Privacy policy Wellbeinn

1. Identity of the data controller

  • Legal name: Wellbeinn Performance, S.L. ("Wellbeinn")
  • Tax ID (CIF): B-16407355
  • Registered office: P.I. Les Pedreres C/ Primer de maig 11, 03610 Petrer, Alicante.
  • Commercial registry: Commercial Registry of Alicante, Sheet A-199979, IRUS 1000444260360, Electronic folio, Entry 3
  • Data protection contact: privacy@wellbeinn.com

Wellbeinn complies with Regulation (EU) 2016/679 ("GDPR") and Spanish Organic Law 3/2018 of 5 December ("LOPDGDD").

2. Scope and informative nature

This Policy is informative in nature and describes how Wellbeinn processes personal data in the context of:

  • The Wellbeinn mobile application for iOS and Android (the "App").
  • Use of the Wellbeinn V8 wearable and other connected devices in the Wellbeinn ecosystem, which communicate with the App over Bluetooth Low Energy (BLE).
  • The wellbeinn.com website, as regards registration, support and account communications.

Reading this Policy does not by itself constitute or replace the explicit consent required to process health data. That consent is obtained through a separate, specific and unambiguous affirmative action within the App.

Wellbeinn retains evidence of the consent given and of its withdrawal, including user identifier, date and time, the exact version of the text accepted, language and authorised purposes (Art. 7(1) GDPR), in accordance with the periods in §6.

Express statement. Wellbeinn does not sell your personal data, does not disclose it to data brokers or advertising networks and does not use it for third-party advertising. The only disclosures to third parties contemplated in this Policy are (i) the processors listed in §7, acting on our instructions, and (ii) organisations you expressly authorise on a case-by-case basis under §7 bis.

3. Personal data we process

3.1 Identity and account data

First name and surname, email address, password (stored as a one-way hash managed by our identity provider; Wellbeinn has no access to the plaintext), optional profile picture, federated sign-in identifiers where you choose to register with Google, and a unique internal identifier assigned by our system.

We also process the status of the personalisation options you enable (§4 bis.2) and of the organisation authorisations you grant (§4 bis.4), which can be reviewed under Profile → Legal and privacy.

3.2 Health-related data — special category (Art. 9 GDPR)

Through the Wellbeinn V8 wearable, other connected devices and the data you provide to calibrate the service, we process biophysiological and activity information: cardiovascular metrics (heart rate and variability, HRV/RMSSD), sleep and rest data, oxygenation and skin temperature indicators, physical activity parameters, and a basic health profile (date of birth, biological sex, weight and height). This list is indicative: the App may process these and other similar wellbeing and health data within the purposes described in this Policy, with the same legal classification and level of protection.

The derived indicators the App calculates from this data — sleep quality, recovery, vitality, activation, stress, sleep efficiency and other aggregate indicators of physiological state — are likewise considered health-related data (Art. 9 GDPR) and receive the same enhanced protection, legal basis and retention periods as the raw data.

This data is retained at high temporal resolution because that is necessary to calculate the indicators the App provides, and is stored in your personal account. It is not disclosed to third parties unless you expressly authorise it through the feature described in §7 bis. It is deleted in accordance with §6.

Wellbeinn does not process biometric data within the meaning of Art. 4(14) GDPR.

3.3 Device data

Device identifier, model and firmware version, Bluetooth identifier (on Android this may be a persistent public MAC address; on iOS it is typically a rotating UUID issued by the operating system), battery status and connection and disconnection events.

3.4 Technical and usage data

App installation identifier, operating system and version, phone model and device language, technical error and event logs, and timestamps of actions performed within the App.

Note on advertising tracking. The App does not integrate third-party analytics SDKs, does not share data with advertising networks and does not use third-party cookies. We do not build profiles for third-party advertising purposes and we do not disclose your data to advertisers. If you enable Option 3 (§4 bis.2), we use a segment label derived from your indicators to personalise our own commercial communications; that processing is described in full in that Option.

