Privacy Policy
How Wonnda processes personal data when you use our website and B2B sourcing platform.
Last updated: 27 August 2026
This policy explains how Wonnda GmbH processes personal data on our website (wonnda.com), our sourcing platform (app.wonnda.com) and our help centre (help.wonnda.com).
1. Controller and contact
The controller within the meaning of Art. 4(7) GDPR is:
Wonnda GmbH Klosterstraße 65, 10179 Berlin, Germany Phone: +49 30 16634706 Email: privacy@wonnda.com
For all questions about data protection, and to exercise the rights described in sections 13 and 14, write to privacy@wonnda.com.
For the Meta Pixel described in section 7 we are a joint controller with Meta within the meaning of Art. 26 GDPR.
2. Data we process
- Account data — name, business email address, sign-in credentials or magic-link token, job title, language and notification preferences, profile photo.
- Company data — company name, address, country, website, VAT ID, logo and media, categories, certifications, production capabilities, minimum order quantities.
- Sourcing content — the requests you post, product catalogues you upload or import, newsfeed posts, ratings, and attached files and images.
- Messages — the content of chats with other companies, including attachments and voice notes recorded in the message composer.
- Enquiries — what you send us through our contact page, by email, or when you request gated content such as a download.
- Technical data — IP address, browser and device type, operating system, language, referrer, timestamps, error diagnostics.
- Usage data — pages viewed, features used, requests opened, matches accepted or declined, email opens and clicks.
- Billing data — plan, invoices, payment status. Card details are entered directly with our payment provider and never reach our servers.
For supplier companies that do not yet have an account, we also process business information from public sources — see section 10. If you apply for a job with us, see section 11.
3. Purposes and legal bases
| Purpose | Legal basis |
|---|---|
| Creating and running your account; signing you in by magic link or password | Art. 6(1)(b) GDPR — performance of a contract |
| Publishing your requests, matching you with counterparties, delivering chats, notifications and transactional email | Art. 6(1)(b) GDPR |
| Disclosing your request, profile and messages to the counterparty you deal with (section 6) | Art. 6(1)(b) GDPR |
| AI features that draft, summarise, classify or transcribe the content you enter (section 6) | Art. 6(1)(b) GDPR |
| Handling enquiries you send us through the contact page, by email, or when requesting gated content | Art. 6(1)(b) GDPR where it concerns a contract, otherwise Art. 6(1)(f) — our interest in answering you |
| Digests of relevant new requests, which you can switch off in your settings | Art. 6(1)(f) GDPR — our legitimate interest in an active marketplace |
| Subscriptions, invoicing and dunning | Art. 6(1)(b) GDPR; retention under Art. 6(1)(c) with §§ 147 AO, 257 HGB |
| Vetting new registrations; spam, fraud and duplicate-account screening | Art. 6(1)(f) GDPR — protecting the marketplace and its users |
| Providing the website and keeping it secure and available, including server logs | Art. 6(1)(f) GDPR — a secure and functioning service |
| Error monitoring and abuse prevention | Art. 6(1)(f) GDPR — a secure and functioning service |
| Maintaining our supplier directory from public sources (section 10) | Art. 6(1)(f) GDPR — a complete and accurate B2B directory |
| Product analytics and masked session replay in the app | Art. 6(1)(a) GDPR and § 25(1) TDDDG — your consent |
| Reach measurement and advertising on wonnda.com (section 7) | Art. 6(1)(a) GDPR and § 25(1) TDDDG — your consent |
| Responding to legal claims, audits and authority requests | Art. 6(1)(c) and Art. 6(1)(f) GDPR |
Where we rely on legitimate interests, you may object at any time — see section 14.
4. Whether you have to provide data
You are not required by law to give us any data. Account and company data are, however, necessary to enter into and perform the contract with us: without them we cannot create an account, publish your requests, or connect you with a counterparty. Everything else — a profile photo, capability details, analytics consent — is voluntary, and declining has no consequence for your use of Wonnda.
5. Cookies and device storage
We store information on your device, or read information from it, only where that is strictly necessary to provide the service you requested (§ 25(2) TDDDG), or where you have consented (§ 25(1) TDDDG). Consent is asked separately on the website and in the app, and can be changed at any time with effect for the future.
Strictly necessary — no consent required
| Stored item | Purpose | Duration |
|---|---|---|
| Session and authentication cookie | Keeps you signed in and protects the session | Until you sign out, at most 30 days |
| CSRF token | Protects forms against cross-site request forgery | For the session |
| Consent cookie | Records your cookie decision so we do not ask again and can prove the choice | 12 months |
| Theme setting (local storage) | Remembers light or dark mode | Until you clear your browser storage |
__cf_bm (Cloudflare) |
Distinguishes humans from bots | 30 minutes |
With your consent
In the app (app.wonnda.com) — product analytics and session replay through PostHog, stored on your device for up to 12 months. All text and all form inputs are masked in the browser before anything is transmitted: the recording shows layout and interaction, not what you typed or read. Declining also records a durable objection on your account, so the choice applies on your other devices. You can change it under Settings → Account → Cookie preferences.
