Privacy Policy

xWave Privacy Statement

Privacy Notice

Last updated: 10 September 2026

This Privacy Notice explains how xWave Technologies Limited (“xWave”, “we”, “us” or “our”) collects and uses personal data.

It applies when xWave acts as a data controller, including in connection with our website, business relationships, marketing, recruitment, employment, supplier management and certain user-account and support activities.

It also explains xWave’s role when we process patient and clinical information on behalf of healthcare organisations.

1. About xWave

xWave Technologies Limited is registered in Ireland under company number 605730.

Our contact address is:

20 Harcourt Street
Dublin 2
D02 H364
Ireland

xWave provides diagnostic governance, clinical decision-support, referral, order-communications, vetting, workflow and analytics software to healthcare organisations.

Our products include xWave CDS, xWave Refer, xWave Vetting, xWave PatientIQ and xWave Insight.

For questions about this Privacy Notice or our use of personal data, please contact:

Email: dpo@xwave.ie

2. When xWave is a controller or processor

xWave may act either as a data controller or as a data processor, depending on the processing activity.

When xWave is a controller

xWave acts as a controller when we determine why and how personal data is processed. This includes personal data relating to:

  • visitors to our website;

  • people who contact us or request a demonstration;

  • customers, prospective customers and other business contacts;

  • platform user accounts and service administration;

  • marketing and corporate communications;

  • events and webinars;

  • job applicants;

  • employees and contractors;

  • suppliers, advisers and professional contacts; and

  • the security and administration of our corporate systems.

When xWave is a processor

When a healthcare organisation uses the xWave platform to process patient, referral or clinical information, that healthcare organisation normally acts as the data controller and xWave acts as its data processor.

In these circumstances, xWave processes personal data only on the healthcare organisation’s documented instructions and in accordance with the applicable contract and data processing agreement.

The healthcare organisation is responsible for deciding the lawful basis for processing patient information, providing information to patients and responding to requests concerning that information.

If you contact xWave about patient or clinical information controlled by a healthcare organisation, we may refer your request to that organisation.

3. Personal data we collect

Depending on your relationship with xWave, we may collect the following information.

Contact and identity information

This may include your:

  • name;

  • job title and employer;

  • business address;

  • email address;

  • telephone number; and

  • professional or account identifiers.

Customer and platform-user information

This may include:

  • username and account information;

  • organisation and role;

  • access permissions;

  • authentication and login records;

  • support requests;

  • product usage information;

  • training and onboarding information; and

  • communications concerning the service.

Website and technical information

This may include:

  • IP address;

  • browser and device information;

  • operating system;

  • approximate location;

  • pages visited;

  • referral source;

  • website interaction information;

  • cookie identifiers; and

  • security and diagnostic information.

Enquiries, support and communications

This may include information you provide when you:

  • request a demonstration;

  • submit a website form;

  • contact our sales or support teams;

  • respond to a survey;

  • register for an event or webinar; or

  • communicate with us by email, telephone, video conference or another approved channel.

Please do not submit patient information or special-category personal data through our public website, sales forms or general corporate communication channels.

Marketing information

This may include:

  • marketing preferences;

  • newsletter subscriptions;

  • event attendance;

  • campaign responses;

  • publicly available professional information; and

  • your interactions with our corporate communications.

Recruitment information

This may include:

  • CV and employment history;

  • education and qualifications;

  • interview notes and assessments;

  • references;

  • right-to-work information;

  • salary expectations;

  • professional memberships; and

  • information about reasonable adjustments.

Where permitted or required by law, recruitment information may include limited health, disability, background-check or criminal-record information.

Employment and contractor information

This may include:

  • contact and emergency-contact information;

  • contracts and engagement records;

  • payroll, banking and tax information;

  • attendance and leave information;

  • performance and training records;

  • equipment and system-access records;

  • expenses and benefits information; and

  • information required to meet employment, tax, health and safety or other legal obligations.

