Privacy Policy
How Wardio handles personal data. GDPR is the standard we work to, with Israeli privacy law, including Amendment 13, applying as an additional layer. Questions: privacy@wardioai.com. This document is a draft and has not yet been reviewed by counsel.
Who we are
The controller is Tomer Polat, trading as Tomaso Tech, a sole proprietorship registered in Israel, Derech Ben Gurion 136, Bat Yam, Israel. Contact for privacy matters: privacy@wardioai.com.
What we collect
Only what the service needs to work and to be paid for.
- Account details: name, email, phone, business details.
- Billing: payment is handled by Paddle as Merchant of Record; we never store card numbers, only the last four digits and expiry for display.
- Usage: logs, product events, analytics, subject to your cookie choice.
- Specific to Wardio: advertising account data you authorised us to read, including campaigns, budgets and performance, obtained only through the official Meta API.
Why we process it
To provide the service, to bill you, to support you, to keep the service secure, to improve the product, and to send marketing only where you have agreed to it.
Operational email is always sent, because it is part of the service. Marketing email is sent only with explicit consent given through a checkbox that is not pre-ticked, and every marketing message unsubscribes in one click. Consent records are kept. This meets the Israeli anti-spam provisions and CAN-SPAM.
Who else sees it
Our sub-processors, each under a data processing agreement. We do not sell personal data.
- Hosting and infrastructure
- Database: Supabase
- Payments: Paddle, as Merchant of Record
- Email: an email delivery provider
- AI model providers, which differ by product
Transfers out of your country
Our providers and our customers are in the EU, the UK, the US and Israel, so personal data crosses borders. Transfers rely on recognised mechanisms, principally the Standard Contractual Clauses. [Counsel: confirm the SCC set and alignment with Israeli transfer regulations and Amendment 13.]
Data processing agreement
Business customers in the EU and UK can sign a DPA covering our role as processor, the list of sub-processors and our security commitments. It is available from launch, not later.
Security
Encryption in transit and at rest, access control on a need-to-know basis, audit logging, and a documented procedure for notifying a security incident as the law requires.
Your rights
Access, correction, deletion, objection to marketing and portability. Write to privacy@wardioai.com and we will answer within 30 days.
How long we keep it
For as long as the account is active, plus 30 days. Billing records are kept for seven years because tax law requires it.
Children
The service is not for minors and we do not knowingly collect their data.