SweetHive Privacy Policy
Effective date: 30 July 2026 · This policy replaces all previous versions1. Who is the data controller
The controller of your personal data is Werea S.r.l., via Durando 39, 20158 Milano, Italy ("SweetHive", "we", "us"). For any privacy matter you can contact us at info@wiredenterprise.eu. This policy describes how we process personal data when you use our services, applications, client software and websites (the "Services"), in accordance with Regulation (EU) 2016/679 ("GDPR").
2. What data we collect
- Account and profile data - name, surname, email address, password (stored hashed), preferred language, and any optional profile information you add (photo, phone number, timezone).
- Sign-in with Google - if you register or sign in with Google, we receive your basic Google profile (name, email address, profile picture, Google account identifier). We do not receive your Google password.
- Your content - files, notes, links, tasks, events, messages, emails you share into the platform, and the other material you create or upload ("Your Content").
- Connected services - if you choose to connect third-party services (for example Google Gmail, Calendar or Drive), we access the data those connections cover with read-only scopes, only to show and share it inside the Services as you direct. You can revoke a connection at any time.
- Invitations - when a member invites someone, we process the invitee's email address and name to deliver and manage the invitation.
- Payment data - payments are processed by Stripe; we receive the subscription status and billing metadata but never store full card numbers.
- Usage and technical data - log data such as IP address, browser and device information, pages and features used, and the approximate country derived from your IP, collected for security, auditing and service operation.
- Local storage - we use browser local storage strictly to keep you signed in (session tokens) and to remember interface preferences (for example theme and drafts). We do not use third-party advertising or profiling cookies.
3. Why we process your data and on what legal basis
- To provide the Services (account management, hosting and sharing Your Content, collaboration features, support) - performance of a contract (Art. 6(1)(b) GDPR).
- To operate AI features you invoke (context agents, summaries, drafting, extraction) - performance of a contract. AI features only access content within the scope you or your administrators grant them; see the AI section of our Terms and Conditions for the transparency commitments.
- To secure the Services (authentication, abuse prevention, audit logs, backup) - legitimate interest (Art. 6(1)(f)) in keeping the platform and its users safe.
- To send service communications (verification emails, password resets, invitations, billing notices) - performance of a contract.
- To send marketing communications and perform profiling - only with your separate, optional consent (Art. 6(1)(a)), which you can withdraw at any time from your privacy settings.
- To comply with legal obligations (tax, accounting, lawful requests) - Art. 6(1)(c).
4. Who can see your data inside the platform
Content you share into a hive or context is visible to the other members of that space according to its membership and group rules. Administrators of an organization's hive can manage its membership and may access and moderate content within that hive. Your profile fields are shown to other members according to the visibility you set.
5. Who we share data with
We do not sell your personal data. We share it only with service providers who process it on our behalf under data-processing agreements:
- Amazon Web Services - cloud hosting and storage, EU (Ireland) region;
- Twilio SendGrid - transactional email delivery;
- Stripe - payment processing;
- Google - only when you sign in with Google or connect Google services;
- professional advisers and authorities where the law requires it.
6. International transfers
Your data is hosted in the European Union. Where a provider processes limited data outside the EU/EEA (for example email or payment metadata), the transfer is protected by an adequacy decision or by the European Commission's Standard Contractual Clauses.
7. How long we keep your data
We keep your account data and Your Content for as long as your account exists. If you delete your account, we delete or anonymize your personal data within technical backup cycles, except for data we must keep to comply with legal obligations (for example invoicing records) or to establish, exercise or defend legal claims. Security and audit logs are kept for a limited period proportionate to their purpose.
8. Your rights
Under Articles 15-21 GDPR you have the right to access, rectify, erase, and receive a portable copy of your personal data, to restrict or object to its processing, and to withdraw any consent at any time without affecting prior processing. To exercise your rights, contact info@wiredenterprise.eu; we will respond within the timeframes the GDPR sets. You also have the right to lodge a complaint with your supervisory authority - in Italy, the Garante per la protezione dei dati personali (garanteprivacy.it).
9. Security
We protect your data with technical and organizational measures appropriate to the risk, including encryption in transit, hashed credentials, scoped access tokens for agents and integrations, role-based access controls, segregated environments, and audit logging.
10. Children
The Services are not intended for children under 16, and we do not knowingly collect personal data from them. Where the law of your country allows use below that age with parental consent, that consent must be verifiable.
11. Changes to this policy
We may update this policy from time to time and will always post the current version in the app and on our website. If a change meaningfully affects your rights, we will notify you in advance at the email address associated with your account. Each version is identified by its effective date and recorded in our consent register.