Last updated: 5 October 2026
of WAGENOW LTD, prepared under the UK General Data Protection Regulation — Regulation (EU) 2016/679 as retained in UK law by the Data Protection, Privacy and Electronic Communications (Amendments etc) (EU Exit) Regulations 2019 and as amended by the Data (Use and Access) Act 2025 (the “UK GDPR”) — together with the Data Protection Act 2018 and the Privacy and Electronic Communications (EC Directive) Regulations 2003 (PECR).
(hereinafter referred to as the “Privacy Policy”)
1. INTRODUCTORY PROVISIONS
1.1. These Privacy Policy terms of WAGENOW LTD, with its registered office at 71–75 Shelton Street, Covent Garden, London, United Kingdom, WC2H 9JQ, Company No. 16689420, registered with Companies House, England and Wales, as the Provider, govern the principles of personal data protection related to the collection and processing of data arising from contractual and related relationships between the Provider and the Recipient, as defined below.
1.2. This Privacy Policy explains what information the Provider — as data controller of WageNow™ products and services — collects and processes about the Recipient, and describes the technical and organisational measures in place to protect that data.
1.3. The Provider processes the Recipient’s Personal Data primarily on the lawful basis of performance of a contract (UK GDPR Article 6(1)(b)) to which the Recipient is a party — namely, the Agreements referred to in this Privacy Policy. Additional lawful bases relied on for specific processing activities are set out in Section 4.
1.4. Where processing is based on the Recipient’s consent (for example, direct marketing communications or non-essential cookies), that consent is separate from these terms and may be withdrawn at any time by contacting the Provider using the details in Section 1.5.
1.5. The Provider’s contact details are:
General enquiries: info@wagenow.co.uk
Customer support and data protection queries: help@wagenow.com
Registered office: 71–75 Shelton Street, Covent Garden, London WC2H 9JQ, United Kingdom
1.6. This Privacy Policy applies to all natural persons whose Personal Data the Provider processes in the course of providing the WageNow™ services, including: (a) individuals who use the WageNow service through their Employer (referred to in this Privacy Policy as “Recipients“); (b) individuals acting for or on behalf of an Employer or business partner — such as directors, employees, contact persons and beneficial owners — whose Personal Data the Provider receives or processes in connection with an Agreement; and (c) individuals at UK companies and LLPs whom the Provider approaches about its services, as described in Section 5 below. In case of any conflict between this Privacy Policy and a specific data-processing arrangement in an executed Agreement, the executed Agreement prevails.
2. DEFINITIONS
The terms defined in this section shall have the meanings set forth herein for the purposes of this Privacy Policy or in any other documents referred to by this Privacy Policy, unless otherwise stated in such documents:
Application refers to the Provider’s application under the name WageNow, which can be used either as a mobile application (hereinafter also “Mobile Application”) after being installed on a Device, or as a web application accessible through the Website (hereinafter also “Web Application”). The Application serves the following purposes:
a) creating the Recipient’s personal Account,
b) logging into the Recipient’s Account,
c) displaying Statements.
WageNow service means the arrangement under which employees of participating Employers who opt in receive a payment from the Provider on their normal pay date, equal to the part of their pay that falls due later. The Employer pays that deferred pay to the Provider, when due, on the Recipient’s instruction.
Account refers to the user account created for the Recipient by the Provider and subsequently activated by the Recipient in the Application. It is protected by the Recipient’s login credentials (email and password) and is used to access the Application and the services provided through it.
Personal Data refers to the data defined in Article 3.1 of this Privacy Policy.
Statement is the information about the Recipient’s use of the WageNow service, including amounts of pay deferred and their stated due dates. Statements are visible to the Recipient in the Application after logging into their Account.
Recipient means a natural person employed by an Employer who has opted in to use the WageNow service on the agreed conditions.
