Wavio Beta Privacy Policy

Version: Beta 0.9.1 working update Effective date: Not effective — publication pending

1. Who is responsible

Wavio is operated by PREKAS AS, organisation number 938 307 385. PREKAS AS is the controller responsible for the processing described here.

Postal address: Onsøyveien 68, 1614 Fredrikstad, Norway Privacy and rights contact: support@prekas.app

PREKAS AS assumed responsibility for Wavio and existing beta-user information effective 21 August 2026. The purposes of Wavio and the contact route did not change as part of that identity transition.

This policy covers the Wavio app, controlled TestFlight beta, invitations, support and supporting services for individually invited adults in Norway/EEA.

2. Location in plain language

Wavio uses foreground device location to orient the map while the relevant app screen is active. Wavio does not intend to upload a continuous background location track.

When you deliberately check in, Wavio uploads and stores an exact location snapshot together with information such as status, audience, duration and place data. Depending on your selection, the active check-in may be shown to authenticated Wavio users, friends or selected lists. A check-in can therefore reveal your precise location. It is not a live track, and positions or place names can be inaccurate, delayed or outdated.

Wavio and relevant providers also process location-related information to deliver map and place-name functions. Do not use Wavio for navigation, collision avoidance, weather, emergencies or safety-of-life decisions.

Checkout or expiry stops future access by other users through Wavio. Manual checkout deletes the ordinary check-in and its private place record. Automatic expiry immediately removes coordinates, place labels, boat details and audience/list data, leaving only a coordinate-free owner lifecycle record until acknowledgement or automatic deletion no later than 30 days. Information another person has already seen or independently captured cannot necessarily be recalled.

3. Who may use Wavio

Wavio is for people aged 18 or older. Wavio records your confirmation of this rule but does not claim to verify your identity or age unless explicitly stated. If Wavio reasonably believes an account belongs to someone under 18, it may restrict the account and take appropriate deletion steps.

4. Information processed

Wavio may process:

Wavio does not authorise collection for its proposed permanent place-name contribution dataset in this beta pack. Historical check-ins and labels must not be reused for that purpose.

Most information comes directly from you or is created when you use Wavio. Technical information may come from your device, operating system or the providers used to deliver Wavio. Another person may provide limited information about you, for example an email address or name for a beta invitation, a message, a friendship request or a safety report. Wavio may derive limited operational information such as access status, geohash cells, rate-limit categories, deletion status and fixed former-user or former-boat labels. Wavio does not purchase personal-data profiles or obtain advertising-audience data during this beta.

5. Purposes and legal bases

Purpose Intended legal basis under GDPR
Create, authenticate and administer your account; provide requested profiles, check-ins, social features, messaging and notifications Contract — Article 6(1)(b), where the processing is objectively necessary to provide the requested beta service
Process foreground map location and a deliberate check-in/place request Contract — Article 6(1)(b), subject to the documented necessity and minimisation assessment
Record accepted legal versions and your 18+ confirmation Contract for onboarding; legitimate interests — Article 6(1)(f) — for proportionate evidence after acceptance
Protect users, operate blocks/reports, prevent abuse, secure the service and establish or defend claims Legitimate interests — Article 6(1)(f), balanced against user rights and subject to access, retention and appeal safeguards
Operate necessary, minimised Crashlytics stability diagnostics Legitimate interests — Article 6(1)(f), subject to the approved LIA, minimised payload and right to object
Send requested service, account and security communications Contract — Article 6(1)(b), or legitimate interests for proportionate security notices
Send optional Product Updates requested in the app or at https://wavio.no/updates/ Consent — Article 6(1)(a), plus applicable electronic-marketing requirements
Administer an initial controlled beta invitation before the recipient joins Legitimate interests — Article 6(1)(f), subject to the invitation assessment, first-contact notice and objection route
Handle qualifying privacy requests and binding lawful demands Legal obligation — Article 6(1)(c), where the specific obligation applies

An operating-system permission is a device control and is not automatically GDPR consent. Where Wavio relies on legitimate interests, you may object; Wavio will assess the circumstances and applicable exceptions.

6. What other users can see

Other users may see account, profile, boat, social-status and check-in information according to the feature and choices in use. Conversation participants receive messages and associated identity or boat context. Recipients can retain information independently of Wavio.

Only the current active boat may have Wavio's public boat projection. Crew Profile information is shown with that active boat only when the account-level Crew sharing control is on and sharing is assigned to that boat. Boat flag has its own per-boat sharing control and is shown only on the full Boat Profile when enabled. Turning sharing off, removing a value, changing the active boat or deleting the relevant boat must remove the corresponding public projection; private saved values remain until corrected or deleted by the account holder or removed through the applicable deletion lifecycle.

