W Social — Privacy Notice

Last updated: 20 March 2026

1. Who We Are

W Social AB, Malmgårdsvägen 63, 116 38 Stockholm, Sweden (“W Social”, “we,” “us,” or “our”) is the controller responsible for the processing of your personal data as described in this Privacy Notice.

W Social is a social network designed with a foundational commitment to user privacy. The platform requires that each account be associated with a verified human identity in order to maintain the integrity and authenticity of its user base. Notwithstanding this verification requirement, we do not collect, retain, or otherwise access information sufficient to ascertain the actual identity of our users. This approach ensures that identity verification and user privacy remain complementary objectives, enabling us to confirm the legitimacy of the accounts on our platform while preserving the anonymity of our users in accordance with applicable privacy principles. To achieve this objective, identity verification is performed by W Identity, a separate legal entity and separate controller under the EU General Data Protection Regulation (“GDPR”).

You can reach us at info@wsocial.eu and our Data Protection Officer at dpo@wsocial.eu with all privacy-related questions.

2. What This Privacy Notice Covers

This Privacy Notice explains how we process personal data in connection with the W Social platform.

3. What Personal Data We Process and How We Collect It

3.1 Data Collected Directly from You

Waitlist sign-up. If you sign up for our waitlist, we may collect your country, preferred handle, email address, and social profile links from other platforms, depending on what you choose to provide in the waitlist form.

Newsletter sign-up. If you sign up for our newsletter, we collect your email address.

Account usage data.

As the operator of a federated service built on the AT Protocol, we collect and process the following categories of personal data in connection with your use of our platform:

  • Identity and Account Information. Account handles, decentralized identifiers (DIDs), display names, biographical information, profile images, and timestamps of account creation and last activity.
  • User-Generated Content. Posts, replies, quote posts, and embedded media, including edits and deletions, along with associated metadata such as timestamps, language tags, content labels, mentions, hashtags, and embedded links.
  • Social Graph Data. Followed and follower relationships, mute lists, block lists, list memberships, and starter pack associations, including timestamps of creation and removal of such relationships.
  • Engagement and Interaction Data. Likes, reposts, bookmarks, thread participation, and reply structures, both created by you and received on content you have published.
  • Account Settings and Preferences. Content filtering preferences, language settings, notification preferences, accessibility configurations, login activity.
  • Search and Discovery Activity. Search queries submitted, accounts or topics browsed, and interactions with recommended or trending content.
  • Technical and Session Data. IP addresses, approximate geolocation, device and client application identifiers, user agent strings, session durations, access frequency, API request patterns, and error or rate-limiting events.

3.2 Data Received from W Identity

When you sign up for W Social, W Social collects the following data from W Identity via the W Identity app with your explicit approval: Your W Identity UUID (Universally Unique Identifier, which in itself does not reveal anything about you), your passport country, and your year of birth. W Social cannot access any other data from W Identity unless you explicitly approve it in the W Identity app.

3.3 Data Collected from Other Third Parties

W Social is based on the Authenticated Transfer Protocol (“AT Protocol”), a decentralized, open-source protocol for social networks that supports various types of services. The goal of the AT Protocol is to create a common technical standard to make various social networks and applications interoperable.

This enables us to integrate our platform with the social network Bluesky which is operated by Bluesky Social PBC, as well as other service providers using the AT Protocol. Content on Bluesky can be accessed via W Social.

4. Purposes and Legal Bases for Processing

We process your personal data for the purposes set out below, together with the corresponding legal basis:

