Privacy policy

PRIVACY POLICY (including cookie policy)

Amelio Health BV (“Wellis”, “we” whether “us”) respects the privacy of individuals. We are a “controller” within the meaning of the General Data Protection Regulation (EU) 2016/679 (“GDPR”), the Data Protection Act 2018 and the Privacy and Electronic Communications Regulations (EU) 2003/2426 (jointly the referred to as “Data Protection Laws”). 1

  • This privacy policy contains important information about the following:
  • The type of information we collect about you
  • How that information is used
  • Who has access to that information?
  • How long we keep your personal information
  • Our security measures to protect that information
  • How our processing of your personal information is lawful, and
  • Your rights under data protection laws.

The term “personal data” means any information that can identify a living person, such as name, contact details, and photos. Have “Special Categories of Personal Data” relating to more sensitive types of personal data, including (among other things) racial or ethnic origin, physical or mental health or condition, and sexual life. These terms are defined in the Data Protection Act.

Categories of Information Collected

We will collect and store these categories of personal information about you:

  • General questions or complaints: If you ask a general question or make a complaint, we need your:
    • name
    • contact details (address, phone number, email address), and
    • the details of your question or complaint.
  • Account details: We collect the following information to create and maintain your account and to enable the medical services provided to you:
    • your first and last name
    • your email address, username, and password
    • your date of birth
    • your phone number
    • your marketing preferences.
  • Medical information: To assess whether the product you have requested can be prescribed for you, you must complete our medical questionnaire that collects medical information about you. This is a special category of personal data and may include photos that you submit in connection with your medical consultation.
  • Purchase of prescription products: We collect the following information to administer your purchases with us:
    • your contact and delivery details (phone number, email address and postal address)
    • your purchase details (product, date, amount)
    • The prescription issued by a doctor. The doctor who reviews your medical data decides whether you can safely be prescribed the product you want.
  • Payment Information: We don't store your payment card information in your account because all payments are handled directly by Stripe Payments Europe, Ltd. Stripe lets us know if a transaction is successful or not.
  • Surveys: From time to time, we may ask you to provide feedback on the quality of our service. To do this, we need your:
    • name
    • contact details (address, phone number, email address), and
    • information about how you came to us, how you found us, and how you think we can improve our services.
  • Information collected automatically: When you visit our site or use our services, we automatically collect certain information from the hardware and software that you are currently using, which, together with the other information we collect, may constitute “personal data” within the meaning of the Data Protection Act. If you are an unregistered user, we will still collect the following information (which in itself probably does not constitute “personal data” within the meaning of the Data Protection Act, but about which we would at least want to be transparent):
    • your browsing history on our websites
    • the information provided by your device and browser, including referral and tracking information, and
    • your ip address.

Use of Collected Information

Wellis uses your personal data for the following purposes described below. We are allowed to do this on certain legal bases (see section) “Legal basis for processing your personal data” for more information):

  • General questions or complaints (legitimate interests). To answer your general questions and deal with your complaints.
  • Account information (contract). To manage your account, verify your age and identity as some of our products are only available to people aged 18 to 65 (inclusive) and to provide you with information about Wellis and our company, products, and services.
  • Purchase of prescription products and payment information (contract). To process your product payments and administer your product purchase.
  • Medical information (permission). To share with doctors who assess whether you are safe to use the medical products you have ordered, based on the answers you provide to the questionnaire, and to write a prescription.
  • Surveys (legitimate interests). To improve our website, app and/or their respective content, features and/or services; Wellis' products, services, marketing and/or promotional efforts; and create new products, services, marketing and/or promotions for Wellis.

Retention and Sharing of Collected Information

Wellis shares your personal information with Wellis service providers who process your data as part of the services they offer to us. We take steps to ensure that our service providers treat your information in accordance with the law, use it only in accordance with our contract with them, and keep it secure.

Like any company, we use many other suppliers to help us run our business and process your personal data as part of providing their services to us. These providers fall under the following categories:

  • AWS (eu-west-2) - for data storage and hosting
  • Google Cloud - for web hosting
  • Braze - for customer loyalty services including email and SMS storage
  • Google Analytics and Tag Manager - to analyze and develop our web services
  • Amplitude - to analyse and develop our product strategy
  • Facebook - for advertising and marketing
  • Google AdWords - for advertising and marketing
  • Looker - for our own company information

In addition, we share your personal information with the following organizations that act as separate controllers for processing your personal information. You should read their privacy policy to learn how they process your personal data. If you have any questions or complaints about how they process your personal data, please contact them separately using the contact details on their website.

