# Privacy Notice for Waterglass Waves

> How Waterglass processes personal data in the Waterglass Waves platform: accounts, billing, operation, the content customers process, AI model providers and subprocessors.

Canonical: https://www.waterglass.ai/en/products/waves/privacy/
Language: English (Deutsch: https://www.waterglass.ai/de/produkte/waves/datenschutz.md)
Company: Waterglass FlexCo, Börseplatz 1/3/6, 1010 Vienna, Austria · hi@waterglass.ai

Updated: September 2026

## 1. Controller, contact and scope

The controller for the processing described here is Waterglass FlexCo, Vienna, represented by its managing director Bernhard Hauser. You can reach us at [hi@waterglass.ai](mailto:hi@waterglass.ai), and our postal address is stated in the [imprint](https://www.waterglass.ai/en/imprint/). We have not appointed a data protection officer, because the statutory conditions for one are not met. The contact person for data protection matters is Bernhard Hauser, reachable at the same address.

This notice applies to the Waterglass Waves platform, that is the console at waves.waterglass.ai, the application programming interface, the command-line tools and the execution environments in which AI agents run. It supplements the [Product Terms for Waterglass Waves](https://www.waterglass.ai/en/products/waves/terms/) and the [data processing agreement](https://www.waterglass.ai/en/products/waves/data-processing-agreement/), which governs the processing on behalf of customers contractually. Our [privacy policy](https://www.waterglass.ai/en/privacy/) applies to the website www.waterglass.ai.

## 2. Two roles

For the data of your account, your organisation, billing and technical operation, we are the controller. For the content you process in Waves as a customer, you are the controller and we are the processor. We process that content only to provide the service and in accordance with your instructions. Data subjects whose data a customer processes in Waves should contact that customer. We support the customer in this as processor.

For the evaluation for our own purposes described in section 7, we are the controller (Article 28(10) GDPR).

## 3. Account and sign-in

To register and operate an account, we process your name, your email address, your sign-in data in secured form, the name of your organisation and technical details of the registration as evidence of the conclusion of the contract. For API keys we store a label, the scope, the expiry and the time of last use, not the key itself.

When you sign in and on every access, our servers process the technical connection data in order to keep the service running and to detect and limit abuse. These logs are retained only for a short period.

Name, email address, password and organisation name are required, and without them no account can be created. Unconfirmed registrations are removed after a short time. The legal basis for the account is the usage contract (Article 6(1)(b) GDPR). Logs and the protection against abuse rest on our legitimate interest in secure and stable operation (Article 6(1)(f) GDPR).

## 4. Billing

For billing we process your name, your billing address, a VAT identification number you provide, your customer number with our payment service provider Stripe, invoices and payment transactions, and your consumption, that is tokens used, model and cost per day. Card details are entered exclusively with Stripe and do not reach our systems. If you activate automatic credit top-up, we store the time, the IP address and the settings you chose as evidence of your consent.

Invoices for self-service plans are issued through Stripe and held there, and we issue invoices for the "Managed" plan ourselves. We retain invoices and the associated records, including the consumption records and the credit ledger, for seven years (§ 132 BAO (Austrian Federal Fiscal Code) and § 11 UStG (Austrian VAT Act)). The legal bases are the usage contract (Article 6(1)(b) GDPR) and our legal obligations (Article 6(1)(c) GDPR).

## 5. The built-in assistant and feature requests

The console includes an assistant that reads and changes settings on your instruction. Conversations with it are stored and assigned to your user account. You can request their deletion at any time. The model behind the assistant is operated within the European Union. We may evaluate these conversations in summarised form to improve the assistant, on the basis of our legitimate interest (Article 6(1)(f) GDPR). Your organisation can switch this evaluation off in the settings.

If you send us a feature request through the assistant, we receive your name, your email address and the name of your organisation with it so that we can follow up. Nothing is sent without your confirmation.

## 6. Operation, security and prevention of abuse

Operation includes automatic monitoring that notifies us of faults. It receives operational metrics and alert texts, in individual cases the email address of a newly confirmed account, but no content from runs. For this we use the monitoring and notification services named in section 12.

The legal basis is our legitimate interest in a secure and stable operation and in the prevention of abuse (Article 6(1)(f) GDPR).

