Privacy policy

1. Who we are and in which role

Waterglass FlexCo, Börseplatz 1/3/6, 1010 Vienna, Austria, is the controller for the personal data processed through this website and through our Waterglass Waves platform. You can reach us at hi@waterglass.ai with any questions about this policy or your data.

For Waves, two roles need to be distinguished. For the data of your account, your organisation, billing and technical operation, we are the controller. For the content you process in Waves as a customer, you are the controller and we are the processor: we process that content only to provide the service, and in accordance with your instructions. Data subjects whose data a customer processes in Waves should contact that customer.

2. Which offerings this policy covers

This policy applies to this website (www.waterglass.ai) and to the Waterglass Waves platform, that is the console at waves.waterglass.ai, its application programming interface, and the execution environments in which AI agents run. For our consulting and development projects, the respective project and data processing agreements apply in addition.

3. Data we collect through this website

We collect the information you give us directly – for example your name, email address, company and message when you submit our contact form or book a call, or your email address when you subscribe to our event-notification mailing list.

We also collect limited technical data automatically, such as your IP address, browser type and pages visited, to keep the site secure and understand how it is used.

If you arrive on our site through an advertisement, the link may contain campaign parameters and an ad-click identifier (such as Google's gclid). We record these to measure which of our advertisements lead to started and submitted enquiries and to booked calls.

4. Data we process for your Waves account

To register and operate an account, we process your name, your email address, a non-reversible verification value derived from your password, the name and identifier of your organisation, and the IP address from which the registration was made. If you activate two-factor authentication, we store the associated secret and your recovery codes in encrypted form. For API keys we store a label, a prefix, a verification value and the time of last use, not the key itself.

When you sign in, we store the IP address and the browser identification for the active session. Our servers log accesses including the IP address, in order to keep the service running and to investigate faults and misuse. These logs rotate continuously and are not retained permanently.

For billing we process your name, your billing address, a VAT identification number you provide, your customer number with our payment service provider, invoices and payment transactions, as well as your consumption, that is tokens used, model and cost per day. Card details are entered exclusively with our payment service provider and do not reach our systems. If you activate automatic credit top-up, we store the time, the IP address and the settings you chose as evidence of your consent.

The console includes a built-in assistant. Conversations with it are stored until you delete them and are assigned to your user account. We evaluate these conversations to improve the assistant and the platform, on the basis of our legitimate interest (Art. 6(1)(f) GDPR): before the evaluation we remove names and email addresses, the evaluation produces summarised categories and no profiles of individual users, and an AI model used for it is operated within the European Union. Your workspace can switch this evaluation off at any time in the settings.

If you ask the assistant to send us a feature request, your name, your email address and the name of your workspace are transmitted to us together with the request so that we can follow up. Nothing is sent without your confirmation, and the confirmation dialog shows what will be sent.

5. Content you process in Waves

Waves stores the content you contribute or that arises during a run: the configuration of your AI agents including system instructions, the instructions with which a run is started, the complete trail of a run with all messages, tool calls, outputs of executed commands and retrieved content, the documents of your knowledge bases together with their vector representation, your notes and skills, and an archive of the working directory of each run.

The trail of a run is append-only by design and is not modified. It is at the same time the record of what an agent did. If you delete a run, it is marked as deleted and no longer displayed. Its trail and the archive of its working directory initially remain stored. We carry out a final deletion on request.

Credentials you store are held in encrypted form only. Their values are never returned by any interface and are masked in trail data, logs and instructions sent to AI models. We do not use your content to train AI models. The only exception is a service you expressly order, such as the distillation of a model on your own content. It covers only your workspace, and the result is provided to you.

6. How we use your data

We use your data to respond to your enquiries, to provide and improve our services, to operate and secure the website, to measure the effectiveness of our advertising, and to comply with our legal obligations. We do not sell your personal data.

Where you have subscribed to our event-notification mailing list, we use your email address to send you information about our upcoming events, on the basis of your consent, until you unsubscribe. Every such email contains an unsubscribe link, and you can opt out at any time.

For Waves we use your data to provide and bill the platform, to start and monitor runs, to ensure the security and stability of operation, to prevent misuse, and to comply with our legal obligations. Operation includes automatic monitoring that notifies us of faults. It receives operational metrics and, in individual cases, the email address of a newly confirmed account, but no content from runs.

To operate, secure and develop the platform, we evaluate usage metadata of runs: the model used, the number and type of steps, token counts, durations, costs, and whether a run succeeded. The content of a run, meaning its instructions, messages, outputs and files, is not part of this evaluation. The legal basis is our legitimate interest in the operation and improvement of the service (Art. 6(1)(f) GDPR).

