1. Who we are and what this policy covers
1.1Who we are. MyWellOps is provided by My Well Ops Ltd, a company registered in England and Wales under company number 16452645, with its registered office at 8 Golden Square, London W1F 9HY ("MyWellOps", "we", "us"). References to "we" include our group companies where they process data with us, as described in section 4.
1.2Representatives. We have not yet appointed a representative in the European Union under Article 27 GDPR. We will publish the details here once appointed. We are established in the UK, so we do not need a UK representative.
1.3Our two roles. How we handle your data depends on who you are:
| Who you are | Our role | Whose policy applies |
|---|---|---|
| A practitioner or business using MyWellOps, or their staff | Controller of your account, billing, usage, support and marketing data | This policy |
| A visitor to mywellops.com, or a prospect we contact | Controller | This policy |
| A client of a practitioner (booking, portal, messages, forms, video, records) | Processor, acting only on the practitioner's instructions | The practitioner's privacy notice. This policy explains how we handle that data on their behalf |
1.4If you are a practitioner's client, your practitioner decides what data is collected about you and why. Contact your practitioner first to exercise your rights. We will help them respond. We do not use client data for our own purposes, do not sell it, and do not use it for advertising.
1.5This policy does not cover practitioners' own website content, booking policies or practices, or third-party services you connect yourself, such as your own Google or Stripe account.
2. Data we collect
2.1Data you give us. Name, email, phone number, practice or company name, job title, professional registration details, insurance and DBS (background check) certificates you upload for verification, billing address, VAT number, communication preferences, and anything you send us in support requests, calls, chats, surveys or demos.
2.2Account and billing data. Plan, subscription history, invoices, payment status and the last four digits and expiry of your card. Full card details are collected and held by our payment processor, not by us.
2.3Usage and device data. IP address, browser and device type, operating system, language, approximate location, pages and features used, clicks, session duration, referring URLs, log-in history, error logs and, recordings of how the MyWellOps app is used, made by Hotjar (section 10).
2.4Data from other sources. We may obtain business contact details (name, role, practice name, business email, phone and professional listing) from public professional registers, practice websites, professional directories, LinkedIn and business data providers such as Apollo.io, to contact practitioners about MyWellOps. We also receive data from referral and partner programmes, from Marsh Ltd where you were introduced, and from fraud prevention and identity verification services.
2.5Client data processed for practitioners. When practitioners use MyWellOps, we process their clients' data as processor, which may include identity and contact details, appointments, payments, messages, forms, documents, session notes and health information. See section 1.3.
3. How we use data and our lawful bases
This section covers data we control. Client data we process for practitioners is used only to provide the Services to them.
| Purpose | Data used | Lawful basis (UK/EU GDPR) |
|---|---|---|
| Create and run your account, provide the Services and support | Account, usage, support | Contract |
| Bill you, collect payment, recover unpaid fees (including through debt collection agencies) | Account, billing | Contract; legitimate interests (recovering debts) |
| Keep the Services secure, prevent fraud, abuse, chargebacks and attacks, and review risk accounts | Account, billing, usage, device | Legitimate interests (security and fraud prevention); legal obligation |
| Send service messages (billing, price changes, security, changes to terms) | Contact | Contract; legal obligation |
| Improve the Services and create aggregated, de-identified statistics | Usage, device | Legitimate interests (product improvement) |
| Contact practitioners about MyWellOps by email, phone or LinkedIn (business-to-business outreach) | Business contact data from section 2.4 | Legitimate interests (business development). Email to sole traders relies on consent or the soft opt-in where the law requires |
| Send newsletters and marketing to customers | Contact, preferences | Soft opt-in or consent; you can opt out at any time |
| Analytics and advertising cookies on our website | Device, usage | Consent |
| Credit introductions to Marsh Ltd when you follow our link to them | Account, usage (the click) | Legitimate interests (being paid for introductions) |
| Comply with law, tax, accounting and regulator requests; establish or defend legal claims | Any relevant data | Legal obligation; legitimate interests |
| Transfer the business in a merger, acquisition or reorganisation | Any relevant data | Legitimate interests |
3.1Legitimate interests. Where we rely on legitimate interests, we have balanced them against your rights. You can ask us for that assessment and object at any time (section 9).
