Skip to content
WhafyWhafy — homeProvider sign in

Privacy Policy

What we collect, why we are allowed to, who else sees it, how long we keep it, and what you can make us do about it.

Last updated

1. Who we are

WHAFY LTD is the data controller for the personal data described in this policy. We operate from Larnaca, Cyprus and provide a platform that connects people in Cyprus with independent home and car service providers.

You can reach us about anything in this policy at support@whafy.com.

Still to be settled: WHAFY LTD is being registered as a Cyprus company and the registrar has not yet issued its registration number or confirmed its registered office. Both will be published in this clause as soon as they exist. We would rather leave them out than print something we cannot evidence.

We have not appointed a Data Protection Officer. We do not believe Article 37 requires one at our size and activity, but that assessment has not been formally reviewed, and it will be before launch.

2. What we collect

Different people give us different things, so this is split by who you are. Nothing here is a category we might collect one day — it is what the system stores today.

If you are a customer

  • Your account: phone number, name, email address if you give one, a hash of your password (never the password itself), whether you told us you live in Cyprus or are visiting, when your number was verified, and when the account was created and last changed.
  • Your addresses: a label if you give one, street line, area, city, country, and — when we have been able to work them out — the coordinates of the address, plus which address is your default.
  • Your bookings: the service and options chosen, the time, the addresses involved, the price you were quoted and any discount, the provider assigned, the status history of the job, and any reason you give for cancelling.
  • Quote requests: the description you write of the job, and any photographs you attach — which are often of the inside of your home.
  • Reviews: a star rating, an optional comment in your own words, and optional tags.
  • Your preferences: whether you want booking updates, whether you have opted in to marketing, and when you opted in.
  • Security records: counts and times of failed sign-in attempts, and any lock placed on the account as a result.
  • Technical records: your IP address, used for rate limiting and written to server logs.

If you are visiting Cyprus and told us so

A traveller profile holds your country of origin, your preferred language, your arrival and departure dates, and the type of place you are staying in — hotel, short-let, villa or other. We deliberately do not collect passport or identity-document data: it would be a liability with no use in this version of the product.

If you are a service provider

Provider accounts are created by us, not by self sign-up. We hold your legal or trading name, a contact person’s name, phone number and email address, registered address, VAT and business registration numbers where they apply, bank account holder name, IBAN and bank name for payouts, any salon name and address with its coordinates, the areas and map boundaries you cover, your working hours and days off, your staff members’ names, the services you offer with the price you stated and the commission agreed for each, the documents you upload for onboarding — identity, business registration, insurance and licence declarations — a hash of your password, and sign-in and lockout records.

If you are a Whafy administrator

The same account fields as a customer, plus an audit trail: every status change, price change, promo code, coverage boundary, quoted price and support-details edit records which administrator made it and when. That trail is deliberately not erasable — it is what makes an administrative action attributable.

4. Who else receives your data

Two kinds of recipient. First, the provider assigned to your booking: they receive your name, the service address, the time and what you asked for, because somebody has to arrive at your door. They do not receive your email address, your other saved addresses or your booking history.

Second, the companies that run parts of our infrastructure. Each acts on our instructions and for no purpose of its own. This is all of them, and precisely what each one gets:

