Privacy
How Warber handles personal data.
Effective 23 July 2026
This notice explains how Warber.io ("Warber", "we", "us") processes personal data when you visit warber.io, create or use a workspace, contact us, or pay for a subscription.
Controller and contact
For the marketing site, subscriptions, billing, service security and direct customer relationships, the controller is Warber.io, Gratemawei 3, 9041EJ Berltsum. Trade register: 42121380. Privacy requests can be sent to hello@warber.io or made by phone at +31 6 15 71 99 95 .
Our role for workspace data
The customer that administers a workspace normally determines why its users and workspace content are processed and is the controller for that data. Warber processes that data to provide the hosted service and acts as processor where data protection law assigns those roles. Workspace users should first contact their workspace administrator about the use of their content or membership. Warber will assist the customer with valid data-subject requests.
Warber remains an independent controller for its own account administration, billing, security, fraud prevention, operational audit and legal compliance.
Data we process
- Account and identity data: name, e-mail address, workspace membership, role, authentication credentials in protected form, security settings and invitation state.
- Workspace data: projects, tasks, comments, documents, chats, planning, notifications, settings, contributions and attachment metadata entered by users.
- Billing data: customer type, legal name, billing address, country, optional tax ID, billing contact, seats, consent timestamps, Stripe identifiers, subscription and invoice projections.
- Technical and security data: IP address, browser and request information, session state, access and security events, rate-limit signals, deployment generation and operational logs.
- Communications: support requests, billing correspondence and other messages sent directly to Warber.
We receive this data from you, your workspace administrator, activity within the service, and Stripe for billing and tax reconciliation. We do not receive or store full payment-card credentials.
Purposes and legal bases
- Contract
- To create and operate workspaces, manage accounts and seats, provide support, process subscriptions and invoices, and perform requested cancellation or withdrawal.
- Legitimate interests
- To secure tenant isolation, prevent abuse and fraud, diagnose failures, maintain reliable backups, reconcile provider state and protect Warber, customers and users. We balance these interests against the rights of affected people.
- Legal obligations
- To maintain tax and accounting records, answer valid authority requests, enforce payment and financial rules, and meet data-protection and security duties.
- Consent
- Where we expressly ask for consent. Consent can be withdrawn at any time without affecting earlier lawful processing.
Warber does not use workspace content for advertising and does not make solely automated decisions about individuals that produce legal or similarly significant effects. Stripe may independently perform payment, tax and fraud checks under its own terms and privacy notice.
Service providers, customer integrations and transfers
We disclose only the data needed to operate Warber to hosting and managed-database providers, private backup storage, transactional e-mail providers, Stripe for Checkout, Billing and Tax, and professional advisers or authorities where legally required. These parties process data under their own legal role or under appropriate processor terms.
Stripe processes billing, payment, tax and fraud-prevention data and may act as both processor and independent controller. See Stripe's Privacy Policy.
Workspace administrators may configure their own SMTP and S3-compatible storage. File bytes are uploaded directly to that customer-controlled storage. Warber authorizes uploads and stores attachment metadata, but does not copy customer-owned S3 files into Warber backups. The customer is responsible for selecting and governing those providers.
When personal data is transferred outside the European Economic Area, we require a lawful transfer mechanism appropriate to the provider and transfer, such as an adequacy decision or the European Commission's standard contractual clauses. Information about applicable safeguards is available on request.
Retention and deletion
- Active workspace and account data is kept while needed to provide the service.
- A workspace marked unpaid can be quarantined. A quarantined workspace becomes eligible for controlled destruction after 90 days. Verified tenant-database backups expire after at least 28 full days under the backup lifecycle.
- Customer-owned S3 files are outside Warber's deletion and backup boundary and must be managed by the customer.
- Stripe invoices and accounting records are retained for the applicable statutory period, normally seven years in the Netherlands and ten years for records covered by the EU One Stop Shop rules.
- Security, audit and support records are retained only as long as needed for security, dispute handling, legal obligations and the documented service lifecycle.
Deletion from active systems does not remove data from an existing backup immediately. Backup copies are isolated from normal use and disappear through the fixed retention lifecycle unless a legal preservation duty applies.
Security
Warber uses tenant-isolated databases, access controls, encrypted transport, protected secrets, security logging, generation-bound sessions and background work, verified backups and recurring restore tests. No service can eliminate every risk; suspected security incidents should be reported promptly to hello@warber.io.
Your rights
Depending on the circumstances, you may request access, correction, deletion, restriction, portability, or object to processing based on legitimate interests. You may withdraw consent where processing relies on consent. These rights can be limited by another person's rights or a legal retention duty.
Send a request to hello@warber.io. We may ask for proportionate information to verify identity and authority. You may also complain to the Dutch Data Protection Authority or the competent authority in your country.
Children and changes
Warber is not directed to children under 16. Contact us if you believe a child has provided personal data without valid authorization.
We may update this notice when the service or legal requirements change. Material changes will be communicated through the service or billing contact before they take effect where required.