Wellmade Intelligence Privacy Policy
Version: pilot 1.1
Effective date: 29 September 2026
This English version is provided for convenience. If there is any discrepancy, the Polish version of the Privacy Policy prevails.
1. Data Controller
- The controller is SOMA Sp. z o.o., registered office in Warsaw, ul. Białej Floty 2/2, 02-654 Warsaw, Poland, entered in the National Court Register under KRS 0001164842, tax ID (NIP) 5214111998, REGON 541342374, share capital PLN 10,000, registered by the District Court for the Capital City of Warsaw in Warsaw, 13th Commercial Division of the National Court Register (the “Controller”).
- Privacy enquiries may be sent to k.bodziony@somahealthco.com.
2. Personal data we process
- Account data – email address, encrypted password, registration and login dates, role in the Service.
- Company data – company name, files and company information provided by the Tester.
- Conversation content – questions to the Agent, answers, projects, goals and plans stored in the Service.
- Reports and feedback – reports of incorrect answers, description and related conversation.
- Usage data – number of questions, Service usage cost and technical traces of Agent operation.
- Technical data – IP address, browser and device type, server logs.
- Correspondence – emails sent to the Controller.
- Data submitted through askwellmade.com forms – data included in the contact, partner application or report request forms, including name, email, company, website, topic, request scope and message content.
3. Purposes and legal bases
| Purpose | Legal basis under the GDPR |
|---|---|
| Account creation and provision of the Service, including Agent responses | Art. 6(1)(b) – performance of a contract |
| Review of conversations and reports to improve the Service during the Pilot | Art. 6(1)(f) – legitimate interest: development and improvement of the Service |
| Usage limits, security and abuse prevention | Art. 6(1)(f) – legitimate interest: security of the Service |
| Handling contact forms, report requests, cooperation and partnership enquiries, and business correspondence | Art. 6(1)(f) – legitimate interest: business communication and handling enquiries; where the contact directly leads to a contract with an individual, also Art. 6(1)(b) |
| Displaying information about paid plans in the Service after the Pilot | Art. 6(1)(f) – legitimate interest: development of our own service |
| Marketing communication by email or another electronic channel | only where required, after the appropriate consent has been obtained; for personal-data processing – Art. 6(1)(a) |
| Establishment, exercise or defence of legal claims | Art. 6(1)(f) – legitimate interest: protection of legal rights |
Providing data is voluntary, but an email address is required to create an Account or receive a reply to a form submission.
4. Recipients and processors
The Controller may use the following providers to operate the Service and website:
- Supabase Pte. Ltd (supabase.com) – database, authentication and Account-related technical services.
- Vercel Inc. (vercel.com) – hosting and technical logs.
- Anthropic PBC (anthropic.com) – AI models used by the Agent. The question, conversation context and information necessary to generate an answer may be sent to Anthropic. Under Anthropic's commercial terms, business customer data is not used for model training by default.
- FormSubmit (formsubmit.co) – technical processing of forms on askwellmade.com and forwarding submissions to the Controller's mailbox. According to FormSubmit's public documentation, submissions may be retained by the provider for up to 30 days.
- The Controller's email provider – operation of the mailbox receiving messages and form submissions.
Public authorities may also receive data where required by law.
Queries to the Agent may trigger requests to external market-data sources. Such requests should contain only the search terms and parameters needed to perform the request, without the Tester's personal data unless personal data is necessary for a specific function.
5. Transfers outside the EEA
Some infrastructure or AI providers may process data outside the European Economic Area, including in the United States or Singapore. Where such a transfer occurs, the Controller relies on a lawful GDPR transfer mechanism appropriate to the provider, including an adequacy decision, the European Commission's Standard Contractual Clauses or another applicable safeguard. Information about the mechanism used may be requested using the contact details in section 1.
6. Retention
- Account data, company data, conversations and reports – for the duration of the Pilot and any read-only period, then deleted 90 days after the Pilot ends. If the Tester moves to a paid plan, retention will be governed by the terms applicable to that plan.
- At the Tester's request, the Account and related data may be deleted earlier, subject to data that must be retained for legal or security reasons.
- Technical and security logs – generally up to 12 months, unless longer retention is required to investigate an incident or defend legal claims.
- Form submissions and correspondence – for the time needed to handle the enquiry and then for the period reasonably necessary to document the contact and defend potential claims. A technical copy may be retained by FormSubmit for up to 30 days according to the provider's documentation.
- Data required to establish, exercise or defend legal claims – until the applicable limitation periods expire.
7. Your rights
You may have the right to access and obtain a copy of your data, rectify it, request deletion or restriction, data portability where applicable, object to processing based on legitimate interests, withdraw consent where processing is based on consent, and lodge a complaint with the Polish Data Protection Authority (UODO).
To exercise your rights, contact the Controller using the address in section 1.
8. Automated decisions
The Agent generates responses automatically but does not make decisions about the Tester that produce legal effects or similarly significantly affect the Tester within the meaning of Art. 22 GDPR. We do not profile Testers for such a purpose.
9. Cookies and similar technologies
The Service may use cookies, local storage and similar technologies that are necessary for login, session management, security and settings. As of the effective date of this Policy, askwellmade.com does not use advertising or analytics cookies that require separate consent. If such tools are introduced, this Policy and the consent mechanism will be updated accordingly.
10. Third-party personal data
Do not submit special categories of personal data, especially other people's health data. Submit other people's personal data only where it is genuinely necessary to use the Service and you have an appropriate legal basis to do so.
11. Security
We apply technical and organisational measures appropriate to the nature of the Service. No internet system can guarantee complete security. Testers should protect login credentials, use up-to-date software and not share Accounts with unauthorised persons.
12. Changes to this Policy
We will inform users about material changes by email or within the Service where required or appropriate. The current version is always available on the Wellmade Intelligence website.