Provider refers to the operator of the WageNow service. The Provider owns the copyright and other intellectual property rights related to the Application and acts as the data controller of Personal Data for UK data subjects. The Provider is WAGENOW LTD, with its registered office at 71–75 Shelton Street, Covent Garden, London WC2H 9JQ, United Kingdom, Company No. 16689420, registered with Companies House, England and Wales.
Complaint refers to a submission by the Recipient to the Provider concerning the accuracy or quality of the services provided under the Agreements.
Website means the Provider’s website: wagenow.co.uk.
Device refers to a mobile phone, tablet, PC, or any other device with internet access that meets the hardware and software requirements necessary to use or install the Application.
Employer refers to the company that employs the Recipient and which has entered into an agreement with the Provider concerning the rights and obligations related to the provision of the WageNow service in respect of its employees.
Agreements refer to the contracts concluded between the Recipient, the Employer and the Provider in connection with the WageNow service, including in particular the Recipient’s deferral agreement and payment instruction, and the Employer’s agreement with the Provider.
3. PROCESSED PERSONAL DATA
3.1. The Provider processes the following categories of personal data:
a) Identification data of the Recipient provided by the Employer (e.g., first and last name, date of birth)
b) Contact details (e.g., email address, phone number)
c) Information from communication between the Recipient and the Provider, if such information qualifies as personal data under the UK GDPR or the Data Protection Act 2018 (e.g., email, chat, SMS messages, notifications)
d) Data related to the use of the Application and services provided through it (e.g., statistical data on how the Application is used; information on Account usage)
e) Transaction data (e.g., the Recipient’s bank account number)
f) Payroll data (e.g., salary information, hours worked, amounts of pay deferred under the WageNow service and their stated due dates)
g) Other data and information necessary to generate Statements (to the extent of the data included in such Statements)
h) Technical data about the device from which the Recipient logs in and manages the Account through the Application (e.g., IP address, device operating system, browser settings, Application settings, cookies)
i) Other Personal Data if the Recipient voluntarily enters additional personal information in their Account.
3.2. The Recipient’s Personal Data is provided to the Provider either by the Recipient themselves or by the Employer.
3.3. The Recipient acknowledges that they are obliged to always provide accurate and truthful Personal Data and to inform the Provider and their Employer without undue delay about any changes.
3.4. Some Personal Data is required in order to enter into or perform the Agreements and for the Provider to comply with its legal obligations (in particular under UK tax and company law). Where a data element is identified as required — marked as such in the Application or in an Agreement — the Recipient’s refusal or failure to provide it will mean the Provider cannot: (a) create or maintain the Recipient’s Account, (b) enable the Recipient’s use of the WageNow service, or (c) comply with its legal obligations. In those cases the Provider may decline to onboard the Recipient, suspend the Recipient’s Account, or terminate the Agreements. Data marked as optional may be withheld without consequence to the Recipient’s access to the core service.
3.5. The WageNow service is intended for adults in employment. The Provider does not knowingly collect Personal Data of persons under the age of 16. If the Provider becomes aware that Personal Data of a person under 16 has been collected without appropriate authorisation from a person holding parental responsibility, that data will be deleted without undue delay.
4. PURPOSES OF PROCESSING AND RETENTION PERIOD OF PERSONAL DATA
4.1. The Provider processes the Recipient’s Personal Data under the UK GDPR on the basis of:
(i) performance of Agreements,
(ii) compliance with legal obligations,
(iii) the Provider’s legitimate interests, and/or
(iv) the Recipient’s legitimate interests.
4.2. In accordance with the Regulation, the Provider processes the Recipient’s Personal Data mainly for the following purposes:
(i) Identification and verification of the Recipient’s identity: The Provider identifies and verifies the Recipient to provide services under the Agreements through the Application. Personal Data is processed on the basis of contract performance (UK GDPR Article 6(1)(b)) and, where applicable, legal obligation (Article 6(1)(c)). Data is retained for the duration of the Agreements and for six years after their termination, reflecting the Provider’s obligations under UK tax and company law and the limitation period for contract and tort claims in England and Wales.