Additional information about workforce processing may be provided directly to employees and contractors.

Supplier and professional-contact information

This may include contact details, contracts, invoices, payment details, due-diligence records and communications with suppliers, advisers, consultants and other business partners.

4. How we obtain personal data

We may obtain personal data:

  • directly from you;

  • from your employer or the healthcare organisation you work for;

  • through the xWave website and approved communication channels;

  • from customers, suppliers and professional advisers;

  • from recruitment agencies and referees;

  • from event organisers;

  • from publicly available professional sources, company websites and professional networking platforms;

  • through cookies and similar technologies, where permitted; and

  • from security, authentication and system-administration tools.

Where we obtain business-contact information from a public or third-party source, we will provide appropriate privacy information when required.

5. Why we process personal data

Operating our website

We process website and technical information to operate, protect and improve our website.

Our lawful bases are our legitimate interests in providing a secure and effective website and your consent where non-essential cookies or tracking technologies are used.

Responding to enquiries and demonstration requests

We process contact details and communications to respond to enquiries, arrange demonstrations and provide requested information.

Our lawful bases are taking steps at your request before entering into a contract and our legitimate interests in developing and managing our business.

Managing customers and platform users

We process business-contact, user-account and support information to:

  • provide and administer our services;

  • create and secure user accounts;

  • communicate service information;

  • provide support;

  • manage contractual relationships;

  • monitor availability and security; and

  • maintain appropriate audit records.

Our lawful bases are performance of a contract where you are a party to that contract and our legitimate interests in delivering and securing services provided to your organisation.

Marketing and corporate communications

We may process business-contact information to provide information about xWave products, services, events and company developments.

We rely on consent where consent is required. In other appropriate business-to-business circumstances, we may rely on our legitimate interests in communicating with customers and relevant professional contacts, subject to applicable electronic-marketing rules.

You can withdraw consent or object to direct marketing at any time by using the unsubscribe facility in a message or by contacting dpo@xwave.ie.

We will stop using your personal data for direct marketing when you object. We may retain limited information on a suppression list to ensure that your preference continues to be respected.

Events, surveys and webinars

We process registration, attendance, feedback and, where applicable, recording information to organise and evaluate events, webinars and research activities.

We rely on consent, performance of a contract or our legitimate interests, depending on the nature of the activity. We will give additional information before recording an event where appropriate.

Recruitment

We process applicant information to:

  • assess suitability for a role;

  • arrange and conduct interviews;

  • verify qualifications and experience;

  • make recruitment decisions;

  • make reasonable adjustments;

  • prepare an offer or contract; and

  • comply with employment and immigration requirements.

Our lawful bases include taking steps at your request before entering into a contract, compliance with legal obligations and our legitimate interests in recruiting suitable personnel and defending legal claims.

Where special-category information is processed, we rely on the conditions applicable to employment, social-security and social-protection law or, where appropriate, explicit consent. Criminal-record information is processed only where authorised by law.

Employment and contractor administration

We process workforce information to administer contracts, payroll, benefits, access, equipment, security, training, performance, leave and legal obligations.

Our lawful bases include performance of a contract, compliance with legal obligations and our legitimate interests in operating and protecting the business.

Suppliers and advisers

We process supplier and professional-contact information to conduct due diligence, administer contracts, make payments, receive professional advice and manage business relationships.

Our lawful bases include performance of a contract, compliance with legal obligations and our legitimate interests in managing our operations and suppliers.

Security, compliance and legal claims

We process relevant information to:

  • protect our personnel, systems and information;

  • prevent and investigate security incidents;

  • manage access and authentication;

  • maintain audit and compliance records;

  • respond to complaints;

  • establish, exercise or defend legal claims; and

  • comply with legal and regulatory obligations.

Our lawful bases are compliance with legal obligations and our legitimate interests in protecting xWave, our customers and other individuals.

