Privacy Policy
May 9, 2026
QAWave s.r.o. is committed to protecting your privacy. This policy describes how we collect, use, and protect your personal data in compliance with GDPR.
1. Data Controller
QAWave s.r.o., registered in the Czech Republic. Contact: privacy@qawave.ai.
2. Data We Collect
Contact information: name, email address, company name, job title — provided when you book a call, subscribe to our newsletter, or contact us.
Usage data: anonymized analytics about how you interact with qawave.ai, collected via privacy-respecting analytics.
Customer data: source code access and CI/CD logs are processed solely to deliver contracted services and are not stored beyond the engagement period.
3. How We Use Your Data
To deliver contracted QA services. To respond to inquiries and schedule calls. To send newsletter updates (with explicit consent, unsubscribe anytime). To improve our website and services.
4. Data Storage and Security
All data is hosted in the EU (Frankfurt, Germany) on Vercel and Supabase infrastructure. We use encryption in transit (TLS 1.3) and at rest. Access to customer data is restricted to authorized personnel only.
5. Your Rights
Under GDPR, you have the right to: access your personal data, request correction or deletion, object to processing, data portability, and lodge a complaint with the Czech Data Protection Authority (ÚOOÚ).
To exercise any of these rights, contact privacy@qawave.ai.
6. Data Retention
Contact data: retained for the duration of our business relationship plus 3 years. Customer engagement data: deleted within 90 days of engagement completion unless otherwise agreed. Newsletter subscriptions: until you unsubscribe.
7. Cookies
qawave.ai uses only essential cookies required for the website to function. We do not use tracking cookies or third-party advertising cookies.