Legal
Data processing agreement
This is the Article 28 GDPR processing agreement between whoever uses ALL WR for their business data (the controller) and Wealthreader, S.L. (the processor), for that data.
Two roles, not one
For the business data you upload — invoices, customer contacts, file documents, your team’s working time — you are the controller and we are the processor. We process it to provide the service, on your instructions, which are these pages plus what you configure in the product.
For the account itself — sign-up, access, the security of the service and the invoices we send you — Wealthreader, S.L. is an independent controller. That part is explained in the privacy policy.
Bank data
The connection to the institution goes through the Wealthreader widget. The data arrives with your consent and on the basis of the account-information service. We do not use it for another purpose and we do not sell it.
How it is processed
- The people who can access it are limited to those who operate or support the service.
- IBANs and bank tokens are encrypted. Transport is over TLS.
- We help with requests from data subjects that reach us and that belong to you.
- When the service ends, we delete or return the business data, except what a law requires us to keep.
- We make available the information needed to show this processing is in order, and we allow a reasonable audit, announced and during working hours.
Where, and with whom
The application is hosted in the European Union. We do not publish a subprocessor list here that would become false the day a vendor changes. The current list is requested from privacy@allwr.io and is given to someone who has an account or is evaluating a contract.
If a subprocessor handles data outside the European Economic Area, it will be with a Chapter V GDPR safeguard. The design today is to host the service in the Union.