6. Cookies and similar technologies

We use strictly necessary cookies and similar technologies to operate and secure our website.

Our website is hosted by Squarespace. We also use HubSpot technology to manage website interactions, forms and communications with business contacts and to understand engagement with our website.

Where HubSpot or another technology is used for non-essential analytics, functionality or marketing, it will be used only in accordance with your cookie choices.

We do not currently use Google Analytics or Microsoft Clarity.

You can withdraw or change your cookie choices at any time through the cookie settings available on our website.

Further information about the technologies currently in use is available in our Cookie Policy.

7. Sharing personal data

We may share personal data with:

  • authorised xWave employees and contractors;

  • the customer or organisation with which you are associated;

  • cloud, hosting and IT service providers;

  • website and form-hosting providers;

  • customer-relationship management and marketing providers;

  • communication and customer-support providers;

  • analytics providers, where you have consented;

  • accountants, payroll providers, banks, pension and benefit providers;

  • insurers, auditors, legal advisers and other professional advisers;

  • recruitment agencies and background-check providers;

  • event and webinar providers;

  • public authorities, regulators, courts or law-enforcement bodies where required; and

  • a purchaser, investor or adviser involved in a proposed corporate transaction, subject to appropriate confidentiality measures.

Key service providers used for relevant corporate processing may include Google Workspace, HubSpot, Squarespace and Intercom.

AWS provides hosting infrastructure for the xWave platform in customer-approved regions. Where xWave processes patient or clinical information through AWS, it does so as a processor under the healthcare customer’s instructions and contractual arrangements.

Some providers act as processors on our behalf. Others may act as independent controllers for particular activities. We assess relevant suppliers and put appropriate contractual and security arrangements in place.

We do not sell personal data.

8. International transfers

xWave and its service providers may process personal data within Ireland, elsewhere in the European Economic Area, the United Kingdom or, in limited circumstances, another country.

Some corporate service providers may use infrastructure or subprocessors located outside the EEA or UK.

Where personal data is transferred internationally, we use an appropriate transfer mechanism. This may include:

  • a European Commission or UK adequacy decision;

  • the European Commission’s Standard Contractual Clauses;

  • the UK International Data Transfer Agreement or UK Addendum; or

  • another transfer mechanism permitted by applicable data-protection law.

We also apply supplementary contractual, organisational or technical safeguards where appropriate.

Core xWave platform data is hosted in customer-approved AWS regions, including Ireland or London where contractually agreed. The applicable location and transfer arrangements are documented with the relevant healthcare customer.

You can request additional information or a copy of the applicable transfer safeguards by contacting dpo@xwave.ie. Commercial or security-sensitive information may be redacted where appropriate.

9. How long we retain personal data

We retain personal data only for as long as it is needed for the relevant purpose or to meet legal, regulatory and contractual requirements.

Our normal retention periods include:

  • Website enquiries and demonstration requests: up to 24 months after our last meaningful interaction.

  • Marketing contacts: until consent is withdrawn, you object or there has been no meaningful interaction for 24 months. Limited suppression information may be retained to honour an opt-out.

  • Customer and platform-user operational data: for the duration of the customer relationship and normally deleted within 45 days after termination where the applicable contract requires this.

  • Contracts, invoices and financial records: normally six years after the relevant transaction, accounting period or end of the relationship.

  • Support and customer communications: for the customer relationship and afterwards where reasonably required for service, contractual or legal purposes.

  • Event and webinar registrations: normally six months after the event.

  • Event or webinar recordings: normally 12 months unless a different period is communicated when the recording is made.

  • Corporate event and engagement records: normally three years.

  • Unsuccessful job applications: normally six months after the recruitment process ends, unless the applicant agrees to a longer period.

  • Successful job applications: transferred to the individual’s employment record.

  • Core employment and payroll records: during employment and normally for seven years after employment ends, subject to specific legal requirements.

