Skip to main content

PRIVACY POLICY OF WEAVIATE B.V.

This is the privacy policy of Weaviate B.V. (“Weaviate”, “we”, and “our”). Weaviate is a private limited company, established at the Prinsengracht 769A in Amsterdam, the Netherlands. Weaviate is responsible for the collection and use of your personal data as described in this privacy policy. 


1. What is the purpose of this Privacy Policy?


At Weaviate we respect your privacy and seek to protect the personal data we collect and use in accordance with applicable personal data protection legislation. Therefore, this privacy policy serves to clarify what personal data we collect, use, share, store and otherwise process in various situations, and how, why and on what legal basis we do so. 

What is relevant to you depends on your relationship with us. Therefore, this privacy policy is structured in a layered way to allow you to read only what is relevant to you. Therefore, please refer to:


Section 2, if you make use of our Weaviate products and services;


Section 3, if you visit our websites or complete forms on our websites;


Section 4, if you contact us;


Section 5, if you subscribe to or receive our newsletter.


The subsequent sections address general matters. More specifically, Section 6 clarifies what (third) parties may have access to or may receive your personal data. Furthermore, Section 7 informs you about the measures we have taken to protect your personal data and the period during which we store your personal data. In Section 8 you can read what rights you have in relation to your personal data and how you may exercise these rights. Finally, in Section 9, you can find our contact details in case you have any questions, remarks, or complaints regarding the processing of your personal data by us.


This privacy policy was most recently amended in February 2024 and this version replaces earlier versions. We may need to amend this privacy policy from time to time. The most recent version of this privacy policy is available on our website. In case of important changes, we will actively inform you on these changes. 


2. If you make use of Weaviate products and services


Weaviate is an open-source vector database that permits you to store data objects and vector embeddings. You may use our Weaviate vector database in different manners. You may use our open-source vector database technology yourself by deploying it within your own self-managed environment. You may also simplify your cloud management with our cloud solution called Weaviate Cloud, which we offer serverless (referred to as our “Serverless service”) or inside your customer managed VPC (referred to as our “BYOC service”).


What personal data Weaviate collects and uses depends on what product or service you use and how you use it, as further detailed below. Generally, Weaviate will offer its products and services to companies, rather than individuals. In such cases, we may still collect and use personal data, for instance of representatives or personnel of those companies or other users of our products and services. 


You may provide us with personal data relating to another individual than yourself, for example a colleague or a representative of the company you are working for. If this is the case, please provide the relevant individual with a copy of this privacy policy before providing us with this individual’s personal data.


a. If you download or use our open-source database, or if you use our Weaviate vector database via GCP or AWS marketplace, we do not process your personal data.


b. If you make use of our Serverless service, we process the following personal data, for the following purposes and on the following legal basis:


Type of dataPurposes
Information about you as a user. This includes your name, email address, company name, position, user rights, country of residence and the use case you are using Weaviate for. To supply our service, to manage our relationship with you (which may include notifying you about changes to our terms or policies), and to make suggestions and recommendations to you about goods or services that may be of interest to you.
Information about the device that you use to access Weaviate. This includes IP-addresses, device attributes and connection information.To supply our service, to supply our support, to improve our products and services, to ensure the security of our services, and to deal with possible complaints and disputes.
Information about your use of Weaviate. This includes the dates and times you access Weaviate, how you navigate inside the Weaviate environment, crash logs, and page load times.To supply our service, to supply our support, to improve our products and services, to improve our customer support.
Information about your organization. This includes the trade register number of your organization and bank information.To set up your contract, to contact the financial and procurement team, and to send invoices and collect payments.

For the processing of this personal data, we rely on the performance of our contract with you.

Although Weaviate may access personal data you store in the Weaviate database that is provided through our Serverless service, we are not responsible for the processing of such data. Instead, you (the relevant corporate customer) qualify as the sole data controller under the GDPR with respect to such personal data. If you are a consumer, please refer to the privacy policies of the relevant corporate customer for more information on how, why, and what personal data is processed in this regard. 


c. If you make use of our BYOC Offering, we process the following personal data, for the following purposes and on the following legal basis:


Type of dataPurposes
Information about you as a user. This includes: Contact information such as your name, the name of your organization and your email address. Billing information such as your preferred method of payment and your billing address.To supply our service, to send you our invoices, to match payments and claims, to manage (outstanding) payments, to collect outstanding and due payments, to deal with possible complaints and disputes, and to establish, defend and exercise our (legal) position.

