Wattly’s Privacy Policies

Institutional-grade privacy for bankable infrastructure

Your privacy is central to how we build and operate GreenBridge360™. Wattly processes personal data lawfully, fairly, and transparently in line with the EU GDPR and applicable local laws. This notice explains what we collect, why we collect it, how we protect it, and the choices you have.

Scope & roles

This notice covers personal data processed by Wattly Group in connection with our websites (including wattly.se), GreenBridge360™, investor and partner onboarding, and our communications.

  • Controller: For most activities, Wattly acts as data controller.

  • Processor: When we operate GreenBridge360™ on behalf of enterprise clients under contract, we act as data processor and follow their instructions.

What we collect

We collect only what’s necessary for defined purposes:

  • Identification & contact: name, email, phone, employer, role, postal address.

  • KYC/AML & compliance: identity documentation, sanctions/PEP screening results where required by law.

  • Professional & transactional: organisation, mandate details, deal documentation, signatures, audit logs.

  • Technical & usage: IP address, device/browser, session metadata, security logs, cookie preferences.

  • Communications: inquiries, meeting notes, support tickets, marketing opt-ins/opt-outs.

We do not intentionally collect special categories of data. If legal screening incidentally reveals such data, we handle it with heightened safeguards.

Lawful bases

Depending on context, we process data because it is:

  • Necessary for a contract (e.g., to provide platform access, fulfil a mandate).

  • Required by law (e.g., AML/KYC, record-keeping, sanctions compliance).

  • In our legitimate interests (e.g., platform security, fraud prevention, service improvement, B2B relationship management) — balanced against your rights.

  • Based on consent (e.g., certain cookies/analytics, optional marketing). You may withdraw consent at any time.

Why we process your data

  • Service delivery: account creation, user administration, support, and feature operation.

  • Compliance & governance: AML/KYC, audit trails, covenants, reporting, incident management.

  • Security: access control, monitoring, threat detection, and investigation.

  • Relationship management: meetings, updates, event invitations (with opt-out), satisfaction surveys.

  • Product improvement: usage analytics and performance metrics to enhance GreenBridge360™.

Sources & automated decision-making

Data comes directly from you, your organisation, public registries, screening providers, and analytics/security tools. We do not make decisions solely by automated means that produce legal or similarly significant effects; risk scoring and screening always include human review.

Sharing & recipients

We share data only as needed and under contract:

  • Service providers: cloud hosting, security, analytics, communications, identity verification.

  • Professional advisors & banks: legal, audit, fiduciary, and transaction counterparties.

  • Affiliates & corporate transactions: where relevant and subject to safeguards.

  • Authorities: when legally required.
    All vendors are vetted, bound by confidentiality and data-processing terms, and monitored.

International transfers

Where data leaves the EEA/UK, we use approved transfer tools (e.g., EU Standard Contractual Clauses, UK addenda) plus technical/organisational measures and documented transfer-impact assessments, consistent with EDPB guidance.

Security & retention

Security is “by design” and “by default.” Controls include role-based access, MFA, encryption in transit and at rest, secure SDLC, logging, monitoring, and independent testing. (See our Legal & Security page for detail.)
We retain data only as long as needed for the purposes above and to meet legal obligations (e.g., AML/KYC records for the statutory period), then securely delete or anonymise it.

Your rights

Subject to law, you can: access, rectify, erase, restrict, object (including to processing based on legitimate interests), and port your data; and withdraw consent where relied upon. You can also lodge a complaint with your local authority (in Sweden: Integritetsskyddsmyndigheten, IMY).
To exercise your rights, contact us at privacy@wattly.se

Cookies & similar technologies

We use essential cookies for site and platform functionality and (with consent) analytics. Manage preferences via our Cookie Notice and consent banner at any time.

Children

Our services are business-focused and not directed to children under 16.

Updates & contact

We may update this notice to reflect legal, technical, or business changes. We’ll post the latest version here with an effective date.
Controller: Wattly Group AB, [registered address].
Data Protection Contact / DPO: dpo@wattly.se

Important informaton

For professional and institutional investors only. This material is informational and does not constitute investment advice or an offer to buy or sell any security. Investments involve risk and are subject to eligibility and definitive documentation. Past performance is not a reliable indicator of future results.