Third parties that receive personal data, what each receives, and where
Amazon Web ServicesEverything the service stores: the database, uploaded quote photographs and provider documents, cache and queue contents, and server logs.Hosting and storage.eu-central-1 (Frankfurt, Germany) — inside the EU.
TwilioYour phone number, and the one-time code when it is checked. Nothing else — no name, no address, no booking.Sending and verifying the one-time code that proves the number is yours.Twilio's Verify service. TODO(legal): the processing region has not been pinned in the Twilio console, so a transfer outside the EEA cannot currently be ruled out.
LocationIQFor a map pin: a latitude and longitude, nothing more. For a typed address: the full address line — street, area, city, country — as you wrote it. Never your name, your account or any identifier.Turning addresses into coordinates and back.us1.locationiq.com — a United States endpoint. This is a transfer to a third country.
OpenRouteService (HeiGIT gGmbH)Coordinate pairs only — a start and an end point, or a grid of points. No address text, no identifier.Driving distance and travel time, used to price a move.Heidelberg, Germany — inside the EU.
OpenStreetMap Foundation (Nominatim) (not active yet)The same coordinates or address line as LocationIQ, plus a contact email address in the request header, which their usage policy requires.A fallback geocoder. Configured and working, but not the one production uses.United Kingdom / EU community infrastructure.
PostHog (not active yet)Which pages you viewed and which actions you took, against a random identifier — and only after you accept analytics cookies. If you are signed in, your internal account number travels with the event so a journey can be joined to a booking. Never your IP address, and never your phone number, email address, name, postal address, coordinates or anything you typed into a form.Understanding how the site and app are used. Lawful basis: your consent — Art. 6(1)(a).PostHog Cloud EU (Frankfurt) — inside the EU, and the same city as our own servers. Events go to our server first and are forwarded from there, so your browser never connects to PostHog, no PostHog code ever runs on your device, and your IP address stops with us.
Stripe (not active yet)Nothing yet. Payments are not switched on — the platform runs in a mode where no money moves and no card details are collected anywhere.Card payments and provider payouts, when payments launch.To be confirmed before payments go live.
CloudflareConnection metadata, including your IP address, for requests to whafy.com and whafyapp.com.Domain name resolution and edge routing, and the redirect that sends the former marketing domain whafyapp.com to whafy.com.Global edge network.
Zoho (Zoho Corporation B.V.)Anything you put in an email you send us, or that we send you: your email address, the subject and body, and any attachment. Mail to the published support address is delivered here and stored in the mailbox.Whafy's email on whafy.com — the published support address, and transactional mail to you when the product sends any.Zoho's European data centres (zoho.eu) — inside the EU. Whafy's mail has been on this account since 12 Aug 2026.

One of these is on consent rather than on contract, and the difference is visible to you. Every recipient above except PostHog receives data because it is needed to run the service, so it happens whether or not you have an opinion about it. PostHog receives nothing at all unless you accept analytics cookies, and if you withdraw that consent we delete the analytics profile and every event in it, not merely stop collecting more. The same erasure runs when you delete your account, provided the app tells us which analytics identifier is yours — see the cookie page to change your mind at any time.

The distinction between a coordinate and an address is real and we are making it deliberately. When you drop a pin on a map, the only thing that leaves our systems is a latitude and a longitude. When you type an address, the address line itself is sent to the geocoder so it can be found. Route pricing sends coordinates only. In none of these cases is your name, your account or any identifier sent along with it.

Still to be settled: we have not yet executed a written data processing agreement with each of these companies, which Article 28 requires. This is being done before launch.

We also disclose personal data where the law requires it — to a court, a regulator or a law-enforcement authority acting under a valid request. We will tell you when that happens unless we are legally prohibited from doing so.

5. Where your data goes

Everything Whafy itself stores is held in the European Union— the database, uploaded photographs and documents, the cache and the server logs all live in Amazon’s Frankfurt region. That was chosen for closeness to Cyprus, and it means the bulk of your data never leaves the EEA.

Two exceptions, both named plainly:

  • Address lookups reach a United States endpoint. Our geocoding provider serves us from us1.locationiq.com. What travels there is a coordinate or an address line, never an identifier — but it is a transfer to a third country and we are not going to describe it as anything else.
  • One-time codes go through Twilio.Your phone number is sent to Twilio to deliver and check the code. Twilio’s processing region has not been pinned in our account configuration, so we cannot currently promise the processing stays in the EEA.

Still to be settled: a transfer out of the EEA needs a safeguard under Chapter V of the GDPR — usually Standard Contractual Clauses, plus an assessment of the destination country. Neither is in place for the two transfers above. Closing this is on the pre-launch list, and the alternatives are signing the clauses, pinning both vendors to EU processing, or replacing them.

Whafy intends to operate beyond Cyprus, including in the Middle East. When it does, this section will gain a sub-section per jurisdiction rather than being rewritten: the European rules described here will continue to apply to everyone whose data is processed in the EU or who is in the EU, and a country with its own data protection law will get its own clause naming that law, its regulator and its complaint route.

6. How long we keep it

The short version: while your account is open we keep what the account needs; when you delete it we erase everything that identifies you and keep the commercial record with your name taken out of it.