## 7. Usage analysis and content classification

To operate, secure and develop the platform, we evaluate technical usage data of runs, such as the model used, volume, duration and cost. The content of a run is not part of this evaluation. The legal basis is our legitimate interest in the operation and improvement of the service (Article 6(1)(f) GDPR).

We may additionally introduce an automated classification of content by usage category. Before we activate it, we inform you. Personal details are removed beforehand as far as possible, the evaluation takes place within the European Union, only categories and metrics are retained, and no profiles of individual persons are created. Your organisation can switch the classification off at any time. For this evaluation we act as controller on the basis of our legitimate interest (Article 6(1)(f) GDPR).

## 8. Content you process in Waves

Waves stores the content you contribute or that arises during a run, in particular the configuration of your AI agents, the trails and results of runs, the documents of your knowledge bases and the selections you make for connected services.

The trail of a run is the record of what an agent did. If you delete a finished run, it is deleted permanently. Data in backups is removed at the end of the backup cycle. The deletion of an account or an organisation is carried out on request (section 14).

Credentials you store are held in encrypted form only. We do not use your content to train AI models. The only exception is a service you expressly order, such as the distillation of a model on your own content.

## 9. AI model providers

So that an AI agent can work, the content of a run is transmitted to the operator of the model you selected for that agent. The call runs through our own gateway, which stores neither inputs nor outputs.

The recipient is whoever operates the deployment we call, which is not always the company that developed the model. With processing in the European Union these are currently Amazon Web Services EMEA SARL (Luxembourg), Microsoft Ireland Operations Limited (Ireland), Google Cloud EMEA Limited (Ireland) and Mistral AI (France), each on the basis of a data processing agreement. Outside the Union, and only if you select such a model, it is Anthropic, PBC (United States) on the basis of its terms with a data processing addendum and standard contractual clauses. The console states for every model which operator provides it and in which country.

Operators may retain transmitted content for a limited period in order to detect misuse of their services, as a rule up to 30 days, and that can include inspection by the operator's personnel. With Amazon Web Services, retention is excluded. Anthropic retains content that its systems classify as a violation of its usage policy for considerably longer. This retention serves the security of the respective service and no purpose of ours.

You decide for each AI agent which model may be used. If a fallback model is configured, the same content may go to its operator, possibly in a different country. The console points this out to you.

Regardless of the language model selected, we transmit documents you upload to a knowledge base, as well as your search queries within it, to Mistral AI (France) in order to prepare them for search.

## 10. Services you connect and access to the internet

If you connect a third-party service to Waves, you authorise that connection yourself in the respective service and with the permissions displayed in the process. An agent then acts with the permissions of the person who established the connection, and the data exchanged goes to that service. We keep the access tokens in encrypted form.

If you give an agent access to the internet or store your own tool servers and network destinations, you determine the recipients of the data transmitted in the process. They are not processors engaged by us. Without such an authorisation, the execution environments reach only our own services.

## 11. Web search

If you allow the web search tool for an agent, we transmit the search query to Google, whichever language model is used. Google stores logs containing the query and its context for up to three days, not associated with you or your users. That storage cannot be switched off, and Google does not undertake to process the data inside the European Union for this feature. For this tool Google is our processor and appears in our list of subprocessors. The tool is active only if you allow it for an agent.

## 12. Recipients and subprocessors

For Waves we engage Hetzner Online GmbH (Germany) for computing, storage and backups in data centres in Germany, Stripe (Stripe Payments Europe, Ltd., Ireland) for payments and invoices, Resend (Resend, Inc., processing in Ireland) for account emails, the model operators named in section 9, Google for the web search under section 11, and the services healthchecks.io and ntfy.sh for the monitoring under section 6.

The current [list of subprocessors](https://www.waterglass.ai/en/subprocessors/) engaged for Waves, with purpose and country of processing, is published on our website and forms part of the data processing agreement.

## 13. Transfers to third countries

The operation of the Waves platform itself, including databases, object storage and backups, takes place in the European Union. The same applies to payment processing and to the sending of emails. Transfers to third countries therefore arise only from the choice of AI model, from the web search tool where you allow it, and from services outside the Union that you connect yourself. For most models a version operated inside the Union is available, so that no such transfer occurs.

