WILS

Terms Privacy

Privacy Policy

Last updated: July 22, 2026

Draft notice: This Privacy Policy is provided as a draft and should be reviewed by a qualified legal professional before production use.

1. Introduction

This Privacy Policy describes how WILS collects, uses, stores, protects, and shares personal data. WILS is a business-to-business (B2B) Software-as-a-Service warehouse management platform — a Warehouse Item Location System designed for small and medium-sized warehouses.

This policy applies to:

  • Visitors to our website.
  • Pilot programme applicants and prospective customers.
  • Customer account administrators.
  • Users and warehouse operators who access the WILS platform.
  • Support contacts and other business contacts who interact with us.

It is intended to be read together with our Terms of Service and, where applicable, any Data Processing Agreement entered into with a customer.

2. Who We Are

The data controller responsible for personal data described in this policy (other than personal data we process on behalf of customers) is:

  • [LEGAL COMPANY NAME]
  • [REGISTERED ADDRESS]
  • Company registration number: [COMPANY REGISTRATION NUMBER]
  • General legal contact: [LEGAL EMAIL]
  • Data protection contact: [DATA PROTECTION CONTACT EMAIL]
  • Data Protection Officer: [DPO CONTACT, IF APPLICABLE]

Our role under data protection law depends on the type of data involved:

  • For personal data relating to our website, sales enquiries, billing, and the customer account relationship, WILS generally acts as the controller.
  • For operational warehouse data uploaded or generated by customers through the Service (which may include personal data about the customer’s employees, operators, suppliers, or business contacts), the customer generally acts as the controller and WILS acts as the processor.
  • Processing carried out on behalf of customers may be governed by a separate Data Processing Agreement which prevails over this policy in the event of conflict.

3. Personal Data We Collect

We collect the following categories of personal data.

A. Website and enquiry data

  • Name.
  • Email address.
  • Phone number (where provided).
  • Company name.
  • The content of your message or enquiry.
  • IP address.
  • Device and browser information (for example, browser type, operating system).
  • Cookie and analytics data, where used (see section 6).

B. Account and subscription data

  • Account administrator name and email address.
  • Company details (such as trading name and address).
  • Billing contact details.
  • Plan and subscription details.
  • Payment status (we do not store full card details — see section 7).
  • Records of support communications.

C. User and operator data inside WILS

  • User name.
  • Email address.
  • Role and permissions.
  • Employee or operator identifier.
  • Warehouse assignment.
  • Login and activity timestamps.
  • Audit and security logs.

D. Operational data uploaded or generated by customers

  • Item and inventory records.
  • Supplier and customer references where entered.
  • Warehouse locations and configurations.
  • Batch and expiry records.
  • Receiving records.
  • ASN and delivery note records.
  • Pick, pack, and dispatch records.
  • Transaction ledger records.
  • Reports and exported files.

Operational data may include personal data where the customer chooses to enter employee, operator, supplier, customer, or contact details into WILS. The customer decides what data is entered and is the controller of that data.

4. How We Collect Personal Data

  • Through forms on our website.
  • When you register for an account, request a demo, or apply for the pilot programme.
  • When customer administrators create users within their tenant.
  • When you and your Users use the WILS platform in the normal course of warehouse operations.
  • From files you or your Users upload or import into the Service.
  • From support communications (email, in-app messages, scheduled calls).
  • Through cookies or similar technologies, where used (see section 6).
  • From third-party services and integrations enabled by the customer (for example, carriers or ERP systems).

5. Purposes and Legal Bases

Where WILS acts as controller, we rely on the following purposes and legal bases under the GDPR:

Purpose Legal basis
Provide and operate the ServicePerformance of a contract / legitimate interests
Create and manage customer accounts and usersPerformance of a contract / legitimate interests
Process billing and subscription paymentsPerformance of a contract / legal obligation
Provide customer supportPerformance of a contract / legitimate interests
Maintain security, audit logs, and prevent fraud or abuseLegitimate interests / legal obligation
Improve, debug, and develop the ServiceLegitimate interests
Send service, security, and billing communicationsPerformance of a contract / legitimate interests
Send marketing communications where legally permittedConsent or legitimate interests, with an opt-out
Comply with legal, tax, accounting, and regulatory obligationsLegal obligation
Process customer operational data through the ServiceOn the customer’s documented instructions, in our role as processor

6. Cookies and Similar Technologies

We use a small number of cookies and similar technologies. The categories that may apply are:

  • Essential / session cookies — required to keep you signed in and to operate the Service (for example, the PHPSESSID session cookie).
  • Security cookies — used to protect against cross-site request forgery and other abuse.
  • Preference cookies — used to remember basic interface choices, where applicable.
  • Analytics cookies — only where an analytics provider is in use ([ANALYTICS PROVIDER, IF USED]).

Most browsers allow you to view, manage, and delete cookies through their settings. Blocking essential cookies may prevent the Service from functioning correctly.

7. How We Share Personal Data

We share personal data only where it is necessary to operate, secure, support, or improve the Service, or where required by law. Categories of recipients include:

  • Hosting and infrastructure providers ([HOSTING PROVIDER]) that host the Service and store data on our behalf.
  • Payment providers ([PAYMENT PROVIDER]) that process subscription payments. Payment card details are entered directly with the payment provider; we do not store full card numbers.
  • Email and support providers ([EMAIL PROVIDER]) used to send transactional, service, and support communications.
  • Analytics providers ([ANALYTICS PROVIDER, IF USED]), where used and where lawful.
  • Professional advisers such as lawyers, accountants, and auditors, under appropriate confidentiality obligations.
  • Public authorities and regulators, where we are required to do so by law or by valid legal process.
  • Integration providers enabled by the customer, such as carriers, ERP systems, point-of-sale systems, or e-commerce platforms.

