Wavize privacy policy
Your data, your choices
This policy explains processing on wavize.com and in the Wavize service, including its WordPress and WooCommerce connection. For an assistant installed on a customer’s website, please also read that website’s privacy policy.
Updated 6 September 2026
1. Who processes your data?
Wavize is published by AMPLIFEO, SARL, 32 ALLEE DE LA ROBERTSAU, 67000 STRASBOURG, FRANCE, SIREN 921501771. Contact us at support@wavize.com.
AMPLIFEO is the controller for its customer accounts, billing, support and service security. When a customer uses Wavize to assist visitors on their own website, that customer determines the purposes of this use; Wavize processes assistant data on their behalf, according to their settings and instructions. Please preferably direct requests about such conversations to the website operator; we can help them respond.
2. What data is used, and why?
| Use | Data concerned | Legal basis |
|---|---|---|
| Account and subscription | Identity, contact and company details, access, plan, payment and billing references. | Performance of the contract; legal obligations for accounting records. |
| Assistant and support | Messages, AI or human replies, language, attachments and contact details you voluntarily provide. | Delivery of the service to the customer; the website determines and communicates the legal basis for its visitors. |
| Knowledge and catalogue | Pages and documents authorised by the customer; products, descriptions, prices, images, availability and links from the connected store. | Performance of the service requested by the customer. |
| Order tracking | Order number, verification email address and order and delivery information needed to answer the request. | Handling the visitor’s request on behalf of the merchant. |
| Operation and security | Session identifiers, dates, pages and referrers, IP address, browser, time zone, technical identifier or fingerprint and approximate location depending on settings. | Legitimate interest in securing and operating the service; consent for trackers that require it. |
| Enabled options | Data needed for voice dictation, appointments, human handoff or marketing tools expressly connected by the customer. | Requested service; consent where required, particularly for marketing and optional trackers. |
Information needed for a feature is requested in the relevant form. Without it, that feature may be unavailable. Avoid sharing sensitive data, passwords or payment card information in a conversation.
3. WordPress and WooCommerce
Installing the WordPress connector does not by itself create a Wavize account or start store synchronisation. An administrator chooses to connect the site to Wavize. This process sends the site URL, language, technical connector information and the authorisation information needed for the connection.
On a regular WordPress site, the connector displays the Wavize assistant. With WooCommerce, a separate authorisation grants Wavize read access to the catalogue and information needed for order tracking. Wavize stores API keys encrypted for server-to-server requests; these keys are not included in the visitor-facing script.
The service synchronises the catalogue through scheduled jobs. Order information can be accessed when a visitor requests tracking; the lookup checks the match between the order and the supplied email address. The plugin does not perform a general import of all customers and all orders.
AI, knowledge, catalogue and conversation features are provided by the remote Wavize service. The connector is free; the service requires an account and an active plan after any trial. Trial and subscription conditions are shown before subscribing.
Disconnecting stops future access authorised through the connector. It does not cancel the subscription or erase all previously processed data. Use account management and deletion controls or contact support. Merchants must inform their visitors and configure their consent manager where needed.
4. Artificial intelligence and recipients
To generate a reply, Wavize may send the message, relevant conversation context and extracts from sources or the catalogue to the configured AI provider, including OpenAI. Voice dictation, when used, requires sending audio to the transcription service. Automated replies may be inaccurate: confirm important information with the website or merchant.
Recipients include authorised AMPLIFEO personnel, the customer’s authorised team and providers needed for enabled features: hosting and infrastructure, AI and transcription, real-time messaging, email delivery, payments and security. Service code supports OVH, OpenAI, Pusher for real-time messaging, Stripe for payments and Google reCAPTCHA when enabled. Commerce platforms and other integrations selected by the customer receive the data needed for their own functions.
Recipients depend on the services actually enabled. Some providers may process data outside the European Economic Area. Applicable safeguards depend on the provider and processing agreement: an adequacy decision where it covers the transfer, or standard contractual clauses and appropriate supplementary measures. Contact support@wavize.com for the providers, destinations and safeguards applicable to your configuration and information about those safeguards.
5. Retention periods
| Data | Service rule |
|---|---|
| Conversations | 365 days by default from the session’s last update; customers can choose 30, 90, 180 or 365 days. |
| Contacts | 730 days by default from the last update; customers can choose 180, 365, 730 or 1,095 days. |
| Technical session data | 90 days by default; customers can choose 30, 60 or 90 days. Purging removes session IP, user agent, fingerprint, time zone, referrer and geolocation data. |
| Data exports | Account export files expire after 7 days. |
| Account, sources and authorisations | While used for the service, then according to deletion requests, retention obligations and any dispute that needs resolving. |
| Invoices and accounting records | 10 years from the end of the relevant financial year where French accounting retention requirements apply. |
| Backups and infrastructure logs | For rotation cycles and periods needed for recovery, security and applicable obligations; contact support for the relevant provider’s arrangements. |
These settings concern Wavize. They do not set retention periods for data the merchant holds in WordPress, WooCommerce or other tools. Expired data purges are scheduled daily. Copies archived for a legal obligation or dispute are restricted to that purpose.
Account closure removes the operational data covered by that procedure and retains information needed for accounting obligations or the defence of legal claims. Revoking a key or uninstalling the plugin does not replace a deletion request.
6. Exercising your rights
Depending on your circumstances, you have rights of access, rectification, erasure, restriction, objection and portability. You can withdraw consent at any time for future processing without affecting lawful prior processing. French law also provides for instructions about your data after your death.
Email support@wavize.com with the relevant website or account and your request. We ask for proof of identity only where needed to resolve reasonable doubt. We normally respond within one month, with extensions where permitted by the GDPR. Customers also have account export, retention and closure tools.
You can complain to the CNIL, including at cnil.fr, or your competent data protection authority. A Wavize assistant must not be used as the sole basis for a decision with legal or similarly significant effects on a person.
7. Security and policy changes
Wavize uses HTTPS connections, access controls, connection keys encrypted at rest and authorisation checks appropriate to each feature. Do not share credentials and revoke a connection if you suspect compromise. No measure eliminates every risk; report incidents to support@wavize.com.
The date at the top identifies this version. Changes to purposes or recipients may require additional information or renewed consent. Our cookie policy explains trackers and how to change your choices.
8. Legal notice
Publisher: AMPLIFEO, SARL — SIREN 921501771 — RCS Strasbourg — VAT FR87921501771. Registered address: 32 ALLEE DE LA ROBERTSAU, 67000 STRASBOURG, FRANCE. Contact: support@wavize.com.
Publication director: ANEBARI SENHAJI Nacer. Website host: OVH SAS, 2 rue Kellermann, 59100 Roubaix, France; telephone: 1007.
Wavize and its brand assets are protected. The WordPress connector is distributed under GNU GPL v2 or later; rights granted by that licence remain applicable. The website, remote service and third-party components are subject to their respective terms and licences.