Privacy Policy

Last updated: July 16, 2026. Version 2026-07-16.

This Privacy Policy explains how WeRecoverData ("WeRecoverData," "we," "our," or "us") collects, uses, discloses, and protects information when you visit werecoverdata.com, submit a case or estimate, use our client or partner portals, apply for employment, or otherwise interact with our data recovery services (collectively, the "Services"). This page is maintained by WeRecoverData and is not an independent certification.

1. Scope

This Policy applies to information we collect through our public website, client portal, partner portal, intake and estimate forms, phone, SMS, WhatsApp, email, chat, and in-person drop-off at our labs and drop-off offices. Where we process data on behalf of a business customer under a separate data processing agreement, that agreement controls to the extent of any conflict.

2. Information We Collect

2.1 Information You Provide

  • Contact and identity data: name, email, phone, mailing/shipping address, company, job title.
  • Case intake data: device type, make/model, serial number, failure symptoms, description of lost data, photographs of the device, prior recovery attempts, chain-of-custody information, and, where you elect to send it, the storage media itself and its contents.
  • Payment data: billing address, card brand and last four digits, and tokenized card information handled by our payment processor. We do not store full card numbers on our servers.
  • Account and portal data: username, password (hashed), authentication tokens, and support communications.
  • Employment/partner data: resume, work history, references, and information you submit as an IT-consultant referral partner.
  • Communications: emails, SMS, WhatsApp messages, call recordings where lawful and disclosed, and support tickets.

2.2 Information Collected Automatically

  • Device and log data: IP address, approximate location derived from IP, browser, operating system, device identifiers, referring URL, pages viewed, and timestamps.
  • Cookies and similar technologies: see Section 6. We honor Global Privacy Control (GPC) signals in jurisdictions that require it.
  • Error and performance logs used to diagnose and secure the Services.

2.3 Information From Third Parties

  • Referral partners and resellers who submit a case on your behalf.
  • Public review and mapping platforms (e.g., Google Business Profile).
  • Advertising and analytics providers who report aggregate campaign performance.

2.4 Sensitive Personal Information

The contents of the storage media you send us can contain information you consider sensitive (for example, financial records, health information, government identifiers, credentials, or private communications). We treat all recovered data as confidential customer content, access it only as needed to perform the recovery you requested, and do not use it for any secondary purpose.

3. How We Use Information

We use information to: (a) perform the data recovery, evaluation, shipping, and billing services you request; (b) operate, maintain, and secure the Services; (c) communicate with you about your case, quotes, invoices, and support requests; (d) send service updates and, with your consent where required, marketing communications; (e) prevent fraud, enforce our Terms, and comply with law; and (f) improve our Services through aggregated analytics.

Legal bases (EEA/UK): performance of a contract, our legitimate interests in operating a secure service, compliance with a legal obligation, and your consent (which you may withdraw at any time).

4. How We Share Information

We do not sell personal information for money. We may share information with:

  • Service providers / sub-processors that host, secure, and operate the Services, including hosting and CDN providers, transactional email, payment processing, accounting/invoicing, shipping and postal-mail providers, customer support tooling, analytics and advertising measurement, and communications providers (email, SMS, WhatsApp). A current sub-processor list is available on request to privacy@werecoverdata.com.
  • Referral partners when you were referred to us, limited to case status and identifiers needed to credit the referral.
  • Professional advisors (auditors, lawyers, insurers) under duties of confidentiality.
  • Legal and safety disclosures when required by law, subpoena, or to protect rights, property, or safety.
  • Business transfers in connection with a merger, acquisition, financing, or sale of assets, subject to this Policy.

"Sharing" for cross-context behavioral advertising: to the extent our use of advertising cookies and pixels is considered "sharing" or a "sale" under U.S. state privacy laws, you can opt out using the "Manage Preferences" link in our cookie banner, by sending a Global Privacy Control signal, or by contacting us at privacy@werecoverdata.com.

5. International Data Transfers

We are based in the United States, and our infrastructure and sub-processors may process data in the United States and other countries. Where we transfer personal data out of the EEA, United Kingdom, or Switzerland, we rely on appropriate safeguards, including the European Commission's Standard Contractual Clauses and the UK International Data Transfer Addendum.

6. Cookies, Tracking, and Analytics

We use strictly necessary cookies to operate the site, and — with your consent where required — functional, analytics, and advertising cookies (including Google Tag Manager, Google Analytics, Google Ads, and other measurement pixels). You can accept, reject, or fine-tune categories at any time using the "Manage Preferences" link in the cookie banner or in the footer. We honor GPC signals for California and Colorado residents. We do not respond to browser "Do Not Track" headers because there is no consensus standard, but GPC accomplishes the same result.

