1. Who We Are
Waabbler (“we”, “us” or “our”) operates the website www.waabbler.com (the “Site”). Waabbler partners with founders to build and scale focused software across operations, compliance and commerce.
This policy covers the Site only. Each of our ventures (Complio, OPS Assist and ReceiptRoo) runs its own website and service under its own privacy policy.
For the purposes of applicable data protection legislation, Waabbler is the data controller of the personal data described in this policy.
2. Scope & Jurisdictions
This policy applies to everyone who uses the Site, wherever they are located. We have designed our practices to meet the requirements of the following frameworks:
GDPR / UK GDPR
European Union & United Kingdom: Regulation (EU) 2016/679
CCPA / CPRA
California, USA: California Consumer Privacy Act & Privacy Rights Act
PDPA (Singapore)
Personal Data Protection Act 2012, where our servers are located
PDPA (Thailand)
Personal Data Protection Act B.E. 2562 (2019)
PDPA (Malaysia)
Personal Data Protection Act 2010
PDP Law (Indonesia)
Undang-Undang Perlindungan Data Pribadi 2022
LGPD (Brazil)
Lei Geral de Proteção de Dados Pessoais (Law 13,709/2018)
Privacy Act (Australia)
Privacy Act 1988 & Australian Privacy Principles
BDSG (Germany)
Bundesdatenschutzgesetz: national supplement to the GDPR
If there is a conflict between this policy and a regional requirement that gives you stronger rights, the regional requirement prevails in your jurisdiction.
3. Data We Collect
The Site is an information website. It has no user accounts, takes no payments, and runs no analytics or advertising tools, so we collect very little.
3.1 Data you provide directly
- Enquiries: our contact form does not send anything to our servers. It opens your own email application with your message pre-filled, and nothing is sent until you choose to send it. When you email us we receive what you include, typically your name, email address, organisation and message.
- Founder and partnership materials: any documents or information you choose to send us about your business.
3.2 Data collected automatically
- Server logs: your IP address, the date and time of your visit, the page requested, the referring page and your browser’s user-agent string, recorded by our web server for security and fault diagnosis.
- Consent records: when you make a cookie choice we record a random consent ID, the categories you allowed, the date and time, and the policy version. This record does not include your IP address.
- Consent preference: your cookie choice is stored in your own browser (see section 11).
3.3 Data from third parties
We do not receive personal data about you from third parties through the Site.
4. Legal Basis for Processing (GDPR / UK GDPR)
For users in the EU, UK and other jurisdictions that require a legal basis, we process personal data on the following grounds:
- Legitimate interests (Art. 6(1)(f)): to operate and secure the Site through server logs, and to respond to enquiries you send us. We balance these interests against your privacy rights.
- Steps prior to a contract (Art. 6(1)(b)): where your enquiry relates to a potential partnership, investment or agreement with us.
- Legal obligation (Art. 6(1)(c) and 7(1)): to keep records that demonstrate your cookie consent, and to meet other obligations under applicable law.
- Consent (Art. 6(1)(a)): for any non-essential cookies or similar technologies. None are in use today, and we would only use them after you opt in. You may withdraw consent at any time.
5. How We Use Your Data
- Delivering the Site to your browser and keeping it secure and available.
- Detecting and preventing abuse, attacks and security incidents.
- Replying to your enquiries and evaluating partnership or investment opportunities.
- Remembering and evidencing your cookie choices.
- Complying with legal obligations and responding to lawful requests from authorities.
We do not use your data for marketing without your consent, for profiling, or for automated decision-making that produces legal or similarly significant effects.
7. International Data Transfers
Our web server is located in Singapore, and our email provider may process data in the United States and other countries. When personal data from the EEA or UK is transferred to a country the European Commission has not recognised as providing adequate protection, we rely on:
- Standard Contractual Clauses (SCCs) approved by the European Commission (Decision 2021/914), included in our providers’ data processing terms.
- The UK International Data Transfer Addendum for transfers from the UK.
- Adequacy decisions where they apply.
A copy of the applicable safeguards is available on request from waabbler@gmail.com.
