September offer: 70% off your first 6 months on any paid plan. Sign up by 30 September 2026.

Start free trialTerms
MyWellOps home
Legal

Privacy Policy

How My Well Ops Ltd collects and uses personal data — as the controller of practitioners' account data, and as a processor of the client data practitioners hold in MyWellOps.

Last updated: 27 September 2026Privacy requests: support@mywellops.com
In plain terms

A quick orientation. The full policy below is what applies.

Two rolesWe control your account, billing and marketing data. For your clients’ records we are your processor and act only on your instructions.Section 1
Clients: ask your practitioner firstYour practitioner decides what is collected and why. We help them respond to your requests.Section 1.4
We never sell dataClient data is never used for advertising or for our own purposes.Section 4
Named providersEvery provider is listed with its purpose and location, and matches the Terms.Section 4.1
AI cannot train on your dataProviders are contractually barred from training on it. Only what a request needs is sent.Section 5
Where data is hostedHosted with Akamai (Linode) in Frankfurt, Germany. Transfers elsewhere use adequacy decisions or standard clauses.Section 6
Clear retention periodsAccount data 2 years after closure, billing 6 years, client data kept while the account is open and deleted on request.Section 7
Your rights and complaintsAccess, correct, delete, object and opt out. You can complain to the ICO or your regulator.Section 9

1. Who we are and what this policy covers

1.1Who we are. MyWellOps is provided by My Well Ops Ltd, a company registered in England and Wales under company number 16452645, with its registered office at 8 Golden Square, London W1F 9HY ("MyWellOps", "we", "us"). References to "we" include our group companies where they process data with us, as described in section 4.

1.2Representatives. We have not yet appointed a representative in the European Union under Article 27 GDPR. We will publish the details here once appointed. We are established in the UK, so we do not need a UK representative.

1.3Our two roles. How we handle your data depends on who you are:

Who you areOur roleWhose policy applies
A practitioner or business using MyWellOps, or their staffController of your account, billing, usage, support and marketing dataThis policy
A visitor to mywellops.com, or a prospect we contactControllerThis policy
A client of a practitioner (booking, portal, messages, forms, video, records)Processor, acting only on the practitioner's instructionsThe practitioner's privacy notice. This policy explains how we handle that data on their behalf

1.4If you are a practitioner's client, your practitioner decides what data is collected about you and why. Contact your practitioner first to exercise your rights. We will help them respond. We do not use client data for our own purposes, do not sell it, and do not use it for advertising.

1.5This policy does not cover practitioners' own website content, booking policies or practices, or third-party services you connect yourself, such as your own Google or Stripe account.

2. Data we collect

2.1Data you give us. Name, email, phone number, practice or company name, job title, professional registration details, insurance and DBS (background check) certificates you upload for verification, billing address, VAT number, communication preferences, and anything you send us in support requests, calls, chats, surveys or demos.

2.2Account and billing data. Plan, subscription history, invoices, payment status and the last four digits and expiry of your card. Full card details are collected and held by our payment processor, not by us.

2.3Usage and device data. IP address, browser and device type, operating system, language, approximate location, pages and features used, clicks, session duration, referring URLs, log-in history, error logs and, recordings of how the MyWellOps app is used, made by Hotjar (section 10).

2.4Data from other sources. We may obtain business contact details (name, role, practice name, business email, phone and professional listing) from public professional registers, practice websites, professional directories, LinkedIn and business data providers such as Apollo.io, to contact practitioners about MyWellOps. We also receive data from referral and partner programmes, from Marsh Ltd where you were introduced, and from fraud prevention and identity verification services.

2.5Client data processed for practitioners. When practitioners use MyWellOps, we process their clients' data as processor, which may include identity and contact details, appointments, payments, messages, forms, documents, session notes and health information. See section 1.3.

3. How we use data and our lawful bases

This section covers data we control. Client data we process for practitioners is used only to provide the Services to them.

