Privacy policy.

Draft. Under legal review before publication. The final text will carry its date.

1. Controller

WelloWork AB, Sweden, is the controller for personal data collected through this website and the access request form.

2. What we collect

  • Access requests: name, work email, institution, organization or hospital, role, fields, ORCID if given, intended use, compliance needs, how you heard about us.
  • Website use: technical logs needed to run and secure the site. No advertising trackers.
  • Project data you bring to the workspace, where WelloWork acts as processor under a data processing agreement.

3. Why and on what legal basis

  • Reviewing access requests and contacting you about them: our legitimate interest and steps before a contract (Art. 6(1)(b) and (f) GDPR).
  • Running and securing the service: legitimate interest (Art. 6(1)(f)).
  • Legal obligations, such as accounting: Art. 6(1)(c).

4. Retention

Access requests are kept until a decision is made and for a limited period after it. Account data is kept while the account exists and for a limited period after it closes.

5. Recipients and transfers

We use cloud and model providers as sub-processors. A list will be published on the security page. Where data leaves the EU or EEA, we rely on adequacy decisions or standard contractual clauses.

6. Your rights

You can ask for access, rectification, erasure, restriction and portability, and you can object to processing based on legitimate interest. You can complain to the Swedish Authority for Privacy Protection (IMY).

7. Cookies

The site uses only technically necessary storage. No advertising cookies and no third-party trackers.

8. Changes

We will post changes here with a new date.

See also: Terms of service.