For the processing of this personal data, we rely on the performance of our contract with you.


d. If you create an account on (one of) our websites, we may process the following personal data for the following purposes and on the following legal basis:


Type of dataPurposes
Your email address and any information you provide (please also refer to Section 3 in this perspective).To supply our service, to communicate with you, and for marketing purposes.

For the processing of this personal data, we rely on your consent.


3. If you visit our websites or complete forms on our websites


a. If you visit (one of) our websites (such as weaviate.io and console.weaviate.cloud), we process the following personal data, for the following purposes and on the following legal basis:


Type of dataPurposes
We process some types of personal data automatically, for instance by using cookies. For more information on how we use cookies, please refer to the information on cookies below.To supply our service, to improve our products and services, to improve our customer support, and for marketing purposes.
We also process some types of personal data that you voluntarily provide to us (please also refer to Section 3(b) in this perspective). This personal data is business-oriented and is limited to contact information that is necessary to maintain our relationship with you, such as your name, company name, job title, and email address.To contact you based on your request, to contact you with relevant offers or services, and for marketing purposes.

Cookies are small text files placed on a computer hard drive to record a visitor’s information such as user ID and browsing behavior. Our websites use cookies for analytical and functionality purposes that allow us to improve our websites based on visitor experience. Furthermore, we use cookies or similar technologies (such as web beacons and JavaScript) to analyze trends, administer the website, monitor how visitors navigate around the websites, and to gather demographic information about our user base as a whole. 

Below, you can read more about the cookies we use and why we use them.


  • Essential cookies: These cookies are strictly necessary to provide you with services available through our websites.

  • Performance cookies: These cookies are used to enhance the performance and functionality of our websites but are non-essential to their use. However, without these cookies, certain functionality may become unavailable.

  • Analytics cookies: These cookies collect information that is used either in aggregate form to help us understand how our websites are being used or how effective our marketing campaigns are, or to help us customize our websites for you.

  • Advertising cookies: These cookies are used to make advertising messages more relevant to you. They perform functions like preventing the same ad from continuously reappearing, ensuring that ads are properly displayed for advertisers, and in some cases selecting advertisements that are based on your interests.


Cookies categorized as “Embedded” may qualify as any of the above types and are used by third parties (e.g. YouTube). These cookies allow us to display embedded content (such as YouTube videos) on our websites. The data collected with embedded cookies is not visible to us, but we do ask for your prior consent before allowing these third parties to use them.


