General Terms
This consolidated version covers the General Terms, the Data Processing Agreement and security measures. The specific terms of the Service ordered also apply: VMware Cloud, colocation including the data centre access procedure, dedicated servers, web hosting and domain services.
By using the services provided by WaveCom AS (registry code 10756058), you agree to the following terms and conditions (the “Terms”):
Contents · 14 sections
1. General provisions
The service provider is WaveCom AS (commercial registry code 10756058, address Endla 16, Tallinn) (“WaveCom”).
The current Terms are available on WaveCom's website at www.wavecom.ee (the “Website”).
Services means all services provided by WaveCom, such as cloud services, colocation, dedicated servers, cloud servers and web hosting (the “Service” or “Services”). The Customer can order, modify and terminate Services in the self-service portal on the Website (the “Customer Portal”). Service prices are set out in the price list published in the Customer Portal (the “Price List”).
Each Service has separate service-specific terms setting out the details of service provision, responsibilities, including information security, and the service level.
The Customer is the natural person who has ordered the Service in their own name or the legal person on whose behalf the Service has been ordered (the “Customer”).
Customer service available through the Customer Portal operates Monday to Friday from 09:00 to 21:00, and on Saturdays, Sundays and public holidays from 12:00 to 17:00. The customer support telephone +372 6850 000 is answered Monday to Friday from 09:00 to 17:00.
The Services must not be used in breach of the Terms, the law or good morals.
The Terms also include any technical and supplementary terms that WaveCom may establish for the use of a Service (the “Service Terms”), which are generally shown to the Customer before the Service is ordered. By ordering and using the Service, the Customer also agrees to such Service Terms.
WaveCom sends invoices to the Customer's email address or to the electronic invoicing channel selected in the Customer Portal. Business customers can choose to have electronic invoices sent directly to their accounting or enterprise resource planning (ERP) software. Invoices are also available in the Customer Portal. WaveCom sends service and contractual notices by email or by a Customer Portal notification addressed to the Customer's account, unless the law or the Service Terms require another method. The Customer keeps contact and electronic invoicing details up to date, ensures that the selected channel works and monitors Customer Portal notifications. An email is presumed to have been received no later than the second working day after it was sent. WaveCom retains the content, addressee and sending time of Customer Portal notifications. Notices of changes to subprocessors are governed by clause 12.10.
The Estonian version of the Terms, including the Service Terms and annexes, is legally binding. Translations into other languages are provided to help the Customer understand the Terms; they are reviewed for linguistic accuracy and consistency with the Estonian text. In the event of discrepancies or disputes over interpretation, the Estonian text prevails. This does not limit any Customer rights that cannot be excluded or restricted by contract under applicable law. The current Estonian Terms are available on the Website.
WaveCom may refuse to provide Services if the person wishing to order a Service has breached the terms of use of services provided by WaveCom or third parties (including payment obligations), breached good internet usage practices, or for another compelling reason for WaveCom. WaveCom is not obliged to explain or substantiate the grounds for refusal.
The Customer may withdraw from an order for a Service placed through the Website within fourteen (14) calendar days of the date on which the Service was activated, by terminating the Service in the Customer Portal. If, when terminating the Service, the Customer requests a refund for the unused portion of the Service (the amount paid less the charge for the days on which the Service was used), this will be refunded without delay and no later than 14 days after WaveCom receives the withdrawal notice. A fully performed domain registration or renewal operation is subject to the exception to withdrawal and refunds set out in section 7 of the Domain Service Terms. The expiry of a consumer's statutory right of withdrawal requires their prior express request and acknowledgement.
WaveCom may cease providing Services for compelling reasons by giving 30 days' notice.
2. Customer representations
By using the Service, the Customer makes the following representations. WaveCom may rely on them until the Customer notifies WaveCom of any change.
The Customer has carefully read the Terms, understands them and is aware of their rights and obligations.
The Customer has legal capacity and active legal capacity, no bankruptcy proceedings have been initiated against them and no bankruptcy caution has been issued to them, and, in the case of a Customer that is a legal person, no decision has been made to dissolve it.
The information provided by the Customer is correct. The Customer understands that both WaveCom and other persons may rely on it. Providing false information may result in sanctions and claims for damages against both the Customer and WaveCom.
All consents and authorisations required to use the Services in accordance with the Terms have been obtained, and such use does not cause the Customer to breach any obligation arising from legislation, an administrative act, a court judgment or any legal relationship. The Customer has the resources and skills necessary to fulfil their obligations to WaveCom.
The Customer notifies WaveCom immediately if any representation ceases to be true.
3. WaveCom's rights and obligations
WaveCom provides the Services within its certified management systems, following ISO 9001:2015, ISO 14001:2015, ISO/IEC 27001:2022, ISO/IEC 27017:2015 and ISO 22301:2019, as well as relevant industry good practices. The certified scope covers all Services provided by WaveCom and all locations at which the Services are provided. The certificates demonstrate conformity of the management systems and do not constitute a promise that any Service is entirely uninterrupted or risk-free.
WaveCom provides the Customer with continuous access to the Services. The operation of the Services also depends on other parties, such as internet networks and electricity suppliers. WaveCom cannot guarantee uninterrupted operation outside its area of responsibility.
WaveCom remedies faults within its area of responsibility that prevent use of the Service, at its own expense and within the time specified in the Terms.
WaveCom publishes anticipated, current and past Service outages and disruptions on the Website (https://clients.wavecom.ee/status) and/or provides this information by email at the Customer's request. WaveCom endeavours to give notice of anticipated Service interruptions and disruptions within its control (such as maintenance) as early as possible, at least 5 days in advance.
WaveCom may suspend provision of a Service or restrict its use if the Customer breaches the Terms, including where an invoice is at least 5 days overdue. WaveCom gives at least 5 days' notice of suspension or restriction, unless the circumstances of the breach justify immediate suspension or restriction (see also the Acceptable Use Policy (AUP) below).
