Snapshot 27136
Normalized text
Scripts and page chrome removed; this is what change detection compares.
Trust & Security Enterprise-Grade Trust for Your Employee Data We handle employee data with the same precision as financial data: private, encrypted, and never used beyond its purpose. Explore Data Privacy Contact Trust Team Data Privacy Security Compliance Transparency FAQs Privacy by Design from Data Capture to Deletion Every signal, feedback, or performance record we process follows clear privacy-first principles. From the moment data is collected until it is deleted, every step is governed by purpose, consent, and transparency. Minimal data collection We only store what is required to power insights. No hidden tracking, no unnecessary fields. Purpose-bound use Data is used exclusively for its intended context. It is never reused for advertising, marketing, or external analytics. Employee rights built in Employees can view, correct, or delete their data through the admin dashboard. Every organisation can honour access and erasure requests seamlessly. All processing aligns with GDPR and UK GDPR Defence in Depth to Protect Sensitive Employee Data Security is not an afterthought. It is built into every layer of our system. We apply enterprise-grade standards to protect people data. Encryption everywhere All data is encrypted at rest (AES-256) and in transit (TLS 1.2 or higher). Strict access controls Role-based permissions and zero-trust principles ensure least-privilege access. Segregated environments Production, staging, and test environments are fully isolated. Continuous monitoring Real-time anomaly detection and complete audit logs. Built to Meet Global Data-Protection Standards Our approach ensures you can meet your regulatory obligations with confidence. From GDPR readiness to subprocessors lists, compliance is clear and verifiable. GDPR and UK GDPR All data handling and storage follow these frameworks. Data residency options EU and UK hosting supported with transparent documentation. DPIA readiness Templates and cooperation make completing DPAs simple. Subprocessor transparency Third-party vendors are reviewed for privacy, security, and compliance. Trust is Built on Transparency We publish clear documentation and make it simple to reach our team for detailed questions. Request data-flow diagram View subprocessors Contact DPO We never sell or share employee data with any third parties. Frequently Asked Questions Do you store Slack or Teams messages? We process messages only to generate the insights you ask for and don't retain raw message content beyond what's needed. No personal identifiers are shared with our AI subprocessors. Can employees opt out of data processing? Yes. Employees can view, correct, or delete their data from the admin dashboard, and organisations can honour access and erasure requests at any time. Where is data hosted? Data is hosted in the EU and UK with transparent documentation, and data residency options are available for teams with specific requirements. Do you use data to train AI models? No. Your data is never used to train AI models, and it is never reused for advertising, marketing, or external analytics. Frequently Asked Questions General Do you store Slack or Teams messages? We only collect data via our conversational workflows in Slack and Teams. This data is required to power features you enable, such as 1:1 preparation, prompts, or recognition. We store the minimum necessary snippets and metadata to generate insights and keep a history for that manager–employee pair. Do you snoop on our data? No. We never browse customer workspaces or private messages. Access is strictly limited, role-based, and audited. We only process data to deliver the features you activate. No employee at Wellence reads your content unless you explicitly request support on a specific item, and then access is time-bound and logged. Where is data hosted? By default we host in the EU/UK region on a major cloud provider with encryption at rest and in transit. If you need a different region, speak to us and we can discuss options. We do not move your data between regions without consent. Do you use data to train AI models? We do not use customer data to train public or third-party foundation models. Your data is processed solely to provide the service and to generate your organisation’s insights. Optional, organisation-scoped learning (to improve prompts or suggestions for your company only) can be enabled by the admin. What data do you collect? Only what is needed for the features you switch on. Typical categories: Workspace identifiers, users, teams, roles 1:1 prompts, responses, actions, recognition notes (if modules are enabled) Usage metadata such as timestamps and feature clicks We do not collect passwords, payment card data, or sensitive medical information. How long do you keep data? Default retention is in accordance with our policy. Admins can shorten or extend retention, and can request deletion at any time. Backups follow the same retention policy. Can