On wonnda.com — reach measurement and advertising tags loaded through Google Tag Manager: Google Analytics 4, Google Ads conversion tracking and the Meta Pixel. These set identifiers on your device for up to 24 months and allow the providers named in sections 6 and 7 to recognise your browser across visits and, for Meta, across its own platforms. They are used only with your consent, which you can give, refuse or withdraw at any time using the privacy button at the bottom left of the page.
6. Recipients
The following service providers process personal data on our instructions under data processing agreements pursuant to Art. 28 GDPR. Locations refer to where the data is processed for us. The advertising providers in section 7 are not processors — that relationship is described separately.
Hosting and infrastructure
| Recipient | Purpose | Location |
|---|---|---|
| Vercel | Hosting and execution of app.wonnda.com | Frankfurt (fra1); provider established in the USA |
| Lovable Cloud | Database, file storage and realtime messaging | AWS eu-central-1, Frankfurt |
| Lovable Labs | Hosting and server-side execution of wonnda.com and help.wonnda.com | Global edge network via Google Cloud and Cloudflare; provider established in Sweden |
| Cloudflare | DNS, content delivery and attack protection | Global edge network |
| Notion | Hosting of our careers page | USA |
Communication
| Recipient | Purpose | Location |
|---|---|---|
| Resend | Delivery of transactional email and delivery events from our own domain | Ireland (eu-west-1); provider established in the USA |
| Customer.io | Onboarding and lifecycle email | EU region |
| Slack | Internal operational alerts that can contain your name, email address and company | USA |
| Browser push services | Delivery of push notifications you enabled, through Google, Apple, Mozilla or Microsoft | Depends on your browser |
Analytics and monitoring
| Recipient | Purpose | Location |
|---|---|---|
| PostHog | Consent-based product analytics and masked session replay | EU cloud, Frankfurt |
| Sentry | Error and performance monitoring, configured without IP addresses or request bodies; with your consent also session replay | EU region, Germany |
| Segment, Mixpanel | Routing and analysis of product events | USA |
| Vercel Analytics and Speed Insights | Aggregate performance measurement without cookies or cross-site identifiers | Frankfurt |
| Google Ireland Ltd. (Google Analytics 4) | Consent-based reach measurement on wonnda.com | Ireland, with onward transfer to Google LLC, USA |
| Usercentrics | Consent management on wonnda.com; stores your consent decision as proof | Germany |
PostHog
We use PostHog (PostHog Inc., hosted in the EU) to understand how our web application is used: which pages are visited, where people click, and anonymised recordings of sessions in the application.
Session recordings are masked before they leave your browser. All text content and all form inputs are replaced with placeholders, so the recording shows the structure of a page and how it was navigated, never what was written or read. We do not record message contents, request details, or anything you type.
PostHog only runs if you have accepted analytics cookies. If you decline, or choose "Only essential", PostHog is not loaded at all and no recording takes place.
Legal basis: your consent (Art. 6(1)(a) GDPR), which you can withdraw at any time.
What our analytics never contain
Our analytics record that an action happened and what kind of action it was. They do not record what you wrote.
Specifically, the following never reach any analytics provider:
- the contents of messages you send or receive,
- the text of sourcing requests, product descriptions, posts, or reviews,
- the search terms you enter.
Where we need to understand how a feature is used, we record structural information instead of content. A search, for example, is recorded as the length of the query and the number of results it returned, never the query itself.
Business contact details such as your name, email address, phone number, and company name are transmitted to the providers named above so that your account can be recognised across sessions. These are contact details, not content.
AI providers
| Recipient | What we transmit | Location |
|---|---|---|
| OpenAI | Request and product text, chat messages sent to our in-app assistant, uploaded catalogue files, voice notes for transcription, and content generated or edited in our internal tools | USA |
| Request and supplier profile data for matching, prompts for generated imagery, and content generated or edited in our internal tools | USA | |
| Perplexity | Company names and public web queries about them | USA |
These providers act as processors and are contractually barred from using the transmitted content to train their models. Voice notes are passed through for transcription and are not stored by us.
Business operations
| Recipient | Purpose | Location |
|---|---|---|
| Stripe | Subscription payments; card data is entered directly with Stripe | EU and USA |
| HubSpot | CRM for sales and account management | EU (eu1) |
| Firecrawl, Apollo.io | Collection and enrichment of public supplier information (section 10) | USA |
We also disclose data to tax advisers, auditors and authorities where we are legally required to, and to lawyers where necessary to establish or defend legal claims.