WaveCom may suspend a Service if there is reason to believe that it is under attack or otherwise interferes with the provision of services to other customers, even if the Customer is not at fault.
WaveCom may change the principles governing use of the Service, its technology and its software in order to develop the Service. Reasons for a change may include changes in the law, technological developments or security. If a change may materially affect use of the Service, WaveCom notifies the Customer at least 30 calendar days in advance.
WaveCom monitors its data centres, networks and systems in real time, around the clock, using redundant monitoring solutions and automatic notifications through various channels, including automated calls. System operation, administrative activities and security events are logged centrally. Security information and event correlation and analysis (SIEM), extended detection and response (XDR), behavioural analysis and machine learning methods are used to detect threats and anomalies as appropriate to the system and Service. Network flows are analysed to detect and counter cyberattacks. Response to a detected threat and implementation of appropriate protective and mitigation measures begin immediately, including through automation.
Monitoring also covers possible misuse or compromise of customer services, including spam, cyberattacks, third-party complaints and other issues. Services are monitored to the extent necessary to ensure proper operation, remedy faults or threats and ensure compliance with the Terms, using methods consistent with the law.
WaveCom may grant Estonian law enforcement authorities access to its equipment upon their lawful request and to the relevant extent, to enable monitoring of Service use or the obtaining of related data.
4. Customer rights and obligations
The Customer may use the Services according to their needs, in compliance with the Terms, the law and good practices.
The Customer must not use the Services in a manner that disrupts the operation of communications networks, technical systems or servers.
The Customer reports a defect or fault in the Service by a support ticket in the Customer Portal, by email or by calling customer service.
The Customer is responsible for the security of their data and user accounts in accordance with the allocation of responsibilities for the Service ordered. This includes software updates and backups within their area of responsibility. The Customer must not disclose information enabling use of their Services (such as usernames and passwords) to other persons; a Customer that is a legal person ensures that persons using the Services on its behalf do not disclose such information to unauthorised persons. The Customer is responsible for all actions performed using their username and password.
The Customer is strongly advised to enable multifactor authentication or another supported form of strong authentication in the Customer Portal and, where possible, disable password-only login. Supported methods in the Customer Portal include an authenticator app, SMS, the Estonian ID card and Smart-ID. The Customer selects a suitable method and keeps authentication and recovery methods up to date. These recommendations do not impose a mandatory MFA requirement on all Customers.
The Customer updates their contact person's details in the Customer Portal when they change.
The Customer uses the Service within the technical limits ordered. If these are insufficient, the Customer orders a suitable Service or additional resources. Exceeding the limits incurs the additional charge specified in the Price List.
The Customer also pays the monthly fee for periods during which provision of the Service was restricted or suspended due to circumstances arising from the Customer's actions.
The Customer may obtain from WaveCom, to a reasonable extent, copies of valid certificates relevant to the Services. Relevant audit reports may also be disclosed to the Customer's independent auditor under a confidentiality obligation, to the extent that this does not compromise the security or confidentiality of WaveCom, other customers or third parties.
WaveCom may perform a low-risk operation on the basis of a verified support ticket from the Customer or their authorised representative, or an email sent from the registered contact address. Before a higher-risk operation, such as disclosure of data, a change involving a risk of data loss or a change to access rights, WaveCom additionally verifies the requester's identity and authority and obtains clear confirmation of what is to be done. The risk of data loss is explained before confirmation. If the necessary verification or confirmation is missing, the operation is not performed.
5. Prices and payment
The Customer pays for the Services in accordance with the current Price List. The Price List is available on the Website.
WaveCom invoices according to the billing period ordered. The period begins when the Service is activated in the Customer Portal, regardless of whether the Customer actually uses it. If an invoice does not arrive on time or contains an error, the Customer notifies WaveCom immediately.
The Customer pays for the Service until it ends. If a Service subject to a periodic fee is terminated before the end of the billing period, the full period must be paid for and the unused portion is not refunded. The refund rules in clauses 1.11 and 6.1 apply to withdrawal and termination due to changes to the Terms.
The Customer pays the invoice by the deadline specified in the Service Terms. If no deadline is specified there, the deadline on the invoice applies and must be at least 14 days.
WaveCom may change the Price List by giving the Customer at least 30 days' notice. If the Customer continues to use the Service after the change takes effect, they are deemed to have accepted it.
6. Changes to the Terms
WaveCom may change the content and prices of the Services and the Terms by notifying the Customer in a format that can be reproduced in writing at least 30 calendar days in advance. If the Customer continues to use the Services after the date stated in the notice, they are deemed to have accepted the changes, unless applicable law or clause 12.19 requires separate confirmation. The changes are also published on the Website before taking effect. The addition or replacement of a subprocessor within the general authorisation under the existing DPA follows clause 12.10 and does not require the 30-day notice period in this clause merely because the register has changed. If the Customer does not agree with changes to the Terms, they may terminate the Service in the Customer Portal before the changes take effect. WaveCom will refund prepayments for the unused period.
If the Customer does not agree to changes to the Terms, they may discontinue use of the Services by submitting termination through the Customer Portal; WaveCom refunds prepayments for the unused period.
WaveCom may add, update or replace software, hardware and other technical components to develop the Service. Not every such change requires separate Customer consent or notice. A change must remain within the agreed purpose and scope of the Service and data processing and must not materially reduce the level of data protection. Clauses 3.7 and 6.1 govern notification of changes that materially affect use of the Service. Clause 12.10 applies when engaging a new subprocessor.
7. Suspension and termination of Services
WaveCom may suspend a Service or the Services or refuse to continue providing Services if the Customer has materially or repeatedly breached the Terms.
Access to data may end when the Service is suspended or terminated. Before the Service ends, the Customer downloads the necessary data or instructs WaveCom to return it. On termination, WaveCom deletes data in accordance with the specific Service Terms and clause 12.15; data may no longer be recoverable after deletion. Section 9 of the VMware Cloud specific terms applies when switching that Service. Closure of the Service does not end the availability of the download copy provided for there.
