Privacy Policy | Waitwhile

Waitwhile's External Privacy Notice

11 February 2025 

1. INTRODUCTION AND SCOPE

Waitwhile Inc. ("Waitwhile", "we", “our” or "us") are committed to protecting your privacy. We understand that your privacy is important to you, and we want you to feel that you can trust Waitwhile when we process your “Personal Data”, that is any information relating to an identified or identifiable natural person.

This Privacy Notice (the “Notice”) outlines how Waitwhile collects, uses, transfers, or otherwise processes (collectively “process”) your Personal Data as data controller, i.e. when we determine the purpose and means of the processing. The Notice is published with the aim to enable you to understand how we process your Personal Data, why we do so, and to inform you about your data protection rights. As elaborated in section 2 below this Notice does not apply when we process your Personal Data on behalf of our customers as a data processor/service provider.

We are responsible for and committed to processing your Personal Data in accordance with applicable data protection laws, such as the EU General Data Protection Regulation 2016/679 (“GDPR"), the California Consumer Privacy Act as amended by the California Privacy Rights Act (together the “CCPA”) and other applicable national legislation. You can get in touch with us using the contact details set out in section 11 below.

You have a right to information about how we process your Personal Data. We, therefore, encourage you to read this Notice in full.

2. SCOPE

This Notice applies when you:

(i) Visit or interact with us through our websites that display or link to this Notice;

(ii) Visit our branded social media pages;

(iii) Visit our office;

(iv) Otherwise visit or interact with or receive communications from us;

(v) Use our services in those instances when we act as a controller for your Personal Data as an authorized user (“Authorized User”) of the Waitwhile Platform (the “Platform”) such as when we provide support or process your feedback (see section 4.4 below);

(vi) Register for, attend or take part in our events, webinars, programs and trainings;

(vii) Interact with us as a representative for an existing or potential service provider/supplier to us or where your information has been shared with us by the service provider/supplier to the extent we act as a controller for your Personal Data;

(viii) Interact with us as a representative for an existing or potential customer to us or where your information has been shared with us by the customer in our capacity as a controller for your Personal Data;

(ix) Interact with us as a representative for an existing or potential partner to us or where your information has been shared with us by the partner in our capacity as a controller for your Personal Data;

(x) Participate in our surveys or research.

In addition, this Notice applies when we collect and process Personal Data about you in your professional capacity that we have collected from a third party for our sales, marketing or other business activities. 

Please note that we will not as data controller collect any categories of personal data that are considered special categories of personal data under the GDPR (e.g., information about your racial or ethnic origin or health, political opinions, religious or philosophical beliefs, or trade union membership).

This Notice does not apply when we process Personal Data as a processor/service provider on behalf of our customers such as when our customers is using the Platform for managing its queue and appointment bookings and you either are a guest (“Guest”) – i.e. an individual visiting or making an appointment with our customer – or an Authorized User of the customer. In such a case our customer is the controller and responsible for both its Guests and its Authorized Users’ Personal Data and we will only process such data in accordance with the applicable data processing agreement in place between us and the customer. For detailed privacy information relating to a customer’s processing of your Personal Data in relation to the Platform please contact the customer in question directly. Kindly note that we are not responsible for the privacy or data security practices of our customers, which may differ from those explained in this Notice. However, as an exception to this we may still as the controller process your data as an Authorized User in the limited number of cases detailed in section 4.4 below.

Our websites and services may contain links to other websites, applications, platforms and services maintained by third parties. The information practices of these third parties, including the social media platforms that host our branded social media pages, are governed by their privacy statements, which you should review to better understand their privacy practices.

3. WHAT PERSONAL DATA WE COLLECT AND HOW WE COLLECT IT

Most of the time, we collect your personal data directly from you, such as when you fill in a form on our website - e.g., demo requests and resource downloads - or when you otherwise interact with us. However, we also collect your personal data from other sources, such as information that is publicly available, for example, information about you on your employer’s website, social media such as LinkedIn or from suppliers/partners providing us with your contact details as a business representative of a prospective customer. (In certain circumstances, personal data will be generated internally by our systems, such as internal reference numbers.)

