Legal

Privacy Policy

We sell privacy software. It would be difficult to explain a policy that gave us licence to do the things we tell clients not to do. This one describes what actually happens, in the order it happens.

Legal status: Uwitz Corporate is currently unincorporated. We are preparing to legally register and operate under Estonia in the foreseeable future. We operate under a Founder's Agreement from Uwitz. All Stripe transactions are processed via our Financial Representative based in Malaysia.

Effective 31 July 2026 Last updated 31 July 2026

1. Who we are

Uwitz Corporate is the data controller for everything described in this policy. Uwitz Corporate is not yet a fully incorporated entity — we are preparing to legally register and operate in Estonia in the foreseeable future.

This policy covers uwitz.co and the commercial products and services sold from it. It does not cover uwitz.org, which publishes its own policy, or any deployment of our software that you run yourself — in that case you are the controller and we are not involved.

2. What we collect

Visiting this website

Our web server writes an access log entry for each request: your IP address, the time, the path requested, the HTTP status, your browser's user-agent string, and the referring page if your browser sent one. This is ordinary server logging, not a profile — we do not tie these entries to a person and we do not build behavioural records from them.

This site sets no cookies. It runs no analytics, no tag manager, no advertising or social pixels, and no session recording. There is nothing to opt out of because there is nothing running.

Two things on this site are fetched from another company's servers, which means those companies can see your IP address and user-agent when a page loads. They are listed in section 5.

Contacting us

Our contact page uses plain mailto: addresses — there is no web form and nothing is submitted to us in the background. If you email us, we hold that message, your address, and anything you chose to put in it, for as long as we need to deal with the matter and to keep a record of the engagement.

Payments

Card payments are handled by Stripe using their hosted fields. Card numbers, expiry dates, and security codes never reach a Uwitz server — they go from your browser to Stripe directly, and we could not log them if we wanted to. What our server receives and records is the amount, payment frequency, any reference you provide, and a Stripe payment-method token. Financial transactions are processed via a Financial Representative based in Malaysia.

If you pay by bank transfer, we receive whatever your bank puts on the transfer: name, account identifiers, and the reference.

Staff and client console accounts

Accounts that sign in to internal tooling have an email address, display name, and role stored against a password hash. Successful and failed sign-in attempts are logged with the source IP address and the email attempted — this is a security control, and it is deliberate. Your browser stores a session record in localStorage under irys_admin_session; it is cleared when you sign out.

3. What we do not do

Stated plainly, so it can be held against us:

4. Why we may lawfully hold it

Under the UK GDPR and EU GDPR we rely on the following bases:

Where we rely on legitimate interests, we have considered whether our interest is overridden by your rights, and we have kept the data minimal so that it is not. You can object at any time — see section 8.

5. Who else sees it

We use a small number of processors. Each one is listed here because we think an unenumerated "trusted partners" clause is worthless to you.

We will also disclose data where we are legally compelled to. If we receive a valid order, we will tell you unless we are prohibited from doing so, and we will challenge requests we consider overbroad.

6. How long we keep it

7. International transfers

Our engineering is distributed across the EU and the US, and some of the processors above are US-based. Where personal data leaves the UK or EEA, it is transferred under Standard Contractual Clauses or an equivalent approved mechanism, together with technical measures — encryption in transit and at rest — intended to make the data useless to anyone intercepting it.

8. Your rights

If you are in the UK or EEA you have the right to access a copy of your data, correct it, have it erased, restrict or object to how we use it, receive it in a portable format, and withdraw consent where consent was the basis. If you are in California you have equivalent rights of access, deletion, correction, and portability, and a right not to be discriminated against for exercising them — noting that we do not sell or share personal information as those terms are defined under the CCPA.

Write to hello@uwitz.co. We will respond within one month. We do not require you to create an account or prove identity beyond what is necessary to be confident we are not disclosing your data to someone else.

If you are unhappy with our response you can complain to your supervisory authority. In the UK that is the Information Commissioner's Office at ico.org.uk. We would rather you came to us first, but that is your choice, not a precondition.

9. How it is protected

If we suffer a breach affecting your personal data, we will notify the relevant supervisory authority within 72 hours where required, and we will tell you directly where there is a meaningful risk to you. We will describe what happened rather than what is convenient.

10. Client data in our products

When you use Irys SSO, the personal data of your users is yours, not ours. You are the controller; we are a processor acting on your written instructions under the data processing agreement attached to your contract.

For zero-knowledge features specifically, the point of the architecture is that we hold ciphertext and access policy and nothing else. Keys are derived and unwrapped on your side. We cannot read your secrets, we cannot recover them for you, and we cannot produce them in response to a legal order — not as a matter of policy, but as a matter of what exists on the disk.

11. Changes

If we change this policy materially, we will update the version and effective date above and notify contract holders directly. We will not make a substantive change quietly and rely on you re-reading the page.

12. Contact

Privacy questions and rights requests: hello@uwitz.co
Security reports: security@uwitz.co
Everything else: our contact page

As Uwitz Corporate is not yet a registered entity, we do not currently have a formal Data Protection Officer or representative under Art. 27 GDPR. Privacy requests will be handled by our team directly. Once incorporated, we will appoint the appropriate representative and update this notice.


See also our Terms of Service.