In the Customer Portal, the Customer can choose to terminate the Service immediately or at the end of the billing period. A warning concerning the data is displayed before termination is confirmed.
8. Liability
The Services are provided in accordance with the description of the Service ordered, the Service Terms and the Price List. WaveCom does not guarantee suitability of the Service for a particular purpose of the Customer that has not been agreed in writing. Within the scope of its certified management systems, WaveCom applies the relevant processes and controls arising from ISO 9001:2015, ISO 14001:2015, ISO/IEC 27001:2022, ISO/IEC 27017:2015 and ISO 22301:2019.
WaveCom is not liable for Service outages caused by the Customer's breach of the Terms.
WaveCom does not guarantee that the Services will be error-free or uninterrupted. Although WaveCom makes every effort to provide the Services as continuously and free of errors as possible, WaveCom is not liable for any losses the Customer may incur as a result of outages or errors. This does not exclude compensation provided for in the specific Service Terms or liability arising by law.
WaveCom is liable only for direct pecuniary loss caused to the Customer by WaveCom's intentional or grossly negligent breach of its obligations. Among other things, WaveCom is not liable for claims and losses arising from the Customer's insufficient measures and practices, attacks originating from the internet or interception of network traffic. WaveCom's maximum liability in providing the Services shall in no event exceed one (1) month's fee for the relevant Service. These limitations do not exclude or limit liability to the extent that exclusion or limitation is prohibited by law, including data subject rights under the GDPR.
The parties endeavour to resolve disputes relating to the Service by agreement. If no agreement is reached, the dispute is resolved by Harju County Court.
The Customer reimburses WaveCom for debt collection costs, including the costs of reminders, legal assistance and collection services.
9. Confidentiality and data protection
WaveCom and the Customer keep confidential information received from each other secret, regardless of its form. This includes information marked confidential, information reasonably expected to be confidential, personal data and special categories of personal data. Information is used only to perform obligations relating to the contract and on a lawful basis. WaveCom's confidentiality obligation is indefinite and continues after the end of the Service, contract or cooperation. WaveCom ensures that the same obligation continues for its employees and contracted data processors. This does not mean indefinite retention of data: data is deleted in accordance with the retention rules. Information may be disclosed with the Customer's documented permission or as required by law, only to the extent permitted or required.
WaveCom may provide information and documents concerning the Customer's debts to credit registers.
With the Customer's additional consent, WaveCom may use the fact that it provides Services to the Customer to advertise its activities.
10. Processing of personal data by WaveCom as controller
WaveCom itself determines the purposes and essential means of processing the customer relationship data described in this section. This primarily includes data relating to the Customer Portal, the service management and billing system, orders, payments, sales, customer support, notifications, security and compliance with requirements. Processing of data in the Customer's Service environment is governed by section 12 and the specific Service Terms.
As controller, WaveCom may process the names, contact details, information about authority to represent, account and authentication data, order and service configuration data, billing and payment data, communications and customer support requests, Customer Portal usage and security logs, IP addresses and marketing preferences of the Customer, their representatives and users.
The purposes of processing are preparing and performing the contract, managing the customer relationship and Services, billing, customer support, sending service and security notices, preventing fraud and misuse, establishing or defending claims, complying with accounting and other statutory obligations, and developing the Services. Depending on the operation, the legal basis is performance of a contract or taking pre-contractual steps, WaveCom's legitimate interests, compliance with a legal obligation or consent. Data concerning a legal person's contact person is generally processed on the basis of WaveCom's legitimate interest in managing the customer relationship, taking the contact person's rights into account.
Direct marketing is sent on the basis of consent or another basis permitted by law. Consent may be withdrawn at any time in the Customer Portal or through the opt-out option in the message. Withdrawal of consent does not affect the lawfulness of prior processing.
WaveCom discloses personal data only to the extent necessary to its contracted service providers, payment and communications partners, auditors and advisers, registers, competent authorities or another person where there is a legal basis for disclosure. When a domain name, certificate or other third-party service is ordered, the necessary information may be transmitted to the relevant service provider.
WaveCom uses processors in its customer relationship systems only under an appropriate agreement and with sufficient security safeguards. A software vendor is not WaveCom's processor merely because its licence is used; it is treated as a processor for the specific operations in which it can process personal data on WaveCom's behalf. The vendor of the Customer Portal and service management and billing software is HostBill Krzysztof Pająk (Poland, Szkolna 30A/2, 35-301 Rzeszów; VAT number PL8133336364). Any access by HostBill vendor support is limited to the necessary Customer Portal and service management and billing system data and takes place as part of a time-limited support operation controlled by WaveCom, under a valid data processing agreement. This does not give the vendor access to the content of the Customer's virtual machines. Processing and access by vendor support must comply with the EU restriction in clause 10.7.
Hosting and backup of the personal data referred to in this section, and processing through service providers selected by WaveCom, take place exclusively in the European Union (EU). WaveCom does not transfer this personal data to its service providers outside the EU or allow service providers remote access to it from outside the EU. WaveCom uses its own infrastructure and, where necessary, engages only processors established in the EU whose relevant processing and support activities, including those of their subprocessors, take place in the EU. Where external cloud infrastructure is used, only providers established in and managed from the EU are suitable; infrastructure of global public cloud platforms managed from outside the EU is not used, even in their EU regions. Compliance is checked before engaging a partner or introducing a service. A limited exception for technical information used in VMware Cloud vendor support is set out in clause 12.17.1. This exception does not extend to Customer Portal or service management and billing system data. As an exception to the above location, establishment and management requirements, WaveCom may transmit registration and contact data necessary to register and manage a domain to the relevant registry, registrar or registration intermediary and allow that data to be processed outside the EU. Before transfer, WaveCom checks the actual processing chain, the parties' roles, agreements and security measures, and ensures a transfer basis and the required safeguards under Chapter V of the GDPR. Information about the actual registrar, recipients, processing countries and data protection terms is made available to the Customer before ordering in the Domain Service Terms and the privacy information referenced there. The exception covers only data necessary to register and manage the selected domain. It does not authorise transfer outside the EU of the entire Customer Portal or billing system database, support tickets or hosted content, or general remote access to them. The EU hosting and backup requirement for these systems and any stricter restrictions separately agreed with the Customer remain in place.