3.5 Data arising from use of the Coach AI assistant

Contextual memory across conversations.
To avoid asking you again about something you have already told the assistant, and to avoid suggesting activities that are incompatible with any limitations you have stated, the assistant retains a limited set of data that you expressly provide: a physical or activity-related limitation, your goal in your own words, your life context and your preferences.

Only what you expressly state is retained: the assistant does not infer or record its own conclusions about your health based on the conversation. You can view, edit or delete this information at any time via the app. The retention period is set out in §6.

Information you provide to the assistant (§3.5): scope, purpose, context and preferences | For as long as you keep the account open, or until you amend or delete this information, with reconfirmation every 12 months 

What it remembers. In addition to the conversation history (§6), the assistant uses the data you have provided in accordance with §3.5 as context. It does not retain its own inferences or clinical labels.

3.6 Archetype and segment label

Based on your derived indicators, the App assigns you an archetype (a wellbeing behaviour group) and a segment label. Both derive from health data and receive the same level of protection under Art. 9 GDPR.

They are only used for commercial communication purposes if you expressly enable Option 3 (§4 bis.2).

4. Legal bases for processing

Data category / processing Legal basis Reference
Identity, account, device, technical Performance of a contract Art. 6(1)(b) GDPR
Health data (Art. 9), including derived indicators — core service Explicit consent Arts. 6(1)(a) and 9(2)(a) GDPR
Coach AI assistant (§7 ter) Performance of a contract + explicit consent for the health data used as context Arts. 6(1)(b), 6(1)(a) and 9(2)(a) GDPR
Commercial communications without health data (Option 1) Separate, revocable consent Art. 6(1)(a) GDPR + Art. 21 LSSI
Personalisation and analytical improvement (Option 2) Separate, revocable consent Arts. 6(1)(a) and 9(2)(a) GDPR
Communications based on health data (Option 3) Separate, revocable explicit consent Arts. 6(1)(a) and 9(2)(a) GDPR + Art. 21 LSSI
Disclosure to authorised organisations (§7 bis) Explicit consent, specific to each organisation, revocable Arts. 6(1)(a) and 9(2)(a) GDPR
Support and legal obligations Legal obligation / legitimate interest Arts. 6(1)(c) and 6(1)(f) GDPR
Retention of consent evidence Duty to demonstrate consent Art. 7(1) GDPR

Explicit consent for health data is requested separately and unambiguously within the App, distinct from acceptance of the Terms and Conditions. You may withdraw it at any time, without this closing your account and without affecting the lawfulness of prior processing (Art. 7(3) GDPR). Withdrawal will immediately suspend the capture of new health data and, at your choice, either preserve or delete data already stored.

4 bis. Mandatory acceptances, options and authorisations

Wellbeinn applies the principles of Art. 4(11) and Art. 7(4) GDPR: consent must be freely given, specific, informed and unambiguous, and consent for distinct purposes is obtained separately.

4 bis.1 Mandatory acceptances

# Acceptance Legal basis
1 Terms and Conditions of Service Art. 6(1)(b) GDPR
2 Privacy Policy Arts. 13 and 14 GDPR
3 Explicit consent to the processing of health data Arts. 6(1)(a) and 9(2)(a) GDPR

Refusing any of the three prevents use of the App. This is not an abusive condition: the nature of the service — a companion app for a physiological measurement device — makes its operation materially impossible without processing health data.

No other acceptance conditions access to the service. You may use the App with every option in §4 bis.2 disabled and with no authorisation under §4 bis.4.

4 bis.2 Personalisation options

These are strictly voluntary and do not condition use of the App. They are presented as separate checkboxes, in their own block, after the mandatory acceptances, and are disabled by default. You may enable or disable them at any time under Profile → Legal and privacy, with no penalty or loss of functionality.

Option 1 — Marketing communications

"I want to receive personalised wellbeing tips and Wellbeinn news by email."

  • Legal basis: Art. 6(1)(a) GDPR + Art. 21 LSSI.
  • Purpose: sending commercial communications with wellbeing tips, product news and offers from the Wellbeinn ecosystem.
  • Data used: account identifiers and email address. With this option alone, your health data is not used to segment these communications. If you want communications tailored to your indicators, you must also enable Option 3.
  • Withdrawal: under Profile → Legal and privacy or via the unsubscribe link in every communication.
  • Effect on the service: none.

