Privacy, cookies and GDPR
Configure Wavize according to your policy and process data requests.
Updated 7 August 2026Wavize processes conversations, contacts and technical data to deliver service
Website owner must define legal basis, visitor information, retention periods and authorized people. Wavize settings help display notice and limit collection, but do not replace the organization’s legal analysis.
Widget may receive message, viewed page, technical data and explicitly supplied contact details. Commerce integrations check orders and catalogue; marketing integrations may transfer contacts according to selected mode.
Scope of this guide
It describes product controls and good practices, not legal advice tailored to every country or activity.
Map actual data use
Start from your configuration, not a generic template.
Conversation
Questions, replies, timestamp, session and page context needed for service and analysis.
Contact
Name, email, phone and need when form or detection is enabled. Document whether a person will be contacted or added to a tool.
Commerce and marketing
Reference and email for order verification; profile and consent for Klaviyo/Mailchimp. Do not automatically reuse support data for advertising.
Configure notice and minimization
Under Behaviour, enter clear notice and HTTP/HTTPS policy URL.
Purpose before collection
Explain why email or phone is requested, who will reply and whether marketing transfer is optional.
Minimum fields
Disable unused fields or mechanisms. “Just in case” collection increases risk and obligations without improving service.
Organization-owned link
Policy should be public, current and mobile accessible. Do not link to a generic page omitting chatbot or recipients.
Coordinate cookies and widget loading
Depending on analysis, code may need to wait for a consent category.
Consent manager
Place script in decided category and test Accepted, Rejected and Changed. Widget must not bypass choice after reload.
Proactive campaigns
If widget is not loaded before consent, campaign cannot display or count. Document this effect in impression analysis.
Extensions and storage
Test without blockers then with common protections. Do not claim visitor consent merely because a script loaded.
Manage access, export, deletion and incident
Define a verifiable process before receiving a request.
Identity check
Reasonably verify requester without collecting more data than needed. Do not disclose a conversation from a guessed reference.
Team access
Use individual accounts, least privilege and immediate deactivation on departure. Also review integration keys and recipients.
Coordinated deletion
Data synced to Klaviyo, Mailchimp or another tool must be handled in each system according to your process, not only in Wavize.
Incident
Immediately revoke exposed keys, preserve useful evidence and apply notification process. Do not copy compromised secret into ticket.
Functional compliance review
Repeat after adding a form, integration or new language.
- Accurate notice — It describes actually active uses.
- Minimum collection — No unnecessary field or transfer.
- Request tested — Access and deletion are executable within internal timelines.
Still need help?
Our team can help from your client area.