PurposeData usedLawful basis (UK/EU GDPR)
Create and run your account, provide the Services and supportAccount, usage, supportContract
Bill you, collect payment, recover unpaid fees (including through debt collection agencies)Account, billingContract; legitimate interests (recovering debts)
Keep the Services secure, prevent fraud, abuse, chargebacks and attacks, and review risk accountsAccount, billing, usage, deviceLegitimate interests (security and fraud prevention); legal obligation
Send service messages (billing, price changes, security, changes to terms)ContactContract; legal obligation
Improve the Services and create aggregated, de-identified statisticsUsage, deviceLegitimate interests (product improvement)
Contact practitioners about MyWellOps by email, phone or LinkedIn (business-to-business outreach)Business contact data from section 2.4Legitimate interests (business development). Email to sole traders relies on consent or the soft opt-in where the law requires
Send newsletters and marketing to customersContact, preferencesSoft opt-in or consent; you can opt out at any time
Analytics and advertising cookies on our websiteDevice, usageConsent
Credit introductions to Marsh Ltd when you follow our link to themAccount, usage (the click)Legitimate interests (being paid for introductions)
Comply with law, tax, accounting and regulator requests; establish or defend legal claimsAny relevant dataLegal obligation; legitimate interests
Transfer the business in a merger, acquisition or reorganisationAny relevant dataLegitimate interests

3.1Legitimate interests. Where we rely on legitimate interests, we have balanced them against your rights. You can ask us for that assessment and object at any time (section 9).

3.2Automated decisions. We do not make decisions with legal or similarly significant effects on you solely by automated means. Fraud and risk screening may flag accounts automatically, but a person reviews any closure.

4. Who we share data with

We do not sell personal data, and we never share client data for advertising.

4.1Service providers (subprocessors). These providers process data on our behalf under written contracts:

ProviderPurposeMain location
Akamai (Linode)Hosting, databases and file storageGermany (Frankfurt)
StripeSubscription billing and client paymentsUSA, Ireland
TwilioSMS, messaging and videoUSA
Twilio SendGridTransactional and notification emailUSA
MailgunTransactional and notification emailUSA, EU
AssemblyAITranscribing recorded sessions for AI notesEU
AnthropicReading your website or directory profile when you use the practice importUSA
Google (Gemini)AI note assistance, session summaries and document draftingUSA, EU
GoogleSign in with Google, optional calendar sync, and address lookup (Google Maps)USA
MicrosoftSign in with Microsoft, if you use itUSA, EU
CloudflareDNS, security, content delivery and certificates for custom domainsGlobal
EntriCustom domain connectionUSA
GleapIn-app support, chat, bug reporting and feedbackEU
Atlassian (Jira)Support ticket and issue trackingUSA, EU
Google (Analytics, Tag Manager, Ads)Website and app analytics, and measuring our advertisingUSA
HotjarRecordings and heatmaps of how the app is usedEU
ContentsquareWebsite and app analyticsEU
MetaMeasuring our advertising (Meta Pixel and Conversions API)USA, Ireland
PipedriveOur customer relationship management (CRM)EU
n8nRouting demo requests from our website to our CRMEU
CalendlyBooking demos from our websiteUSA
SlackInternal alerts when a practice signs upUSA

This is the current list. Customers are notified of changes as set out in our Data Processing Agreement.

4.2Group companies. Companies in the MyWellOps group, who may provide, support, bill for or collect payment for the Services, under the same protections as this policy.

4.3Marsh Ltd. We do not pass your details to Marsh Ltd. If you follow our link to Marsh Ltd, we record that you did, so the introduction can be credited to us. Anything you then give Marsh Ltd is handled by it as an independent controller under its own privacy notice.

4.4Debt recovery. Debt collection agencies, solicitors and debt purchasers, where fees remain unpaid, limited to your contact, account and billing details.

4.5Payment and fraud partners. Payment processors, card networks, banks and fraud prevention agencies, to process payments and prevent fraud.

4.6Marketing providers. Email, CRM, advertising and analytics platforms, for our own marketing to practitioners, using marketing and cookie data. We do not send them client data or practitioners' records. Hotjar's recordings of the app can capture what is on screen, including client details a practitioner has open (section 10).

4.7Professional advisers and insurers. Lawyers, accountants, auditors and our insurers, under confidentiality.

