Last updated: August 19, 2026

Appendix 1 – Data Processor Agreement (DPA)

Wellsteps’ General Terms and Conditions

1. Parties and Background

This Data Processing Agreement (“the Agreement”) is entered into between the Customer, as specified in the order confirmation, acting as the data controller, and Wellstep AB, corporate ID no. 559322-5187, Göteborgsvägen 46, 431 37 Mölndal (“Wellstep”), as the data processor.

The Data Processing Agreement is part of the agreement regarding Wellstep365 entered into by the parties (the “Master Agreement”) and governs Wellstep’s processing of personal data on behalf of the Customer in accordance with Article 28 of the General Data Protection Regulation (EU) 2016/679. In the event of any conflict, the Data Processing Agreement shall prevail in matters relating to personal data.

If the Customer instead wishes to enter into a separate, signed service agreement, Wellstep shall accommodate this request.

2. Treatment

The purpose, duration, and scope of the treatment are set forth in Appendix A.

Wellstep processes personal data solely to provide, maintain, and support the service, not for its own purposes. However, Wellstep has the right to use anonymized and aggregated statistics to develop the service, provided that individual persons or customers cannot be identified.

3. Instructions

Wellstep processes personal data solely in accordance with the Customer’s instructions. The Master Agreement, this Data Processing Agreement, and the Customer’s own use and configuration of the service constitute the Customer’s instructions. Additional instructions must be provided in writing, and Wellstep is entitled to reasonable compensation for instructions that require work beyond the normal operation of the service.

If Wellstep determines that an instruction violates data protection laws, the Customer must be notified.

The customer is responsible for ensuring that there is a legal basis for the processing, that the information in the service is accurate, and that the data subjects have been informed about the processing.

4. Confidentiality and Security

Only employees who need access to personal data in order to fulfill Wellsteps’ obligations are granted such access, and are subject to a duty of confidentiality that remains in effect even after their employment ends.

Wellstep implements appropriate technical and organizational security measures in accordance with Article 32 of the General Data Protection Regulation, including:

  • TLS encryption during transmission between the user’s device and Wellstep’s servers
  • Storage in data centers within the EU
  • Needs-based and role-based access with individual accounts
  • Two-factor authentication for certain parts of the service offering, including Wellstep Engage
  • Regular backups and ongoing system updates
  • Internal Procedures for Data Protection and Incident Management

Wellstep may modify the measures as long as the level of security is not compromised.

5. Sub-processors

The Customer agrees that Wellstep may engage sub-processors. The current sub-processors are listed in Appendix B, and an updated list is available upon request.

Wellstep enters into agreements with each subprocessor that impose obligations equivalent to those set forth in this Subprocessor Agreement, and is responsible for the subprocessor’s processing as if it were its own.

Wellstep shall notify the Customer at least 30 days in advance if a sub-processor is added or replaced. The Customer has the right to object on objective grounds within this period. If no resolution is reached, the Customer has the right to terminate the Master Agreement effective as of the date the change takes effect, without being bound for the remainder of the term of the Agreement.

6. Transfer to a Third Country

Data processing within the service takes place within the EU/EEA. For certain functions, such as the distribution of push notifications, data may be processed outside the EU/EEA. In such cases, Wellstep ensures that there is a valid basis for the transfer in accordance with Chapter V of the General Data Protection Regulation (GDPR), such as standard contractual clauses or a decision on an adequate level of protection.

7. Assistance to the Customer

The service includes a feature that allows a user to request deletion. The Customer hereby instructs Wellstep to immediately deactivate the user’s data upon such a request so that it is no longer accessible in the service, and to flag the request in the administration interface. Permanent deletion will then take place in accordance with Wellstep’s procedures for handling deletion requests, unless the Customer specifies otherwise.

Other inquiries from registered users are referred to the Customer, who is notified of the request.

8. Data Breaches

Wellstep will notify the Customer without undue delay, and no later than 48 hours after discovery, of any personal data breach affecting the Customer’s data. The notification will include the information Wellstep has regarding the nature, scope, and likely consequences of the breach, as well as the measures taken.

Wellstep assists the Customer in preparing the documentation required for filing a report with the regulatory authority and registered entities, but does not file any reports on the Customer’s behalf.

9. Audit

Upon request, Wellstep will provide the information necessary to demonstrate compliance with the obligations under the Data Processing Agreement and will facilitate an audit conducted by the Customer or by an auditor appointed by the Customer.

Audits are conducted no more than once a year, must be announced at least 30 days in advance, and may not be performed by a competitor of Wellstep. Wellstep is entitled to reasonable compensation for time spent. If a current third-party audit covers the scope of the audit, it may be accepted in its place. Audits of sub-processors are conducted by Wellstep.

10. Deletion upon Termination of the Agreement

When the Master Agreement expires, the Customer’s personal data will be deleted as specified therein, unless the Customer has requested otherwise prior to that time or continued storage is required by law.

Data in backups is deleted as they are purged in accordance with standard procedures, and until then is subject to the same security measures as the rest of the data.

11. Term of the Agreement

The Data Processing Agreement remains in effect as long as Wellstep processes personal data on behalf of the Customer, including during any trial, demo, or evaluation period, and terminates upon deletion in accordance with Section 10.

In all other respects, the provisions of the Master Agreement regarding liability, amendments, governing law, and dispute resolution shall apply.


Appendix A – Scope of Treatment

Purpose and nature: Collection, storage, organization, processing, transfer, and deletion of personal data to provide, administer, and support Wellstep365, including any optional features.

Term: For the duration of the Master Agreement, plus the cancellation period specified in the Master Agreement.

Registered Users: The Customer’s employees and other users to whom the Customer grants access to the Service, as well as the Customer’s administrators and contact persons.

Personal Information:

  • Name and email address
  • Phone number, when the service is used for SMS messaging
  • Login Information
  • Employee ID number, date of birth, and other identifiers that the Customer chooses to provide
  • Segmentation and grouping, such as department, location, team, or type of employment
  • Steps, recorded activities, and other activity data
  • Activity and health data that the user chooses to share from a health service on their device, such as Apple Health or Health Connect
  • Survey Responses and Results
  • Messages and comments in the service’s chat and dialogue features
  • Log data related to the use of the service

Special Categories: Activity and health data constitute health information under Article 9. The customer is responsible for ensuring that an applicable exception under Article 9.2 exists. The customer shall not enter other special categories of personal data into the service and is responsible for ensuring that surveys and free-text fields are not designed to collect such data.


Appendix B – Sub-processors

Assistant Position Treatment location
[Hosting Provider] Operations, server management, and data storage Sweden/EU
[Email Provider] Email Delivery EU
[SMS Provider] SMS Delivery EU
[Push notification provider] Distribution of push notifications to mobile apps EU and the U.S.
[Support/CRM System] Management of support cases and customer contact EU
[Financial System] Invoicing and Accounting EU
[Logistics Provider] Delivery of pedometers EU

An up-to-date list is available upon request at info@wellstep.se.