Verified Wavize guide

Privacy, cookies and GDPR

Configure Wavize according to your policy and process data requests.

Updated 7 August 2026

Wavize processes conversations, contacts and technical data to deliver service

Website owner must define legal basis, visitor information, retention periods and authorized people. Wavize settings help display notice and limit collection, but do not replace the organization’s legal analysis.

Widget may receive message, viewed page, technical data and explicitly supplied contact details. Commerce integrations check orders and catalogue; marketing integrations may transfer contacts according to selected mode.

Scope of this guide
It describes product controls and good practices, not legal advice tailored to every country or activity.

Map actual data use

Start from your configuration, not a generic template.

  • Conversation

    Questions, replies, timestamp, session and page context needed for service and analysis.

  • Contact

    Name, email, phone and need when form or detection is enabled. Document whether a person will be contacted or added to a tool.

  • Commerce and marketing

    Reference and email for order verification; profile and consent for Klaviyo/Mailchimp. Do not automatically reuse support data for advertising.

Configure notice and minimization

Under Behaviour, enter clear notice and HTTP/HTTPS policy URL.

  1. Purpose before collection

    Explain why email or phone is requested, who will reply and whether marketing transfer is optional.

  2. Minimum fields

    Disable unused fields or mechanisms. “Just in case” collection increases risk and obligations without improving service.

  3. Organization-owned link

    Policy should be public, current and mobile accessible. Do not link to a generic page omitting chatbot or recipients.

Coordinate cookies and widget loading

Depending on analysis, code may need to wait for a consent category.

  1. Consent manager

    Place script in decided category and test Accepted, Rejected and Changed. Widget must not bypass choice after reload.

  2. Proactive campaigns

    If widget is not loaded before consent, campaign cannot display or count. Document this effect in impression analysis.

  3. Extensions and storage

    Test without blockers then with common protections. Do not claim visitor consent merely because a script loaded.

Manage access, export, deletion and incident

Define a verifiable process before receiving a request.

  • Identity check

    Reasonably verify requester without collecting more data than needed. Do not disclose a conversation from a guessed reference.

  • Team access

    Use individual accounts, least privilege and immediate deactivation on departure. Also review integration keys and recipients.

  • Coordinated deletion

    Data synced to Klaviyo, Mailchimp or another tool must be handled in each system according to your process, not only in Wavize.

  • Incident

    Immediately revoke exposed keys, preserve useful evidence and apply notification process. Do not copy compromised secret into ticket.


Functional compliance review

Repeat after adding a form, integration or new language.

  • Accurate notice — It describes actually active uses.
  • Minimum collection — No unnecessary field or transfer.
  • Request tested — Access and deletion are executable within internal timelines.