Fill out the form below, and we'll reach out to explore how Wayfor can best support you and transform your team's growth.
Last modified: July 15, 2025
This Privacy Policy explains how Wayfor S.A. (“Wayfor”, “we”, “us”, or “our”) collects, uses, and protects the personal data submitted through the Wayfor website (wayfor.ai) in compliance with the General Data Protection Regulation (EU) 2016/679 (“GDPR”) and other applicable data protection legislation.
This Privacy Policy applies exclusively to personal data collected through the website’s contact form and through the automatic collection of technical data when you visit the website. For information about our use of cookies, please refer to our separate Cookie Policy available on the website. Our website may contain links to third-party websites. This Privacy Policy applies solely to data collected through the Wayfor website. Any personal data you provide to third-party websites is governed by their own privacy policies, over which we have no control. We recommend reviewing the privacy policy of any third-party website you visit.
Wayfor is the data controller responsible for the personal data collected through this website (within the meaning of art. 4 GDPR). As data controller, Wayfor determines the purposes and means of processing your personal data and is accountable for ensuring that processing is carried out lawfully, fairly, and transparently in accordance with the GDPR.
Wayfor S.A.
Registration Number: ELGEMI.180456803000
Address: 21 Karaiskaki Street, Kifissia, 14562, Greece
Email: info@wayfor.ai
Data Protection Officer (DPO):
Antonios Fix
Email: dpo@wayfor.ai
We collect only the personal data that you actively provide through the contact form on our website, together with limited technical data collected automatically when you visit. Failure to provide the required fields in the contact form will prevent us from processing your inquiry. We do not collect any special categories of personal data (such as health, racial or ethnic origin, political opinions, or biometric data) through this website. We do not knowingly collect personal data from individuals under the age of 16. Personal data we collect:
Contact Form (Required):
Contact Form (Optional):
Automatically Collected:
Wayfor processes your personal data only where a valid legal basis exists under the GDPR. Please find below each processing activity, its purpose, and the applicable legal basis:
Responding to contact form submissions: We process the data you submit in order to respond to your inquiry, provide information about our services, and conduct sales follow-up. Legal basis: consent (Article 6(1)(a) GDPR).
Customer relationship management: We retain contact details to manage the relationship arising from your inquiry. Legal basis: consent (Article 6(1)(a) GDPR) and, where a pre-contractual relationship arises, performance of a contract (Article 6(1)(b) GDPR).
Website security and performance: Technical data (IP address, browser type, device information) is processed to ensure the security, integrity, and proper functioning of the website, and to detect and prevent misuse, fraud, or cyber threats. Legal basis: legitimate interests (Article 6(1)(f) GDPR).
Compliance with legal obligations: Where required, we may process your data to comply with applicable law. Legal basis: legal obligation (Article 6(1)(c) GDPR).
We do not use the data collected through this website for automated decision-making or profiling within the meaning of Article 22 of the GDPR.
Where processing is based on your consent, you may withdraw your consent at any time by contacting dpo@wayfor.ai. Withdrawal does not affect the lawfulness of processing carried out prior to withdrawal.
Retention period: Personal data submitted through the contact form is retained for 12 months from the date of your last interaction with us, after which it is securely deleted. The retention period may be extended where necessary to: comply with a legal or regulatory
obligation, resolve a dispute or enforce our agreements and/or respond to an exercise of your data protection rights. Once the retention period expires and there is no longer a legal or business justification for retaining your data, it will be permanently deleted. Where immediate deletion is not technically feasible, the data will be isolated from further processing, stored securely, and deleted as soon as practicable.
Storage location: Personal data is primarily stored within the EU/EEA, including EU-region infrastructure of Amazon Web Services EMEA SARL (“AWS”), AC PM LLC, Google LLC and Amplitude, Inc. Personal data might also be stored or transferred outside the EU/EEA. Any such storage and/or transfer shall made in a GDPR compliant-manner (Chapter V GDPR transfer tools). It should be noted that all aforementioned providers are registered on the EU-U.S. Data Privacy Framework (DPF) List and therefore any data transfer to said providers is covered by the art. 45 GDPR adequacy decision mechanism so as to ensure GDPR compliance.
