Last updated: 2026-09-01
Compliance attestation
Where WAVE stores your data, who can access it, and how long it stays. Vendor-by-vendor breakdown of every subprocessor in the path.
Effective date: 2026-05-01 · Last reviewed: 2026-09-01
Region pinning
Enterprise customers can pin all PII + audit storage to US-only or EU-only regions via the inference_geo account setting. Default is multi-region edge.
At-rest encryption
AES-256 on every storage tier. Supabase and Cloudflare R2 encrypt by default. Customer-managed keys available for enterprise.
Right to deletion
GDPR/CCPA deletion requests honored within 30 days. EU AI Act Article 26 audit rows are excluded — they retain for 5 years per Article 26 §4.
Subprocessors that hold customer data
Every vendor below both processes customer data and is live in the current going-forward stack — the same list published on our Trust Center, sourced from a single registry so the two pages cannot disagree.
| Vendor | Category | Role |
|---|---|---|
| Cloudflare | Infrastructure & data | Edge compute, CDN, storage, DNS, and AI inference (speech-to-text, embeddings) — SOC 2 Type II |
| Supabase | Infrastructure & data | Application database & authentication — SOC 2 Type II |
| PostHog | Infrastructure & data | Product analytics — pseudonymous usage events, never message content |
| Upstash | Infrastructure & data | Redis cache & message queue |
| Stripe | Payments | Payments, subscriptions & metered billing — PCI DSS / SOC 2 Type II |
| Bridge | Payments | Stablecoin on/off-ramp & KYB verification |
| Privy | Payments | Embedded & smart-wallet provisioning and key management |
| Tempo | Payments | Stablecoin settlement (pathUSD) |
| Coinbase CDP | Payments | Wallet infrastructure & gas sponsorship |
| Metronome | Payments | Usage-based billing metering |
| Twilio | Communications | Inbound & outbound telephony and A2P messaging |
| Resend | Communications | Transactional & notification email |
| Zoom | Media & video | Meeting recording import, with your authorization |
| Deepgram | AI inference | Speech-to-text transcription |
| ElevenLabs | AI inference | Text-to-speech voice synthesis |
| Groq | AI inference | Low-latency language-model inference |
| RunPod | AI inference | GPU compute for AI inference and media transcoding |
Retention buckets
Each data class has a defined retention period. After expiry the data is purged automatically — no manual sweep.
| Class | Retention | Why |
|---|---|---|
| Active stream metadata | Until deletion | User-controlled |
| VOD recordings | Default 30 days; Scale (custom, on request) | Configurable per account |
| Argus audit + Article 26 receipts | 5 years | EU AI Act §4 mandate |
| Payment records | 7 years | SOX + tax compliance |
| Application logs | 90 days | Operational only |
Cross-border data transfer controls
For transfers from the EU/EEA/UK to the US, WAVE relies on Standard Contractual Clauses (SCCs) and the EU-US Data Privacy Framework. Our DPA at /legal/dpa is GDPR Article 28 compliant and signed before any EU customer data is processed.
Enterprise customers can require all storage + processing to remain in their region (EU, US, or UK). Contact enterprise sales for regional pinning.
What happens when you delete your account
- Account marked deleted (soft) within 1 minute.
- Stream metadata + VOD recordings purged within 24 hours.
- Cloudflare R2 objects purged within 7 days (CDN cache TTL).
- Supabase rows purged within 30 days (GDPR/CCPA deadline).
- Backups age out within 35 days. After day 35, no copy exists.
- Argus + payment records retained per legal mandate (5y / 7y).
Data subject access requests (DSAR)
Email privacy@wave.online with subject “DSAR” and we will respond within 30 days. Requests we honor:
- Export — all data we hold about you, in JSON
- Correct — fix inaccurate fields
- Delete — remove all non-mandated data (see retention)
- Restrict — pause processing while we resolve a dispute
- Portability — JSON export suitable for import to another platform
Related compliance pages
- EU AI Act Article 26 5-year audit retention, immutable logs, per-agent decision-log export.
- Data Processing Addendum GDPR Article 28 DPA. Signed before any EU customer data flows.
- Service Level Agreement Tiered monthly uptime targets and support response times. The same SLA covers traffic from agents and people.
- Privacy Policy Full GDPR + CCPA disclosure of data we collect and why.
Need a region pin or audit attestation?
Enterprise customers can require regional pinning + custom retention buckets. Procurement can request a signed compliance attestation.