PurposeCategories of DataLegal Basis
Verifying that you hold a valid W Identity account and creating your W Social accountW Identity UUID (Universally Unique Identifier), passport country, year of birthEntering into a contract (Art. 6(1)(b) GDPR)
Enabling you to share content and send messages to other users of the platform and other service providers using the AT ProtocolPosts, replies, quote posts, embedded media, direct messages, mentions, hashtags, profile information (handle, display name, bio, profile picture), and associated metadata such as timestamps and language tagsPerformance of a contract (Art. 6(1)(b) GDPR)
Receiving content from other service providers using the AT ProtocolAny public information you share with other service providers using the AT ProtocolOur legitimate interest in integrating our services with the services of other service providers using the AT Protocol (Art. 6(1)(f) GDPR)
Managing your waitlist registrationCountry, preferred handle, email address, social profile links (as provided)Entering into a contract (Art. 6(1)(b) GDPR)
Sending our newsletterEmail addressYour consent (Art. 6(1)(a) GDPR)
Platform security and fraud preventionIP addresses, session data, device identifiers, user agent strings, error and rate-limiting eventsOur legitimate interest in keeping our platform secure (Art. 6(1)(f) GDPR)
Moderation of illegal or harmful contentPost content, account identifiers, reported contentCompliance with legal obligations (Art. 6(1)(c) GDPR)
Compliance with legal obligationsAny data relevant to the specific legal obligationCompliance with legal obligations (Art. 6(1)(c) GDPR)

5. Recipients and Sharing of Personal Data

5.1 Processors

We use third-party service providers who act as our processors under the GDPR, such as an email marketing platform and a hosting provider.

5.2 Other Recipients

We share content you create on our platform with service providers who use the AT protocol, and in particular with Bluesky Social PBC, to enable you to interact with their users.

6. Retention of Personal Data

Your personal data will be stored by us and our service providers in accordance with applicable data protection laws to the extent necessary for the processing purposes set out in this Privacy Notice. Subsequently, we will delete your personal data in accordance with our data retention and deletion policy or take steps to properly render the data anonymous, unless we are legally obliged or permitted to keep your personal data longer (e.g. for legal compliance, tax, accounting or auditing purposes, or to detect and prevent illegal activity).

As far as legally permissible or required, we restrict the processing of your data instead of deleting it (e.g. by restricting access to it). This applies in particular to cases where we may still need the data for the performance of the contract or for the assertion of or defense against legal claims, or where such retention is otherwise required or permitted by law. In these cases, the duration of the restriction of processing depends on the respective statutory limitation or retention periods. The data will be deleted after the relevant limitation or retention periods have expired.

7. International Transfers of Personal Data

We only use third-party service providers who process your data within the European Economic Area or countries for which the European Commission has confirmed an adequate level of data protection via a so-called “adequacy decision”.

We share content you post on our platform with service providers who use the AT protocol, and in particular with Bluesky Social PBC. This may include a transfer of personal data outside of the European Economic Area. In these cases, we rely on Art. 49(1)(b) GDPR. The transfers are necessary to fulfil our contractual obligations under the user agreement.

8. Automated Decision-Making

We do not use technologies that are considered automated decision-making in the sense of Art. 22 GDPR.

9. Your Rights Under the GDPR

Under the GDPR, you have the following rights in relation to your personal data, subject to the conditions and exceptions set out in the GDPR:

Right of access (Article 15): You have the right to obtain confirmation as to whether your personal data is being processed and, where that is the case, to access the data and receive certain information about the processing.

Right to rectification (Article 16): You have the right to obtain the rectification of inaccurate personal data and, taking into account the purposes of the processing, to have incomplete personal data completed.

Right to erasure (Article 17): You have the right to obtain the erasure of your personal data in certain circumstances, such as where the data is no longer necessary for the purposes for which it was collected.

Right to restriction of processing (Article 18): You have the right to obtain restriction of processing in certain circumstances, such as where you contest the accuracy of the data.

Right to data portability (Article 20): Where processing is based on consent or on a contract and is carried out by automated means, you have the right to receive your personal data in a structured, commonly used, and machine-readable format and to transmit it to another controller.

Right to object (Article 21): Where processing is based on legitimate interests, you have the right to object to the processing on grounds relating to your particular situation.

Right to withdraw consent (Article 7(3)): Where processing is based on your consent, you have the right to withdraw your consent at any time, without affecting the lawfulness of processing based on consent before its withdrawal.

Right to lodge a complaint: You have the right to lodge a complaint with a data protection supervisory authority of your choice.

To exercise any of these rights, please contact us at info@wsocial.eu.

© 2026 W Social AB (559544-6690), Stockholm, Sweden - all rights reserved.