Legal

Privacy Policy

Last updated: June 2026 — PENDING LEGAL REVIEW

01

Introduction

WeLink (operated by Adamas Group SA, Switzerland) is committed to protecting the privacy of its users. This privacy policy describes how we collect, use and protect your personal data.

02

Data collected

We collect the following data when you use WeLink:

  • Account information: first name, last name, email address
  • Organization data: company name, logo, contact details
  • Team member data: name, position, professional contact details, photo
  • Usage data: login logs, pages visited
03

Use of data

Your data is used exclusively to:

  • Provide and improve the WeLink service
  • Generate email signatures, profile pages, QR codes and VCF cards
  • Communicate with you regarding your account
  • Ensure the security and proper functioning of the platform
05

Hosting and security

Core data is hosted on Supabase servers in the EU/Swiss region. Data is encrypted at rest and in transit (TLS 1.3). Some processors (Stripe, Vercel, Postmark) are based in the USA; such transfers are covered by appropriate safeguards — EU Standard Contractual Clauses (SCCs) or applicable adequacy decisions.

06

Sub-processors and third parties

We share your data with the following processors: Supabase (database and file storage; EU/Swiss region), Stripe (payment processing; USA, under Standard Contractual Clauses), Vercel (hosting and edge delivery; USA, under SCCs), Sentry (error monitoring; Germany — EU residency), PostHog (product analytics; EU region), Postmark (transactional email; USA, under SCCs), Upstash (rate-limiting cache; EU region), Microsoft (Microsoft 365 integration; when enabled by your organisation), Google (Google Workspace integration; when enabled by your organisation), Shlink (URL shortening; self-hosted).

07

Microsoft 365 integration & Outlook add-in

When your organisation connects Microsoft 365, WeLink accesses only what is needed to manage and deploy your email signatures:

  • Directory data — names, email addresses and departments of your team members (Microsoft Graph: User.Read.All, Directory.Read.All), used to map signatures to the right people.
  • Signature deployment — for server-side modes, signatures are written through Microsoft Exchange (Set-MailboxMessageConfiguration or a transport rule). This requires your administrator to grant WeLink the Exchange Administrator role, which can be revoked at any time.
  • Outlook add-in — when used, the add-in inserts the chosen signature into the message you are composing, entirely on your device at compose time.
  • No access to the content of your emails — WeLink never reads, stores or processes the body of your messages.

Sub-processors for this integration are Microsoft (Graph and Exchange APIs) and our core hosting provider. You can disconnect Microsoft 365 at any time from the WeLink dashboard, which revokes WeLink's access.

08

Data retention

Account data is retained for the duration of your subscription plus 30 days after deletion. Audit logs are retained for 12 months. Error and performance monitoring data at Sentry is retained for 90 days. Analytics data at PostHog is retained for 12 months. Billing records at Stripe are retained as required by applicable financial regulations.

09

Your rights

In accordance with GDPR and Swiss nDSG, you have the following rights:

  • Right of access to your personal data
  • Right to rectification of inaccurate data
  • Right to erasure of your data
  • Right to data portability
  • Right to object to processing
10

Cookies

We use strictly necessary session/authentication cookies and, with your consent, analytics cookies (PostHog) and error-monitoring data (Sentry).

12

Contact

For any questions regarding your personal data, contact us at:

privacy@wecode.swiss