Weaviate.io


NameProviderPurposeDurationCategory
__cf_bmbeehiivCloudflare places the __cf_bm cookie on end-user devices that access customer sites protected by Bot Management or Bot Fight Mode. The __cf_bm cookie is necessary for these bot solutions to function properly.1 dayEssential
 cf_clearancebeehiivSpecifies the duration a website is accessible to a specific visitor after passing an access challenge.1 yearEssential
test_cookiedoubleclick.netUnclassified.1 dayEssential
VISITOR_PRIVACY_METADATAyoutube.comStores the user's cookie consent state for the current domain.180 daysEssential
XSRF-TOKENemailpig.comEnsures visitor browsing-security by preventing cross-site request forgery. This cookie is essential for the securityof the website and visitor.SessionEssential
CookieConsentweaviate.ioStores the user's cookie consent state for the current domain.1 yearPerformance
_hjAbsoluteSessionInProgressHotjarThis cookie is used to count how many times a website has been visited by different visitors - this is done by assigning the visitor an ID, so the visitor does not get registered twice.1 dayAnalytics
_hjFirstSeenHotjarThis cookie is used to determine if the visitor has visited the website before, or if it is a new visitor on the website.1 dayAnalytics
_hjIncludedInSessionSample_#HotjarCollects statistics on the visitor's visits to the website, such as the number of visits, average time spent on the website and what pages have been read.1 dayAnalytics
_hjSession_#HotjarCollects statistics on the visitor's visits to the website, such as the number of visits, average time spent on the website and what pages have been read.1 dayAnalytics
_hjSessionUser_#HotjarCollects statistics on the visitor's visits to the website, such as the number of visits, average time spent on the website and what pages have been read.1 yearAnalytics
tdgoogletagmanager.comRegisters statistical data on users' behavior on the website. Used for internal analytics by the website operator.SessionAnalytics
_gaGoogle AnalyticsRegisters a unique ID that is used to generate statistical data on how the visitor uses the website.2 yearsAdvertising
_ga_#Google AnalyticsUsed by Google Analytics to collect data on the number of times a user has visited the website as well as dates for the first and most recent visit.2 yearsAdvertising
_gcl_auGoogleUsed by Google AdSense for experimenting with advertisement efficiency across websites using their services.3 monthsAdvertising
elfsight_viewed_recentlycore.service.elfsight.comDetermines which products the user has viewed, allowing the website to promote related products.1 dayAdvertising
IDEdoubleclick.netUsed by Google DoubleClick to register and report the website user's actions after viewing or clicking one of the advertiser's ads with the purpose of measuring the efficacy of an ad and to present targeted ads to the user.1 yearAdvertising
LAST_RESULT_ENTRY_KEYyoutube.comUsed to track user’s interaction with embedded content.SessionEmbedded
LogsDatabaseV2:V#||LogsRequestsStoreyoutube.comUnclassified.PersistentEmbedded
nextldyoutube.comUsed to track user’s interaction with embedded content.SessionEmbedded
pagead/1p-conversion/#/google.comUnclassified.SessionEmbedded
remote_sidyoutube.comNecessary for the implementation and functionality of YouTube video-content on the website.SessionEmbedded
Requestsyoutube.comUsed to track user’s interaction with embedded content.SessionEmbedded
ServiceWorkerLogsDatabase#SWHealthLogyoutube.comNecessary for the implementation and functionality of YouTube video-content on the website.PersistentEmbedded
TESTCOOKIESENABLEDyoutube.comUsed to track user’s interaction with embedded content.1 dayEmbedded
VISITOR_INFO1_LIVEyoutube.comUnclassified180 daysEmbedded
YSCyoutube.comUnclassifiedSessionEmbedded
ytidb::LAST_RESULT_ENTRY_KEYyoutube.comUsed to track user’s interaction with embedded content.PersistentEmbedded
YtIdbMeta#databasesyoutube.comUsed to track user’s interaction with embedded content.PersistentEmbedded
yt-remote-cast-availableyoutube.comStores the user's video player preferences using embedded YouTube video.SessionEmbedded
yt-remote-cast-installedyoutube.comStores the user's video player preferences using embedded YouTube video.SessionEmbedded
yt-remote-connected-devicesyoutube.comStores the user's video player preferences using embedded YouTube video.PersistentEmbedded
yt-remote-device-idyoutube.comStores the user's video player preferences using embedded YouTube video.PersistentEmbedded
yt-remote-fast-check-periodyoutube.comStores the user's video player preferences using embedded YouTube video.SessionEmbedded
yt-remote-session-appyoutube.comStores the user's video player preferences using embedded YouTube video.SessionEmbedded
yt-remote-session-nameyoutube.comStores the user's video player preferences using embedded YouTube video.SessionEmbedded

console.weaviate.cloud

NameProviderPurposeDurationCategory
__Host-next-auth.csrf-tokenconsole.weaviate.cloudEnsures visitor browsing-security by preventing cross-site request forgery. This cookie is essential for the securityof the website and visitor.SessionNecessary
__Secure-next-auth.callback-urlconsole.weaviate.cloudUsed in order to detect spam and improve the website's security.SessionNecessary
graphiql:themeconsole.weaviate.cloudUsed to store the query module design theme.PersistentNecessary
nextauth.messageconsole.weaviate.cloudPreserves users' states across page requests.PersistentNecessary
CookieConsentconsole.weaviate.cloudStores the user's cookie consent state for the current domain.1 yearPerformance
_hjAbsoluteSessionInProgressHotjarThis cookie is used to count how many times a website has been visited by different visitors - this is done by assigning the visitor an ID, so the visitor does not get registered twice.1 dayAnalytics
_hjCookieTestHotjarCollects data on the user’s navigation and behavior on the website. This is used to compile statistical reports andheatmaps for the website owner.SessionAnalytics
_hjFirstSeenHotjarThis cookie is used to determine if the visitor has visited the website before, or if it is a new visitor on the website.1 dayAnalytics
_hjIncludedInSessionSample_#HotjarCollects statistics on the visitor's visits to the website, such as the number of visits, average time spent on the website and what pages have been read.1 dayAnalytics
_hjSession_#HotjarCollects statistics on the visitor's visits to the website, such as the number of visits, average time spent on the website and what pages have been read.1 dayAnalytics
_hjSessionUser_#HotjarCollects statistics on the visitor's visits to the website, such as the number of visits, average time spent on the website and what pages have been read.1 yearAnalytics
_hjTLDTestHotjarRegisters statistical data on users' behavior on the website. Used for internal analytics by the website operator.SessionAnalytics
hjActiveViewportIdsHotjarThis cookie contains an ID string on the current session. This contains non-personal information on whatsubpages the visitor enters – this information is used to optimize the visitor's experience.PersistentAnalytics
hjViewportIdHotjarSaves the user's screen size in order to adjust the size of images on the website.SessionAnalytics
hjActiveViewportIdsHotjarThis cookie contains an ID string on the current session. This contains non-personal information on what subpage the visitor enters – this information is used to optimize the visitor's experience.PersistentAnalytics

