Privacy Policy
Last updated:
1. Who we are
Wicely is a product of Tres Comas Ventures, S.L. ("Wicely", "we", "us", "our").
| Legal name | Tres Comas Ventures, S.L. |
| Tax ID (CIF) | B23868268 |
| Registered address | Carrer del Raval 11, 08150 Parets del Vallès, Barcelona, Spain |
| Commercial Registry | Registro Mercantil de Barcelona, entry 1/2025/2025134135 of 20 January 2025, record (asiento) 1/2025/66646 |
| Privacy contact | privacy@wicely.com |
We are established in Spain. This policy is governed by the EU General Data Protection Regulation (Regulation (EU) 2016/679, "GDPR") and Spanish Organic Law 3/2018 on Data Protection and Digital Rights (LOPDGDD).
We have not appointed a Data Protection Officer, because our processing does not meet the conditions in Article 37 GDPR: we do not carry out large-scale monitoring of individuals and we do not process special categories of data. Privacy matters are handled directly by our management, at privacy@wicely.com.
2. Scope, and the two roles we play
This policy covers:
- This website, wicely.com, including its Spanish-language pages, our marketing forms, published reports and the gated investor data room.
- The Wicely platform, our subscription software for industrial R&D teams that monitors patents, research papers, regulation and industry news across a customer's business lines and delivers analysis.
Our role under data protection law differs between the two, and the distinction matters:
| Activity | Our role | What it means |
|---|---|---|
| Website visitors, contact and demo requests, report downloads, newsletter signups, data room access, and the business contacts we research | Controller | We decide why and how the data is processed. This policy governs it in full. |
| Personal data inside a customer's Wicely workspace (their users' accounts and usage) | Processor | Our customer is the controller. We act only on their documented instructions under a signed Data Processing Agreement (DPA). Their own privacy notice governs their employees' data, not this one. |
If you are an employee of a Wicely customer and want to exercise your rights in relation to your workspace account, contact your own employer first. We will support them in responding, and you can always write to us at privacy@wicely.com.
3. Information you give us
| Where | What we collect | Why |
|---|---|---|
| Contact and demo request form | Name, business email, phone number (optional), your message | To reply to you and arrange a meeting |
| Report access form | Name, business email, company name, and whether you agree to be contacted | To give you access to the requested report and, if you agreed, to follow up |
| Product updates signup | Business email, the capability you are interested in | To tell you when that capability ships |
| Investor data room | Business email and the access code you were given | To authenticate you, and to notify us that the data room was opened |
Our forms accept business email addresses only and reject personal webmail addresses. We do not knowingly collect personal data from consumers.
Where a field is marked as required, providing it is a contractual requirement in the sense of Article 13(2)(e) GDPR: without it we cannot reply to you, give you access to the report, or open the data room. There is no statutory obligation on you to give us any of this, and the only consequence of not providing it is that we cannot perform the action you asked for.
Booking a meeting takes you to our Google Calendar appointment page, where Google collects the details you enter in order to schedule the meeting. That step is governed by Google's own privacy policy in addition to this one.
4. Information we collect from other sources
Some of the personal data we hold did not come from you directly. Article 14 GDPR requires us to be explicit about this, so here it is in full.
How we identify potential customers. We research organisations that may need Wicely by hand, using public professional sources: principally LinkedIn public profiles, company websites and public professional directories. A person does this research and decides who is relevant.
| Categories of data | Name, job title, employer and professional profile link. We do not guess or infer email addresses, because we contact people on LinkedIn rather than by email |
| Source | Public professional networking profiles, corporate websites and public professional directories. Always publicly accessible sources, never private ones |
| Purpose | To assess whether Wicely is relevant to your organisation, and to contact you in your professional capacity |
| Legal basis | Our legitimate interest in identifying potential business customers (Art. 6(1)(f) GDPR), read together with Article 19 LOPDGDD on the contact data of people acting in a professional capacity |
| Retention | 12 months from collection if there is no engagement, then deletion. See section 12 |
We do not buy lists. We do not purchase personal data from data brokers, we do not use automated lead databases or scraping tools to build our prospect lists, and we do not run third-party enrichment to append data to profiles. Our outbound tooling automates the sending of messages to contacts we researched ourselves; it is not the source of those contacts.
