Data & security
Ownership is written down
The split between what you own and what we own is contractual, not implied. This page summarises it; the MSA and DPA state it precisely.
Who owns what
| Yours | Ours |
|---|---|
| Your app, brand and customer relationships | Platform code and generic algorithms |
| Your configuration and input data | Model architecture and model weights |
| Customer-specific outputs | SDKs, documentation, general improvements |
Dedicated fine-tuned artefacts change hands only under express Order Form terms; model weights are not transferred by default.
Processing rules
Under contract
All processing runs under the MSA with a DPA schedule. Sub-processors are listed at /legal/subprocessors and provided to customers during onboarding.
No cross-customer transfer
One customer's datasets are never transferred to another. Aggregated, de-identified telemetry may be used to secure and improve the platform where legally supported — with no re-identification.
Health data, stricter config
Health and nutrition data receives the stricter configuration required by the customer's markets, agreed during onboarding.
Regions
Primary compute and data regions are outside the United States. Customer-specific hosting reviews are available on request.
Security posture
| Identity & data | Pseudonymisation at ingestion; consent signals honoured end-to-end; access controls on every surface. |
|---|---|
| Operations | Observability, security logging and audit trails run alongside every stage of the pipeline. |
| Models | Versioned deployments with monitored serving and rollback; experiments isolated per customer. |
Questions a security review would ask are welcome before an Order Form is signed: support@wellix.io.