GDPR
In effect since 27 August 2026
This describes how Wally Solutions, LLC ("Wally", "we") handles personal data under the UK GDPR and the EU General Data Protection Regulation. Read it alongside our Privacy Policy, which covers everything not specific to those regulations.
1. Who is responsible for what
Two different relationships run through this platform, and they carry different obligations.
We are a processor for the contact data our customers put into Wally. When a business uploads their customer list and sends messages to it, that business decides why and how those people are contacted. They are the controller. We act on their instructions and do not use their contacts for our own purposes, do not sell them, and do not message them except when instructed by that customer.
We are a controller for the data about the account itself: the names, email addresses and phone numbers of the people who sign in to Wally, billing records, and our logs of how the service was used. We decide what we collect there and why.
The distinction matters when someone exercises their rights. A person who received a text from one of our customers should contact that customer, and we will support that customer in responding. A person who has a Wally login should contact us directly.
2. What we hold, and why
Contact data, on behalf of our customers
Names, mobile numbers, email addresses, any tags or reference values the customer chooses to store, records of consent, records of opt-out, message content and delivery outcomes, and records of link clicks where a shortened link was used.
We process this to provide the service our customer has asked for. Our lawful basis is performance of our contract with that customer; their basis for contacting the person is theirs to establish and record, and the platform requires them to record it.
Account data, as controller
Names, email addresses, mobile numbers where two-step sign-in is enabled, hashed passwords, sign-in attempts including IP addresses, audit records of actions taken in the console, API request logs, and billing history.
Our basis is performance of our contract with the account holder, and our legitimate interest in operating the service securely and detecting misuse. Sign-in attempt logging in particular exists so that an attack on a customer's account is visible; we consider that interest to outweigh the limited privacy impact of retaining an IP address and an outcome for a short period.
3. Consent, and the record we keep of it
Every contact in Wally carries a consent record naming how that person agreed to be contacted, when, and by what route. The platform will not send a campaign to a contact without one. Where a customer imports contacts, they are required to state at the point of import how consent was obtained, and that statement is stored against every contact in the import.
We do not verify our customers' consent claims and cannot; we require them to make the claim, record it, and stand behind it.
4. Withdrawal, and why some data survives deletion
Anyone can withdraw consent at any time. On text messages, replying STOP works and takes effect immediately. On email, every marketing message carries an unsubscribe link. Neither requires contacting anybody or explaining a reason.
When somebody opts out, we keep a record of the opt-out itself, and we keep it even if the contact record is deleted. This is deliberate and we want to be plain about it, because it is an apparent conflict with the right to erasure.
The record consists of the phone number or email address, the date, and the reason. We retain it because it is the only way to guarantee the objection is honoured. If we erased it, the same person could be re-added by a later import and would begin receiving messages again, having done everything right. We rely on Article 17(3)(b) and Article 21(3): we are required to stop processing for direct marketing on objection, and the suppression record is how we comply. Retaining less would make the objection unenforceable.
Everything else about that person is deleted or anonymised on request.
5. How long we keep things
| Data | Retained for |
|---|---|
| Contact records | Until the customer deletes them or closes their account |
| Message content and delivery outcomes | Up to 12 months, then removed |
| Opt-out records | Indefinitely, for the reason given above |
| Consent records | For as long as the contact exists, plus the period during which a complaint could be raised |
| Sign-in attempts | 90 days |
| API request logs | 30 days |
| Console audit records | Approximately 13 months |
| Billing records | Seven years, to meet tax and accounting obligations |
Billing records are held in an append-only ledger that cannot be edited after the fact. This is a deliberate design choice for financial integrity, and it means a billing line naming an amount and a date cannot be removed on request. It contains no message content and no recipient identity.
6. Where data goes
Wally operates in the United States and stores data there. Our servers, our database, and every service we depend on are US based. If you are in the UK or the EEA, using Wally means your data is transferred to and processed in the United States.
We rely on the UK International Data Transfer Addendum and the EU Standard Contractual Clauses for those transfers, and we will provide them on request.
We share data with these processors, and no others:
| Who | What for | Where |
|---|---|---|
| Twilio | Delivering text and picture messages | United States |
| Amazon Web Services | Delivering email, and storing images used in messages | United States |
| Stripe | Taking payment for credit | United States |
| Cloudflare | Serving and protecting our websites | Global network |
Mobile carriers necessarily receive the message and the recipient's number in order to deliver it. They are not our processors and we cannot control what they retain.
We do not sell personal data, and we do not share it for advertising.
7. Rights, and how to use them
If your data is in Wally because a business you dealt with put it there, contact that business. They control it and can act immediately. If you do not know who that is, write to us with the number or address that received the message and we will identify the sender and pass your request to them, usually within a few working days.
If you have a Wally account, write to privacy@wallysolutions.com.
You have the right to ask for a copy of your data, to have it corrected, to have it erased, to restrict or object to processing, to receive it in a portable format, and to withdraw consent at any time. We respond within one month, and will tell you if we need longer and why.
You can complain to a supervisory authority. In the UK that is the Information Commissioner's Office; in the EEA it is the authority in the country where you live.
8. Security
Passwords are stored using PBKDF2-SHA256 with a high iteration count and a unique salt per account; we cannot read them and cannot recover them for you. Two-step sign-in is available on every account. All traffic runs over TLS. API keys are stored as hashes, so a copy of our database contains no working credentials. Access to production data is limited to people who need it, and administrative actions are recorded against the individual who took them.
Message content is not stored indefinitely and is not used to train anything.
9. Automated decision making
We do not make automated decisions producing legal or similarly significant effects about anybody. Our customers may automate when a message is sent, including through our automation and API features, but the platform enforces consent and opt-out on every send regardless of what automated the request. No automated process can override an objection.
10. Children
Wally is a business tool and is not directed at children. We do not knowingly hold data about anybody under 16. If you believe a customer has uploaded a child's details, tell us and we will act.
11. Breaches
If we suffer a breach affecting personal data, we notify affected customers without undue delay and in any event within 72 hours of becoming aware, with what we know at that point rather than waiting until we know everything. Where we act as processor, we notify the customer so they can meet their own obligation to notify a regulator.
12. Changes
We keep every previous version of this policy with the date it took effect. If you need to know what it said on a particular date, ask and we will send it to you.
Contact
Wally Solutions, LLC
privacy@wallysolutions.com