Law Enforcement Guidelines
Reading note. These Guidelines are for competent authorities seeking data from WiseWave Limited in relation to the Tirvea platform. We respond to valid legal process and cooperate in genuine emergencies. Requests are handled by a manual, case-by-case legal process; we do not operate automated reporting.
1. Purpose
Purpose. To explain how WiseWave Limited receives and responds to lawful requests for user data from law enforcement and other competent authorities, and what those authorities should include in a request. We aim to cooperate with valid legal process while protecting our members' rights.
2. Scope
Purpose. To state what these Guidelines cover. They cover requests from law enforcement, courts, and other competent authorities for data held by WiseWave Limited about the Tirvea platform. They do not change how we retain data (Data Retention Policy, /legal/data-retention) or process it (Privacy Policy, /legal/privacy), and they do not apply to security-researcher reports (Vulnerability Disclosure Policy, /legal/vulnerability-disclosure) or member abuse reports (in-product tools).
3. Legal Basis for Requests
Purpose. To state the legal framework. WiseWave Limited is established in Ireland and subject to Irish and EU law. We disclose user data only where we are legally required or permitted to do so, in response to valid legal process appropriate to the requesting authority's jurisdiction. Cross-border requests should come through the applicable mutual legal assistance channels or other lawful mechanisms. We may decline or seek to narrow requests that are overbroad, legally deficient, or inconsistent with applicable law and fundamental rights.
4. Who May Submit a Request
Purpose. To identify valid requesters. Requests should come from a competent authority (for example law enforcement, a court, or a regulator) acting within its jurisdiction and legal powers, on official letterhead or through an official channel, from an identifiable official with contact details we can verify.
5. How to Submit a Request
Purpose. To explain how to reach us. Send requests to info@tirvea.com with "Law Enforcement Request" in the subject line. Include the legal basis and process, the specific account identifiers (for example the account email or user id), the precise data sought, the relevant time period, and a point of contact. There is currently no dedicated intake portal; requests are handled manually. [Legal review required before publication - confirm the intake channel and any dedicated address.]
6. Types of Request
Purpose. To describe the kinds of request we act on.
- Preservation request - a request to retain specified data pending lawful process (see §7).
- Disclosure request - a request to produce specified data under valid legal process (see §8), such as a court order, warrant, or equivalent, appropriate to the data sought and the jurisdiction.
- Emergency request - a request relating to an imminent risk to life or safety (see §9).
The legal instrument required depends on the data sought and the applicable law; we assess each request against that law. [Legal review required before publication - map request types to the legal instruments required under Irish/EU law.]
7. Data Preservation
Purpose. To explain preservation. On a valid preservation request, we can act to retain specified records pending lawful process, for the period the request and the law require. Preservation is a manual, organisational step; there is no dedicated legal-hold system, and preservation does not itself disclose data. General retention and deletion are governed by the Data Retention Policy (/legal/data-retention). [Legal review required before publication - confirm preservation scope, timescales, and process.]
8. Data Disclosure
Purpose. To explain disclosure. We disclose data only under valid legal process and only the data that process requires - we seek to narrow overbroad requests and disclose the minimum necessary. Disclosure decisions are made manually with legal review. We do not sell data, and we do not provide bulk or standing access. What we can produce is limited to what we actually hold (see §12).
9. Emergency Requests
Purpose. To explain emergencies. Where there is a good-faith basis to believe there is an imminent risk of death or serious physical harm, we may voluntarily disclose limited information necessary to help prevent that harm, in line with applicable law, without waiting for formal process. Emergency requests should be clearly marked and explain the nature and immediacy of the risk and the information needed. We assess each emergency request on its facts. [Legal review required before publication - confirm the emergency-disclosure basis and internal approval.]
10. Child Safety
Purpose. To explain child-safety cooperation. We treat child safety as a priority and cooperate with competent authorities and child-protection bodies in relation to suspected child sexual abuse or exploitation, consistent with the Child Safety Policy (/legal/child-safety) and applicable law. We do not operate automated detection or automated reporting in the current platform; child-safety cooperation and any reporting are handled manually and case by case. [Legal review required before publication - confirm mandatory child-safety reporting obligations and the correct reporting bodies.]
11. User Notice
Purpose. To explain when we tell users. Our general approach is to notify affected users of a request for their data where we are lawfully able to do so, so they may seek to protect their rights - unless we are legally prohibited from doing so (for example by a court order or non-disclosure requirement) or where notice would be counterproductive in an emergency or a child-safety matter. [Legal review required before publication - confirm the user-notice policy and its exceptions.]
12. What We Hold
Purpose. To set expectations about available data. Subject to what exists at the time of a request and our retention periods, we may hold: account and registration data (identity anchored to our authentication provider), profile and photo data, messages, subscription and payment records held with our payment provider (Stripe), verification status, and moderation, report, and appeal records. We can only produce data we actually hold; we do not have access to data held solely by third-party providers except as those providers allow, and we do not hold plaintext account passwords. Categories are described in the Privacy Policy (/legal/privacy).
13. Authentication and Cost
Purpose. To explain verification of requests and costs. We may take steps to verify the authenticity of a request and the identity and authority of the requester before acting. Where the law permits, we may recover reasonable costs of responding to certain requests. We reserve the right to seek clarification, to object, or to challenge a request through appropriate legal channels. [Legal review required before publication - confirm authentication steps and any cost-recovery position.]
14. Records and Audit
Purpose. To explain record-keeping. Actions taken on a request can be recorded in our administrative audit trail. We are establishing a dedicated request register so that volumes and outcomes can be reported in the Transparency Report (/legal/transparency); until that register is in place, request statistics are not yet available. [Legal review required before publication - establish the request register and reporting.]
15. Policy Updates
Purpose. To explain changes. We may update these Guidelines as our processes and the law evolve, including to add a dedicated intake channel or request register. The current version and effective date are shown on this page. These Guidelines do not create rights for third parties and do not limit our legal obligations or our members' rights.
16. Contact
Purpose. To tell authorities how to reach us.
- Contracting entity: WiseWave Limited (Company Number 762171)
- Registered office: 39 Cooley Park, Dundalk, Co. Louth, A91 AP2V, Ireland
- Law enforcement requests: info@tirvea.com (subject line "Law Enforcement Request")
For data categories and processing, see the Privacy Policy (/legal/privacy); for retention and legal holds, the Data Retention Policy (/legal/data-retention); for child-protection specifics, the Child Safety Policy (/legal/child-safety).