To maintain and improve the platform, we additionally evaluate the content of runs in summarised form: an automated classification assigns runs to fixed usage categories (for example extraction, research, drafting) and quality indicators. Names, email addresses and similar identifiers are removed before this evaluation. It takes place exclusively within the European Union, and only the categories and indicators are retained, never the content itself. No profiles of individual users are formed. Your workspace can switch this evaluation off at any time in the settings.

7. Legal basis

We process personal data on the basis of your consent (Art. 6(1)(a) GDPR), the performance of a contract or steps taken at your request before entering one (Art. 6(1)(b) GDPR), our legitimate interests in running and improving our business (Art. 6(1)(f) GDPR), and compliance with legal obligations (Art. 6(1)(c) GDPR).

For Waves in detail: the account, its use and billing rest on the usage contract (Art. 6(1)(b) GDPR). The retention of invoices and the VAT records rest on legal obligations (Art. 6(1)(c) GDPR, in particular § 132 of the Austrian Federal Fiscal Code and § 11 of the Austrian VAT Act). Logs, the protection against misuse and the operational monitoring rest on our legitimate interest in secure and stable operation (Art. 6(1)(f) GDPR). Content you process in Waves we process as a processor on the basis of Art. 28 GDPR and your instructions.

8. AI model providers

So that an AI agent can work, the content of a run is transmitted to the provider of the model you selected for that agent. What is transmitted is the system instruction, your instruction, the trail so far, and the results of the tools, which therefore also includes outputs of executed commands, file contents, retrieved websites and excerpts from your knowledge bases. The call runs through our own gateway. The execution environment receives no credentials of the provider.

The recipient is whoever operates the deployment we call, which is not always the company that developed the model. With processing inside the European Union these are: Amazon Web Services EMEA SARL, processing in Sweden, for the European versions of models by Anthropic, DeepSeek, Z.ai and Moonshot; Google Cloud EMEA Limited, processing in the European Union, for the European versions of the Google models; Microsoft Ireland Operations Limited, processing in the European Union, for the OpenAI models; and Mistral AI, processing in France, for the Mistral models. Outside the Union, and only if you select one of their models: Anthropic, processing in the United States, for those of their models for which no European deployment is available to us. The console states the place of processing for every model, and you decide for each AI agent which model may be used. If a fallback model is configured, the same content may go to its provider, which can be in a different country from the primary model. The console warns you when that is the case.

Providers may retain the transmitted content for a limited period in order to detect misuse of their services, as a rule no longer than 30 days, and that can include inspection by their own personnel. It differs by provider: some store nothing at all for the models we call, others store only what their systems have flagged. Where a provider's systems flag content as suspected misuse, it can be kept longer and examined more closely. This retention is the provider's and serves the security of their service, not any purpose of ours, and it happens whether or not we keep the content ourselves. Whether it can be switched off differs by provider and is not always within our control.

Regardless of the language model selected, we transmit documents you upload to a knowledge base, as well as your search queries within it, to Mistral AI (France), in order to convert them into a vector representation usable for search.

9. Services you connect and access to the internet

If you connect a third-party service to Waves, for example Slack, GitHub, Notion or HubSpot, you authorise that connection yourself in the respective service and with the permissions displayed in the process. An agent then acts with the identity and the permissions of the person who established the connection, and the data exchanged goes to that service. We keep only the access tokens, in encrypted form.

If you give an agent access to the internet, your instruction determines which websites are retrieved. Their operators are recipients as a result. You can likewise store your own tool servers and network destinations. You determine these recipients. They are not processors engaged by us. Without such an authorisation, the execution environments reach only our own services.

The web search tool is the one exception to that, and we name it separately because the recipient does not follow from your choice. If you allow the tool for an agent, we transmit the search query to Google, whichever language model that agent uses, because the search runs as an enquiry to Google Search with a Google model. According to Google's terms for this feature, Google stores logs containing the query derived from the prompt, together with any context sent with it, for up to three days and not associated with you or your users, and uses them to debug the systems behind the search. That storage cannot be switched off while the feature is in use. For this feature Google also does not undertake to process the data inside the European Union, because its data residency terms expressly exclude grounding with Google Search, so allowing the tool can mean processing outside the Union even where the agent's own model is one operated inside it. For this tool Google is therefore a processor engaged by us and is listed as such in our subprocessors list, not a recipient you have determined. The tool is inactive unless you allow it for an individual agent.

