Effective Date: 7-27-2026
Last Updated: 9-4-2026
Work in Waves — Master Privacy Policy
Contents
- In Short
- 1. About This Policy
- 2. Information We Collect
- 3. Why We Collect It, and Our Legal Basis
- 4. How We Use Information — In Detail
- 5. Artificial Intelligence
- 6. Cookies and Tracking
- 7. How We Share Information
- 8. Your Rights and Choices
- 9. How Long We Keep Information
- 10. How We Protect Information
- 11. Children
- 12. International Transfers
- 13. Business Customers and Organization-Provisioned Accounts
- 14. United States State Privacy Rights
- 15. EU, UK, and Swiss Rights
- 16. Other Jurisdictions
- 17. Third-Party Links and Services
- 18. Changes to This Policy
- 19. Contact Us
- SCHEDULE A — The Waves Suite
- SCHEDULE B — Programs
- SCHEDULE C — Books and Publications
- SCHEDULE D — Subscriptions, Newsletters, and Memberships
- SCHEDULE E — Workspaces and Collaboration
- SCHEDULE F — Business and Organizational Customers
In Short
This summary is for orientation only. The full text below governs.
- We do not sell your personal information. We never have.
- We do not use your content to train AI models — ours or anyone else's. We do use AI (primarily Claude, from Anthropic) to process and organize your content so the products work.
- We do not use your name, face, voice, or words in marketing unless you opt in. Buying something, joining a program, or being on a recorded call is not opt-in.
- We do use third-party analytics and advertising pixels (Google, Meta, PostHog). You can opt out — see Section 6.
- Where a Workspace is gated, we hold no contact details for anyone who has not signed up. Members send their own invitations from their own phones. A gated Workspace may ask you to verify something — such as that you control a particular email address — and workspace administrators can see which lessons each member views. See Schedule E.
- Work studies work differently, and we would rather be exact about it than clever. Where a business owner runs a work study for their own team, they enter each person's name and the work email address their business issued them. We use it to recognize that person at the door of the study. We do not send email to it, and if that ever changes we will say so here before it does. See Schedule E.13.
- You can see, correct, export, or delete your data. Section 8 tells you how, wherever you live.
1. About This Policy
1.1 Who We Are
This Privacy Policy explains how JEMS Enterprises, LLC, a California single-member limited liability company, 28106 Bouquet Canyon Rd, Unit #114, Santa Clarita, California 91350 ("JEMS," "we," "us," "our"), collects, uses, shares, and protects personal information.
We operate under the umbrella brand Work in Waves. This Policy covers every product, program, publication, subscription, website, and service we offer (the "Offerings"), including the Waves Suite, our Programs, our books and publications, our newsletters and subscriptions, the Learn application, and our websites.
For purposes of the EU and UK General Data Protection Regulation, JEMS Enterprises, LLC is the data controller, except where we act as a processor on behalf of a Business Customer as described in Section 13.
1.2 How This Policy Is Organized
Sections 1 through 12 apply to everyone. Sections 13 through 16 contain rights and disclosures specific to particular jurisdictions and customer types. The Schedules at the end describe data practices specific to each Offering.
1.3 Relationship to Our Terms of Service
This Policy is incorporated into our Master Terms of Service. Where this Policy and the Terms conflict on a privacy matter, this Policy controls. Definitions used in the Terms have the same meaning here.
1.4 Prior Policies Superseded
This Policy supersedes all prior privacy policies relating to the Offerings as of the Effective Date.
2. Information We Collect
2.1 Information You Give Us
| Category | Examples | When |
|---|---|---|
| Identity | Name, business name, job title, professional affiliation | Account creation, purchase, enrollment |
| Contact | Email, phone, mailing address, business address | Account creation, purchase, support |
| Account | Username, password (hashed), preferences, settings | Account creation and use |
| Payment | Billing name and address, last four digits and card type, transaction records | Purchase — full card numbers are handled by our payment processor and never reach our systems |
| Purchase | Products purchased, plan, price, dates, installment schedule, refund history | Purchase |
| Program | Enrollment details, attendance, submissions, exercises, goals, business context you choose to share | Program participation |
| Content | Documents, Artifacts, notes, files, and other material you create or upload | Use of the Waves Suite |
| Verification | Information you give to meet a Workspace's access requirements — for example, an additional email address you prove you control. We do not send email to an address verified for this purpose — see Schedule E | Requesting access to a gated Workspace |
| Referral | The name you type when you invite someone to a Workspace (a label only — no phone number, no email); the referral identifier of the member who referred you, if you joined without a link | Workspace referrals — see Schedule E |
| Work study roster | Where you run a work study, the name and the employer-issued work email address you enter for each person on your team, so that we can recognize them at the door. We hold it as an identifier and do not send email to it — see Schedule E.13 | Setting up a work study |
| Work study entries | What a participant records about how their time is spent | Taking part in a work study — see Schedule E.13 |
| Communications | Emails, support tickets, survey and form responses, feedback | Any interaction |
| Marketing consent | Testimonials, releases, case study participation, consent records | Only when you opt in |
2.2 Information We Collect Automatically
| Category | Examples |
|---|---|
| Device | Device type, operating system, browser type and version, screen resolution, language |
| Network | IP address, approximate location derived from IP (city/region level), ISP |
| Usage | Pages viewed, features used, buttons clicked, session duration, referring URL, exit pages |
| Workspace activity | That a referral link was opened; which lessons a member opens and how long the page stays open; video playback requests — see Schedules B and E |
| Work study activity | That a participant opened the study and moved through it, recorded against an identifier that means nothing outside our own systems — see Schedule E.13 |
| Performance | Load times, errors, crash reports, API response times |
| Authentication | Login timestamps, session identifiers, security events, failed login attempts |
| Cookies | Identifiers and preferences — see Section 6 |
2.3 Information Generated Through Participation
When you take part in a Program, we and other participants may generate information about you, including:
- Call recordings — video, audio, and transcripts of group sessions you attend
- Chat and forum contributions — messages posted in community spaces
- Attendance and engagement records
- Written submissions — exercises, worksheets, plans, and materials you submit for review
- Coaching notes — our notes about your situation, progress, and needs
Recording is a condition of Program participation. Section 4.6 explains what we do with recordings and what we will not do without your opt-in.