Option 2 — Product personalisation and improvement

"I want to help Wellbeinn improve my experience by analysing how I use the App, in aggregate form, without my data being disclosed to third parties for analytical purposes."

  • Legal basis: Arts. 6(1)(a) and 9(2)(a) GDPR.
  • Purpose: aggregate analysis of App usage and of the behaviour of derived indicators, to improve the service, calibrate algorithms and study internal cohorts.
  • Data used: derived indicators and App usage patterns.
  • Scope: analyses are carried out exclusively on internal cohorts and their results are not disclosed to third parties. They are not used to draw conclusions about individual users. This option is independent of the organisation-sharing in §7 bis.
  • Withdrawal: under Profile → Legal and privacy. It will stop the inclusion of new data in the analyses.
  • Effect on the service: none.

Option 3 — Communications based on my health data

"I agree that Wellbeinn may use my health data to send me personalised communications and campaigns. This is optional and I can unsubscribe at any time."

  • Legal basis: Arts. 6(1)(a) and 9(2)(a) GDPR (explicit consent for special category data) + Art. 21 LSSI.
  • Relationship with Option 1: this option determines only how communications are personalised, not whether they are sent. If Option 1 is disabled you will not receive commercial communications, so this option will have no effect.
  • It is not offered to users under 18 (§10).
  • Purpose: to tailor the content, timing and frequency of our commercial communications to your wellbeing profile, so that you receive content relevant to your specific situation rather than generic communications.
  • Data used: your email address, your internal account identifier, the archetype the App assigns you and the segment label derived from your indicators (§3.6).
  • How the archetype is generated: through automated processing of your derived indicators, assigning you to a behaviour group. This constitutes profiling (Art. 4(4) GDPR) and produces no legal effects and does not significantly affect you (Art. 22 GDPR): its only effect is which commercial communication you receive.
  • Who runs the campaign: the Wellbeinn marketing team, through the platform identified in §7, which processes the data on Wellbeinn's behalf as a processor (Art. 28 GDPR).
  • Withdrawal: under Profile → Legal and privacy or via the unsubscribe link in every communication. It stops the sending of new segmented communications and the transmission of new labels to the campaign system. Data already transmitted is deleted in accordance with §6.
  • Effect on the service: none. Disabling it does not condition access to any functionality or commercial offer.

4 bis.3 Where no option is enabled

If you enable no personalisation option, your health data will be processed solely to provide the core service: receiving, storing and displaying your metrics and derived indicators, and answering your Coach AI queries. The legal basis combines Art. 6(1)(b) and Art. 9(2)(a) GDPR (mandatory acceptance no. 3).

4 bis.4 Organisation authorisations

Authorisations allowing an organisation to access your data (§7 bis) are not part of the personalisation options block and are not requested during registration. They are granted one by one, at your initiative, and require you to expressly select which data types you make available to that specific organisation.

Each authorisation constitutes an independent consent (Arts. 6(1)(a) and 9(2)(a) GDPR), is recorded separately and is revoked separately.

5. Purposes of processing

  1. Provide the core service: receive, store and display your physiological, health and activity metrics.
  2. Calculate derived indicators from the device's raw data (see §5 bis).
  3. Pair and maintain the connection with your devices.
  4. Manage your account: registration, authentication, password recovery.
  5. Handle your support and incident requests.
  6. Improve our products through aggregate analysis (only if you enable Option 2, §5.6).
  7. Comply with legal obligations.
  8. Provide the Coach AI assistant (§7 ter).
  9. Personalise our commercial communications (only if you enable Option 3).
  10. Make certain data available to an organisation you authorise, once that functionality is available (§7 bis).
  11. Retain evidence of consents given and withdrawn (Art. 7(1) GDPR).

