Privacy Policy for Waffle
Last updated: July 20, 2026
1. The Purpose of this Privacy Policy
At Friskly AB ("Friskly", "Waffle", "we", or "us"), we care about your privacy and are committed to protecting your personal data. This Privacy Policy explains how we collect, use, protect, and handle your personal data when you use Waffle, our team communication and collaboration service (the "Service"), and when you visit or contact us in connection with it.
This policy is part of our Terms of Service. It describes the basis on which personal data is collected and processed when you use the Service.
We regularly update this policy. Any changes are published on this page, and in the case of significant changes, you will be informed by email or within the Service.
2. Data Controller
Friskly AB is registered with the Swedish Companies Registration Office (Bolagsverket) under organization number 559500-7526, with its registered office at Färögatan 33, 164 51 Kista, Sweden.
Friskly AB is the data controller for the personal data described in this policy that we process to operate the Service and to manage our relationship with you (for example, account data and billing data).
Where we process personal data within the content of a customer workspace on behalf of a customer organization, we act as a data processor for that organization, which is the controller. That processing is governed by a separate Data Processing Agreement (DPA), available on request.
If you have questions about how we process your personal data, or wish to exercise your rights under the General Data Protection Regulation (GDPR), please contact us at hello@trywaffle.app.
3. Third-Party Links
The Service and our website may contain links to third-party websites and services. These have their own privacy policies, and we take no responsibility for their handling of personal data. We recommend that you review their policies before submitting personal data or using their services.
4. What Personal Data We Collect and Why
Depending on how you use the Service, we may collect, store, and process the following categories of personal data.
Account data. When you create an account or join a workspace, we collect identity information such as your name, email address, and password (stored in hashed form). This information is necessary to create and operate your account and to identify you within your workspace. Your profile may also include optional information you choose to provide, such as a display name, avatar, bio, pronouns, time zone, or status.
Workspace and message content. The Service stores the content that you and your workspace members create, including channel and direct messages, threads, reactions, files and attachments you upload, and the content you direct to Waffle AI. This content is stored to provide the Service to your workspace. Within a customer workspace, this content is processed on behalf of, and under the control of, the customer organization (see Section 2).
Payment and billing metadata. When your workspace subscribes to a paid plan, we and our payment processor Stripe process billing-related data, such as your subscription plan, seat count, billing interval, subscription status, and (for business customers) tax or VAT identification information. Payment card details are collected and processed directly by Stripe; we do not store full card numbers. We store limited billing metadata (for example, subscription and payment status) needed to operate billing and to keep records.
Usage and technical data. We collect limited information necessary to operate and secure the Service, such as log data, device and connection information, and records of certain actions taken within the Service (for example, audit records of consequential actions). We do not use third-party advertising or web analytics trackers, and we do not use cookies for marketing.
Website measurement. We measure how our public website is used with our own first-party, privacy-friendly analytics, which we operate ourselves rather than through a third-party analytics provider. This measurement is cookieless (it sets no cookie and stores nothing on your device beyond a temporary session identifier that is discarded when you close the browser tab), and it does not track you across websites or build a profile of you. When a page reports a visit, your IP address and browser user agent are used only momentarily, on receipt, to derive coarse, non-identifying signals (such as an approximate country, a device type, and a daily, rotating, one-way visitor count), and are then discarded and never stored. The result is aggregate statistics (for example, page views, popular pages, referrers, and general interaction patterns) that help us understand and improve the website. We rely on our legitimate interest in operating, securing, and improving our website for this measurement (see Section 5), and because it is first-party and does not use non-essential cookies or similar device storage, no separate cookie consent is required for it.
Contact data. If you contact us for support or other inquiries, we process the information you provide (such as your name, email address, and message content) to respond to you.
5. Legal Bases for Processing
We only process your personal data where the law permits, on one or more of the following legal bases:
- Performance of a contract. To create and operate your account and workspace, provide the Service, and process your subscription and payments.
- Legitimate interests. To secure, maintain, and improve the Service, prevent misuse, and communicate with you about the Service, where these interests are not overridden by your rights.
- Legal obligation. To comply with legal obligations, such as accounting and bookkeeping obligations under Swedish law.
- Consent. Where we rely on your consent, for example for certain optional communications. You may withdraw consent at any time.
6. Cookies
Waffle uses only strictly necessary cookies required to operate the Service. In particular, we use a session cookie named terminal_session to keep you signed in and to maintain your authenticated session. This cookie is essential for the Service to function and cannot be switched off through the Service.
We do not use Google Analytics or other third-party traffic analysis tools, and we do not use cookies for marketing or advertising purposes. Because we use only strictly necessary cookies, no separate cookie consent is required for their use. By using the Service, you accept the use of these necessary cookies.
