מידע משפטי

Privacy Policy

עודכן 27 ביולי 2026

1. Our Commitment To Privacy

This Privacy Policy explains how Expimetrics, Inc. d/b/a ExpiWell ("ExpiWell") collects, uses and safeguards the information you provide, and assists you in making informed decisions when using the Services. This Privacy Policy applies to the ExpiWell Survey Maker Terms of Service and the ExpiWell Survey Taker Terms of Service and all Services. Certain terms in this Privacy Policy may be applicable only to Makers or to Takers if specifically noted. Capitalized terms not defined herein shall have the meanings stated in the Terms of Service. For specific information about GDPR, please visit Expiwell's GDPR.

2. Data Controller and Processor

Because ExpiWell both gathers and facilitates the gathering and control of user data by Makers (who may also be referred to as "Customers"), ExpiWell shares the responsibility of proper data control with Customers. This shared control may be described in this Privacy Policy, and additional information on the shared responsibility of data protection while using ExpiWell is available at Expiwell's GDPR. To contact the ExpiWell data processor, please contact us at privacy@expiwell.com.

3. Age Requirement

You must be at least 13 years of age to use, access, or register an Account with the Services or to submit personally identifying information to ExpiWell via any website, application, or other platform owned or operated by ExpiWell ("Websites").

The Websites are not intended for children. If you are a parent or guardian and believe your child has used the Services, you may contact ExpiWell at privacy@expiwell.com. If we obtain actual knowledge that a user is under the age of 13, we will take reasonable steps to remove that user's Active Information and Passive Information (both defined below) from ExpiWell's databases. By using the ExpiWell Services, you are representing that you are at least 13 years old.

4. What Information Do We Collect?

We may collect two types of information from all users: (1) "Active Information", which is personally identifiable information and is only collected when you disclose it, or when you authorize us to obtain it from a third party, unless otherwise specified herein, and (2) "Passive Information", which is information collected in a way not visible to you and on an aggregate, anonymous, and/or de-identified basis as users use the Services and browse our Websites.

5. Active Information

By voluntarily registering an Account with ExpiWell, you may choose to or be required to submit your name, email address, zip code, phone number, billing or payment information, and other personally identifiable information from time to time.

If you are a Taker participating in surveys or other forms of market research ("Surveys"):

  • You may choose to submit personally identifiable information in your Survey responses, which for example may include (but may not be limited to) your opinions, information about your education, job, earnings, race, gender, ethnicity, religion, sexual orientation, your signature, photographs or videos of you, your voice, your gestures, your distinctive appearances, your mannerisms, or other personal identifying information. If you allow ExpiWell to access information from a third-party on your behalf, various types of Active Information may be obtained from such third party, and you consent to ExpiWell obtaining such information and treating it as Active Information for all purposes hereunder.
  • Certain Surveys may request or require that you enable certain tracking features on your device, including enabling either ExpiWell or the Maker of the Survey to access your global position system (GPS) data. By providing your consent to such to tracking feature(s), you agree to provide such data. You can revoke this consent at any time by submitting a request through your Account or by contacting privacy@expiwell.com, but please note that revoking such consent may disable your ability to continue participating in certain Surveys.
  • Survey response data, including all Active Information that you provide through Surveys or which you authorize us to obtain from one or more third parties as part of a Survey, is provided to the Maker of such Survey in each case, and the Maker controls such data as more fully provided below. Once data is disclosed to a Maker, Expiwell does not and cannot control all uses of such Survey response data.

If you are a Maker, then by creating and administering Surveys, you may choose to submit questions or tasks, some of which may include sensitive information about you or the business on whose behalf you are creating the Survey. You may also choose to submit email addresses and other contact information for potential Takers you desire to invite to complete surveys. If you provide such contact information for potential Takers, you represent and warrant that you have the right to provide the same to ExpiWell. You acknowledge that we may offer any potential Taker the right to opt-out of any Survey or of receiving information or requests through the ExpiWell system more generally.

6. Who controls my information?

If you have provided Survey responses, the Maker is the controller of that data, and ExpiWell is the processor or service provider related to such data. ExpiWell only accesses your Survey responses as necessary to act as a service provider to Makers. ExpiWell may not access or have access to all of your Survey responses.