5 bis. Derived indicators, profiling and non-medical nature

The indicators for sleep quality, recovery, vitality, activation, stress and other aggregate indicators of physiological state are calculated through automated processing of your health data, which constitutes profiling in relation to physiological state (Art. 4(4) GDPR). They are governed by the same legal basis as the raw data.

These calculations do not produce legal effects concerning you or similarly significantly affect you (Art. 22 GDPR): they are personal information displayed on your device. They are only used to personalise commercial communications if you expressly enable Option 3, and are never disclosed to third-party advertising networks.

On stopping this processing. It is not separable from provision of the service: without it, the App cannot deliver its core functionality. If you wish to stop it, your options are to stop using the App or to delete your account, which results in deletion of the associated data in accordance with §6.

The App and the devices in the Wellbeinn ecosystem are not a medical device within the meaning of Regulation (EU) 2017/745 (MDR). They are not intended to diagnose, prevent, clinically monitor, treat or alleviate disease, and are not a substitute for the judgement of a healthcare professional. If you have any symptom or health concern, consult a doctor.

5.6. Scope of the Option 2 analysis

The analysis referred to in purpose 6 — carried out only if you enable Option 2 — is performed in aggregate form, on internal cohorts, and is not used to draw conclusions about individual users.

Statistical results that are genuinely anonymous within the meaning of Recital 26 GDPR, because they do not reasonably permit re-identification, may be retained after the right to erasure has been exercised, since they cease to be personal data. Any result not meeting that condition is deleted along with the rest of your data.

Should Wellbeinn in future wish to process pseudonymised data for secondary research or statistical purposes, it will do so only on the basis of additional specific consent or the safeguards of Art. 89 GDPR, following a Data Protection Impact Assessment and with a defined retention period, and we will inform you beforehand.

6. Retention periods

Data Period
Active account data For as long as your account remains open
Health and device data associated with the account For as long as your account remains open
Following a deletion request Deletion within a maximum of 30 calendar days
Technical and access logs 12 months, on the basis of our legitimate interest in the security and integrity of the service (Art. 6(1)(f) GDPR)
Archetype and segment label in the campaign system For as long as Option 3 is enabled. Deletion within 30 calendar days of it being disabled or of account closure
Organisation authorisations (organisation, scope, grant, revocation) For as long as the authorisation is active + 4 years as evidence of consent
Coach AI conversation history Maximum 12 months from each conversation
Consent audit record (version accepted, date and time, language, purposes, withdrawals) 4 years from withdrawal of consent or from account closure (Art. 7(1) GDPR)

Once these periods elapse, data is deleted or irreversibly anonymised.

Why the consent record outlives account closure. If we also deleted the evidence that you consented, we could not demonstrate to you or to the supervisory authority that the processing was lawful. That record contains only the trace of the consent — identifier, date, version, purposes — not your health data, which is deleted within the 30 days.

Note on the service model. The service is currently free with no in-app purchases. Wellbeinn may in future introduce a paid subscription model; this does not alter the periods described here.

7. Processors, independent controllers and sub-processors

Provider Service Role Location
Google Ireland Limited (Firebase / Google Cloud) Authentication, Firestore, Storage, Cloud Functions and Cloud Logging Processor (Art. 28 GDPR) European Economic Area — region europe-west3
Google LLC "Sign in with Google" Independent controller of the identity service USA — Adequacy Decision 2023/1795 (EU-US Data Privacy Framework)
Language model provider Generation of Coach AI assistant responses (§7 ter) Processor (Art. 28 GDPR) Outside the European Economic Area, with the safeguards set out in §8
Klaviyo, Inc. Sending and segmentation of commercial communications (Options 1 and 3) Processor (Art. 28 GDPR) USA — Adequacy Decision 2023/1795 (EU-US Data Privacy Framework) and Standard Contractual Clauses
Organisations authorised by the user Access to the data the user authorises (§7 bis) Independent controller Varies by organisation; disclosed before you grant the authorisation

Data measured by the Wellbeinn V8 wearable is transmitted locally over Bluetooth between the device and your phone.

For transfers to third countries without an adequacy decision we apply the Standard Contractual Clauses (Decision 2021/914) together with the supplementary measures required under the EDPB's Recommendations 01/2020.