2.4 Information From Third Parties
| Source | What we receive |
|---|---|
| Payment processors | Transaction confirmations, payment status, partial card details, fraud signals |
| Publishing platforms | Aggregate sales and royalty data — generally not individual purchaser identities |
| Advertising platforms | Aggregated campaign performance, audience insights, conversion events |
| Analytics providers | Aggregated and individual usage data |
| Business Customers | Contact and role details for users they provision |
| Other Workspace members | The name a member types when inviting you, and your referral identifier if a member names you as the person who referred them. See Schedule E.7 |
| An account holder running a work study | Your name and your work email address, entered by the business that issued that address so we can recognize you at the door of its study. It is supplied by your employer rather than by you, and we hold it to recognize you, not to reach you. See Schedule E.13 |
| Publicly available sources | Business information, professional profiles, company details — including, where a Workspace access request is reviewed by a person, information that helps us check whether you meet the requirement (Schedule E.6) |
2.5 Information We Do Not Collect
We do not intentionally collect:
- Full payment card numbers — handled entirely by our payment processors
- Government identification numbers, including Social Security numbers
- Health information, biometric identifiers, or genetic data
- Precise geolocation — we derive only approximate location from IP address
- Information from persons under 18 — see Section 11
- Special category data under GDPR — racial or ethnic origin, political opinions, religious beliefs, trade union membership, health, sex life, or sexual orientation
- Contact details for people who have not signed up — Workspace invitations are sent by members themselves, so we never need a phone number or email address for the person invited. A work study is the one place we hold a work email address for someone with no account, and we would rather describe it exactly than argue about the label. The address is issued and controlled by the business the person works for, not by that person, and their employer supplies it. We hold it to recognize them at the door, we do not send email to it, and it is not added to any mailing list. It is still personal information and we treat it as such throughout this Policy — see Schedule E.13
Please do not submit any of the above to us. If you share such information in a Program submission, a support ticket, or a Workspace, you do so voluntarily and we will handle it under this Policy but we do not seek it.
2.6 Information About People Who Have Not Signed Up
There are three things we may hold about people who have no account with us. Two arise in gated Workspaces: the name a member types when inviting someone, and a referral identifier a new member enters to name who referred them. The third arises in a work study: the name and the employer-issued work email address that the business owner running the study enters for each member of their own team. None of it is used to reach those people. We do not send email to a study participant's work address, and we would tell you here before we started. Schedule E.7 describes each item and what it is used for, and Schedule E.13 describes work studies in full. People who hold an account with us in another of our applications are not covered by this section — they are members, and Schedule E.6(d) describes how a verification they completed there is recognized.
3. Why We Collect It, and Our Legal Basis
The table below states each purpose and, for individuals in the EU, UK, and other jurisdictions requiring a lawful basis, the basis on which we rely.
| Purpose | What this involves | Lawful basis (EU/UK) |
|---|---|---|
| Provide the Offerings | Creating accounts, delivering programs and software, hosting your content, processing payments | Contract — necessary to perform our agreement with you |
| Verify access requirements and run referrals | Checking that you meet a Workspace's access requirements, recognizing a verification you already completed in another of our applications, connecting new members to the person who referred them | Contract for members; Legitimate interests — keeping a gated Workspace gated — for verification and referral records |
| Coaching visibility | Showing workspace administrators which lessons each member views and for how long, so they can support and coach members | Contract; Legitimate interests — delivering a coached Program |
| Run a work study | Holding the name and the employer-issued work email address the study owner enters for each person on their team, matching a typed address against that list to admit the person, and storing what they record | Contract with the study owner; Legitimate interests — the employer's interest in understanding how its own team spends its time, and ours in admitting the right person without holding anything more than an identifier the employer already controls. Where the study owner is an organization purchasing for its personnel, Section 13 applies and the organization is the controller |
| Support | Answering questions, troubleshooting, resolving disputes | Contract |
| Transactional communications | Receipts, schedule changes, security alerts, policy updates, service notices | Contract; Legal obligation where required |
| Security and fraud prevention | Authentication, abuse detection, incident investigation | Legitimate interests — securing our services and protecting users |
| Improve and develop | Understanding feature use, fixing errors, planning development | Legitimate interests — improving our products |
| Analytics | Understanding traffic patterns and product usage | Consent where required by ePrivacy rules; otherwise legitimate interests |
| Advertising and remarketing | Measuring campaigns, showing ads to people likely to be interested | Consent |
| Marketing communications | Telling you about other Offerings | Consent (opt-in); legitimate interests for existing-customer messaging where permitted by local law |
| Testimonials and promotional use | Publishing your name, likeness, or words | Consent — always, without exception |
| Accounting, tax, and legal compliance | Financial records, tax reporting, responding to lawful requests | Legal obligation |
| Establishing or defending legal claims | Preserving records relevant to a dispute | Legitimate interests; Legal claims |
| Business transfer | Due diligence and transition in a merger or sale | Legitimate interests |
Where we rely on consent, you may withdraw it at any time (Section 8). Withdrawal does not affect processing carried out before withdrawal.
Where we rely on legitimate interests, you may object (Section 8). We have carried out balancing assessments and will provide a summary on request.
4. How We Use Information — In Detail
4.1 To Deliver What You Bought
Creating and maintaining your Account, granting access, delivering Programs and Materials, hosting and processing your Content, running sessions, issuing recordings to participants, processing payments and installments, and administering refunds.
4.2 To Support and Communicate With You
Responding to enquiries, sending transactional messages (receipts, schedule changes, renewal reminders, security notices, changes to these terms, sign-in and verification codes, and reminders to finish signing up). Transactional messages are not marketing, and you cannot unsubscribe from them while you hold an active Account or Subscription, though you may close your Account.
4.3 To Improve the Offerings
Analyzing which features are used and where people get stuck, diagnosing errors, testing changes, and planning development. This uses usage and performance data, not the substance of your Content.
4.4 To Market to You — With Your Consent
We send marketing about other Offerings only where you have opted in, or where local law permits messaging to existing customers about similar products. Every marketing message contains an unsubscribe link that works. Unsubscribing from marketing does not affect transactional messages.
Note on Programs: some Programs teach the use of our own software as part of the curriculum. That instruction is Program delivery, not marketing. Where we go beyond instruction and actively promote a separate paid Offering to you, we treat that as marketing and it requires your opt-in.
4.5 To Advertise
We use advertising and analytics pixels to measure campaigns, build audiences, and show ads on third-party platforms. This involves sharing identifiers with those platforms. Section 6 explains your controls, and Section 7.3 explains why we say we do not "sell" your information while still describing this activity honestly.
4.6 Recordings — What We Do and What We Do Not Do
We do: make recordings available to participants of that Program, produce transcripts and summaries, use recordings to create Program Materials, and review recordings internally to improve delivery.
We do not, without your separate opt-in: use a recording or any excerpt of it in advertising, on public channels, on social media, in sales materials, or in communications to people who are not participants of that Program.
