Privacy Policy
Version 4.0, July 3, 2026. Last updated: .
1. In brief
This is a short summary. The full detail is in the sections below, which prevail if there is any conflict.
- Who runs Wevion: Bhblasted SRL SB (VAT IT08466861211), an Italian company, is the data controller for your account. Contact: privacy@wevion.ai
- What we collect: account and billing details, how you use the platform, data from the ad accounts you connect, support and AI-chat interactions, and cookies.
- Why: to run the Service (contract), to bill and keep it secure (contract / legitimate interest / legal obligation), for aggregate analytics (legitimate interest), and for marketing (only with your consent).
- Your data is not sold. We do not sell it for money. Some advertising cookies may count as a "share" under California law; during the closed beta you can request an opt-out by emailing privacy@wevion.ai.
- Your rights: access, correct, delete, export, and object. EU/UK/EEA users can complain to their data protection authority (in Italy, the Garante).
- Ad platforms: when you connect Meta, Google or others, you remain responsible for collecting valid consent from the people you advertise to. For Meta Business Tools you and Meta may be joint controllers (see the Meta section).
2. Who we are and our role
Bhblasted SRL SB is the Business (CCPA/CPRA) and Data Controller (GDPR) for the personal data of platform users (account holders). For personal data that our customers process through the Service (for example audience or lead data), Bhblasted SRL SB acts as a Service Provider (CCPA) / Data Processor (GDPR), on the customer's documented instructions. B2B customers enter into a separate Data Processing Agreement (DPA) that governs those processor activities. Bhblasted SRL SB is established in the European Union (Italy). An EU representative under GDPR Art. 27 is therefore not required, because Art. 27 applies only to controllers not established in the Union. We have not appointed a Data Protection Officer as we are not required to; privacy matters are handled at privacy@wevion.ai. Contact for any privacy question: privacy@wevion.ai.
3. Data we collect
3.1 Account data
Name, email, password (stored hashed), preferred language, role, organization affiliation.
3.2 Billing data
Processed through Stripe: name, billing address, tax ID (VAT/EIN/GST), payment-method token. We do not store full payment card numbers.
3.3 Usage data
Actions on the platform (logins, campaigns created, rules triggered), device information (browser, OS), IP address, session cookies, and timestamps.
3.4 Ad account data (via integrations)
When you connect Meta, Google or other ad accounts: OAuth tokens, ad account IDs, campaign data, performance metrics, audience data, and creative assets you upload.
3.5 Support interactions
Email, chat and support-widget messages, attachments, and related metadata.
3.6 AI chat data
Prompts you send to AI assistants and conversation history, retained per your account retention setting.
3.7 Cookies and analytics
First- and third-party cookies for authentication, preferences, analytics and, where consent is required, marketing attribution. See the Cookie Policy.
Some analytics tools (Microsoft Clarity, PostHog) record session activity; recordings are configured to mask user input and sensitive fields. During the closed beta these tools may run for all beta participants; strict EU/UK consent-gating will be enabled before we open the Service to the general public.
4. How we use your data (legal bases)
4.1 EU/UK/EEA users (GDPR Art. 6)
- Providing the Service (account, core features): Contract (Art. 6(1)(b))
- Billing, fraud prevention, security: Contract + legitimate interest (Art. 6(1)(b),(f))
- Aggregated / anonymized analytics: Legitimate interest (Art. 6(1)(f))
- Marketing communications: Consent (Art. 6(1)(a)), withdrawable at any time
- AI assistant features: Contract / consent
- Legal compliance (tax, lawful requests): Legal obligation (Art. 6(1)(c))
4.2 California residents (CCPA/CPRA)
We process personal information for the business purposes listed below. We do not sell personal information for money, and we do not share it for cross-context behavioral advertising without honoring your opt-out (see the California section).
- Providing the Service and related operations
- Billing, fraud prevention, and security
- Product improvement and analytics (anonymized where feasible)
- Marketing communications (only with opt-in consent)
- Legal compliance (tax records, lawful requests)
4.3 Other jurisdictions
We comply with applicable law (e.g. LGPD, PIPEDA, APPI, PDPA, and US state privacy laws). Your rights are described in the "Your rights" section.
5. Sharing your data and international transfers
We do not sell your personal data (in the ordinary meaning or under the CCPA/CPRA definition). We share personal data only as follows:
- Sub-processors (hosting, email delivery, AI inference, payments, analytics). The current versioned list is at /sub-processors. We give advance notice of new sub-processors and customers may object.
- Legal authorities, where required by law or to protect our rights.
- An acquirer in a merger, acquisition, or asset sale (equivalent privacy protection required).
- For recipients outside the EEA, transfers are covered by SCCs or an adequacy mechanism (see /sub-processors).
International data transfers
Bhblasted SRL SB is an Italian company. Some personal data may be processed in the United States or globally by our sub-processors. By default, data is stored in US- and EU-based cloud infrastructure (e.g. AWS us-east-1, eu-west-1, depending on the service).
For transfers of personal data from the EU/UK/EEA, we rely on the Standard Contractual Clauses (SCCs) approved under EU Commission Decision 2021/914, or on an adequacy mechanism where one applies. Data subjects keep their GDPR rights, enforceable against Bhblasted SRL SB.
6. Meta Business Tools and joint controllership
When you connect a Meta ad account and use Meta Business Tools through Wevion (for example the Meta Pixel or the Conversions API), you and Meta Platforms may act as joint controllers under GDPR Art. 26 for the collection and transmission of certain event data, as set out in Meta's Controller Addendum / Joint Controller terms. In this arrangement, Wevion acts as your service provider / processor, operating the integration on your documented instructions. You remain responsible for:
- obtaining valid consent from the individuals you advertise to before any pixel, tag, or Conversions API event fires, where consent is required;
- keeping proof of that consent, in line with Meta's requirements; and
- honoring opt-outs and providing any notices your local law requires.