During an active authorised check-in, recipients may receive the check-in identifier, user and boat identifiers, exact coordinates, display label, status and visibility, creation/expiry times and only the recipient-specific audience marker needed by supported clients. The shared response does not include geohash, private suggested/edited place labels or selected-list identifiers. Blocking in either direction, friendship/list removal, checkout and expiry stop future server-authorised access.

7. Providers and international transfers

The beta may use:

Some providers may process information outside Norway/EEA. Where required, Wavio must use an approved transfer mechanism and provide information about relevant safeguards. Provider-controlled technical and security logs may have separate retention.

Wavio may include user-initiated links to independent websites or services. The independent provider's own privacy information applies when you choose to leave Wavio. PREKAS AS remains responsible for its own product design and for its use of processors.

If the Wavio operation is reorganised, financed, merged, sold or transferred, relevant information may be disclosed or transferred where necessary for that process and permitted by law. PREKAS AS will apply confidentiality, data minimisation and security controls, ensure that a receiving controller has a lawful basis, and inform affected users where required. A transaction does not permit personal information to be used for unrelated purposes without a separate lawful basis.

8. Crash diagnostics and analytics

Wavio retains Firebase Crashlytics only in release builds for necessary stability diagnosis. It may process crash/error data, stack traces, app/device/operating-system context, timestamps and installation/session identifiers. Wavio's custom diagnostics use fixed technical categories and exclude account UID, email domain, precise location, place labels, message content and access tokens. Arbitrary Flutter error messages and context are replaced before the application-controlled handler reports them. Google's standard Crashlytics retention for crash stack traces and associated identifiers is currently recorded as 90 days.

Wavio does not use Firebase Analytics or another outside provider for product, behavioural, advertising or attribution analytics during this beta. The Analytics application dependency/event path is removed, native collection is permanently deactivated, optional Firebase secondary use is off and the former Google Analytics property was unlinked and placed in provider Trash for final deletion.

Optional Product Updates

Product Updates are voluntary and separate from surveys, beta access, account creation and necessary service, security or legal messages. You can request them in Wavio or through the public form at https://wavio.no/updates/. The public form asks for your email address, explicit consent and confirmation that you are at least 18. It then sends a private, single-use confirmation link that expires after 24 hours. No Product Updates subscription or withdrawal takes effect until that link is used.

For a public request, Wavio temporarily processes the email address, a hashed address reference, requested action, consent version and time, age confirmation, request expiry and bounded delivery/provider-sync state. Wavio's application does not store your IP address, user agent or request/query logs for this flow and does not use page analytics, open tracking or click tracking for it. Cloudflare still processes ordinary connection, routing and security metadata when it delivers and protects the page and request service. The confirmation email is an operational message for the action you requested. Resend processes the address, delivery information and the preference for Wavio's dedicated Product Updates topic on behalf of PREKAS AS.

Every Product Update includes a free unsubscribe route. You may also withdraw using the public form without a Wavio account. Confirmed withdrawal stops future Product Updates promptly. Wavio may retain the minimum consent, withdrawal or suppression evidence needed to demonstrate and honour your choice; it will not use that evidence to restart Product Updates or for an unrelated purpose.

9. Retention

Wavio retains information only while needed for the stated purpose, with restricted exceptions for safety, security, legal obligations and claims.