7 bis. Sharing with organisations you authorise

This functionality is not currently available in the App. When it is activated, it will work as described below, and this Policy will be updated to reflect its launch.

The App will allow you to authorise an organisation — a sports club, trainer, healthcare professional, employer or other entity — to access certain data in your account. The feature will be strictly voluntary, will be disabled by default and will be activated solely by your action.

How it will work. From the "Add access" screen you will enter a code or scan a QR code provided by the organisation. You will be shown who that organisation is and why it is requesting your data, and you will select which data types you wish to make available (for example: sleep and rest, recovery, physical activity). The authorisation will not take effect until you confirm it.

Who will receive the data, and in what capacity. The organisation you authorise will act as an independent controller: it will determine on its own account what it uses the data for and will be answerable for that use to you and to the supervisory authorities. Wellbeinn will not instruct or control that subsequent use.

Before enabling any access, Wellbeinn will enter into a contract with each organisation requiring it to: limit use to the purpose communicated, apply appropriate security measures, not reuse the data for other purposes, not disclose it to third parties, respond to any rights you exercise against it, notify any security breach, and delete the data when the relationship ends or when you revoke the authorisation.

Legal basis. Your explicit consent, specific to each organisation (Arts. 6(1)(a) and 9(2)(a) GDPR). It will not be generic consent and will not be requested at registration.

What data will be shared. Only the types you have selected. Types you have not selected will not be shared, nor will your identity data beyond the name associated with your account, nor the content of your Coach AI conversations.

How to revoke. You will be able to revoke any authorisation at any time from the App. Revocation will take effect immediately: the organisation will cease to be able to access your data and will be contractually obliged to delete anything downloaded within a maximum of 30 days. Revocation will not affect the lawfulness of prior accesses (Art. 7(3) GDPR) and will have no effect on your account.

Record. Wellbeinn will retain evidence of every authorisation and revocation (user identifier, organisation, data types, date and time, version of the text accepted) in accordance with §6.

7 ter. Conversational assistant (Coach AI)

The App includes a conversational assistant that answers your questions about wellbeing, rest and training.

How it works. When you submit a query, Wellbeinn transmits to the language model provider identified in §7 the text of your query and the account data needed to contextualise the response, limited to what is strictly necessary for that purpose.

The provider's role. It acts as a processor (Art. 28 GDPR): it processes the data on Wellbeinn's behalf and on our instructions, and may not use it for its own purposes.

Important limitation. Coach AI responses are indicative and general in nature. They do not constitute medical advice, diagnosis or prescription, may contain errors and are not a substitute for the judgement of a healthcare professional. The warning in §5 bis applies in full.

Your conversation data. See §3.5 and §6.

8. International transfers

As a general rule, your data is stored on servers located in the European Economic Area.

Where a provider processes data from the USA — the federated identity provider, the language model provider and the campaign platform — the transfer basis will primarily be the Adequacy Decision 2023/1795 (EU-US Data Privacy Framework), to the extent the provider is certified under that framework. Subsidiarily, and for third countries without an adequacy decision, the Standard Contractual Clauses (Decision 2021/914) will apply with the necessary supplementary measures.

Organisations outside the European Economic Area (§7 bis). When the functionality is available and an organisation is established in a third country, Wellbeinn will structure the transfer through Standard Contractual Clauses incorporated into the contract with that organisation.

If exceptionally those safeguards cannot be applied, the transfer may only rely on your explicit consent under Art. 49(1)(a) GDPR, in which case you will be expressly informed, before giving it, that the destination country has no adequacy decision and no appropriate safeguards, and of the risks this entails for your data: among others, the possible absence of an independent supervisory authority, of effective rights of access and rectification, and of judicial remedies equivalent to those in the European Economic Area.

9. Your rights

  • Access to the data we process about you.
  • Rectification of inaccurate or incomplete data.
  • Erasure ("right to be forgotten"), subject to the exceptions in Art. 17(3) GDPR.
  • Objection to processing. For derived indicators, see §5 bis.
  • Restriction of processing.
  • Portability in a structured, commonly used and machine-readable format.
  • Not to be subject to automated individual decisions producing significant effects (Art. 22 GDPR).
  • Withdrawal of consent given for health data processing, for any personalisation option or for any organisation authorisation, without retroactive effect and free of charge.