In some circumstances, we also collect publicly available information which may contain Personal Data that you have published or that has been made available online. In addition, our partners or suppliers may also provide us with your Personal Data. The way in which our partners collect this is detailed in their own privacy notices.

If you provide us with any Personal Data relating to other individuals, you represent that you have the authority to do so, and where required, have obtained the necessary consent, and acknowledge that it may be used in accordance with this Notice.

The personal data we collect, and process can be categorized in the following categories:

Authorized User Information: Authorized User account data and user-generated data that is collected when you use the Platform as an Authorized User, such as name, business email, log-in-credentials, job role and log data.

Communication Information: Personal Data that is collected through our interaction with you and includes the content of our communications with you, such as your Contact Information (as defined below).

Contact Information: Personal Data that will enable us to get in touch with you, as well as understand more about the organization that you represent, such as your contact details, job role and social media profiles such as LinkedIn and information about the organization that you represent.

Signature Information: Personal data collected to enable you to electronically sign an agreement such as your name, role, business e-mail, signature including the time and date of the signature.

Technical and Device Information: Personal data which we may receive when you visit our website such as IP-address and information about your device.

Financial and Payment Information: Personal Data needed for our accounting, reporting and billing such as billing name and address, credit card information, bank account information, invoice data, transaction reference number and usage data for the Platform relevant for the billing.

Video and Photo Data: Photos, videos or recording of you.

4. WHY AND HOW WE USE YOUR PERSONAL DATA

4.1 When you visit and interact with us through our websites

4.1.1 When you interact with us through our websites

Purpose (Situations)

Categories of Personal Data Processed

Legal Basis for Processing

If you express an interest in obtaining information about our business, operations and services such as;

  • To book a discovery call and provide a demo for you upon your request on our Website.

  • To enable you to download our informational material, such as webinars, interactive tool results, and white papers.

  • To respond to your inquiries and provide requested information when you fill in relevant forms on our Website or when you contact us via other communication channels.

  • Contact Information

  • Communication Information

Our legitimate interest in providing information about our business, operations and products including to provide you with the requested material and information.

If you purchase a subscription to the Platform

  • Contact Information

  • Signature Information

  • Financial and Payment Information

Our legitimate interest in providing our services. 

To improve our website's performance, usability, and security, including analyzing how users interact with different pages to enhance their experience.

  • Technical and Device Information

Our legitimate interest in improving our website.


⁠4.1.2 Cookies and similar technologies

When you interact with us through our websites or when you use our Platform we may place cookies and similar technologies on Your device. More information about the types of cookies we use, the personal data categories processed, the purposes and legal basis of processing and retention time, as well as how you can control cookies are provided in the respective applicable Cookie Notice available on the website or in the platform for the processing in question. You can manage your consent settings through your browser or our cookie management tool.

4.2 When the company that you represent is a customer or a prospective customer of Waitwhile

In case you represent an existing customer or a prospective customer of ours or one of our partners, we will process your personal data for the following purposes (in addition to the purposes set out in clause 4.1 above):

Purpose (Situations)

Categories of Personal Data Processed

Legal Basis for Processing

To market our services to potential and existing customers, including distributing marketing communications about our services, invitations to webinars and events, case studies, and other content relevant to you as a representative of a current or prospective customer.

  • Contact Information

  • Communication Information

Our legitimate interest in marketing our services to persons representing potential customers or your prior consent depending on the applicable national legal requirements.

To sign relevant agreements with Waitwhile.

  • Contact Information

  • Signature Information

  • Any other personal data that the agreement may contain

Our legitimate interest in ensuring that relevant agreements are in place with our customers.

To manage our relationship with our (existing and prospective) clients and day-to-day operations.

  • Contact Information

  • Communication Information

Our legitimate interest in administering our relationship with the company that you represent.

To manage our relationship with our (existing and prospective) clients by recording meetings.

  • Video and Photo Data

Your consent to the processing or our legitimate interest in administering the relationship with the company you represent.

For charging, billing, invoicing, financial reporting and analyses and accounting.

  • Contact Information

  • Financial and Payment Information

Our legitimate interest in charging for our services and to administer our financial reporting and analyzing and accounting including to comply with legal obligations, such as bookkeeping laws.