3.2Automated decisions. We do not make decisions with legal or similarly significant effects on you solely by automated means. Fraud and risk screening may flag accounts automatically, but a person reviews any closure.
4. Who we share data with
We do not sell personal data, and we never share client data for advertising.
4.1Service providers (subprocessors). These providers process data on our behalf under written contracts:
| Provider | Purpose | Main location |
|---|---|---|
| Akamai (Linode) | Hosting, databases and file storage | Germany (Frankfurt) |
| Stripe | Subscription billing and client payments | USA, Ireland |
| Twilio | SMS, messaging and video | USA |
| Twilio SendGrid | Transactional and notification email | USA |
| Mailgun | Transactional and notification email | USA, EU |
| AssemblyAI | Transcribing recorded sessions for AI notes | EU |
| Anthropic | Reading your website or directory profile when you use the practice import | USA |
| Google (Gemini) | AI note assistance, session summaries and document drafting | USA, EU |
| Sign in with Google, optional calendar sync, and address lookup (Google Maps) | USA | |
| Microsoft | Sign in with Microsoft, if you use it | USA, EU |
| Cloudflare | DNS, security, content delivery and certificates for custom domains | Global |
| Entri | Custom domain connection | USA |
| Gleap | In-app support, chat, bug reporting and feedback | EU |
| Atlassian (Jira) | Support ticket and issue tracking | USA, EU |
| Google (Analytics, Tag Manager, Ads) | Website and app analytics, and measuring our advertising | USA |
| Hotjar | Recordings and heatmaps of how the app is used | EU |
| Contentsquare | Website and app analytics | EU |
| Meta | Measuring our advertising (Meta Pixel and Conversions API) | USA, Ireland |
| Pipedrive | Our customer relationship management (CRM) | EU |
| n8n | Routing demo requests from our website to our CRM | EU |
| Calendly | Booking demos from our website | USA |
| Slack | Internal alerts when a practice signs up | USA |
This is the current list. Customers are notified of changes as set out in our Data Processing Agreement.
4.2Group companies. Companies in the MyWellOps group, who may provide, support, bill for or collect payment for the Services, under the same protections as this policy.
4.3Marsh Ltd. We do not pass your details to Marsh Ltd. If you follow our link to Marsh Ltd, we record that you did, so the introduction can be credited to us. Anything you then give Marsh Ltd is handled by it as an independent controller under its own privacy notice.
4.4Debt recovery. Debt collection agencies, solicitors and debt purchasers, where fees remain unpaid, limited to your contact, account and billing details.
4.5Payment and fraud partners. Payment processors, card networks, banks and fraud prevention agencies, to process payments and prevent fraud.
4.6Marketing providers. Email, CRM, advertising and analytics platforms, for our own marketing to practitioners, using marketing and cookie data. We do not send them client data or practitioners' records. Hotjar's recordings of the app can capture what is on screen, including client details a practitioner has open (section 10).
4.7Professional advisers and insurers. Lawyers, accountants, auditors and our insurers, under confidentiality.
4.8Authorities. Regulators, law enforcement, courts, tax authorities and professional bodies, where the law requires or to protect our rights, our users or the public.
4.9Business transfers. A buyer, investor or successor in a merger, acquisition, financing or sale of assets, under confidentiality, who must continue to protect the data in line with this policy.
