Privacy Policy
Last updated: 18 July 2026
This policy explains what personal data BWAVE LTD collects, why, and what you can do about it. It is written to be read, not to be survived.
Who we are
BWAVE LTD (“βWave”, “we”, “us”) is the data controller.
Registered in England & Wales, company number 16870670.
Registered office: 128 City Road, London, EC1V 2NX, United Kingdom.
Data protection contact: privacy@betawave.co.uk
The short version
- This website sets no cookies and runs no analytics or tracking of any kind.
- We self-host our fonts, so visiting this site sends your IP address to no third party.
- If you run the βWave software yourself, your data never reaches us — it stays on your own infrastructure.
- We do hold business contact details for B2B outreach. You can tell us to stop at any time and we will.
What we collect, and why
1. Website visitors
No cookies, no analytics, no tracking pixels, no fingerprinting. Our web host keeps standard server logs (including IP addresses) for security and reliability — that is a normal part of serving a website and is kept only briefly.
2. Waitlist / contact form
If you give us your email address, we use it to contact you about βWave. That is it — we do not sell, rent or share it. Lawful basis: consent. You can withdraw consent whenever you like by emailing us, and we will delete your address.
3. Business contact data (B2B outreach)
We maintain records of business contacts — typically name, job title, employer, professional profile URL and, where obtained, a work email address — in order to introduce βWave to people whose job it plausibly relates to. This data comes from professional networking platforms, public business directories and licensed data providers.
Lawful basis: legitimate interests (Article 6(1)(f) UK GDPR) — namely marketing a relevant business product to professionals in a role it is designed for. We have weighed this against your interests: we only hold work-related information, never special-category or personal-life data; we contact people in a professional capacity about something relevant to their job; and we stop immediately on request. If you would rather we did not, say so and we will suppress your record — see Your rights below.
4. Clients and prospective clients
If you engage us for done-for-you services, or book a call, we process the contact and business information needed to provide that service and meet our legal and accounting obligations. Lawful basis: contract, and legal obligation for records we must keep.
Self-hosted βWave — an important distinction
βWave is open-source software you can download and run on your own servers. When you do that, the software runs entirely under your control: your content, your contacts and your API keys stay on your infrastructure. We do not receive, collect or have any access to that data. In that arrangement you are the data controller for whatever you process, and this policy does not cover it.
This policy covers only data we hold: our website, our own outreach, and clients we work with directly.
Who we share data with
We do not sell personal data. We use a small number of service providers who process data on our behalf:
- Hosting and infrastructure — for running our website and systems.
- Backup storage — encrypted backups of our own business records.
- Email and scheduling providers — to correspond with you and book calls.
- Business data providers — where we verify or obtain business contact details.
Some providers may process data outside the UK. Where that happens, we rely on appropriate safeguards such as UK adequacy regulations or standard contractual clauses.
How long we keep it
- Waitlist emails — until you ask us to remove you, or until the waitlist is clearly finished.
- Business contact records — while they remain relevant, reviewed periodically. Records suppressed on request are retained only as a minimal “do not contact” entry, precisely so we do not contact you again by mistake.
- Client records — for the duration of our engagement plus the period required by UK accounting and tax law.
Your rights
Under UK GDPR you have the right to:
- ask what we hold about you, and get a copy;
- have inaccurate data corrected;
- have your data erased;
- object to processing based on legitimate interests — including our outreach;
- ask us to restrict processing;
- receive your data in a portable format;
- withdraw consent at any time, where consent is the basis.
Email privacy@betawave.co.uk and we will action it — normally well within the one month the law allows. You do not need to give a reason to be removed from outreach.
If you are unhappy with how we have handled your data, you can complain to the Information Commissioner’s Office (ico.org.uk), the UK supervisory authority. We would rather you told us first so we can put it right.
Security
Access to our systems is restricted and authenticated. Credentials and API keys are encrypted at rest. Backups are encrypted. No system is perfectly secure, but we do not collect data we do not need, which is the most reliable protection there is.
Changes
If we change this policy we will update the date above. Material changes affecting how we use your data will be communicated directly where we hold a contact address for you.