Privacy Policy
WellDesk — welldesk.ai
Last updated: July 28, 2026
1. Who We Are
WellDesk ("we", "us") operates the WellDesk platform at welldesk.ai — an online service that lets customers create an account and book appointments and services with independent businesses ("Shops").
We are established in Spain and operate as a sole trader (autónomo).
| Data Controller | WellDesk |
| Privacy contact | [email protected] |
This Privacy Policy explains how we collect, use, share, and protect your personal data when you use the WellDesk platform, and what rights you have under the EU General Data Protection Regulation (GDPR) and Spanish Organic Law 3/2018 on Data Protection and Digital Rights (LOPDGDD).
Please also read our Terms & Conditions, Legal Notice, and Cookie Policy, which together govern your use of the platform.
2. Our Role as Platform Operator vs. Shops
WellDesk is the data controller for your platform account and identity data, and for the operation of the platform itself.
Each Shop you book with is an independent data controller for the personal data it processes in order to fulfil and manage your booking and its own customer relationship with you. When you make a booking, we share the relevant booking details with that Shop so they can provide the service. How the Shop then uses your data is governed by that Shop's own privacy policy — we encourage you to read it.
3. What Personal Data We Collect
3.1 Account and identity data
- Full name
- Email address
- Phone number
- Password (stored in hashed form — we never store your plain-text password)
3.2 Booking data
- Services booked, date and time, and which Shop
- Any optional notes you provide when making a booking
3.3 Payment data
Payments on the platform are processed by Stripe. When you pay, your card details are entered directly with Stripe and are not transmitted to or stored by WellDesk. We retain only payment metadata: amount, currency, payment status, the last four digits of the card used, and Stripe's own transaction identifiers.
3.4 Technical and usage data
- IP address
- Device type and browser information
- Log data (pages visited, timestamps, errors)
- Cookies and similar technologies (see Section 10 and our Cookie Policy)
3.5 What we do NOT collect
We do not collect or store special-category (sensitive) personal data such as health information, medical notes, or allergies.
3.6 Google Calendar integration data (if enabled)
If a Shop enables the Google Calendar integration (see Section 7), we additionally collect:
- Google account email address, for the Shop owner/admin and for any staff member who connects their Google account
- OAuth access and refresh tokens (encrypted at rest), for the Shop owner/admin who connects Google Calendar
4. Why We Process Your Data and on What Legal Basis
| Purpose | Legal basis (GDPR Art. 6) |
|---|---|
| Creating and managing your account | Art. 6(1)(b) — performance of a contract |
| Processing and managing your bookings | Art. 6(1)(b) — performance of a contract |
| Sharing booking details with the relevant Shop | Art. 6(1)(b) — performance of a contract |
| Processing payments via Stripe | Art. 6(1)(b) — performance of a contract |
| Sending transactional emails (booking confirmations, reminders) | Art. 6(1)(b) — performance of a contract |
| Maintaining accounting and tax records | Art. 6(1)(c) — legal obligation |
| Anti-money-laundering compliance | Art. 6(1)(c) — legal obligation |
| Security, fraud prevention, and abuse detection | Art. 6(1)(f) — legitimate interests |
| Improving and monitoring platform performance | Art. 6(1)(f) — legitimate interests |
| Non-essential cookies and analytics | Art. 6(1)(a) — consent |
| Marketing communications (if opted in) | Art. 6(1)(a) — consent |
You may withdraw consent at any time for processing based on consent (Art. 6(1)(a)) by contacting us at [email protected] or using the unsubscribe link in any marketing email. Withdrawal does not affect the lawfulness of processing carried out before withdrawal.
5. Who We Share Your Data With
We do not sell your personal data. We share it only as described in this policy.
| Recipient | Role | Purpose |
|---|---|---|
| Stripe Payments Europe, Ltd. | Processor | Payment processing via Stripe Connect |
| Twilio SendGrid | Processor | Transactional email delivery (booking confirmations, etc.) |
| Cloudflare R2 | Processor | File and object storage, CDN |
| DigitalOcean | Processor | Application hosting — data hosted in the EU (Amsterdam region) |
| Processor | Map embeds displayed on Shop and booking pages; for Shops that enable Google Calendar integration, synchronisation of booking events to the Shop's dedicated Google Calendar (see Section 7) | |
| Relevant Shop(s) | Independent controller | Fulfilment and management of your booking |
We require all processors to process your data only on our instructions and in accordance with applicable data protection law. Each Shop, as an independent controller, is responsible for its own compliance.
6. International Transfers
Some of our service providers — including Stripe, Twilio SendGrid, Cloudflare, and Google — may process personal data outside the European Economic Area (EEA), including in the United States. Where this occurs, we rely on appropriate safeguards, including:
- EU Standard Contractual Clauses (SCCs) approved by the European Commission; and/or
- The EU-US Data Privacy Framework, where the recipient is certified.
Our application infrastructure (DigitalOcean) is hosted within the EU (Amsterdam region, AMS3), so your core account and booking data is stored in the EEA.
You can request further information about the safeguards in place by contacting us at [email protected].
7. Google Calendar Integration
Shops may optionally enable a Google Calendar integration to keep a shared shop calendar of bookings in sync with Google Calendar. This section describes what Google user data we access, how it is used, and the safeguards that apply.