Category Intended beta rule
Account/profile/private Crew Profile information While active. After 12 months without qualifying user activity, Wavio intends to give 30 days' notice, reminders with 7 days and 24 hours remaining, and delete through the verified account process unless activity or an explicit keep-account action cancels deletion
Individual boat information, media and private Boat flag choice While the boat remains in the account; removed through the verified individual-boat or account-deletion process. Public projections are removed on sharing withdrawal, active-boat change or deletion
Active check-in Until checkout or expiry; other-user access must stop immediately
Precise post-expiry check-in information Strip or delete as soon as operationally safe and no later than 30 days; prefer complete ordinary-record deletion
Place-resolution cache/rate limits Delete at their configured expiry after TTL is verified
Routine stripped safety/moderation records Delete 12 months after case closure
Serious/repeated stripped safety evidence Maximum 36 months with annual review; longer only for a specific documented dispute, claim or binding duty
Ordinary security/technical logs 90 days by default; longer only for a documented active incident or claim
Crashlytics Provider's documented 90-day cycle, without longer Wavio export unless justified
Public Product Updates request Unconfirmed confirmation link expires after 24 hours; the bounded pending/audit request is logically deleted after 7 days. The current Workers Free plan also keeps Cloudflare D1 recovery history for 7 days. After confirmation, keep the active preference while subscribed and only the minimum consent, withdrawal and suppression evidence needed to demonstrate and honour the choice
User-visible notification records Intended maximum 90 days
Shared active Conversation While needed by an active participant, subject to an intended 24-month inactivity maximum with 30-day and 7-day notices where contact remains possible; qualifying activity cancels purge
Unaccepted invitation Link expires after 7 days; direct invitation data stripped/deleted within the verified 30-day boundary
Completed invitation after inviter deletion Replace inviter with a fixed tombstone and delete the residual record after 30 days unless a specific active complaint has a documented hold
Accepted beta-participation record Beta participation plus 90 days unless converted into an account relationship or needed for an active matter
Routine support case 12 months after closure
Minimal rights-request/acceptance evidence Maximum 3 years, restricted and limited to what is necessary to demonstrate compliance or resolve a dispute; subject to final LIA/counsel review
Account-deletion completion marker UID only as the record key with bounded status/timestamps; delete 30 days after successful completion
Provider logs, replicas and backups Removed or isolated under the relevant provider's documented schedule; Wavio does not claim immediate physical purge where provider evidence does not support it

Where Wavio controls backups, it targets the shortest feasible rolling cycle and no more than 35 days. Deleted live data will not be restored for ordinary use; if disaster recovery restores an older copy, completed deletions must be reapplied before normal service resumes. Provider-controlled limits remain subject to verification.

Messages shared with another participant require special explanation: account deletion removes the departing user's authored messages under the reviewed design, while the other participant retains their own messages in an archived/read-only conversation. Information another person independently copied is outside Wavio's control.

10. Account deletion and your rights

You can initiate account deletion through Settings or contact support. Once deletion starts, ordinary access and previously issued device sessions are blocked. Wavio deletes the account, profile, boats and public projections, check-ins and private place records, media, social state, notification tokens and the departing user's authored messages before deleting the authentication identity. If cleanup fails, access remains blocked, retry is automatic and support is alerted. The completion marker is deleted after 30 days.

Another participant may retain their own messages in a read-only archived Conversation, where the deleted person is shown only as a former Wavio user. When no real participant remains, Wavio deletes the remaining Conversation tree. Narrowly stripped moderation evidence may remain for the periods above. Provider logs, replicas and backups may be removed later under provider schedules.

Where GDPR applies, you may have rights to access, correct, erase or restrict information; object to certain processing; receive qualifying information in a portable format; withdraw consent where consent is used; and complain to Datatilsynet or another competent supervisory authority. You can withdraw Product Updates consent through the unsubscribe link, the public withdrawal form or the available in-app control. Legal conditions and exceptions may apply.

Contact support@prekas.app. Wavio may request proportionate information to verify the requester's identity. Wavio will normally respond within one month. If a lawful extension is necessary because a request is complex or numerous requests are received, Wavio will explain the extension and reason within the original one-month period.

Where required and not impossible or disproportionate, Wavio will notify relevant recipients when personal information is corrected, erased or restricted and will identify those recipients on request. Qualifying information supplied by you and processed by automated means on the basis of consent or contract may be provided in a structured, commonly used and machine-readable format. Rights are not absolute; if Wavio cannot fulfil a request in whole or in part, it will explain the applicable reason and available complaint route.

Datatilsynet: www.datatilsynet.no

11. Safety and security

Wavio uses measures intended to protect information, including authenticated access, private/shared record separation, backend access rules, provider controls, testing and deletion processes. No online service can guarantee absolute security. Protect your credentials and report suspected misuse.

Reports are not monitored as an emergency channel. Contact local emergency services if there is immediate danger.

12. Automated decisions

Wavio does not make solely automated decisions that produce legal or similarly significant effects during this beta.

13. Changes and contact

This policy will identify its version and effective date. Wavio will communicate material changes appropriately and request renewed acceptance or consent where required.

The Wavio website uses no product analytics, advertising trackers or non-essential cookies at the verified Beta 0.9 boundary. Website delivery and security metadata processed by Cloudflare is described in the Website and Cookie Notice. That notice must be updated before any non-essential cookie, tracking pixel, analytics tag or similar storage technology is introduced.

PREKAS AS (org. no. 938 307 385)

Onsøyveien 68, 1614 Fredrikstad, Norway

support@prekas.app