Other users of the platform
Wonnda is a marketplace, so part of what you enter is disclosed to the companies you deal with. This happens to perform our contract with you (Art. 6(1)(b) GDPR). Those companies are separate controllers for what they do with the data afterwards, and their own privacy policies apply.
- Your company profile is visible in the directory, and to search engines where the profile is public.
- Your requests are visible to matching suppliers. If you post incognito, your company name stays hidden and your contact details are disclosed only once you accept a match.
- Everything you write in a chat, and every file you attach, is visible to the other company and to their colleagues on the same company account.
- Sharing a request or inviting a colleague discloses your name and the content to the recipient.
- Ratings you submit are shown with your company name.
7. Joint controllership with Meta
Where you consent to the Meta Pixel on wonnda.com, we are a joint controller with Meta for the collection of the data on our website and its transmission to them, within the meaning of Art. 26 GDPR:
- Meta Platforms Ireland Ltd., Merrion Road, Dublin 4, Ireland — Meta Pixel. Joint controllership is governed by the Controller Addendum at https://www.facebook.com/legal/controller_addendum; information on the processing is at https://www.facebook.com/privacy/policy. The essence of this arrangement: we are responsible for obtaining your consent and for informing you, which is what this section does. Meta is responsible for everything that happens after the data reaches it — the security of that processing, and answering your requests about it. Data is processed further by Meta for its own purposes, including profiling for advertising, which we cannot influence and to which we have no access at the level of an identified person.
You may exercise your rights under Arts. 15 to 22 GDPR against us or against Meta directly. Requests that concern Meta's own processing can only be answered by Meta, and we will forward such requests. The most effective way to stop this processing entirely is to withdraw your consent using the privacy button at the bottom left of any page.
Google Ads works differently. With your consent we transmit conversion and remarketing data to Google Ireland Ltd., Gordon House, Barrow Street, Dublin 4, Ireland, which processes it as an independent controller for its own purposes rather than jointly with us. The legal basis for our transmission is your consent under Art. 6(1)(a) GDPR; what Google does afterwards is governed by https://policies.google.com/privacy. Google Analytics, by contrast, runs as a processor on our instructions and is listed in section 6.
8. Transfers outside the EEA
Our database, file storage, transactional email, error monitoring, product analytics and CRM are located in the EU where listed in section 6. wonnda.com and help.wonnda.com are served through a global edge network, so website hosting and security processing can take place at network locations outside the EEA. The recipients marked USA in section 6, and the onward transfers described in section 7, involve processing outside the EEA.
Those transfers are safeguarded either by the recipient's certification under the EU–US Data Privacy Framework, which the European Commission has recognised as providing an adequate level of protection (Art. 45 GDPR), or by the European Commission's Standard Contractual Clauses together with supplementary technical and organisational measures (Art. 46(2)(c) GDPR). Despite these safeguards, US public authorities may in principle be able to access data held by US providers, and effective legal remedies against this may be limited.
You can request a copy of the safeguards, including which mechanism applies to which recipient, at privacy@wonnda.com.
9. Automated decisions and profiling
Three checks in the platform run automatically before a person is involved:
- Company review. New registrations are scored against public information about the company and the plausibility of the profile. A clear result can approve an account without delay; anything doubtful goes to a member of our team.
- Request review. New sourcing requests are checked for spam, duplicates and completeness before publication.
- Matching. Requests and supplier profiles are compared to decide which suppliers see a request, and in what order. This involves profiling within the meaning of Art. 4(4) GDPR, based on the categories, capabilities and activity recorded in your company profile.
We do not take decisions producing legal effects concerning you, or similarly significantly affecting you, solely by automated means within the meaning of Art. 22(1) GDPR. An automated check never results in a rejection on its own: every negative outcome is reviewed by a person before it takes effect. You can ask for that review, state your position and contest the decision at privacy@wonnda.com. We do not use these scores to assess creditworthiness and we do not pass them on.
10. Data from public sources
Our supplier directory contains company profiles created before the company registered with us. If you are a contact person at such a company, this section is the information we owe you under Art. 14 GDPR.
- Categories of data: company name, address and country, website, business email address and phone number, production capabilities, certifications, product categories, company size, and the name and job title of a business contact where these are published.
- Sources: the company's own website and public pages, retrieved through our processor Firecrawl; public business registers and trade-show directories; and the B2B data provider Apollo.io. All sources are publicly accessible.
- Purpose and legal basis: maintaining a complete and accurate supplier directory and matching it against buyer requests, on the basis of our legitimate interest in a functioning B2B marketplace under Art. 6(1)(f) GDPR. We process data relating to your professional role, not your private life.
- Recipients: the providers named in section 6.