If you delete your account

There is a “Delete account” control in the app. It is irreversible — there is no undelete and support cannot put it back. What happens is:

  • We refuse if a job is still live. If you have a booking that is neither completed nor cancelled, we will not delete the account until it is resolved, and we tell you how many are outstanding. Deleting anyway would strand a provider who is on their way to an address for a customer who no longer exists. An open quote request is not a live job and does not block anything — those are withdrawn automatically as part of the deletion.
  • Erased outright: your saved addresses, your traveller profile if you have one, any stored one-time codes, password reset tokens, and the photographs you uploaded with quote requests.
  • Erased from your account record: your name (replaced with a marker showing the account was deleted), your email address, your phone number, your password hash, your marketing preferences and the record of your marketing consent.
  • Your phone number is released and can be used to register a completely new account immediately. The new account inherits nothing from the old one.
  • Your analytics profile is deleted— the person record and every event in it, not just the identifier. This happens when the app sends us the random analytics identifier it holds as part of the deletion. We cannot look that identifier up ourselves, deliberately: we keep no link between your account and it, precisely so it cannot be used to identify you. One consequence is worth stating — if you used Whafy on more than one device, each device holds its own identifier and deleting your account from one of them erases that one. Email us if you want all of them gone and we will do it.
  • Kept, with you removed from it: bookings, orders, quote requests, reviews and visit packages. These carry no name, no email address and no phone number — the schema was built that way — and they continue to point at an account that is now nobody.

The basis for keeping that ledger is Article 17(3)(b) — compliance with a legal obligation, being tax and accounting records — and Article 17(3)(e) — the establishment, exercise or defence of legal claims, being a dispute about a job that was actually done. Neither of those justifies keeping a name, an email address, a phone number or a home address, and none of those is kept.

Once your account is deleted, every route that could issue a new session refuses it, and the account cannot be signed into again. A session token already issued stays valid until it expires, which is at most fifteen minutes — and by the time that window opens the account holds nothing personal to read.

Other retention periods

  • Server logs: 30 days, then deleted automatically.
  • Rate-limiting counters: minutes to hours; they expire on their own.
  • One-time codes:ten minutes. When codes are delivered through Twilio we store none at all — the code’s whole life happens at Twilio and never touches our database.
  • Your cookie choice: six months, then we ask again.

What we have not decided yet, and are telling you rather than hiding

We have not set an end date for the anonymised commercial record. Article 13(2)(a) requires us to give you either a retention period or the criteria for working one out, and today we can only give you the reason we keep it, not the point at which we stop. The statutory retention period for Cyprus accounting records is the thing that should set it, and that is a question for a qualified adviser rather than for us.

Invoicing will conflict with this and we know it.When card payments launch, a completed booking will generate a VAT invoice, and a Cyprus VAT invoice is legally required to carry the customer’s name and address for a statutory period — the two fields deletion erases. The likely resolution is that invoices become separate immutable documents with their own retention period and their own carve-out from erasure, and that the carve-out has to exist before the first invoice is issued, because it cannot be applied retrospectively to accounts already deleted. This is recorded as an open question in our engineering decision log, not discovered later.

We record that you withdrew marketing consent, but not when.Turning the marketing switch off works immediately and stops everything; what is stored is the current state, not the moment it changed. Article 7(3) requires withdrawal to be as easy as consent — it is — and does not require the moment to be logged, but we would not be able to answer “when did they opt out?” and that is worth saying.

Free text you wrote is not inspected. A review comment, a cancellation reason, a quote description or a note attached to a declined quote survives your account deletion attached to the anonymised record. It is content rather than identity — but if you put your name or address inside one, no automatic process will find and remove it. Email us and we will.

7. Your rights, and how to use them

These are your rights under Chapter III of the GDPR. Each one names the control that exercises it, because a right you can only reach by writing an email and waiting is a right in a weaker sense.

