Your data, with the rules stated plainly
Privacy and cookie policy
What information we collect on this site, what we use it for, and which cookies you can accept or reject. You can change your choice at any time.
What this covers
This policy explains what personal data we process when you visit wattiot.io (the "Site") or contact us through it: when you request a demo, book a video call, write to the Site assistant or send us an email. It also contains our cookie policy. It is in force from 22 August 2026 and replaces any earlier version.
It does not cover the wattiot platform (https://app.wattiot.io/login and demo.wattiot.io). Plant data and platform user data are processed by each customer as controller, and by wattiot as processor, under the service contract and its data processing agreement. The platform's security measures are described in the Trust Center.
This policy is also published in Spanish and in Catalan. The Spanish version is the binding one: where a translation differs from it, the Spanish text prevails.
Data controller
- Registered name: [registered name pending] ("wattiot", "we", "us").
- Tax ID: [tax ID pending].
- Registered address: [registered address pending].
- Privacy contact: hello@wattiot.io.
We process your data under Regulation (EU) 2016/679, the General Data Protection Regulation (GDPR), and under Spanish Organic Law 3/2018 on data protection and the guarantee of digital rights (LOPDGDD). Although the Site is aimed at industrial plants, these rules apply regardless of the country you visit us from.
Principles
We collect only the data each purpose needs. We do not sell it or share it for advertising, we do not build profiles or take automated decisions with legal effects on you, and we do not process special categories of data (health, beliefs, trade union membership and the like). Please do not send us data of that kind through any of the Site’s channels.
The Site is aimed at professionals and businesses and is not intended for minors; we do not knowingly collect data from them. If you believe a minor has given us data, write to us and we will delete it.
Summary by purpose
Each row is one processing activity: what we do with the data, which data, what allows us to process it, and how long we keep it.
| Purpose | Data | Legal basis | Retention |
|---|---|---|---|
| Answering your demo or contact request (the /demo and /contact forms) | Name, company, email, phone (optional), the use case you describe, and the date and time of the submission | Pre-contractual steps taken at your request (art. 6.1.b GDPR). Any follow-up about that request rests on the consent you tick in the form (art. 6.1.a) | 12 months from the last contact if no commercial relationship follows; if one does, for the life of the contract and the legal periods that follow it |
| Booking a video call in the /demo calendar | Name, email, chosen slot, time zone and any notes you add | Pre-contractual steps taken at your request (art. 6.1.b GDPR) | 12 months from the last contact if no commercial relationship follows; if one does, for the life of the contract and the legal periods that follow it |
| Answering your questions in the Site assistant | The messages you write and the interface language. They are not linked to your identity unless you put it in the text | Legitimate interest in answering the question you put to us (art. 6.1.f GDPR); email is the alternative if you would rather not use it | We do not store them: the conversation lives in your browser and is gone when you close the tab. Anthropic retains API inputs and outputs temporarily to detect abuse, under its commercial terms |
| Measuring Site use in aggregate (Google Analytics 4), only if you accept analytics cookies | The random identifier in the _ga cookies, pages viewed, referrer, device and browser type, and approximate location derived from the IP address, which Google does not store | Consent (art. 6.1.a GDPR and art. 22.2 LSSI-CE), which you can withdraw from the cookie notice | Cookies: 2 years. Event data in Google Analytics: 14 months at most |
| Keeping the Site available and secure (server logs and attack protection) | IP address, user agent, requested URL, date and time, and the technical headers of each request | Legitimate interest in the security and operation of the Site (art. 6.1.f GDPR and recital 49) | Short periods: those our hosting provider, Cloudflare, needs to operate and protect the service |
| Managing customer and supplier relationships (contracts, invoicing and support) | Professional contact details, tax and billing details, and the correspondence exchanged | Performance of the contract (art. 6.1.b GDPR) and legal, tax and accounting obligations (art. 6.1.c) | For the life of the contract and, afterwards, the statutory periods: 6 years for commercial and accounting records |
| Answering your emails and handling your rights requests | Your email, the content of the message and, if you exercise a right, what is needed to verify your identity | Legitimate interest in replying to you (art. 6.1.f GDPR) and the legal obligation to handle your rights (art. 6.1.c) | 12 months from the last contact; rights requests, 3 years as evidence that they were handled |
Demo and contact forms
The fields marked as required (name, company, work email and use case) are what we need to prepare the session; without them we cannot act on the request. The phone number is optional. The consent checkbox authorises us to contact you about that request: it does not add you to any list, and we will not send you commercial messages you have not asked for.
