Third Party Index

Snapshot 27136

Document
Trust center
URL
https://www.wellence.me/trust
Fetched
HTTP status
200
Content type
text/html; charset=utf-8
Fetch mode
static
Size
85501 bytes
SHA-256 (raw)
7479568d1f9e2458fb029029c24a77ffa3870fd72be896a9d6825424eddad9ab
SHA-256 (normalized text)
c9de82dce553906b5954335b79faec77cb9787aaee9854fd94daa916b4e49af7

Normalized text

Scripts and page chrome removed; this is what change detection compares.

Trust & Security
Enterprise-Grade Trust for Your Employee Data
We handle employee data with the same precision as financial data: private, encrypted, and never used beyond its purpose.
Explore Data Privacy
Contact Trust Team
Data Privacy
Security
Compliance
Transparency
FAQs
Privacy by Design from Data Capture to Deletion
Every signal, feedback, or performance record we process follows clear privacy-first principles. From the moment data is collected until it is deleted, every step is governed by purpose, consent, and transparency.
Minimal data collection
We only store what is required to power insights. No hidden tracking, no unnecessary fields.
Purpose-bound use
Data is used exclusively for its intended context. It is never reused for advertising, marketing, or external analytics.
Employee rights built in
Employees can view, correct, or delete their data through the admin dashboard. Every organisation can honour access and erasure requests seamlessly.
All processing aligns with GDPR and UK GDPR
Defence in Depth to Protect Sensitive Employee Data
Security is not an afterthought. It is built into every layer of our system. We apply enterprise-grade standards to protect people data.
Encryption everywhere
All data is encrypted at rest (AES-256) and in transit (TLS 1.2 or higher).
Strict access controls
Role-based permissions and zero-trust principles ensure least-privilege access.
Segregated environments
Production, staging, and test environments are fully isolated.
Continuous monitoring
Real-time anomaly detection and complete audit logs.
Built to Meet Global
Data-Protection Standards
Our approach ensures you can meet your regulatory obligations with confidence. From GDPR readiness to subprocessors lists, compliance is clear and verifiable.
GDPR and UK GDPR
All data handling and storage follow these frameworks.
Data residency options
EU and UK hosting supported with transparent documentation.
DPIA readiness
Templates and cooperation make completing DPAs simple.
Subprocessor transparency
Third-party vendors are reviewed for privacy, security, and compliance.
Trust is Built on Transparency
We publish clear documentation and make it simple to reach our team for detailed questions.
Request data-flow diagram
View subprocessors
Contact DPO
We never sell or share employee data with any third parties.
Frequently Asked Questions
Do you store Slack or Teams messages?
We process messages only to generate the insights you ask for and don't retain raw message content beyond what's needed. No personal identifiers are shared with our AI subprocessors.
Can employees opt out of data processing?
Yes. Employees can view, correct, or delete their data from the admin dashboard, and organisations can honour access and erasure requests at any time.
Where is data hosted?
Data is hosted in the EU and UK with transparent documentation, and data residency options are available for teams with specific requirements.
Do you use data to train AI models?
No. Your data is never used to train AI models, and it is never reused for advertising, marketing, or external analytics.
Frequently Asked Questions
General
Do you store Slack or Teams messages?
We only collect data via our conversational workflows in Slack and Teams. This data is required to power features you enable, such as 1:1 preparation, prompts, or recognition. We store the minimum necessary snippets and metadata to generate insights and keep a history for that manager–employee pair.
Do you snoop on our data?
No. We never browse customer workspaces or private messages. Access is strictly limited, role-based, and audited. We only process data to deliver the features you activate. No employee at Wellence reads your content unless you explicitly request support on a specific item, and then access is time-bound and logged.
Where is data hosted?
By default we host in the EU/UK region on a major cloud provider with encryption at rest and in transit. If you need a different region, speak to us and we can discuss options. We do not move your data between regions without consent.
Do you use data to train AI models?
We do not use customer data to train public or third-party foundation models. Your data is processed solely to provide the service and to generate your organisation’s insights. Optional, organisation-scoped learning (to improve prompts or suggestions for your company only) can be enabled by the admin.
What data do you collect?
Only what is needed for the features you switch on. Typical categories:
Workspace identifiers, users, teams, roles
1:1 prompts, responses, actions, recognition notes (if modules are enabled)
Usage metadata such as timestamps and feature clicks
We do not collect passwords, payment card data, or sensitive medical information.
How long do you keep data?
