This notice explains what personal data we collect through this website and the Maimava platform, why we hold it, who else sees it, how long we keep it, and what you can ask us to do about it. It is written to be read rather than to be defensible, and every retention period in it is the period the software actually enforces.
1. Who we are
WooSee Limited ("we", "us") is the data controller for the personal data described in this notice. Maimava is the smart-fridge operations platform we supply.
- Company: WooSee Limited, registered in England and Wales, no. 14364528
- Registered office: 71–75 Shelton Street, Covent Garden, London WC2H 9JQ
- VAT registration: GB 486 515 656
- ICO registration: ZB532687
- Data protection contact: solo@woosee.pro
There is no data protection officer — we are not required to appoint one — so that address reaches a person directly.
2. What this notice covers — and what it does not
It covers the personal data we decide the purposes for, as controller:
- what you send us when you apply for early access (section 3);
- the account, credential and audit records that let us run the platform securely for the people who sign in to it (section 4);
- what happens when you use "See your own numbers" at maimava.com/try (section 5); and
- ordinary use of this website (section 6).
What it does not cover
The data inside an operator's workspace. When a business uses Maimava to run its machines, that business is the controller for the personal data it puts in — its hosts' contact and bank details, its staff's records, any prospect data it gathers — and we are its processor, acting on its instructions. What we do with that data is set out in Annex A of the operator terms, which is the processing agreement between us and that business. If you are a host, a venue contact or a prospect, the operator you deal with is the controller and their own privacy notice applies; we will always tell you who that is if you ask.
Host portals. Each operator's host portal carries a link to that operator's own privacy notice.
3. If you apply for early access
The form at maimava.com/signup asks for two things. A few more are recorded by the server when you submit it, and we would rather list them than let you find out later.
| What | Why we have it | Lawful basis |
|---|---|---|
| Your email address | To send you the confirmation link, and to reply to your application either way | Steps taken at your request before entering a contract (Art 6(1)(b)) |
| Your business name | To know who is applying, and to set up your workspace if you go ahead | Steps taken at your request before entering a contract (Art 6(1)(b)) |
| Which version of the terms you accepted, and when | So that we can show which text you agreed to, rather than reconstructing it later | Our legitimate interest in keeping a record of agreement (Art 6(1)(f)) |
| How you reached us — recorded only when you arrive by a link that says so (for example a campaign link) | To know which channels bring applications | Our legitimate interest in understanding our own reach (Art 6(1)(f)) |
| Your IP address, recorded with the application | Kept as part of the record of a submission to a public form, so that abuse of it can be identified. It is not used to profile you, is not shown on any screen, and is not read in the ordinary course of dealing with your application | Our legitimate interest in protecting a public form from abuse (Art 6(1)(f)) |
What happens to it
- We email you a confirmation link so we know the address is yours. The link works for 24 hours. We never store the link itself — only a one-way fingerprint of it, so a copy of our database cannot be turned into somebody else's confirmed application.
- When you confirm, an internal notice goes to the person who reviews applications. It contains your business name, your email address, how you reached us and when you applied.
- Applications are read by a person. There is no automated decision-making and no profiling: nobody is accepted or refused by a machine.
- If we go ahead, we create your organisation record, your workspace and your account from the details above, and email you a link to set a password.
- If we decline after you have confirmed your address, we email you to say so. If the address was never confirmed we do not — we have no evidence the mailbox is yours, and writing to it would mean mailing a stranger about an application they may not have made. Either way we do not keep you on a list for later, and we do not add you to any marketing list: we send no marketing email at all.
- If we decline, whoever decided may record a short internal note about why. It is never shown to you or to anyone outside the company, but it is part of your data and you can ask for a copy of it (section 9).
One consequence worth stating plainly
Applications we decline, and those where the address is never confirmed, are deleted after 90 days. But the record that we made a decision lives in our audit log, which is kept for 7 years — and that record contains your email address and business name. So deleting the application does not erase every trace of it, and it would be misleading to let the 90 days imply otherwise. If you want the audit entry removed as well, ask us (section 9) and we will consider it on its merits.
Applications that are confirmed and awaiting a decision, or approved, are not deleted automatically — the first because somebody is still waiting for an answer, the second because it is the record of how a live account came to exist. Ask us to delete your application at any time and we will.
