Data & security

Ownership is written down

The split between what you own and what we own is contractual, not implied. This page summarises it; the MSA and DPA state it precisely.

Who owns what

Ownership boundaries
YoursOurs
Your app, brand and customer relationships Platform code and generic algorithms
Your configuration and input data Model architecture and model weights
Customer-specific outputs SDKs, documentation, general improvements

Dedicated fine-tuned artefacts change hands only under express Order Form terms; model weights are not transferred by default.

Processing rules

Under contract

All processing runs under the MSA with a DPA schedule. Sub-processors are listed at /legal/subprocessors and provided to customers during onboarding.

No cross-customer transfer

One customer's datasets are never transferred to another. Aggregated, de-identified telemetry may be used to secure and improve the platform where legally supported — with no re-identification.

Health data, stricter config

Health and nutrition data receives the stricter configuration required by the customer's markets, agreed during onboarding.

Regions

Primary compute and data regions are outside the United States. Customer-specific hosting reviews are available on request.

Security posture

Platform controls
Identity & data Pseudonymisation at ingestion; consent signals honoured end-to-end; access controls on every surface.
Operations Observability, security logging and audit trails run alongside every stage of the pipeline.
Models Versioned deployments with monitored serving and rollback; experiments isolated per customer.

Questions a security review would ask are welcome before an Order Form is signed: support@wellix.io.