PRIVACY POLICY

Last Updated: {{12/30/2025}}


Welya places data security and privacy at the core of its priorities.

Welya applies all applicable personal data protection requirements to its own operations and provides its Clients with tools designed to facilitate compliance with their own regulatory obligations, particularly regarding the General Data Protection Regulation (GDPR).


This Privacy Policy sets forth the terms and conditions under which Welya, Inc. collects, processes, uses, retains, and protects personal data obtained through the use of the Welya platform.


Welya, Inc. is a Delaware corporation whose principal address is:


Welya, Inc.

131 Continental Dr, Suite 305

Newark, DE 19713

United States


Welya operates the Welya platform and acts as a SaaS provider. In this capacity, Welya solely provides a technical SaaS infrastructure enabling the hosting, broadcasting, and automated processing of data and content provided by Clients, without editorial intervention, prior review, or involvement in determining the purposes or content of the processing performed by Clients via the platform.


This Policy applies to all users, whether residing in the United States, the European Union, the United Kingdom, Canada, Switzerland, or any other jurisdiction.


Use of the platform implies full and unreserved acceptance of this Policy.


DEFINITIONS


  • Client / Client-Organizer: Refers to any natural or legal person acting in a professional capacity who holds an account on the Welya platform, uses the Service to organize, broadcast, or administer webinars, and in this capacity determines the purposes and means of processing personal data relating to Attendees.

  • Attendee / Participant: Refers to any natural person registering for, accessing, or participating in a webinar organized via the Welya platform, whose personal data is processed on behalf of the Client-Organizer.

  • User: Refers to any natural person accessing the website or the Welya platform, whether as a Client, Prospect, Authorized User, or Attendee.

  • Authorized User: Refers to any person expressly authorized by the Client to access the Welya platform under its responsibility, particularly for managing, configuring, or administering webinars.

  • Prospect: Refers to any person who does not yet hold Client status but has provided certain personal data to Welya, particularly when signing up for a free trial.

  • Service / Platform: Refers to all services, features, software tools, interfaces, and infrastructure provided by Welya, accessible via the website and associated applications, enabling the organization and broadcasting of webinars.

  • Personal Data: Refers to any information relating to an identified or identifiable natural person, within the meaning of applicable data protection laws, including the General Data Protection Regulation (GDPR).

  • Client Data: Refers to all data, including personal data, provided, uploaded, generated, or processed by the Client through the use of the Welya platform, including data relating to Attendees.

  • Data Controller: Refers to the natural or legal person who determines the purposes and means of the processing of personal data, within the meaning of the GDPR and equivalent legislation. Under the Welya platform, the Client-Organizer acts as Data Controller for Attendee data, and Welya acts as Data Controller for Client account and Prospect data.

  • Data Processor: Refers to the natural or legal person who processes personal data on behalf of the Data Controller, upon its documented instructions. In the context of webinars, Welya acts as Data Processor for Attendee data.

  • Sub-processor: Refers to any third-party service provider engaged by Welya to perform specific personal data processing activities on its behalf (hosting, security, technical streaming, payment, etc.), subject to applicable contractual guarantees.

  • Cookies and Trackers: Refers to files or technologies that may be deposited or read on a user's terminal while browsing the website or using the platform, enabling, among other things, the operation of the Service, audience measurement, or user experience enhancements.

  • Standard Contractual Clauses (SCCs): Refers to the model clauses adopted by the European Commission pursuant to Article 46 of the GDPR, governing transfers of personal data to third countries that do not benefit from an adequacy decision.

  • Policy: Refers to this Privacy Policy and Personal Data Protection Policy, including its schedules.


1. APPLICABLE LEGAL FRAMEWORK


Due to the geographic diversity of its users, Welya applies a combined legal framework to ensure consistent protection of personal data.


  • United States: Data is processed in compliance with rules governing user transparency, fair practices, data security, and child protection (Section 5 of the Federal Trade Commission Act; Children’s Online Privacy Protection Act – COPPA; Delaware General Corporation Law; California Consumer Privacy Act / California Privacy Rights Act – CCPA/CPRA).


  • European Union: Data is processed in accordance with the principles of transparency, purpose limitation, security, and respect for data subjects' rights (General Data Protection Regulation – GDPR).


  • United Kingdom: Data is processed under principles equivalent to those applicable in the European Union (United Kingdom General Data Protection Regulation – UK GDPR).