(ii) Use of the Application and provision of the WageNow service: Personal Data is processed as part of contract performance (UK GDPR Article 6(1)(b)). Transactional and account records are retained for the duration of the Agreements and for six years after their termination, reflecting the Provider’s obligations under UK tax and company law and the limitation period for contract and tort claims in England and Wales.
(iii) Communication with the Recipient and handling complaints and claims: The Provider processes Personal Data for handling Recipient inquiries, suggestions, complaints, and claims. Data is processed as part of contract performance and is retained for the duration of the Agreements and six years thereafter, consistent with the limitation period for contract and tort claims in England and Wales.
(iv) Fraud monitoring and prevention: The Provider processes Personal Data of the Recipient and potentially of other individuals to monitor Application usage and detect fraud, in order to protect both its own and the Recipient’s interests. This processing is based on the Provider’s legitimate interest in preventing fraud and financial crime and in protecting its business, its Recipients and its Employer partners (UK GDPR Article 6(1)(f)), balanced against the Recipient’s rights and freedoms. Data is retained during the Agreements and for six years thereafter, or longer if a fraud case, investigation or dispute remains open.
(v) Improvement of the Application: This processing is based on the Provider’s legitimate interest in improving, securing and developing its services (UK GDPR Article 6(1)(f)). Data is retained for the duration of the Agreements and, wherever practical, is aggregated or pseudonymised so that individual Recipients cannot be identified.
(vi) Resolution of legal disputes involving the Provider: The Provider may process Personal Data of the Recipient and others to assert, enforce, or defend legal claims. This processing is based on the Provider’s legitimate interest in exercising and defending its legal rights (UK GDPR Article 6(1)(f)) and, where relevant, on legal obligation. Data is retained for the duration of any dispute and thereafter for the applicable limitation period under the Limitation Act 1980 (generally six years for contract and tort claims in England and Wales).
(vii) Direct marketing: The Provider processes the Recipient’s Personal Data to inform them about relevant services and products. For business (B2B) contacts acting in a corporate capacity, this is based on the Provider’s legitimate interest in marketing its services to relevant business audiences (UK GDPR Article 6(1)(f)). For individual (B2C) contacts, marketing communications by electronic means (email, SMS or automated calls) are sent only where the Recipient has given prior, specific consent (UK GDPR Article 6(1)(a)) or, in relation to the Provider’s own similar products and services following an initial enquiry or contract, under the “soft opt-in” in regulation 22(3) of PECR. Every marketing communication contains a clear and free-of-charge means to opt out; the Recipient can also opt out at any time by contacting help@wagenow.com. Marketing preference records are retained for as long as the Recipient remains engaged with the Provider and for up to three years after the last positive engagement; if the Recipient objects to marketing, a suppression record is retained indefinitely for the sole purpose of honouring that objection. This paragraph does not apply to business contacts that the Provider approaches about its services: section 5 applies to them, including its 12-month retention period.
(viii) Compliance with the Provider’s archiving and statutory retention obligations — including UK tax law (HMRC record-keeping requirements) and the Companies Act 2006 (for statutory books and records).
4.3. When processing Personal Data based on the Provider’s legitimate interest, all necessary steps will be taken to ensure that the impact on the Recipient’s privacy is minimised and that a balance is maintained between the Provider’s legitimate interests and the Recipient’s right to privacy.
4.4. The Provider will retain data, including Personal Data, for the periods mentioned above, unless a longer retention period is required by law. Once the retention period expires, the Provider will delete the Personal Data.
4.5. If the Recipient does not complete Account activation, Personal Data collected during the incomplete registration will be deleted no later than 365 days after the last registration step, unless a longer retention period is required by law.