8. Data Retention
- Server logs: a rolling 10-day window, then automatically deleted.
- Consent records: 13 months, covering the 12-month life of a consent plus a margin, then automatically deleted.
- Your consent preference (in your browser): 12 months, or until you change or clear it.
- Enquiries and correspondence: as long as needed to deal with your enquiry. Enquiries that do not lead to an ongoing relationship are deleted within 24 months of our last contact.
9. Your Privacy Rights
Depending on where you live, you have some or all of the following rights. We honour all of them regardless of jurisdiction:
Your rights at a glance
Access
Receive a copy of the personal data we hold about you.
Rectification
Correct inaccurate or incomplete personal data.
Erasure
Ask us to permanently delete your personal data.
Restriction
Temporarily restrict processing while a dispute is resolved.
Portability
Receive your data in a machine-readable format.
Objection
Object to processing based on legitimate interests or for direct marketing.
Withdraw consent
Revoke consent at any time without affecting earlier processing.
No automated decisions
We make no solely automated decisions about you. You may always ask for human review.
California (CCPA / CPRA)
California residents may also opt out of the sale or sharing of personal information (we do not sell or share personal information), limit the use of sensitive personal information, and appoint an authorised agent to exercise their rights.
Singapore (PDPA)
You may request access to and correction of your personal data, and withdraw consent. You may also contact Singapore’s Personal Data Protection Commission (PDPC).
Thailand (PDPA)
You have the right to withdraw consent, object to processing and request erasure. Requests are handled within 30 days. You may also complain to Thailand’s Personal Data Protection Committee (PDPC).
Malaysia (PDPA 2010)
You have the right to access, correct and limit the processing of your personal data. Requests are handled within 21 days.
How to exercise your rights
Email waabbler@gmail.com. We will respond within 30 days, or any shorter period required by applicable law. We may ask you to verify your identity first, to protect your data from unauthorised access.
If you are not satisfied with our response, you have the right to complain to your national supervisory authority, for example the ICO in the UK, the CNIL in France, the BfDI in Germany, or the data protection authority in your EU member state.
10. Data Deletion Requests
We will delete your data promptly and permanently on request. You do not need to give a reason.
Request data deletion
Email us from the address you used to contact us. We will confirm receipt promptly, complete deletion within 30 days, and confirm in writing when it is done.
Send deletion requestWhat we delete
- Your emails, enquiry details and any materials you sent us, within 30 days.
- Your consent record, if you give us the consent ID shown in section 11, within 30 days.
- Server logs containing your IP address are deleted automatically within 10 days, so they are usually already gone.
- You can delete the consent preference stored in your browser yourself at any time by clearing this site’s data.
12. Children’s Privacy
The Site is not directed at children under 16 (or under 13 in the United States). We do not knowingly collect personal data from children. If you believe a child has sent us personal data, contact waabbler@gmail.com and we will delete it promptly.
13. Security
We use technical and organisational measures appropriate to the small amount of data we hold, including:
- Encryption in transit: the Site is served only over HTTPS (TLS 1.2 or 1.3), and plain HTTP is redirected automatically.
- Access controls: server access is limited to authorised personnel, using passphrase-protected SSH keys and the principle of least privilege.
- Data minimisation: no accounts, no analytics and no third-party scripts, with short, automatic log retention.
- Incident response: we will notify affected individuals and the relevant supervisory authorities of a personal data breach as required by law, within 72 hours of discovery where the GDPR applies.
No transmission over the internet is completely secure. If you discover a security vulnerability, please report it responsibly to waabbler@gmail.com.
14. Changes to This Policy
We may update this policy from time to time to reflect changes in the law or in our practices. The “Last updated” date at the top shows the latest revision. If a change affects cookies or similar technologies, we will ask for your consent again.
15. Contact Us
For questions, concerns or rights requests about this policy or your personal data:
- Email (privacy and security): waabbler@gmail.com
- Data controller: Waabbler
- Registered address: available on request to verified data subjects and supervisory authorities.
If you are in the EU or UK and want to escalate an unresolved complaint, you have the right to contact your local data protection supervisory authority. A list of EU authorities is available at edpb.europa.eu.