WaveCom retains data only for as long as necessary for the purpose. Accounting source documents are retained for the statutory period, generally seven years. Retention periods for customer support records, security and usage logs and other customer relationship information are determined on the basis of the purpose, contractual requirements, potential legal claims and WaveCom's internal retention rules. Support information marked as sensitive in the Customer Portal is encrypted and removed from the active support ticket when it is closed. Backups are subject to their separate retention rules. Evidence of acceptance of the contract and DPA, and necessary case-handling data, are retained separately.
Subject to the conditions laid down by law, data subjects may access their data, request its rectification or erasure, restrict processing, object, withdraw consent and receive data in a portable format. They can view and download their data in the Customer Portal. Requests to exercise other rights can be sent to privacy@wavecom.ee. Data subjects may lodge a complaint with the Estonian Data Protection Inspectorate. Submitting a request does not require a new DPA or access to the support ticket form. WaveCom responds within the period specified in the GDPR, generally one month; the requester is informed of any extension permitted by law and the reasons for it.
WaveCom implements technical and organisational measures appropriate to the risk to protect personal data and maintains documented incident management. Personal data breaches are notified to the competent supervisory authority and the data subject in the cases and within the time limits specified in the GDPR.
WaveCom and the Customer may have different roles in different processing operations. WaveCom is the controller of the customer relationship data described in this section and generally acts as the Customer's processor for personal data in the Customer's Service environment, in accordance with section 12 and the applicable specific Service Terms.
In the Customer Portal, the Customer can view the account, service and billing data available to them, download their data and submit an erasure request. WaveCom deletes data for which there is no further legal basis for retention; where retention is required by law or a legitimate need to defend a claim, WaveCom explains the restriction. WaveCom uses cookies necessary to provide the Service; the terms and choices for other cookies are presented in the cookie information on the Website.
To manage data centre access and ensure security, WaveCom processes identity and authorisation data, access logs, CCTV recordings and background check data to the extent necessary. Access control and CCTV necessary to protect people, property and critical data are based on a documented legitimate interest. Criminal record data is processed only to the extent permitted by law. Biometric identification is based on separate, explicit and revocable consent; an authorised representative has a free, round-the-clock non-biometric access option. Further terms are set out in the data centre access procedure and the background check notice and biometric consent form.
11. Acceptable Use Policy
The Acceptable Use Policy (the “AUP”) helps ensure compliance with the law, network security and availability, customer privacy and the operation of the Services.
Any breach of the AUP constitutes a material breach of the Terms, entitling WaveCom to suspend the Services temporarily or terminate them permanently.
The Services and WaveCom's infrastructure must not be used contrary to the law, good morals or the AUP. Prohibited activities include those described in the following clauses.
WaveCom applies zero tolerance to spam / email marketing. Spam means messages sent to recipients who have not requested or asked to receive them. An exception applies to a legal person's general email address associated with that legal person's domain.
In addition, bulk messages must not be sent to addresses registered with free service providers (such as Gmail, Hotmail and others), even if such an address is listed as an official email address in the commercial register.
Bulk messages with falsified email headers and/or false contact information are prohibited.
Unsolicited bulk messages. Sending unsolicited bulk messages is treated as sending spam. All messages sent to natural persons who have not specifically confirmed that they wish to receive messages from the sender are considered unsolicited. Senders of bulk messages must keep complete and accurate records of all natural persons who have subscribed to their emails.
All evidence that a natural person has subscribed must be retained (including relevant email messages and their headers) and provided at WaveCom's request. If the Customer cannot provide evidence, the recipient's complaint is treated as evidence that they did not subscribe and that the message was therefore unsolicited.
The bulk messaging rules also apply to mailing lists and newsletters. Mailing lists and newsletters are permitted where they target a specific audience that has joined voluntarily or made its email addresses available to the Customer for information sharing. A mailing list or newsletter must provide automatic unsubscription and guarantee that no further messages are sent to that email address.
Unsolicited bulk messaging through another provider that in any way creates the impression that WaveCom is involved is also prohibited, regardless of whether the message originated from WaveCom's network.
Hacking or exploiting any security vulnerability is prohibited. This includes unauthorised access to any server or system, including intrusion into or scanning of accounts belonging to other WaveCom customers or WaveCom itself.
Using WaveCom's Services to store, post, display, transmit or otherwise make child sexual abuse material available is strictly prohibited. If WaveCom becomes aware that its network is being used to store or transmit such material, the police are notified immediately.
Infringement of intellectual property, including copyright, trademarks and patents, is prohibited, as is storing, using or distributing pirated software or using third-party software without the required licence or consent.
Network attacks or any other attempt to disrupt a service or server on another network are prohibited.
Distribution of viruses, malware or otherwise harmful code is prohibited.
If the Customer's use of the Service involves a DoS or DDoS attack that disrupts other customers or obstructs their Services, WaveCom may impose the necessary restrictions on the Service.
If the Customer's breach of the AUP causes WaveCom's mail servers or IP ranges to be included on a blacklist or in other email filtering software used by businesses on the internet, a one-off fee of €50 is added to the Customer's invoice for the estimated working time required to remove the mail servers and IP ranges from blacklists and protect them.
WaveCom permits adult content on its servers where it complies with the laws of the Republic of Estonia and does not otherwise breach the AUP.
When reselling a Service, the Customer remains responsible to WaveCom. The Customer ensures that their customers know and comply with the AUP.