4.6. Personal Data is processed either electronically in an automated manner or manually. The Provider does not carry out solely automated individual decision-making that produces legal effects on the Recipient or similarly significantly affects them, within the meaning of Article 22 of the UK GDPR, without meaningful human review. Where automated processing forms part of an eligibility or fraud-detection step, a member of the Provider’s team reviews any adverse outcome before it takes effect. The Recipient retains the rights under Article 22 to obtain human intervention, to express their point of view, and to contest the decision — they may exercise these rights by contacting the Provider at help@wagenow.com.
5. BUSINESS CONTACTS WE APPROACH ABOUT OUR SERVICES
5.1. The Provider may contact people at UK companies and LLPs about WageNow’s services. For this the Provider uses their name, job title, business email address, business phone number where the Provider has it, and the company they work for.
5.2. The Provider obtains these details from Companies House, company websites and other published sources, and business-contact data providers.
5.3. The Provider uses these details to tell businesses about its services, on the basis of the Provider’s legitimate interest in marketing to business audiences (UK GDPR Article 6(1)(f)). The Provider shares them only with the service providers that send its emails and host its records.
5.4. You can object at any time by replying “no” to any of the Provider’s emails or by writing to help@wagenow.com, and the Provider will stop contacting you.
5.5. The Provider keeps these details for up to 12 months after the last contact, unless the Provider is in discussions with your company or your company becomes a customer. If you object, the Provider keeps a minimal record so that it does not contact you again.
6. COOKIES
6.1. The Provider uses cookies when the Application and Website are used. Cookies are small data files stored on the Recipient’s Device upon visiting the Website or logging into the Account. Some cookies — including those used for analytics and marketing — may contain identifiers that constitute personal data under the UK GDPR. Detailed information about the specific cookies the Provider uses, their purposes, retention, and how to control them is available in the Cookie Policy.
6.2. As part of cookie and analytics usage, the Provider may record: the URL visited, the Recipient’s IP address, an approximate location derived from that IP address at country or region level (the Provider does not collect precise GPS location without separate consent), the browser type and language, hostname, screen resolution, time zone, type of Device, and the date and time of the visit, together with information on which part of the Website or Application was accessed.
6.3. Strictly-necessary cookies are set without consent, as permitted under the Privacy and Electronic Communications Regulations 2003 (PECR). All other cookies (analytics, marketing, and preference) are set only after the Recipient has given prior, specific, informed and unambiguous consent through the cookie banner presented on first visit to the Website. The Recipient can review and change their cookie preferences at any time via the “Cookie Settings” link in the Website footer, or by managing cookies in their browser settings.
7. DISCLOSURE OF PERSONAL DATA
7.1. The Provider may disclose Personal Data to other trusted entities if necessary for the performance of Agreements, if the Recipient has given consent for such disclosure, or if there is another legal basis for sharing the Personal Data—such as the Provider’s legal obligations. These trusted parties may include, for example:
- the Employer, for the provision of the WageNow service,
- payment service providers and banks used to make and receive payments in connection with the WageNow service,
- KYC and identity-verification providers,
- cloud infrastructure and hosting providers for the Application, the Website and supporting databases,
- email, messaging and SMS gateway providers for transactional and support communications,
- web analytics providers, only where the Recipient has consented to non-essential cookies,
- customer support, CRM and ticketing providers,
- accounting, tax, audit and legal advisers,
- regulators, courts and law-enforcement authorities, where the Provider is required by law to disclose Personal Data.
A current list of the Provider’s material sub-processors is maintained by the Provider and is available on request by contacting help@wagenow.com. Each sub-processor is bound by a written data-processing agreement compliant with Article 28 of the UK GDPR.
7.2. Personal Data will be shared only to the minimal and necessary extent required for the stated purposes.
7.3. Where Personal Data is transferred outside the United Kingdom, the Provider ensures that appropriate safeguards are in place as required by the UK GDPR. Transfers to countries covered by the UK’s adequacy regulations (including the European Economic Area) do not require additional safeguards. For transfers to other jurisdictions, the Provider relies on the International Data Transfer Agreement (IDTA) issued by the Information Commissioner’s Office, or the UK Addendum to the EU Standard Contractual Clauses. The Recipient may request a copy of the relevant safeguard by emailing help@wagenow.com.
