Last updated: 12 June 2026
W Social AB, Malmgårdsvägen 63, 116 38 Stockholm, Sweden, “W Social”, “we”, “us”, or “our”, is the controller responsible for the processing of personal data described in this Privacy Notice.
W Social provides a social networking service built for privacy, authenticity and interoperability. The platform requires each W Social account to be associated with a verified human identity in order to reduce abuse, impersonation and automated fake accounts.
Identity verification is performed by W Identity AB, a separate legal entity and separate controller under the EU General Data Protection Regulation, “GDPR”. W Social receives only limited verification attributes from W Identity, as described in this Privacy Notice. As part of the standard account creation flow, W Social does not receive your passport, selfie, full date of birth, passport number, legal name or full verified identity profile from W Identity.
However, W Social does process personal data about you when you use the platform. This includes account data, content, social graph data, interactions, technical data and other information described below. Information you choose to publish, link to, or share on W Social may also make you identifiable to other users or third-party services.
You can contact us at info@wsocial.eu. You can contact our Data Protection Officer at dpo@wsocial.eu for privacy-related questions.
This Privacy Notice explains how W Social processes personal data in connection with the W Social platform, including waitlist sign-up, newsletter sign-up, account creation, use of the platform, federation and interoperability with services using the AT Protocol.
This Privacy Notice does not describe how W Identity processes personal data for identity verification. W Identity is a separate controller and provides its own privacy notice.
Third-party services, including other services using the AT Protocol, are responsible for their own processing of personal data under their own privacy notices.
3.1 Data Collected Directly from You
Waitlist sign-up. If you sign up for our waitlist, we may collect your country, preferred handle, email address and social profile links from other platforms, depending on what you choose to provide in the waitlist form.
Newsletter sign-up. If you sign up for our newsletter, we collect your email address and related subscription metadata, such as consent timestamp, subscription status and unsubscribe status.
Account and profile information. When you create or use a W Social account, we process account handles, decentralized identifiers, “DIDs”, display names, biographical information, profile images, account settings, account status and timestamps of account creation, modification and last activity.
User-generated content. We process content you create, upload, publish or send through the platform. This may include posts, replies, quote posts, embedded media, direct messages where supported, edits and deletions, together with associated metadata such as timestamps, language tags, content labels, mentions, hashtags, embedded links, thread structure and visibility settings.
Social graph data. We process followed and follower relationships, mute lists, block lists, list memberships, starter pack associations and related timestamps.
Engagement and interaction data. We process likes, reposts, bookmarks, thread participation, replies, reports and other interactions, both created by you and received on content you have published. Some interactions may be public or federated, depending on the feature.
Account settings and preferences. We process content filtering preferences, language settings, notification preferences, accessibility settings, privacy settings, login activity and similar configuration data.
Search and discovery activity. We may process search queries, accounts or topics browsed, interactions with recommended or trending content and other discovery-related activity.
Technical, security and session data. We process IP addresses, approximate geolocation derived from IP address, device and client application identifiers, user agent strings, session durations, access frequency, API request patterns, error events, rate-limiting events and security events.
3.2 Data Received from W Identity
When you sign up for W Social, W Social receives limited data from W Identity through the W Identity app, with your approval. This may include your W Identity account identifier or UUID, passport country and year of birth.
The W Identity account identifier is used to confirm that the account is linked to a verified W Identity account and to help prevent duplicate or abusive account creation. W Social cannot access additional W Identity data unless you approve such sharing through the W Identity app.
3.3 Data Collected from Other Third Parties and Federated Services
W Social is based on the Authenticated Transfer Protocol, “AT Protocol”, a decentralized and open protocol for social networking and interoperability. The AT Protocol allows different services, clients, relays, app views and applications to exchange and display social networking data.
This means that public or federated content and associated metadata may be exchanged with, received from, indexed by, cached by, or displayed through other services using the AT Protocol, including Bluesky Social PBC and other AT Protocol service providers.