The form reaches our mailbox (hello@wattiot.io) through the email delivery service Resend, which also sends you a confirmation. We do not keep requests in any database of our own: the Site is static and has no user accounts.
Calendar booking
The /demo calendar is a Cal.com component embedded in the page. When you book, you give your data directly to Cal.com, which processes it as our processor to create the appointment and send you the invitation; the booking appears in our calendar. It loads on that page only, because booking is exactly what that page is for. If you would rather not use it, the form on the same page and email do the same job.
Site assistant
The assistant answers questions about wattiot using an Anthropic language model, to which our server forwards your message and the last few turns of the conversation together with a fixed knowledge base about the product. The suggested questions are answered with predefined text and never leave your browser.
We do not log conversations or link them to your IP address or to other data, and exchanges with the Anthropic API are not used to train its models, under its commercial terms. If you include personal data in a message, yours or someone else’s, we process it only to answer you; please avoid including confidential or third-party information.
Web analytics
We use Google Analytics 4 only if you accept the "Analytics" category in the cookie notice. Until then, Google’s script loads with storage denied (consent mode v2): it sets no cookies and stores no identifiers, and sends Google only cookieless signals without user identifiers (the consent state and basic functional data, such as the page visited).
If you accept, Google receives aggregate usage statistics — pages viewed, referrer, device, approximate location — under a random identifier that does not let us know who you are. We do not use Google advertising tags and we do not share data with Google for advertising: the advertising consent signals stay denied unless you accept the "Marketing" category, and no tag uses them today. Google processes this data as our processor; on this page it explains how it uses information from sites that use its services.
Processors
To run the Site we rely on providers that process data on our behalf, under processing agreements (art. 28 GDPR) that require them to use it only to provide us the service:
| Provider | Service | Data processed | Location and safeguards |
|---|---|---|---|
| Cloudflare, Inc. | Site hosting, content delivery network, server functions and attack protection | Access logs (IP, user agent, URL) and the contents of forms and chat in transit | United States and global network. European Commission standard contractual clauses and certification under the EU–US Data Privacy Framework · Privacy policy |
| Resend | Sending the demo form emails: the notice to the team and the confirmation you receive | Name, company, email, phone and use case | United States. Standard contractual clauses · Privacy policy |
| Cal.com, Inc. | Booking calendar embedded in /demo | Name, email, booked slot, time zone and notes | United States. Standard contractual clauses · Privacy policy |
| Anthropic, PBC | Language model behind the Site assistant (API) | The messages in the conversation | United States. Standard contractual clauses; data not used to train models · Privacy policy |
| Google Ireland Ltd. and Google LLC | Google Analytics 4, only with your consent | _ga cookies and aggregate browsing data | Ireland and United States. Standard contractual clauses and certification under the EU–US Data Privacy Framework · Privacy policy |
Other recipients
- Professional advisers (legal, tax or accounting advisers and auditors), as far as they need it to provide us their services.
- Public authorities, courts and law enforcement, where a legal obligation requires it or it is necessary to defend our rights.
- Anyone acquiring all or part of our business in a corporate transaction, who will be bound by this same policy.
We do not sell your data, and we do not pass it to third parties so they can advertise to you.
International transfers
We are established in the European Union and some of the providers in the table above process data in the United States. Those transfers rely on the safeguards in Chapter V of the GDPR: the EU–US Data Privacy Framework adequacy decision for providers certified under it and, otherwise, the standard contractual clauses approved by the European Commission, with any additional measures required. You can ask us for a copy of those safeguards at hello@wattiot.io.
