Wavio Beta Privacy Policy

Version: Beta 0.9 Effective date: 21 August 2026

1. Who is responsible

Wavio is operated by PREKAS AS, organisation number 938 307 385. PREKAS AS is the controller responsible for the processing described here.

Postal address: Onsøyveien 68, 1614 Fredrikstad, Norway Privacy and rights contact: support@prekas.app

PREKAS AS assumed responsibility for Wavio and existing beta-user information effective 21 August 2026. The purposes of Wavio and the contact route did not change as part of that identity transition.

This policy covers the Wavio app, controlled TestFlight beta, invitations, support and supporting services for individually invited adults in Norway/EEA.

2. Location in plain language

Wavio uses foreground device location to orient the map while the relevant app screen is active. Wavio does not intend to upload a continuous background location track.

When you deliberately check in, Wavio uploads and stores an exact location snapshot together with information such as status, audience, duration and place data. Depending on your selection, the active check-in may be shown to authenticated Wavio users, friends or selected lists. A check-in can therefore reveal your precise location. It is not a live track, and positions or place names can be inaccurate, delayed or outdated.

Wavio and relevant providers also process location-related information to deliver map and place-name functions. Do not use Wavio for navigation, collision avoidance, weather, emergencies or safety-of-life decisions.

Checkout or expiry stops future access by other users through Wavio. Manual checkout deletes the ordinary check-in and its private place record. Automatic expiry immediately removes coordinates, place labels, boat details and audience/list data, leaving only a coordinate-free owner lifecycle record until acknowledgement or automatic deletion no later than 30 days. Information another person has already seen or independently captured cannot necessarily be recalled.

3. Who may use Wavio

Wavio is for people aged 18 or older. Wavio records your confirmation of this rule but does not claim to verify your identity or age unless explicitly stated. If Wavio reasonably believes an account belongs to someone under 18, it may restrict the account and take appropriate deletion steps.

4. Information processed

Wavio may process:

Wavio does not authorise collection for its proposed permanent place-name contribution dataset in this beta pack. Historical check-ins and labels must not be reused for that purpose.

5. Purposes and legal bases

Purpose Intended legal basis under GDPR
Create, authenticate and administer your account; provide requested profiles, check-ins, social features, messaging and notifications Contract — Article 6(1)(b), where the processing is objectively necessary to provide the requested beta service
Process foreground map location and a deliberate check-in/place request Contract — Article 6(1)(b), subject to the documented necessity and minimisation assessment
Record accepted legal versions and your 18+ confirmation Contract for onboarding; legitimate interests — Article 6(1)(f) — for proportionate evidence after acceptance
Protect users, operate blocks/reports, prevent abuse, secure the service and establish or defend claims Legitimate interests — Article 6(1)(f), balanced against user rights and subject to access, retention and appeal safeguards
Operate necessary, minimised Crashlytics stability diagnostics Legitimate interests — Article 6(1)(f), subject to the approved LIA, minimised payload and right to object
Send requested service, account and security communications Contract — Article 6(1)(b), or legitimate interests for proportionate security notices
Send optional Product Updates Consent — Article 6(1)(a), plus applicable electronic-marketing requirements
Administer an initial controlled beta invitation before the recipient joins Legitimate interests — Article 6(1)(f), subject to the invitation assessment, first-contact notice and objection route
Handle qualifying privacy requests and binding lawful demands Legal obligation — Article 6(1)(c), where the specific obligation applies

An operating-system permission is a device control and is not automatically GDPR consent. Where Wavio relies on legitimate interests, you may object; Wavio will assess the circumstances and applicable exceptions.

6. What other users can see

Other users may see account, profile, boat, social-status and check-in information according to the feature and choices in use. Conversation participants receive messages and associated identity or boat context. Recipients can retain information independently of Wavio.

During an active authorised check-in, recipients may receive the check-in identifier, user and boat identifiers, exact coordinates, display label, status and visibility, creation/expiry times and only the recipient-specific audience marker needed by supported clients. The shared response does not include geohash, private suggested/edited place labels or selected-list identifiers. Blocking in either direction, friendship/list removal, checkout and expiry stop future server-authorised access.

7. Providers and international transfers

The beta may use:

Some providers may process information outside Norway/EEA. Where required, Wavio must use an approved transfer mechanism and provide information about relevant safeguards. Provider-controlled technical and security logs may have separate retention.

8. Crash diagnostics and analytics

Wavio retains Firebase Crashlytics only in release builds for necessary stability diagnosis. It may process crash/error data, stack traces, app/device/operating-system context, timestamps and installation/session identifiers. Wavio's custom diagnostics use fixed technical categories and exclude account UID, email domain, precise location, place labels, message content and access tokens. Arbitrary Flutter error messages and context are replaced before the application-controlled handler reports them. Google's standard Crashlytics retention for crash stack traces and associated identifiers is currently recorded as 90 days.

