Privacy policy
Last updated: 11 September 2026 · Version 2.1
This Privacy Policy explains how P4Q HEALTH S.L. ("Welleo", "we", "us") collects, uses, shares and protects personal information. It covers two different things, and they are kept apart on purpose:
- Part A — The Welleo online store. Everything you do at www.welleo.com: browsing, ordering, paying, shipping, returns, newsletters and advertising.
- Part B — The Welleo app and your health data. Everything the Welleo mobile app processes: test results, uploaded lab reports, facial-scan estimates, cycle data and your health profile. Health data is never used for marketing or advertising.
Part C applies to both. If you only shop with us, Part A is the part that concerns you. If you use the app, both do.
Who we are and how to reach us
Data controller
P4Q HEALTH S.L.
Calle Nuestra Señora de la Guía 19, 48810 Alonsotegi, Bizkaia, Spain
Tax ID (NIF): B67665364
Registered in the Commercial Registry of Bizkaia, volume 6046, folio 66, sheet BI77644, entry 1
Privacy contact
For anything to do with your personal information, including the rights set out below, write to hello@welleo.com or call +34 944 98 20 28.
Part A — The Welleo online store
The store at www.welleo.com is hosted on Shopify, which is what allows us to run it.
A1. Information we collect
- Contact details — name, billing address, shipping address, phone number, email address.
- Payment information — payment method, transaction details and payment confirmation. Full card numbers are handled by our payment providers and are not stored by us.
- Account information — username, password, preferences and settings.
- Transaction information — items viewed, added to cart or wishlist, purchased, returned, exchanged or cancelled, and your order history.
- Communications with us — what you write when you contact customer support.
- Device information — device, browser, network connection, IP address and similar identifiers.
- Usage information — how and when you interact with the store.
A2. Where it comes from
- Directly from you, when you create an account, order, or contact us.
- Automatically, from your device and through cookies and similar technologies.
- From service providers acting on our behalf.
- From partners such as payment and shipping providers.
A3. Why we use it, and on what legal basis
| Purpose | Legal basis (GDPR Art. 6) |
|---|---|
| Taking and fulfilling your order, payment, shipping, returns and exchanges, managing your account | Performance of a contract — Art. 6(1)(b) |
| Customer support and responding to you | Performance of a contract — Art. 6(1)(b); or legitimate interest — Art. 6(1)(f) |
| Marketing emails, promotions and personalised advertising | Consent — Art. 6(1)(a), withdrawable at any time. Where we email existing customers about similar products, legitimate interest — Art. 6(1)(f), with an unsubscribe link in every message |
| Security, fraud prevention and protecting the store | Legitimate interest — Art. 6(1)(f) |
| Invoicing, accounting and tax | Legal obligation — Art. 6(1)(c) |
| Establishing, exercising or defending legal claims | Legitimate interest — Art. 6(1)(f) |
A4. Marketing and advertising — and what it does not cover
We use store information only — your contact details, what you browsed, what you bought — to send marketing emails and to show you advertising for our products on the store and on other websites.
This never includes health data. Nothing described in Part B — no test result, no uploaded lab report, no facial-scan estimate, no cycle data, no health profile answer, and no fact derived from any of them — is used for marketing, for advertising, for audience building, or for any kind of use-based data mining. Health data is never transferred to advertising platforms, ad networks or data brokers, and is never sold.
You can withdraw marketing consent at any time using the unsubscribe link in any message, or by writing to hello@welleo.com. Withdrawing it does not stop transactional messages about your orders or your account.
A5. Who we share store information with
- Shopify — hosting and operation of the store and checkout.
- Payment providers — to take and verify payment.
- Carriers and logistics providers — to deliver your order and handle returns.
- Marketing and analytics partners — to send campaigns and measure them, where you have consented.
- Professional advisers, authorities and successors — where required by law, to enforce our terms, or in connection with a merger or similar transaction.
A6. Our relationship with Shopify
The store is hosted by Shopify, which collects and processes information about your access to and use of it in order to provide and improve the service. Information you submit to the store is transmitted to Shopify and may be processed in countries other than where you live. We also use Shopify features that draw on data from your interactions with our store, other merchants and Shopify itself. For those features Shopify is responsible for the processing, including for responding to requests about it. See the Shopify Consumer Privacy Policy and the Shopify Privacy Portal.
A7. How long we keep store information
| Category | Retention |
|---|---|
| Store account and profile | For as long as the account exists |
| Orders, invoices and accounting records | 6 years from the end of the financial year, as required by Spanish commercial and tax law |
| Customer support correspondence | For as long as needed to deal with the matter and any claim arising from it |
| Marketing consent and unsubscribe records | Until you withdraw consent, plus the record of the withdrawal itself for as long as needed to honour it |
Part B — The Welleo app and your health data
This part governs the Welleo mobile app. Everything in it is special-category data concerning health under Article 9 GDPR, and we treat it that way.