7. Data Retention

We retain personal data only for as long as necessary for the purposes described in this Policy:

  • Recovered case media (physical drives and recovered data): retained per your written instructions and our Terms; unclaimed media is disposed of after 90 days.
  • Case records and invoices: retained for up to 7 years to meet tax, warranty, and legal-defense obligations.
  • Portal accounts: retained while the account is active and for a reasonable period afterward.
  • Marketing contact data: retained until you opt out, and then only as needed to honor your opt-out.
  • Security and access logs: retained for up to 24 months.

When retention ends, we delete or de-identify the data.

8. Security

We use administrative, technical, and physical safeguards designed to protect personal data, including TLS encryption in transit, encryption of stored recovered data where feasible, access controls and least-privilege authentication, physical chain-of-custody for media received at our labs, and monitoring of our systems. No method of transmission or storage is 100% secure. If we become aware of a personal-data breach affecting you, we will notify you and applicable regulators as required by law (including within 72 hours where GDPR applies).

9. Your Privacy Rights

9.1 Everyone

You may email privacy@werecoverdata.com to request access to, correction of, or deletion of personal information we hold about you, or to opt out of marketing. We will verify your request using information already associated with your account or case.

9.2 California (CCPA/CPRA)

California residents have the right to (i) know the categories and specific pieces of personal information we have collected, the sources, business purposes, and third parties with whom we share it; (ii) delete personal information; (iii) correct inaccurate personal information; (iv) opt out of the "sale" or "sharing" of personal information; (v) limit the use of sensitive personal information; and (vi) not be discriminated against for exercising these rights. You may exercise these rights yourself or through an authorized agent. We respond within 45 days (extendable by an additional 45 days with notice). We honor Global Privacy Control as a valid opt-out of sale/sharing.

9.3 EEA, United Kingdom, and Switzerland (GDPR / UK GDPR)

You have the rights of access, rectification, erasure, restriction of processing, portability, and objection, as well as the right to withdraw consent and the right to lodge a complaint with your local supervisory authority.

9.4 Other U.S. State Privacy Laws

Residents of states with comprehensive privacy laws — including Virginia, Colorado, Connecticut, Utah, Texas, Oregon, Montana, Delaware, New Jersey, Iowa, Tennessee, Indiana, New Hampshire, Kentucky, Maryland, Minnesota, and Rhode Island — have rights similar to those described above, including access, correction, deletion, portability, opt-out of targeted advertising and profiling with legal or similarly significant effects, and appeal of a denied request. To submit a request, email privacy@werecoverdata.com.

9.5 Shine the Light (California Civil Code § 1798.83)

We do not disclose personal information to third parties for their own direct marketing purposes.

10. SMS, Phone, and Messaging

By submitting our forms or otherwise providing your phone number, you consent to receive service, transactional, and — where you opt in — marketing communications from us by phone, SMS, WhatsApp, and email. Message and data rates may apply. Message frequency varies. Reply STOP to any text message to opt out, or HELP for help. We do not share phone opt-in information with third parties or affiliates for their marketing purposes.

11. Automated Decision-Making

We do not make decisions producing legal or similarly significant effects about you based solely on automated processing. Some routing, prioritization, and fraud-prevention tooling is automated but is reviewed by our staff before affecting your case.

12. Children

Our Services are directed to businesses and adult consumers and are not intended for children under 16. We do not knowingly collect personal information from children under 16. If you believe a child has provided us information, contact privacy@werecoverdata.com and we will delete it.

13. Employees and Job Applicants

If you apply for employment or work as a contractor, we process information necessary to evaluate your application, administer employment, and comply with law. California applicants and employees have the CCPA/CPRA rights described above with respect to HR data.

14. Third-Party Sites

Our site may link to third-party websites. This Policy does not apply to those sites, and we are not responsible for their practices.

15. Changes to This Policy

We may update this Policy from time to time. When we do, we will change the "Last updated" date and version above and, for material changes, provide additional notice (for example, an in-app banner or email). Your continued use of the Services after the effective date constitutes acceptance of the updated Policy.

16. Contact Us

WeRecoverData — Privacy Team
20900 NE 30th Ave, 2nd Floor
Aventura, FL 33180, USA
Email: privacy@werecoverdata.com

For EEA/UK residents: you may also contact your local data protection supervisory authority.