Data sharing: We do not sell, rent, or otherwise share your personal data with third parties for their own purposes. AWS, AC PM LLC, Google LLC and Amplitude, Inc. process data on our behalf as a data processor, under GDPR-compliant data processing agreements. We may disclose personal data where required to comply with a legal obligation, a court order, or a request from a competent authority, or where necessary to protect the rights, property, or safety of Wayfor, our users, or others.
Under the GDPR, you have the following rights in relation to your personal data:
Right of access (art. 15 GDPR): You may request a copy of the personal data we hold about you, in a structured, commonly used, and machine-readable format.
Right to rectification (art. 16 GDPR): You may request correction of inaccurate personal data or completion of incomplete information.
Right to erasure (“right to be forgotten”) (art. 17 GDPR): You may request deletion of your personal data where it is no longer necessary for the purpose for which it was collected, or where you withdraw consent on which processing is based. This right may be subject to legal retention obligations.
Right to restriction of processing (art. 18 GDPR): You may request that we limit processing of your personal data in specific circumstances, such as where you contest its accuracy.
Right to object (art. 21 GDPR): You may object to processing based on our legitimate interests. We will cease processing unless we can demonstrate compelling legitimate grounds that override your rights and freedoms.
Right to data portability (art. 20 GDPR): Where processing is based on your consent, you may request that your personal data be provided to you or transferred to another organisation in a machine-readable format, where technically feasible.
Right to withdraw consent (art. 7(3) GDPR): Where processing is based on your consent, you may withdraw it at any time without affecting the lawfulness of prior processing.
Right not to be subject to automated decision-making (Art. 22 GDPR): We do not make decisions about you based solely on automated processing. This right therefore has no current practical application in relation to this website.
To exercise any of these rights, please contact us at dpo@wayfor.ai, providing your name, email address, and a description of your request. We will respond within one (1) month of receipt, free of charge. We may ask you to verify your identity before processing your request.
Wayfor will not discriminate against you in any way for exercising your data protection rights.
If you have concerns about the way we handle your personal data, we encourage you to contact us first at dpo@wayfor.ai so that we can address the matter directly.You also have the right to lodge a complaint with the competent supervisory authority. In Greece, this is:
Hellenic Data Protection Authority (HDPA)
Email: contact@dpa.gr
Tel: +30 210 6475 600
Website: www.dpa.gr
Wayfor implements appropriate technical and organisational security measures to protect your personal data from unauthorised access, unlawful use, accidental loss, alteration, or disclosure. These measures include:
While we take all reasonable precautions, no system of data transmission or storage can be guaranteed to be completely secure. You acknowledge that any submission of personal data to us through the website is made at your own risk.
In the event of a personal data breach that is likely to result in a risk to your rights and freedoms, Wayfor will notify the Hellenic Data Protection Authority (HDPA) within 72 hours of becoming aware of the breach, in accordance with Article 33 of the GDPR.
Where the breach is likely to result in a high risk to your rights and freedoms, we will also notify you directly without undue delay, in accordance with Article 34 of the GDPR, providing information about the nature of the breach, its likely consequences, and the measures taken or proposed to address it.
We may update this Privacy Policy from time to time to reflect changes in our practices, legal requirements, or operational circumstances. The updated version will be published on this page with a revised “Last modified” date. Where changes are material, we will notify you by means of a prominent notice on the website or, where we hold your contact details, by email. We recommend reviewing this Policy periodically.
For general inquiries about this Privacy Policy email WAYFOR S.A. at info@wayfor.ai.
For data protection matters or to exercise your rights email Antonios Fix at dpo@wayfor.ai.
© Wayfor. All Rights Reserved.