Openwake privacy policy (draft — counsel to finalise)
Who we are. Openwake operates a public registry of what software vendors do with customer data, extracted from those vendors' own public documents, and offers change alerts, counterparty checks and reports to organisations.
What we collect about you (customers)
- Organisation name, a contact email for alerts, and API keys (stored hashed).
- Your watchlist: the vendors you ask us to watch. This reveals part of your software stack; it is stored per organisation and never published.
- Alert channels you configure (email addresses, Slack webhook URLs). These are encrypted at rest and used only to deliver your alerts.
- Counterparty checks: the counterparty name, the data classes you declared (e.g. "PII", "credentials"), the decision we returned and when. We never accept, log or store the data itself — the API has no field for it.
What we collect about vendors. Public legal documents (privacy policies, DPAs, subprocessor lists, terms) fetched from public URLs, respecting robots.txt. We store text excerpts and hashes for change detection; we do not republish full documents. Vendors may claim their profile and request corrections (see the corrections policy).
The browser badge. The extension sends the registrable domain of the tab you are on (for example notion.so, never the page, never its content) to the API to look up the vendor behind it, and nothing else. No account or key is needed. Lookups are not tied to a person: the API keeps the ordinary request log for its rate limit and nothing more. The seven-day tally shown in the popup is stored in the browser's local extension storage and is never transmitted.
What we do not collect. No tracking pixels or third-party analytics on the registry. No payload data from checks. No customer documents in v1.
Retention. Registry snapshots and the ledger are kept indefinitely because the record's value is its history. Customer watchlists and checks are kept while your account is active and deleted 30 days after closure on request.
Our own subprocessors. Hosting provider; managed Postgres provider; transactional email provider (for alerts); Slack (only where you configure a webhook). A dated list is published at /legal/subprocessors and changes are announced 30 days in advance — the standard we hold vendors to.
Your rights. Access, correction, deletion and portability of your organisation's data on request to privacy@openwake.ai. EU/UK residents may complain to their supervisory authority.
Security. Every record is appended to a signed, hash-chained ledger; secrets are sealed at rest; see docs/security.md.
Contact. privacy@openwake.ai