Privacy Policy
This policy covers the Welaka website (trywelaka.com and welaka.ai) and the Welaka application. Last updated [PLACEHOLDER — NOT LEGAL COPY: publication date, set at launch]
What this covers
This policy explains what information Welaka collects, why, who we share it with, and what you can ask us to do about it.
It applies to the Welaka marketing website (served at trywelaka.com and welaka.ai) and to the Welaka application — the sales CRM you sign in to and use. Where a rule applies to only one of those, we say so.
Information we collect
From the website. If you request a demo or subscribe to updates, we collect what you type into the form — your name, your email address, and any company or role details the form asks for. When you submit a form we also record the page you submitted from, the referring website, and any campaign parameters in the link you followed (utm_source, utm_medium, utm_campaign, utm_content, utm_term, gclid, fbclid).
Analytics. On the website we use Google Analytics 4 to understand which pages people read and which links they follow — standard measurements such as pages viewed, approximate location derived from IP address, device type, and referral source — and Cloudflare Web Analytics, which is privacy-preserving and sets no client-side identifier.
From the application. When you use the Welaka application, we collect the account information you or your organization provides (such as your name, work email, and role), and the content you put into the product to do your job in it.
[PLACEHOLDER — NOT LEGAL COPY: enumerate the categories of customer data the application stores (contacts, companies, pipeline, messages, etc.) at the level of detail counsel wants disclosed. Operator + counsel supply from the actual data model — do not infer.]
Cookies and similar storage.
[PLACEHOLDER — NOT LEGAL COPY: enumerate the actual cookies and storage keys set on the website and in the application at launch, their purpose, and their lifespan — taken as an inventory from the built site and app, not from the build spec.]
When you sign in with Google or Microsoft
The Welaka application lets you sign in with a Google or a Microsoft account. When you choose to, that provider asks you to approve what Welaka may access, and then shares that information with us so we can create and secure your account.
[PLACEHOLDER — NOT LEGAL COPY: list the EXACT OAuth scopes the application requests from Google and from Microsoft, in plain language (e.g. "your name, email address, and profile picture" for basic sign-in; name any additional scope such as calendar or mailbox access separately with what it is used for). Google verifies this section against the scopes configured on the OAuth client — it must match exactly. Operator supplies the scope list.]
We use the information a sign-in provider shares only to run the features you signed in for — creating your account, keeping you signed in, and the specific tasks tied to any permission you granted. We do not use it for advertising, and we do not sell it.
Google API Services — Limited Use
Welaka's use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
[PLACEHOLDER — NOT LEGAL COPY: keep the sentence above verbatim if the app uses ANY Google OAuth scope (it is Google's required affirmation). If the app uses restricted scopes (e.g. Gmail, Drive), counsel should confirm the app also meets the additional restricted-scope requirements before submitting for verification.]
How we use information
For the website:
To answer you, to schedule and prepare for a demo you asked for, to send you the updates you subscribed to, and to understand which parts of the site are useful.
For the application:
To provide the product, secure your account, operate the features you use, support you, and improve how the product works for you.
What we do not do
Your customer data is yours. We never train on, market to, share, or sell the contacts and records you put into the Welaka application. There is no lead marketplace, no advertising business, and no parent company with either.
We do not run third-party advertising networks or advertising pixels on the website.
We do not use the website to collect health information about any patient, and nothing on it is intended to. Welaka is a sales tool used by businesses that sell to healthcare organizations. It is not a clinical system and plays no part in the relationship between a patient and their provider.
[PLACEHOLDER — NOT LEGAL COPY: counsel to confirm the "we do not sell your information" line against the CCPA/CPRA definitions of "sale" and "share", which are broader than the plain-English meaning and can be triggered by analytics configuration alone.]
Who else sees it
We rely on a small number of service providers to run Welaka. They process information on our behalf and under contract, only to provide their service to us:
- Cloudflare — hosts and delivers the website and application, and provides privacy-preserving analytics.
- Google — provides website analytics (Google Analytics 4 via Google Tag Manager) and, if you choose it, Google sign-in.
- Microsoft — if you choose it, Microsoft sign-in.
[PLACEHOLDER — NOT LEGAL COPY: complete the sub-processor list — the demo-form destination / CRM (open R12 decision), the application's data store and email provider, and any others — with each provider's purpose. Operator + counsel supply the full, accurate list before this policy is submitted for OAuth verification.]
How long we keep it
[PLACEHOLDER — NOT LEGAL COPY: retention periods for website leads and for application data — undecided. Operator + counsel set these. Do not infer a period from any system's failure buffer.]
How to access or delete your data
Ask us what we have. Email hello@welaka.ai and we will tell you what information we hold about you.
Ask us to delete it. Email hello@welaka.ai and we will delete the information we hold about you, including data obtained through Google or Microsoft sign-in, unless we are required by law to keep it. If your access is managed by your organization, we will coordinate the request with them.
Stop hearing from us. Every marketing email we send has an unsubscribe link, and it works.
[PLACEHOLDER — NOT LEGAL COPY: if the application offers in-product self-service deletion (recommended for OAuth), describe where it lives and confirm the timeframe. Operator supplies once the flow exists.]
Your privacy rights
[PLACEHOLDER — NOT LEGAL COPY: jurisdiction-specific rights (GDPR and CCPA/CPRA disclosures, response deadlines, the "Do Not Sell or Share" treatment, and any required site-wide links). Counsel drafts this — do not template it from another company's policy.]
Security
We protect information with technical and organizational measures appropriate to its sensitivity, including encryption in transit. No method of storage or transmission is perfectly secure, and we cannot guarantee absolute security.
Where your data is handled & children
Welaka is a business tool intended for use by people acting for an organization. It is not directed to children and we do not knowingly collect information from anyone under 16.
[PLACEHOLDER — NOT LEGAL COPY: where data is stored/processed (regions) and any international-transfer mechanism. Depends on the hosting/sub-processor configuration; operator + counsel supply.]
Changes to this policy
If we change this policy we will update the date at the top of this page. If a change is significant, we will take reasonable steps to tell you.
Who we are & how to reach us
Privacy questions and requests: hello@welaka.ai — a real person reads this address.
[PLACEHOLDER — NOT LEGAL COPY: legal entity = Welaka Inc (founder-supplied 2026-08-31). STILL NEEDED before this ships: its registered postal address and, if required by law, an EU/UK representative or Data Protection Officer. Terms of Service names the same entity — keep them identical.]