Loading
Loading
Europe
Wrati is developing its European privacy architecture with GDPR principles in mind. This page describes what has been built, and is equally clear about what has not.
What this page is, and is not
This is a description of how Wrati is built. It is not legal advice, and Wrati does not claim to be “GDPR compliant” or GDPR certified — those are assessments for qualified advisers and supervisory authorities, not for a product team. Whether the GDPR applies to Wrati at all depends on how and where it offers services: applicability subject to legal assessment.
A principle without a mechanism is a slogan. Each of these points at something that exists in the product.
Consent for optional processing is captured explicitly and recorded with a timestamp and policy version. Marketing consent is kept separate from service communications, so agreeing to one never silently grants the other.
Content is processed for safety and matching. It is not used to build advertising profiles, and connected-account permissions are scoped to the specific capability granted rather than inherited from sign-in.
Optional profile fields stay optional. Precise location is used for proximity features and can be constrained through discovery settings.
Profile information, preferences and stated intentions are editable at any time, and changes take effect immediately.
Deleted accounts are retained for a limited window and then permanently purged along with associated records. The specific retention period is pending legal assessment and is not stated here yet.
Encrypted transport, salted password hashing, server-side authorisation, and private media reachable only through signed, expiring, access-checked links.
Administrative actions are recorded in an audit trail, and moderation decisions are reviewable by a person.
Wrati is operated from India and hosted in a single region today. EU-region infrastructure and regional data residency are part of the international expansion roadmap, not present capability.
Wrati has not appointed an Article 27 representative. Whether one is required depends on whether and how Wrati offers services to people in the EU — applicability subject to legal assessment.
A portable export of your data is not yet available in-product. Requests are handled manually through the contact below while that is built.
Contractual safeguards and transfer assessments for any future EU processing have not been put in place, because that processing does not exist yet.
Access, correction, deletion, restriction, portability and objection — what Wrati can action today, and what currently requires a manual request, is listed on the Privacy Rights Centre. Deleting your account and withdrawing marketing consent both work in-product right now.
Mindware
Mindware, S4 Pankaj Plaza, Plot Number 7, Pocket 7, Sector 12, Dwarka, New Delhi 110078, India
Privacy contact: Gulshan Marwah — gm@wrati.com
A dedicated Data Protection Officer has not been appointed. Whether one is required depends on the nature and scale of processing — applicability subject to legal assessment.