[ LEGAL_DOCUMENT ]

    Privacy Policy

    Last updated: 29 April 2026

    1. Who we are

    This site (wiregate.io) is operated by Wiregate DOO ("Wiregate", "we", "us"), a limited liability company registered in Montenegro. Wiregate DOO is the data controller for personal data processed through this website.

    For privacy-related questions, including data subject access requests under GDPR or CCPA, contact privacy@wiregate.io. For all other inquiries, use info@wiregate.io.

    2. What data we collect and why

    We process the following categories of personal data, with the purpose and legal basis listed for each:

    CategoryPurposeLegal basis (GDPR art. 6)Retention
    Contact form data: name, email, project descriptionReply to your inquiry, scope a potential engagement(b) pre-contractual measures at your request24 months from last contact
    Email correspondence contentContinue the conversation, deliver services if engaged(b) contract / (f) legitimate interest in record-keeping24 months from last contact, or duration of contract + 7 years for tax/legal records
    Technical data: IP address, browser/device info, referrer, pages viewedSite security, anti-abuse (Cloudflare Turnstile), aggregated analytics with consent(f) legitimate interest in security; (a) consent for analyticsSecurity logs: 90 days. Analytics: see Cookie Policy.
    Behavioral data via Hotjar (session replays, heatmaps)Improve UX based on aggregated user behavior. PII fields are masked.(a) consentPer Hotjar defaults, max 365 days
    Consent state (cookie/tracking choices)Honor your privacy choices across visits(c) legal obligation; necessary to demonstrate consent12 months from last update

    We do not knowingly collect special categories of personal data (health, biometric, political, etc.) and we do not collect data from individuals under the age of 16.

    3. Who receives your data

    We use a small set of processors to operate the site and respond to inquiries. Each is bound by a Data Processing Agreement and, where data leaves the EEA, by Standard Contractual Clauses or an adequate transfer mechanism:

    • Email delivery provider (Resend) — delivers your inquiry to our inbox.
    • Backend infrastructure (Supabase) — forwards form submissions to the email provider. No form data is stored.
    • Security and CDN (Cloudflare) — protects the site from abuse and serves content.
    • Analytics (Hotjar) — loaded only after you consent.

    We do not sell personal data and we do not share it with third parties for their own marketing purposes. We do not run advertising trackers on this site.

    4. International data transfers

    Wiregate is established in Montenegro, which is not currently covered by an EU adequacy decision. When personal data of EEA or UK residents is transferred to us or to processors outside the EEA, we rely on:

    • Standard Contractual Clauses (Commission Decision 2021/914) with each processor where applicable;
    • EU-US Data Privacy Framework certification for US processors that participate (verifiable at dataprivacyframework.gov);
    • Supplementary measures including encryption in transit (TLS 1.2+), encryption at rest, access controls, and minimization.

    You can request a copy of the transfer safeguards in place by emailing privacy@wiregate.io.

    5. Your rights (GDPR / UK GDPR)

    If you are in the EEA, the UK, or Switzerland, you have the following rights regarding your personal data:

    • Right of access — request a copy of the data we hold about you (art. 15).
    • Right to rectification — correct inaccurate or incomplete data (art. 16).
    • Right to erasure — request deletion when one of the conditions in art. 17 applies.
    • Right to restriction — limit processing while a dispute is resolved (art. 18).
    • Right to data portability — receive your data in a structured, machine-readable format (art. 20).
    • Right to object — object to processing based on our legitimate interests, including direct marketing (art. 21).
    • Right to withdraw consent — at any time, without affecting prior lawful processing (art. 7(3)).
    • Right to lodge a complaint — with your local supervisory authority. UK residents may contact the Information Commissioner's Office (ICO).

    To exercise any of these rights, email privacy@wiregate.io. We will respond within 30 days. We may ask for proof of identity to prevent unauthorized requests.

    6. Your rights (California / CCPA & CPRA)

    If you are a California resident, you have the following rights under the California Consumer Privacy Act, as amended by the California Privacy Rights Act:

    • Right to know what categories of personal information we collect, the sources, the business purposes, and the third parties with whom it is shared.
    • Right to delete personal information we hold, subject to legal exceptions.
    • Right to correct inaccurate personal information.
    • Right to opt out of the "sale" or "sharing" of personal information for cross-context behavioral advertising. We do not sell personal information for money, but use of analytics tools may constitute "sharing" under the CPRA's broad definition. You can opt out via the cookie banner or by sending a Global Privacy Control signal — both are honored automatically.
    • Right to limit use of sensitive personal information — we do not collect sensitive PI as defined by the CPRA.
    • Right to non-discrimination — we will not charge different prices or provide a different level of service because you exercised these rights.

    To exercise these rights, email privacy@wiregate.io with the subject line "California Privacy Request". You may also designate an authorized agent.

    7. Cookies and similar technologies

    We use a small number of cookies and tracking scripts. Strictly necessary cookies (e.g. anti-abuse) are set without consent; analytics cookies require your opt-in (or, in California, are disabled if you opt out via banner or GPC). We do not run advertising or remarketing trackers. For the full list, see the Cookie Policy.

    8. Security

    We protect personal data with TLS 1.2+ in transit, encryption at rest at all storage providers, principle-of-least-privilege access controls, and Cloudflare Turnstile anti-bot protection on lead forms. No method of transmission or storage is 100% secure; we keep our practices under regular review.

    9. Children

    Our services are not directed to individuals under 16. We do not knowingly collect personal data from minors. If you believe a minor has submitted personal data, contact privacy@wiregate.io and we will delete it.

    10. Changes to this policy

    We update this policy when our practices change. The "Last updated" date at the top reflects the most recent revision. Material changes will be announced via the cookie banner or a site-wide notice; minor edits (typo fixes, link updates) will not.

    11. Contact

    Privacy inquiries: privacy@wiregate.io
    General contact: info@wiregate.io