Kindly note that our websites may contain links to websites of third parties. This privacy policy is not applicable to the collection and use of personal data via said websites, and neither are we responsible for it. Please see the privacy policies of the relevant third-party websites (where available) for more information on how, why, and what personal data are collected on these websites:


For the processing of this personal data, we rely on your consent or on our legitimate interest to make our websites available to you.


b. If you complete forms on (one of) our websites, we process the following personal data, for the following purposes and on the following legal basis:


Type of dataPurposes
We collect personal data that you provide when you complete forms on our websites. We may process such information, for example when you register for an event or webinar) or if you register to receive a newsletter (please also refer to Section 5 of this Privacy Policy).To contact you based on your request, to provide you with the service you requested, to contact you with relevant offers or services, and for marketing purposes.
We also collect personal data that you voluntarily provide in response to requests and inquiries we may make at various places and through various mechanisms on Weaviate websites.To improve our products and services, to improve our customer support, and or marketing purposes.

For the processing of this personal data, we rely on your consent or on our legitimate interest to make our websites and services available to you.


4. If you contact us


a. If you contact us by email (e.g., via hello@weaviate.io), we process the following personal data, for the following purposes and on the following legal basis:


Type of dataPurposes
We process your contact details. This may include but is not limited to your name, your email address, and your organization.To contact you, to identify you, and to supply our support. 
We process the information you provide to us in those communications. This information may include but is not limited to Service Usage Information.To contact you, to supply our support, and to improve our products and services.

For the processing of this personal data, we rely on our legitimate interest in responding to your contact with us.


b. If you contact us via our customer support, we process the following personal data, for the following purposes and on the following legal basis:


Type of dataPurposes
We process your contact details. This may include but is not limited to your name, your email address, and your organization.To contact you, to identify you, and to supply our support. 
We process the information you provide to us in those communications. This information may include but is not limited to Service Usage Information.To contact you, to supply our support, and to improve our products and services.

For the processing of this personal data, we rely on the performance of our contract with you and our legitimate interest to deliver support.


c. If you contact us via our forum (https\://forum.weaviate.io/), we process the following personal data, for the following purposes and on the following legal basis:


Type of dataPurposes
We process your contact details. This may include but is not limited to your (user)name, email address, and IP address.To contact you, to identify you, and to supply our support. 
We process the information you provide to us in those communications.To supply our support, to improve our communications, and to improve our products and services.

For the processing of this personal data, we rely on our legitimate interest in responding to your contact with us.


d. If you contact us via social media (such as the Weaviate Slack Community), we process the following personal data, for the following purposes and on the following legal basis:


Type of dataPurposes
We process your contact details. This may include but is not limited to your (user)name and email address.To contact you, to identify you, and to improve our support. 
We process the information you provide to us in those communications.To contact you, to supply our support, to improve our communications, and to improve our products and services.

For the processing of this personal data, we rely on our legitimate interest in responding to your contact with us.


5. If you subscribe to or receive our newsletter

If you subscribe to, or receive our newsletter, we process the following personal data, for the following purposes and on the following legal basis:


Type of dataPurposes
We process your contact details. This includes but may not be limited to your email address.To send you our newsletter and for marketing purposes.
We may also process previous mailings you received, and details on when and how you unsubscribed to receiving our newsletter, whether you have opened our newsletter and/or clicked on any links included in our newsletter.To improve our communications and for marketing purposes.Our newsletters make use of certain techniques to track visitor statistics. We use these statistics to improve our newsletters and offer you relevant content.

You may object to the use of your personal data for direct marketing purposes anytime (please see Section 7 in this respect). For example, you can unsubscribe from receiving our newsletter at any time by clicking the unsubscribe link in the newsletter you received or by contacting hello@weaviate.io. Please find the relevant contact details in Section 9. When you unsubscribe, you will still receive our service emails. 


