01Who is responsible for your data
The controller of personal data processed in connection with the activities of the Wellmade Launch brand and the wellmadelaunch.com website is:
02-654 Warsaw, Poland
Tax ID (NIP): 5214111998
For all matters relating to personal data, please write to k.bodziony@somahealthco.com. We respond to every request. We have not appointed a data protection officer, as we are not required to do so - we handle all contact directly.
Wellmade Launch is a trade brand, not a separate legal entity. The company named above remains the controller.
02What data we collect
We do not create user accounts and we do not profile visitors. We receive data only when you contact us yourself - through the contact form or directly by email.
Data from the form and correspondence
- Your first and last name, email address and, optionally, your phone number and job title.
- The name of the company you represent and your role in the project.
- The content of your message and anything you choose to include in it.
- In the form, additionally: the type of project (existing brand or new brand), the markets in which you currently sell, the product category and the areas of interest you select.
The form intentionally does not accept attachments. You share your company's confidential materials only in direct correspondence, once confidentiality terms have been agreed.
Data provided in the course of cooperation
- Information about your products and company: formulations, specifications, labels, sales data and market entry plans.
- Product documentation, certificates, agreements with manufacturers and marketing materials.
- Contact details of individuals acting on behalf of the brand, the manufacturer, the logistics operator or advisers involved in the project.
Technical data
The hosting server records standard access logs - IP address, date and time of the request, and browser type. These logs are used solely for security and diagnostic purposes; we do not link them to your identity and do not use them for marketing.
03Why and on what basis
Each purpose has its own legal basis under the GDPR - Regulation (EU) 2016/679 of the European Parliament and of the Council.
| Purpose of processing | Legal basis |
|---|---|
| Responding to your message and conducting correspondence | The controller's legitimate interest - communicating with a person who has made contact (Art. 6(1)(f) GDPR) |
| Assessing the project, preparing a proposal and negotiations | Taking steps at the request of the data subject prior to entering into a contract (Art. 6(1)(b) GDPR) |
| Providing services: market entry report, entry of a brand into the Polish market, building a new brand, assembling a supply chain | Performance of a contract (Art. 6(1)(b) GDPR) |
| Invoicing, accounting and document archiving | The controller's legal obligation (Art. 6(1)(c) GDPR) |
| Establishing, exercising and defending legal claims | The controller's legitimate interest (Art. 6(1)(f) GDPR) |
| Security and proper functioning of the website | The controller's legitimate interest (Art. 6(1)(f) GDPR) |
Providing data is voluntary, but without contact details we cannot reply to your message, and without product data we cannot prepare an assessment or a market entry plan. We do not make decisions based solely on automated processing and we do not carry out profiling that produces legal effects.
04Confidentiality of product information
This section addresses what brands ask about most often - what happens to formulations, specifications and plans once they reach us.
- We share product documents with counterparties in the supply chain - the manufacturer, the warehouse, the law firm - only to the extent necessary for the project and only with your approval.
- At your request, we sign a non-disclosure agreement (NDA) before any documents are exchanged.
- We do not use one brand's data to work on another brand's project or in our own ventures.
- We do not publish or resell formulations and specifications, and we do not include them in any data product.
- We build market entry reports exclusively on data from public registers and publicly available sources - never on materials entrusted to us by other clients.
Access to materials is limited to the people actually involved in the relevant process. We store files in cloud services protected by two-factor authentication.
05Who we may share data with
We do not sell data or share it for marketing purposes. Recipients may only be:
- Providers of email, hosting and cloud services, under data processing agreements.
- The provider of the contact form handling service (FormSubmit), which forwards the content of your submission to our email inbox.
- The accounting firm and the law and tax firms that serve the controller.
- Counterparties in the supply chain - manufacturers, repackaging facilities, logistics operators and law firms - only to the extent you expressly agree to, and only within the project carried out for you.
- Public authorities, where an obligation to disclose data arises from applicable law.
Some service providers may process data outside the European Economic Area. In such cases, the transfer takes place on the basis of a European Commission adequacy decision or standard contractual clauses.
06How long we keep data
| Category | Period |
|---|---|
| Correspondence not followed by cooperation | Up to 24 months from the last message, after which it is deleted |
| Client data and documents | For the duration of the cooperation and, after it ends, until the limitation periods for claims expire |
| Accounting records and invoices | 5 years from the end of the tax year, in accordance with applicable law |
| Server logs | In accordance with the hosting provider's policy, usually up to 12 months |
We delete product documents at your request at any time, unless their retention is necessary for the defence of legal claims or is required by a legal obligation.
07Your rights
In connection with the processing of your data, you have the right to:
- access your data and obtain a copy of it,
- rectify inaccurate or incomplete data,
- erasure of your data, unless a legal obligation or the defence of legal claims prevents it,
- restriction of processing,
- portability of data processed on the basis of a contract,
- object to processing based on legitimate interest,
- withdraw consent at any time, without affecting the lawfulness of processing carried out before its withdrawal.
Simply send your request to k.bodziony@somahealthco.com. We respond within one month of receiving your request at the latest.
If you believe that we process your data unlawfully, you may lodge a complaint with the President of the Personal Data Protection Office (UODO), ul. Stawki 2, 00-193 Warsaw, Poland.
09Data from public registers
For our market analyses and market entry reports, we use information from publicly available sources: the register of products notified to the Chief Sanitary Inspectorate (GIS), the National Court Register (KRS) together with financial statements, EU registers and search demand data.
This is essentially data about businesses and products, not about natural persons. If personal data appears in such a dataset - for example, the names of individuals representing a company, as disclosed in a public register - we process it on the basis of our legitimate interest in conducting market analyses (Art. 6(1)(f) GDPR), and only to the extent disclosed in the register.
You also have the right to object to such processing. Upon receiving an objection, we remove the data from our analyses, unless we have overriding grounds for further processing.
10Changes to this policy
We update this policy when the scope of our services, the set of tools we use or the applicable law changes. The current version is always available at this address, and the effective date is shown at the top of the document.
If a change is material for the people we work with, we will inform them directly by email.