If you prefer not to appear on camera, you may keep your camera off, use a display name, or submit questions in text. We will accommodate reasonable requests.
4.7 To Keep Things Secure and Lawful
Detecting and preventing fraud and abuse, enforcing our Terms, investigating incidents, complying with legal obligations, and responding to lawful requests from authorities.
4.8 In a Business Transfer
If we are involved in a merger, acquisition, financing, reorganization, or sale of assets, personal information may be transferred as part of that transaction. We will give notice before your information becomes subject to a materially different privacy policy, and where required we will seek your consent.
5. Artificial Intelligence
5.1 We Use AI to Operate the Offerings
The Waves Suite and certain other Offerings use artificial intelligence to process, organize, summarize, generate, transform, and maintain content. Content you submit is processed by AI systems as a normal part of how the products work. This includes documents, Artifacts, notes, and — where the feature applies — transcripts of recorded sessions.
5.2 Who Processes It
Our primary AI provider is Anthropic PBC (Claude). Content processed through AI-enabled features may be transmitted to and processed by Anthropic under our commercial agreement. Anthropic acts as our subprocessor. Any change or addition to our AI providers will be reflected in the subprocessor table in Section 7.2.
5.3 We Do Not Train Models on Your Content
We do not use your Content to train, fine-tune, or improve artificial intelligence or machine learning models, whether ours or a third party's. Our commercial arrangements with AI providers are configured so that Content submitted through the Offerings is not used to train their models.
This is a commitment, not a preference. If it ever changes, it will require an opt-in from you, not a policy update.
5.4 De-identified Improvement
We may use de-identified and aggregated usage data — feature adoption, error rates, latency, and similar metrics — to improve the Offerings. This does not include the substance of your Content and cannot reasonably be used to identify you.
5.5 AI-Narrated Audio
Some publications are narrated using synthetic voice technology. This is not your voice and involves no processing of your personal information. Where a publication is AI-narrated, we disclose it in the product listing.
5.6 Automated Decision-Making
We do not make decisions producing legal or similarly significant effects about you based solely on automated processing. AI features generate content, summaries, and suggestions; they do not decide whether you get access, what you pay, or whether you receive a refund. Those decisions are made by people. Automatic approval for a gated Workspace (Schedule E.6) is recognition of a verification already recorded against your Account, not an AI decision. Where a request is reviewed instead, we may use AI tools to gather and organize publicly available information that helps us check whether you meet the requirement; a person reads that and makes the decision.
5.7 Please Be Careful What You Submit
Because Content is processed by third-party AI systems, do not submit information you are not permitted to disclose to a processor — material under a confidentiality obligation prohibiting such disclosure, regulated health or financial records, or classified information — unless we have a written agreement with you covering it.
6. Cookies and Tracking
6.1 What We Use
| Type | Purpose | Can you turn it off? |
|---|---|---|
| Strictly necessary | Authentication, session management, security, load balancing, remembering your consent choices | No — the Offerings will not work without these |
| Functional | Remembering preferences, language, and settings | Yes |
| Analytics | Understanding how the Offerings are used, measuring performance | Yes |
| Advertising | Measuring campaigns, building audiences, remarketing across platforms | Yes |
A referral link open is not a cookie. When a Workspace referral link is opened we make a note on our own server that the link was used (Schedule E.8). Nothing is placed on your device and nothing follows you to other sites.
6.2 Consent
Where required by law — including in the EU and UK — we ask for your consent before setting non-essential cookies, and we do not set them until you agree. You can review and change your choices at any time through the Cookie Settings link in the footer of our websites.
6.3 Your Other Controls
- Browser settings — most browsers let you block or delete cookies. Blocking essential cookies will break the Offerings.
- Google Analytics opt-out —
tools.google.com/dlpage/gaoptout - Meta ad preferences — in your Facebook or Instagram settings
- Industry opt-outs —
optout.aboutads.info(DAA),youronlinechoices.eu(EDAA),optout.networkadvertising.org(NAI) - Global Privacy Control — we honor GPC signals as opt-out requests for sale and sharing of personal information where applicable law requires it.
6.4 Do Not Track
Browsers vary in how they implement Do Not Track and there is no common standard. We respond to Global Privacy Control signals rather than DNT.
7. How We Share Information
7.1 We Do Not Sell Your Information
We do not sell personal information for money. We have never done so.
However: under California, Colorado, Connecticut, and certain other state privacy laws, the terms "sale" and "sharing for cross-context behavioral advertising" are defined broadly enough that our use of advertising and analytics pixels may constitute "sharing," and possibly "sale," under those definitions. We would rather tell you that plainly than hide behind a narrow reading. Section 6.3 and Section 14 explain how to opt out.
7.2 Service Providers and Subprocessors
We share information with vendors who perform services for us, under contracts that limit their use of it to providing those services.
| Provider | Function | Data involved | Location |
|---|---|---|---|
| Vercel Inc. | Application hosting and delivery | Usage, technical, and Content data in transit | US |
| Neon Inc. | Database hosting | Account, Content, work study, and transaction data | US |
| Cloudflare, Inc. | Video storage and delivery | Program videos and members' playback requests, including IP addresses. Does not receive names, email addresses, or anything a member types | US |
| Anthropic PBC | AI processing (Claude) | Content submitted to AI-enabled features | US |
| Stripe, Inc. | Payment processing | Payment and billing data | US |
| Resend, Inc. | Transactional email | Email address, message content | US |
| PostHog, Inc. | Product analytics | Usage, device, and technical data, including aggregate performance of sign-up and referral flows. For work study participants we send a pseudonymous identifier only, with no name and no email address | US |
| Google LLC | Analytics, advertising, business email | Usage, device, identifiers, correspondence | US |
| Meta Platforms, Inc. | Advertising and conversion measurement | Identifiers, conversion events | US |
| Zoom Communications, Inc. | Live session hosting and recording | Recordings, transcripts, attendance, chat | US |
| EFFI.live | Live session hosting and recording | Recordings, transcripts, attendance | US |
| Substack Inc. | Newsletter publishing and delivery | Email, engagement data — Substack is also an independent controller for its own platform purposes | US |
| MailerLite, Inc. | Marketing and promotional email delivery; Workspace membership messaging | Email, engagement data, list membership. For Workspace members: personal email address and sign-up stage (created, verified, approved, rejected, activated). Verification details, including any verified email address, are not sent to MailerLite | EU (data stored in the European Union) |
| Ruboss Technology Corporation (Leanpub) | Ebook sales and delivery | Purchase and delivery data — collected by Leanpub as its own controller | Canada or US |
| Amazon.com, Inc. | Print fulfilment and sales | Order and shipping data — collected by Amazon as its own controller | US |
We review this list at least every thirty (30) days and update it when a provider is added, removed, or changes how it handles data. Business Customers receive at least thirty (30) days' notice before we add a subprocessor processing their data (Terms, Schedule F.9).