  • Canada: Data is processed based on valid consent, with clear user information and appropriate safeguards (Personal Information Protection and Electronic Documents Act – PIPEDA).


  • Switzerland: Data is processed in compliance with transparency, proportionality, and heightened security requirements (Federal Act on Data Protection – revFADP).


The Client-Organizer is responsible for ensuring that its own business activities and data usage comply with applicable laws and regulations in its operating jurisdictions. This Policy does not relieve the Client-Organizer of its own legal and regulatory duties.


2. ROLES AND RESPONSIBILITIES IN DATA PROCESSING


When a Client uses the Welya platform to organize a webinar, upload or collect Attendee data, or analyze Attendee behavior, it acts as a Data Controller within the meaning of the GDPR, UK GDPR, PIPEDA, and equivalent laws. In this capacity, the Client alone determines the purposes and means of processing Attendee data and remains responsible for complying with applicable legal obligations, particularly regarding transparency and lawful processing bases.


For data relating to webinar Attendees (including names, email addresses, attendance, and interaction data), Welya acts strictly as a Data Processor. Welya processes this data exclusively on the documented instructions of the Client and solely for providing the webinar service. Welya exercises no control over the content, messages, materials, or interactions broadcast during webinars, which remain the sole responsibility of the Client-Organizer.


For data related to the Client Account (including name, email address, credentials, plan details, and billing information), Welya acts as a Data Controller for its own operational needs, platform management, and contractual relationship management.


Welya may engage sub-processors (such as cloud hosting, video streaming, transactional email, payment, or technical security providers). Welya remains responsible for ensuring that these providers maintain an equivalent level of data protection through appropriate contractual guarantees, including when data is hosted or processed in third-party jurisdictions.


3. PERSONAL DATA COLLECTED


In connection with the use of the Welya platform, personal data is collected and processed depending on the capacity in which Welya operates:

  • As Data Controller for platform Client users;

  • As Data Processor for webinar Attendees, processed on behalf of Client-Organizers.


3.1 Data Collected by Welya as Data Controller


In connection with account creation, management, and platform usage, Welya may collect the following data:


  • First and last name;

  • Email address;

  • Phone number, if applicable;

  • Payment information (bank details, card numbers, transaction date, amount, transaction ID). Bank and transaction information provided by the Client is encrypted using industry-standard protocols and cannot be read by Welya or any unauthorized third party;

  • Technical usage data (IP address, connection logs, device type, and browser details).


Personal data collected by Welya from Client users is processed, as Data Controller, strictly as necessary for contract performance, account administration, and platform operations, specifically to:


  • Create, manage, and administer Client accounts;

  • Enable secure access, authentication, and platform features;

  • Manage subscriptions, billing, and payment processing;

  • Enable the configuration and use of platform tools;

  • Provide customer support and address technical inquiries;

  • Ensure platform security, integrity, availability, and stability;

  • Prevent, detect, and handle fraud, abuse, or Terms violations;

  • Improve and develop platform performance and features.


These activities are strictly limited to what is necessary to fulfill contractual commitments.

Furthermore, when a Prospect registers for a free trial, Welya collects and processes identity data (first and last name) and contact data (email address). This data is processed by Welya as Data Controller solely to deliver requested materials, manage Prospect relationships, and send informative communications regarding Welya’s operations. Prospects may unsubscribe at any time via the link provided in each email.


3.2 Data Processed by Welya as Data Processor


In connection with hosting and broadcasting webinars, Welya processes the following Attendee personal data exclusively on behalf of the Client-Organizer:


  • First and last name;

  • Email address;

  • Phone number (when requested by the Client);

  • Country and IP address;

  • Attendance duration and connection timestamps;

  • In-webinar interactions (chat messages, questions, poll responses, link/offer clicks);

  • Technical device and browser data.


This data is processed solely to execute webinars smoothly and deliver associated features in accordance with the Client-Organizer's instructions.


3.3 Integrations and Third-Party Services


Clients may choose to connect third-party software, applications, or tools to the Welya platform, such as CRM systems, email marketing platforms, automation tools, payment solutions, or external APIs.


When integrations are enabled, personal data transferred, synchronized, or processed via these third-party tools is done so at the sole initiative and responsibility of the Client-Organizer.