Default retention is in accordance with our policy. Admins can shorten or extend retention, and can request deletion at any time. Backups follow the same retention policy.
Can we delete data?
Yes. Admins can request to delete employees, teams, or the entire workspace dataset. We honour data subject requests (access, correction, deletion) within statutory timelines.
Who owns the data?
You do. Wellence is a processor of your data. We only process it under your instructions and our Data Processing Addendum.
Which third parties do you use?
We use reputable cloud and infrastructure providers for hosting, logging, and analytics. A current list of sub-processors and their purpose is available on request and in our DPA. We do not sell or share your data for advertising.
Are messages end-to-end encrypted?
Data is encrypted in transit (TLS 1.2+) and at rest with strong encryption. Keys are managed by the cloud provider's KMS. If you require customer-managed keys, contact us to discuss.
What happens if there is a security incident?
We operate an incident response process with 24/7 monitoring and clear escalation paths. If an incident affects your data, we notify your admin promptly with details, scope, and remediation steps.
Can you sign our DPA and SCCs?
Yes. We provide a standard DPA with GDPR terms and UK Addendum. If Standard Contractual Clauses are required for data transfers, we will execute them.
How do permissions work in Slack/Teams?
We request the minimal scopes required for the features you enable. Admins can review scopes during installation, and you may revoke the app at any time from your workspace settings.
Do you perform manual reviews of content?
No, unless you explicitly ask our support team to investigate a specific issue. Any manual access is time-boxed, least-privilege, and logged.
Do you support Bring-Your-Own-LLM or data residency constraints?
We can route model calls to EU endpoints and restrict processing to your chosen region where supported. For BYO-LLM or private endpoints, contact us.
For Buyers and IT/Security
What standards do you follow?
We follow security best practices: least-privilege access, encryption in transit and at rest, network segmentation, secure SDLC, vulnerability management, and regular penetration testing. If you require a questionnaire (e.g., CAIQ/SAQ), we will complete it.
How do you authenticate and authorise access?
Admins define roles for HR, managers, and executives. Access is logged. Privileged access by Wellence staff is restricted and reviewed.
Do you process special category data?
We avoid special category data by design. If customers enter such data in free-text fields, it is processed under your instructions and subject to the same protections.
What is your backup and disaster recovery approach?
Automated encrypted backups, multiple availability zones, and recovery testing.
Can you segregate environments?
Yes. Separate production, staging, and development environments. No production data in lower environments.
For Managers
Can my team see my private notes?
No. Manager notes are visible only to the manager unless you choose to share them. Admins can set organisation-wide defaults.
What if someone writes something sensitive in a 1:1?
1:1 content is private to the manager-employee context by default. We provide reminders and content suggestions to avoid sharing unnecessary personal and sensitive data.
Will this increase my admin work?
No. The product is designed to work in the flow of Slack/Teams with lightweight prompts and templates.
For Employees
Can Wellence read my private messages?
No. We do not have blanket access to private messages. We only see the content you choose to share in the Wellence workflows you interact with.
Will my manager see everything I write?
Only within the specific workflow you submit to them (e.g., a 1:1 prep form). Private wellbeing or feedback inputs are never shared without your consent.
Can I correct or delete my data?
Yes. You can ask your admin or manager, and we will respond via the company's data rights process.
Product-specific
What happens during a 1:1? Do you record meetings?
By default, Wellence does not record meetings. If you enable meeting summaries in the future, recording/transcription will be opt-in with clear notices and consent.
Does Wellence replace our HRIS or performance tool?
No. We complement your HRIS and reviews system by helping managers run high-quality 1:1s, track actions, and surface risks earlier. We integrate with your existing stack.
Can we control who sees org-level insights?
Yes. Access to dashboards is role-based. Exec and HR summaries are aggregated and do not expose private 1:1 text.
Administrative
How do we uninstall?
Admins can remove the app from Slack/Teams at any time. We will delete workspace data within [30] days unless you request immediate deletion.
How do we contact you for privacy questions or DSRs?
Email [email protected] and we will respond quickly.
Ready to Lead with Confidence
Talk to our team about how we protect your employee data
Contact Trust Team
WELLENCE
The AI operating system for managers who give a damn.
[email protected]
Trust & Security
Privacy Policy
Terms of Use
Support
© 2026 Wellence. All rights reserved.