ExpiWell is the controller of all data that is provided to ExpiWell by Takers and Makers when setting up an Account or as otherwise provided directly to ExpiWell (other than through Survey responses).

Makers may provide privacy statements regarding how the Maker will use data provided through Survey responses. Please review these carefully along with any links that Makers provide to their own privacy policies. It is the responsibility of every Taker to contact the Maker of a Survey if you have questions regarding how your Survey response data will be used by the Maker, including any personally identifiable information included therein. You are never required to complete a Survey if you do not desire to provide the information requested. If you believe that your Survey response data has been improperly used, you may report the same to Expiwell, provided that ExpiWell may take or refrain from taking any action we deem appropriate.

7. How Information Is Used

ExpiWell may use your Active Information and/or Passive Information as we deem it necessary or appropriate to further our legitimate interests, including to operate our Websites and to tailor, promote and provide existing and new services and products, and to analyze and improve the functionality, safety, and security of our Websites and services. By using ExpiWell's services, all users are giving consent to ExpiWell to use your Active Information and Passive Information in the manners noted above, as well as for the following purposes:

  • To communicate with you, or respond to your inquiries about the Services, related third party products, or your Account via mail, email, text messages, telephone call, or other communications channels;
  • To deliver, administer, and enhance the Services and any other ExpiWell product or service that you use or we may develop in the future;
  • To deliver, administer, and enhance the Services and any other ExpiWell product or service that you use or we may develop in the future;
  • To provide Takers with survey questions and market research tasks;
  • To send you information, updates, or offers about the Services; and
  • In the event that you have submitted fraudulent or otherwise invalid information to us, to report, disclose, or correct such information.

Further, you grant permission to ExpiWell and its licensors to use, reproduce, copy, and publish your Passive Information for any lawful purposes, including to unaffiliated third parties for marketing and selling their products and services. When ExpiWell uses third-party advertising companies to serve ads to you via the Services and Websites, these companies may use information (not including any personally-identifying information) about your visits to the Websites and other websites that are contained in cookies in order to provide advertisements about the ExpiWell Services, other ExpiWell goods and services, and the goods and services of third parties, that may be of interest to you.

ExpiWell may anonymize, de-identify, and/or aggregate any information provided to us (the "Anonymized Data"), such that the Anonymized Data is no longer capable of identifying a particular person or household. ExpiWell will be the owner of all Anonymized Data sets (including as derived from Active Information or otherwise) and may use, disclose, sell, license, or rent the same for any legal purpose deemed appropriate by ExpiWell.

8. How Information Is Disclosed

ExpiWell may disclose your Active Information and Passive Information in the following ways:

  • As detailed herein above, all information that a Taker provides through a Survey, or which a Taker authorizes us to obtain from a third party for or as part of a Survey, will be provided to the Maker of that Survey;
  • If you are a Maker who has an Account through, or has accessed the Services through, your employer or another entity you are affiliated with, we may provide information to the entity with which your Account is affiliated;
  • As required by law or if ExpiWell reasonably believes that use or disclosure is necessary to enforce this Privacy Policy or the Terms of Service, to protect our rights, and/or to comply with a law, court order, or any legal process;
  • In the event ExpiWell is sold, acquired, or merged (whether through a sale of assets, stock, or otherwise), the information will be disclosed to the acquirer or resulting entity, who may then use it to the same extent permitted herein;
  • To provide it to those third parties who provide services to ExpiWell, such as website, database, email, and server hosting, data analysis, payment processing, order fulfillment, product distribution, IT services, telecom services, credit card processing, auditing services, and other similar services; or
  • If we believe that you may harm, or have harmed, the property or rights of ExpiWell, our users, or any other third party, which includes the act of utilizing the Services or Websites to distribute unsolicited email or text messages or to make unsolicited telephone calls, or to send any emails, text message or make telephone calls in violation of any law or regulation, to report, disclose, limit, respond to, or prevent such conduct or activity.

ExpiWell will not sell your Active Information without your consent.

