Controller and scope
WELORISE LLC (the "Company", "we", "us") is a domestic limited liability company organised under the laws of the Commonwealth of Kentucky, USA, filing number 1607617, Federal EIN 38-4406090, with its registered office at 212 N. 2nd St., Ste 100, Richmond, KY 40475. The Company is the data controller in respect of personal data processed through welorise.com and in the course of providing its services.
This policy applies to visitors to the website, prospective clients who submit an enquiry or run the diagnostic, and clients engaged under a services agreement. It does not apply to the websites of our clients, which are governed by their own policies, nor to third-party platforms which act as independent controllers in respect of their own processing.
Personal data we collect
2.1 Data you provide directly
- Identity and contact data: name, business email address, company name, and any information you choose to include in correspondence.
- Store data: the URL of the storefront you submit to the diagnostic, together with your answers to the diagnostic questionnaire.
- Commercial data: revenue band, advertising spend band, platforms in use, and the services you are enquiring about.
2.2 Data generated by the diagnostic
When you submit a store URL, we retrieve and analyse publicly accessible pages of that storefront. The diagnostic inspects publicly served markup and resources — page performance metrics, the presence of tracking pixels, platform and theme indicators, review widgets, cart behaviour, and metadata. It does not attempt to access any authenticated area, administrative interface, customer record, or order data, and it does not circumvent any access control.
2.3 Data we receive when engaged
Where you engage us, you grant delegated access to advertising, analytics and commerce platforms under your own account permissions. We process the data available through that access solely to perform the engagement. You remain the controller of that data and of the underlying accounts; we act as processor in respect of it, on your documented instructions.
Purposes and legal bases
Where the UK GDPR or EU GDPR applies, we rely on the following legal bases:
- Performance of a contract, or steps taken at your request prior to entering into one — responding to enquiries, producing the diagnostic and audit, and delivering contracted services.
- Legitimate interests — operating and securing the website, maintaining business records, and preventing misuse of the diagnostic. We have assessed that these interests are not overridden by your rights.
- Compliance with a legal obligation — retention of financial and tax records, and responses to lawful requests from competent authorities.
- Consent — where consent is separately requested, such as for optional marketing communications. Consent may be withdrawn at any time without affecting prior processing.
What we do not do
The Company does not sell personal data, and does not share personal data with third parties for cross-context behavioural advertising or for any consideration, as those terms are used under applicable United States state privacy legislation. We do not build advertising profiles of visitors to this website. We do not enrich submitted business contact details with data purchased from brokers.
We do not accept card payments and do not receive, process or store cardholder data. Fees are settled by invoice and bank transfer only, and the resulting records are held by our bank and our accounting records rather than on this website.
Cookies and similar technologies
This website sets only cookies that are strictly necessary for it to function and to remain secure. It does not currently load analytics, advertising or social media tracking technologies, and accordingly no consent banner is presented, because there is nothing non-essential to consent to.
Should the Company later introduce analytics or advertising technologies, a consent mechanism satisfying the requirements of the UK and EU GDPR and the ePrivacy Directive will be implemented before those technologies are deployed, and this policy and the Cookie Notice will be amended accordingly. Full detail is set out in the Cookie Notice.
Disclosure to processors and third parties
We disclose personal data only where necessary, and only to the following categories of recipient:
- Infrastructure and hosting providers engaged to operate the website and its supporting services.
- Communications providers used to send and receive business correspondence.
- Contractors engaged to deliver elements of the services, each bound by written confidentiality and data protection obligations and permitted to process data only as instructed.
- Professional advisers, including accountants and legal advisers, where required.
- Competent authorities, where disclosure is required by law or necessary to establish, exercise or defend legal claims.
Each processor is engaged under a written agreement imposing obligations no less protective than those set out in this policy.
International transfers
The Company is established in the United States and its personnel and contractors are located in more than one jurisdiction. Personal data originating in the United Kingdom, the European Economic Area, Canada or Australia may therefore be transferred to and processed in the United States and other countries.
Where such a transfer occurs from the United Kingdom or the European Economic Area, it is made on the basis of the appropriate safeguards permitted under Article 46 of the UK or EU GDPR, being the applicable Standard Contractual Clauses together with the UK Addendum where relevant, supplemented by a transfer risk assessment. A copy of the safeguards relied upon may be requested using the contact details in section 12.
Retention
- Enquiry and diagnostic records: retained for 24 months from the last substantive contact, then deleted or irreversibly anonymised.
- Client records created during an engagement: retained for the duration of the engagement and for 6 years following its conclusion, reflecting statutory limitation and record-keeping periods.
- Financial and tax records: retained for the period required by applicable tax law.
- Correspondence: retained for so long as necessary for the purpose for which it was sent, and thereafter in accordance with the periods above.
Your rights
9.1 United Kingdom and European Economic Area
You have the right to request access to your personal data; to request rectification of inaccurate data; to request erasure; to request restriction of processing; to object to processing carried out on the basis of legitimate interests; to data portability; and to withdraw consent where processing is based on consent. You also have the right to lodge a complaint with your supervisory authority — in the United Kingdom, the Information Commissioner's Office.
9.2 United States
Residents of states with applicable comprehensive privacy legislation, including California, have the right to know what personal data is collected and the purposes of collection, to request deletion, to request correction, and to opt out of sale or sharing. As stated in section 4, the Company does not sell or share personal data. You will not be subjected to discriminatory treatment for exercising any right.
9.3 Canada and Australia
Residents of Canada may request access to and correction of personal information under the Personal Information Protection and Electronic Documents Act, and may complain to the Office of the Privacy Commissioner of Canada. Residents of Australia may request access and correction under the Australian Privacy Principles, and may complain to the Office of the Australian Information Commissioner.
9.4 Exercising a right
Requests should be sent to legal@welorise.com. We will respond within one month, or within such shorter period as applicable law requires, and will confirm receipt promptly. We may request information reasonably necessary to verify your identity before acting, and will not use that information for any other purpose. No fee is charged unless a request is manifestly unfounded or excessive.
Security
We apply technical and organisational measures appropriate to the risk, including transport encryption for data in transit, multi-factor authentication on accounts under our control, least-privilege access to client platforms, and written confidentiality obligations binding on all personnel and contractors. Access to client advertising and commerce platforms is held under delegated permissions which you may revoke at any time without our involvement.
No method of transmission or storage is entirely secure, and we do not represent otherwise. Where a personal data breach occurs which is likely to result in a risk to your rights and freedoms, we will notify the relevant supervisory authority and, where required, affected individuals, within the periods prescribed by applicable law.
Children
The services are offered exclusively to businesses and are not directed to children. We do not knowingly collect personal data from any person under the age of 18. Where we become aware that such data has been collected, it will be deleted without undue delay.
Contact and amendments
Privacy enquiries and rights requests should be addressed to legal@welorise.com. General correspondence may be sent to contact@welorise.com. Written correspondence may be sent to WELORISE LLC, 212 N. 2nd St., Ste 100, Richmond, KY 40475.
This policy may be amended to reflect changes in our processing or in applicable law. The effective date and date of last revision are stated at the head of this document, and any material change will be reflected there. Continued use of the website following an amendment constitutes acknowledgement of the amended policy.