legal basis is our legitimate interest in administering those professional relationships under Article 6(1)(f) GDPR. Where the data subject is a contracting party, Article 6(1)(b) applies. Account and permission management on behalf of a client follows section 6.
5.3. Complying with legal obligations
We process information needed for billing, accounting and tax record retention under applicable legal obligations, including VAT and accounting and tax laws. The legal basis is Article 6(1)(c) GDPR. We also process data needed to respond to binding authority requests where disclosure is legally required.
5.4. Protecting systems and preventing misuse
We use technical data needed to detect unauthorised access, investigate incidents, preserve system availability and integrity, and prevent fraudulent use. The legal basis is our legitimate security interest under Article 6(1)(f) GDPR. Data processed for clients remains subject to their instructions and is not reused to build risk databases or profiles for our own purposes without a specific lawful framework.
5.5. Commercial communications
Wisiex does not automatically enrol contacts in commercial communications. If a subscription is introduced, contact details and preferences will be processed on the basis of separate consent under Article 6(1)(a) GDPR and electronic communications law. Consent will not be a condition for receiving a response or contracting services and may be withdrawn free of charge at any time.
5.6. Optional technologies and usage analytics
The Site does not currently activate optional cookies, optional audience analytics or advertising technologies. If this changes, those technologies will be enabled only after clear information and, where required, prior consent under Article 6(1)(a) GDPR.
5.7. Managing complaints and defending rights
We may retain and use information needed to manage complaints and establish, exercise or defend rights. The legal basis is our legitimate interest in protecting those rights under Article 6(1)(f) GDPR. Access and retention are limited to what each situation requires.
Whenever we rely on legitimate interests, we assess the need for processing and its compatibility with data subjects' rights, freedoms and reasonable expectations. You may request information about that assessment and exercise your right to object.
6. Processing on behalf of institutional clients
For services provided on behalf of institutional clients, the controller determines the purposes, necessary data, recipients, retention periods and processing instructions within legal limits.
Wisiex follows documented instructions and the agreement required by Article 28 GDPR, including for support, sub-processing and international transfers. Access is limited to service needs and protected by security measures and confidentiality duties.
Information about financial operations, identity verification, transaction monitoring and the legal bases for that processing appears in the controller's privacy notice.
Requests relating to data processed for a client should be sent to that controller. If Wisiex receives one, we help identify the correct channel, notify the client under the processing agreement and provide necessary assistance.
Processing special-category data or data concerning criminal convictions and offences requires the conditions in Articles 9 and 10 GDPR, including where information comes from public sources or verification tools.
7. Who may receive data
Internal access is limited to people who need the data for their duties and who are subject to confidentiality obligations and appropriate permissions.
Contact form submissions are transmitted through a Cloudflare Worker and delivered by email through Resend. Cloudflare provides the form transmission and security layer; Resend provides email delivery and retains message content for 30 days. These providers process data under the applicable contracts and instructions.
Depending on the purpose and service, we may also use hosting and infrastructure, email, contact management and support, security, maintenance, accounting and professional advisers. When they act for us, they are bound by contract and appropriate data protection obligations.
The organisation you represent may receive data as needed for the professional relationship. Administrative, judicial, tax or supervisory authorities may receive data where a lawful basis exists. Advisers or providers acting as independent controllers are subject to their own information and confidentiality obligations.
For client processing, use of other providers, including verification and blockchain analytics vendors, follows applicable instructions and authorisations. The client receives the list of sub-processors, their functions and the change procedure under the processing agreement.
In a corporate reorganisation, data is disclosed only as necessary, with a legal basis, confidentiality duties and notice to data subjects where required.
8. International transfers
Use of Cloudflare and Resend may involve processing or access outside the European Economic Area, including in the United States. Before a transfer, Wisiex verifies the recipient's role, the processing location and the applicable transfer mechanism.
Transfers to countries or recipients covered by a European Commission adequacy decision rely on that decision. Otherwise, appropriate safeguards such as the European Commission's standard contractual clauses are used with the necessary assessment and supplementary measures. Article 49 GDPR derogations are used only in exceptional cases that meet their conditions.
You may request information and a copy of applicable safeguards through the privacy contact, subject to redactions needed to protect confidential information and third-party rights. Transfers made for clients also comply with their instructions and authorisations.
9. How long we keep data
We retain data for the purposes stated, compliance with legal obligations and the defence of rights, using these criteria:
- Contacts, messages and proposals without a contract: up to 12 months from the last interaction, unless earlier deletion is requested or continued retention is justified.
- Messages processed by Resend: 30 days in the delivery service. The copy received by Wisiex follows the 12-month period from the last interaction where no contract follows.
- Representatives, contacts and contractual support: for the relevant relationship and afterwards only as long as needed for legal compliance, complaints and the defence of rights.
- Tax and accounting documents: for the applicable legal period. Records covered by Article 52 of the Portuguese VAT Code are generally kept for the following 10 calendar years, subject to specific rules.
