Privacy Policy

Last Updated: December 08, 2024

Intro

1.1 Who we are

Welcome to Welo Badge, the platform designed to guarantee security, transparency and reliability in the digital world. We are an innovative company that offers advanced solutions for the certification of companies through the Welo Badge, detailed analyses and services dedicated to consumers to make the web a safer place.

The protection of our users' personal data is a top priority for us. This Privacy Policy aims to explain in a clear and transparent way:

  • What personal data do we collect.
  • How we use and protect that data.
  • Your rights regarding the processing of your personal data.

We invite all users to read this Privacy Policy carefully to fully understand how we handle personal information.

1.2 Acceptance of the Privacy Policy

The use of Welo services implies full acceptance of this Privacy Policy. If you do not accept the terms described in this policy, please stop using our services immediately.

Welo reserves the right to update or modify this Privacy Policy at any time. In the event of significant changes, we will notify you via email or notifications on our website with adequate notice. Your continued use of our services after such changes constitutes acceptance of the new terms.

Effective date: [Enter date]

Types of Data Collected

2.1 Data provided by the user

When using our services, we collect data that users voluntarily share, including:

  • For companies:
    • Name of the company and data of the owner or legal representative.
    • Business email address and support contacts (toll-free number, chat, etc.).
    • Link to the website, the Terms and Conditions, the Privacy Policy and other legal pages.
    • Financial information, such as IBAN or chosen payment method.
    • Logo, images for the Welo page and a brief description of the business.
  • For private customers:
    • First and last name.
    • Email address and phone number (for support requests or refunds).
    • Link or details about the company to verify (for private verification).

2.2 Data collected automatically

When browsing our site or using the services, we automatically collect:

  • Technical data:
    • IP address, type of device, operating system and browser used.
  • Usage data:
    • Interactions with the site, such as pages visited, time spent on each page, and clicks.
  • Analytical data:
    • Collected through tools such as Google Analytics and Clarity to improve the user experience and optimize services.

2.3 Data collected for specific purposes

  • For business audits:
    • Documents necessary for analysis, such as certifications, licenses, or details of the payment methods used (e.g. Stripe, PayPal).
  • For refunds and assistance:
    • Order details, such as receipts, purchase dates, or descriptions of the problem encountered.
  • For marketing purposes:
    • Email addresses and telephone numbers for sending promotions, offers and updates on services.

Purposes of the Treatment

3.1 Service Management

We collect and process the personal data of users to provide our services in an efficient and personalized way. In particular:

  • For companies:
    • Verify that the company complies with the Welo Badge criteria.
    • Create and manage Welo Pages, with detailed information and verified analysis.
    • Provide assistance and support to improve the company's reliability, if necessary.
    • Monitor the number of views to ensure adherence to the subscribed plan.
  • For private customers:
    • Provide quick and accurate answers to private verification requests.
    • Manage requests for assistance on refunds or issues with online orders.
    • Offer support for any doubts or questions regarding companies or products.

3.2 Analysis and improvement of services

We use the collected data to:

  • Optimize the user experience on the site and improve the services offered.
  • Analyze user behavior to identify opportunities for improvement.
  • Perform market analysis and reporting to understand audience needs.

3.3 Marketing and communications

Personal data can be used to:

  • Send promotional emails, special offers, and notifications related to Welo services.
  • Personalize communications based on the user's interests and preferences.
  • Share updates on new services, features, or partnerships.

Note: Users can choose not to receive promotional communications at any time through the unsubscribe link included in each email or by contacting us directly.

3.4 Legal Compliance

We process personal data to comply with legal obligations, including:

  • Compliance with personal data protection regulations (e.g. GDPR).
  • Compliance with legal or regulatory requests, court orders, or government investigations.
  • Fraud prevention and protection of user and platform security.

Legal Basis of the Treatment

4.1 Execution of the Contract

We process the personal data of users mainly to provide the requested services, such as:

  • Verify companies and assign the Welo Badge.
  • Create and manage Welo Pages and subscription plans.
  • Provide assistance to private customers for checks, refunds, and support.

These activities are necessary for the execution of the contract between Welo and its users.

4.2 Explicit consent

In some cases, we collect and process personal data based on the explicit consent of users. This happens, for example, when:

  • Users sign up to receive promotional emails or marketing updates.
  • We provide optional features that require specific consent (e.g. detailed analysis of preferences).

Users can revoke their consent at any time, without affecting the lawfulness of the previous processing.

