---
title: Privacy
description: What Welila holds, where it lives and how long it is kept.
canonical: https://welila.com/privacy
---

# Privacy

Personal data stays in the region it belongs to, and a log holds a receipt, never the contents.

This page says what Welila holds and why. It is written to be read, not to be survived. Where a supplier processes data on Welila's behalf, the trust page names it and says what it sees.

## Where data lives

Every account carries a region. A person's identity, their sign-in and their sessions live in that region and do not leave it. A business's facts and records live in the region of the business. The control plane holds no personal data, only the meta it needs to route a request to the right region.

## What a log holds

A request leaves one log line with the time and the outcome, and an id a person can quote. It does not hold an address, a code, a name or the contents of a request. The record of a fact holds who confirmed it and when, and is append-only, so a correction is a new row and the history stays readable.

## How long it is kept

- An asker's contact details are kept for ninety days, then the record is deleted.
- A business's facts and records are kept while the account is open, and are exportable at any time.
- A sign-in code is short-lived and is not stored after it is used.

## Your rights

You can read, export or delete the data held about you. Write to hello@welila.com and the request is actioned and recorded. A deletion removes the contents; the receipt that a deletion happened stays, because a record of the act is not a record of the data.

This page states current practice. The full data protection notice for launch is prepared with legal review.