A note on MailerLite. Our marketing email provider stores data in the European Union. This means some information about subscribers — including subscribers located in the United States — is stored outside the US. We rely on the safeguards described in Section 12.2 for these transfers. For gated Workspaces, MailerLite also holds each member's sign-up stage so that we can send the right message at the right point in sign-up. It does not hold verification details, and it never sends to an address you verified to meet a requirement.
A note on Cloudflare. Cloudflare stores Program videos and streams them to members. To do that it sees each playback request, including the IP address it comes from. It does not hold names, email addresses, or anything a member types.
A note on Substack. Where you subscribe to a publication we host on Substack, Substack collects and processes your information for its own purposes as well as ours, under its own privacy policy. It is not solely acting on our behalf. See Schedule D.
7.3 Advertising Platforms
We share identifiers, conversion events, and audience signals with advertising platforms. See Section 7.1 for how this is characterized under state privacy law, and Section 6 for your controls.
7.4 Within the Work in Waves Family
We may share information across our own Offerings — for example, to recognize you across products, to provision access you have earned, to avoid marketing something you already own, and to give you a coherent experience. All Offerings are operated by the same legal entity, JEMS Enterprises, LLC, under this same Policy.
7.5 With Other Participants and Workspace Members
Programs and Workspaces are collaborative. Information you share in them is visible to other participants.
- Your name, business name, and profile as you configure it
- Anything you say or post in a session, chat, or forum
- Your presence and contributions on recorded calls, visible to participants who watch the recording
- Content you publish to a shared Workspace — and per Terms Schedule E.3, that Content remains licensed to other members even after you delete it
- In a gated Workspace, the name you typed for an invitee is visible only to you. The person you referred is connected to you in our records (Schedule E.8)
We cannot control what other participants do with what you share. Terms Section 13 obliges them to keep it confidential; that is a contractual promise, not a technical control. Share accordingly.
7.6 With Business Customers
If your Account was provisioned by your employer or another organization, that organization's administrators may access, export, restrict, or delete your Account and its Content, subject to applicable law. See Section 13.
7.7 Legal Requirements
We may disclose information where we believe in good faith it is necessary to comply with law, legal process, or a governmental request; to enforce our Terms; to detect or address fraud or security issues; or to protect the rights, property, or safety of any person. Where we are legally permitted to notify you of a request for your information, we will.
7.8 Business Transfer
As described in Section 4.8.
7.9 With Your Consent
Any other sharing is done with your consent.
7.10 What We Do Not Do
- We do not sell your personal information for money
- We do not share your Content with other customers except through features you use deliberately
- We do not use your Content to train AI models
- We do not use your name, likeness, or words in marketing without your opt-in
- We do not share your information with data brokers
- We do not disclose the substance of your business information to competitors
- We do not send email to an address you verify to meet a Workspace requirement, and we do not share it outside the administrators of Workspaces that require it
8. Your Rights and Choices
8.1 Rights Available to Everyone
Regardless of where you live, you may:
| Right | What it means |
|---|---|
| Access | Ask what personal information we hold about you and get a copy |
| Correct | Have inaccurate or incomplete information fixed |
| Delete | Ask us to delete your personal information |
| Export | Receive your data in a portable, machine-readable format |
| Opt out of marketing | Unsubscribe from marketing at any time |
| Withdraw consent | Withdraw any consent you have given, including for testimonials |
| Object | Object to processing based on legitimate interests |
| Restrict | Ask us to limit processing while a dispute is resolved |
| Complain | Complain to us or to a supervisory authority |
8.2 How to Exercise Them
Email intake@workinwaves.com with your request and the email address associated with your Account.
- We will respond within thirty (30) days, or within the shorter period your local law requires. Complex requests may be extended by a further sixty (60) days with notice.
- We will verify your identity before acting, proportionate to the sensitivity of the request.
- These rights are free to exercise. We may charge a reasonable fee for manifestly unfounded or repetitive requests, or refuse them, and will explain why.
- We will not discriminate against you for exercising your rights — no denial of service, no different price, no reduced quality.
8.3 Authorized Agents
You may use an authorized agent. We will require proof of authorization and may require you to verify your identity directly.
8.4 Limits on Deletion
We may retain information where we have a legal obligation or an overriding legitimate ground, including:
- Financial and tax records — retained as described in Section 9
- Records needed to establish, exercise, or defend legal claims
- Records of your opt-outs — we must remember that you opted out
- De-identified or aggregated data that can no longer identify you
- Content in shared Workspaces already licensed to other members under Terms Schedule E.3
- Backups — deleted from live systems immediately; purged from backups on the normal backup rotation
Where we cannot fully delete, we will tell you what we are retaining and why.
8.5 Marketing Opt-Out
Use the unsubscribe link in any marketing email, or email intake@workinwaves.com. This does not stop transactional messages about products you hold.
8.6 Withdrawing Testimonial Consent
Email intake@workinwaves.com. We will stop new uses, remove the material from our own channels within thirty (30) days where technically feasible, and use reasonable efforts with third-party channels we control. We cannot recall printed books, distributed media, or materials already in third parties' hands — see Terms Section 11.4.
8.7 If You Are a Work Study Participant and Have No Account
You have the same rights as everyone else, and you do not need an account to use them. Email intake@workinwaves.com from the work email address the study owner entered for you, and tell us what you want. We will identify you by that address, which is the only identifier we hold for you. If you no longer have access to that mailbox — it belongs to the business, not to you, so this can happen — tell us who you are and who runs the study, and we will work it out with them.
Two things you should know before you write to us. First, the study was set up by the person who runs it, and the record we hold about you exists because they put you on it, so we will tell them we heard from you and, where they are the controller of that record under Section 13, we will refer your request to them. Second, asking us to delete your record removes you from the study; it does not affect anything else, because there is nothing else.
If you would rather not take part at all, tell the person running the study. We do not decide who is on it.