7.4. The Provider engages WageNow, s.r.o. (a company registered in the Slovak Republic in the Commercial Register of the District Court Bratislava I, Section: Sro, File No. 158682/B) as a data processor to operate and maintain the Application, Website, and supporting technical infrastructure on the Provider’s behalf and on the Provider’s documented instructions. WageNow, s.r.o. processes Personal Data only for the purposes and on the terms set out in a written Data Processing Agreement compliant with Article 28 of the UK GDPR. Transfers of Personal Data from the Provider (United Kingdom) to WageNow, s.r.o. (Slovak Republic, European Economic Area) are covered by the UK’s adequacy regulations for the EEA and require no additional transfer safeguard beyond the Article 28 contract.
8. DATA SECURITY
8.1. The Recipient’s Personal Data is adequately protected against loss, destruction, alteration, misuse, unauthorised disclosure, transmission, and/or processing through appropriate technical and organisational measures. These measures are implemented with consideration for the current state of technology, the costs of implementation, the nature, scope, context, and purposes of processing, as well as the level of risk to the rights and freedoms of natural persons.
8.2. To ensure the required level of security, the Provider has implemented the following technical and organisational measures, internal control systems, and IT protection mechanisms, including but not limited to:
- Device security (e.g., use of usernames and passwords),
- Data encryption (e.g., SSL certificates),
- Restrictions on the retention, handling, and/or disposal of data,
- Regular data backups and restoration procedures,
- Role-based access controls and the principle of least privilege for staff and processors,
- Staff training on data protection and information security, and confidentiality obligations under employment or engagement terms.
8.3. In the event of a personal data breach, the Provider will assess the likelihood and severity of the risk to the Recipient’s rights and freedoms. Where the breach is likely to result in a risk to the Recipient’s rights and freedoms, the Provider will notify the Information Commissioner’s Office (ICO) without undue delay and, where feasible, no later than 72 hours after becoming aware of the breach, in accordance with Article 33 of the UK GDPR. Where the breach is likely to result in a high risk to the Recipient’s rights and freedoms, the Provider will also notify the affected Recipients without undue delay, in accordance with Article 34 of the UK GDPR. The Provider maintains an internal record of all personal data breaches, whether notified or not, in accordance with Article 33(5).
9. RECIPIENT’S RIGHTS RELATED TO THE PROCESSING OF PERSONAL DATA
9.1. In connection with the processing of Personal Data, the Recipient has the following rights:
(i) Right of access to Personal Data (Article 15 of the UK GDPR):
The Recipient has the right to request information from the Provider about whether or not their Personal Data is being processed, as well as details regarding the purposes of the processing, the categories of processed Personal Data, recipients or categories of recipients, etc. The Recipient also has the right to request a copy of the Personal Data being processed.
(ii) Right to rectification or completion of Personal Data (Article 16 of the UK GDPR):
The Recipient has the right to request the correction of inaccurate or the completion of incomplete Personal Data.
(iii) Right to erasure of Personal Data – the “Right to be forgotten” (Article 17 of the UK GDPR):
The Recipient has the right to request that the Provider erase their Personal Data without undue delay in specific cases, such as when the data is no longer necessary for the purposes for which it was collected or otherwise processed; when consent is withdrawn; when the data has been processed unlawfully; or when there is a legal obligation to delete the data. The Provider will carry out such deletion upon review and validation of the Recipient’s request.
(iv) Right to restriction of processing (Article 18 of the UK GDPR):
The Recipient may request restriction of Personal Data processing, for example: if the accuracy of the Personal Data is contested (for the period during which the Provider verifies its accuracy); if the Provider no longer has a legal basis for processing but the Recipient requests restriction instead of erasure; or if the data is needed by the Recipient for the establishment, exercise, or defence of legal claims.