WaveCom does not refund the Service fee if the Service was suspended or terminated due to the Customer's breach of the AUP.
The Customer is responsible for compliant use of the Service within their software and hardware infrastructure, even where it is used by unauthorised persons or hackers.
If the Customer has information about a third party's breach of the AUP, they should notify WaveCom by emailing abuse@wavecom.ee.
If the Customer notices infringement of their intellectual property, including copyright, trademarks or patents, on WaveCom's infrastructure, they should contact the infringer and request immediate removal of the content. If the infringer refuses to remedy the infringement or does not respond within a reasonable time, WaveCom should be notified at abuse@wavecom.ee.
The email must include information about attempts to contact the infringer and their results, and about the infringing material hosted on WaveCom's infrastructure (the name of the material and the domain or IP address where it is located). It must also include official evidence that the intellectual property rights concerned belong to the Customer.
Addressing terrorist content
The Services must not be used to disseminate terrorist content within the meaning of Regulation (EU) 2021/784 (the TCO Regulation). Content is assessed in context, taking account of freedom of expression and the exceptions for educational, journalistic, artistic and scientific material and information that raises awareness of terrorism.
Notices are assessed by an authorised employee. WaveCom does not use automated detection of terrorist content. Where necessary, content is removed or access to it is restricted, with preference given to a measure targeted as precisely as possible; the Service may be suspended temporarily if necessary. A removal order under the TCO Regulation is implemented in all EU Member States as quickly as possible and no later than one hour after receipt, subject to the exceptions in the Regulation. Prior Customer consent is not required.
WaveCom notifies the content provider concerned of removal or blocking without undue delay, unless disclosure is prohibited by the competent authority. On request, information about the reasons and available remedies, or a copy of the removal order, is provided in accordance with the Regulation.
Content removed or blocked under Articles 3 and 5 of the TCO Regulation and the necessary related data are securely retained for six months, or longer where necessary on a basis provided for in the Regulation. Access and use are limited to purposes permitted by the Regulation. Routine deletion of backups, termination of the Service or closure of a support ticket does not end the retention obligation.
The TCO contact for authorities is tco@wavecom.ee; the languages of communication are Estonian and English. Other notices and complaints about WaveCom's own removal or blocking decisions may be submitted free of charge to abuse@wavecom.ee, identifying the content concerned, the grounds for the complaint and contact details. A Customer Portal account is not required. A reasoned response is provided within two weeks; an unjustified restriction is lifted immediately. Challenges to an authority's order follow the procedures in Articles 4 and 9 of the TCO Regulation, and a complaint to WaveCom does not suspend compliance with a valid order.
The special procedure under the TCO Regulation applies within its scope. A removal order or temporary restriction does not in itself prove that the Customer breached the AUP. Statutory remedies remain available; the specific provisions of this section are also taken into account when applying clauses 11.2 and 11.18.
12. Processing of the Customer's personal data as processor
This section, together with the applicable specific Service Terms and annexes, constitutes the data processing agreement (DPA) between WaveCom and the Customer under Article 28 of the GDPR. The DPA is an integral part of the Terms and is concluded in written electronic form when the Service is ordered or the Terms are accepted in the Customer Portal. WaveCom retains evidence of the identity of the person accepting, the time of acceptance and the applicable version. Acceptance of a valid DPA does not need to be repeated when creating each ordinary support ticket.
The DPA applies to the extent that WaveCom processes personal data in the Customer's Service environment on the Customer's behalf. The Customer is a controller or a processor acting for another controller, and WaveCom is accordingly a processor or subprocessor. WaveCom remains a separate controller for the customer relationship, billing, security and legal compliance data described in section 10.
The subject matter, nature, purpose and duration of processing, types of personal data, categories of data subjects, retention periods, data location and use of subprocessors follow from the applicable service description, specific Service Terms, Annex B and the Customer's order. The service order, selected configuration and Customer actions in the management interface constitute documented instructions within the agreed scope. A more specific description of service data processing takes precedence over the general description.
WaveCom processes personal data only on the Customer's documented instructions and to the extent necessary to provide, secure, back up and restore the Service, provide support, terminate the Service and delete data. If EU or Member State law requires other processing, WaveCom notifies the Customer before processing, unless notification is prohibited on important grounds of public interest.
If WaveCom considers that a Customer instruction infringes the GDPR or other applicable data protection law, WaveCom notifies the Customer immediately and may suspend execution of the instruction until it is amended or its lawfulness is confirmed.
The Customer is responsible for the lawfulness, transparency, minimisation and accuracy of personal data processing and ensures the necessary legal bases, notices, consents and instructions. The Customer assesses the suitability of the Service for their risks, configures the operating systems, applications, users, access, encryption and backup policy within their area of responsibility, and does not provide WaveCom with data they are not entitled to process.
WaveCom ensures that persons processing personal data are bound by confidentiality obligations, have access only to the extent necessary for their duties, and comply with WaveCom's security and data protection procedures. Access rights are role-based, assigned to individuals, reviewed periodically and removed when employment or the need for access ends. The confidentiality obligation applies indefinitely, including after employment, cooperation or access rights end.
WaveCom implements risk-appropriate technical and organisational measures under Article 32 of the GDPR, as described in Annex A. WaveCom may update the measures and their technical implementation as technology and risks change, provided that the agreed purpose and scope of processing remain unchanged and the overall level of data protection is not materially reduced. Such updates do not require separate Customer authorisation. Clauses 6.1 and 12.19 apply to material changes.
The Customer grants WaveCom general written authorisation to engage subprocessors necessary to provide the Service under this DPA. WaveCom generally provides the Services using its own infrastructure and employees; engagement of an external processor is limited to a justified need, including an exceptional need for software vendor or platform support. Before engaging a subprocessor, WaveCom checks its security safeguards and contractually ensures substantially the same data protection obligations. WaveCom is liable to the Customer for the subprocessor's performance of its obligations to the extent specified in Article 28(4) of the GDPR. Separate authorisation for each vendor support session is not required if the activity remains within the scope of the valid authorisation, notified processor and processing. The subprocessor and its processing chain must comply with the location and data protection requirements in clauses 12.17–12.17.1.
