Wayah Summit
Privacy Policy
How Wayah Technologies LLC handles information from website visitors, Summit users and invitees, and support and business contacts.
1. Information we collect and use
We collect account and organization information, user and administrator contact details, support communications, Customer Data, billing and transaction records after billing launches, and technical records needed to operate and secure Summit. Technical records may include IP address, browser and device details, sign-in and security events, request and error logs, timestamps, cookie or local-storage identifiers used for essential functions, and service activity. We receive information from users and customers, their authorized administrators, service providers, and automatically from use of Summit.
We use information to authenticate users, manage access and workflows, provide support, secure and troubleshoot the service, investigate incidents, maintain audit records, communicate service information, process future billing and taxes, comply with law, enforce agreements, and improve reliability. We limit collection and use to what is reasonably necessary for these purposes and do not sell personal information or use it for targeted advertising.
2. Customer business information
Customers own their recipes, versions, plants, machines, parameters, change requests, documents, production records, and other operational information. For personal information contained in Customer Data, the Customer generally determines the purposes and means of processing and Wayah acts as its processor or service provider, processing that information only on documented instructions and as needed to provide, host, secure, support, back up, administer, and operate Summit, unless law requires otherwise. For account administration, billing, security, and Wayah's own business records, Wayah may act as an independent controller or business.
General product improvement relies on aggregated or de-identified service telemetry unless the Customer gives broader written permission. We do not use identifiable Customer Data, including recipe, process, or manufacturing data, to train a general-purpose or shared artificial-intelligence model without the Customer's express written authorization, and we do not attempt to re-identify de-identified data.
3. Essential technologies and providers
Summit uses service providers and essential authentication, security, hosting, payment, routing, communications, support, and service-operation technologies. Clerk provides authentication and identity. Stripe will provide payments, subscriptions, billing, fraud prevention, and tax processing after billing launches. Cloudflare provides DNS, routing, security, and network protection. Providers may process information only for contracted purposes and under applicable confidentiality, security, and data-protection duties. Wayah will maintain a current subprocessor list or other reasonable disclosure and provide notice of material changes when required by contract or law.
This site does not use advertising or behavioral tracking, Meta Pixel, Google Analytics, session replay, or similar marketing analytics. We do not sell personal information, share it for cross-context behavioral advertising, or use Customer Data for advertising. If these practices change, Wayah will update this Policy and provide any notice, consent, or opt-out required by law before the new practice begins.
4. Billing information
After billing launches, records include billing contacts, subscription status, invoices, transaction identifiers, complete billing address, and related records. Stripe processes payment card details. Never send full card numbers through support, email, or forms.
5. Disclosures
We disclose information when required by law or valid process, to protect rights, property, safety, or security, or as part of a merger, acquisition, financing, reorganization, or asset sale subject to applicable privacy duties.
6. Customer data processing and DPA
Where Wayah processes personal information for a Customer, the parties' DPA governs that processing and is incorporated into the agreement when required by applicable law or signed by the parties. The DPA will describe processing instructions, purpose, duration, data types and data subjects; confidentiality and security duties; subprocessors; assistance with rights requests, security incidents, and assessments; audit information; and return or deletion at the end of service. If the DPA conflicts with this Policy on Customer Data processing, the DPA controls.
Summit is initially offered for United States self-service customers. International access or sales require Wayah's written approval and any appropriate DPA, transfer mechanism, localization assessment, or additional privacy terms before regulated personal information is transferred across borders.
7. Retention, deletion, and exports
After a paid subscription ends, read-only access lasts 12 months and Customer Data is retained for five years total. After year one, dormant information may move to archival storage. During years two through five, an authorized administrator may request restoration or export. After five years, Customer Data is deleted or irreversibly de-identified subject to legal, accounting, tax, fraud-prevention, dispute, security, and backup needs. For a trial-only organization that does not begin paid service, read-only access lasts 30 days and Customer Data may be deleted or irreversibly de-identified 90 days after trial expiry following reasonable advance notice.
Authorized administrators may request earlier deletion or an export of available Customer Data in a commonly used machine-readable format where practical. We verify authority. Active and archival deletion occurs first; protected backups remain isolated from ordinary use and expire through normal rotation. No exact public backup duration is promised.
Wayah retains account records, security logs, support communications, billing and transaction records, and audit information only as long as needed for service operation, security, legal, tax, accounting, fraud prevention, dispute handling, or other legitimate business requirements, subject to applicable law.
8. Security and incidents
We use administrative, technical, and organizational safeguards appropriate to the nature and volume of information and promptly investigate suspected incidents. If a confirmed incident affects Customer Data, we notify the affected Customer without undue delay and as required by applicable law, provide available information reasonably needed for the Customer's legal obligations, and take reasonable steps to contain and remediate the incident. Notification may be delayed when law enforcement or legitimate security needs require. No online service guarantees protection from every threat.
9. Privacy requests
to request access, correction, deletion, portability, or another right provided by applicable law. We verify identity and support authorized-agent and appeal processes where required. When Wayah acts as a processor for Customer Data, we may direct the requester to the relevant Customer and will assist that Customer as required by the DPA or law.
Individual privacy rights do not transfer ownership of customer business information. A user cannot require deletion of organization-owned recipes, machines, production records, or other operational information solely because the user's account appears in those records.
10. Age, geography, and changes
Summit is intended for business users age 18 or older and is not directed to children. Self-service paid subscriptions launch for United States customers. Organizations outside the United States may contact Wayah and require manual legal, tax, security, and privacy review before access or purchase; Summit is not permanently restricted to the United States.
Material changes receive reasonable advance email or in-application notice and, where required by law, consent before materially different processing begins. Minor corrections, formatting, contact updates, and legally required administrative changes do not automatically require acceptance.
Registered office: 4030 Wake Forest Road, Ste 349, Raleigh, NC 27609, United States
The registered office is not currently designated for routine customer correspondence.