9. How Long We Keep Information
| Category | Retention | Why |
|---|---|---|
| Account information | Life of Account + 30 days | Allow recovery and export |
| Your Content and Artifacts | Life of Account + 30 days | Allow export; see Terms Schedule A.6 |
| Content published to shared Workspaces | Indefinitely, per member licence | Terms Schedule E.3 — cannot be unwound from collaborators' work |
| Financial and transaction records | 7 years | Tax, accounting, and audit obligations |
| Purchase and entitlement records | Access period + 7 years | Prove what you bought and were entitled to |
| Program submissions and coursework | Access period + 2 years | Support alumni access and continuity |
| Call recordings and transcripts | 3 years unless you request deletion | Participant access and Program Materials |
| Coaching notes | 3 years | Continuity of support |
| Workspace verification details (for example, a verified email address) | Life of Account + 30 days | Prove a requirement was met; prevent the same credential being used on two Accounts |
| Referral records (invitee names, link opens, referral matches) | Life of the inviting member's Account + 30 days | Let members track their invitations; attribute approved referrals |
| Lesson viewing activity (lessons opened, time on page) | Life of Account + 30 days | Coaching visibility for workspace administrators |
| Work study roster (participant name and work email address) | Life of the study owner's Account + 30 days, or until the study owner removes the person or deletes the study | Let the named person into the study the owner is running |
| Work study entries (what a participant records) | Life of the study owner's Account + 30 days, or until the study owner deletes the study | The study is the thing the owner asked us to deliver |
| Working lists of verified members used for automatic approval (Schedule E.6(d)) | Entry removed when the person is approved in the new application, or no longer holds an Account | Recognize already-verified members without a review queue |
| Usage and analytics data | 12 months | Product improvement |
| Security and authentication logs | 12 months | Incident investigation |
| Communications and support tickets | 24 months; 7 years if transaction-related | Support history and dispute defense |
| Marketing consent records | Duration of consent + 3 years | Prove consent was given and when withdrawn |
| Opt-out and suppression records | Indefinitely | We must remember not to contact you |
| Backups | Normal rotation, up to 90 days | Disaster recovery |
Where a period expires, we delete or irreversibly de-identify the information.
10. How We Protect Information
We maintain administrative, technical, and physical safeguards appropriate to the risk, including encryption in transit (TLS) and at rest, access controls on a least-privilege basis, hashed password storage, contractual security obligations on our vendors, and regular review of access.
No system is perfectly secure. We cannot guarantee absolute security, and you share information at your own risk. Use a strong, unique password and tell us immediately at intake@workinwaves.com if you suspect unauthorized access.
Breach notification. If a breach affecting your personal information occurs, we will notify you and the relevant authorities as required by applicable law — including within 72 hours to the supervisory authority where GDPR applies.
11. Children
The Offerings are for adults. You must be at least 18 to purchase or use them. We do not knowingly collect information from anyone under 18. If we learn we have, we will delete it promptly.
If you believe a person under 18 has given us information, contact intake@workinwaves.com.
12. International Transfers
12.1 We Operate From the United States
We are based in the United States and our infrastructure and most of our vendors are located there. If you use the Offerings from outside the US, your information will be transferred to, stored in, and processed in the United States, which may not offer the same level of data protection as your home country.
12.2 Transfer Safeguards
Where we transfer personal information out of the EEA, UK, or Switzerland, we rely on:
- Standard Contractual Clauses approved by the European Commission, and the UK International Data Transfer Addendum, with our vendors and within our own operations;
- Adequacy decisions, where the destination benefits from one; or
- Your explicit consent, or necessity for performance of a contract with you, where applicable.
You may request a copy of the safeguards we rely on by emailing intake@workinwaves.com.
13. Business Customers and Organization-Provisioned Accounts
13.1 Who Controls What
Where an organization purchases an Offering for its personnel:
- The organization is the controller of personal information within its account and Workspaces
- We act as a processor on its behalf for that information
- We remain the controller for account administration, billing, security, and product improvement
Work studies. Where an account holder runs a work study for the people who work with them, they choose who is on it, why it is running, and what is done with the results — and they answer to us for everything that happens on it. The work email addresses on the roster are issued and controlled by their business, and they confirm to us that they are entitled to give them to us and will tell their team (Terms, Schedule G.3 and G.5). Where that account holder is an organization purchasing for its personnel, the bullets above apply and the organization is the controller of the study roster and the entries. Where the account holder bought as an individual, we act as controller of those records and rely on the basis stated in Section 3, and the account holder remains responsible for telling their team the study is running (Terms, Schedule G.3).
13.2 What This Means For You as an Individual User
If your employer or another organization provisioned your Account, that organization's administrators may access, export, restrict, or delete your Account and the Content in it. Direct requests about that organization's data practices to the organization, not to us. We will refer you to them.
Your organization is responsible for telling you about this and for obtaining any consent required by employment or privacy law where you are.
If someone put you on a work study, they entered your name and the work email address their business issued you, so that we could recognize you at the door, and they can see what you record. They chose to run the study and they chose who is on it; we did not. Ask them first about why it is running and what they will do with it. Section 8.7 and Schedule E.13 tell you what we hold and how to reach us directly.
Meeting a Workspace requirement is not the same thing. If you verify an email address at an organization's domain to meet a Workspace's access requirement, your Account remains yours. Proving you control that address says nothing about your employment or any other relationship with that organization; it does not make the organization a Business Customer, does not give it any access to your Account or activity, and does not mean we share anything with it (Schedule E.6).
13.3 Data Processing Agreement
Where required by applicable law, our Data Processing Addendum governs our processing on the organization's behalf and forms part of our agreement with it. Business Customers requiring a signed DPA should contact intake@workinwaves.com.
13.4 Subprocessors
The table in Section 7.2 is our current subprocessor list. Business Customers receive at least 30 days' notice before we add a subprocessor processing their data, with a right to object on reasonable data protection grounds (Terms Schedule F.9).
14. United States State Privacy Rights
14.1 Which States
If you are a resident of California, Colorado, Connecticut, Virginia, Utah, Texas, Oregon, Montana, Delaware, Iowa, Nebraska, New Hampshire, New Jersey, Tennessee, Minnesota, Maryland, Indiana, Kentucky, or Rhode Island, or of another state with a comprehensive privacy law, you have the rights in this Section. We apply them to residents of any US state whose law provides them.
US state privacy laws continue to come into force on a rolling basis. We review this list regularly and extend these rights to residents of any state whose law provides them, whether or not that state is named above.