WaveCom notifies only the affected Customer of the addition of a new actual subprocessor or replacement of an existing one, by an active Customer Portal notification addressed to their account or by email. The notice includes the subprocessor's legal name, location and processing countries, task, affected Service, scope of processing and planned start time. It is sent sufficiently in advance of processing to give the Customer a real opportunity to raise a reasoned data protection objection; the deadline is specified in the notice, taking account of the nature and risk of the change. The content, addressee and transmission time of the Customer Portal notice are retained in an evidential form; if timely notification cannot be ensured through the portal, email is also used. Merely changing text on the Website or in a register does not constitute notification. Under the general authorisation, separate Customer consent is not required for each change. In the event of an objection, the parties seek a reasonable solution; if the risk cannot be mitigated, the Customer may terminate the affected Service before the change is implemented. Until a reasoned objection is resolved, the new subprocessor is not given the relevant Customer's personal data to process. In an urgent case, the Customer may give separate authorisation for earlier engagement in a specific support ticket.
Adding, updating or replacing software, hardware, technology or another service component is not a subprocessor change if the supplier does not process or gain access to the Customer's personal data in doing so. Selling a licence or billing licence fees does not in itself make the supplier a subprocessor of data in the Customer's Service environment. Before vendor support is engaged, the actual processing is assessed; unnecessary content, authentication data and identifiers are removed from support material. Fully anonymised material contains no personal data; pseudonymised IP addresses, VM names and other identifiers, or those that can be linked to a natural person, may still be personal data. If vendor support involves processing the Customer's personal data on WaveCom's behalf, clauses 12.9–12.10 and the applicable data transfer requirements apply.
Taking into account the nature of processing and the information available to WaveCom, WaveCom assists the Customer through reasonable technical and organisational measures in responding to data subject requests. If WaveCom receives a request concerning the Customer's data directly from a data subject, it forwards it to the Customer and does not respond substantively except on the Customer's instructions or as required by law.
WaveCom provides reasonable assistance to the Customer in fulfilling obligations under Articles 32–36 of the GDPR, including security risk assessment, handling personal data breaches, impact assessments and prior consultation, taking account of the nature of processing and the information available to WaveCom.
WaveCom notifies the Customer without undue delay after becoming aware of a breach affecting the Customer's personal data. The notice includes, to the extent available, the nature of the breach, the data and persons affected, possible consequences, measures taken or planned, and a contact for further communication. Missing information is provided in stages without undue delay. WaveCom's notification does not constitute an admission of liability.
On termination of the Service, WaveCom enables the Customer to export the data themselves before the Service is closed, where the Service supports this. The availability period specified in the specific Service Terms applies to retention and deletion of an export copy requested for switching providers. After the Service ends, WaveCom, at the Customer's choice, deletes or returns the personal data and deletes existing copies in accordance with the specific Service Terms, except to the extent that retention is required by law. Data retained by law is isolated from other processing and used only to fulfil the retention obligation. Technically immutable backups awaiting deletion are retained only until the end of the lock period actually applied to them and are then removed through the service-specific deletion process. During this period, the data remains protected, its use is restricted and the DPA obligations continue until deletion. Clause 11.25 applies to retention under the TCO Regulation.
WaveCom makes available to the Customer the information necessary to demonstrate compliance with the DPA, including relevant certificates and, where possible, audit reports. If this is insufficient, WaveCom allows the Customer or their independent auditor to conduct a relevant audit on reasonable prior notice, up to once a year, except in the event of a breach, a supervisory authority's request or another compelling reason. An audit must not harm the Services or the confidentiality of other customers; the Customer bears reasonable ordinary costs unless the audit identifies a material breach by WaveCom.
WaveCom hosts, replicates, backs up and otherwise processes the Customer's personal data only in the location within the EU specified in the specific Service Terms or order. The same restriction applies to administration, vendor support, diagnostics and security services arranged by WaveCom, except for the vendor support exception in clause 12.17.1. Otherwise, personal data is not transferred outside the EU and remote access from outside the EU is not permitted. Only subprocessors established in the EU whose relevant processing and support activities, including those of further subprocessors, take place in the EU are engaged. Infrastructure of global public cloud platforms managed from outside the EU, including their EU regions, is not used to host or back up the Customer's Service environment. Where necessary, a cloud provider established in and managed from the EU may be used if it meets the same location, access and data protection requirements; clauses 12.9–12.10 apply to its engagement. The DPA's general authorisation or an instruction in an individual support case does not authorise other exceptions. The Customer is responsible for the destination and lawfulness of transfers initiated by their own users, applications and integrations. As an exception to the above location and provider restrictions, the Customer may use its own backup repository, such as file-based or object storage (including S3 and Amazon S3), under a special agreement pursuant to clause 8.2.1 of the VMware Cloud terms and where technically feasible. The repository, provider and storage region are specified in the special agreement. The exception covers only the agreed Customer backups and does not extend to WaveCom’s other systems or other customers’ data. Transfers of personal data outside the EU require the applicable basis and safeguards under Chapter V of the GDPR.
As an exception, Broadcom and Veeam vendor support for VMware Cloud may involve processors and communication channels located or established outside the EU, solely for technical information necessary to resolve the fault. The Customer's virtual machines, disks, content and backups are not provided to vendor support, and access to the guest operating system is not permitted. Before disclosing personal data, WaveCom checks the agreements and security measures throughout the processing chain, meets clauses 12.9–12.10 and ensures a transfer basis and required safeguards under Chapter V of the GDPR. This also applies to screen sharing. If the requirements cannot be met, technical information without personal data is used. Any stricter restrictions separately agreed with the Customer remain in place. The exception does not cover automatic diagnostic or security transmissions. When investigating a problem affecting the Customer’s specific virtual machine or application, processing personal data outside the EU is prohibited by default and requires the Customer’s documented permission described in clauses 7.12.1–7.12.4 of the VMware Cloud terms. That permission does not replace the data protection measures required by this clause or change the rules for general platform support.