7. How We Use Waffle AI and Your Data
Waffle includes an integrated AI assistant, Waffle AI. The following describes how AI processing is structured.
Model and infrastructure. Waffle AI uses an Anthropic Claude model accessed through Microsoft Azure AI Foundry. AI inference is performed by this hosted model service on the messages, files, and context that you or your workspace members direct to the assistant.
Training on your content. Your workspace content and the content you send to Waffle AI are not used by us to train or improve any language model. Our use of the model through Microsoft Azure AI Foundry is governed by Microsoft's terms for that service.
Third-party connectors. Where an administrator connects a third-party tool to a workspace (for example, through a Model Context Protocol connector), Waffle AI may send relevant context to, and receive data from, that tool to perform requested actions. Data sent to a connected third-party service is subject to that service's own privacy practices. Third-party and tool output is treated by the assistant as untrusted data, not as instructions.
8. Data Storage, Retention, and International Transfers
We store your personal data only for as long as necessary for the purposes for which it was collected. When data is no longer needed, it is deleted or anonymized, unless legislation requires a longer retention period (for example, accounting records). Content within a workspace is retained for the duration of the workspace and deleted after a reasonable period following termination, subject to any legal retention obligations.
Data is encrypted in transit using industry-standard transport encryption (TLS). Connector credentials are encrypted at rest.
Some of our sub-processors (see Section 9) may process data outside the EU/EEA. Where personal data is transferred to a country outside the EU/EEA, we apply appropriate safeguards in line with GDPR, including the European Commission's Standard Contractual Clauses where applicable.
9. Sub-processors
We engage the following sub-processors to provide the Service. Each is bound by a data processing agreement that meets the requirements of GDPR Article 28 and, where applicable, the Standard Contractual Clauses for international data transfers.
| Sub-processor | Service | Region |
|---|---|---|
| Stripe | Payment processing and billing | EU and US |
| Microsoft Azure AI Foundry (Anthropic Claude) | AI model inference for Waffle AI | EU and US |
| Railway | Application hosting and infrastructure | US |
| Cloudflare | Content delivery, network security, and email routing | Global |
| GitHub | Optional code repository integration for Waffle AI, where the integration is enabled by a workspace administrator | US |
| Resend | Transactional email delivery, such as password reset and email verification | US and EU |
We notify customers of any planned changes to our sub-processor list with reasonable notice before the change takes effect.
10. Disclosure of Your Personal Data
Only authorized personnel, based on their areas of responsibility, have access to personal data. Access is strictly limited to what is necessary to perform relevant tasks.
Your personal data may be shared with:
- Service providers and sub-processors, as listed in Section 9. These parties process the data only to enable us to provide the Service and are bound by confidentiality and data processing agreements.
- Authorities, when legally required or in response to lawful requests.
- Professional advisors, including lawyers, consultants, and insurers, where acting as data processors.
- A successor entity, in connection with a merger, acquisition, or sale of assets, subject to this policy.
We do not disclose your personal data to other third parties without your consent, unless required by law.
11. Your Rights Under GDPR
Under the GDPR, you have the following rights regarding your personal data:
- Right to information: to receive information about how we process your personal data.
- Right of access: to request a copy of the personal data we hold about you.
- Right to rectification: to have inaccurate or incomplete data corrected.
- Right to erasure ("right to be forgotten"): to request deletion of your data in certain circumstances.
- Right to restriction: to request restriction of the processing of your personal data.
- Right to data portability: to receive your personal data in a portable format or have it transferred to another provider.
- Right to object: to object to processing based on our legitimate interests.
- Right to withdraw consent: where processing is based on consent, at any time.
Where we act as a processor within a customer workspace, we will refer requests to the relevant controller (the customer organization) and support that organization in responding.
To exercise any of these rights, contact us at hello@trywaffle.app. You also have the right to lodge a complaint with a supervisory authority. In Sweden, this is the Swedish Authority for Privacy Protection (Integritetsskyddsmyndigheten, IMY).
12. Data Security
We take appropriate technical and organizational measures to protect your personal data, including access management, encryption in transit, encryption of connector credentials at rest, logging, and incident response. Where personal data is transferred to third countries outside the EU/EEA, we apply appropriate safeguards in line with European regulations, including Standard Contractual Clauses where applicable.
We will notify affected customers and, where required, the supervisory authority of a personal data breach in accordance with the GDPR.
13. Contact
If you have questions about this policy or how we handle your personal data, please contact us:
- Email: hello@trywaffle.app
- Company: Friskly AB (organization number 559500-7526)
- VAT number: SE559500752601
- Address: Färögatan 33, 164 51 Kista, Sweden
We reserve the right to update this Privacy Policy as needed. In case of significant changes, we will publish the updated policy and, where appropriate, notify you by email or within the Service. We recommend that you regularly check this page to stay informed about how we protect your data.