Compliance Statement
Reading note. This Statement summarises how WiseWave Limited approaches its legal and regulatory obligations for the Tirvea platform, and points to the policies that own each area. It claims no certifications and is candid about work in progress.
1. Purpose
Purpose. To summarise the legal and regulatory framework within which WiseWave Limited operates the Tirvea platform, and to direct readers to the policies that own each area. It is a map, not a substitute for those policies.
2. Scope
Purpose. To state what this Statement covers. It covers the platform's principal areas of legal and regulatory relevance: data protection, digital services, artificial intelligence, consumer rights, privacy, security, child safety, identity verification, and biometric processing. It does not itself implement controls; each is owned by the referenced policy.
3. Operating Entity and Jurisdiction
Purpose. To identify the entity and law. The platform is operated by WiseWave Limited, a company registered in Ireland (Company Number 762171), with its registered office at 39 Cooley Park, Dundalk, Co. Louth, A91 AP2V. The platform is provided from the EU and is subject to Irish and EU law.
4. Data Protection (GDPR)
Purpose. To describe our data-protection posture. We process personal data in accordance with the GDPR and Irish data-protection law, as set out in the Privacy Policy (/legal/privacy) and GDPR Rights policy (/legal/gdpr). Data-subject rights are supported operationally, including data portability (export) and erasure (account deletion). Data minimisation is applied in logs and audit (identifiers are hashed). Retention is governed by the Data Retention Policy (/legal/data-retention).
5. Digital Services (DSA)
Purpose. To describe our approach to digital-services obligations. We provide mechanisms consistent with the aims of the Digital Services Act, including member reporting, content moderation with human review, member notices, and an appeals process (Appeals Policy, /legal/appeals). Formal DSA artefacts - such as a statement-of-reasons register, a trusted-flagger process, and DSA transparency reporting - are partial or pending, and the precise obligations depend on the platform's size and status. [Legal review required before publication - confirm DSA applicability and obligations.]
6. Artificial Intelligence (EU AI Act)
Purpose. To describe our approach to AI regulation. The platform uses AI-assisted moderation through configurable providers, with meaningful human oversight: automated systems may flag content or temporarily suspend pending review, but do not make permanent adverse decisions, which are made by a human (AI Moderation Policy, /legal/ai-moderation). A formal EU AI Act classification and conformity assessment has not yet been recorded. [Legal review required before publication - confirm AI Act classification and any obligations.]
7. Consumer Rights
Purpose. To describe consumer-protection compliance. Paid subscriptions are governed by the Subscription Terms (/legal/subscription-terms), and refunds and the statutory right of withdrawal by the Refund Policy (/legal/refund-policy). We preserve mandatory consumer rights under Irish and EU law and do not exclude rights that cannot be excluded.
8. Privacy
Purpose. To point to privacy compliance. How we collect, use, and share personal data, the lawful bases, and international transfers are set out in the Privacy Policy (/legal/privacy). Cookie and similar-technology use is addressed in the Cookie Policy (/legal/cookies).
9. Security
Purpose. To point to security compliance. Our technical and organisational security measures - authentication, access control, least-privileged cloud access, signed webhooks, rate limiting, hardening headers, and audit logging - are set out in the Security Policy (/legal/security). Encryption in transit is enforced; encryption at rest and backups are provider-managed.
10. Child Safety
Purpose. To describe child-safety compliance. The platform is for adults (18+), with age confirmation, and we prohibit and act on child-safety violations under the Child Safety Policy (/legal/child-safety), cooperating with authorities under the Law Enforcement Guidelines (/legal/law-enforcement). We do not operate automated child-safety detection; cooperation is manual and case by case.
11. Identity Verification
Purpose. To describe verification compliance. Identity verification is provided through Stripe Identity, as set out in the Identity Verification Policy (/legal/identity-verification). Verification is used for trust and safety and is subject to the Privacy Policy and Data Retention Policy.
12. Biometric Processing
Purpose. To describe biometric compliance. A facial-comparison (biometric) capability exists and is treated as special-category data (GDPR Article 9), governed by the Biometric Information Policy (/legal/biometric-data) and requiring explicit consent. This layer is dormant by default, and the biometric data protection impact assessment and final retention periods are pending sign-off. [Legal review required before publication - complete the DPIA before any activation.]
13. Certifications and Standards
Purpose. To be honest about certifications. WiseWave Limited does not claim any security or privacy certification (such as ISO 27001 or SOC 2) for the Tirvea platform. Card payments are processed by Stripe, a PCI-DSS compliant payment processor; Tirvea does not store card numbers, so cardholder-data scope sits primarily with Stripe. We align our practices with recognised good practice, but we do not represent that we hold certifications we have not obtained. [Legal review required before publication - confirm the certification and PCI position.]
14. Supervisory Authority
Purpose. To identify the regulator and complaints route. As an Ireland-established controller, our lead supervisory authority for data protection is the Data Protection Commission (Ireland). You may contact us first at info@tirvea.com (or our data-protection contact as set out in the Privacy Policy), and you have the right to lodge a complaint with the Data Protection Commission or your local supervisory authority. [Legal review required before publication - confirm the DPC details and any representative.]
15. Policy Updates
Purpose. To explain changes. We may update this Statement as our compliance posture and the law evolve, including as pending items (DSA artefacts, AI Act classification, the biometric DPIA, and any certifications) are completed. The current version and effective date are shown on this page.
16. Contact
Purpose. To tell you how to reach us.
- Contracting entity: WiseWave Limited (Company Number 762171)
- Registered office: 39 Cooley Park, Dundalk, Co. Louth, A91 AP2V, Ireland
- Email: info@tirvea.com
For data protection, see the Privacy Policy (/legal/privacy) and GDPR Rights (/legal/gdpr); for security, the Security Policy (/legal/security); for verification and biometrics, the Identity Verification Policy (/legal/identity-verification) and Biometric Information Policy (/legal/biometric-data).