4. If you have an account on the platform
This section is about the people who sign in — an operator's staff, and the host contacts who use a host portal. We are the controller for the records that let us run the service securely, whichever workspace you belong to.
| What | Why we have it | Lawful basis |
|---|---|---|
| Your email address, and your name where it was given | To identify your account, sign you in, and send you account email such as an invitation or a password reset | Our legitimate interest in operating the service securely (Art 6(1)(f)); performance of our contract with your organisation (Art 6(1)(b)) |
| Your credentials — a password, a passkey, or both | To authenticate you | As above |
| Your sessions — a record of each sign-in, so it can be ended | So that signing out, a password change, or removing you from a workspace takes effect immediately rather than waiting for a session to expire | As above |
| Your appearance preference — whether you chose the light or dark theme | So the platform looks the way you set it, on whichever device you sign in from | Our legitimate interest in a usable service (Art 6(1)(f)) |
| An audit log of significant actions taken in the platform, which records who did what and when, and can include email addresses | Security, accountability, and being able to answer afterwards what happened to a money document | Our legitimate interest in a reliable record (Art 6(1)(f)); legal obligation where the action concerns an accounting record (Art 6(1)(c)) |
Your credentials are never stored in a form anybody here can read. Passwords are hashed, and a passkey is held as a public key — the private half never leaves your device. Nobody at WooSee can recover your password, which is why a reset replaces it rather than telling you what it was.
Invitation and password-reset links are stored the same way as the signup confirmation link: as a one-way fingerprint, never the link itself. An invitation lasts 24 hours, because the colleague it was minted for may not be at their desk. A password reset lasts 2 hours — you asked for it a moment ago and are waiting on the email, and a link that is enough on its own to take an account over should not sit in a mailbox for a day. A link for registering a passkey lasts 10 minutes, because you are at the keyboard when you use it. The stored fingerprint of any of them is cleared within 24 hours of the link expiring.
If you are removed from a workspace, your access ends on your next request — it does not wait for your session to run out. The account record itself is not deleted automatically, because you may hold access to another workspace. Ask us and we will delete it.
5. If you use "See your own numbers"
maimava.com/try lets you drop a sales export from your own machines and get your months, products and takings back, with no account and no sign-up.
We keep no copy of your file. It is read as it arrives, the summary is computed and returned to your browser, and nothing is saved to any database. There is nothing to delete afterwards, because there is nothing kept. We do not require an email address to use it and we do not ask for one.
We are deliberately not claiming the bytes never touch a disk, because for a large file that would not be true: our web server buffers an upload over about 2 MB to a temporary file while it is being received, which is deleted as soon as the request finishes. Nothing else reads it — it exists only so the upload can be handed to the reader — and nothing survives the request.
As with any web service, our server logs record the request itself — the time, the address it came from, and, where a file could not be read cleanly, a short technical note that may quote an identifier from the row that failed. Those are operational logs about business data, not a copy of your file.
6. Cookies, browser storage and server logs
This website sets no cookies. There is no analytics, no advertising tag, and no third-party script of any kind. The fonts are served from our own server rather than from a font provider, specifically so that visiting a page does not disclose your IP address to a third party.
The platform's signed-in applications do use your browser's local storage. In full, it holds:
- your session token — what keeps you signed in from page to page — and, in the operator dashboard, which workspace you are currently viewing. Both are removed when you sign out;
- in the operator dashboard, a copy of your light or dark theme choice; and
- in the operator dashboard, the last area you searched on the leads map — a postcode and its coordinates — so it is still there when you come back.
The host portal stores only the session token. The theme is the one item that is not only in your browser: the copy there exists so the page paints in the right colours before you have signed in, but your choice is saved to your account as well, which is what makes it follow you to another device. Clearing your browser data will not forget it — it comes back from your account at the next sign-in. The saved leads area, by contrast, never leaves your browser and clearing your browser data does remove it.
We consider the session token strictly necessary for the service to work, and the other two preferences you have set yourself; we do not use any of them to track you, and none is shared with anyone. Nothing else is stored, and neither this website nor the applications use cookies or session storage at all.
Server logs
Our web server keeps an ordinary access log of the requests it serves — including the ones that produced this page. Each entry records the time, the address the request came from, which page was asked for, the page you came from if any, and what the browser reported about itself. That is how a web server is operated and how abuse is investigated; we do not use it to build a profile of you, and it feeds no analytics of any kind. Our lawful basis is our legitimate interest in running the service securely. These logs rotate daily and we keep about ten days of them, so an entry is gone inside a fortnight.