Wavio does not use Firebase Analytics or another outside provider for product, behavioural, advertising or attribution analytics during this beta. The Analytics application dependency/event path is removed, native collection is permanently deactivated, optional Firebase secondary use is off and the former Google Analytics property was unlinked and placed in provider Trash for final deletion.

9. Retention

Wavio retains information only while needed for the stated purpose, with restricted exceptions for safety, security, legal obligations and claims.

Category Intended beta rule
Account/profile/boat information While active. After 12 months without qualifying user activity, Wavio intends to give 30 days' notice, reminders with 7 days and 24 hours remaining, and delete through the verified account process unless activity or an explicit keep-account action cancels deletion
Active check-in Until checkout or expiry; other-user access must stop immediately
Precise post-expiry check-in information Strip or delete as soon as operationally safe and no later than 30 days; prefer complete ordinary-record deletion
Place-resolution cache/rate limits Delete at their configured expiry after TTL is verified
Routine stripped safety/moderation records Delete 12 months after case closure
Serious/repeated stripped safety evidence Maximum 36 months with annual review; longer only for a specific documented dispute, claim or binding duty
Ordinary security/technical logs 90 days by default; longer only for a documented active incident or claim
Crashlytics Provider's documented 90-day cycle, without longer Wavio export unless justified
User-visible notification records Intended maximum 90 days
Shared active Conversation While needed by an active participant, subject to an intended 24-month inactivity maximum with 30-day and 7-day notices where contact remains possible; qualifying activity cancels purge
Unaccepted invitation Link expires after 7 days; direct invitation data stripped/deleted within the verified 30-day boundary
Completed invitation after inviter deletion Replace inviter with a fixed tombstone and delete the residual record after 30 days unless a specific active complaint has a documented hold
Accepted beta-participation record Beta participation plus 90 days unless converted into an account relationship or needed for an active matter
Routine support case 12 months after closure
Minimal rights-request/acceptance evidence Maximum 3 years, restricted and limited to what is necessary to demonstrate compliance or resolve a dispute; subject to final LIA/counsel review
Account-deletion completion marker UID only as the record key with bounded status/timestamps; delete 30 days after successful completion
Provider logs, replicas and backups Removed or isolated under the relevant provider's documented schedule; Wavio does not claim immediate physical purge where provider evidence does not support it

Where Wavio controls backups, it targets the shortest feasible rolling cycle and no more than 35 days. Deleted live data will not be restored for ordinary use; if disaster recovery restores an older copy, completed deletions must be reapplied before normal service resumes. Provider-controlled limits remain subject to verification.

Messages shared with another participant require special explanation: account deletion removes the departing user's authored messages under the reviewed design, while the other participant retains their own messages in an archived/read-only conversation. Information another person independently copied is outside Wavio's control.

10. Account deletion and your rights

You can initiate account deletion through Settings or contact support. Once deletion starts, ordinary access and previously issued device sessions are blocked. Wavio deletes the account, profile, boats and public projections, check-ins and private place records, media, social state, notification tokens and the departing user's authored messages before deleting the authentication identity. If cleanup fails, access remains blocked, retry is automatic and support is alerted. The completion marker is deleted after 30 days.

Another participant may retain their own messages in a read-only archived Conversation, where the deleted person is shown only as a former Wavio user. When no real participant remains, Wavio deletes the remaining Conversation tree. Narrowly stripped moderation evidence may remain for the periods above. Provider logs, replicas and backups may be removed later under provider schedules.

Where GDPR applies, you may have rights to access, correct, erase or restrict information; object to certain processing; receive qualifying information in a portable format; withdraw consent where consent is used; and complain to Datatilsynet or another competent supervisory authority. Legal conditions and exceptions may apply.

Contact support@prekas.app. Wavio may request proportionate information to verify the requester's identity and will respond within the legally required period.

Datatilsynet: www.datatilsynet.no

11. Safety and security

Wavio uses measures intended to protect information, including authenticated access, private/shared record separation, backend access rules, provider controls, testing and deletion processes. No online service can guarantee absolute security. Protect your credentials and report suspected misuse.

Reports are not monitored as an emergency channel. Contact local emergency services if there is immediate danger.

12. Automated decisions

Wavio does not make solely automated decisions that produce legal or similarly significant effects during this beta.

13. Changes and contact

This policy will identify its version and effective date. Wavio will communicate material changes appropriately and request renewed acceptance or consent where required.

PREKAS AS (org. no. 938 307 385)

Onsøyveien 68, 1614 Fredrikstad, Norway

support@prekas.app