To publish your feedback about our services

  • Contact Information

  • Communication Information

Our legitimate interest in promoting our services or your prior consent.


⁠4.3 When you are or you are interested in becoming our business partner

Whether you choose to become a referral or solution business partner, we will process your personal data for the following purposes:

Purpose (Situations)

Categories of Personal Data Processed

Legal Basis for Processing

To identify relevant partnerships, enable you to apply to become our business partner or deliver a demo that you have requested.

  • Contact data

We base the processing on our legitimate interest in reaching out to potential partners, administering the partnership applications, and responding to your inquiries.

To sign relevant agreements with Waitwhile.

  • Contact data

  • Signature data

We base the processing on our legitimate interest in ensuring that relevant agreements, such as partnership agreements, are in place with our clients.

To administer our relationship with you and day-to-day operations.

  • Contact data

  • Communication data

We base the processing on our legitimate interest in administering our relationship with our partners.


⁠4.4 When you use the Platform as an Authorized User

As detailed above please note that if you are using our Platform as an Authorized User we are processing your Personal Data on behalf of the customer who is responsible for assigning you access to our services. Notwithstanding the above we remain the data controller for certain purposes of processing when you are using our Platform which are the following:

Purpose (Situations)

Categories of Personal Data Processed

Legal Basis for Processing

To improve the quality, functionality, and user experience of the Platform.

  • Authorized User Information

  • Contact Information

  • Communication Information

  • Technical and Device Information

Our legitimate interest in improving our services.

To improve our services by processing your feedback and contacting you with follow-up questions.

  • Contact Information

  • Communication Information

Our legitimate interest in improving our services.

To provide technical support.

  • Authorized User Information

  • Contact Information

  • Communication Information

  • Technical and Device Information

Our legitimate interest in offering support to our customers and their Authorized Users.

To be able to operate the Platform, including maintenance and debugging.

  • Authorized User Information

  • Contact Information

  • Communication Information

  • Technical and Device Information

Our legitimate interest in operating and ensuring the proper functionality of the Platform.


⁠4.5 When you visit, participate in our webinars and events or otherwise interact with us

We want to be on top of things, and to do that, we organize various webinars, events, and other activities. During those events, we will process your personal data for the following purposes:

Purpose (Situations)

Categories of Personal Data Processed

Legal Basis for Processing

To process your registration and manage your participation in webinars, events, and training sessions, including sending event-related updates and materials.

  • Contact Information

  • Communication Information

Our legitimate interest to administer and arrange our events or your consent.

To take photos, videos, and recordings during events for promotional purposes, including making webinar recordings available on-demand and using event highlights for future promotional materials.

  • Photos and/or Video Data

Our legitimate interest to have the webinars available on- demand and/or use the material to promote similar events.

To add you to relevant mailing lists and contact you after the webinar or event to gather feedback and provide relevant follow-up information, such as recordings, presentation slides, or invitations to future events.

  • Contact Information

  • Communication Information

Our legitimate interest to collect your feedback to improve the quality of our webinars and/or events and provide relevant follow-up information.

To otherwise interact with you.

  • Contact Data

  • Communication Data

  • Any other Personal Data as applicable.

Our legitimate interest to communicate with you or your consent.


⁠4.6 To enable us to comply with legal obligations and defend against legal claims

Purpose (Situations)

Categories of Personal Data Processed

Legal Basis for Processing

To comply with various legal obligations.

In order to comply with applicable laws, we are obliged to process certain personal data. The personal data categories collected and stored for this purpose may vary depending on the specific requirements stipulated in, for example applicable tax, accounting, or book- keeping legislation.

For this purpose, the processing of your personal data is based on our necessity to comply with legal obligations.

To enable Waitwhile Inc. to establish, exercise or defend legal claims.

“Legal claims” in this context is not limited to current legal proceedings but also includes:

  • actual or prospective court proceedings;

  • obtaining legal advice; or

establishing, exercising, or defending legal rights in any other way.

For this purpose, we will process any Personal Data.

We base the processing on our legitimate interest in being able to establish, exercise, and defend against legal claims according to applicable law.

