Data processing agreement | Well
Data processing agreement
Last updated: August 6, 2026
Processor: Well App, Inc., 1111B S Governors Ave STE 29109, Dover, DE 19904
Controller: The entity identified in the applicable Order Form or Subscription Agreement with Well
This DPA forms part of the agreement between Well and Customer regarding the provision of Services where Well processes Personal Data on behalf of Customer.
1. Definitions
| Term | Definition |
|---|---|
| Personal Data | Any information relating to an identified or identifiable natural person that is processed by Well on behalf of Customer. |
| Processing | Any operation performed on Personal Data (e.g., storage, access, transmission). |
| Data Subject | The individual whose personal data is being processed. |
| Applicable Law | Includes the GDPR, UK GDPR, CCPA, and any other privacy laws relevant to Customer’s use of the Services. |
| Sub-processor | Any third party engaged by Well to process Personal Data on behalf of Customer. |
| Standard Contractual Clauses (SCCs) | The 2021 EU model clauses (Module 2: Controller to Processor), as approved by the European Commission. |
2. Scope and roles
Well acts as a Processor of Personal Data on behalf of the Customer, the Controller.
The nature and purpose of processing is limited to providing the Well platform, including data extraction, integration, transformation, and routing.
The duration is the term of the agreement between the parties unless otherwise required by law.
3. Customer obligations
Customer, as Controller, agrees to:
- Ensure lawful basis for all processing of Personal Data via the Services
- Not instruct Well to process data in a way that violates any Applicable Law
- Provide privacy notices to Data Subjects as required
- Be solely responsible for determining if the Services meet their data processing needs
4. Well’s obligations
Well agrees to:
- Process Personal Data only on documented instructions from Customer unless required by law
- Not retain, use, or disclose Personal Data for any purpose other than providing the Services
- Maintain confidentiality and ensure its personnel are bound by appropriate obligations
- Implement appropriate technical and organizational measures to protect Personal Data
5. Security measures
Well maintains administrative, technical, and physical safeguards appropriate to the sensitivity of the Personal Data, including:
- Access controls and authentication
- Encryption in transit and at rest
- Role-based access limitations
- Incident detection and response
- Data backup and disaster recovery
A written description of these measures is available on request.
6. EEA / UK / Swiss users: GDPR compliance
Well App, Inc. is a United States company and runs its production infrastructure on Google Cloud Platform. Personal Data processed on behalf of EEA, UK and Swiss customers is transferred to and processed in the United States, and is also processed by the sub-processors named in our sub-processor list, in the locations stated there, where Well has verified them. Where that list says the location is determined by the provider, Well has not verified it and does not state it here.
A contract governed by European law is not European hosting. Well does not claim European data residency. Transfers out of the EEA, UK and Switzerland rely on the European Commission’s standard contractual clauses (Module 2: Controller to Processor) and, for UK transfers, the UK International Data Transfer Addendum.
If you are in the EEA, UK, or Switzerland, we process your data under the legal bases of:
- Performance of a contract (e.g., providing services)
- Legitimate interest (e.g., improving services, ensuring security)
- Consent (e.g., marketing emails)
You may lodge a complaint with your local data protection authority if you believe we have violated your rights.
7. Data subject requests
To the extent legally permissible, Well shall:
- Promptly notify Customer of any Data Subject request (e.g., access, deletion, rectification)
- Not respond directly unless authorized
- Assist Customer in fulfilling its obligations, using appropriate technical and organizational measures
8. Sub-processors
Customer gives Well general authorization to engage the Sub-processors listed at wellapp.ai/subprocessors, which forms part of this DPA and is the current list. Well imposes on each Sub-processor data protection obligations no less protective than those in this DPA, and remains fully liable to Customer for its Sub-processors’ performance.
Before adding or replacing a Sub-processor, Well will update that page and notify the administrative contact on the account at least 30 days in advance. Customer may object on reasonable data protection grounds within those 30 days by writing to privacy@wellapp.ai. If the parties cannot agree on a resolution, Customer may terminate the affected Services without penalty for the remainder of the then-current term.
9. Assistance with compliance
Well shall, at Customer’s request:
- Provide necessary information to demonstrate compliance with Article 28 of the GDPR (or equivalent)
- Assist with data protection impact assessments (DPIAs)
- Cooperate with supervisory authorities if requested
10. Security incident notification
If Well becomes aware of a Personal Data Breach, it shall:
- Notify Customer without undue delay (within 48 hours of confirmation)
- Provide available details including:
- Nature of the breach
- Categories of data affected
- Steps taken or proposed to mitigate the breach
- Cooperate in the investigation and remediation
11. Return or deletion of data
Upon termination of Services, Well will:
- Delete or return all Personal Data to Customer (at Customer’s option)
- Retain no copies except as required by law
- Certify deletion upon request
Backup archives may be retained for up to 30 days post-termination, with continued security controls in place.
12. Audits and demonstrations
Upon written request no more than once annually, Well shall:
- Provide Customer with Well’s current SOC 2 Type I report, under a confidentiality agreement, where such a report is available. A Type I report describes the design of controls at a point in time, not their operation over a period. Well does not hold a SOC 2 Type II report or an ISO 27001 certification
- Cooperate with audits or inspections by Customer or its auditors, provided:
- 30 days’ advance notice is given
- The audit does not unreasonably interfere with Well’s operations
- Customer signs a confidentiality agreement
13. Liability
Each party’s liability under this DPA is subject to the limitations of liability set forth in the main Terms of Service, except for liability that Applicable Law does not permit to be limited.
No provision of this DPA or of the Terms of Service limits either party’s obligations under Applicable Law, a Data Subject’s right to compensation under Article 82 of the GDPR, or the liabilities the standard contractual clauses allocate between the parties.
14. Governing law and venue
This DPA shall be governed by:
- The laws of the State of Delaware, USA (for non-EU customers)
- EU law and the relevant Member State’s jurisdiction (for GDPR-bound customers, solely for SCC purposes)
For any claim relating to the processing of Personal Data by a GDPR-bound Customer, this Section and the standard contractual clauses prevail over the dispute resolution and governing law provisions of the Terms of Service, including any agreement to arbitrate and any waiver of collective proceedings.
15. Modifications
We may update this DPA to reflect changes in our Sub-processors, Services, or Applicable Law. Material changes will be notified to the Customer with a 30-day notice period, unless legally required earlier.
16. Contact us
For processing where Well acts as controller rather than processor, see our privacy policy.
Questions regarding this DPA may be directed to:
Data Protection Officer (DPO)
Well App, Inc.
1111B S Governors Ave STE 29109
Dover, DE 19904, USA