- Retention: until you object; profiles with no contact for 24 months are reviewed and deleted.
Because we usually have no reliable way to reach the individual contacts behind these company records, notifying each one would involve disproportionate effort within the meaning of Art. 14(5)(b) GDPR. We therefore make this information publicly available here, and provide it directly at the latest when we first communicate with you.
You can object at any time, without giving reasons, at privacy@wonnda.com. We then delete the profile and record the domain so that it is not collected again. On request we also tell you which field came from which source.
11. Applications for employment
If you apply to work with us, we process the data in your application — contact details, CV, references, and anything else you send — solely to decide on your application, on the basis of § 26(1) BDSG and Art. 6(1)(b) GDPR. Applications are visible only to the people involved in the decision.
If we do not hire you, we delete your application six months after the process ends, which covers the period for claims under the AGG. If you agree, we keep it for up to a further twelve months so we can approach you about other roles; that consent is voluntary and can be withdrawn at any time. If we do hire you, the data moves into your personnel file.
12. How long we keep data
We keep personal data for as long as it is needed for the purpose it was collected for, unless a statutory retention period requires longer.
| Data | Period |
|---|---|
| Account and company profile | For the duration of the account; deleted within 30 days of a deletion request, backups within a further 90 days |
| Requests, catalogues, posts, ratings | Deleted or anonymised together with the account; ratings remain visible without your name |
| Chats and messages | For the duration of the account. Messages already sent remain in the counterparty's business record, attributed to a deleted user |
| Enquiries through the contact page or by email | 6 months after the matter is closed, unless it becomes part of a contract |
| Invoices and payment records | 10 years (§ 147 AO, § 257 HGB) |
| Business correspondence relevant to a contract | 6 years (§ 257 HGB) |
| Server and access logs | 30 days |
| Error reports and performance data | 90 days |
| Product analytics events | 24 months |
| Session replay recordings | 30 days |
| Email delivery events | 12 months |
| Push notification subscriptions | Until you disable notifications or the browser endpoint expires |
| Consent and objection records | 3 years after the decision or its withdrawal, as evidence |
| Suppression lists for unsubscribes and objections | Indefinitely, in minimised form, so that we do not contact you again |
| Applications for employment | See section 11 |
| Directory profiles from public sources | See section 10 |
13. Your rights
You have the right to:
- Access your personal data and receive a copy (Art. 15 GDPR).
- Rectification of inaccurate or incomplete data (Art. 16 GDPR). Most of it you can correct yourself in your settings.
- Erasure (Art. 17 GDPR). You can request deletion under Settings → Account or by email; we delete or anonymise your data within 30 days, except where a period in section 12 requires otherwise.
- Restriction of processing (Art. 18 GDPR).
- Data portability — the data you provided, in a structured, commonly used and machine-readable format (Art. 20 GDPR).
- Withdraw consent at any time with effect for the future (Art. 7(3) GDPR), without affecting processing already carried out.
How to exercise your rights
Write to privacy@wonnda.com. We respond within one month and may ask for information to verify your identity. Exercising a right is free of charge.
Right to lodge a complaint
You may lodge a complaint with a supervisory authority, in particular in the member state of your residence, place of work or of the alleged infringement. The authority responsible for us is the Berliner Beauftragte für Datenschutz und Informationsfreiheit, Alt-Moabit 59–61, 10555 Berlin.
14. Your right to object — Art. 21 GDPR
Where we process your personal data on the basis of a legitimate interest under Art. 6(1)(f) GDPR, you have the right to object at any time, on grounds relating to your particular situation, to that processing. This applies in particular to the request digests, the screening of new registrations, our server logs and error monitoring, and the supplier profiles built from public sources described in section 10.
If you object, we will no longer process the data concerned unless we can demonstrate compelling legitimate grounds that override your interests, rights and freedoms, or the processing serves to establish, exercise or defend legal claims.
Where personal data is processed for direct marketing, you may object at any time without giving reasons. After such an objection the data will no longer be used for that purpose.
An objection is free of form and free of charge. Send it to privacy@wonnda.com. Declining the analytics banner in the app is also treated as an objection and is recorded on your account.
Objecting to analytics. You can object to analytics at any time, with no reason required, and we will stop processing your data for this purpose.
The quickest way is in the application itself: Settings → Account → Privacy & cookies, where "Turn analytics off" applies to your account. Choosing "Only essential" in the cookie banner has the same effect.
An objection made this way applies to your whole account, not just the browser you made it in. It survives clearing your cookies and applies on every device you sign in from. It takes effect immediately: once recorded, no further analytics events or profile updates are sent for you, and no profile is created for you at any of the providers named above.
You can also object by writing to privacy@wonnda.com, and you can switch analytics back on at any time from the same settings page.