5. RETENTION PERIODS

We retain the personal data for a period of time consistent with the original purpose of collection or as long as we have an ongoing legitimate business need to do so (e.g., to exercise or defend legal claims or to comply with applicable legal, tax, or accounting requirements). When we have no ongoing legitimate business need or legal reason to process your personal data, we will either delete or anonymize it.

6. MINORS

Our website and services are not directed at minors, and we do not knowingly collect Personal Data from any individual under the age of 18.

7. TRANSFERS OF PERSONAL DATA

We disclose the Personal Data described above for the purposes above to the following categories of recipients:

(a) Courts and similar judicial entities and/or authorities if we are required to do so by law or due to legal proceedings.

(b) Our affiliates.

(c) Our business partners, shareholders and potential investors.

(d) Our customers with whom you are affiliated with.

(e) Service providers/processors, suppliers or advisors upon which we rely for our operational activities, such as payment/invoicing processors, data analytics partners and our CRM-system-provider

Our processing and the above third parties processing of your Personal Data may take place in the United States or other countries outside the EU/EEA (collectively “Third Countries”). In such cases, we ensure that adequate safeguards are in place to require that your personal data remain protected in accordance with this Notice and applicable data protection laws.  We ensure that the recipient of your Personal Data offers an adequate level of protection and security, either through an adequacy decision by the European Commission or through legally approved transfer mechanisms such as EU Standard Contractual Clauses (SCCs) or an alternative mechanism for the transfer of data as approved by the European Commission (Art. 46 GDPR) or other safeguards where applicable.

8. DATA PRIVACY FRAMEWORK NOTICE

Waitwhile (we) complies with the EU-U.S. Data Privacy Framework (“EU-U.S. DPF”), the UK Extension to the EU-U.S. DPF, and the Swiss-U.S. Data Privacy Framework (“Swiss-U.S. DPF”) as set forth by the U.S. Department of Commerce. Waitwhile has certified to the U.S. Department of Commerce that it adheres to the EU-U.S. Data Privacy Framework Principles (“EU-U.S. DPF Principles”) with regard to the processing of personal data received from the European Union in reliance on the EU-U.S. DPF and from the United Kingdom (and Gibraltar) in reliance on the UK Extension to the EU-U.S. DPF.  Waitwhile has certified to the U.S. Department of Commerce that it adheres to the Swiss-U.S. Data Privacy Framework Principles (“Swiss-U.S. DPF Principles”) with regard to the processing of personal data received from Switzerland in reliance on the Swiss-U.S. DPF.  If there is any conflict between the terms in this Notice and the EU-U.S. DPF Principles and/or the Swiss-U.S. DPF Principles, the Principles shall govern. To learn more about the Data Privacy Framework (DPF) program, and to view our certification, please visit the Data Privacy Framework website.

In the context of an onward transfer, Waitwhile is responsible for the processing of Personal Data it receives under the DPF Principles and subsequently transferred to a third party acting as our agent/processor.

The Federal Trade Commission has jurisdiction over Waitwhile’s compliance with the EU-U.S. DPF, the UK Extension to the EU-U.S. DPF, and the Swiss-U.S. DPF.

If you have an inquiry regarding our privacy practices in relation to our DPF certification, we encourage you to contact us. In compliance with the EU-U.S. DPF, the UK Extension to the EU-U.S. DPF and the Swiss-U.S. DPF, Waitwhile commits to resolve DPF Principles-related complaints about our collection and use of your personal information. EU, UK and Swiss individuals with inquiries or complaints regarding our handling of personal data received in reliance on the EU-U.S. DPF, the UK Extension to the EU-U.S. DPF and the Swiss-U.S. DPF should first contact Waitwhile (us) at compliance@waitwhile.com. We will respond in accordance with DPF requirements.

In compliance with the EU-U.S. DPF, the UK Extension to the EU-U.S. DPF and the Swiss-U.S. DPF, Waitwhile commits to cooperate and comply respectively with the advice of the panel established by the EU data protection authorities (DPAs) and the UK Information Commissioner’s Office (ICO) and the Gibraltar Regulatory Authority (GRA) and the Swiss Federal Data Protection and Information Commissioner (FDPIC) with regard to unresolved complaints concerning our handling of personal data received in reliance on the EU-U.S. DPF,  the UK Extension to the EU-U.S. DPF and the Swiss-U.S. DPF.