B1. The health data we process
- Biomarker results — values from Welleo rapid tests read by the test reader, values you enter yourself, values read from lab reports you upload, and results recorded for you by a pharmacy or health professional.
- Uploaded lab reports — the PDF or photograph you upload, and the values read from it.
- Facial-scan estimates — heart rate, heart-rate variability, breathing rate, blood pressure and stress index, plus derived wellness indices. These are estimates, not measurements.
- Cycle data — period log, daily check-ins, flow and symptoms.
- Health profile — height, weight, whether you smoke, whether you have diabetes, and whether you are treated for hypertension.
- Onboarding and wizard answers, and the recommendations derived from them.
- Supplement programmes and intake records.
- Appointments with pharmacies and health professionals, and your favourite pharmacies.
- Consents — which professional or organisation you have granted access to, to which categories of your record, and when.
- Access log — an append-only record of every access to your health record by a professional or organisation, which you can read in full inside the app.
- Notifications sent to you, and the categories you have muted.
We do not store your date of birth, and we do not store video from the facial scan.
B2. Legal basis
We process health data on the basis of your explicit consent under Article 9(2)(a) GDPR, together with Article 6(1)(a). Consent is asked for separately, per purpose and per source — connecting a pharmacy, granting a professional access to your record, or enabling a feature are each their own decision.
You can withdraw consent at any time in the app, under Profile → Privacy. Withdrawing a professional's or organisation's access stops any further access immediately; it does not undo accesses that already happened, and the access log keeps its record of them. Withdrawal does not affect the lawfulness of processing carried out before it.
Where we are required to keep something — for example a record needed to defend a legal claim — we say so, and we keep only that.
B3. What we never do with health data
We do not, under any circumstances:
- use health data for marketing, advertising, audience building, or any use-based data mining;
- serve you personalised or interest-based advertising based on health data;
- sell health data, or transfer it to advertising platforms, ad networks or data brokers;
- use health data to assess credit-worthiness, insurance eligibility, employment suitability or lending;
- store health data in iCloud or any consumer cloud backup service.
B4. How health data reaches us
- From you — values you enter, reports you upload, check-ins and period entries you record, answers you give.
- From a Welleo test read by the reader — at home or at a participating pharmacy.
- From a health professional or pharmacy — results and appointments they record for you, where you have consented to that link.
- From the camera, during a facial scan — processed on your device, as described in B5.
B5. Who processes health data, and what they receive
| Recipient | What they process | Location |
|---|---|---|
| Our hosting provider | The Welleo database and object storage: all of the above | European Union (Spain) |
| Our CRM (operated by us) | The product and test catalogue, professional accounts, and appointment logistics. It does not receive your results | European Union (Spain) |
| Shen.AI — facial-scan technology | Nothing. The scan runs entirely on your device. Shen.AI receives only a short-lived licence token issued by our server. No video and no vital signs ever reach them | — |
| Google (Firebase Cloud Messaging) — push notifications | A device token and the notification text. Notification text never contains a result value | United States |
| Our email provider | Your email address and the message content. Emails never contain a result value | European Union (Ireland) |
| Apple / Google — sign-in, where you choose it | Authentication only. No health data | United States |
| Map and geocoding providers — finding pharmacies near you | A location or an address. No health data | See B6 |
Qassay is not a third party. It is a brand of P4Q HEALTH S.L., the same company — a test strip read by the reader never leaves Welleo. And automated reading of uploaded reports is not switched on: today a report you upload is stored, and you enter the values from it yourself. If we ever enable automated reading, we will name the provider and where it operates in this section before a single report is sent to it.
B6. International transfers
Your health data is stored and processed inside the European Union — in Spain, with email delivery from Ireland.
The two recipients outside the EEA receive no health data: sign-in with Apple or Google, which sees only authentication, and push notifications, whose text never carries a result. Those transfers rely on the European Commission's Standard Contractual Clauses or on an adequacy decision for the country concerned.
We will update this policy before any change to where your data is processed takes effect.
B7. How long we keep health data
| Category | Retention |
|---|---|
| Test results, facial-scan estimates, cycle data, health profile, supplement records | For as long as your account exists. Deleting your account deletes them |
| Uploaded lab report files | 180 days from upload, or sooner if you delete it yourself. The values taken from a report are part of your health history and are kept separately, under the row above |
| Consents and their withdrawal | Kept as the record of what you did and did not authorise, including after your account is deleted |
| Access log | For as long as your account exists. It is append-only: it cannot be edited, by you or by us |
| Appointments | For as long as your account exists |
| Notifications sent | Kept as a delivery record, including after your account is deleted |
Deleting your account removes your health data from our systems — your results, scan estimates, cycle data, health profile, supplement records, appointments, uploaded reports and the access log. Two things survive it, as the table above says: the record of the consents you granted and withdrew, and the record that a notification was sent. Neither contains a health value. Disconnecting a professional or pharmacy does not delete anything — it stops their access from that moment on. The two are different actions with different effects, and the app says so at the point you take them.
