Wrysto Logo
Legal & Compliance Center

Privacy Policy

At Wrysto, we build mission-critical industrial maintenance and CMMS software. We respect the confidentiality and privacy of every plant operator, engineer, and enterprise that trusts our platform. This policy explains what information we collect, how it is safeguarded, and your legal rights.

Effective Date: January 1, 2026Last Updated: September 2026Version 2.4

You Own Your Data

All industrial asset registers, maintenance records, and drawings entered into Wrysto remain strictly customer property.

No Data Selling

We never sell, rent, monetize, or trade your personal or operational facility data to any third-party brokers or advertisers.

Enterprise Encryption

All communications and databases are secured with TLS 1.3 in-transit encryption and AES-256 at-rest protection.

GDPR & Global Standards

Compliant with international privacy frameworks (GDPR, CCPA/CPRA) and standard contractual data clauses.

1

Introduction & Scope

Welcome to Wrysto (“we”, “us”, or “our”). We are committed to safeguarding the privacy, confidentiality, and integrity of data entrusted to us by our customers, website visitors, webinar attendees, and authorized platform users.

This Privacy Policy governs our data collection, processing, and protection practices when you interact with:

  • Our corporate website located at wrysto.com and related landing pages.
  • The Wrysto Computerized Maintenance Management System (CMMS) cloud application and operations portal.
  • The Wrysto mobile application used by plant technicians for offline work orders, asset scanning, and inspections.
  • Our technical webinars, live product demonstrations, support portals, and sales inquiries.
Important Role Distinction: Under the European Union General Data Protection Regulation (GDPR) and similar data regulations, Wrysto acts as a Data Controller for account management, marketing, and website analytics. With respect to maintenance records, equipment telemetry, work orders, and plant asset data entered by our enterprise customers into our CMMS software, Wrysto operates strictly as a Data Processor on behalf of the customer (who serves as the Data Controller).

2

Information We Collect

We collect information in three ways: direct input from you, automatic system telemetry, and authorized enterprise account provisioning.

A. Information You Voluntarily Provide

  • Contact & Identity Data: Full name, professional work email address, telephone/WhatsApp number, job title, and physical facility address.
  • Corporate & Facility Profile: Company name, industrial vertical (e.g., Power Plants, Manufacturing, Steel, Textile, Pharmaceuticals, Food & Beverage), facility size, and approximate technician count.
  • Communications: Inquiries sent via our contact forms, book-a-demo forms, live webinar registrations, technical support requests, or discovery questionnaires.
  • Billing & Transaction Details: Corporate payment method, invoice contact details, billing address, and tax registration identifiers (financial transactions are processed securely through certified PCI-DSS compliant gateways; Wrysto does not store full card numbers).

B. Device & Automated Technical Data

  • Log & Connection Data: Internet Protocol (IP) address, browser family, operating system, network details, and access timestamps.
  • Software Telemetry: Feature utilization rates, error traces, latency metrics, and API call response times utilized to ensure operational uptime.
  • Mobile Hardware Features: When using the Wrysto technician mobile app, camera access may be requested strictly to scan equipment QR/barcodes and capture maintenance damage photos. No unauthorized background media access is conducted.

3

Customer Plant & Operational Data

Industrial enterprises manage highly proprietary assets inside Wrysto, including equipment manuals, piping and instrumentation diagrams, bill-of-materials (BOM), sensor thresholds, maintenance schedules, work permits, and breakdown logs.

Our Strict Industrial Guarantee

Your plant data is 100% yours. Wrysto will never view, mine, sell, lease, or distribute your proprietary maintenance logs, engineering diagrams, spare parts pricing, or asset structures to third parties or competitors under any circumstances.

Wrysto staff access customer database instances only when explicitly requested by your designated system administrator to resolve an active support ticket or perform database migration.


4

How We Use Your Information

We process your data strictly for legitimate operational purposes, including:

Purpose / ActivityType of DataLegal Basis (GDPR Art. 6)
Provisioning and managing your Wrysto CMMS subscriptionIdentity, Contact, Corporate ProfilePerformance of a contract
Delivering automated work orders, PM alerts & SMS notificationsContact Data, System LogsPerformance of a contract
Hosting webinars, live demos, and technical discovery sessionsContact, Role, Industry VerticalLegitimate interest / Consent
Preventing unauthorized intrusion and platform abuseIP Address, Audit Trail LogsLegitimate interest & Security compliance
Tax documentation, statutory auditing, and invoice generationBilling & Transaction DetailsLegal obligation

5

Legal Bases for Processing

If you reside in the European Economic Area (EEA), United Kingdom, or Switzerland, our legal basis for collecting and using the personal information described above depends on the context:

  • Contractual Necessity: We need your data to fulfill our Master Service Agreement (MSA) or Terms of Service with your organization.
  • Legitimate Interests: Operating and securing our CMMS infrastructure, measuring application performance, responding to business inquiries, and improving features.
  • Legal Compliance: To satisfy mandatory statutory tax, corporate, or industrial safety recording requirements.
  • Consent: For opt-in direct marketing newsletters or non-essential cookies. You may revoke consent at any time.