WaveCom discloses Customer data to a public authority only under applicable law and to the extent necessary. Where possible, WaveCom checks the lawfulness of the request, limits disclosure to the required minimum and notifies the Customer before disclosure, unless prohibited by law.
The Customer is notified directly of material changes to the DPA in accordance with clause 6.1. If a change requires a new documented Customer instruction, for example because it extends processing beyond the agreed purpose or scope, it is documented electronically in the Customer Portal or by another verifiable method. An ordinary change to the technical solution within clause 12.8 and a subprocessor change under the general authorisation in clauses 12.9–12.10 do not, solely for that reason, require renewed acceptance of the DPA. Editorial clarifications do not create a new acceptance obligation. Silence alone does not replace an instruction or confirmation required by applicable law for a particular change.
In the event of a conflict concerning processing of the Customer's personal data, the order of precedence is: mandatory law, the service data processing annex, this section 12, other Service Terms, and the remaining provisions of the General Terms.
Annex A. Technical and organisational measures
Annex A is an integral part of the DPA. The specific implementation of the measures depends on the Service, its configuration and risk.
A.1. Governance and compliance
WaveCom manages the Services within documented quality, environmental, information security, cloud security and business continuity management systems. The relevant standards are ISO 9001:2015, ISO 14001:2015, ISO/IEC 27001:2022, ISO/IEC 27017:2015 and ISO 22301:2019 within their certified scope. Risk assessments, policies, controls and improvement measures are reviewed regularly.
A.2. Organisation and personnel
Information security roles and responsibilities are assigned. The Services are managed by trained employees subject to confidentiality and security requirements. Deputies are provided for key responsibilities; access is granted on the principles of least privilege and need to perform the task, and removed when no longer needed.
A.3. Physical security
WaveCom's data centre uses controlled and logged physical access, CCTV, biometric or other multistage access measures and equipment cabinets with restricted access. The infrastructure includes redundant power, cooling and communications components and gas fire suppression in accordance with the data centre service description.
A.4. Identity and access
Administrative access is individual, role-based, restricted and logged. Multifactor authentication is mandatory for employees' privileged administrative access. Authentication and identity management are redundant; access rights are checked regularly and removed when no longer needed. Access protection includes identity-based and network-based restrictions.
A.5. Customer isolation
On its managed service platform, WaveCom ensures logical separation of different Customers' environments and data, with access limited to authorised users and systems. For cloud services, this includes isolated virtual environments and access restrictions at the compute, network, management and storage layers. Web hosting uses isolated user environments, file system and process access restrictions, and resource limits. Rights granted to one Customer do not provide access to another Customer's data; sharing or connections between Customers require documented instructions from the Customers concerned. The isolation requirement applies regardless of the software or platform used and remains in force when technology changes.
A.6. Network and communications protection
WaveCom uses a redundant managed network, network segmentation, identity-based and network-based access rules, and next-generation firewalls (NGFW). Depending on the Service and protected system, application-level traffic control, intrusion detection and prevention (IDS/IPS), a web application firewall (WAF), and DDoS detection and mitigation are applied. Management traffic is encrypted, and administrative access is separated and restricted according to duties. Threat intelligence-based detection and prevention rules are updated continuously, and appropriate protective or restrictive measures are applied immediately when a threat is detected.
A.7. Encryption
Encrypted protocols are used for management traffic and remote access. Storage media or backup encryption applies only where included in the selected Service or configuration. Encrypted NVMe storage and Veeam backup encryption are separate paid options. In the VMware Service, the Customer may use vTPM in a supported configuration to implement guest operating system encryption (such as BitLocker), or a BYOK solution, and manage the keys themselves. The Customer is responsible for application-, database- and file-level encryption and key management unless otherwise agreed.
A.8. Logging and monitoring
WaveCom monitors its data centres, networks, service platforms and its own managed tools in real time, around the clock. Centralised collection, correlation and analysis of security events (SIEM) and extended detection and response (XDR) are used. Depending on the system, behavioural and machine learning-based analysis, malware and ransomware protection, network and endpoint security monitoring and vulnerability detection are applied. Response to a detected threat begins immediately; automatic alerts, blocking, suspension of suspicious activity or network isolation of an affected device are applied as appropriate to the incident. Security events and administrative activities are logged; access to logs is restricted and they are protected against unauthorised alteration. Log retention periods follow the purpose, Service and internal retention rules. Processing of security logs and diagnostic data complies with the location and data protection requirements in clauses 10.7 and 12.17–12.17.1.
A.9. Vulnerabilities and changes
WaveCom monitors vendor security advisories, threat intelligence and vulnerabilities in real time and immediately assesses their impact on the systems in use. Relevant detection and prevention rules, security settings and protective measures are implemented immediately. Security patches are installed without delay according to the criticality of the threat and the controlled change management procedure, assessing their suitability and impact on the Service. In the event of a critical or actively exploited vulnerability, restrictions or other mitigation measures are applied immediately even if the final fix still requires a vendor solution or technical verification. Significant changes are documented and their operation is checked.
A.10. Backup and recovery
Backup frequency, retention and recovery options are determined by the specific Service Terms and the Customer's configuration. WaveCom's Veeam backup repositories use immutability protection. When a backup job is deleted, copies are removed in accordance with the immutability settings actually applied to them and the deletion process; deleting the job does not cancel an active lock. Veeam backup encryption is a separate paid option. WaveCom tests the operation of its managed backup and recovery solutions under a risk-appropriate procedure. The scope of testing and the parties' responsibilities are specified in the specific Service Terms. The Customer is responsible for the adequacy of their backup policy and for recovery testing where necessary.
