Summary: Wenect is a Living Professional Identity Platform operated by Wenect in Austria. We collect only what we need to provide the service. We never sell your personal data. You have full rights over your data under GDPR.
1. Data Controller
The data controller responsible for your personal data is:
Wenect
Austria
Email: support@wenect.app
Legal: support@wenect.app
If you have any questions about how your personal data is handled, please contact us at support@wenect.app.
2. Data We Collect
2.1 Account & Identity Data
- Full name, display name
- Email address
- Password (stored as a hashed, salted value — never in plain text)
- Profile photo and portfolio images
- Job title, company name, professional biography
- Phone number, website URL, social media handles
2.2 Business Card & Networking Data
- Digital business card content you create (templates, colours, layout choices)
- QR code identifiers linked to your cards
- Connections and saved contacts
- Notes and reminders you attach to contacts
- Event context data (event name, date, location) associated with networking interactions
- Lead capture data submitted by visitors to your public card page
2.3 Media & Uploads
- Profile photos, portfolio images, and cover images uploaded by you
- Video introductions (if provided)
- Voice pronunciation clips (if provided)
- Business card images submitted for OCR scanning
2.4 Usage & Analytics Data
- Card view counts and scan counts
- QR code scan events (including approximate location if permitted)
- Feature usage patterns within the app
- Session duration and screen interaction data
2.5 Device & Technical Data
- Device type, operating system, and version
- App version
- IP address (used for security and fraud prevention)
- Push notification tokens (if notifications are enabled)
- Language and locale settings
2.6 Communications
- Emails we send you (transactional and service notifications)
- Feedback or support messages you send to us
3. Camera, QR & Scanner Features
Wenect includes features that access your device camera. We access your camera only when you actively use the following features:
- QR Code Scanner: Reads QR codes to import contacts or scan Wenect business cards. QR images are processed locally on your device and not stored.
- Badge & Business Card OCR Scanner: Allows you to photograph a physical business card or event badge. The image is sent to our servers for text extraction (OCR) using Tesseract OCR. The image is processed to extract name, title, company, email, phone and website fields, then discarded. We do not retain the raw image beyond processing.
- Profile Photo: You may use your camera to take a profile photo. This photo is uploaded to our secure cloud storage and associated with your account.
- Portfolio Images: You may photograph portfolio items. These are stored in your account.
Camera permission is requested only when you attempt to use one of the above features. You may deny camera access and use manual text entry alternatives instead.
4. AI Features
Wenect uses artificial intelligence to enhance certain features of the platform, including:
- AI-assisted card content suggestions (bio, tagline, professional summary)
- Smart contact insights and networking recommendations
- Automated text extraction from scanned business cards
These features are powered by OpenAI (OpenAI, L.L.C., USA). When you use an AI feature, relevant data (such as your professional profile information or scanned text) is transmitted to OpenAI's API for processing. OpenAI processes this data under a data processing agreement with Wenect and does not use API inputs to train its models.
You can choose not to use AI-powered features. AI assistance is always opt-in and clearly labelled within the app.
5. Payments & Subscriptions
Wenect offers paid subscription plans (Wenect Pro and Wenect Business). All payment processing is handled by Stripe, Inc. (USA), a PCI-DSS Level 1 certified payment processor.
Wenect does not store your full payment card number, CVV, or sensitive payment data. Stripe handles all card data directly and returns a secure token to us.
We store:
- Your Stripe Customer ID
- Your subscription plan and status
- Billing period and renewal dates
- Invoice records (required for tax and legal compliance)
For Stripe's own privacy practices, see stripe.com/privacy.
6. How We Use Your Data
We use your personal data to:
- Create and manage your Wenect account
- Provide the digital business card creation, sharing, and management platform
- Enable QR code generation, scanning, and sharing features
- Process OCR scanning of physical business cards and event badges
- Deliver push notifications (with your consent)
- Generate analytics about your card engagement
- Process subscription payments and manage billing
- Enable Apple Wallet and Google Wallet integrations
- Provide AI-powered content suggestions (with your active use)
- Respond to your support requests and feedback
- Send transactional emails (account confirmation, password reset, billing receipts)
- Maintain platform security and prevent fraud
- Comply with legal obligations
- Improve and develop the platform based on aggregated usage patterns
We do not sell your personal data to third parties. We do not use your data for behavioural advertising.
