Privacy Policy

How Wardio handles personal data. GDPR is the standard we work to, with Israeli privacy law, including Amendment 13, applying as an additional layer. Questions: privacy@wardioai.com. This document is a draft and has not yet been reviewed by counsel.

Who we are

The controller is Tomer Polat, trading as Tomaso Tech, a sole proprietorship registered in Israel, Derech Ben Gurion 136, Bat Yam, Israel. Contact for privacy matters: privacy@wardioai.com.

What we collect

Only what the service needs to work and to be paid for.

  • Account details: name, email, phone, business details.
  • Billing: payment is handled by Paddle as Merchant of Record; we never store card numbers, only the last four digits and expiry for display.
  • Usage: logs, product events, analytics, subject to your cookie choice.
  • Specific to Wardio: advertising account data you authorised us to read, including campaigns, budgets and performance, obtained only through the official Meta API.

Why we process it

To provide the service, to bill you, to support you, to keep the service secure, to improve the product, and to send marketing only where you have agreed to it.

Email

Operational email is always sent, because it is part of the service. Marketing email is sent only with explicit consent given through a checkbox that is not pre-ticked, and every marketing message unsubscribes in one click. Consent records are kept. This meets the Israeli anti-spam provisions and CAN-SPAM.

Who else sees it

Our sub-processors, each under a data processing agreement. We do not sell personal data.

  • Hosting and infrastructure
  • Database: Supabase
  • Payments: Paddle, as Merchant of Record
  • Email: an email delivery provider
  • AI model providers, which differ by product

Transfers out of your country

Our providers and our customers are in the EU, the UK, the US and Israel, so personal data crosses borders. Transfers rely on recognised mechanisms, principally the Standard Contractual Clauses. [Counsel: confirm the SCC set and alignment with Israeli transfer regulations and Amendment 13.]

Data processing agreement

Business customers in the EU and UK can sign a DPA covering our role as processor, the list of sub-processors and our security commitments. It is available from launch, not later.

Security

Encryption in transit and at rest, access control on a need-to-know basis, audit logging, and a documented procedure for notifying a security incident as the law requires.

Your rights

Access, correction, deletion, objection to marketing and portability. Write to privacy@wardioai.com and we will answer within 30 days.

How long we keep it

For as long as the account is active, plus 30 days. Billing records are kept for seven years because tax law requires it.

Children

The service is not for minors and we do not knowingly collect their data.