Privacy Policy
Last updated: 18 June 2026
This policy explains how Malaiya Trading B.V. (“we”), operating Waveonic (waveonic.com), handles personal data. We are based in the Netherlands and follow the EU General Data Protection Regulation (GDPR).
1. What we collect
- Email address — if you join our mailing list or create an account.
- Account and session data — if you create an account: your intentions, session history, preferences, and settings, used to personalise sessions (including the auto-deepening that adapts to how you sit).
- Payment data — if you purchase a paid plan, handled by our payment provider; we do not store full card details.
- Technical data — server logs (IP address, browser type, request path) retained briefly by our hosting provider (Vercel) for security and operational purposes. We do not run analytics or use tracking tools of any kind.
2. Why we use it (lawful bases)
- To provide and personalise the service (performance of a contract / legitimate interest).
- To send you emails you asked for (consent).
- To process payments (performance of a contract).
- To maintain security and improve the product (legitimate interest).
3. Mailing list
If you join our mailing list, we use your email to send occasional updates about Waveonic. You can unsubscribe at any time via the link in any email. Email is handled through our email provider (Resend) and stored in our database (Supabase).
4. Sharing
We do not sell your personal data. We share data only with service providers who help us run Waveonic (hosting, database, email, payments), under agreements that require them to protect it. Some providers may process data outside the EU under appropriate safeguards.
5. Retention
We keep personal data only as long as needed for the purposes above, or as required by law. You can ask us to delete your account and associated data.
6. Your rights
Under the GDPR you have the right to access, correct, delete, restrict, or port your data, and to object to certain processing or withdraw consent. To exercise these rights, contact us at hello@waveonic.com. You may also complain to the Dutch Data Protection Authority (Autoriteit Persoonsgegevens).
7. Security
We take reasonable technical and organisational measures to protect your data. No system is perfectly secure; we cannot guarantee absolute security.
8. Changes
We may update this policy. Material changes are reflected by the “Last updated” date.
9. Cookies and browser storage
Waveonic does not use advertising cookies, analytics cookies, or any third-party tracking. We use only strictly necessary and functional storage:
- Authentication cookies — set by our authentication provider (Supabase) when you sign in. These are essential to keep you logged in and cannot be declined without breaking the service.
- Functional localStorage — we store your preferences and session state locally in your browser: theme (light/dark), sound preference, voice-intro preference, visual-mode preference, session history (used as a local fallback and for personalisation), per-intent settings and session counts (used for adaptive depth), recently played audio (to avoid repeats), and one-time safety acknowledgements (photosensitivity caution, taster health notice). All keys are prefixed waveonic- or waveonic_ and contain no personal data beyond your own settings.
- sessionStorage — temporary tab-scoped flags used to pass state between screens during a session (e.g. whether the current session is a taster, or an AI-composed plan). These are cleared automatically when the browser tab is closed.
Because we use no analytics or advertising cookies, no cookie-consent banner is required under the ePrivacy Directive for our current storage use.
10. Contact
Privacy questions or requests: hello@waveonic.com.
Malaiya Trading B.V., Woldberglaan 7, 5628 DL Eindhoven, the Netherlands.