Welliba
Privacy Notice

Last revised on 4th July, 2022

1. Overview

Welliba® designs tools that empower and inspire you to improve your experience at work and at home. Living a life that is Well and In Balance requires people to fully see their lives as they really are.

At Welliba we are all about enabling you to improve your present experience in ways that work for you. The better we understand you, the better we can enable you. We appreciate this means you have to trust us with information that is important to you, and we want to be transparent about how we use it.

This Privacy Notice (“Notice”) provides you with relevant information as to what personal data is collected, how we process your personal data, with whom we share it, how long we keep it when you visit our website (https://www.welliba.com). This Notice also provides details of how to contact us if you have any queries or concerns about our use of your personal data. Please note that some information is only applicable where the EU General Data Protection Regulation (“GDPR”) applies to you. This Notice does not apply to your use of Welliba Lounge and Welliba Companion App (the “Welliba Service”). Any data (including personal data) that is collected through the Welliba Service is processed in accordance with its separate data protection policies.

Our use of Cookies is described in our Cookie Policy.

2. Controller & Welliba Data Protection Officer

The below stated entity is the controller for your personal data. You can also use these details to contact our Data Protection Officer:

Welliba Ireland Ltd.

Block 3 Harcourt Centre,
Harcourt Road,
Dublin 2,
Ireland.

E-Mail: privacy@welliba.com

 

3. Purpose and Legal Basis

Below you will find information about how we process your personal data, the purpose for our processing, and the legal basis according to the GDPR if applicable:

3.1. WEBSITE USERS

3.1.1 Use of website
The purpose of our processing is:

  1. Technical provision & optimisation of our site;
  2. Understand your interests;
  3. Provide information, products and services.

Certain technical data is always processed by us when you visit our site such as IP-Address, Session ID, and information concerning your systems browser and device when you visit our website (https://www.welliba.com). This ensures that we can provide you with the best possible service, that it is secure and functions correctly.

The legal basis for our processing is our legitimate interest (Article 6(1)(f) GDPR), our legitimate interests being the successful technical provision of our website, IT security, understanding user interests and providing information on our products and services in line with our business goals.

3.2 COMMUNICATION    

The purpose of our processing is:

  1. Allow you to use our contact form;
  2. Allow you to contact us directly via a provided email address.

The legal basis for our processing is our legitimate interests (Article 6(1)(f) GDPR), our legitimate interests being to make contact with you and respond to your requests/provide requested information.

3.3. CUSTOMERS, PARTNERS & PUBLIC

3.3.1 Managing contractual relationship
The purpose of our processing is:

  1. Manage relationship;
  2. Facilitate the performance of the contractual relationship and fulfilment of contractual rights and obligations;
  3. Facilitate communications.


The legal basis for our processing where there is a direct contractual relationship is the carrying out of such contract (Article 6(1)(b) GDPR). Where there is no direct contractual relationship, our legal basis for the processing is our legitimate interests (Article 6(1)(f) GDPR). Our legitimate interests in the processing are managing contact persons for communication and customer care and carrying out of the contractual relationship and related rights and obligations in relation to our business.

3.3.2 Marketing
The purpose of our processing is:

  1. Send you marketing material such as emails and/or newsletters;
  2. Allow you to participate in webinars or other promotional/informational offers;
  3. Send you technical information and/or legal updates.


Where you have consented to us processing your personal data for marketing purposes, our processing is based on this consent (Article 6(1)(a) GDPR). Where you have purchased goods or services from us in the past, we may send you similar promotional material based on our legitimate interests (Article 6(1)(f) GDPR) – our legitimate interest being the promotion of our products.

4.  General Information
 

4.1. Recipients of your Personal Data

Here you will find information about recipients of your personal data. We only share your personal data where it is necessary. We will never share your personal data without a valid reason or interest connected to the above stated purposes in section 3 of this Notice.

4.1.1 Internal & Affiliates of Welliba
We will share your personal data internally and possibly also with our affiliates where required. We only do this where we have a defined reason for doing so.

4.1.2 Unaffiliated third parties

  1. We may share your session related personal data with unaffiliated third parties who perform administrative, business, marketing, professional, payment or technological support functions.              
  2. Where we engage external service providers to support us in promotional and/or advertising activities, your personal data will be shared with them to the extent necessary such as HubSpot.
  3. If we are obliged to share your personal data due to legal requirements, we will do so to the extent necessary in line with our legal obligations. We reserve the right to contact appropriate authorities when activities that are illegal or violate our policies occur on our website.