4.3 Legitimate interest

We use personal data even when it is in our legitimate interest to do so, ensuring that the user's fundamental rights and freedoms do not prevail. Purposes may include:

  • Ensure platform security and prevent fraud.
  • Improve services through analysis of user interactions.
  • Offer personalized communications about the services that users are already using.

4.4 Compliance with legal obligations

We process data to comply with applicable legal regulations, including:

  • Accounting and tax obligations.
  • Response to valid legal requests from competent authorities.
  • Compliance with local and international data protection regulations (e.g. GDPR, ePrivacy).

Data Sharing

5.1 Who do we share data with

To provide our services efficiently, the personal data collected may be shared with:

  1. External service providers:
    • Technical partners who manage the IT infrastructure, the website and the payment system (e.g. Stripe, PayPal).
    • Analysis platforms, such as Google Analytics and Clarity, to monitor and improve the user experience.
  2. Affiliated or associated companies:
    • We share data with any partners that work with Welo to expand and optimize services.
  3. Public or legal authorities:
    • In the event of legitimate requests, court orders, or legal requirements, we may share data with government bodies or competent authorities.

5.2 International transfers

If data needs to be transferred outside the European Union or the European Economic Area (EEA):

  • We ensure that the transfer takes place in accordance with the GDPR, using protection mechanisms such as standard contractual clauses or appropriateness decisions of the European Commission.

5.3 Shared Data Security

We ensure that all partners and suppliers:

  • They comply with strict security and data protection standards.
  • They process data only for specific purposes and in accordance with our instructions.
  • We have taken appropriate technical and organizational measures to prevent unauthorized access.

5.4 What we don't do

  • We never sell your personal data to third parties.
  • We do not share data for purposes other than those explicitly indicated in this Privacy Policy.

Data Retention

6.1 Duration of storage

We keep personal data only for as long as necessary to fulfill the purposes for which they were collected, in accordance with current legislation. Retention periods vary depending on the type of data and specific use, as follows:

  • Business data for the Welo Badge and the checks:
    • Retained for the entire duration of the subscription or service subscribed to.
    • Extended storage up to 6 months after the cancellation or suspension of the plan, for any disputes or requests for assistance.
  • Personal data of private customers:
    • Retained for a maximum of 12 months after the conclusion of the request for assistance or private verification.
  • Financial data:
    • Retained for the time required by tax and accounting regulations (usually 10 years).
  • Data collected through cookies or analysis tools:
    • Stored for specific periods defined by our Cookie Policy, generally no longer than 24 months.

6.2 Retention Criteria

The data will be kept only for:

  1. Meet contractual and legal obligations.
  2. Resolve any disputes.
  3. Prevent fraud and abuse.
  4. Improve the user experience and the services offered.

At the end of the storage period, the data will be securely deleted or made anonymous for statistical and analytical purposes.

6.3 Deleting data

Users can request the cancellation of their personal data at any time, by contacting our support.

  • The request will be evaluated to ensure that there are no legal or contractual obligations that prevent us from proceeding with the immediate cancellation.

User Rights

7.1 Right of access

Users have the right to obtain confirmation on the processing of their personal data and to access:

  • A copy of the data collected.
  • Information on the purposes of the processing.
  • Details about the recipients or categories of recipients with whom the data is shared.

7.2 Right to rectification

Users may request that inaccurate or incomplete personal data be corrected or updated at any time.

7.3 Right to cancellation (Right to be forgotten)

Users have the right to request the deletion of their personal data in the following cases:

  • The data is no longer necessary for the purposes for which it was collected.
  • The user revokes the consent to the processing and there is no other legal basis for the processing.
  • The data has been processed unlawfully.

7.4 Right to object

Users can object to the processing of their data for specific purposes, such as direct marketing or profiling.

7.5 Right to restrict processing

Users can request that the processing of their data be limited, for example:

  • When verifying the accuracy of the disputed data.
  • If the processing is illegal but the user does not want cancellation.

7.6 Right to data portability

Users have the right to receive the personal data provided to Welo in a structured, commonly used and machine-readable format, and to transmit them to another data controller.

7.7 Exercise of rights

Users can exercise their rights by contacting our support through:

  • Email: [support email]
  • Contact form on the website: [link to the form]
  • Mailing address: [business address]

Requests will be handled within 30 days, except for complex cases that require a longer time (up to 90 days).

7.8 Complaints

If a user believes that their rights have been violated, they can file a complaint with the personal data protection authority of their country (for example, the Privacy Guarantor in Italy).