(v) Right to data portability (Article 20 of the UK GDPR):
The Recipient has the right to receive their Personal Data in a structured, commonly used, and machine-readable format, and to transfer it to another controller, provided that the data was collected based on a contract or the Recipient’s consent and is processed by automated means.
(vi) Right to object (Article 21 of the UK GDPR):
The Recipient has the right to object, on grounds relating to their particular situation, to the processing of Personal Data where it is based on a legitimate interest or carried out in the public interest, including profiling based on such grounds.
(vii) Right not to be subject to automated individual decision-making, including profiling (Article 22 of the UK GDPR):
The Recipient has the right not to be subject to a decision based solely on automated processing, including profiling, which produces legal effects or significantly affects them. This right does not apply if the decision:
a) is necessary for entering into or performing a contract between the Recipient and the Provider,
b) is authorised by UK law which also lays down suitable measures to safeguard the data subject’s rights and freedoms and legitimate interests;
c) is based on the Recipient’s explicit consent.
(viii) Right to withdraw consent (Article 7 of the UK GDPR):
The Recipient has the right to withdraw their consent to the processing of Personal Data at any time, provided the data was originally processed based on consent.
(ix) Right to lodge a complaint with a supervisory authority (Article 77 of the UK GDPR):
The Recipient has the right to lodge a complaint with the Information Commissioner’s Office (ICO):
Information Commissioner’s Office
Wycliffe House, Water Lane
Wilmslow, Cheshire SK9 5AF, United Kingdom
Phone: 0303 123 1113
Email: icocasework@ico.org.uk
Website: ico.org.uk
9.2. The Recipient may contact the Provider at any time to inquire about the processing of their Personal Data via email at help@wagenow.com. The Provider will respond within one month, extendable by up to two further months for complex or numerous requests, as permitted by UK GDPR Article 12(3). No fee is payable unless the request is manifestly unfounded or excessive, in which case the Provider may charge a reasonable fee or refuse to act on the request.
9.3. The Provider will only provide information regarding the processing of Personal Data upon receiving a request from the Recipient that includes all necessary information and supporting documents required for processing the request and verifying its legitimacy. The Provider must also be able to reliably verify the identity of the Recipient. Without successful identity verification, the Provider is not obligated to provide any information regarding Personal Data processing. This procedure is in place to prevent unauthorised access to the Recipient’s Personal Data and to protect their rights from being violated by unauthorised parties.
9.4. The Provider has not appointed a Data Protection Officer. Under Article 37 of the UK GDPR, appointment of a Data Protection Officer is not mandatory in the Provider’s circumstances (the Provider is not a public authority, does not carry out large-scale regular and systematic monitoring of data subjects as its core activity, and does not process special-category or criminal-conviction data on a large scale as its core activity). All data protection queries — including subject access requests, deletion requests, and complaints — should be directed to help@wagenow.com.
10. FINAL PROVISIONS
10.1. The Provider may update this Privacy Policy from time to time, in particular in response to changes in legislation, regulatory guidance, or the Provider’s services. The current version is always available on the Website and within the Application, and the “Last updated” date at the top shows when the Policy was last changed. Where the Provider makes a material change (in particular to the methods, purposes, or lawful bases of processing, or to the categories of recipients or international transfers), the Provider will notify the Recipient by email (where an email address is on file) and by prominent notice on the Website and in the Application, at least 14 days before the change takes effect. Non-material changes take effect on publication.
10.2. The Provider handles the Recipient’s Personal Data with the utmost care and respect, processes it in accordance with applicable legal regulations, and applies available technical safeguards. If the Recipient has any questions regarding Personal Data protection that are not answered in this Privacy Policy, they are entitled to contact the Provider at: help@wagenow.com.