For the purposes mentioned in this Section, we may share your personal information with third parties that help us to automate and analyze our mailings. For more information on the protection of your personal data in this regard, please refer to Section 6.


For the processing of this personal data, we rely on your consent.


6. What parties have access to your personal data?


We may disclose your personal data or make your personal data available to third parties for the purposes mentioned above. This disclosure includes the following third parties for the following purposes:


  • Sendgrid, for helping us with organizing, automating, and analyzing our mailings;

  • Hubspot, for customer relationship management and marketing automation;

  • Beehiiv, for sending our newsletter;

  • Zendesk, for technical support inquiry management and communications;

  • Stripe, for payment processing;

  • Google, for email, document storage, and data warehousing;

  • Zapier, for workflow automation.

These third parties may be located outside the European Economic Area. The regulations in these countries do not always provide the same level of protection of personal data as the regulations in the Netherlands. Where required, Weaviate takes appropriate measures to comply with the requirements that the applicable privacy regulations impose on the international transfer of personal data.


We may, for instance, conclude so-called European Model Agreements for the transfer of personal data with our service providers. We may also supply personal data to recipients established in the US if they have a valid EU-US Data Privacy Framework certification. 


7. How do we secure your personal data and how long do we retain it?

Weaviate has implemented various measures to protect your personal data. For instance, our internal procedures concerning your personal data are compliant with our internal security policy, we have obtained and commit to obtaining various data security certifications (such as SOC2 Type 1, SOC2 Type 2, and ISO27001), and we use end-to-end encryption to protect any stored personal data.


We retain your personal data for a period of 5 years or as long as required to realize the objectives as described in this privacy policy. If we no longer require personal data, then we delete this personal data or anonymize it in order that they can no longer be linked to you.


8. Your rights and how to exercise them 

You may contact legal@weaviate.io to exercise any of the rights you are granted under applicable personal data protection legislation, including the following rights:


a. The right to access: you may ask us whether or not we process any of your personal data and, if so, receive a copy of such personal data. When complying with an access request, we will also provide you with additional information, such as the purposes of the processing, the categories of personal data concerned as well as any other information necessary for you to exercise the essence of this right; 


b. The right to rectification: you have the right to have your data rectified in case of inaccuracy or incompleteness. Upon request, we will correct inaccurate personal data about you and, taking into account the purposes of the processing, complete incomplete personal data, which may include the provision of a supplementary statement; 


c. The right to erasure: you also have the right to have your personal data erased, which means the deletion of your data by us and, where relevant, any other controller to whom we have disclosed your data. Erasure of your personal data only finds place in certain cases, prescribed by law, and listed under article 17 of the GDPR. This includes situations where your personal data are no longer necessary in relation to the initial purposes for which they were processed as well as situations where they were processed unlawfully;


d. The right to restriction of processing: you have the right to ask us to restrict the processing of your personal data, which means that we suspend the processing of your data for a certain period of time. Circumstances which may give rise to this right include situations where the accuracy of your personal data was contested but some time is needed for us to verify their (in)accuracy. This right does not prevent us from continuing to store your personal data. We will inform you before the restriction is lifted;


e. The right to data portability: under certain circumstances, you may request us to provide you with your personal data in a structured, commonly used, and machine-readable format and to have such data transmitted directly to another controller, where technically feasible. Upon request and where this is technically feasible, we will transmit your personal data directly to the other controller; and


f. The right to object: you also have the right to object to the processing of your personal data, which means you may request us to no longer process your personal data. This only applies in case the ‘legitimate interests’ ground (including profiling) constitutes the legal basis for processing (which is indicated above. 


Please note that we may require you to provide additional information to verify your identity before responding to your request. Furthermore, there may be situations where we are lawfully entitled to deny or restrict your rights described in this Section. In any case, we will carefully assess whether such an exemption applies and inform you accordingly. We may, for example, deny your request for access when necessary to protect the rights and freedoms of other individuals or refuse to delete your personal data in case the processing of such data is necessary for compliance with legal obligations. The right to data portability, for example, does not apply in case the personal data was not provided by you or if we process the data not on the basis of your consent or for the performance of a contract.


9. How to contact us

You can always contact us if you have any questions, remarks, or complaints in relation to this privacy policy. For any such questions, remarks, or complaints, please contact legal@weaviate.io.


If you have any unresolved concerns, you have the right to lodge a complaint with the Dutch Data Protection Authority (Autoriteit Persoonsgegevens).