1. Who we are
Uwitz Corporate is the data controller for everything described in this policy. Uwitz Corporate is not yet a fully incorporated entity — we are preparing to legally register and operate in Estonia in the foreseeable future.
This policy covers uwitz.co and the commercial products and services sold from it. It does not cover uwitz.org, which publishes its own policy, or any deployment of our software that you run yourself — in that case you are the controller and we are not involved.
2. What we collect
Visiting this website
Our web server writes an access log entry for each request: your IP address, the time, the path requested, the HTTP status, your browser's user-agent string, and the referring page if your browser sent one. This is ordinary server logging, not a profile — we do not tie these entries to a person and we do not build behavioural records from them.
This site sets no cookies. It runs no analytics, no tag manager, no advertising or social pixels, and no session recording. There is nothing to opt out of because there is nothing running.
Two things on this site are fetched from another company's servers, which means those companies can see your IP address and user-agent when a page loads. They are listed in section 5.
Contacting us
Our contact page uses plain mailto: addresses — there is no web form and nothing is submitted to us in the background. If you email us, we hold that message, your address, and anything you chose to put in it, for as long as we need to deal with the matter and to keep a record of the engagement.
Payments
Card payments are handled by Stripe using their hosted fields. Card numbers, expiry dates, and security codes never reach a Uwitz server — they go from your browser to Stripe directly, and we could not log them if we wanted to. What our server receives and records is the amount, payment frequency, any reference you provide, and a Stripe payment-method token. Financial transactions are processed via a Financial Representative based in Malaysia.
If you pay by bank transfer, we receive whatever your bank puts on the transfer: name, account identifiers, and the reference.
Staff and client console accounts
Accounts that sign in to internal tooling have an email address, display name, and role stored against a password hash. Successful and failed sign-in attempts are logged with the source IP address and the email attempted — this is a security control, and it is deliberate. Your browser stores a session record in localStorage under irys_admin_session; it is cleared when you sign out.
3. What we do not do
Stated plainly, so it can be held against us:
- We do not sell, rent, or trade personal data. There is no circumstance in which this changes without your explicit consent.
- We do not use your data to train machine-learning models, ours or anyone else's.
- We do not run advertising, and we do not share data with advertising or data-broker networks.
- We do not track you across other websites, and we honour
Do Not Trackand Global Privacy Control by having nothing to disable. - We do not read the contents of what you store in our zero-knowledge products. Section 10 explains why we architecturally cannot.
4. Why we may lawfully hold it
Under the UK GDPR and EU GDPR we rely on the following bases:
| Data | Basis | Reasoning |
|---|---|---|
| Server access logs | Legitimate interests | Operating the site securely, diagnosing faults, and investigating abuse. |
| Sign-in and auth-failure logs | Legitimate interests | Detecting credential attacks against our systems. |
| Correspondence | Legitimate interests / contract | Answering you, and performing an agreement where one exists. |
| Billing and payment records | Contract and legal obligation | Taking payment, and meeting tax and accounting retention rules. |
| Account credentials | Contract | Providing the service you or your employer contracted for. |
Where we rely on legitimate interests, we have considered whether our interest is overridden by your rights, and we have kept the data minimal so that it is not. You can object at any time — see section 8.
5. Who else sees it
We use a small number of processors. Each one is listed here because we think an unenumerated "trusted partners" clause is worthless to you.
| Recipient | What they receive | Why |
|---|---|---|
| Stripe | Card details entered on our billing page, payment amounts, any reference you provide, IP address | Card processing. Stripe is a controller in its own right for fraud prevention. Financial transactions are processed via a Financial Representative based in Malaysia. |
| Wise and our banking providers | Transfer details for payments you send us | Receiving bank payments. |
| Our hosting provider | Everything transiting the server, as infrastructure operator | Running the site. Contabo GmbH, Germany. |
We will also disclose data where we are legally compelled to. If we receive a valid order, we will tell you unless we are prohibited from doing so, and we will challenge requests we consider overbroad.
6. How long we keep it
- Server access logs — 90 days, then deleted.
- Authentication logs — 12 months, as a security record.
- Correspondence — for the life of the relationship plus 12 months.
- Billing records — seven years, or whatever the applicable tax law requires, whichever is longer. We cannot delete these on request.
- Account records — until the account is closed, then deleted within 30 days.
7. International transfers
Our engineering is distributed across the EU and the US, and some of the processors above are US-based. Where personal data leaves the UK or EEA, it is transferred under Standard Contractual Clauses or an equivalent approved mechanism, together with technical measures — encryption in transit and at rest — intended to make the data useless to anyone intercepting it.
8. Your rights
If you are in the UK or EEA you have the right to access a copy of your data, correct it, have it erased, restrict or object to how we use it, receive it in a portable format, and withdraw consent where consent was the basis. If you are in California you have equivalent rights of access, deletion, correction, and portability, and a right not to be discriminated against for exercising them — noting that we do not sell or share personal information as those terms are defined under the CCPA.
Write to hello@uwitz.co. We will respond within one month. We do not require you to create an account or prove identity beyond what is necessary to be confident we are not disclosing your data to someone else.
If you are unhappy with our response you can complain to your supervisory authority. In the UK that is the Information Commissioner's Office at ico.org.uk. We would rather you came to us first, but that is your choice, not a precondition.
9. How it is protected
- All traffic is served over TLS 1.3. Our edge uses post-quantum signatures (ML-DSA-87).
- Credentials are stored as salted PBKDF2 hashes, never in recoverable form.
- Authentication endpoints are rate-limited, and failures are logged and reviewed.
- Access to production systems is scoped, time-bound, and logged.
- We publish our own security research and accept reports about ourselves — see our safe-harbour commitment.
If we suffer a breach affecting your personal data, we will notify the relevant supervisory authority within 72 hours where required, and we will tell you directly where there is a meaningful risk to you. We will describe what happened rather than what is convenient.
10. Client data in our products
When you use Irys SSO, the personal data of your users is yours, not ours. You are the controller; we are a processor acting on your written instructions under the data processing agreement attached to your contract.
For zero-knowledge features specifically, the point of the architecture is that we hold ciphertext and access policy and nothing else. Keys are derived and unwrapped on your side. We cannot read your secrets, we cannot recover them for you, and we cannot produce them in response to a legal order — not as a matter of policy, but as a matter of what exists on the disk.
11. Changes
If we change this policy materially, we will update the version and effective date above and notify contract holders directly. We will not make a substantive change quietly and rely on you re-reading the page.
12. Contact
Privacy questions and rights requests: hello@uwitz.co
Security reports: security@uwitz.co
Everything else: our contact page
As Uwitz Corporate is not yet a registered entity, we do not currently have a formal Data Protection Officer or representative under Art. 27 GDPR. Privacy requests will be handled by our team directly. Once incorporated, we will appoint the appropriate representative and update this notice.
See also our Terms of Service.