7.1 Owner/Admin Connection
When a Shop owner or admin connects Google Calendar, we request the openid, email, and https://www.googleapis.com/auth/calendar scopes, and access their Google account email address. The calendar scope is used only to:
- create a dedicated secondary calendar for the Shop under the connected Google account, named by the owner/admin when connecting (default: "WellDesk Bookings" if no name is provided);
- insert, update, and delete booking events on that calendar as bookings are created, rescheduled, or cancelled; and
- grant a read-only share (Google Calendar ACL) of that calendar to staff members who connect their own Google account.
We do not access, read, or modify any other calendar in the owner's or admin's Google account.
7.2 Staff Connection
When a staff member connects their Google account to receive a read-only view of the shop calendar, we request only the openid and email ("userinfo.email") scopes. This is used solely to identify the staff member's Google account so that we can grant them a read-only calendar share. No calendar scope is requested from staff, and no staff OAuth tokens are stored.
7.3 Storage, Retention, and Revocation of Google Tokens
OAuth access and refresh tokens obtained from the owner/admin connection are encrypted and stored in our database while the connection is active. When you disconnect the integration or revoke access, we revoke the authorisation with Google and, in all cases, immediately invalidate the stored token so that it can no longer be used to access your Google account. The encrypted, now-unusable token record is retained on the disconnected connection (e.g. to support a later reconnect), rather than immediately hard-deleted. You can revoke access, or independently confirm that access has been revoked, at any time:
- using the "Disconnect" action in WellDesk Shop Settings; or
- directly from your Google Account at myaccount.google.com/permissions.
7.4 Customer Data Placed on Google Calendar
When a Shop enables this integration, each booking event written to the Shop's Google Calendar includes only the minimum fields needed to identify the appointment: the customer's first name, the service booked, and the assigned staff member's name. We do not include payment data, health-related notes, or the customer's full contact details in these events. By enabling the integration, a Shop is transferring this limited booking information to a Google-hosted calendar, and the Shop remains responsible, as an independent controller, for how it uses that calendar.
7.5 How We Use Google User Data
Consistent with the Google API Services User Data Policy, WellDesk's use of Google user data is limited as follows:
- Google user data is not used for advertising purposes.
- Google user data is not sold.
- Google user data is not used to train or improve artificial intelligence or machine learning models.
- Google user data is not transferred to any other party, except as necessary to provide this feature (for example, to the relevant Shop, as described in Section 7.4) or as required by applicable law.
WellDesk's use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
8. How Long We Keep Your Data
| Data category | Retention period |
|---|---|
| Account and booking data | For as long as your account is active |
| Account and booking data after closure | Deleted or anonymised, unless retention is required by law |
| Tax and accounting records | Up to 6 years, as required under Spanish commercial and tax law |
| Payment metadata | As required by applicable financial regulations |
| Log and technical data | Up to 12 months (rolling) |
| OAuth tokens (Google Calendar integration) | Until the Shop owner/admin or staff member disconnects or revokes access, at which point the token is invalidated at Google and can no longer be used; the invalidated encrypted record is retained to support a later reconnect |
When retention periods expire, data is securely deleted or irreversibly anonymised.
9. Your Rights
Under GDPR and LOPDGDD you have the following rights regarding your personal data:
- Access — request a copy of the data we hold about you
- Rectification — ask us to correct inaccurate or incomplete data
- Erasure — ask us to delete your data ("right to be forgotten"), subject to legal retention obligations
- Restriction — ask us to limit processing while a dispute is resolved
- Portability — receive your data in a structured, machine-readable format
- Objection — object to processing based on legitimate interests
- Withdraw consent — at any time for consent-based processing, without affecting prior processing
To exercise any of these rights, contact us at [email protected]. We will respond within one calendar month. We may ask you to verify your identity before acting on a request.
Right to lodge a complaint: If you are not satisfied with our response, you have the right to lodge a complaint with the Spanish supervisory authority:
Agencia Española de Protección de Datos (AEPD)
www.aepd.es
C/ Jorge Juan, 6, 28001 Madrid, Spain
10. Cookies
We use cookies and similar tracking technologies on the platform. Essential cookies are necessary for the platform to function and are placed without consent. Non-essential cookies (analytics, preferences) are only placed with your prior consent.
For full details of the cookies we use, their purposes, and how to manage your preferences, please read our Cookie Policy.
11. Security
We implement appropriate technical and organisational measures to protect your personal data against unauthorised access, alteration, disclosure, or destruction. These include encrypted data transmission (HTTPS/TLS), hashed password storage, access controls, and regular security monitoring.
No method of transmission over the internet is completely secure. If you believe your account has been compromised, please contact us immediately at [email protected].
12. Children
The WellDesk platform is not directed at children under the age of 14. Under LOPDGDD Art. 7, users under 14 may only use the platform with the consent of a parent or person holding parental responsibility. If we become aware that we have collected personal data from a child under 14 without the appropriate consent, we will delete that data promptly. If you believe a child's data has been collected without proper consent, please notify us at [email protected].
13. Automated Decision-Making
We do not carry out any automated decision-making or profiling that produces legal effects or similarly significant effects on you.
14. Changes to This Policy
We may update this Privacy Policy from time to time. When we make material changes, we will notify you by email or by a prominent notice on the platform, and we will update the "Last updated" date at the top of this document. We encourage you to review this policy periodically.
Continued use of the platform after changes take effect constitutes acceptance of the updated policy, to the extent permitted by applicable law.
15. Contact
For any questions, concerns, or requests relating to this Privacy Policy or your personal data, please contact us:
WellDesk
Email: [email protected]
This Privacy Policy should be read together with the WellDesk Terms & Conditions, Legal Notice, and Cookie Policy.