How we contact you. We reach out on LinkedIn: a connection request, followed by a single message if you accept. We do not send cold email, and we do not run email sequences to people who have not asked to hear from us.
That first message links to this policy, so you can see who we are and where your details came from. That is how we meet Article 14(3)(b). Declining or ignoring the request is enough to end it. If you would rather we deleted your details altogether, write to privacy@wicely.com and we will, keeping only the minimum needed to avoid contacting you again.
5. Personal data in the public sources we analyse
This is the core of what the Wicely platform does, and it necessarily involves some personal data.
Patent filings name inventors, applicants and representatives. Scientific papers name authors and their institutional affiliations. Regulatory publications and industry news name executives, researchers and officials. Those names are personal data under Article 4(1) GDPR, and Wicely analyses documents that contain them.
What we do with them:
- We process names as they appear in the public official record, in order to analyse technology developments, competitive activity and research trends. Knowing which organisation filed what, and who published which paper, is the substance of the analysis.
- Our legal basis is our legitimate interest (Art. 6(1)(f) GDPR) in analysing information that has been deliberately published by patent offices, scientific publishers and regulators, for a purpose those individuals would reasonably expect from a professional publication.
- Sources are official patent offices and their public databases, scientific publishers and open repositories, official regulatory publications, and published industry news.
What we do not do:
- We do not build profiles about these individuals, score them, or evaluate them as people.
- We do not enrich these records with data from other sources.
- We do not use a patent or paper as a lead source. Appearing as an inventor or author will not get you contacted by us.
If you appear in one of these public records and want to exercise your rights, write to privacy@wicely.com. Please note we can act on our own copies and analysis, but we cannot alter the underlying public register, which is maintained by the patent office, publisher or authority in question.
6. Cookies and analytics
We think you will find this section shorter than you expect.
We use one cookie. When you sign in to the investor data room we set a signed session cookie so you do not have to sign in on every page. It lasts 7 days and is HTTP-only. It is strictly necessary to provide a service you expressly requested, and is therefore exempt from the consent requirement under Article 22.2 of Spanish Law 34/2002 (LSSI-CE). Nothing else on this website sets a cookie.
Our analytics are cookieless. We use PostHog, hosted in the European Union, configured so that:
- No cookies, local storage or session storage are used to identify you. Visitors are counted using a rotating, non-reversible server-side hash.
- Automatic event capture is switched off. We record page views and a small set of deliberate events such as "book a demo was clicked", never keystrokes or form contents.
- Analytics requests are served through our own domain rather than a third-party script host.
- We never send your email address or name to our analytics provider. In the investor data room we deliberately record only the fund code, never the visitor.
Because we store nothing on your device for analytics or advertising, and use no tracking pixels, this website does not need a cookie consent banner. If that ever changes, we will ask for your consent before it does.
We do not track you across websites, so there is nothing for browser signals such as Do Not Track or Global Privacy Control to switch off.
7. What we process inside the Wicely platform
When an organisation subscribes to Wicely, we process on their behalf:
- Identification and contact data of their authorised users: name and corporate email address, used to create and authenticate platform accounts.
- Technical usage logs: sign-in records, feature usage and error traces, used to keep the service secure, available and supportable.
The substance of a customer's workspace is business information: their business lines, strategic priorities, technology areas of interest and the public patents, papers and news we analyse against them. Customers retain ownership of their content, and we do not use one customer's content to serve another.
A customer may also choose to include personal data in the content they upload or configure. Where that happens, the customer decides what goes in, and we process it strictly as their processor under the DPA. Our terms ask customers not to put special categories of data (health, biometric and similar) into the platform, because it is not designed for them and the DPA does not cover them.
We process all of this only on the customer's documented instructions, under a Data Processing Agreement that names our sub-processors, restricts processing to the European Union and sets out our confidentiality, security, breach notification and deletion obligations. Changes to the sub-processor list are handled under that agreement with each customer. On termination, customer data is returned or deleted within 30 days.
8. How we use artificial intelligence
Wicely is an AI product, so we want to be precise about what that does and does not mean.