WILS does not sell personal data. WILS does not share customer operational data with advertisers. Third-party processors are used only where necessary for the purposes described above and are subject to appropriate contractual safeguards.

8. International Transfers

Personal data may be stored or processed in Ireland, elsewhere in the European Economic Area (EEA), the United Kingdom, or in other locations depending on the providers we use. [CONFIRM HOSTING REGION / INTERNATIONAL TRANSFER POSITION].

Where personal data is transferred outside the EEA to a country that is not subject to an adequacy decision, we will put in place appropriate safeguards as required by applicable law, such as the European Commission’s Standard Contractual Clauses, supplemented where necessary by additional technical and organisational measures.

9. Data Retention

  • Account data is retained for as long as the account is active. [RETENTION PERIOD FOR ACCOUNT DATA].
  • Billing and legal records are retained for as long as required by tax, accounting, and other legal obligations.
  • Support records are retained for a reasonable period to support ongoing service delivery and dispute resolution.
  • Security and audit logs are retained to support service integrity, incident investigation, and legal obligations. [RETENTION PERIOD FOR AUDIT LOGS].
  • Customer operational data is retained in accordance with the Customer’s subscription and account retention terms.
  • After termination of the Service, Customer Data may be exported by the Customer for a reasonable period and will then be deleted or anonymised in accordance with our retention policies. [RETENTION PERIOD AFTER TERMINATION].

10. Security

We implement appropriate technical and organisational measures designed to protect personal data, including:

  • Access controls and role-based permissions.
  • Authentication, including secure password storage.
  • Warehouse boundary and tenant isolation enforcement within the platform.
  • Audit logs and security monitoring.
  • Routine backups for operational continuity.
  • Encryption of data in transit using HTTPS/TLS, and encryption at rest where applicable.
  • Principle of least privilege for internal access.

No system can be guaranteed to be 100% secure. Customers are responsible for managing their own user permissions, password security, multi-factor authentication where available, and the security of devices and networks used to access the Service.

11. Customer Responsibilities

  • Customers decide what operational data and user data they enter into WILS.
  • Customers must have a lawful basis under applicable data protection law for uploading personal data about their employees, operators, suppliers, customers, or other contacts.
  • Customers are responsible for managing user access, including granting, reviewing, and removing access when it is no longer needed.
  • Where required, Customers must inform their own employees, operators, and other affected individuals about the use of WILS and any related processing of personal data.

12. Data Subject Rights

Subject to applicable law, individuals have the following rights in relation to their personal data:

  • Access — to obtain a copy of personal data we hold about them.
  • Rectification — to have inaccurate personal data corrected.
  • Erasure — to request deletion of personal data in certain circumstances.
  • Restriction — to request that processing be limited in certain circumstances.
  • Portability — to receive certain personal data in a structured, commonly used, machine-readable format.
  • Objection — to object to processing based on legitimate interests, including direct marketing.
  • Withdraw consent — where processing is based on consent, to withdraw that consent at any time without affecting the lawfulness of processing carried out before withdrawal.
  • Complaint — to lodge a complaint with the Data Protection Commission in Ireland or another competent supervisory authority (see section 18).

To exercise these rights, please contact us at [DATA PROTECTION CONTACT EMAIL]. We may need to verify the identity of the requester before responding.

Where a request relates to personal data that is part of a customer’s operational data (and the customer is the controller), we may refer the request to the relevant customer/controller and assist them in responding as required by our agreement with that customer.

13. Children

WILS is a B2B service intended for warehouse and business operations. It is not directed at, or intended for use by, children. Users of the Service should be authorised business users acting on behalf of a customer organisation.

14. Automated Decision-Making

WILS does not use personal data to make decisions that produce legal effects, or similarly significant effects, on individuals, unless we specifically inform the affected individuals.

Operational recommendations within the Service — for example, stock alerts, expiry alerts, FEFO (first-expiry-first-out) suggestions, or dashboard warnings — are decision-support tools based on Customer Data and require human and business review before being acted upon. They are not automated decisions about individuals.

15. Marketing Communications

Where legally permitted, we may send product updates, service announcements, and marketing communications about WILS. You can opt out of marketing communications at any time using the unsubscribe link in our marketing emails or by contacting [DATA PROTECTION CONTACT EMAIL].

Service, security, billing, and other transactional communications relating to your account or use of the Service are not marketing and may continue to be sent even if you opt out of marketing.

16. Changes to this Privacy Policy

We may update this Privacy Policy from time to time, for example to reflect changes in the Service, our providers, applicable law, or best practice. Where changes are material, we will provide reasonable notice through our website, by email to the account contact, or by an in-app notice. Continued use of the Service after the effective date of an update means that the updated policy applies.

17. Contact

For questions about this Privacy Policy or about how we handle personal data, please contact:

  • [LEGAL COMPANY NAME]
  • [REGISTERED ADDRESS]
  • Data protection contact: [DATA PROTECTION CONTACT EMAIL]
  • General legal contact: [LEGAL EMAIL]
  • Website: [WEBSITE URL]

18. Supervisory Authority

If you are based in the EEA and have concerns about how we process personal data, you have the right to lodge a complaint with a data protection supervisory authority. The Irish supervisory authority is:

  • Data Protection Commission
  • 21 Fitzwilliam Square South
  • Dublin 2
  • D02 RD28
  • Ireland
  • Website: https://www.dataprotection.ie/

This Privacy Policy is provided as a draft and should be reviewed by a qualified legal professional before production use.

© 2026 WILS — Terms · Privacy