4.8Authorities. Regulators, law enforcement, courts, tax authorities and professional bodies, where the law requires or to protect our rights, our users or the public.

4.9Business transfers. A buyer, investor or successor in a merger, acquisition, financing or sale of assets, under confidentiality, who must continue to protect the data in line with this policy.

4.10Google user data. If you connect Google Calendar or sign in with Google, we receive data from Google. MyWellOps’ use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.

4.11Google Calendar. Connecting your Google Calendar is optional (Settings → Integrations in MyWellOps). We ask for two calendar permissions: to read your calendar (calendar.readonly), so the busy times and upcoming events in it keep your booking availability accurate; and to manage events (calendar.events), so appointments you take, move or cancel in MyWellOps are added, updated or removed there. We also receive the connected account’s email address and name, so you can see which calendar is connected. The events we add show the service, the client’s name, the session mode, the location and a link to the appointment in MyWellOps.

4.12What we keep from Google. Your Google access and refresh tokens, encrypted at rest; the connected account’s email address and name; and the IDs of the events we create. Busy times and upcoming events are read when needed and not stored, and we do not store the contents of other events in your calendar.

4.13Sign in with Google. If you sign in with Google, we receive your Google account ID and your email address once Google has verified it, and use them only to create your account and sign you in.

4.14How Google user data is used. Only to provide the features you connected it for. It is not used for advertising, not sold, and not used to develop, improve or train generalised AI or machine-learning models. It is not transferred to others except as needed to provide those features (through the service providers listed in 4.1), to comply with the law, or with your consent. Our staff do not read it unless you ask us to, for security purposes such as investigating abuse, or to comply with the law.

4.15Disconnecting. You can disconnect Google Calendar in MyWellOps at any time (Settings → Integrations). We then stop syncing and delete the stored tokens. You can also remove MyWellOps’ access from your Google account at myaccount.google.com/permissions.

5. AI features

5.1AI features (note assistance, document drafting and similar tools) are optional, and practitioners choose whether to turn them on. When a practitioner records a session for AI notes, its audio is transcribed, and the recording is deleted automatically after the period they choose (30, 60 or 90 days, or as soon as the summary is saved).

5.2When used, only the content needed for the request is sent to the AI provider (Google Gemini; AssemblyAI, which transcribes recorded sessions for AI notes; and Anthropic, which reads your existing website or directory profile if you use the practice import) through their business API.

5.3Our AI providers are contractually prohibited from using this data to train their models. They may keep it for a limited period set by their business terms, for abuse monitoring, after which it is deleted.

5.4We do not use client data to train any AI model of our own.

5.5AI output is a draft for the practitioner to review. It is never used to make automated decisions about clients.

6. International transfers

6.1We are based in the UK, and our group and providers operate in other countries, including the USA, the EU and the UAE. Your data is hosted with Akamai (Linode) in Frankfurt, Germany.

6.2When we transfer personal data out of the UK or EEA, we rely on: an adequacy decision (including the UK–US Data Bridge and EU–US Data Privacy Framework where the provider is certified); the EU Standard Contractual Clauses; the UK International Data Transfer Agreement or Addendum; or another lawful mechanism. Where required we assess the laws of the destination country and apply extra safeguards such as encryption.

6.3You can ask us for a copy of the relevant safeguards by emailing support@mywellops.com.

7. How long we keep data

DataHow long
Account and support dataLife of the account, then 2 years
Billing, invoices and tax records6 years after the end of the financial year (UK tax law)
Client data processed for practitionersWhile the practitioner's account exists: cancelling a paid plan moves it to the free plan and keeps the data. Practitioners delete files and notes themselves; client records and whole accounts are deleted within 90 days of a request to support@mywellops.com, and backups roll off within a further 35 days. AI-notes recordings: 30, 60 or 90 days, as the practitioner chooses
Prospect and marketing data2 years from last contact, or until you opt out (we keep a suppression record so we do not contact you again)
Security, fraud and access logsUp to 12 months, longer where needed for an investigation
Data relevant to a dispute, debt or legal claimUntil the matter is resolved and limitation periods expire
CookiesSee section 10

8. Security

We protect data with encryption in transit (TLS) and at rest, hashed passwords, role-based access controls, multi-factor authentication for staff, activity logging, regular backups, vulnerability patching and supplier due diligence. Staff access to client data is limited to what is needed for support, security or legal reasons, under confidentiality. If a personal data breach affects you, we will notify you and the relevant regulator where the law requires. Practitioners are notified within 48 hours under our Data Processing Agreement.

