Data processing agreement | Well

Data processing agreement

Last updated: August 6, 2026

Processor: Well App, Inc., 1111B S Governors Ave STE 29109, Dover, DE 19904

Controller: The entity identified in the applicable Order Form or Subscription Agreement with Well

This DPA forms part of the agreement between Well and Customer regarding the provision of Services where Well processes Personal Data on behalf of Customer.

1. Definitions

Term Definition
Personal Data Any information relating to an identified or identifiable natural person that is processed by Well on behalf of Customer.
Processing Any operation performed on Personal Data (e.g., storage, access, transmission).
Data Subject The individual whose personal data is being processed.
Applicable Law Includes the GDPR, UK GDPR, CCPA, and any other privacy laws relevant to Customer’s use of the Services.
Sub-processor Any third party engaged by Well to process Personal Data on behalf of Customer.
Standard Contractual Clauses (SCCs) The 2021 EU model clauses (Module 2: Controller to Processor), as approved by the European Commission.

2. Scope and roles

Well acts as a Processor of Personal Data on behalf of the Customer, the Controller.

The nature and purpose of processing is limited to providing the Well platform, including data extraction, integration, transformation, and routing.

The duration is the term of the agreement between the parties unless otherwise required by law.

3. Customer obligations

Customer, as Controller, agrees to:

4. Well’s obligations

Well agrees to:

5. Security measures

Well maintains administrative, technical, and physical safeguards appropriate to the sensitivity of the Personal Data, including:

A written description of these measures is available on request.

6. EEA / UK / Swiss users: GDPR compliance

Well App, Inc. is a United States company and runs its production infrastructure on Google Cloud Platform. Personal Data processed on behalf of EEA, UK and Swiss customers is transferred to and processed in the United States, and is also processed by the sub-processors named in our sub-processor list, in the locations stated there, where Well has verified them. Where that list says the location is determined by the provider, Well has not verified it and does not state it here.

A contract governed by European law is not European hosting. Well does not claim European data residency. Transfers out of the EEA, UK and Switzerland rely on the European Commission’s standard contractual clauses (Module 2: Controller to Processor) and, for UK transfers, the UK International Data Transfer Addendum.

If you are in the EEA, UK, or Switzerland, we process your data under the legal bases of:

You may lodge a complaint with your local data protection authority if you believe we have violated your rights.

7. Data subject requests

To the extent legally permissible, Well shall:

8. Sub-processors

Customer gives Well general authorization to engage the Sub-processors listed at wellapp.ai/subprocessors, which forms part of this DPA and is the current list. Well imposes on each Sub-processor data protection obligations no less protective than those in this DPA, and remains fully liable to Customer for its Sub-processors’ performance.

Before adding or replacing a Sub-processor, Well will update that page and notify the administrative contact on the account at least 30 days in advance. Customer may object on reasonable data protection grounds within those 30 days by writing to privacy@wellapp.ai. If the parties cannot agree on a resolution, Customer may terminate the affected Services without penalty for the remainder of the then-current term.

9. Assistance with compliance

Well shall, at Customer’s request:

10. Security incident notification

If Well becomes aware of a Personal Data Breach, it shall:

11. Return or deletion of data

Upon termination of Services, Well will:

Backup archives may be retained for up to 30 days post-termination, with continued security controls in place.

12. Audits and demonstrations

Upon written request no more than once annually, Well shall:

13. Liability

Each party’s liability under this DPA is subject to the limitations of liability set forth in the main Terms of Service, except for liability that Applicable Law does not permit to be limited.

No provision of this DPA or of the Terms of Service limits either party’s obligations under Applicable Law, a Data Subject’s right to compensation under Article 82 of the GDPR, or the liabilities the standard contractual clauses allocate between the parties.

14. Governing law and venue

This DPA shall be governed by:

For any claim relating to the processing of Personal Data by a GDPR-bound Customer, this Section and the standard contractual clauses prevail over the dispute resolution and governing law provisions of the Terms of Service, including any agreement to arbitrate and any waiver of collective proceedings.

15. Modifications

We may update this DPA to reflect changes in our Sub-processors, Services, or Applicable Law. Material changes will be notified to the Customer with a 30-day notice period, unless legally required earlier.

16. Contact us

For processing where Well acts as controller rather than processor, see our privacy policy.

Questions regarding this DPA may be directed to:

Data Protection Officer (DPO)

privacy@wellapp.ai

Well App, Inc.

1111B S Governors Ave STE 29109

Dover, DE 19904, USA