Effective date: 2026-05-18.
The EU General Data Protection Regulation (2016/679) ("GDPR"), the UK Data Protection Act 2018 and UK GDPR, and the Swiss Federal Act on Data Protection ("FADP") are laws that apply to how we handle personal data. This Statement describes how we meet those obligations and how you can exercise your rights.
1. Our roles
We act in two different capacities depending on the data:
- Controller, for personal data we collect for our own purposes: our website visitors, sales prospects, billing contacts, and vendor contacts. The lawful bases and purposes are described in our Privacy Policy.
- Processor, for personal data that a Customer submits to or generates within the Services on behalf of its end users, employees, and contacts. Our obligations as processor are set out in our Data Processing Addendum.
2. Lawful bases (when we act as controller)
| Processing | Lawful basis |
|---|---|
| Creating & servicing your account | Performance of a contract (Art. 6(1)(b)) |
| Processing payment & tax | Performance of a contract; legal obligation |
| Security monitoring & abuse prevention | Legitimate interests (Art. 6(1)(f)) |
| B2B marketing to existing customers | Legitimate interests (with opt-out) |
| Marketing to prospects | Consent where required; legitimate interests where permitted |
| Compliance with legal obligations | Legal obligation (Art. 6(1)(c)) |
| Aggregate analytics & product improvement | Legitimate interests |
3. Your rights
Under the GDPR you have the right to:
- Information (Art. 13 & 14), be informed about what we do with your personal data;
- Access (Art. 15), obtain a copy of your personal data and information about its processing;
- Rectification (Art. 16), have inaccurate or incomplete data corrected;
- Erasure (Art. 17), request deletion of your personal data;
- Restriction (Art. 18), restrict our processing in certain circumstances;
- Portability (Art. 20), receive your personal data in a structured, commonly used, machine-readable format;
- Object (Art. 21), object to processing based on legitimate interests, including direct marketing;
- Not be subject to automated decision-making (Art. 22), including profiling that produces legal or similarly significant effects.
To exercise these rights, contact contact@wrxstack.com. Where wrxstack acts as a processor, we will forward your request to the relevant Customer (the controller) and assist them in responding.
4. Automated decision-making & profiling
We do not use Customer Content to make decisions with legal or similarly significant effects about data subjects.
5. International data transfers
wrxstack is based in the United States and its infrastructure is hosted there. For transfers from the EEA, UK, or Switzerland to the United States or other non-adequate countries, we rely on the EU Standard Contractual Clauses, the UK International Data Transfer Addendum, and the Swiss FDPIC addendum. There is more detail in our DPA Annex II.
6. Data retention principles
We retain personal data only for as long as needed for the purpose for which it was collected, to comply with law, and to resolve disputes. When a subscription ends, Customer Content is promptly deleted from the live database, and copies in our hosting provider's backups age out on that provider's ordinary rotation. We may retain limited records (for example, billing and tax) for the period required by law.
7. Security and certifications
We protect personal data with encryption in transit (TLS 1.3), encryption at rest inherited from our managed hosting provider, and a commitment that Customer Content is not used to train models, enforced by the model provider's API terms. We want to be plain about this: wrxstack holds no security or compliance certifications. We have no SOC 2 report, no ISO 27001 certificate, and we have not undergone a third-party audit or penetration test. See DPA Annex II.
8. Complaints
If you believe our processing of your personal data violates the GDPR, please contact us first so we can address your concern. You also have the right to lodge a complaint with a supervisory authority, in particular the supervisory authority in the EU member state of your habitual residence, place of work, or place of the alleged infringement. A list of EU supervisory authorities is published by the European Data Protection Board. UK residents may complain to the UK ICO; Swiss residents to the Federal Data Protection and Information Commissioner.
9. Contact
For any GDPR-related question, contact contact@wrxstack.com.