  • Keijzer General Practice and the affiliated doctors who review your medical information to prescribe the products
  • Wellis Pharmacy and other affiliated pharmacies - sells and delivers prescription products to you
  • Stripe Payments Europe, Ltd. - takes payment for the products
  • Chargebee Inc. - manages subscriptions

We also share information when necessary to enforce our legal rights, defend legal claims, and if required by law to disclose it to courts, police, law enforcement agencies, or regulators.

Data Retention

The list below details how long we process your data.

  • General questions or complaints. For general inquiries, the information will be kept until the question is completed and no further responses are received for a reasonable period of time. If you are an existing customer, the question may be added to other information that we have about you as a customer. For complaints, the information is stored for up to 6 years after the complaint has been dealt with. If you are an existing customer, the complaint and its resolution may be added to other information that we hold about you as a customer.
  • Account details. For the duration of your account and up to 6 years after you closed your account with us.
  • Purchase of prescription products. Up to 6 years after purchase.
  • Payment details. We do not store payment information. Payment information is processed by our service provider Stripe Payments Europe, Ltd.
  • Medical Information. 7 years after purchase
  • Regulations. 6 years after purchase
  • Surveys. For the duration of your account and up to 1 year after you closed your account with us.

security

Wellis implements security measures to help protect the personal information we hold. We do this by implementing and using appropriate technical and organizational measures to protect your personal information from accidental or unlawful destruction, accidental loss or alteration, unauthorized disclosure or access, and other unlawful forms of processing.

We also strive to ensure that the level of security and measures taken to protect your personal information are appropriate to the risks associated with the nature and use of your personal information. We do this by following recognized industry practices to protect our IT environment and physical facilities: for example, we encrypt the transmission of information via the website and app using Secure Socket Layer (SSL) technology and use AWS and Aptible to provide ISO 27001 and SOC2 compliance for the personal information we store on your behalf.

To ensure the security of your personal information, we ask you to notify us immediately of any unauthorised visit to, access or use of the website or the loss or unauthorised use of your username or password using the contact details provided below.

Legal basis for processing your personal information

Wellis may process your personal data and special categories of personal data on the following legal grounds:

ACCOUNT INFORMATION, PRESCRIPTION PRODUCT PURCHASE, PAYMENT INFORMATION, MEDICAL INFORMATION

Contract: Processing your personal information is necessary for the performance of our contract with you. These obligations include facilitating the process of obtaining a consultation with a doctor and purchasing prescription products from our associated pharmacy. If you do not provide us with your personal data, we will be unable to fulfil our obligations under the terms of the contract.

Legal claims: We need to process your personal data to defend or bring legal claims (for example, claims related to our services under contract law).

SPECIAL DATA CATEGORIES

Explicit consent: We process your special categories of personal data with your explicit consent to facilitate your access to a doctor to obtain a consultation and possibly a prescription and purchase the relevant prescription medicine from our affiliated pharmacy. Please note that you have the right to withdraw this consent at any time. However, if you withdraw your consent, it means that we are unable to fulfil our obligations.

Legal claims: We need to process your personal data to defend or bring legal claims (for example, claims related to our Membership Service under the law of obligations).

GENERAL QUESTIONS OR COMPLAINTS AND RESEARCH

Legitimate interests: We may process your personal data if it is based on our “legitimate interests”, i.e. we have good, sensible, practical reasons for processing your personal data that are in our interest. To do this, we have considered the impact on your interests and rights and have put in place appropriate safeguards to ensure that the invasion of your privacy is minimized. Our legitimate interest is to provide you with the information you request, provide effective and helpful customer service, and improve our products, services, and marketing. You can object to the processing that we carry out on the basis of legitimate interests. For more information, see the “Your Privacy Rights Under Data Protection Laws” section below.

Our Use of Cookies

Our websites use cookies (small text files that are stored on your device) to distinguish you from other users. Some of these are set up by us and others by our approved third parties. We use the following types of cookies:

  • that are strictly necessary for the operation of our site, including those that allow you to log into the user area, use the shopping cart or make purchases
  • analytical and performance cookies that allow us to track the use of our site before, during and after accessing it and that in turn enable us to improve the site
  • cookies that improve functionality and user experience for you, including remembering your visit to the site and personalizing the site based on your previous use and preferences, and
  • targeting cookies, which record your visit to our site, the pages visited and the links followed and are used to provide you with relevant advertisements and information where possible.