Data Security

8.1 Measures taken

Welo is committed to protecting the personal data of users through advanced technical and organizational measures. These include:

  • Data encryption: All sensitive data is encrypted both in transit (for example, via HTTPS) and at rest.
  • Limited access: Only authorized personnel have access to personal data, and only for specific purposes.
  • Firewall and monitoring: Our infrastructure is protected by advanced firewalls and continuous monitoring tools to prevent unauthorized access.
  • Regular backups: We regularly back up data to ensure its integrity and recovery in the event of an incident.

8.2 Preventing unauthorized access

We have implemented strict procedures to identify, prevent, and respond to potential unauthorized access, including:

  • Two-Factor Authentication (2FA): Used to access our internal systems.
  • Regular checks: Periodic security audits to verify regulatory compliance and identify any vulnerabilities.
  • Malware protection: Threat detection and prevention systems to avoid virus or malware infections.

8.3 What to do in the event of a data breach

In the event of a personal data breach, Welo undertakes to:

  1. Notify involved users: Providing clear information about what happened, the compromised data and the measures taken to solve the problem.
  2. Inform the competent authorities: As required by the GDPR, we will notify any significant violations to the supervisory authority within 72 hours of identification.
  3. Take corrective measures: To prevent a recurrence of the accident and further strengthen security.

8.4 User Responsibility

Users have an active role in protecting their data. We invite everyone to:

  • Keep your login credentials confidential.
  • Use strong and unique passwords for your accounts.
  • Report any suspicious activity or violations to our support immediately.

Use of Cookies and Similar Technologies

9.1 What are cookies

Cookies are small text files that are stored on the user's device while browsing our website. These files allow the site to work properly, improve the user experience and collect useful data for analysis and optimization.

9.2 Types of cookies used

Welo uses different types of cookies for various purposes:

  1. Technical cookies:
    • Necessary for the operation of the website.
    • They allow you to navigate between pages and use essential functions (e.g. authentication).
  2. Analysis cookies:
    • They collect anonymous information on how users interact with the site (e.g. pages visited, time spent on the site).
    • We use tools such as Google Analytics and Clarity to analyze and improve the user experience.
  3. Marketing cookies:
    • Used to show personalized ads based on user interests.
    • These cookies can also track browsing on sites external to ours.
  4. Preference cookies:
    • They save the settings chosen by the user, such as the language or the way the site is displayed.

9.3 Managing cookies

Users can manage or disable cookies at any time through:

  1. Cookie banner:
    • During the first visit to our site, users are shown a banner that allows them to accept, reject or customize cookies.
  2. Browser settings:
    • Users can configure their browser to block or delete cookies.
    • The steps vary depending on the browser used (e.g. Chrome, Safari, Firefox).
  3. Revocation of consent:
    • Users can change their cookie preferences by accessing the 'Cookie Settings' section of our site at any time.

9.4 Third-party cookies

Some cookies on our site are provided by third parties, such as:

  • Google Analytics: For traffic and performance analysis.
  • Advertising tools: To manage campaigns and track conversions.

These third-party providers are responsible for the processing of the data collected through their cookies. We invite you to consult their privacy policies for more details.

9.5 Cookie storage period

  • Technical cookies are kept for the duration of the session or for the time necessary for their purpose.
  • Analysis and marketing cookies can be kept for up to 24 months, unless otherwise configured.

Changes to the Privacy Policy

Updates and communications

Welo reserves the right to change or update this Privacy Policy at any time, for legal, technical or business reasons. Any substantial changes will be communicated to users in the following ways:

  • Email: Registered users will receive an email notification if significant changes are introduced to the privacy policy.
  • Notification on the website: When you visit our site, a banner may appear informing users of changes to the Privacy Policy.

The changes will take effect from the date of publication of the new version on our website, unless otherwise indicated.

10.2 Effective Date

This Privacy Policy is effective as of [insert date]. Each change will be updated with the effective date indicated at the top of the page.

Contacts

11.1 Support and Requests

For any questions related to the Privacy Policy or to exercise your rights over your personal data, you can contact our support team at the email address:

  • Email: support@welobadge.com

You can also use our online contact form to send specific requests:

11.2 Data controller

If you need more information regarding the processing of your data, you can contact our Data Protection Officer (DPO) at:

  • AFTER: support@welobadge.com

11.3 Complaints

If you believe that your rights have not been respected, you can file a complaint with the competent data protection authority in your country of residence.