14.2 Your Rights
- Know and access — what we collect, why, who we share it with, and a copy
- Correct inaccurate information
- Delete your personal information
- Portability — a copy in a portable format
- Opt out of sale of personal information
- Opt out of sharing for cross-context behavioral advertising / targeted advertising
- Opt out of profiling producing legal or similarly significant effects — we do not do this
- Limit use of sensitive personal information — we do not collect it as defined
- Non-discrimination for exercising your rights
- Appeal a denial — see 14.5
14.3 Categories We Collect, Disclose, and Share
Under the California Consumer Privacy Act as amended:
| Category (CCPA) | Collected | Disclosed for a business purpose | "Shared" / "Sold" |
|---|---|---|---|
| Identifiers (name, email, IP, account ID) | Yes | Service providers; video delivery provider (IP, video playback) | Yes — advertising platforms |
| Customer records (Civ. Code §1798.80) — name, address, payment info | Yes | Payment processors | No |
| Commercial information (purchases, products considered) | Yes | Service providers | Yes — advertising platforms |
| Internet activity (browsing, usage, interactions) | Yes | Analytics providers; workspace administrators (lesson viewing) | Yes — advertising platforms |
| Geolocation — approximate only, from IP | Yes | Analytics providers | Yes |
| Audio/visual — call recordings | Yes | Video platform, participants | No |
| Professional or employment information (including an email address verified to meet a Workspace requirement, and an employer-issued work email address entered by a study owner to place a member of their own team on a work study) | Yes | Service providers; workspace administrators; the study owner who entered it | No |
| Inferences (preferences, interests) | Yes | Analytics providers | Yes — advertising platforms |
| Sensitive personal information | No | — | — |
| Biometric information | No | — | — |
| Education information | No | — | — |
Sources are described in Section 2; purposes in Sections 3 and 4; recipients in Section 7.
14.4 How to Opt Out of Sale and Sharing
- Use the Do Not Sell or Share My Personal Information link in the footer of our websites
- Enable Global Privacy Control in your browser — we honor it
- Adjust your choices through the Cookie Settings link in the footer of our websites
- Email intake@workinwaves.com
14.5 Appeals
If we decline a request, you may appeal by replying to our decision or emailing intake@workinwaves.com with "Privacy Appeal" in the subject. We will respond within 45 days with our decision and reasons. If we deny the appeal, you may contact your state Attorney General.
14.6 California Shine the Light
California residents may request information about disclosures to third parties for their direct marketing purposes. We do not disclose personal information to third parties for their own direct marketing.
14.7 Notice of Financial Incentive
If we offer a discount, free content, or other benefit in exchange for personal information or marketing consent, we will describe the incentive, its material terms, and how to withdraw, at the point of offer. The value of the information relates to the reasonable expense of collecting and maintaining it. Where a Workspace or Program offers a benefit for approved referrals, this Section applies to that benefit.
15. EU, UK, and Swiss Rights
If you are in the European Economic Area, United Kingdom, or Switzerland:
15.1 Your Rights
- Access (Art. 15) — confirmation, a copy, and information about the processing
- Rectification (Art. 16) — correct inaccurate or incomplete data
- Erasure (Art. 17) — "right to be forgotten," subject to the limits in Section 8.4
- Restriction (Art. 18) — limit processing in defined circumstances
- Portability (Art. 20) — receive data you provided in a structured, machine-readable format, and have it transmitted to another controller where technically feasible
- Object (Art. 21) — to processing based on legitimate interests, and absolutely to direct marketing
- Not be subject to solely automated decision-making (Art. 22) — we do not do this
- Withdraw consent at any time
- Lodge a complaint with a supervisory authority
15.2 How to Exercise
Email intake@workinwaves.com. Section 8.2 applies. We respond within one month, extendable by two further months for complex requests, with notice.
15.3 Supervisory Authorities
- EEA — the authority in your country of residence, place of work, or place of the alleged infringement. A list is at
edpb.europa.eu/about-edpb/board/members_en. - UK — the Information Commissioner's Office,
ico.org.uk - Switzerland — the Federal Data Protection and Information Commissioner,
edoeb.admin.ch
We would appreciate the chance to address your concern first, at intake@workinwaves.com.
15.4 EU and UK Representative
Not intended for sale to EU/UK individuals at this time. Will be updated when/if that becomes relevant.
15.5 Legal Basis
See the table in Section 3.
15.6 Consequences of Not Providing Data
Where we need information to perform our contract with you — your email to create an Account, payment details to process a purchase, verification details to be approved for a gated Workspace — we cannot provide the Offering without it. All other provision is optional.
16. Other Jurisdictions
Canada. You have rights of access and correction under PIPEDA and may complain to the Office of the Privacy Commissioner of Canada.
Australia. You have rights under the Privacy Act 1988 and may complain to the Office of the Australian Information Commissioner.
Brazil. You have rights under the LGPD including access, correction, anonymization, portability, deletion, and information about sharing.
Elsewhere. Where your local law grants you privacy rights, we will honor them. Email intake@workinwaves.com.
17. Third-Party Links and Services
The Offerings link to and integrate with third-party sites and services. We do not control them and are not responsible for their privacy practices. Read their policies. Where you purchase through a third-party platform — Leanpub, Amazon, an audiobook retailer, a newsletter platform — that platform collects and controls your information under its own policy, not this one.
18. Changes to This Policy
We may update this Policy. For material changes, we will give at least thirty (30) days' notice by email, in-product notice, or prominent website posting, and update the "Last Updated" date. Where a change requires your consent under applicable law, we will obtain it before applying the change to you. Continued use after the effective date constitutes acceptance where consent is not required.
Prior versions are available on request.
19. Contact Us
JEMS Enterprises, LLC 28106 Bouquet Canyon Rd Unit #114 Santa Clarita, California 91350 United States
| Purpose | |
|---|---|
| Privacy, data rights, testimonial consent | intake@workinwaves.com |
| Support | intake@workinwaves.com |
| Legal | intake@workinwaves.com |
SCHEDULE A — The Waves Suite
A.1 What we collect specifically. Across all Waves Suite applications, including Artifacts, Learn, and Capture: Account and profile data; Content and Artifacts you create or upload; Workspace membership and activity; feature usage, session, and performance data; integration data from services you connect.
A.2 AI processing. Section 5 applies in full. Content in the Waves Suite is routinely processed by AI to deliver core functionality.
A.3 Content visibility. Content in your private area is visible only to you and to our personnel where necessary for support, security, or legal compliance. Content published to a shared Workspace is visible to Workspace members — see Schedule E.
A.4 Export. You may export your Content at any time during your access period.
A.5 Deletion. On Account closure, Content is retained 30 days for retrieval, then deleted from live systems. Backups purge on normal rotation. Content published to shared Workspaces persists under Terms Schedule E.3.
A.6 Support access. Our personnel may access your Content only where necessary to provide support you have requested, investigate a security incident, or comply with law. Access is logged.
