Privacy
Personal data stays in the region it belongs to, and a log holds a receipt, never the contents.
This page says what Welila holds and why. It is written to be read, not to be survived. Where a supplier processes data on Welila's behalf, the trust page names it and says what it sees.
Where data lives
Every account carries a region. A person's identity, their sign-in and their sessions live in that region and do not leave it. A business's facts and records live in the region of the business. The control plane holds no personal data, only the meta it needs to route a request to the right region.
What a log holds
A request leaves one log line with the time and the outcome, and an id a person can quote. It does not hold an address, a code, a name or the contents of a request. The record of a fact holds who confirmed it and when, and is append-only, so a correction is a new row and the history stays readable.
How long it is kept
- An asker's contact details are kept for ninety days, then the record is deleted.
- A business's facts and records are kept while the account is open, and are exportable at any time.
- A sign-in code is short-lived and is not stored after it is used.
Your rights
You can read, export or delete the data held about you. Write to hello@welila.com and the request is actioned and recorded. A deletion removes the contents; the receipt that a deletion happened stays, because a record of the act is not a record of the data.
This page states current practice. The full data protection notice for launch is prepared with legal review.