What they are
A cookie is a small file the Site stores in your browser so it can recognise it on later visits. Local storage (localStorage) does something similar, but its data never travels to the server. Cookies can be first-party (set by wattiot.io) or third-party (set by another domain, such as Google), and session (gone when you close the browser) or persistent (lasting for the stated period).
What we use
| Name | Category | Set by | Purpose | Lifetime |
|---|---|---|---|---|
wattiot_consent | Necessary | wattiot.io (first-party) | Remembering your choice in the cookie notice — analytics and marketing, accepted or refused — so we do not ask again | 12 months |
_ga | Analytics | Google (third-party) | Telling visitors apart with a random identifier. Only if you accept analytics | 2 years |
_ga_<id> | Analytics | Google (third-party) | Keeping the Google Analytics 4 session state. Only if you accept analytics | 2 years |
theme, billingCycle | Necessary (local storage) | wattiot.io (first-party) | Remembering the colour theme and the billing cycle chosen on /pricing. They are not sent to any server | Until you clear your browser data |
| Cal.com cookies | Necessary (on /demo only) | app.cal.com (third-party) | Making the embedded booking calendar work; Cal.com manages them inside its own component | As per Cal.com’s policy |
The "Marketing" category in the notice exists so your choice is recorded as a consent signal (ad storage, ad user data and ad personalisation), but we use no marketing cookie or tag today. If we ever add them, they will only run for anyone who has accepted that category, and this table will be updated first.
How consent works
Necessary cookies do not require consent. Analytics cookies are set only if you press "Accept all" or switch on "Analytics" in "Cookie preferences"; "Reject all" leaves the Site working exactly the same, without analytics. Your choice is stored in wattiot_consent for 12 months and, after that, we will ask again. Without JavaScript no analytics loads and the notice does not appear.
How to change your choice
- Reopen the notice from the "Cookies" link in the footer or from here and change whichever categories you want; the change takes effect immediately.
- Delete or block cookies from your browser settings. If you block
wattiot_consent, the notice will appear on every visit. - Install the Google Analytics opt-out add-on to stop Google Analytics using your data on any website.
What rights you have
- Access: to know whether we process data about you and to obtain a copy.
- Rectification: to correct inaccurate or incomplete data.
- Erasure: to have us delete your data when it is no longer needed or you withdraw your consent.
- Restriction: to have us stop using it, without deleting it, while a complaint is resolved or its accuracy is checked.
- Portability: to receive the data you gave us in a structured, commonly used format, or to have us send it to another controller.
- Objection: to object to processing based on legitimate interest on grounds relating to your particular situation and, in every case, to direct marketing.
- Withdrawing consent at any time, without affecting the lawfulness of processing before then: for cookies, from the notice; for everything else, by writing to us.
- Not to be subject to automated decisions with legal or similar effects: we do not take any.
How to exercise them
Write to hello@wattiot.io with the subject "Data protection", or by post to [registered address pending], saying which right you are exercising. If we have reasonable doubts about your identity, we may ask you to prove it. We will reply within one month, extendable by two more if the request is complex — we will tell you if so — and free of charge unless the requests are manifestly unfounded or excessive.
Complaints
If you believe we have not handled your request properly or that we process your data improperly, you can complain to the Spanish Data Protection Agency (C/ Jorge Juan, 6, 28001 Madrid) or to the supervisory authority of the EU country where you live. We would be grateful if you wrote to us first: we can almost always sort it out directly.
Security
We apply technical and organisational measures proportionate to the risk: all traffic is encrypted (HTTPS with HSTS), third-party service keys are held only on the server, forms are revalidated server-side and carry bot protection, and access to the request mailbox is limited to the team that handles it. The Site stores no data in any database of its own, which reduces the surface of risk.
No system is infallible: if we detect a breach affecting your data, we will notify it as the law requires. To report a vulnerability, write to hello@wattiot.io (see the Trust Center).
Changes to this policy
We will publish any change here, with its effective date at the top of the policy. If the change is substantial — new purposes, new recipients — we will highlight it on the Site and, where we have your contact details and it is appropriate, tell you directly. The version in force is always the one published on this page.