B8. Security
- All traffic between the app and our servers is encrypted in transit (TLS).
- Uploaded lab reports are held in separate, private storage with no public address. They are served only through an authenticated request that has checked the record is yours.
- A professional can only see the categories of your record you have granted, and every access is written to the access log.
- Data used for testing and development is anonymised before it leaves production.
No system is perfectly secure, and information sent over the internet is never entirely without risk. If a breach affects your rights, we will notify you and the supervisory authority as Articles 33 and 34 GDPR require.
B9. Your rights over health data
In addition to the rights in Part C, the app gives you three of them directly:
- Delete your account and your data — Profile → Delete account → Confirm.
- Download everything we hold — Profile → Download my data, as a JSON file. A clinical export in FHIR R4 format is also available for sharing with a doctor.
- See who has looked at your record — the access log, in Profile → Privacy, together with the consents you have granted and a control to withdraw each one.
B10. Not a medical device, and not a diagnosis
The Welleo app is not a medical device, and nothing in it is a diagnosis.
Facial-scan values are wellness estimates, not clinical measurements. Neither they nor any other value in the app is used to decide a treatment, to select a clinical protocol, or to generate a referral. Results are presented for your own information and for a conversation with a health professional.
Always consult a doctor or pharmacist about your health. Never delay seeking medical advice, or disregard advice you have been given, because of something the app showed you. If you think you may have a medical emergency, contact the emergency services.
Part C — Applying to both
C1. Your rights
Under the GDPR you have the right to:
- Access — obtain a copy of the personal information we hold about you.
- Rectification — have inaccurate information corrected.
- Erasure — have your information deleted.
- Portability — receive your information in a machine-readable format and have it transmitted to another controller.
- Restriction — ask us to limit how we use your information.
- Object — object to processing based on our legitimate interests, and object at any time to direct marketing.
- Withdraw consent — at any time, without affecting processing already carried out.
- Not be subject to automated decision-making that produces legal or similarly significant effects. We do not make such decisions.
Exercise any of these in the app where indicated, or by writing to hello@welleo.com. We will respond within one month, extendable by two further months for complex requests, and we will tell you if we need the extension. We may need to verify your identity first. You may appoint someone to act for you; we will ask for proof of the authorisation. Exercising a right never costs you anything and we will never treat you differently for it.
C2. Complaints
If you are unhappy with how we handle your personal information, please write to hello@welleo.com first — it is usually the fastest route to a fix.
You also have the right to lodge a complaint with a supervisory authority. In Spain that is the Agencia Española de Protección de Datos (AEPD), C/ Jorge Juan 6, 28001 Madrid — www.aepd.es. If you live elsewhere in the EEA, you may complain to your own national authority; the list is here.
C3. Children
Welleo is not intended for anyone under 16, and we do not knowingly collect personal information from anyone under 16. If you are a parent or guardian and believe a child has given us their information, write to hello@welleo.com and we will delete it.
C4. Links to other sites
Our store and app may link to sites we do not control. We are not responsible for their content, their privacy practices or their security. Read their policies before giving them your information.
C5. Changes to this policy
We update this policy when our practices change, or for operational, legal or regulatory reasons. The revised version is published here with a new "Last updated" date and version number, and where the change is significant we will tell you before it takes effect. The table below records what changed and when.
| Version | Date | What changed |
|---|---|---|
| 2.1 | 11 September 2026 | Corrections from a verification pass. Uploaded report files are kept for 180 days, not for the life of the account. Consents and notification records are stated as surviving account deletion, which is what happens. Qassay is named as a brand of the controller rather than a separate recipient, and automated reading of uploaded reports is stated as not enabled — it is not. Processing locations are now named: Spain, with email from Ireland. Removed a claim that the minimum age is aligned across both app stores, which has not yet been checked. |
| 2.0 | 11 September 2026 | Split into a store part and an app-and-health-data part. Added legal bases, an inventory of the health data processed, the Article 9 basis, an explicit exclusion of health data from marketing and advertising, named recipients, per-category retention, security practices, a named privacy contact, and the statement that the app is not a medical device. Merged a duplicated rights section. Recipient locations and the retention of commercial records are stated in general terms pending a completed inventory; they will be named in a later version. |
| 1.0 | 5 August 2026 | Initial version. |
C6. Contact
P4Q HEALTH S.L.
Calle Nuestra Señora de la Guía 19, 48810 Alonsotegi, Bizkaia, Spain
Privacy contact: hello@welleo.com · +34 944 98 20 28
For the purposes of data protection law, P4Q HEALTH S.L. is the controller of your personal information.