Privacy Policy | GDPR by Construction
What Dweve B.V. collects, under which Article 6 basis, for how long, where it lives, and how you exercise your data-subject rights. A controller notice.
Autoriteit Persoonsgegevens. Web: autoriteitpersoonsgegevens.nl. Privacy line: +31 88 1805 250 (Mon to Thu, 10:00 to 12:00). General: +31 70 888 8500 (weekdays, 09:00 to 13:00). Postal: Postbus 93374, 2509 AJ Den Haag.
Contact us first at privacy@dweve.com. Dweve will acknowledge within 48 hours. Investigation completed within 30 days. Written response with resolution. Appeal process is available if you are unsatisfied.
Privacy rights: privacy@dweve.com. Data breaches: security@dweve.com (24/7). GDPR compliance: compliance@dweve.com. Legal matters: legal@dweve.com. General support: support@dweve.com.
Dweve B.V., DPO. Email: dpo@dweve.com. Phone: +31 (0)85 0041 022. Postal: Dweve B.V., Meander 251, 6825 MC Arnhem, Netherlands. KVK: 98215043.
Write to the Dweve Data Protection Officer. You also have the unconditional right to lodge a complaint with the Dutch supervisory authority, without contacting us first.
Questions, rights requests, and complaints.
Review changes before the effective date. Object to specific changes by contacting privacy@dweve.com. Export your data. Close your account without penalty before the change takes effect. Existing agreements may be grandfathered for their current term.
Minor changes: dashboard notification. Material changes: email 30 days before the effective date. Critical changes (those that materially reduce your rights or protections): explicit re-consent required before the change takes effect.
This policy is updated when legal or regulatory requirements change, when new features or services are added, when security enhancements require revised disclosures, and on an annual review at minimum. Version history is always available online.
Dweve does not knowingly collect data from, or direct marketing to, anyone under 18.
Where an approved educational institution manages student accounts: the institution carries GDPR controller responsibilities for student data, data collection is limited to what the institution authorises, no behavioural profiling applies, and enhanced privacy controls are active.
The account will be suspended immediately. A parent or guardian will be notified. Data will be deleted within 48 hours. No data will be retained or used for any processing purpose.
If Dweve discovers a minor’s data.
Dweve services are designed for professional use by adults. The minimum age is 18 years. Business accounts require legal capacity to contract. Educational-institution accounts are managed by the institution under a separate addendum, with parental consent handled at institution level.
Dedicated support during the period following notification. Regular updates on the investigation and remediation. Transparent reporting on improvements made. Compensation per applicable law.
The nature of the breach and the categories of data affected. The likely consequences and risks to your rights. The measures taken or proposed to address the breach. Recommendations for protective actions you can take. Contact information for questions.
Supervisory authority (AP): within 72 hours of detection where risk threshold is met (GDPR Art. 33). Affected data subjects: without undue delay where high risk to rights and freedoms is established (GDPR Art. 34). Partners: per contractual obligations.
24/7 automated security monitoring. Immediate incident response team activation on detection. Containment targeted within 4 hours. Forensic analysis and scope determination. Law enforcement cooperation where required.
In the event of a personal data breach, Dweve follows documented procedures to contain the incident, notify the relevant authority, and, where required, inform affected data subjects. GDPR Article 33 requires notification to the Autoriteit Persoonsgegevens within 72 hours of becoming aware of a breach likely to result in a risk to the rights and freedoms of individuals.
Transparency in AI decision-making processes. Human oversight requirements for high-risk AI applications are documented and passed to deploying customers. Bias monitoring, fairness assessments, and regular AI impact assessments are part of the release process. Documentation of AI system capabilities and limitations is published with each Loom release.
Dweve designs public website and form/control-plane processing around European-first deployment. Cloudflare is a disclosed network and infrastructure dependency; its service path may involve provider-specific processing outside the EU/EEA. Contracted customer data-plane boundaries are agreed separately in the applicable order and data-processing terms.
Customer data is processed only for the contracted service and the instructions you provide. Retention and deletion depend on the service path, stated purpose, user actions and legal obligations; this notice does not promise automatic deletion.
The platform learns mathematical patterns (binary constraints), not personal information. These constraints contain zero personal data; they are pure mathematical discoveries that improve AI efficiency.
Dweve never uses your data to train its AI models. Your data is processed only when you explicitly instruct the system.
Dweve’s AI architecture is designed so that privacy is structural, not procedural. The platform learns from mathematical constraints discovered during processing, not from your personal data.
24/7 security monitoring and incident response. Regular penetration testing and vulnerability assessments. Employee security training. EU compliance frameworks (GDPR, NIS2, DORA, CRA). Secure development lifecycle.
Access controls and reviews, multi-factor authentication, constraint separation, and an operational process for data-subject requests. This notice does not promise automated deletion.
Post-quantum cryptographic algorithms for future-proof security. TLS 1.3 with quantum-resistant ciphers for data in transit. Hardware security modules (HSM) with PQC support. All stored data uses post-quantum cryptographic protection.
Encryption in transit with TLS 1.3 and forward secrecy. Encryption at rest with AES-256 and post-quantum-ready key hierarchies. Role-based access control, least-privilege service accounts, hardware-backed secret storage, and continuous audit logging. Quarterly penetration testing, continuous dependency scanning, and automated vulnerability management. For the full controls matrix, SSDLC, incident-response posture, and vulnerability-disclosure policy, see the dedicated security page.
Manage preferences in Account Settings. Browser controls are always respected. Detailed cookie list available on request.
Persona, language, and view-mode selection so the site does not re-ask on every visit. Cleared when you sign out or reset preferences.
Matomo website measurement runs by default without measurement cookies and uses privacy-preserving, aggregate measurement of Dweve pages. It records page views and interactions for aggregate reporting and is not used for advertising or cross-site profiling. Analytics consent may enable first-party measurement cookies for more accurate repeat-visit and session measurement; if consent is withdrawn, measurement returns to cookieless mode. Cloudflare may still provide aggregate traffic and security statistics through its edge service.
Cookieless Matomo measurement, optional first-party cookies, and aggregate site statistics.
Session authentication, CSRF tokens, load balancing, language and accessibility preferences. Not subject to consent under ePrivacy Art. 5(3).
Dweve uses only the storage needed to keep sessions secure and remember choices made on the site. Matomo measures Dweve pages without measurement cookies by default; Analytics consent may enable first-party measurement cookies for more accurate repeat-visit and session measurement. No third-party advertising trackers, cross-site fingerprinting, Google Analytics, Plausible, social-media pixels or supercookies are used.
Necessary storage plus optional categories.
Email: privacy@dweve.com. Response SLA: 30 days, extendable by 60 if complex. Identity verification: proportionate, minimum data. Cost: free for reasonable requests. Withdraw consent: Account → Privacy → Consent. Appeal: AP (Autoriteit Persoonsgegevens).
Object to processing based on legitimate interest. Unconditional opt-out from direct marketing, honoured on first request.
Export of your personal data in a structured, commonly used, machine-readable format. Direct controller-to-controller transfer where technically feasible.
Where you contest accuracy, processing is restricted pending verification, without terminating account access.
“Right to be forgotten.” Dweve assesses erasure requests against the purpose for which data was collected and any legal obligations. Some records may need to remain for a statutory or legal period; this notice does not promise cryptographic deletion or a fixed backup window.
Correction of inaccurate data and completion of incomplete data. In most cases, self-service through the account dashboard.
A copy of the personal data Dweve holds about you, plus the purposes, categories, recipients, retention, and the source where it was not collected from you.