Where no adequacy decision of the European Commission covers a recipient, we base the transfer on the standard contractual clauses of the European Commission and supplementary measures. The only such recipient for Waves is Anthropic in the United States, and only if you select one of its models processed there. Where a service provider established in the Union processes outside it on our behalf, as is the case for the web search tool, we rely on the transfer safeguards in that provider's own data protection terms. For service providers established outside the European Union that process within the Union on our behalf, we additionally base any access from their country of establishment on the standard contractual clauses.

If you require processing exclusively within the European Union in Waves, select a model operated in the Union, which is possible for most of the models we offer, leave the web search tool switched off, and refrain from connections to services outside the Union.

The infrastructure on which Waves is operated is located in the European Union and is subject to the law of the Union and its member states. We protect your data against unlawful access by authorities of third countries by operating and backing up exclusively within the Union, by encryption, by restricted and logged administrative access, and by handing data over to authorities only on the basis of an order binding under Union law or the law of a member state. This information is provided in accordance with Article 28 of Regulation (EU) 2023/2854 (Data Act).

## 14. Retention and deletion

Account and organisation data are stored for the term of the contract and for the subsequent transitional and retrieval period under § 5a of the product terms. Content you process in Waves is stored until you delete it or until the end of that period. Invoices and the associated records are retained for seven years (§ 132 BAO). Server logs are retained only for a short period. Encrypted backups are kept for a few weeks at a second location in the same country, and a deletion takes effect there only when that cycle has elapsed.

You delete individual runs yourself. The deletion of your account or organisation, including all content, is carried out on request to [support@waterglass.ai](mailto:support@waterglass.ai) and confirmed if you wish.

## 15. Security of processing

We take technical and organisational measures appropriate to the risk, in particular operation of our own systems exclusively within the European Union, transport encryption, encrypted storage of credentials and backups, and execution environments separated per run. The measures are described in detail in the data processing agreement.

Administrative access to the systems is limited to a very small group of persons, confined to operation, fault diagnosis and recovery, and logged.

## 16. Cookies in the console

In the Waves console we set an essential cookie for your sign-in session and, if you choose it, a value for a device classified as trusted for two-factor authentication, which is valid for 30 days. We do not use analytics or advertising cookies in the console.

## 17. Your rights

Under the GDPR you have the right of access to the data stored about you (Article 15), to rectification (Article 16), to erasure (Article 17), to restriction of processing (Article 18) and to data portability (Article 20). You may withdraw any consent you have given at any time with effect for the future. The lawfulness of the processing carried out until the withdrawal remains unaffected.

To exercise your rights, contact [support@waterglass.ai](mailto:support@waterglass.ai). We respond within one month. Where there are reasonable doubts about your identity, we may request additional information to verify it.

## 18. Right to object

Where we process your data on the basis of a legitimate interest under Article 6(1)(f) GDPR, you have the right to object to that processing at any time on grounds relating to your particular situation (Article 21 GDPR). We then no longer process the data unless we can demonstrate compelling legitimate grounds for the processing that override your interests, rights and freedoms, or the processing serves the establishment, exercise or defence of legal claims.

You may object to processing for the purpose of direct marketing at any time without stating reasons. Send your objection to [support@waterglass.ai](mailto:support@waterglass.ai).

## 19. Right to lodge a complaint

You have the right to lodge a complaint with a data protection supervisory authority, in particular in the member state of your habitual residence, your place of work or the place of the alleged infringement. The authority competent for us is the Austrian Data Protection Authority (Datenschutzbehörde), Barichgasse 40–42, 1030 Vienna, [www.dsb.gv.at](https://www.dsb.gv.at).

## 20. Obligation to provide data and automated decisions

You are neither legally nor contractually obliged to provide us with personal data. Without the information marked as required in the individual sections, however, we cannot provide the respective service, for example answer an enquiry, send a report or maintain an account.

No automated decision-making producing legal effects or similarly significant effects within the meaning of Article 22 GDPR takes place.

## 21. Changes

We update this privacy information when our processing, the legal situation or our service providers change. The version in force is published on this page together with its date. We additionally inform customers with a current contract in text form about material changes that affect them.