The same principles apply to comparable tools from other ad platforms you connect. Wevion provides consent-gating and controls, but it cannot replace your own legal basis for advertising to your audiences.
7. Retention
Account data: While the account is active + 30 days after deletion Billing records: As required by tax law (typically 10 years under Italian fiscal law; longer where another applicable law requires) Usage logs: 180 days (aggregated analytics may be kept longer in anonymized form) Support tickets: 3 years Marketing consent records: Until withdrawn + 2 years Ad account data: While the integration is active; deleted on request AI chat history: Per account setting (configurable; default 12 months)
8. Your rights
8.1 Rights available in most jurisdictions
- Access your personal data
- Correct inaccurate data
- Delete your data (subject to legitimate retention requirements)
- Portability: receive your data in a machine-readable format
- Object to, or restrict, certain processing (Art. 18, 21)
- Withdraw consent at any time (Art. 7(3)) without affecting prior lawful processing
- Opt out of marketing communications
- Not be subject to automated decision-making with legal or similarly significant effect (Art. 22)
- California: Know, Delete, Correct, Opt out of sale/sharing, Limit use of sensitive personal information, and Non-discrimination for exercising rights
8.2 EU/UK/EEA (GDPR / UK GDPR)
You can exercise the rights below by contacting privacy@wevion.ai or using the Data Subject Request form in account settings. We respond within 30 days (extendable to 90 days for complex requests, Art. 12).
You also have the right to lodge a complaint with a supervisory authority. In Italy this is the Garante per la protezione dei dati personali (Piazza Venezia 11, 00187 Roma; www.garanteprivacy.it). If you are in another EEA country or the UK, you may contact your local data protection authority instead.
8.3 California (CCPA/CPRA)
California residents have the rights listed below. We verify identity before we fulfil a request (we may ask you to log in or answer security questions) and respond within 45 days (extendable to 90). You may use an authorized agent with signed written authorization. See the California opt-out section for "Do Not Sell or Share."
8.4 Other jurisdictions
Comparable rights apply under LGPD (Brazil), PIPEDA (Canada), APPI (Japan), PDPA (Singapore), and US state laws (VCDPA, CPA, CTDPA, UCPA and others). Contact us to exercise them.
9. California: Do Not Sell or Share and notice at collection
We do not sell personal information for money. Certain advertising cookies and tools (for example Meta Pixel and Google Ads) may qualify as a "share" for cross-context behavioral advertising under the CPRA, even without payment. During the current closed beta you can reopen the "Manage cookie preferences" panel from the app footer to review the cookie categories in use, and you can opt out of any "share" of your personal information by emailing privacy@wevion.ai. A self-service "Do Not Sell or Share My Personal Information" control and automated Global Privacy Control (GPC) handling are not yet available and will be enabled before we open the Service to the general public; until then we action opt-out requests received by email within 15 days. At the point where we collect personal information (for example the sign-up form and the cookie banner) we provide a short notice at collection describing the categories we collect, the purposes, whether data is sold or shared, and a link to this Policy.
10. AI features and automated decision-making
Wevion's AI features assist you, for example by drafting copy, generating creative assets, or suggesting budget adjustments. They do not make automated decisions that produce legal or similarly significant effects on you under GDPR Art. 22. You always review AI output before it is published or acted on, and final decisions rest with you. AI output is provided "as is"; you are responsible for reviewing it for accuracy, compliance, and rights clearance before use (see Terms of Service, section “AI & Machine Learning Features”). We do not sell your prompts or use them to train third-party models without your consent. California ADMT (effective 1 January 2026): to the extent any feature is treated as automated decision-making technology under CPRA rules, California residents may opt out and request information about the logic involved by contacting privacy@wevion.ai.
11. Security
We use technical and organizational measures appropriate to the risk (GDPR Art. 32). No system is completely secure; in the event of a breach we notify affected users and authorities as required by applicable law.
- TLS 1.2+ encryption in transit
- Encryption at rest for sensitive fields (AWS KMS)
- Role-based access control and MFA for production access
- Regular vulnerability scanning
- Documented incident-response plan
- Employee privacy and security training
- GDPR Art. 33–34: notification to the supervisory authority within 72 hours where required, and to affected individuals without undue delay
- CCPA/CPRA and US state laws: notice without unreasonable delay, as mandated
12. Children's data
Wevion is a B2B service and is not directed at children under 18 (or under 16 in the EU). We do not knowingly collect data from children under 13 (US COPPA). If you believe a child has provided us data, contact privacy@wevion.ai for removal.
13. Changes to this Privacy Policy
We may update this Policy from time to time. Material changes take effect 30 days after we notify you by email or in-app notice. Non-material updates (clarifications, new sub-processors covered by SCCs) are published with an updated "Last updated" date. Each version is identified by a version number and effective date, and your acceptance is recorded against the specific version in force when you accept.
14. Contact
Privacy inquiries: privacy@wevion.ai Bhblasted SRL SB, Attn: Privacy Via Boscofangone SNC, Zona ASI, Lotto C8, 80035 Nola (NA), Italy VAT IT08466861211
Contact
Bhblasted SRL SB
Via Boscofangone SNC, Zona ASI, Lotto C8, 80035 Nola (NA), Italy
Privacy inquiries: privacy@wevion.ai