  • Supplier and professional-contact information: for the relationship and normally six years afterwards where required for contract, financial or legal purposes.

  • Website security and system logs: for the period needed to protect systems and investigate incidents, normally no longer than 12 months unless an incident requires longer retention.

  • Cookie information: for the periods described in our Cookie Policy and cookie-management tool.

  • Patient and clinical information processed for healthcare customers: for the period determined by the relevant healthcare controller and documented in the customer contract and deployment arrangements.

We may retain information for longer where necessary because of a legal obligation, investigation, dispute, security incident or legal claim. Information may also be securely anonymised so that it can no longer identify an individual.

10. Security

xWave maintains an Information Security Management System and is certified to ISO/IEC 27001.

Our security measures include, as appropriate:

  • role-based access controls and least-privilege access;

  • multi-factor authentication;

  • encryption in transit and at rest;

  • endpoint security and managed device controls;

  • security logging and monitoring;

  • secure software-development practices;

  • supplier due diligence;

  • backup and recovery arrangements;

  • staff security and data-protection training; and

  • incident-response and breach-management procedures.

No internet-based system can be guaranteed to be completely secure. We regularly review our safeguards and update them according to risk, technology and legal requirements.

11. Children’s information

Our corporate website and marketing activities are not directed at children under 16, and we do not knowingly collect children’s personal data through those activities.

xWave products may process information relating to child patients where a healthcare organisation uses the xWave platform. In those circumstances, the healthcare organisation is normally the controller and xWave processes the information only on its documented instructions.

12. Automated decision-making and AI-assisted processing

xWave does not use website, marketing, recruitment, employment or business-contact information to make decisions based solely on automated processing that produce legal or similarly significant effects.

Certain xWave platform features may use AI-assisted processing to support clinical decision-making, referral analysis, vetting, workflow or audit. These features are intended to support, rather than replace, professional judgement.

Where configured by a healthcare customer, automated vetting may approve referrals that meet predefined rules and confidence thresholds. It does not automatically reject or decline referrals. The healthcare organisation determines whether and how such functionality is used and is responsible for the applicable lawful basis, transparency and safeguards.

Additional information is provided to healthcare customers through contractual, implementation and data-protection documentation.

13. Your rights

Depending on the circumstances, you may have the right to:

  • receive information about how your personal data is used;

  • access your personal data;

  • have inaccurate or incomplete information corrected;

  • request deletion of your personal data;

  • request restriction of processing;

  • object to processing based on legitimate interests;

  • object at any time to processing for direct marketing;

  • receive certain information in a portable format;

  • withdraw consent at any time, without affecting processing carried out before withdrawal; and

  • request safeguards relating to certain automated decisions.

These rights are not absolute and may be subject to legal exemptions or limitations.

To exercise a right, contact dpo@xwave.ie. We may ask for information necessary to confirm your identity.

We normally respond within one month. Where a request is complex or numerous requests are received, this period may be extended by up to two further months. We will explain any extension.

There is normally no fee. We may charge a reasonable fee or refuse a request where it is manifestly unfounded or excessive, as permitted by law.

Where xWave processes information solely on behalf of a healthcare organisation, your request should normally be directed to that organisation. We will assist the organisation with the request where required.

14. Complaints

If you have concerns about our use of personal data, please contact us first at dpo@xwave.ie so that we can investigate.

You also have the right to complain to the Data Protection Commission:

Data Protection Commission
6 Pembroke Row
Dublin 2
D02 X963
Ireland
www.dataprotection.ie

Where UK data-protection law applies, you may also contact the UK Information Commissioner’s Office:

www.ico.org.uk

15. Changes to this notice

We may update this Privacy Notice to reflect changes in our services, processing activities, suppliers or legal obligations.

The “Last updated” date at the beginning of the notice shows when the most recent changes were made. Where a change materially affects how we use personal data, we will take reasonable steps to bring the change to the attention of affected individuals.