We may receive public profile data, public content, interaction data, social graph data and related metadata from other AT Protocol services where this is necessary to provide interoperability, discovery, federation, moderation, security or user-requested interactions.
3.4 Public and Federated Content
The W Social platform is designed to interoperate with other services. Some information you publish or make available through the platform may be public or federated by design. This means that it may be accessible to other users, third-party applications, AT Protocol infrastructure providers, search tools, archives or other services.
If you delete content from W Social, we will process the deletion within our own systems according to the functionality available to us. However, because of the federated and interoperable nature of the AT Protocol, copies, cached versions, screenshots, quotes, reposts, archives or records held by third parties may not be under our control and may not be deleted by W Social.
3.5 Special Categories of Personal Data
W Social does not require you to provide special categories of personal data, such as information about health, political opinions, religion, trade union membership, sexual orientation or similar information. However, you may choose to include such information in your profile, posts, messages or other content.
Where you choose to manifestly make such information public, processing may fall under Article 9(2)(e) GDPR. In other cases, we process such information only where necessary to provide the service, comply with legal obligations, enforce platform rules, protect users, or establish, exercise or defend legal claims, and only where a valid legal basis and applicable Article 9 condition are available.
We process your personal data for the purposes and legal bases set out below.
| Purpose | Categories of Data | Legal Basis |
|---|---|---|
| Managing waitlist registration and related pre-launch communication | Country, preferred handle, email address, social profile links, waitlist metadata | Steps prior to entering into a contract, Article 6(1)(b) GDPR, and where applicable legitimate interest, Article 6(1)(f) GDPR |
| Sending newsletters and marketing communication | Email address, consent status, subscription metadata | Consent, Article 6(1)(a) GDPR |
| Verifying that you hold a valid W Identity account and creating your W Social account | W Identity account identifier or UUID, passport country, year of birth, W Social account data | Performance of a contract, Article 6(1)(b) GDPR |
| Operating your W Social account and providing the platform | Account data, profile data, settings, preferences, login activity, content, social graph data, interaction data | Performance of a contract, Article 6(1)(b) GDPR |
| Publishing content and enabling interaction with other users and AT Protocol services | Posts, replies, quote posts, embedded media, profile data, social graph data, interaction data, metadata | Performance of a contract, Article 6(1)(b) GDPR |
| Sending and receiving direct messages where supported | Message content, sender and recipient identifiers, timestamps, delivery metadata | Performance of a contract, Article 6(1)(b) GDPR |
| Receiving, displaying and indexing content from other AT Protocol services | Public profile data, public content, social graph data, interaction data, metadata received from AT Protocol services | Legitimate interest in providing interoperable social networking, Article 6(1)(f) GDPR, and where applicable performance of a contract, Article 6(1)(b) GDPR |
| Search, discovery, recommendations and trending functionality | Search queries, browsing and interaction data, public content, account and topic metadata | Performance of a contract, Article 6(1)(b) GDPR, and legitimate interest in improving discovery and relevance, Article 6(1)(f) GDPR |
| Platform security, abuse prevention and fraud prevention | IP addresses, session data, device identifiers, user agent strings, access patterns, error events, rate-limiting events, security logs | Legitimate interest in keeping the platform secure and preventing misuse, Article 6(1)(f) GDPR |
| Moderation of illegal content, harmful content, spam and platform abuse | Account identifiers, content, reports, moderation metadata, enforcement history, technical and security data | Legal obligation, Article 6(1)(c) GDPR, where applicable, and legitimate interest, Article 6(1)(f) GDPR |
| Compliance with legal obligations | Data relevant to the specific legal obligation | Legal obligation, Article 6(1)(c) GDPR |
| Establishing, exercising or defending legal claims | Data relevant to the claim or dispute | Legitimate interest, Article 6(1)(f) GDPR, and where applicable Article 9(2)(f) GDPR |
Where we rely on legitimate interest, our legitimate interests include keeping the platform secure, preventing abuse and fraud, providing an interoperable social networking service, improving discovery and relevance, enforcing platform rules, protecting users and protecting our legal rights. You have the right to object to processing based on legitimate interests as described in section 10.
Providing the data required for account creation, including a valid W Identity verification status and the limited W Identity attributes described above, is necessary to create and use a W Social account. If you do not provide this information, we may not be able to create or maintain your W Social account.
Providing public profile information, posts, replies, media, follows, likes and similar social activity is optional, but some information is necessary to use the relevant platform features.
Providing an email address for the newsletter is optional. You may withdraw your newsletter consent or unsubscribe at any time.
Because W Social is an interoperable and federated service, choosing to publish or interact with content may result in that content and related metadata being shared with other services using the AT Protocol.
6.1 Processors
We use third-party service providers that process personal data on our behalf under data processing agreements. These may include hosting providers, email service providers, email marketing platforms, infrastructure providers, analytics providers, support providers, security service providers and content delivery providers.
These providers may only process personal data according to our documented instructions and must protect the data in accordance with applicable data protection law.
6.2 W Identity
W Identity AB is a separate controller for the identity verification service. W Social receives limited verification attributes from W Identity as described in this Privacy Notice. W Social does not receive your full identity verification file from W Identity as part of the standard account creation flow.
6.3 AT Protocol Services and Other Users
We share public and federated content, profile data, social graph data, interaction data and related metadata with other services and users where necessary to provide the W Social service and AT Protocol interoperability.
This may include Bluesky Social PBC, other AT Protocol service providers, client applications, relays, app views, moderation services, indexing services and users who access, interact with, store, quote, repost or otherwise process public or federated content.
Third-party services and users may be independent controllers for their own processing of personal data. W Social is not responsible for how independent third parties process personal data after they receive or access it, except where applicable law provides otherwise.
6.4 Authorities and Legal Recipients
We may disclose personal data where required by law, court order, or a binding request from a competent authority. We may also disclose personal data where necessary to establish, exercise or defend legal claims.
We store personal data only for as long as necessary for the purposes described in this Privacy Notice, unless we are legally required or permitted to retain it for a longer period.
Waitlist data. Waitlist data is retained until the waitlist purpose has been fulfilled, you withdraw your waitlist registration, or 30 days after the public launch of the service, unless we are legally required or permitted to retain it for longer.
Newsletter data. Newsletter data is retained for as long as you remain subscribed. If you unsubscribe, we may retain limited suppression or unsubscribe records to ensure that we do not send you further newsletters unless you resubscribe.
Account data. Account data is retained for as long as your W Social account remains active. If you delete your account, we delete or anonymise account data within 30 days, unless we are legally required or permitted to retain limited information for security, fraud prevention, dispute resolution, legal claims, accounting, audit or compliance purposes.
Public and federated content. Public and federated content is retained for as long as it remains published or as long as necessary to provide the W Social service. If you delete content, we will delete it or mark it as deleted in our own systems according to the functionality available to us. Because of the federated and interoperable nature of the AT Protocol, third parties may retain copies, cached versions, screenshots, quotes, reposts, archives or records that are outside W Social’s control.
Direct messages. Direct messages, where supported, are retained for as long as necessary to provide the messaging functionality, unless deleted by the relevant user or retained for security, abuse prevention, legal compliance or legal claims. The exact retention period depends on the technical design of the messaging feature and should be confirmed in the service documentation.
Security and technical logs. Security and technical logs are retained for 30 days, unless longer retention is necessary to investigate abuse, fraud, security incidents, technical errors, legal obligations or legal claims.
Moderation records. Moderation reports, enforcement history and related records may be retained for as long as necessary to enforce platform rules, prevent repeat abuse, comply with legal obligations, protect users, or establish, exercise or defend legal claims.