4.2. Transfer to third countries and/or international organisations

If you are located in the European Union, personal data collected may be processed in a country where the adequacy of that countries data protection laws have not been approved by an adequacy decision of the European Commission. Some service providers, for example, may be based outside the EU. Where we transfer personal data in this manner, we will take all steps reasonably necessary to ensure that your personal data is protected to an acceptable EU standard. The safeguards in place with regard to the transfer of your personal data outside of the EEA to third parties shall include (but shall not be limited to) the entry by us into appropriate contracts with all transferees of such and the carrying out of risk assessments and adoption of supplementary and/or mitigating measures to ensure compliance with GDPR.

If you would like more information as to how we protect your personal data in these circumstances, please contact the Data Protection Officer with the contact details we provided above or contact us at privacy@welliba.com

4.3. Storage of your Personal Data 

We only store your personal data for a period reasonable for our purposes of processing and/or for a period of time that is required of us by applicable laws. This may include retaining your personal data as necessary to comply with our legal obligations, to resolve disputes, to enforce our agreements, to support business operations, and to continue to develop and improve our website.

We will implement appropriate technical and organisational measures to ensure a level of security appropriate to the risks that are presented by the processing of your personal data. In particular, we will consider the risks presented by accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to your personal data transmitted, stored or otherwise processed.

 We do not process your data any longer than we need to. If you would like more information about our retention periods, please contact our Data Protection Officer with the contact details that we provided above.

4.4 Your rights

You can use the contact information provided above to - based on your specific situation and subject to our review to exercise the following rights set out in the table below. We will respond to any rights that you exercise within one (1) month of receiving your request, unless the request is particularly complex in which case, we will respond within three (3) months (we will inform you within the first month if it will take longer than one (1) month for us to respond.

Right

Further Information

Right of Access (Article 15 GDPR)

You have the right to request a copy of the personal data held by us about you.

We will usually provide this free of charge.  We will only charge you for making such an access request where we feel your request is unjustified or excessive.

For security reasons, we will take reasonable steps to confirm your identify before providing you with any personal data we may hold about you.
 

Right of Rectification (Article 16 GDPR)

You have the right to request that we amend any inaccurate or incomplete personal data that we have about you.
 

Right to Object (Article 21 GDPR)

You have the right to ask us to stop using your personal information, and we will comply unless there is a legal basis for us to continue using it, which we will explain to you.
 

Right to Erasure (Article 17 GDPR)

You have the right to ask us to erase your personal data where:

It is no longer necessary to perform our contract with you;

You object to the processing and we have no overriding legitimate grounds;

Your personal data has been unlawfully processed; or

It must be erased to comply with a legal obligation. 

Sometimes we have to maintain records for legal reasons. If we cannot comply with your request then we will contact you and explain why. If you ask us to stop using your information we will still keep it, but we will not do anything with it.
 

Right to Restriction of Processing (Article 18 GDPR)

You have the right to ask us to restrict processing your personal data in the following situations:

  1. Where you contest the accuracy of your personal data;
  2. Where the processing is unlawful and you do not want us to delete your personal data; or
  3. Where we no longer need your personal data for the purposes of processing but you require the data in relation to a legal claim.
  4. When you exercise this right we may only store your personal data

We may not further process the data unless you consent or the processing is necessary in relation to a legal claim or to protect the rights of another person or for reason of important public interest.

We will inform you before the processing restriction is lifted.
 

Right to Data Portability (Article 20 GDPR)

You have rights to obtain and reuse your personal data for your own purposes across different services. You can request that we transfer information we hold about you to you or a third party in electronic form, where this is technically feasible.
 

Right to be informed

You have the right to clear, transparent and easily understandable information about how we use your information and your rights. 
 

Right to Withdraw Consent

Where processing is based on your consent, you have the right to withdraw your consent at any time with future effect by contacting privacy@welliba.com or by adjusting the cookie settings in our cookie layer on our website (https://www.welliba.com).

However, if you do withdraw your consent we may not be able to continue to provide the service we offer to you.

4.5. Complaints

You may submit a complaint regarding your personal information to a supervisory authority regarding our processing of your personal data.

4.6. Provision of Personal Data

You are not legally required to share your personal data with us. However, where our processing of your personal data is based on Article 6(1) (a), we cannot carry out the processing without your consent. Where our processing of your personal data is based on Article 6(1)(b) of the GDPR, we cannot carry out the contractual relationship without your personal data. Where our processing is based on another legal basis, it will often not be possible to fulfil the intended purpose without your personal data, or at least such fulfilment would be restricted without the provision of such personal data.