Legal
Data processing — DPA summary
Summary of the DPA schedule to the MSA · updated 2026-08-08
Every platform engagement includes a data processing agreement as a schedule to the MSA. This page summarises its structure; the signed DPA is the binding text.
1. Roles
For end-user data our customers send to the platform, the customer is the controller and WELLIX APPS TECHNOLOGIES FZCO processes on documented instructions. Customers keep ownership of their input data and customer-specific outputs.
2. Processing rules
- Pseudonymisation at ingestion; consent signals honoured end-to-end.
- No transfer of one customer's datasets to another, ever.
- Aggregated, de-identified telemetry may be used to secure and improve the platform where legally supported; re-identification is prohibited.
- Health and nutrition data receives the stricter configuration required by the customer's markets.
3. Regions
Primary compute and data regions are outside the United States. Customer-specific hosting reviews are available during scoping.
4. Sub-processors
The current list is published at /legal/subprocessors and provided with the DPA during onboarding, with change notice per the DPA.
5. Full text
The complete DPA is provided with the MSA during scoping: support@wellix.io.
This summary is informational and does not replace the DPA. In any conflict, the signed schedule controls.