SCHEDULE B — Programs
B.1 What we collect specifically. Enrollment and payment data; attendance and engagement; call recordings, video, audio, and transcripts; chat and forum contributions; written submissions and exercises; business context you share; coaching notes; feedback and exit interview responses.
B.2 Recordings. Sections 2.3 and 4.6 apply. Recording is a condition of participation. Marketing use requires separate opt-in.
B.3 Visibility to other participants. Section 7.5 applies. Assume anything you say or submit in a group setting is seen by other participants and preserved in the recording.
B.4 Exit interviews. Where you request a refund, we ask for a short exit conversation. We may record it with your agreement. What we learn is used to improve the Program. We will not use your exit interview in marketing, and we will not use it to pressure you to stay.
B.5 Alumni communications. After a Program ends, we may send you Program-related communications (materials, alumni access, community notices) as part of your entitlement. Marketing about other Offerings requires opt-in.
B.6 Retention. Section 9 applies. Recordings and submissions are retained for the periods stated there, subject to your deletion rights.
B.7 Video delivery. Recordings and other video Materials are stored on and streamed by Cloudflare. To serve a video, Cloudflare receives the playback request, including the IP address it comes from. Cloudflare does not receive your name, your email address, or anything you type. Section 7.2 lists it as a subprocessor.
B.8 Programs delivered through a Workspace. Where a Program is delivered through a Workspace, Schedule E also applies, including the lesson-viewing visibility in E.9.
SCHEDULE C — Books and Publications
C.1 Purchases through third-party platforms. Where you buy through Leanpub, Amazon, or an audiobook retailer, that platform collects your information as its own controller under its own privacy policy. We typically receive only aggregate sales and royalty data, not individual purchaser identities.
C.2 Direct purchases. Where you buy directly from us, we collect name, email, billing information, and delivery details, and process payment through our payment processor.
C.3 Print fulfilment. Print orders are fulfilled by Amazon or another print-on-demand provider. Your shipping address is collected and used by that provider. We do not hold, pack, or ship physical inventory and generally do not receive shipping addresses.
C.4 AI narration. Section 5.5 applies. AI narration involves no processing of your personal information.
C.5 Reader communications. If you give us your email in connection with a book — for a bonus resource, a mailing list, or a companion download — that is separate from the purchase and is governed by your marketing opt-in.
SCHEDULE D — Subscriptions, Newsletters, and Memberships
D.1 What we collect. Email address; subscription and billing status; engagement data (opens, clicks, content viewed); community contributions where applicable.
D.2 Hosted platforms. We deliver subscription and newsletter content through two routes:
- Substack — where a publication is hosted on Substack, Substack collects and processes subscriber data under its own privacy policy, for its own purposes as well as ours, and is an independent controller of that data. Your subscription may also be visible to Substack across its wider network. Direct requests about Substack's own processing to Substack.
- MailerLite — where we send from our own list, MailerLite processes subscriber data on our behalf as our processor, and we remain the controller. MailerLite stores this data in the European Union (see Section 7.2).
Which route applies depends on where you subscribed. If you are unsure, ask us.
D.3 Email tracking. Our emails may contain tracking pixels recording opens and clicks. You may disable image loading in your email client to prevent open tracking.
D.4 Unsubscribing. Every marketing and newsletter email carries a working unsubscribe link. Unsubscribing from a paid Subscription's content does not cancel the Subscription or stop billing — cancel under Terms Section 7.
D.5 Free lists. Joining a free list is marketing consent for that list. You may leave at any time.
SCHEDULE E — Workspaces and Collaboration
E.1 Shared by design. A Workspace is a shared environment. Content you publish into it is visible to every member. A Workspace may also be the group through which a Program is delivered, and may be gated by access requirements set by its administrator (E.6).
E.2 The member licence. Under Terms Schedule E.3, publishing Content to a shared Workspace grants other members a perpetual, irrevocable licence that survives your deletion of the Content and your departure.
This has a direct privacy consequence: we cannot fully honor a deletion request for Content you published into a shared Workspace, because other members hold rights in it and may have built on it. We will delete your copy and remove your Account association where feasible. Do not publish personal information into a shared Workspace that you may later want erased.
E.3 Activity visibility. Workspace members may see your name, profile, contributions, edits, comments, and activity timestamps.
E.4 Administrators. Workspace administrators can see membership, the requirements each member has met, activity, and Content. They do not see the names members type for their invitees, or referral activity between members; that is held only by us (E.7, E.8). Where a Workspace is organization-owned, Section 13 applies.
E.5 Departure. On leaving, you lose access to Workspace Content. Your contributions remain per E.2.
E.6 Access requirements and verification.
a. How it works. Your Account is tied to your personal email address and belongs to you. A workspace administrator may make access to their Workspace conditional on requirements the administrator defines — for example, proving that you control an email address at a particular domain, or meeting a criterion the administrator checks another way. The administrator defines the requirements and how they are checked. When you meet one, we record that against your Account; it may then satisfy the same requirement on any other Workspace that imposes it.
b. What we collect. Whatever you provide to meet the requirement. Where it is an email address, we hold the address against your Account as evidence that you control it. It is not your contact address, we do not send email to it, and it is seen only by us and by the administrators of Workspaces that require it. Proving that you control an address says nothing about your employment or any other relationship with the organization that issued it, and we do not treat it as doing so.
c. One credential, one Account. A credential used to meet a requirement may be associated with only one Account. We keep it for as long as your Account exists so that the same credential cannot be used on a second Account (Section 9).
d. Automatic and reviewed approval. Where you have already met the same requirement in another of our applications (Schedule A.1.1), that verification is carried forward and approval is automatic. To do this we may keep a working list of members verified in one application, checked when someone signs up to another. Everyone on it holds an account with us and is covered by this Policy; being on it means one thing — that we verified them — and it is not used to contact anyone or for any other purpose. Otherwise a person reviews your request. To help with that review we may use AI tools to gather and organize publicly available information relevant to the requirement — for example, public professional listings. The decision is made by a person (Section 5.6). Approval records that you met the requirement when we checked; we do not re-check it afterwards.
e. Organizations you verify against. Verifying against a requirement does not give any organization access to your Account or activity, and we do not share anything with it (Section 13.2).