- AI models analyse public technical and commercial sources (patent filings, scientific literature, regulatory publications and news) together with a customer's own business context. Where those sources name people, section 5 explains how we handle it.
- All inference runs on Microsoft Azure AI services within the European Union. Customer content is not sent to a third-party model vendor outside our sub-processor list.
- Customer content is not used to train foundation models, ours or anyone else's.
- We do not carry out automated decision-making or profiling that produces legal effects concerning you or similarly significantly affects you, within the meaning of Article 22 GDPR. Our reports are analysis about technologies and markets, not judgements about people.
AI transparency (Regulation (EU) 2024/1689, the AI Act). Analysis and reports produced in the Wicely platform are generated with AI assistance and are identified as such in the product. Reports we publish openly on this website are reviewed and edited by a person before publication, and we take editorial responsibility for them. We will apply the machine-readable marking of AI-generated output required by Article 50(2) of the AI Act within the timeline that applies to systems already on the market.
9. Legal bases for processing
| Purpose | Legal basis |
|---|---|
| Replying to your enquiry and arranging a demo | Steps taken at your request prior to entering a contract (Art. 6(1)(b) GDPR) |
| Researching and identifying potential business customers, and maintaining professional relationships | Our legitimate interest (Art. 6(1)(f) GDPR), read with Art. 19 LOPDGDD on professional contact data |
| Contacting you on LinkedIn to introduce Wicely | Our legitimate interest in direct business-to-business marketing (Art. 6(1)(f) GDPR), with an unconditional right to object |
| Sending you email about our products | Your consent (Art. 6(1)(a) GDPR), given through one of our forms, or Article 21.2 LSSI where you are already a customer and the message concerns our own similar products |
| Sending product update emails you asked for | Your consent (Art. 6(1)(a) GDPR), withdrawable at any time |
| Analysing public patents, papers, regulation and news that name individuals | Our legitimate interest in analysing deliberately published professional information (Art. 6(1)(f) GDPR) |
| Providing and securing the platform to subscribers | Performance of a contract (Art. 6(1)(b)), and our legitimate interest in service security (Art. 6(1)(f)) |
| Keeping a record of people who asked not to be contacted | Compliance with a legal obligation to honour objections (Art. 6(1)(c) GDPR) |
| Keeping accounting and tax records | Compliance with a legal obligation (Art. 6(1)(c) GDPR) |
Spanish law (Article 21 LSSI-CE) restricts commercial email that was not requested or expressly authorised. We do not send unsolicited commercial email at all: our emails go to people who asked to hear from us through one of our forms, or who are already customers. You can stop them at any time by telling us, either by replying or by writing to privacy@wicely.com, and we honour that permanently.
Where we rely on legitimate interest we have weighed our interest against your rights, and we have documented that assessment. You can ask us for a summary of it, and you can object at any time by writing to privacy@wicely.com. If you object to direct marketing we will stop, without exception and without asking why.
10. Who we share data with
We do not sell personal data, and we do not share it for advertising. We use a small number of service providers, each bound by a written agreement to process data only on our instructions.
Platform sub-processors (as listed in the Data Processing Agreement we sign with customers):
| Provider | Service | Location |
|---|---|---|
| Microsoft Corporation (Azure) | Cloud infrastructure, hosting, database and AI services | European Union |
| Twilio Inc. (SendGrid) | Transactional email delivery | European Union |
| PostHog Inc. | Product and usage analytics | European Union |
| Functional Software Inc. (Sentry) | Application error and performance monitoring | European Union |
Website and marketing service providers, used for our own commercial activity and never for customer content:
| Provider | Service | Location |
|---|---|---|
| Cloudflare, Inc. | Hosting and delivery of wicely.com | Global edge network, request served nearest the visitor |
| Google Ireland Limited | Appointment scheduling for demo bookings | European Union, with group transfers under an adequacy decision |
| Attio Ltd. | Customer relationship management for business contacts | United Kingdom, covered by the European Commission's adequacy decision of 19 December 2025 |
| Lemlist SAS | Automating and managing our LinkedIn outreach messages | European Union (France) |
We may also disclose personal data where we are legally required to, or to establish, exercise or defend legal claims. If we ever undergo a merger, acquisition or asset sale, we will tell affected individuals before their data becomes subject to a different privacy policy.