7. Who else handles your data
We keep the number of third parties small. Only one of them holds or is sent the personal data described in this notice:
| Who | What for | Where |
|---|---|---|
| Amazon Web Services | Hosting, database, and sending our email | United Kingdom (London region) |
The data described in this notice stays in the United Kingdom. We do not transfer it outside the UK, and it is not sold, rented or shared with anyone for their own purposes.
There is one exception, and it is about your browser rather than our servers. The operator dashboard has a map of prospective venues, and that map is Google's: when you open that screen your browser loads Google's mapping code directly, which discloses your IP address to Google in the United States, as loading a Google map on any website does. It happens only on that screen, we send Google nothing about you ourselves, and no other page of the platform or of this website loads anything from a third party. We would rather name it than let "everything stays in the UK" quietly cover something a network log would contradict.
Workspace content is a different question, and the answer differs. Two US sub-processors — Anthropic, which reads supplier documents an operator uploads, and Google, which powers venue discovery — process data inside an operator's workspace. That processing belongs to the operator as controller and is described in Annex A of the operator terms, together with the honest note that the transfer paperwork for it is not yet in place. None of it applies to an applicant, to an account holder's own account records, or to a visitor to this site.
We will disclose personal data where the law requires it — for example to a regulator or in response to a valid legal request. If that ever happens we will tell you, unless the law forbids us from doing so.
8. How long we keep it
| What | How long | Why that long |
|---|---|---|
| An application we declined, or one where the address was never confirmed | 90 days from when you applied | Long enough to answer a query about it; after that we have no use for a stranger's details |
| An application that is confirmed and awaiting a decision, or approved | Kept — no automatic deletion | Somebody is still waiting for an answer; or it is the record of how a live account came to exist. Ask us and we will delete it |
| A confirmation link for a new application, or an invitation for a new member | 24 hours, then it stops working | The person it was sent to may not be at their desk |
| A password-reset link | 2 hours, then it stops working | You asked for it a moment ago. A link that is enough on its own to take an account over should not sit in a mailbox for a day |
| The stored fingerprint of an invitation or reset link | Cleared within 24 hours of the link expiring | Once the link is dead the fingerprint has no further use. An application's own fingerprint stays with the application record instead, and goes when it goes |
| Your account and credentials | For as long as you have an account. Ask us and we will delete it | You need to be able to sign in |
| A session | Removed within 24 hours of expiring; immediately if you sign out or we revoke it | It is only a revocation record |
| The audit log | 7 years | It records actions taken on accounting and tax documents, and is tied to the same clock as those records |
| Web server access logs | About 10 days | They rotate daily and ten are kept. Long enough to investigate a fault or abuse, and no longer |
| Backups | 35 days, then they age out | Enough to recover from a failure, not so long that a deletion never really takes effect |
Deletion from our live systems is immediate. Copies persist in backups for up to 35 days and then age out; they are not used for any purpose in the meantime. We will not tell you deletion is instantaneous everywhere, because it is not.
9. Your rights
Under UK GDPR, you have the right to:
- Access — request a copy of the personal data we hold about you
- Rectification — ask us to correct inaccurate or incomplete data
- Erasure — ask us to delete your data (subject to the retention requirements above)
- Restriction — ask us to stop using your data while we look into a concern
- Objection — object to processing we carry out on the basis of legitimate interests
- Data portability — receive a machine-readable copy of data you gave us
- Withdraw consent — at any time, where we rely on consent. Withdrawal does not affect the lawfulness of processing carried out beforehand
There is no charge to exercise any of these rights, and we will respond within one calendar month. Email solo@woosee.pro. If you are asking about data held inside an operator's workspace rather than by us — see section 2 — we will pass you to the right controller rather than leave you without an answer.
10. Complaints
If you are unhappy with how we have handled your data, please email us first at solo@woosee.pro — we would rather put it right.
You also have the right to complain to the UK Information Commissioner's Office:
- Information Commissioner's Office, Wycliffe House, Water Lane, Wilmslow, Cheshire SK9 5AF
- Telephone: 0303 123 1113
- Website: www.ico.org.uk
11. Changes to this notice
If we change how we handle personal data, we change this page and move the date at the top of it. Where a change materially affects you and we hold your address, we will tell you rather than relying on you to re-read the page.
The retention periods in section 8 are checked automatically against the software that enforces them, so this page cannot quietly fall out of step with what actually happens to your data.
Questions
Write to solo@woosee.pro. A question about this notice reaches a person, not a queue.