4.10Google user data. If you connect Google Calendar or sign in with Google, we receive data from Google. MyWellOps’ use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
4.11Google Calendar. Connecting your Google Calendar is optional (Settings → Integrations in MyWellOps). We ask for two calendar permissions: to read your calendar (calendar.readonly), so the busy times and upcoming events in it keep your booking availability accurate; and to manage events (calendar.events), so appointments you take, move or cancel in MyWellOps are added, updated or removed there. We also receive the connected account’s email address and name, so you can see which calendar is connected. The events we add show the service, the client’s name, the session mode, the location and a link to the appointment in MyWellOps.
4.12What we keep from Google. Your Google access and refresh tokens, encrypted at rest; the connected account’s email address and name; and the IDs of the events we create. Busy times and upcoming events are read when needed and not stored, and we do not store the contents of other events in your calendar.
4.13Sign in with Google. If you sign in with Google, we receive your Google account ID and your email address once Google has verified it, and use them only to create your account and sign you in.
4.14How Google user data is used. Only to provide the features you connected it for. It is not used for advertising, not sold, and not used to develop, improve or train generalised AI or machine-learning models. It is not transferred to others except as needed to provide those features (through the service providers listed in 4.1), to comply with the law, or with your consent. Our staff do not read it unless you ask us to, for security purposes such as investigating abuse, or to comply with the law.
4.15Disconnecting. You can disconnect Google Calendar in MyWellOps at any time (Settings → Integrations). We then stop syncing and delete the stored tokens. You can also remove MyWellOps’ access from your Google account at myaccount.google.com/permissions.
5. AI features
5.1AI features (note assistance, document drafting and similar tools) are optional, and practitioners choose whether to turn them on. When a practitioner records a session for AI notes, its audio is transcribed, and the recording is deleted automatically after the period they choose (30, 60 or 90 days, or as soon as the summary is saved).
5.2When used, only the content needed for the request is sent to the AI provider (Google Gemini; AssemblyAI, which transcribes recorded sessions for AI notes; and Anthropic, which reads your existing website or directory profile if you use the practice import) through their business API.
5.3Our AI providers are contractually prohibited from using this data to train their models. They may keep it for a limited period set by their business terms, for abuse monitoring, after which it is deleted.
5.4We do not use client data to train any AI model of our own.
5.5AI output is a draft for the practitioner to review. It is never used to make automated decisions about clients.
6. International transfers
6.1We are based in the UK, and our group and providers operate in other countries, including the USA, the EU and the UAE. Your data is hosted with Akamai (Linode) in Frankfurt, Germany.
6.2When we transfer personal data out of the UK or EEA, we rely on: an adequacy decision (including the UK–US Data Bridge and EU–US Data Privacy Framework where the provider is certified); the EU Standard Contractual Clauses; the UK International Data Transfer Agreement or Addendum; or another lawful mechanism. Where required we assess the laws of the destination country and apply extra safeguards such as encryption.
6.3You can ask us for a copy of the relevant safeguards by emailing support@mywellops.com.
7. How long we keep data
| Data | How long |
|---|---|
| Account and support data | Life of the account, then 2 years |
| Billing, invoices and tax records | 6 years after the end of the financial year (UK tax law) |
| Client data processed for practitioners | While the practitioner's account exists: cancelling a paid plan moves it to the free plan and keeps the data. Practitioners delete files and notes themselves; client records and whole accounts are deleted within 90 days of a request to support@mywellops.com, and backups roll off within a further 35 days. AI-notes recordings: 30, 60 or 90 days, as the practitioner chooses |
| Prospect and marketing data | 2 years from last contact, or until you opt out (we keep a suppression record so we do not contact you again) |
| Security, fraud and access logs | Up to 12 months, longer where needed for an investigation |
| Data relevant to a dispute, debt or legal claim | Until the matter is resolved and limitation periods expire |
| Cookies | See section 10 |
8. Security
We protect data with encryption in transit (TLS) and at rest, hashed passwords, role-based access controls, multi-factor authentication for staff, activity logging, regular backups, vulnerability patching and supplier due diligence. Staff access to client data is limited to what is needed for support, security or legal reasons, under confidentiality. If a personal data breach affects you, we will notify you and the relevant regulator where the law requires. Practitioners are notified within 48 hours under our Data Processing Agreement.