E.7 People who have not signed up. There are three things we may hold about people who have no account with us, and this is all of them. The first two arise in a gated Workspace and are described here; the third arises in a work study and is described in E.13.
a. The name a member types when inviting you. When a member invites someone, they type that person's name — and nothing else. No phone number, no email address. It is a label so the member can keep track of who they have invited, and it may be a first name or a nickname. The person named has not agreed to anything and may never join, and this is all we hold about them. We cannot connect that name to any real person, we do not use it to contact anyone, and it is visible only to the member who typed it and to our own system administrators.
b. A referral identifier. Each verified member has a referral identifier — the part of their verified email address that identifies them, which the people they invite already know. If a new member joins without a working referral link, they can enter the identifier of the person who told them about the Workspace, and we connect the two Accounts. The identifier is entered by the new member, so we may hold it before the person it refers to has an account with us. We use it only to make that connection, and we do not use it to contact anyone.
c. The name and work identifier a study owner enters. Where a business owner runs a work study for their own team, they enter a name and a work email address for each person on it, before that person has done anything. The address is one their business issued and controls; the owner supplies it, and confirms to us that they are entitled to. It does one job: when that person opens the study and types it in, we recognize them and let them through. We do not send email to it. E.13 sets this out in full.
E.8 The click on a referral link. When someone opens a referral link, we record that the link was opened — at the moment the page loads, before the person has clicked anything or agreed to anything. This is a note on our own server saying "this link was used." It is how we connect a new member to the person who referred them. It is not a tracking cookie, it places nothing on the device, and it does not follow anyone around the web. If the person never signs up, the note stays a note: we do not know who they are. A referral is complete only when the referred person is approved for the Workspace.
E.9 What each member views, and for how long. Where a Program is delivered through a Workspace, we record which lessons a member opens and how long the page stays open, and we show that to workspace administrators so they can coach from it. We want to be direct about what this is: it is per person and by name, not anonymous totals, and it looks more like monitoring than a view count does. It exists so that the people running a Program can see who is stuck and help. It is not used to make automated decisions about you (Section 5.6), it is not shared with any organization you verified against, and it is not used for advertising.
E.10 Messages we send. Verification codes and sign-in links go to your personal email address through Resend. Reminders to finish signing up, and messages about the Workspace or Program you belong to, go through MailerLite and are transactional or Program delivery, not marketing. Marketing about other Offerings requires your opt-in and carries an unsubscribe link. Nothing is ever sent to an address you verified to meet a requirement, and nothing is sent to a work email address entered for a work study participant (E.13(d)).
E.11 Product analytics. We use PostHog to see how sign-up and referral flows perform in aggregate — where people drop out, which steps take too long. Section 6 explains your controls over analytics.
For work study participants we do this more narrowly, on purpose. We send our analytics provider nothing that identifies you — not your name, not your work email address. You are a string of characters that means something only inside our own database. It lets us see that the same person came back on a later day; it does not let anyone at our analytics provider work out who you are.
E.12 Retention and rights. Section 9 applies; the rows for verification details, referral records, lesson viewing activity, and work study records cover this Schedule (E.13 and E.14 follow). Section 8 applies in full, and Section 8.7 explains how a work study participant with no account exercises those rights.
E.13 Work studies.
a. What a work study is. A business owner may run a work study for the people who work for them, in which each person records how their time is actually spent over a period. We provide this through the Capture application (Schedule A.1); the rest of this clause applies wherever else we provide it. The owner sets it up, decides who is on it, sees what those people record, and is answerable to us for everything that happens on it. We supply the tool; the owner runs the study.
b. Only the owner holds an account. The owner signs up, accepts our Terms, and holds a real Account. Nobody else on the study does. A participant does not register, does not choose a password, does not give us a personal email address, and does not become a member of anything.
c. How a participant gets in. The owner lists the people who may take part. When someone opens the study they type their work email address, and we admit them if it matches a name the owner already put on the list. If it does not match, they are not admitted. That is the whole of the mechanism: recognition at a door, against a list the owner controls.
d. What that address is, and what it is not. It is a work email address issued and controlled by the business the person works for. The owner supplies it, and confirms to us that they are entitled to (Terms, Schedule G.3). We hold it to recognize the person, not to reach them. We do not send email to it — no verification code, no sign-in link, no reminder, no marketing — and it is not passed to our email providers or added to any list. If that ever changes we will update this Schedule before it does, not after. It is still personal information about that person, and every right in Section 8 applies to it.
e. What the owner enters, and nothing more. For each person, a name and that work email address. No phone number, no personal email address, no home address, no job title.
f. What a participant records. Whatever they type into the study, which is a description of how their working time is spent. It is visible to the owner who set the study up. Please do not put anything sensitive into it — Sections 2.5 and 5.7 apply, and a study about where the hours go does not need anything of that kind in it.
g. Measurement. E.11 applies, including the narrower treatment described there.
h. Telling the people on the study. The owner is responsible for telling their team that the study is running, that they listed each person by name and work address, and that they can see what is recorded, and for meeting any notice or consent requirement that employment or privacy law places on them where they are. Terms Schedule G.3 says the same thing. We are not in a position to do it for them, because we do not contact participants.
i. Retention, and getting out. Section 9 gives the periods. An owner can remove someone from a study at any time. If you are on a study and you want your record gone, Section 8.7 tells you how to ask us, and tells you what happens when you do.
E.14 Team members who hold their own account. A work study is not the only way someone can arrive through their employer, and the other way works differently in every respect that matters.
a. A real account, and a real address. Where an employer brings a member of their team into the Waves Suite as a user, that person signs up themselves, accepts our Terms, and gives us a personal contact address that is theirs. We do communicate with them at it, as Section 4 and E.10 describe. This is an ordinary Account and this whole Policy applies to it. It is not what happens in a work study (E.13).
b. What we learn when an employer removes them. When an employer deprovisions a team member, we learn that the working relationship between them has ended. That fact belongs to the account, and we may use it.
c. What we may do with that. Their Account and their personal address remain theirs (Terms, Schedule F.6). We may contact them about their own account and about what is available to them as an individual rather than through their former employer. Anything that amounts to marketing a separate Offering to them still runs on the footing described in Section 4.4 and Section 8.5 — their opt-in, and an unsubscribe link on every message. We do not pass anything about them back to the former employer beyond what Section 13 already provides for.
SCHEDULE F — Business and Organizational Customers
F.1 Roles. Section 13 applies.
F.2 What we collect about Authorized Users. Name, work email, role, seat assignment, activity, and Content created in the organization's account.
F.3 Administrator visibility. Administrators can see user lists, seat usage, activity, and Content in the organization's account and Workspaces.
F.4 Individual requests. If you are an Authorized User and ask us to delete or correct data your organization controls, we will refer you to the organization and notify it of your request.
F.5 Termination. On termination of the organization's agreement, data is available for export for 30 days, then deleted, subject to Section 9 retention obligations.
F.6 DPA. Section 13.3 applies.