A.11. Incident management
WaveCom has a process for detecting, escalating, containing and resolving information security incidents, preserving evidence, recovering and conducting post-incident analysis. Clause 12.14 applies to a breach affecting the Customer's personal data.
A.12. Business continuity
Critical Services use redundancy, monitoring, escalation, recovery procedures and deputies for responsible persons. Business continuity and recovery measures are reviewed and tested according to the criticality of the Service and the ISO 22301 management system.
A.13. Storage media lifecycle
Storage media are put into service, reused, removed and destroyed under a controlled procedure. Customer data is deleted on termination of the Service according to the service-specific retention rules; reusable media are sanitised and failed media are disposed of securely.
A.14. Vendor support
Software vendor support is engaged exceptionally where WaveCom's own technical expertise and normal diagnostic tools cannot resolve the problem. Unnecessary personal data, Customer content and authentication data are removed from support material. Vendor support involving personal data, its communication channel and all parties involved in processing must comply with the location and data protection requirements in clauses 10.7 and 12.17–12.17.1. If compliance cannot be ensured, personal data is not shared and the problem is resolved using WaveCom's resources or fully anonymised technical material. A remote support session is controlled by WaveCom and time-limited. Screen sharing and temporary remote control for VMware (Broadcom) and Veeam vendor support take place under the continuous supervision of a WaveCom employee and are limited to the infrastructure issue being resolved. Before the session, the shared view and access are restricted to the necessary technical information. Throughout the session, the WaveCom employee monitors the scope of the actions and immediately stops remote control or screen sharing if an action exceeds the agreed scope or creates a risk of disclosing data to vendor support where such disclosure is not permitted. Before the session continues, the view or access is restricted or a different diagnostic method is selected. The vendor is not given permanent independent access. Cloud infrastructure vendor support sessions are not recorded, file transfer is prohibited and vendor support is not given access to the Customer's virtual machine content or guest operating system. Partners undergo a prior security assessment, including assessment of ISO/IEC 27001 or equivalent certificates, independent audits and demonstrated security controls. A certificate does not replace a risk assessment of the specific service and processing.
The following procedure for diagnostic extracts applies to VMware/Broadcom and Veeam vendor support. File transfers are prohibited during remote vendor support sessions. Outside a remote session, a WaveCom employee may send vendor support a diagnostic extract required to resolve the problem, provided its contents have been checked before sending and personal data, authentication credentials and information unnecessary for resolving the problem have been removed.
This permission does not cover the transfer of unchecked support bundles, memory dumps, virtual disks or backups. If a required extract contains personal data, its transfer is subject to the restrictions on personal data processing set out in these terms and to the Customer's documented selection.
A.15. Assessment of measures
The effectiveness of controls is assessed through internal reviews, monitoring, audits, tests, risk assessments and certifications. Deficiencies are documented and corrective actions assigned.
A.16. Sensitive support information and contractual evidence
The Customer Portal allows support information to be marked as sensitive. Marked information is encrypted and removed from the active support ticket after it is closed; backups are subject to separate retention rules. Evidence of the Customer's acceptance of the DPA, the version and necessary case-handling data are retained separately and their retention does not depend on the deletion of sensitive support information.
Annex B. General service-specific description of data processing
This annex specifies the application of the DPA. The detailed data processing description for VMware Cloud also applies to that Service. The service order and configuration determine the operations actually ordered; this annex does not add backups or other functions that the Customer has not ordered.
| Processing aspect | Description |
|---|---|
| Subject matter and purpose | Providing the data hosting, storage, transmission, backup, recovery or managed support service ordered by the Customer, ensuring security and terminating the Service. |
| Nature | Depending on the Service: storage, transmission, organisation, technical copying, recovery, restriction and erasure of data; content is accessed only within the necessary and documented Customer instruction. |
| Duration | From activation of the Service until the Service ends and the agreed deletion is completed or the service-specific retention or immutability period expires. |
| Data subjects | Persons determined by the Customer, including their employees, users, customers, partners and others whose data the Customer processes in the Service. |
| Types of data | Contact, identification, account, contract, transaction, communication, technical and other application data selected by the Customer. Special categories of data or offence-related data only on the basis of the Customer's lawful decision and appropriate safeguards. |
| Location and retention | The location follows from the specific Service Terms, order and configuration within the EU; clause 12.17 applies. The limited exception in clause 12.17.1 applies to technical information for VMware Cloud vendor support. Clause 12.15 applies on termination. Customer relationship data is processed and retained under section 10. The special-agreement exception in clause 12.17 applies to the Customer’s own backup repository. |
| Subprocessors | Subprocessors are used to the extent of actual processing under clauses 12.9–12.11 and in compliance with the location and data protection requirements in clauses 12.17–12.17.1. Information about the specific legal entity, task and processing locations is made available to the affected Customer before engagement, and changes are actively notified. |
| Type of Service | Application of the DPA |
|---|---|
| Cloud services, VPS and web hosting | WaveCom is a processor or subprocessor to the extent that it hosts or otherwise processes personal data in the Customer's Service environment. The Customer determines the content, purposes, users and application-level permissions. |
| Backup and replication | Copying, retaining, restoring and deleting Customer data constitutes processing on the Customer's behalf even where WaveCom does not read the content. |
| Dedicated server or colocation | The role depends on the actual service. Merely providing space, electricity or equipment without a task involving personal data processing does not automatically determine a processor role. The DPA applies to the relevant extent to data hosting, administration, backup or substantive support provided on the Customer's behalf. |
| Ordering domains or certificates, and customer administration | Processing of order, contact and billing data for WaveCom's own purposes is governed by section 10; the role of the relevant registries or certificate providers depends on their task and terms. The domain exception in clause 10.7 applies to limited processing of domain registration and contact data outside the EU; it does not extend to certificate services or content in the Customer's Service environment. |