we delete data? Yes. Admins can request to delete employees, teams, or the entire workspace dataset. We honour data subject requests (access, correction, deletion) within statutory timelines. Who owns the data? You do. Wellence is a processor of your data. We only process it under your instructions and our Data Processing Addendum. Which third parties do you use? We use reputable cloud and infrastructure providers for hosting, logging, and analytics. A current list of sub-processors and their purpose is available on request and in our DPA. We do not sell or share your data for advertising. Are messages end-to-end encrypted? Data is encrypted in transit (TLS 1.2+) and at rest with strong encryption. Keys are managed by the cloud provider's KMS. If you require customer-managed keys, contact us to discuss. What happens if there is a security incident? We operate an incident response process with 24/7 monitoring and clear escalation paths. If an incident affects your data, we notify your admin promptly with details, scope, and remediation steps. Can you sign our DPA and SCCs? Yes. We provide a standard DPA with GDPR terms and UK Addendum. If Standard Contractual Clauses are required for data transfers, we will execute them. How do permissions work in Slack/Teams? We request the minimal scopes required for the features you enable. Admins can review scopes during installation, and you may revoke the app at any time from your workspace settings. Do you perform manual reviews of content? No, unless you explicitly ask our support team to investigate a specific issue. Any manual access is time-boxed, least-privilege, and logged. Do you support Bring-Your-Own-LLM or data residency constraints? We can route model calls to EU endpoints and restrict processing to your chosen region where supported. For BYO-LLM or private endpoints, contact us. For Buyers and IT/Security What standards do you follow? We follow security best practices: least-privilege access, encryption in transit and at rest, network segmentation, secure SDLC, vulnerability management, and regular penetration testing. If you require a questionnaire (e.g., CAIQ/SAQ), we will complete it. How do you authenticate and authorise access? Admins define roles for HR, managers, and executives. Access is logged. Privileged access by Wellence staff is restricted and reviewed. Do you process special category data? We avoid special category data by design. If customers enter such data in free-text fields, it is processed under your instructions and subject to the same protections. What is your backup and disaster recovery approach? Automated encrypted backups, multiple availability zones, and recovery testing. Can you segregate environments? Yes. Separate production, staging, and development environments. No production data in lower environments. For Managers Can my team see my private notes? No. Manager notes are visible only to the manager unless you choose to share them. Admins can set organisation-wide defaults. What if someone writes something sensitive in a 1:1? 1:1 content is private to the manager-employee context by default. We provide reminders and content suggestions to avoid sharing unnecessary personal and sensitive data. Will this increase my admin work? No. The product is designed to work in the flow of Slack/Teams with lightweight prompts and templates. For Employees Can Wellence read my private messages? No. We do not have blanket access to private messages. We only see the content you choose to share in the Wellence workflows you interact with. Will my manager see everything I write? Only within the specific workflow you submit to them (e.g., a 1:1 prep form). Private wellbeing or feedback inputs are never shared without your consent. Can I correct or delete my data? Yes. You can ask your admin or manager, and we will respond via the company's data rights process. Product-specific What happens during a 1:1? Do you record meetings? By default, Wellence does not record meetings. If you enable meeting summaries in the future, recording/transcription will be opt-in with clear notices and consent. Does Wellence replace our HRIS or performance tool? No. We complement your HRIS and reviews system by helping managers run high-quality 1:1s, track actions, and surface risks earlier. We integrate with your existing stack. Can we control who sees org-level insights? Yes. Access to dashboards is role-based. Exec and HR summaries are aggregated and do not expose private 1:1 text. Administrative How do we uninstall? Admins can remove the app from Slack/Teams at any time. We will delete workspace data within [30] days unless you request immediate deletion. How do we contact you for privacy questions or DSRs? Email [email protected] and we will respond quickly. Ready to Lead with Confidence Talk to our team about how we protect your employee data Contact Trust Team WELLENCE The AI operating system for managers who give a damn. [email protected] Trust & Security Privacy Policy Terms of Use Support © 2026 Wellence. All rights reserved.