Welya acts strictly as a technical provider enabling tool interconnection, without determining the purposes or means of third-party processing. The Client-Organizer must ensure that third-party services comply with applicable privacy regulations and that data subjects are properly informed. Welya disclaims all liability regarding processing carried out by third-party services.


4. DISCLOSURE OF PERSONAL DATA


Personal data collected and processed via the Welya platform is intended exclusively for Welya, acting as Data Controller or Data Processor, as set out herein. Welya commits to never rent, sell, or trade personal data to third parties for marketing purposes.


No personal data will be disclosed to third parties without prior consent, except in the following cases:


  • Sub-processors: Welya may share necessary data with authorized sub-processors (hosting, security, streaming, or operations) strictly to execute assigned tasks. These providers have access only to data required for their tasks and are bound by strict contractual duties of confidentiality and security.

  • Legal Compliance: Welya may disclose personal data if required by law, regulation, or a valid, enforceable order from a competent judicial or administrative authority. Only strictly necessary data will be disclosed.


5. INTERNATIONAL DATA TRANSFERS OUTSIDE THE EU


Because certain technical infrastructure or service providers are located in the United States or other jurisdictions, personal data collected via Welya may be hosted, accessed, or processed outside the European Union.


Where data relating to EU residents is transferred internationally, Welya ensures that transfers strictly comply with GDPR requirements. Specifically, data transfers outside the European Union are governed by the Standard Contractual Clauses (SCCs) adopted by the European Commission pursuant to Article 46 of the GDPR.


Copies of the Standard Contractual Clauses are available upon request.


6. DATA RETENTION PERIODS


Personal data collected by Welya is retained strictly for the duration necessary to process requests, perform ordered services, or meet legal and regulatory obligations.

Welya implements systematic deletion and archiving procedures to guarantee effective data erasure or irreversible anonymization once applicable retention periods expire.


Users may unsubscribe from informational or marketing emails at any time via the unsubscribe mechanism included in every message. Upon processing an unsubscribe request, Welya will cease sending marketing messages and update or remove the corresponding data accordingly.


Retention periods vary based on the relationship and data type:


  • Client Personal Data (account, identity, and professional information): Retained throughout the account's active period. Following account closure, data is erased or irreversibly anonymized within a maximum of twenty-four (24) months, unless longer retention is required by law or evidentiary needs.

  • Billing, Accounting, and Contractual Data: Retained for ten (10) years to satisfy statutory tax and legal obligations.

  • Technical Client Data (IP addresses, connection logs): Retained for up to twenty-four (24) months, after which it is anonymized for statistical, security, and performance tracking purposes.

  • Prospect and Event Attendee Data: Retained strictly for the duration necessary to organize, manage, and follow up on the event. Following the event, data is erased or anonymized within twenty-four (24) months, unless instructed otherwise by the Client-Organizer or required by law.

  • In-Event Interaction Data (chats, poll responses, attendance rates, clicks): Anonymized as soon as practical. Once anonymized, data may be kept indefinitely for aggregate statistics and feature optimization without identifying individuals.

  • Attendee Technical Connection Logs: Retained for up to twelve (12) months and then anonymized, unless security threats or legal duties necessitate longer retention.


The Client-Organizer remains solely responsible for setting and complying with retention periods for Attendee data collected via its webinars. Welya acts solely as Data Processor and provides management tools to assist the Client-Organizer in fulfilling these obligations.


7. DATA SUBJECT RIGHTS

Under applicable data protection laws, including the GDPR, individuals whose personal data is collected and processed enjoy the following rights:


  • Right of Access: The right to obtain confirmation as to whether personal data concerning them is being processed and, where applicable, access to that data.

  • Right to Rectification: The right to request the correction of inaccurate, incomplete, or obsolete personal data.

  • Right to Erasure ("Right to be Forgotten"): The right to request the deletion of personal data when it is no longer needed or when processing is unlawful.

  • Right to Restriction of Processing: The right to request the restriction of processing under statutory conditions, such as when data accuracy is contested.

  • Right to Data Portability: The right to receive personal data in a structured, commonly used, machine-readable format or request its transfer to another controller.

  • Right to Object: The right to object at any time, on grounds relating to their particular situation, to data processing based on legitimate interests.

  • Right to Withdraw Consent: The right to withdraw consent at any time where processing is based on consent, without affecting the lawfulness of processing performed prior to withdrawal.


