Privacy Policy
Last updated: March 10, 2026
1. Data Controller
The data controller for personal data collected through the websites wolflow.it and wolflow.pro and the desktop application Wolflow is:
Wolflow
Contact email: support@wolflow.it
2. Data Collected
Wolflow may collect the following categories of personal data:
2.1 Voluntarily provided data
- Email address (for registration, contact or PRO plan purchase)
- Username or alias (if chosen by the user)
- Payment information (handled exclusively through secure third-party providers)
2.2 Automatically collected data
- Browsing data: IP address, browser type, operating system, pages visited, date and time of access
- Application technical data: app version, operating system, anonymous error logs (if enabled by the user)
2.3 Data NOT collected
Wolflow does not collect, transmit or store the contents of your creative projects (audio files, video, DAW sessions). All scans and project analyses are performed exclusively locally on your device. No project file is ever sent to our servers.
3. Purpose of Processing
Personal data is processed for the following purposes:
- Service delivery: provision, management and improvement of Wolflow application features
- Account management: registration, authentication and subscription management
- Service communications: sending technical notifications, security updates and service information
- Customer support: responding to support requests and reports
- Analysis and improvement: aggregate and anonymous analysis of service usage to improve user experience
- Legal obligations: compliance with legal obligations or requests from competent authorities
4. Legal Basis for Processing
The processing of personal data is based on the following legal bases under GDPR (EU Regulation 2016/679):
- Contract performance (Art. 6.1.b): to provide the service requested by the user
- Consent (Art. 6.1.a): for sending promotional communications, where expressly consented to
- Legitimate interest (Art. 6.1.f): for aggregate analysis of service usage and fraud prevention
- Legal obligation (Art. 6.1.c): for compliance with legal obligations
5. Data Retention
Personal data is retained for the time strictly necessary to achieve the purposes for which it was collected and in any case no longer than the terms provided by applicable law:
- Account data: retained for the duration of the account and up to 30 days after deletion
- Browsing data: retained for a maximum of 26 months
- Payment data: retained according to applicable tax and accounting obligations (up to 10 years)
- Error logs: retained for a maximum of 90 days
6. Data Sharing
Your personal data is not sold to third parties. It may only be shared with:
- Service providers: hosting providers (Hostinger), payment services, analytics — all bound by data processing agreements (DPA)
- Competent authorities: when required by law or court order
8. User Rights
Under Articles 15-22 of the GDPR, the user has the right to:
- Access: obtain confirmation of the existence of processing and access to their data
- Rectification: obtain correction of inaccurate or incomplete data
- Erasure: obtain deletion of data ("right to be forgotten")
- Restriction: obtain restriction of processing
- Portability: receive their data in a structured, machine-readable format
- Objection: object to processing for legitimate reasons
- Withdrawal of consent: withdraw consent at any time, without affecting the lawfulness of prior processing
To exercise your rights, contact us at: support@wolflow.it
You also have the right to file a complaint with the Italian Data Protection Authority (www.garanteprivacy.it).
9. Data Security
We adopt appropriate technical and organizational measures to protect personal data from unauthorized access, loss, alteration or disclosure, including:
- Data encryption in transit (HTTPS/TLS)
- Limited access to personal data only to authorized personnel
- Regular infrastructure monitoring
10. Extra-EU Data Transfer
Personal data is processed and stored within the European Union. If it becomes necessary to transfer data to third countries (e.g. for cloud services), such transfer will only occur to countries that ensure an adequate level of protection or based on appropriate safeguards (such as Standard Contractual Clauses approved by the European Commission).
11. Minors
The Wolflow service is not intended for individuals under the age of 16. We do not knowingly collect personal data from minors. If we become aware of having collected a minor's data, we will proceed to delete it immediately.
12. Changes to Privacy Policy
We reserve the right to modify this policy at any time. Changes will be published on this page with the date of last update. We encourage you to periodically consult this page. Continued use of the service after publication of changes constitutes acceptance thereof.
13. Contact
For any questions or requests regarding this Privacy Policy or the processing of your personal data, you can contact us at: