Privacy Policy
Last updated: 27/07/2026
This privacy policy (“Policy”) applies to Weave Services Limited along with its affiliates and was last updated on the 21st of July, 2026.
We may change or update this Policy at any time, and the same will be updated on the website. Please read such notices carefully.
We believe you should always know what data we collect from you, the purposes for which it is used, and that you should have the ability to make informed decisions about what you share with us.
Therefore, we want to be transparent about:
- how and why we collect, store, and use your personal data in the various capacities in which you interact with us; and
- the rights you have to determine the contours of this interaction.
While we strongly advise you to read this Policy in full, the following summary gives you a snapshot of the salient points covered herein:
- This Policy details the critical aspects governing your personal data relationship with Weave Services Limited, having its registered office at 7/F, TAL Building, 49 Austin Road, Hong Kong, and its affiliates that operate the Weavenow.com website.
- For any clarifications or support, please feel free to reach out to us at
- This Policy clarifies the rights available to you with respect to the personal data you share with us.
If you have any queries or concerns with this Policy, please contact our Data Protection Officer (refer to Section 11). If you do not agree with the Policy, we advise you not to visit or use the Weavenow website.
1. What Data We May Collect
- The name and email of the person;
- Company name.
2. How and Why We Use It
We collect this data to facilitate the provision of our Services, respond to your enquiries, and may also use it for marketing purposes.
For the avoidance of doubt, in the event we anonymise and aggregate information collected from you, we will be entitled to use such anonymised data freely, without any restrictions other than those set out under applicable law.
You can unsubscribe from marketing communications at any time by contacting us at weave@weavenow.com.
3. Use of Artificial Intelligence
We do not use customer personal data to train external AI models or for any purpose beyond the agreed scope of our Services. Any personal data processed by our AI systems is handled in compliance with applicable data protection laws, including the GDPR where relevant.
4. Your Rights and Preferences as a Data Subject
Subject to the GDPR and applicable law’s limitations, the rights afforded to you as a data subject are:
- Right to be Informed: You have a right to be informed about the manner in which any of your personal data is collected or used, which we have endeavoured to do by way of this Policy.
- Right of Access: You have a right to access the personal data you have provided by requesting us to provide you with the same.
- Right to Rectification: You have a right to request us to amend or update your personal data if it is inaccurate or incomplete.
- Right to Erasure: You have a right to request us to delete your personal data.
- Right to Restrict: You have a right to request us to temporarily or permanently stop processing all or some of your personal data.
- Right to Object: You have a right, at any time, to object to our processing of your personal data under certain circumstances. You have an absolute right to object to us processing your personal data for the purposes of direct marketing.
- Right to Data Portability: You have a right to request us to provide you with a copy of your personal data in electronic format and you can transmit that personal data for using another third party’s product or service.
- Right not to be Subject to Automated Decision Making: You have a right not to be subject to a decision based solely on automated decision making, including profiling.
- Right to Consent Withdrawal: You have the right to withdraw your consent at any time where rely on your consent to process your personal data. Withdrawal of consent will not affect the lawfulness of any processing carried out before you withdraw your consent.
In case you wish to exercise the rights set out above, please contact our Data Protection Officer whose details are set out in Section 11 below.
5. Grounds for Processing
The data provided by you will be processed by us for the purpose of rendering Services to you, or in order to take steps prior to rendering such Services at your request. Where such data is not being used by us to render Services to you, we shall explicitly seek your consent for using the same. You can withdraw this consent at any time by contacting our Data Protection Officer.
Additionally, we may process your data to serve legitimate interests. Accordingly, the grounds on which we engage in processing are as follows:
| Nature of Data | Grounds |
| Account Registration Data | Compliance with applicable laws; Legitimate Interest |
If you believe we have used your personal data in violation of the rights above or have not responded to your objections, you may lodge a complaint with your local supervisory authority.
Additionally, please note:
- If you are a Customer or User using one of our Services to collect data about an EU data subject from third parties, it shall be your sole obligation to inform such data subject about the source of such data.
- We do not collect any Special Categories of Personal Data. Further, you agree and acknowledge that you shall not, under any circumstances, whether directly or indirectly, use our Services to collect or process Special Categories of Personal Data or transfer such data to us.
- The term “Special Categories of Personal Data” shall have the meaning ascribed to it under the GDPR and shall include, without limitation, data pertaining to a data subject’s race, ethnic origin, genetics, political affiliations, biometrics, health, or sexual orientation.
6. EU Representative
In accordance with Article 27 of the GDPR, FABRICiQ has appointed an EU representative to act as a point of contact for data subjects and supervisory authorities in the European Union on matters relating to the processing of their personal data.
EU Representative Details:
- Name: Amos Tin
- Address: 11 Eastbourne Crescent, Stockport, Manchester, United Kingdome SK58BJ
- Email: amostin@weavenow.com
Data subjects in the EU may contact the EU representative directly with any queries regarding the processing of their personal data by FABRICiQ.
7. Retention of Personal Information
We will store any personal data we collect from you for as long as it is necessary in order to facilitate your use of the Services and for ancillary legitimate and essential business purposes. These include, without limitation, improving our Services, attending to technical issues, and dealing with disputes.
The criteria we use to determine our retention periods include:
- The length of time we maintain an ongoing relationship with you, and the period thereafter during which we may have a legitimate need to reference your personal information to address issues that may arise
- Whether we are subject to a legal obligation requiring us to retain certain records for a specific period before we can delete them
- Whether retention is advisable in light of our legal position, such as applicable statutes of limitations or potential disputes
We may need to retain your personal data even if you seek deletion thereof, if it is needed to comply with our legal obligations, resolve disputes, and enforce our agreements.
8. Transfer of Information
In order to facilitate our operations, we may transfer and store the data we collect and process in accordance with this Policy to our database servers in different geographical regions for service delivery, redundancy, and disaster recovery purposes.
FABRICiQ uses Amazon Web Services (AWS) as its primary cloud infrastructure provider. Customer data is stored in the AWS region selected to match the Customer’s geography and applicable regulatory requirements. For example, data of EU and UK-based Customers is hosted within AWS regions located in the United Kingdom or the European Economic Area, as applicable.
Your rights and protections will, under no circumstances, be diluted by any transfer.
9. Compelled Disclosure
In addition to the purposes set out in this Policy, we may disclose any data we collect or process from you if it is required:
- Under applicable law or to respond to a legal process, such as a search warrant, court order, or subpoena;
- To protect our safety, your safety, or the safety of others, or in the legitimate interest of any party in the context of national security, law enforcement, litigation, criminal investigation, or to prevent death or imminent bodily harm;
- In connection with legal proceedings brought against FABRICiQ, its officers, employees, affiliates, customers, or vendors; or
- To establish, exercise, protect, defend, and enforce our legal rights.
10. Security of Your Personal Information
We implement industry-standard technical and organisational measures by using a variety of security technologies and procedures to help protect your data from unauthorised access, use, loss, destruction, or disclosure. When we collect particularly sensitive data, it is encrypted using industry-standard cryptographic techniques including but not limited to SSL, TLS, RSA, and AES.
We adhere to the ISO/IEC 27001:2022 standard, an internationally recognised framework for Information Security Management Systems (ISMS). Our commitment to ISO 27001 ensures that we follow rigorous security practices and maintain high standards for information security.
The following reasonable security practices and procedures are in place to protect your personal data:
| Measure | Description |
| Access Control | Access to personal data is granted only to authorised personnel on a need-to-know basis, and such access is logged and monitored. |
| Data Encryption | Sensitive personal data is encrypted both in transit and at rest using strong encryption methods such as AES-256. |
| Network Security | Secure network architecture, including firewalls and intrusion detection systems, prevents unauthorised access. |
| Regular Audits | Regular security audits and assessments identify potential vulnerabilities and ensure compliance with our security policies. |
| Incident Management | Established protocols for managing and responding to security incidents, including data breaches, mitigate any potential impact on your personal data. |
| Employee Training | Regular training programs for our employees ensure they are aware of and comply with our security policies and procedures. |
| Third Party Compliance | Third-party service providers who handle personal data on our behalf adhere to equivalent security standards and practices. |
| Physical and Environmental Security | Robust physical security controls protect our data centres and other facilities from unauthorised access, damage, and interference. |
| Business Continuity Management | Tested business continuity plans ensure the availability of critical information and systems in the event of a disruption, including Multi AZ deployment for database resilience. |
| Risk Assessment and Treatment | Regular risk assessments identify potential security threats and vulnerabilities, and appropriate risk treatment plans mitigate identified risks. |
| Audit and Compliance | Regular internal and external audits ensure compliance with ISO 27001 standards and continuously improve our ISMS. |
11. Data Protection Officer and Grievance Contact
The name and contact details of our Data Protection Officer, whom you may contact if you have any concerns, complaints, or feedback pertaining to this Policy, or if you wish to exercise any of your rights under this Policy, are as follows:
Data Protection Officer:
- Name: Aravind Nambiar
- Address: 7/F, TAL Building, 49 Austin Road, Jordan, Hong Kong
- Email: aravindnambiar@weavenow.com
We will respond to your request within a reasonable timeframe and in accordance with applicable law.