When Welya acts as a Data Processor on behalf of a Client-Organizer, Attendee requests will be forwarded to the respective Client-Organizer, who remains responsible for responding as Data Controller. Welya will cooperate with the Client-Organizer to facilitate responses within legal deadlines.


To exercise data protection rights or request information, individuals may contact Welya at:


Welya, Inc.

131 Continental Dr, Suite 305

Newark, DE 19713

United States

Email: contact@welya.io


Requesters should specify the details of their request and the data concerned. To verify identity, Welya may request a copy of a valid government-issued ID, which will be used strictly for verification and deleted immediately thereafter.


Erasure requests may be restricted where statutory obligations mandate data retention. Individuals also retain the right to lodge a complaint with their local supervisory authority.


8. DATA SECURITY AND PROTECTION MEASURES


Welya implements appropriate technical and organizational safeguards to ensure a level of security appropriate to the risks involved in data processing, maintaining confidentiality, integrity, availability, and system resilience.


Key measures implemented by Welya include:


  • Isolated private network infrastructure without public exposure outside essential service channels (VPC, subnets, firewalls, NAT);

  • Data encryption in transit using current industry standards (TLS / HTTPS);

  • Web Application Firewalls (WAF) to protect against DDoS attacks and common software vulnerabilities (OWASP);

  • Multi-factor authentication mechanisms for access to internal tools, technical infrastructure, and accounts;

  • Strict role-based access controls limiting data access to authorized personnel;

  • Comprehensive logging, monitoring, and security incident management procedures.


In the event of a personal data breach, Welya will notify affected Client-Organizers promptly after becoming aware of the breach and will assist in fulfilling statutory notification duties to authorities and affected individuals.


9. CHILDREN'S PRIVACY


The Welya platform is designed exclusively for adults and business professionals.

Welya does not knowingly collect or process personal data from children under 18 years of age. Platform usage by minors is prohibited.


If a minor’s data is inadvertently collected during a webinar hosted by a Client-Organizer, the Client-Organizer remains solely responsible for the lawfulness of such collection and obtaining necessary parental consent. Upon learning that a minor's data was collected in violation of applicable laws, Welya will take swift action to delete such data.


The Client-Organizer agrees to hold Welya harmless against any claims or penalties resulting from unauthorized collection of minors' data through the platform.


10. HYPERLINKS AND THIRD-PARTY WEBSITES


The Welya website and platform may contain links to third-party websites or services. Welya exercises no control over third-party content, policies, or privacy practices.

Accessing third-party sites is done at the user's sole risk. Users are encouraged to review the privacy policies of any external sites visited.


11. COOKIES AND TRACKING TECHNOLOGIES


When visiting the website or platform, cookies and trackers may be placed on the user's device in accordance with applicable regulations and consent preferences.


11.1 Definition


A cookie is a small text file stored on an end-user device to recognize terminals, remember preferences, or gather browsing analytics.


11.2 Cookies Used by Welya


  • Strictly Necessary Cookies: Essential for platform navigation, authentication, and security. These cannot be disabled.

  • Performance & Audience Measurement Cookies: Used to analyze platform traffic, measure usage, and enhance user experience.

  • Functional Cookies: Used to remember user settings and preferences.

  • Webinar & Interaction Cookies: Used within webinars to enable participation, monitor technical operations, and support interactive tools.


11.3 Consent Management


Non-essential cookies are deposited only after obtaining prior consent via a consent management tool. Users can update or withdraw consent at any time via platform privacy settings or browser controls.


11.4 Client-Organizer Duties


When cookies or trackers are deployed within webinars for Client tracking or analytics, the Client-Organizer (as Data Controller) must inform Attendees and obtain required consent under applicable law. Welya provides technical management tools but does not dictate processing purposes.


12. WEB BEACONS AND PIXELS


Welya may use web beacons (also known as tags, pixels, or clear GIFs) on its website, platform, and emails. Beacons collect technical data (e.g., page views, email open rates, interactions).


Beacons are used to:

  • Measure and analyze audience engagement;

  • Enhance site performance and operations;

  • Detect fraud and enforce security;

  • Track webinar technical operations.


Beacons requiring consent are managed in accordance with the user's cookie consent preferences.


13. POLICY AMENDMENTS


Welya reserves the right to amend or update this Privacy Policy at any time to reflect legal, regulatory, technical, or operational changes.


Material amendments will be communicated in advance via appropriate channels, such as notices published on the platform or direct electronic messages.