9. Your rights
9.1Everyone. You can ask us to access, correct or delete your data, opt out of marketing at any time using the unsubscribe link or by emailing us, and withdraw any consent you gave.
9.2UK, EU and EEA. You also have the right to restrict processing, to data portability, and to object to processing based on legitimate interests, including direct marketing (which we will always stop).
9.3United States. Depending on your state (including California, Colorado, Connecticut, Virginia, Texas and others), you may have the right to know, access, correct and delete personal data, and to opt out of sale, sharing for targeted advertising, and profiling. We do not sell personal data. We share limited data with advertising platforms (Meta and Google) to measure our own advertising, which some state laws treat as "sharing". To opt out, email support@mywellops.com. We will not discriminate against you for exercising your rights. You may use an authorised agent.
9.4UAE, Canada, Australia and elsewhere. You have the rights given by your local law, such as UAE Federal Decree-Law No. 45 of 2021, PIPEDA or the Australian Privacy Principles. Contact us and we will respond in line with that law.
9.5How to make a request. Email support@mywellops.com. We may need to verify your identity. We respond within one month (or the period your local law requires), and may extend this where the law allows. If you are a practitioner's client, contact your practitioner first (section 1.4).
9.6Complaints. Please contact us first so we can try to fix it. You also have the right to complain to your data protection regulator:
| Where you are | Regulator |
|---|---|
| UK | Information Commissioner's Office |
| Ireland | Data Protection Commission |
| Other EU/EEA | Your national data protection authority |
| Elsewhere | Your local privacy regulator |
10. Cookies
We use essential cookies, and similar storage in your browser, to run the site and app. On mywellops.com we only set analytics and advertising cookies if you accept them in our cookie banner, and you can change your choice at any time from "Cookie settings" in the footer. The MyWellOps app works differently, as set out below the table.
| Type | Purpose | Consent needed | Examples |
|---|---|---|---|
| Essential | Log-in, security, remembering your cookie choice and region | No | In the app: sign-in cookies (access_token, user_data) and your practice branding (mwo_branding). On our website: your cookie choice and region, kept in local storage |
| Analytics | Understanding how the site and app are used | Yes on our website; see below for the app | Google Analytics (through Google Tag Manager), Contentsquare, Hotjar |
| Advertising | Measuring and targeting our campaigns | Yes on our website; see below for the app | Google Ads, Meta Pixel |
| Support and booking | Chatting with our support team, and booking a demo | Chat: yes on our website; see below for the app. Calendly: only when you choose to book | Gleap (support chat, on our website and in the app), Calendly (the booking calendar on our demo page, loaded when you ask to book) |
Practitioners' booking pages and websites use essential cookies only. The MyWellOps app at app.mywellops.com, including the client portal, loads Google Tag Manager (with Google Analytics), Hotjar, the Meta Pixel and Gleap's support chat, and Contentsquare on its public pages, and does not currently ask for consent before doing so.
11. Marketing
We send marketing to customers about similar services under the soft opt-in, and to others only where the law allows or with consent. Every email includes an unsubscribe link. Service messages (billing, security, price or terms changes) are not marketing and will still be sent.
12. Children
MyWellOps is a business service and is not directed at anyone under 18. Practitioners who work with children are responsible, as controller, for the lawful handling of their clients' data, including parental consent where required.
13. Changes to this policy
We will update this policy when our practices or the law change. We will tell customers about material changes by email or in-app notice before they take effect. The date at the top shows the latest version.
14. Contact us
- Company: My Well Ops Ltd (company number 16452645), 8 Golden Square, London W1F 9HY
- Privacy questions and requests: support@mywellops.com
- General: info@mywellops.com
- EU representative: not yet appointed