10. Recipients and processors

We share data only with service providers who help us operate the site and deliver our services – for example hosting, analytics, email delivery and scheduling providers – under agreements that require them to protect your data. Call scheduling is provided by Cal.com Europe (Cal.eu), hosted in the EU. Our event-notification mailing list is stored and the notification emails are sent through Resend (Resend, Inc.), with processing in Ireland. Where you reached us through an advertisement, we share ad-click identifiers with Google, together with the time at which you started or submitted an enquiry or booked a call, to measure advertising performance.

For Waves we engage Hetzner Online GmbH (Germany) for computing power, object storage and encrypted backups in data centres in Germany. Payment processing, invoices and the determination of VAT run through Stripe. Account emails such as confirmation and password links are sent through Resend (Resend, Inc.), with processing in Ireland. Added to this are the AI model providers named in section 8. For the reachability of the services, a certificate provider and a public name service are involved, which receive technical connection data only.

The current list of the subprocessors engaged for Waves, with purpose and place of processing, is available at Subprocessors.

11. Transfers to third countries

The operation of the Waves platform itself, including databases, object storage and backups, takes place in the European Union. The same applies to the sending of emails and to call scheduling. For Waves, transfers to third countries therefore arise only from the choice of AI model, from the web search tool where you allow it, and from services outside the Union that you connect yourself, and for most models a version operated inside the Union is available, so that no such transfer occurs. On this website, a transfer to the United States concerns the measurement of advertising performance where you reach us through an advertisement.

Where no adequacy decision of the European Commission covers a recipient, we base the transfer on the EU standard contractual clauses and supplementary measures. The only such recipient remaining for Waves is in the United States, and only if you select one of those models. Where a service provider established in the Union processes outside it on our behalf, as is the case for the web search tool, we rely on the transfer safeguards in that provider's own data protection terms. For service providers established outside the European Union that process within the Union on our behalf, we additionally base any access from their home jurisdiction on the standard contractual clauses.

If you require processing exclusively within the European Union in Waves, select a model operated in the Union, which is possible for most of the models we offer, leave the web search tool switched off, and refrain from connections to services outside the Union.

12. Data retention

We keep personal data only as long as necessary for the purposes described here or as required by law, after which it is deleted or anonymised.

For Waves in detail: account and organisation data are stored for the duration of the contract. Content you process in Waves is stored until you delete it or request its deletion. Invoices and the associated records are retained for seven years (§ 132 of the Austrian Federal Fiscal Code). Server logs rotate continuously by volume and are not retained permanently. Encrypted backups of the database are kept for around two weeks, so that a state prior to a failure can be restored. A deletion takes effect there only when that cycle has elapsed.

We carry out the deletion of accounts, organisations and individual run trails on request. There is currently no function for this in the console. Please contact hi@waterglass.ai. Until such a deletion, the trail of a run marked as deleted and the archive of its working directory remain stored.

13. Security of processing

We take technical and organisational measures appropriate to the risk. These include operation exclusively within the European Union, transport encryption for all public access, encrypted storage of stored credentials with a separate key per entry, encrypted storage of the secrets for two-factor authentication, a database identity for the application with restricted rights, an append-only and unmodifiable run trail, execution environments that are separated per run and restricted towards the outside, and encrypted backups. Administrative access to the systems is limited to a small group of people and is necessary for operation, fault diagnosis and recovery. In the course of that, access to stored content is technically possible. There is no certification under ISO 27001 and no comparable audit report.

14. Your rights

Subject to applicable law, you have the right to access, correct, delete or restrict the processing of your personal data, to object to processing, and to data portability. You can also withdraw consent at any time. To exercise these rights, contact hi@waterglass.ai. You also have the right to lodge a complaint with the Austrian Data Protection Authority (Datenschutzbehörde). If your request concerns content that a customer processes in Waves, please address it to that customer. We support our customers in this as a processor.

15. Cookies and local storage

We use a small number of essential cookies to operate the site, and analytics cookies only where permitted. You can control cookies through your browser settings.

We do not use advertising cookies. If you arrive through an advertisement, we store the campaign parameters and ad-click identifier from the link in your browser's local storage for up to 90 days, solely to attribute a later enquiry or booked call to the advertisement. This information stays in your browser and is transmitted only to us when you start or send an enquiry or book a call; you can remove it at any time by clearing your browser's site data.

In the Waves console we set an essential cookie for your sign-in session and, if you choose it, a value for a device classified as trusted for two-factor authentication. We do not use analytics or advertising cookies in the console.

16. Changes to this policy

We may update this policy from time to time. The current version is always published on this page with its effective date.

Last updated August 2026