6

Data Sharing & Sub-processors

We do not sell personal data. We only share information with vetted third-party vendors and sub-processors bound by strict confidentiality and data protection agreements:

  • Cloud Infrastructure Providers: Certified tier-3/tier-4 enterprise data centers (e.g., AWS, Google Cloud) with ISO 27001 certifications.
  • Transactional Communication Services: Vetted transactional email and SMS dispatch vendors (SendGrid, Twilio) for alerts and work order dispatches.
  • Payment Gateways: PCI-DSS Level 1 certified processors (Stripe) for recurring billing.
  • Legal & Regulatory Authorities: Only when strictly mandated by enforceable court subpoenas, lawful warrants, or applicable statutory mandates.

7

Security & Storage Measures

Wrysto implements multi-layered defensive security architecture designed to prevent data theft, unauthorized modification, or service disruption:

In-Transit Encryption

All data in motion is guarded by TLS 1.3 / HTTPS protocols with 2048-bit RSA or ECDSA cryptographic certificates.

At-Rest Protection

Database storage blocks and customer file uploads are encrypted with industry-standard AES-256 cipher keys.

Role-Based Access (RBAC)

Strict permission controls ensure technicians, supervisors, and plant directors access only permitted modules.

Automated Backups

Daily encrypted offsite snapshots with tested disaster recovery protocols guarantee rapid operational continuity.


8

Data Retention & Purging

We retain personal data only for as long as necessary to fulfill operational or contractual requirements:

  • Active Accounts: Maintained for the duration of the subscription to provide uninterrupted maintenance history and regulatory audit trails.
  • Terminated Subscriptions: Upon account closure, customers have a 30-day grace period to export all plant data (CSV, JSON, PDF). Following the grace period, all operational databases are permanently wiped from production environments.
  • Marketing Inquiries: Contact information from prospective demo or webinar registrations is retained for up to 24 months, after which inactive contacts are archived or removed.

9

Your Privacy Rights (GDPR & CCPA)

Depending on your jurisdiction, you possess statutory legal rights concerning your personal information:

  • Right of Access: Request a confirmation and copy of all personal data we maintain about you.
  • Right to Rectification: Require prompt correction of inaccurate or incomplete profile information.
  • Right to Erasure (“Right to Be Forgotten”): Request permanent deletion of your personal records.
  • Right to Data Portability: Obtain your personal records in a structured, machine-readable format.
  • Right to Object or Restrict Processing: Restrict or object to specific processing operations.
  • California Consumer Rights (CCPA / CPRA): Wrysto does not sell or share personal information as defined under California law.

To exercise any of these rights, submit your request to privacy@wrysto.com. We respond to all verified consumer requests within 30 calendar days.


10

Cookies & Tracking Technologies

Our website and software platform use small text files known as cookies to ensure functional stability, user authentication, and performance:

  • Strictly Necessary Cookies: Required to keep you authenticated across web sessions and preserve security tokens.
  • Functional Cookies: Store preferences such as preferred language and measurement units (Metric vs Imperial).
  • Performance & Analytics Cookies: Gather aggregated, anonymous telemetry on page visits and button interactions to optimize UI responsiveness.

11

International Data Transfers

Wrysto operates globally. If you access our platform from outside the country where our servers are hosted, your information may be transferred across international borders. Whenever cross-border data transfers occur, we implement Standard Contractual Clauses (SCCs) approved by the European Commission and industry-standard security safeguards.


12

Children's Privacy

Wrysto is an enterprise business-to-business (B2B) application designed exclusively for professional industrial engineering teams. We do not knowingly solicit or collect personal information from individuals under the age of 18.


13

Policy Updates

We may revise this Privacy Policy periodically to reflect technological advancements, evolving regulatory requirements, or platform enhancements. Continued use of Wrysto following an update constitutes acceptance.


14

Contact Our Privacy Team

If you have questions, comments, or requests regarding this Privacy Policy or wish to execute a custom enterprise Data Processing Addendum (DPA), please contact our Data Protection Officer:

Wrysto Data Privacy & Compliance Office
Email Addressprivacy@wrysto.com
Corporate Office500 Industrial Parkway, Suite 10, Houston, TX
Technical Sales & Inquiries+1 (888) 555-WRYS