9. Your rights

9.1Everyone. You can ask us to access, correct or delete your data, opt out of marketing at any time using the unsubscribe link or by emailing us, and withdraw any consent you gave.

9.2UK, EU and EEA. You also have the right to restrict processing, to data portability, and to object to processing based on legitimate interests, including direct marketing (which we will always stop).

9.3United States. Depending on your state (including California, Colorado, Connecticut, Virginia, Texas and others), you may have the right to know, access, correct and delete personal data, and to opt out of sale, sharing for targeted advertising, and profiling. We do not sell personal data. We share limited data with advertising platforms (Meta and Google) to measure our own advertising, which some state laws treat as "sharing". To opt out, email support@mywellops.com. We will not discriminate against you for exercising your rights. You may use an authorised agent.

9.4UAE, Canada, Australia and elsewhere. You have the rights given by your local law, such as UAE Federal Decree-Law No. 45 of 2021, PIPEDA or the Australian Privacy Principles. Contact us and we will respond in line with that law.

9.5How to make a request. Email support@mywellops.com. We may need to verify your identity. We respond within one month (or the period your local law requires), and may extend this where the law allows. If you are a practitioner's client, contact your practitioner first (section 1.4).

9.6Complaints. Please contact us first so we can try to fix it. You also have the right to complain to your data protection regulator:

Where you areRegulator
UKInformation Commissioner's Office
IrelandData Protection Commission
Other EU/EEAYour national data protection authority
ElsewhereYour local privacy regulator

10. Cookies

We use essential cookies, and similar storage in your browser, to run the site and app. On mywellops.com we only set analytics and advertising cookies if you accept them in our cookie banner, and you can change your choice at any time from "Cookie settings" in the footer. The MyWellOps app works differently, as set out below the table.

TypePurposeConsent neededExamples
EssentialLog-in, security, remembering your cookie choice and regionNoIn the app: sign-in cookies (access_token, user_data) and your practice branding (mwo_branding). On our website: your cookie choice and region, kept in local storage
AnalyticsUnderstanding how the site and app are usedYes on our website; see below for the appGoogle Analytics (through Google Tag Manager), Contentsquare, Hotjar
AdvertisingMeasuring and targeting our campaignsYes on our website; see below for the appGoogle Ads, Meta Pixel
Support and bookingChatting with our support team, and booking a demoChat: yes on our website; see below for the app. Calendly: only when you choose to bookGleap (support chat, on our website and in the app), Calendly (the booking calendar on our demo page, loaded when you ask to book)

Practitioners' booking pages and websites use essential cookies only. The MyWellOps app at app.mywellops.com, including the client portal, loads Google Tag Manager (with Google Analytics), Hotjar, the Meta Pixel and Gleap's support chat, and Contentsquare on its public pages, and does not currently ask for consent before doing so.

11. Marketing

We send marketing to customers about similar services under the soft opt-in, and to others only where the law allows or with consent. Every email includes an unsubscribe link. Service messages (billing, security, price or terms changes) are not marketing and will still be sent.

12. Children

MyWellOps is a business service and is not directed at anyone under 18. Practitioners who work with children are responsible, as controller, for the lawful handling of their clients' data, including parental consent where required.

13. Changes to this policy

We will update this policy when our practices or the law change. We will tell customers about material changes by email or in-app notice before they take effect. The date at the top shows the latest version.

14. Contact us

  • Company: My Well Ops Ltd (company number 16452645), 8 Golden Square, London W1F 9HY
  • Privacy questions and requests: support@mywellops.com
  • General: info@mywellops.com
  • EU representative: not yet appointed