Legal and compliance records. Where data is needed to comply with legal obligations or to establish, exercise or defend legal claims, we may retain the relevant data for the applicable statutory retention or limitation period.
We aim to process and store personal data within the European Economic Area where possible.
Where our processors or service providers process personal data outside the European Economic Area, we ensure that an appropriate transfer mechanism is in place in accordance with Chapter V of the GDPR. This may include an adequacy decision by the European Commission, the European Commission’s Standard Contractual Clauses, and, where required, supplementary technical and organisational measures.
Because W Social is an interoperable service based on the AT Protocol, public and federated content may be accessed, received, stored, indexed, cached, displayed or otherwise processed by third-party services and users in countries outside the European Economic Area. This may include Bluesky Social PBC and other AT Protocol service providers.
Where W Social is responsible for a transfer of personal data outside the European Economic Area, we will rely on an appropriate transfer mechanism where required. Where you request interaction with a third-party AT Protocol service and no other transfer mechanism is available, the transfer may be necessary for the performance of the contract with you or for the implementation of pre-contractual measures at your request, Article 49(1)(b) GDPR. This derogation is used only where applicable.
You may contact us at info@wsocial.eu if you would like more information about the safeguards used for international transfers.
We may use automated technical systems to operate the platform, including spam detection, rate limiting, security monitoring, abuse prevention, content labelling, recommendation systems, search ranking and moderation support.
We do not make decisions based solely on automated processing that produce legal effects or similarly significant effects for you within the meaning of Article 22 GDPR.
Where automated systems are used to support moderation or account security, significant enforcement actions such as account suspension, account termination or similar restrictions may be subject to human review where required by law or where otherwise appropriate.
Subject to the conditions and exceptions set out in the GDPR, you have the following rights in relation to your personal data.
You have the right of access under Article 15 GDPR. This means that you may request confirmation as to whether we process personal data about you and receive information about that processing.
You have the right to rectification under Article 16 GDPR. This means that you may request correction of inaccurate personal data and completion of incomplete personal data.
You have the right to erasure under Article 17 GDPR. This means that you may request deletion of your personal data in certain circumstances, for example where the data is no longer necessary for the purposes for which it was collected.
You have the right to restriction of processing under Article 18 GDPR. This means that you may request that we restrict the processing of your personal data in certain circumstances.
You have the right to data portability under Article 20 GDPR. Where processing is based on consent or contract and carried out by automated means, you may request to receive your personal data in a structured, commonly used and machine-readable format and transmit it to another controller.
You have the right to object under Article 21 GDPR. Where processing is based on legitimate interests, you may object to the processing on grounds relating to your particular situation.
You have the right to withdraw consent under Article 7(3) GDPR. Where processing is based on your consent, you may withdraw your consent at any time. Withdrawal does not affect the lawfulness of processing carried out before the withdrawal.
You have the right to lodge a complaint with a supervisory authority. In Sweden, the relevant supervisory authority is Integritetsskyddsmyndigheten, IMY, the Swedish Authority for Privacy Protection. You may also lodge a complaint with another competent EU or EEA supervisory authority.
To exercise your rights, please contact us at info@wsocial.eu or dpo@wsocial.eu.
Please note that, because W Social is an interoperable and federated service, some personal data may also be processed by independent third-party services. You may need to contact those third parties directly to exercise your rights in relation to their independent processing.
We apply technical and organisational measures designed to protect personal data against unauthorised access, loss, misuse, alteration and disclosure. These measures include access controls, encryption where appropriate, logging, security monitoring, retention controls, separation of duties and abuse prevention measures.
You are responsible for keeping your account credentials, devices and recovery information secure.
We may update this Privacy Notice from time to time. The latest version of this Privacy Notice will always indicate the date on which it was last updated.
© 2026 W Social AB (559544-6690), Stockholm, Sweden - all rights reserved.