Data subject rights and the control that exercises each
Access — Art. 15Settings → Download my data in the app. Produces a structured JSON file of your account, addresses, traveller profile, bookings, orders, quote requests, reviews and preferences, generated on request from live data.
Portability — Art. 20The same download. It is machine-readable JSON so it can be loaded elsewhere, which is what portability means.
Rectification — Art. 16Settings → Edit profile for your name and email; Settings → Addresses for your addresses. Your phone number cannot be changed in the app yet because changing it requires re-verifying the new number — email us and we will do it.
Erasure — Art. 17Settings → Delete account. What survives and why is set out in section 6.
Withdraw consent — Art. 7(3)Settings → Notifications for marketing; the cookie page for analytics. Both are one tap, in the same place you gave consent, and take effect immediately.
Object — Art. 21Applies to the two things we do on legitimate interests (abuse prevention and diagnostic logging). Email us saying what you object to and why; we will stop unless we can show compelling grounds that override your reasons.
Restriction — Art. 18Email us. Typically used while a dispute about accuracy or objection is resolved.
Complain — Art. 77To us first if you are willing, and to the Office of the Commissioner for Personal Data Protection in Cyprus whether or not you contact us.

We answer within one month, as Article 12(3) requires, and we will not charge you for it. We may ask you to prove who you are before acting on a request that arrives by email — not to obstruct you, but because handing somebody’s data to a person who merely knows their email address would be the breach the right exists to prevent.

8. How we protect it

Passwords are stored only as hashes and never in a form we could read. Traffic is encrypted in transit. One-time codes are never written to a log. Access to the production database is restricted to what the application needs. Accounts lock themselves after repeated failed sign-in attempts, and repeated attempts from one source are rate limited.

No system is perfect. If a breach happens that is likely to risk your rights and freedoms, we will notify the Cyprus supervisory authority within 72 hours as Article 33 requires, and tell you directly if the risk to you is high.

9. Children

Whafy is not for children. You must be at least 18 to hold an account, and we do not knowingly collect data from anyone younger. If you believe a child has given us personal data, tell us and we will delete it.

10. If you are a California resident

This section is provided voluntarily. The California Consumer Privacy Act does not currently apply to Whafy, and we would rather say so than imply an obligation that does not attach.

The CCPA, as amended by the CPRA, applies to a business that meets at least one of three thresholds. Whafy meets none of them:

  • Annual gross revenue above the statutory threshold (in the region of $25 million, adjusted for inflation). Whafy has not launched paid transactions — the platform runs with payments switched off and no money has moved through it.
  • Buying, selling or sharing the personal information of 100,000 or more California consumers or households a year. Whafy operates in Cyprus, does not target California, and buys, sells and shares no personal information at all.
  • Deriving 50% or more of annual revenue from selling or sharing personal information. Whafy derives none of its revenue that way, because it does not do it.

We are setting the position out anyway because it is the useful thing to know and because it will need revisiting if Whafy ever operates in the United States. If you are in California, here is where you stand:

Categories of personal information collected

In the CCPA’s vocabulary: identifiers (name, phone number, email address, IP address, account identifier); customer records information (postal address, bank details for providers); commercial information (services booked, prices, history); geolocation data (address coordinates); internet activity (server logs, and analytics if you accept them); and professional information for providers (business registration, VAT number, licences and insurance documents). We collect no biometric data, no precise real-time location tracking, no government identifiers from customers, and none of the sensitive personal information categories.

Categories sold or shared

None. Whafy does not sell personal information, and does not share it for cross-context behavioural advertising — the two things the CPRA means by those words. We have verified this against what the software actually does rather than asserting it: there is no advertising network, no data broker, no marketing pixel and no cross-site tracking anywhere in the product. The recipients listed in section 4 are service providers acting on our instructions and are paid by us, not for the data.

Do Not Sell or Share My Personal Information

Because we do not sell or share personal information, there is nothing to opt out of. If that ever changes we will add the opt-out link the statute requires and say so here first. In the meantime, if you want confirmation of our position in writing, or you want to exercise the CCPA rights to know, delete or correct, use the same controls in section 7 or email us. We will not discriminate against you for exercising any of them.

11. Cookies

This website sets no analytics or advertising cookies unless you accept them, and rejecting is as easy as accepting. The full list, what each one does and how to change your mind is on the Cookie Policy page.

12. Changes to this policy

When we change this policy we will change the date at the top. If a change materially affects how we use data we already hold — a new purpose, a new recipient, a new transfer — we will tell you directly rather than relying on you noticing a date, and where the change needs your consent we will ask for it rather than assume it.