- Technical access and security logs: for a period proportionate to the security purpose and defined for each system. Logs relevant to an incident may be preserved as needed to manage it and defend rights.
- Proof of consent or objection: while needed to demonstrate compliance and honour the person's choice, without reuse for marketing.
- Data processed for clients: for periods and under documented instructions set by the controller, including return, deletion and backups, unless a legal obligation applies to Wisiex.
For litigation, investigations or legal preservation duties, we keep only necessary information for the justified period with restricted access.
At the end of the applicable period, data is deleted or effectively anonymised. Backups follow each system's technical and contractual replacement cycles, remain protected and unavailable for ordinary use and, if restored, are subject to the applicable deletion measures.
11. Automation, profiling and blockchain
11.1. Decisions in Wisiex's own processing
On the Site and in professional contact management, Wisiex does not make solely automated decisions that produce legal or similarly significant effects on a person. It also does not create profiles for behavioural advertising.
11.2. Tools provided to clients
Depending on the service, the infrastructure may support automated checks, alerts, risk scores and rules for routing or blocking operations. For client processing, the controller explains how those tools are used, the effects of decisions and available review. Wisiex provides necessary assistance for rights requests. A technical result or alert is not, by itself, a Wisiex decision about the data subject.
11.3. Blockchain records
Wallet addresses, identifiers and transaction data are personal data when they can be linked to an identified or identifiable person, even if recorded on a public network or using pseudonyms.
For blockchain services, specific information identifies the recorded data, visibility and participants. Configuration must limit data written to the network and support rights relating to information and associations kept off-chain. Technical limits on changing records are assessed for each request and do not remove data protection obligations.
12. Data security
We adopt technical and organisational measures appropriate to the data and risks, including access limitation, permission management, confidentiality duties, system protection and incident response procedures. Specific measures and responsibilities for institutional services appear in the applicable processing agreement and security schedules.
Protect your credentials and report suspected unauthorised access through support channels. Do not send passwords or private keys through those contacts.
Where Wisiex is controller, it notifies personal data breaches to the supervisory authority without undue delay and, where feasible, within 72 hours after becoming aware, unless the breach is unlikely to risk people's rights and freedoms. Where there is a high risk, affected people are also notified without undue delay, subject to Article 34 GDPR exceptions. As processor, Wisiex notifies the controller without undue delay and provides necessary assistance.
13. Your rights
Subject to the GDPR conditions, you may request confirmation and access, correction of inaccurate or incomplete data, erasure and restriction of processing.
You may object to legitimate-interest processing for reasons relating to your particular situation. Processing will stop unless compelling legitimate grounds override your interests, rights and freedoms or processing is needed to establish, exercise or defend legal claims.
You may object at any time and without giving reasons to direct marketing, including related profiling. Data will then no longer be processed for that purpose.
Where processing is automated and based on consent or a contract with you, you may request portability of data you provided in a structured, commonly used and machine-readable format, including transmission to another controller where technically feasible.
You may withdraw consent at any time without affecting the lawfulness of earlier processing. Withdrawal will be as easy as giving consent.
You also have the right not to be subject to solely automated decisions with legal or similarly significant effects, except where legally permitted with applicable safeguards, including human intervention, an opportunity to state your view and contest the decision where required.
To exercise rights, email [email protected] and describe your request. If reasonable doubts exist about identity, we request only additional information needed for verification.
We respond without undue delay and generally within one month. This may be extended by two further months where complexity and request volume require it; we will explain the extension within the first month.
Rights are exercised free of charge. For manifestly unfounded or excessive requests, we may charge a reasonable fee based on administrative costs or refuse the request, giving reasons. If we do not act, we explain why and inform you of complaint and judicial remedy rights without undue delay and within one month.
14. Complaints to a supervisory authority
You may complain to the Portuguese Data Protection Authority, Comissão Nacional de Proteção de Dados (CNPD), through its official channels. You may also contact the authority in the Member State of your habitual residence, place of work or place of the alleged infringement under Article 77 GDPR.
You do not need to contact Wisiex first. Other applicable administrative and judicial remedies remain available.
15. Providing data and third-party services
Required form fields are identified. Without necessary data, we may be unable to answer a request, manage access or perform a contractual relationship. Data required by law or contract is identified in context. Optional data or marketing consent does not condition services that do not depend on it.
Institutional services are not directed to children. Any processing of minors' data for a client depends on its instructions and legally required safeguards.
The Site may link to third-party services. Their activity is governed by their own privacy notices. Wisiex remains responsible for matters within its control concerning integrated tools and data transmissions it determines or permits.
16. Changes to this Policy
We may update this Policy to reflect changes in services, processing or law. The version and update date appear at the beginning.
We communicate material changes before they apply where legally required. New purposes are assessed and communicated in advance. Where consent is required, processing begins only after consent is obtained.
Contact
WCODE SOLUTIONS, LDA
Av. do Atlântico, n.º 16, Escritório 2.01
1990-019 Lisboa, Portugal