In certain circumstances, the DPF provides the right to invoke binding arbitration to resolve complaints not resolved by other means, as described in Annex I to the DPF Principles

See other part of this Notice for information regarding the Personal Data processed and clause 9 for further information regarding your data protection rights. Please note that we may disclose your Personal Data in response to lawful requests by public authorities.

9. YOUR RIGHTS

You may have certain rights relating to your Personal Data subject to in each case to applicable data protection laws. Depending on the applicable law these rights may include:

Right to Information and Access: You have the right to access and receive a copy of your Personal Data that we process together with other additional information about how we process your data.

Right to rectification:  If you believe that your Personal Data is inaccurate or incomplete, you can ask for it to be corrected or completed.

Right to object. You have the right to object to the processing of your Personal Data which is based on our legitimate interest. If we cannot demonstrate compelling and legitimate grounds to continue processing the Personal Data, we must cease the processing. You always have the right to object to our processing of your personal data for direct marketing purposes.

Right to erasure: In certain cases, you are entitled to have your Personal Data erased (also known as the “right to be forgotten”), such as in cases where the personal data is no longer needed for the purpose for which it was collected, and we no longer have a legal basis to continue processing it.

Right to restriction: In some cases, you have the right to request a restriction of the processing of your Personal Data, which means that the data is marked so that, in the future, it can only be processed for certain limited purposes. This is possible, for example, if you have objected to the processing, if you have disputed the accuracy of your Personal Data, or if the processing is unlawful. By requesting a restriction of our processing, you have the right to stop us from processing your Personal Data for a certain period of time for other purposes than, for example, to establish, exercise or defend legal claims.

Right to withdraw your consent: You have the right to withdraw your consent to any processing for which you have previously given consent at any given time.

Right to transfer your personal data (data portability): If we process your personal data to fulfill a contract or on the basis of your consent, you may, in certain cases, be able to obtain the personal data for use elsewhere, e.g. by obtaining a copy of it in a machine-readable format and transmitting it to another data controller.

We do not discriminate against any individual exercising any of its data protection/privacy rights. We may need to verify your identity and place of residence before completing your rights request and will respond within the deadlines of the applicable legislation.

Please contact us by e-mail on compliance@waitwhile.com if you would like to exercise any of your rights, have a complaint or if you have any other questions. You also have the right to lodge a complaint with the data protection authority having jurisdiction over your complaint.

However, if you are an Authorized user or Guest to one of our customers using the Platform we will in most cases as detailed above  process your personal data as a processor/service provider to our customer who is the controller. If you wish to exercise any rights in relation to your Personal Data which we process as a processor/service provider please contact the relevant customer (controller) directly. If you anyway submit a request to us in this regard we will forward your request to the relevant customer if it is from your request is clear who the relevant customer (controller) is.

10. ADDITIONAL DISCLOSURES FOR CALIFORNIA RESIDENTS

We do not i) sell your Personal Data, or ii) share your personal data for behavioral advertising. Further, we honor “do not track” requests and do not process sensitive personal information as the responsible business/controller.

We collect and share the categories of Personal Data set out above to the recipients and with the purpose set out above.

Please note that a customer may have shared your personal information from the Platform with a third party. The customer is responsible for and can provide you with information about such a potential sharing of information.

If you are unable to access this Notice due to a disability or any physical or mental impairment, please contact us and we will arrange to supply you with the information you need in an alternative format that you can access.

California residents have the right to access, correct, and delete their personal data as further explained in section 9 above but subject to applicable law.

11. CHANGES TO THIS NOTICE AND CONTACT INFORMATION

If we make changes to this Notice, we will notify you on our website. You can see when this Notice was last updated by checking the date at the top of this Notice.

Our contact information is:

Name: Waitwhile Inc.

Address:

548 Market St, 45862, San Francisco, CA, USA, or 

Kungsgatan 32, 111 35 Stockholm, Sweden

Email addresscompliance@waitwhile.com

There’s nothing to lose but the wait

Statement