9.1 How to exercise your rights

Exercising your rights is free of charge (Art. 12(5) GDPR).

  • In the App: under Profile → Legal and privacy you can see which version of the documents you have accepted and enable or disable each personalisation option. From your account settings you can request deletion of your account.
  • By email to privacy@wellbeinn.com, stating which right you are exercising. To verify your identity we will preferentially use the email address associated with your account. Only where there are reasonable doubts (Art. 12(6) GDPR) may we request additional information, proportionate and limited to the minimum; a copy of an identity document is not required by default.

We will respond within a maximum of one month, extendable by two further months in complex cases, informing you of the extension and its reasons (Art. 12(3) GDPR).

9.2 Complaint to the supervisory authority

You may lodge a complaint with the Spanish Data Protection Agency (Agencia Española de Protección de Datos, AEPD), C/ Jorge Juan 6, 28001 Madrid — www.aepd.es.

If you reside in another EU Member State, you may also lodge it with the supervisory authority of your country of residence.

10. Minors

Wellbeinn requires a minimum age of 16 to use the App.

Although Art. 7 LOPDGDD sets the default legal threshold at 14, Wellbeinn applies a more conservative policy of 16, for consistency with the more restrictive rules of other Member States and out of caution given the sensitivity of the data processed.

Commercial communications based on health data. Option 3 (§4 bis.2) is not offered to users under 18. Users aged 16 to 18 may use the App normally and enable Options 1 and 2, but their health data will not be used to segment commercial communications.

If we detect that a minor below the applicable threshold has registered: (i) we will suspend the account immediately, (ii) require parental verification through a secure channel, and (iii) delete the account and associated data if verification is not completed within 30 days.

11. Data security

We apply technical and organisational measures appropriate to the level of risk, including:

  • Encryption of communications in transit (TLS 1.2+).
  • Encryption at rest on storage servers.
  • Granular security rules allowing each user to read and write only their own information (access control by user identifier).
  • Credential storage using one-way hash functions managed by the identity provider.
  • An audit record of consents given and withdrawn in the App, including the exact version of the text accepted.

In the event of a security incident affecting your data and posing a high risk to your rights, we will notify you without undue delay (Art. 34 GDPR), by email and/or in-app message, indicating the nature of the breach, the approximate categories and volumes of data affected, the likely consequences and the measures taken. We will report the breach to the AEPD within 72 hours (Art. 33 GDPR).

12. Cookies and identifiers

The App does not use cookies or equivalent advertising tracking technologies. Only technical identifiers strictly necessary for the service are used (session token, installation identifier). The wellbeinn.com website may use session and, where applicable, measurement cookies, governed by the site's cookie policy.

13. Changes to this Policy

We may update this Policy to reflect legal or technical changes. The version and date appear in §14, and the history in §15.

Material changes include, among others: the addition of new data categories, the introduction of new processors or sub-processors in third countries, changes to purposes or legal bases, and changes affecting your rights.

When we publish a version with material changes, the App will present you with an acceptance screen at your next sign-in. You will need to accept the three mandatory items in §4 bis.1 again to continue using the service; the voluntary options will be offered to you again, but you may continue without enabling any of them.

14. Version and date

  • Version: 1.0.6
  • Effective date: 19 August 2026
  • Available languages: Spanish, English. The English version is a courtesy translation; in the event of a discrepancy, and unless the consumer protection law of the user's country of residence provides otherwise, the Spanish version prevails.

15. Version history

Version Date Material changes
1.0.6 19/08/2026 New Option 3 (communications based on health data). New organisation-sharing section (§7 bis, functionality not yet available). New Coach AI assistant section (§7 ter). Expanded processor table. New retention periods. Correction of clauses stating that no data was shared with third parties and that no profiling took place.
1.0.5 29/04/2026 Previous version