Currently, the following approved third parties may also place cookies when you use our services:

  • to show personalized ads: Facebook, Google AdWords, and Bing
  • to test our services: Visual Website Optimizer
  • for our own internal web analysis: Google Analytics and Amplitude
  • for customer engagement: Braze
  • for payment processing: Stripe
  • for subscription management: Chargebee Inc.

These cookies help us provide you with a personalized experience and improve our services. You can block the use of cookies in your device's browser settings, but this may prevent you from accessing or using our site properly.

Your privacy rights under the Data Protection Act

You have the following rights under the Data Protection Act. We will respond to all rights you exercise within one month of receiving your request, unless the request is particularly complex, in which case we will respond within three months. Please note that there are exceptions to some of these rights that we will apply in accordance with the Data Protection Act.

  1. Right to access your personal information: You can ask to see what personal information we have about you and you can get it:
    • a copy
    • details about the purpose for which the data is or will be processed
    • details about the recipients or categories of recipients to whom the information is or may be transferred, including if they are abroad and what protection is used for those transfers abroad
    • the period for which it is kept (or the criteria we use to determine how long it is kept)
    • all available information about the source of that data; and
    • whether we carry out automated decision-making or profiling, and if we do, information about the logic involved and the intended outcome or consequences of that decision or profiling. To help us find the information easily, please provide us with as much information as possible about the type of information you want to see.
  2. Right to correction: You can ask us to correct any errors in your information that we hold free of charge. If you want to do this, please let us know what information is incorrect and what information should replace it with.
  3. Right to erase (“the right to be forgotten”): You can ask us to erase your personal data when:
    • you do not believe that we need your information to process it for the purposes set out in this Privacy Policy;
    • if you had given us permission to process your data, you withdraw that consent and we cannot process your data in any other legal way;
    • you object to our processing and we have no legitimate interests in processing your personal data; or
    • your personal data has been processed unlawfully or has not been deleted when it should have been.
  4. Right to withdraw consent: For the use of information as specified in this Privacy Policy, you have the right to withdraw the consent you have given us at any time. This is an essential and necessary aspect of consent. If you want to withdraw your consent, you can contact us using the details in the “Contact” section. Please note that any processing performed prior to the date of withdrawal of your consent is still valid and published personal information cannot be withdrawn.
  5. Right to restrict processing: You can request that we temporarily stop processing your personal data if:
    • you believe that your information is incorrect. We will resume processing as soon as we have verified that the data is accurate or not;
    • the processing is unlawful, but you do not want us to erase your data; or
    • we no longer need the personal data for our processing, but you need the data to assert, exercise or defend legal claims.
  6. Right to data portability: You can request an electronic copy of your personal data that you provide to us, that we store electronically and that we process when we have entered into a contract with you. You can also ask us to provide it directly to another party.
  7. Right to object to the processing of your personal data: You can object to the processing of your personal data when we rely on a legitimate interest as the legal basis for processing. If you object to the processing of your personal data, we must demonstrate compelling reasons to continue to do so. We believe that we have demonstrated compelling reasons in the “Lawful basis for processing your personal data” section.
  8. Rights related to automated decision making: We don't make automated decisions about you, so this right doesn't apply.

If your rights under the Data Protection Act are violated, you may be entitled to compensation for damage caused by violating the Data Protection Act.

It is important that you make sure you have read this Privacy Policy - and if you feel that we have not processed your information in accordance with this notice, please let us know as soon as possible. You can also file a complaint with the Data Protection Authority (AP), the data protection regulator in the Netherlands. Information on how to do this can be found on the website at www.autoriteitpersoonsgegevens.nl.

Changes to this Privacy Policy

Wellis may add, change or otherwise amend this Privacy Policy from time to time. We will warn you on the website and/or send you an email when changes are made.

CONTACT

Questions about this privacy policy, our websites or apps, or our services in general should be directed to one of the following people:

By mail: Amelio Health BV with the subject line “Data Protection”, Hoogstraat 42, 2861 Onze-Lieve-Vrouw-Waver, Belgium.

By email: support@getwellis.com, with the subject line “Data Protection”.