Legal, Last updated: 2026-05-18

GDPR Statement.

How wrxstack handles data subject rights, lawful bases, and international transfers under the GDPR and UK GDPR.

Effective date: 2026-05-18.

The EU General Data Protection Regulation (2016/679) ("GDPR"), the UK Data Protection Act 2018 and UK GDPR, and the Swiss Federal Act on Data Protection ("FADP") are laws that apply to how we handle personal data. This Statement describes how we meet those obligations and how you can exercise your rights.

1. Our roles

We act in two different capacities depending on the data:

  • Controller, for personal data we collect for our own purposes: our website visitors, sales prospects, billing contacts, and vendor contacts. The lawful bases and purposes are described in our Privacy Policy.
  • Processor, for personal data that a Customer submits to or generates within the Services on behalf of its end users, employees, and contacts. Our obligations as processor are set out in our Data Processing Addendum.

2. Lawful bases (when we act as controller)

ProcessingLawful basis
Creating & servicing your accountPerformance of a contract (Art. 6(1)(b))
Processing payment & taxPerformance of a contract; legal obligation
Security monitoring & abuse preventionLegitimate interests (Art. 6(1)(f))
B2B marketing to existing customersLegitimate interests (with opt-out)
Marketing to prospectsConsent where required; legitimate interests where permitted
Compliance with legal obligationsLegal obligation (Art. 6(1)(c))
Aggregate analytics & product improvementLegitimate interests

3. Your rights

Under the GDPR you have the right to:

  1. Information (Art. 13 & 14), be informed about what we do with your personal data;
  2. Access (Art. 15), obtain a copy of your personal data and information about its processing;
  3. Rectification (Art. 16), have inaccurate or incomplete data corrected;
  4. Erasure (Art. 17), request deletion of your personal data;
  5. Restriction (Art. 18), restrict our processing in certain circumstances;
  6. Portability (Art. 20), receive your personal data in a structured, commonly used, machine-readable format;
  7. Object (Art. 21), object to processing based on legitimate interests, including direct marketing;
  8. Not be subject to automated decision-making (Art. 22), including profiling that produces legal or similarly significant effects.

To exercise these rights, contact contact@wrxstack.com. Where wrxstack acts as a processor, we will forward your request to the relevant Customer (the controller) and assist them in responding.

4. Automated decision-making & profiling

We do not use Customer Content to make decisions with legal or similarly significant effects about data subjects.

5. International data transfers

wrxstack is based in the United States and its infrastructure is hosted there. For transfers from the EEA, UK, or Switzerland to the United States or other non-adequate countries, we rely on the EU Standard Contractual Clauses, the UK International Data Transfer Addendum, and the Swiss FDPIC addendum. There is more detail in our DPA Annex II.

6. Data retention principles

We retain personal data only for as long as needed for the purpose for which it was collected, to comply with law, and to resolve disputes. When a subscription ends, Customer Content is promptly deleted from the live database, and copies in our hosting provider's backups age out on that provider's ordinary rotation. We may retain limited records (for example, billing and tax) for the period required by law.

7. Security and certifications

We protect personal data with encryption in transit (TLS 1.3), encryption at rest inherited from our managed hosting provider, and a commitment that Customer Content is not used to train models, enforced by the model provider's API terms. We want to be plain about this: wrxstack holds no security or compliance certifications. We have no SOC 2 report, no ISO 27001 certificate, and we have not undergone a third-party audit or penetration test. See DPA Annex II.

8. Complaints

If you believe our processing of your personal data violates the GDPR, please contact us first so we can address your concern. You also have the right to lodge a complaint with a supervisory authority, in particular the supervisory authority in the EU member state of your habitual residence, place of work, or place of the alleged infringement. A list of EU supervisory authorities is published by the European Data Protection Board. UK residents may complain to the UK ICO; Swiss residents to the Federal Data Protection and Information Commissioner.

9. Contact

For any GDPR-related question, contact contact@wrxstack.com.