7. Legal Bases for Processing (GDPR Article 6)
Under the GDPR, we rely on the following legal bases:
| Processing Activity | Legal Basis |
|---|---|
| Account creation and management | Contract performance (Art. 6(1)(b)) |
| Providing the platform and its features | Contract performance (Art. 6(1)(b)) |
| Payment processing and billing | Contract performance (Art. 6(1)(b)) |
| Invoice retention for tax purposes | Legal obligation (Art. 6(1)(c)) |
| Push notifications | Consent (Art. 6(1)(a)) |
| AI-powered suggestions | Legitimate interests / Consent (Art. 6(1)(a)(f)) |
| Security monitoring and fraud prevention | Legitimate interests (Art. 6(1)(f)) |
| Platform improvement via analytics | Legitimate interests (Art. 6(1)(f)) |
| Marketing emails (if any) | Consent (Art. 6(1)(a)) |
8. Data Sharing & Third-Party Providers
We share personal data only with trusted service providers who process it on our behalf, under data processing agreements:
| Provider | Purpose | Location |
|---|---|---|
| Stripe, Inc. | Payment processing and subscription management | USA (SCCs) |
| OpenAI, L.L.C. | AI-powered content suggestions and text analysis | USA (SCCs) |
| Google LLC | Cloud storage (media files), Google Wallet, Google Sign-In | USA/EEA (SCCs) |
| Apple Inc. | Apple Wallet passes, Apple Sign-In, iOS push notifications | USA (SCCs) |
| Resend | Transactional email delivery | USA (SCCs) |
| Replit, Inc. | Cloud hosting and infrastructure | USA (SCCs) |
| LinkedIn (Microsoft) | LinkedIn OAuth sign-in | USA/EEA (SCCs) |
| GitHub (Microsoft) | GitHub OAuth sign-in | USA (SCCs) |
We do not share personal data with advertisers, data brokers, or any third party for their own marketing purposes.
We may disclose data to legal authorities if required by law, court order, or to protect the rights and safety of Wenect and its users.
9. International Data Transfers
Wenect is based in Austria (EEA). Some of our service providers process data outside the EEA, including in the United States.
Where we transfer personal data outside the EEA, we ensure appropriate safeguards are in place, including:
- Standard Contractual Clauses (SCCs) approved by the European Commission
- Adequacy decisions where applicable
- Binding Corporate Rules where applicable
You may request information about the specific safeguards in place for any international transfer by contacting support@wenect.app.
10. Data Retention
| Data Category | Retention Period |
|---|---|
| Account data (active accounts) | For the duration of the account |
| Account data (after deletion request) | Deleted within 30 days of request |
| Usage analytics (aggregated) | Up to 2 years |
| Card engagement analytics | Up to 2 years |
| Lead capture data | Until deleted by the card owner or account closure |
| Invoices and billing records | 7 years (Austrian tax law requirement) |
| Security/fraud logs | Up to 1 year |
| OCR scan images | Not retained — deleted after processing |
| Push notification tokens | Until permission is revoked or account deleted |
| Support communications | Up to 3 years |
11. Your Rights Under GDPR
As a data subject in the EEA, you have the following rights:
- Right of Access (Art. 15): Request a copy of all personal data we hold about you.
- Right to Rectification (Art. 16): Request correction of inaccurate or incomplete data.
- Right to Erasure (Art. 17): Request deletion of your personal data ("right to be forgotten"). See our Data Deletion page for how to exercise this right.
- Right to Restriction of Processing (Art. 18): Request that we limit how we use your data in certain circumstances.
- Right to Data Portability (Art. 20): Receive your personal data in a structured, machine-readable format.
- Right to Object (Art. 21): Object to processing based on legitimate interests, including profiling.
- Right to Withdraw Consent (Art. 7(3)): Where processing is based on consent, withdraw it at any time. Withdrawal does not affect the lawfulness of prior processing.
- Right to Lodge a Complaint (Art. 77): You may lodge a complaint with the Austrian Data Protection Authority (Datenschutzbehörde):
Barichgasse 40–42, 1030 Vienna, Austria | dsb.gv.at
To exercise any of the above rights, contact us at support@wenect.app. We will respond within 30 days.
12. Children's Privacy
Wenect is not directed at children under the age of 16. We do not knowingly collect personal data from anyone under 16. If you believe a child under 16 has provided us with personal data, please contact us immediately at support@wenect.app and we will delete such data promptly.
13. Security
We implement appropriate technical and organisational measures to protect your personal data against accidental loss, unauthorised access, disclosure, alteration, or destruction. These measures include:
- Encryption of data in transit (TLS) and at rest
- Password hashing using bcrypt with salting
- Access controls limiting staff access to personal data on a need-to-know basis
- Regular security reviews
- Secure cloud storage infrastructure
No system can be guaranteed 100% secure. If you become aware of a security issue, please contact us immediately at support@wenect.app.
14. Changes to This Policy
We may update this Privacy Policy from time to time. When we make material changes, we will notify you by:
- Updating the "Last Updated" date at the top of this page
- Displaying an in-app notification on your next login
- Sending an email notification for significant changes
Your continued use of Wenect after changes are posted constitutes acceptance of the updated policy. If you disagree with the changes, you may delete your account.
15. Contact Us
For any questions, concerns, or requests relating to this Privacy Policy or your personal data:
Privacy Team — Wenect
Email: support@wenect.app
Legal: support@wenect.app
Data Deletion: wenect.app/data-deletion
We aim to respond to all enquiries within 30 days. For urgent matters related to data breaches or safety, please mark your email as URGENT.