Privacy and Data Protection

Good data handling starts with purpose, role, and necessity.

WMT distinguishes website processing, customer-controlled system data, service operations, and the contractual responsibilities that apply to each context.

Privacy model

First identify who decides, why data are used, and which service is involved.

Roles and obligations cannot be inferred from the WMT brand alone; they depend on the specific processing activity and agreement.

Public website The Privacy Policy describes processing associated with website visits, enquiries, forms, communications, and configured optional technologies.
Customer-controlled systems The customer generally determines its users, purposes, lawful basis, records, permissions, retention, disclosures, and responses to individuals, subject to the applicable relationship.
WMT services Where WMT processes customer data to provide agreed implementation, hosting, support, migration, or other services, the instructions, access, safeguards, retention, and deletion should be documented.
Third parties Hosting providers, identity providers, email, payment, analytics, integrations, and other vendors may have their own roles, terms, locations, and control responsibilities.
Legal boundary: this page is general information, not legal advice and not a substitute for the Privacy Policy, signed terms, or jurisdiction-specific assessment.

Data-protection principles

Make processing understandable and proportionate.

The exact legal formulation depends on jurisdiction, but these operating principles support clearer decisions and safer implementation.

Purpose and transparency

Define why data are needed, who uses them, how the processing is explained, and which decisions or services depend on them.

Minimization and access

Collect and expose only what is relevant, then align permissions and administrative access with legitimate responsibility.

Quality and lifecycle

Support accurate records, controlled changes, retention decisions, archival where required, and an agreed return or deletion path.

Protection and accountability

Apply proportionate safeguards, document responsibilities, manage vendors and transfers, and retain evidence appropriate to the risk.

Data lifecycle

Privacy decisions continue from discovery through decommissioning.

Migration, integration, support, exports, reporting, backups, testing, and archived environments can all create additional copies and responsibilities.

Every stage should identify the purpose, source, destination, access, validation, retention, and secure disposal or return process appropriate to the engagement.

  1. Discover and classify

    Identify categories, sources, users, purposes, legal constraints, sensitive fields, and connected systems.

  2. Design and configure

    Define roles, fields, workflows, notices, integrations, exports, logging, environments, and vendor dependencies.

  3. Migrate and operate

    Control extracts, transfer, staging, validation, support access, reporting, backup copies, and issue handling.

  4. Retain, return, or delete

    Apply documented rules at end of purpose, contract, user relationship, environment, or legal retention requirement.

Privacy requests and questions

Route the request to the party that can make the required decision.

A request about data in a customer-controlled system may need to go to the school, university, or organization that determines the processing.

Website data

Read the Privacy Policy

Review the website-specific processing summary and contact route.

Privacy Policy

Customer system

Contact the relevant customer

The customer may need to verify identity, authority, legal basis, retention, and the action requested in its system.

Existing service

Use Support

Authorized customer contacts can route product- or environment-specific privacy and data-handling questions through Support.

Contact Support

Evaluation

Contact Sales

Discuss proposed processing, deployment, contractual terms, and due-diligence requirements during evaluation.

Contact Sales

Questions

Frequently asked questions

Is WMT always the data controller?

No. The applicable role depends on the processing activity and relationship. In customer systems, the customer may determine purposes and means while WMT acts under agreed instructions for defined services. Other activities may have different roles.

Where are detailed privacy terms defined?

The Privacy Policy covers website processing. Customer-specific processing should be defined in the applicable agreement, data-processing terms, instructions, security requirements, subprocessor arrangements, and retention or deletion provisions.

Does WMT guarantee compliance with every privacy law?

No general website statement can guarantee a customer’s compliance. Customers remain responsible for their legal basis, notices, user rights, configuration, data use, and jurisdiction-specific obligations, with their own legal advice.

How are data-retention periods determined?

Retention should be based on purpose, customer instructions, legal requirements, operational need, backup design, support obligations, and the agreed deletion or return process.

How can a privacy request be made?

Website-related requests can use the contact route identified in the Privacy Policy. Requests involving a customer-controlled system may need to be directed first to that customer as the relevant decision-maker.

Privacy in context

Define the processing, roles, data, locations, and lifecycle.

The applicable Privacy Policy and signed customer documentation remain authoritative for a specific relationship.