Privacy policy

Last updated: 28 September 2026

This is a translation provided for convenience. The French version is the legally binding one.

This policy explains what personal data webedio processes, why, for how long, and how to exercise your rights. It covers webedio.com, the app.webedio.com platform and our business communications.

1. Data controller

Japaniste OÜ, operating the webedio brand, Ahtri tn 12, 10151 Tallinn, Estonia (Estonian Commercial Register no. 16271540). Contact for any data-related question: hello@webedio.com.

2. webedio.com: no cookies, no trackers

This website sets no cookies and uses no analytics, no advertising pixels and no third-party font or video services, so no consent banner is needed. Like any website, our host technically processes your IP address and connection details to serve the site and protect it from attacks. These technical logs are kept for a limited time.

3. Data we process

SituationDataPurpose and legal basisRetention
You contact usName, email, message, project detailsReply and prepare a proposal (pre-contractual steps)3 years after our last exchange
You become a clientIdentity, contact and billing details, project communicationsPerforming the contract, invoicing (contract, legal obligations)Contract term, then 10 years for accounting records
You use app.webedio.comEmail, name, encrypted password, login logSecure access to your workspace (contract)While the account is active, then deleted within 3 months
Business prospectingProfessional contact detailsPresenting our services (legitimate interest; you may object at any time)3 years after last contact

The only cookie used on app.webedio.com is the session cookie, which is strictly necessary for signing in.

4. Your customers' data (CRM platform)

When we host a CRM or send campaigns on your behalf, you are the data controller for your contacts' data and webedio acts as a processor under Article 28 GDPR, processing it only on your instructions. Each client has a separate database. Details are set out in our terms and conditions.

5. Recipients and sub-processors

We never sell your data. It is accessible to the webedio team and, for technical purposes, to our providers: Cloudflare, Inc. (hosting, security), Postmark (ActiveCampaign, LLC) (email delivery) and Google (Google Workspace) (email and office tools). Transfers to the United States rely on the EU–US Data Privacy Framework and, where applicable, the European Commission's standard contractual clauses.

6. Security

Encrypted connections (HTTPS), irreversibly hashed passwords, access restricted to authorised staff, a separate database for each client, and protection against repeated login attempts.

7. Your rights

You have the right to access, rectify, erase, restrict and port your data, and to object to its processing. Write to hello@webedio.com; we reply within one month. You may also lodge a complaint with the data protection authority of your country of residence or with the Estonian Data Protection Inspectorate (Andmekaitse Inspektsioon, aki.ee), our lead supervisory authority.