11. Where your data is processed
All processing of customer data in the Wicely platform takes place within the European Union.
For our own website and marketing activity, some providers operate globally. Where personal data leaves the European Economic Area, the transfer is covered by an adequacy decision of the European Commission or by its Standard Contractual Clauses, together with the additional safeguards those clauses require.
12. How long we keep data
| Data | Retention period |
|---|---|
| Contact and demo requests, report access leads | 24 months from your last interaction with us |
| Prospect contact data researched from public professional sources | 12 months from collection where there is no engagement |
| Product update subscribers | Until you unsubscribe, plus 12 months to evidence that you opted out |
| Do-not-contact record (people who asked not to be contacted) | Kept indefinitely, precisely so that we do not contact you again. It holds the minimum needed for that purpose |
| Investor data room session cookie | 7 days |
| Website and product analytics | 14 months |
| Platform account data and customer content | For the duration of the subscription, plus 30 days to return or delete it |
| Database backups | Rolling 35 days |
| Technical and security logs | 12 months |
| Contracts and commercial correspondence | 5 years after the relationship ends (Art. 1964 Spanish Civil Code) |
| Invoices and accounting records | 6 years (Art. 30 Spanish Commercial Code) |
When a retention period ends we delete the data or irreversibly anonymise it.
13. How we protect your data
The Wicely platform is built on Microsoft Azure with defence in depth:
- TLS 1.3 in transit and encryption at rest.
- A web application firewall with OWASP rule sets, rate limiting and DDoS protection at the edge.
- Application services in a private virtual network. The database is reachable only through a private endpoint, with no public internet access.
- Outbound traffic restricted to an allow-list of approved destinations.
- Authentication tokens held in HTTP-only cookies, so they cannot be read by scripts in the browser.
- Access to production limited to the personnel who need it, under confidentiality obligations.
No system is perfectly secure. If a personal data breach occurs, we will notify the Spanish Data Protection Agency within 72 hours unless the breach is unlikely to result in a risk to people's rights and freedoms, and we will inform affected individuals without undue delay where the risk to them is high. Where we act as processor, we notify the affected customer without undue delay so that they can meet their own deadline.
14. Your rights
Under the GDPR you have the right to:
- Access the personal data we hold about you, and receive a copy.
- Rectify data that is inaccurate or incomplete.
- Erase your data ("right to be forgotten") where the conditions apply.
- Restrict processing while a dispute about accuracy or legitimate interest is resolved.
- Portability: receive data you gave us in a structured, machine-readable format, and have it transmitted to another provider.
- Object to processing based on our legitimate interest, including direct marketing. If you object to direct marketing, we will stop, without exception.
- Withdraw consent at any time, where consent is the basis. This does not affect processing carried out before you withdrew it.
To exercise any of these, write to privacy@wicely.com. We will respond within one month, extendable by two further months for complex requests, and we will tell you if we need the extension. We may ask you to confirm your identity before we act, in order to avoid disclosing your data to somebody else. Exercising your rights is free.
You also have the right to lodge a complaint with the Spanish Data Protection Agency, the Agencia Española de Protección de Datos (AEPD), C/ Jorge Juan 6, 28001 Madrid, www.aepd.es, or with the supervisory authority in your country of residence.
15. Age
Wicely is a workplace tool sold to organisations. It is not directed at children and we do not knowingly collect personal data from anyone under 18. Spanish law sets 14 as the age from which a person can consent to information society services (Art. 7 LOPDGDD), but our own rule is stricter because the service has no purpose outside a professional context. If you believe a minor has given us personal data, contact privacy@wicely.com and we will delete it.
16. Changes to this policy
We may update this policy as the product and the law evolve. The date at the top always reflects the current version. If we make a change that materially affects how we handle your personal data, we will give notice on this website and, where we hold your contact details and the change requires it, by email before it takes effect.
17. Contact us
Questions, requests or complaints about privacy:
Tres Comas Ventures, S.L. Carrer del Raval 11 08150 Parets del Vallès Barcelona, Spain privacy@wicely.com