Privacy Policy
How we collect, use and protect personal data — and what we deliberately cannot see.
Last updated: 12 August 2026
1. Who We Are
This Privacy Policy describes how WaveFront LLC-FZ, a free-zone company with its address at The Meydan Grandstand, 6th floor, Meydan Road, Nad Al Sheba, Dubai, United Arab Emirates ("WaveFront", "we", "us"), collects, uses and protects personal data in connection with the website wave-front.net (the "Website") and our products and services (Secure Vault, Hardened Devices, Multisig Wallet, and professional security services).
WaveFront is the data controller for the processing described in this Policy. We process personal data in accordance with UAE Federal Decree-Law No. 45 of 2021 on the Protection of Personal Data (PDPL) and other applicable data-protection laws.
Contact for privacy matters: support@wave-front.net
2. Our Zero-Knowledge Design — What We Cannot See
Our products are intentionally designed so that we hold as little of your data as possible:
- Content you store in Secure Vault is encrypted on your device before it reaches our servers. We store only ciphertext and do not hold the keys. We cannot read, decrypt or recover it.
- Private keys and seed phrases for cryptocurrency wallets are generated and kept on your own hardware devices. They are never transmitted to us and we never ask for them.
- Accounts passwords are never stored in plain text; we store only cryptographic hashes.
- We do not perform identity verification (KYC) and do not collect government-issued identity documents.
3. Personal Data We Collect
3.1 Website visitors
- Contact form: name, email address, subject and message text that you choose to submit. The form is processed by a third-party form-delivery provider (FormSubmit) that transmits your message to our support mailbox.
- Technical data: our hosting infrastructure keeps standard web server logs (IP address, request time, requested page, browser user-agent) for security and troubleshooting.
- The Website does not use analytics services, advertising trackers or marketing cookies.
3.2 Customers and users of our products
- Account data: a user identifier used as your login name, display name or initials, preferred language, and account settings.
- Authentication data: password hashes, two-factor authentication (TOTP) secrets, session tokens, and login attempt records used for abuse prevention.
- Device data: identifiers of the devices you register (workstation hardware identifiers and hardware-wallet public identifiers) used to authorize access.
- Wallet metadata: public wallet data required for the service to function — public keys, public addresses, wallet settings, transaction metadata and wallet current state. This data is public-key material and does not enable us to spend your assets.
- Encrypted payloads: ciphertext packages you upload (see Section 2), including, where you use inheritance features, an encrypted copy intended for your designated heir.
- Service records: audit logs of security-relevant actions (logins, wallet operations, confirmations), support correspondence, and check-in/reminder status where you enable inheritance or emergency-access features.
- Billing data: information needed to invoice you under a service agreement.
3.3 Heirs and other participants
If you designate an heir or invite other participants to a shared wallet, we process the identifiers needed to deliver the service to them (for example, their contact information and wallet addresses). If you provide us personal data of another person, you confirm that you are entitled to do so.
4. Purposes and Legal Bases
We process personal data to:
- respond to inquiries you send us (performance of pre-contractual steps at your request);
- create and administer accounts, authenticate users and devices, and provide the contracted services (performance of a contract);
- operate security controls: two-factor authentication, audit logging, fraud and abuse prevention (legitimate interest in securing the services; compliance with legal obligations);
- execute inheritance and emergency-access mechanisms you have configured (performance of a contract);
- notify you of service events, security notices and material changes to terms (performance of a contract; legal obligation);
- invoice and account for services (legal obligation);
- establish, exercise or defend legal claims (legitimate interest).
We do not sell personal data and do not use it for third-party advertising or profiling.
5. Blockchain Data — Public by Design
Cryptocurrency transactions are recorded on public blockchains (for example, Bitcoin and Tron). Wallet addresses and transactions broadcast through our services become part of a public, permanent, decentralized ledger that WaveFront does not control and cannot alter or erase. Rights such as erasure or rectification cannot be applied to data recorded on public blockchains.
6. Recipients and Processors
We share personal data only with:
- the form-delivery provider processing Website contact-form submissions (FormSubmit);
- the Telegram messaging platform, when you interact with our bots or receive service notifications via Telegram (Telegram's own privacy policy applies to your use of Telegram);
- professional advisers (legal, accounting) under confidentiality obligations, where necessary;
- public authorities, where disclosure is required by applicable law or a binding order.
Note that even where infrastructure providers store or transmit our data, vault contents remain encrypted with keys only you hold.
7. International Transfers
Our infrastructure providers may store or process data outside the UAE. Where personal data is transferred internationally, we rely on the safeguards permitted by the PDPL, including transfers to jurisdictions with adequate protection or subject to appropriate contractual safeguards.
8. Retention
- Contact-form inquiries: retained as long as needed to handle the inquiry and for a reasonable follow-up period.
- Account, authentication and device data: retained for the life of the account and deleted or anonymized within a reasonable period after account closure, except where longer retention is required by law.
- Audit logs: retained for the period necessary for security monitoring and legal compliance.
- Encrypted payloads: retained while your account is active or until you delete them; deleted after account closure except where an inheritance process you configured is pending.
- Web server logs: retained for a short rolling period for security and troubleshooting.
9. Security
We apply technical and organizational measures appropriate to the risk, including: client-side end-to-end encryption for stored content (AES-256-GCM with Argon2 key derivation), TLS encryption for all transmissions, certificate pinning in our client applications, mutual TLS between internal systems, hashed credentials, two-factor authentication, device authorization, rate limiting, audit logging, and the principle of least privilege for administrative access.
No system is completely secure. If a personal data breach occurs that is likely to result in a risk to your rights, we will notify the competent authority and affected users as required by law.
10. Your Rights
Subject to applicable law, you have the right to:
- access the personal data we hold about you and receive information about its processing;
- request correction of inaccurate data;
- request erasure of your data, subject to legal retention requirements and the blockchain limitation in Section 5;
- object to or request restriction of certain processing;
- receive data you provided in a portable format;
- withdraw consent, where processing is based on consent, without affecting prior processing;
- lodge a complaint with the UAE Data Office or other competent supervisory authority.
To exercise these rights, contact support@wave-front.net. We may need to verify your identity before acting on a request. Note that we cannot access, produce or erase the contents of client-side encrypted data (Section 2) — such data can only be decrypted or destroyed by the holder of the keys.
11. Children
Our Website and services are not directed at children under 18, and we do not knowingly collect their personal data.
12. Changes to This Policy
We may update this Policy from time to time. The current version, with its "Last updated" date, is published on the Website. Material changes will be notified to active customers where practicable.
13. Contact
WaveFront LLC-FZ
The Meydan Grandstand, 6th floor, Meydan Road,
Nad Al Sheba, Dubai, UAE
Email: support@wave-front.net
Phone: +971 (54) 586-0341