Notwithstanding any other provision herein, ExpiWell does not share, disclose, or transmit any Active Information or other user data to external (meaning third-party, not owned or operated by ExpiWell) artificial intelligence providers for processing, model training, or any other purpose.

9. Maker Restrictions On use Of Information

If you are a Maker, you may receive Active Information of Takers when the Takers participate in your Surveys. Each Maker agrees to the following:

  • You will provide statement regarding how you plan to use Taker information must be provided to Takers before they begin each Survey;
  • You will provide a method for a Taker to contact you, including to request information regarding the types of their data you have collected and how it has been used or shared, and you will promptly respond to these information requests;
  • You will comply with all data privacy laws applicable to you and your collection of information in the manner contemplated, including allowing Takers to opt out of further correspondence from you.

If ExpiWell is made aware or suspects that you have breached this provision of the Privacy Policy, we may immediately terminate your account and any ongoing Surveys.

You, a Maker, agree to indemnify and hold harmless ExpiWell for any breach of the above or any other alleged misuse of Survey data of which the Maker is the controller or owner as designated herein.

10. Security Of Information

ExpiWell uses reasonable organizational, technical, and administrative measures to protect your Active Information and Passive Information from unauthorized access or disclosure, or accidental loss or destruction. However, we cannot guarantee that 100% of data transmissions are secure. Therefore, while we strive to protect your information, you acknowledge that:

  • (a) there are limitations to security and privacy of the internet that are beyond our control;
  • (b) the security, integrity and privacy of the information exchanged between you and us (including through any Survey) cannot be guaranteed; and
  • (c) any information and data may be viewed or tampered with in transit by a third party.

You agree to notify ExpiWell immediately if you suspect that there has been a breach of your Account, or that your user identification and password or interaction with the Services is no longer secure. Communications you may have with ExpiWell via email or mail may not be secure unless you are advised that security measures are in place prior to your sending information. Therefore, if you choose to communicate through these means, you are assuming the risk of doing so and you should not send or post sensitive information through these means.

To the extent we rely on your consent to process any information, you may revoke that consent at any time. If you wish to revoke such consent, or if at any time you do not wish to receive the communications stated herein from ExpiWell or third-party advertising companies, you may do so by sending your request to ExpiWell at 9921 Carmel Mountain Rd. #2, San Diego, CA 92129, or by email at privacy@expiwell.com. It may take up to ten (10) days for the change to be fully effective.

Additionally, if you wish to access, delete or correct any of your information contained in Account or provided directly to ExpiWell, or to complete a user access request for personal data, please send your request to ExpiWell at 9921 Carmel Mountain Rd. #2, San Diego, CA 92129, or by email at privacy@expiwell.com.

Login to your Account to access edit functions for your profile information, as well as the ability to completely remove your account and any identifying information present in the Services. Contact ExpiWell via the contact information provided in this Section for help with this process. Notwithstanding the foregoing, we may continuously maintain any Anonymized Data.

If you wish to revoke a Maker's consent to process or use your information, or if you wish to access, delete, or correct any information, which the Maker controls as set forth herein, please reach out directly to the Maker.

ExpiWell may maintain your Active Information and Passive Information for as long as necessary to fulfill our services to you and to fulfill our contractual obligations, in addition to a reasonable amount of time thereafter, unless you request otherwise. We may retain Anonymized Data indefinitely. If you believe ExpiWell is acting in violation of your data rights you may have the right to file a complaint with your local data protection authority.

ExpiWell is not required to continue to make Survey responses available to Maker if the Maker no longer has an Account, or in any case, is not required to make Survey responses available to Maker more than one year after the Survey is responded to.

12. Residents of certain US states

In the United States, depending on your state of residence (including California), and subject to certain exceptions, you may have some or all of the following rights:

  • Right to Know: The right to request that we disclose to you the Active Information we collect, use, or disclose about you, and to access the same, as well as identifying the types of third parties with whom we have shared Active Information and the categories of Active Information we have shared.
  • Right to Request Correction: The right to request that we correct inaccurate Active Information that we maintain about you.
  • Right to Request Deletion: The right to request that we delete Active Information that we have collected from or about you. (Please note that you may not be able to maintain an Account through the Website without our retention of certain Active Information.)
  • Right to Portability: The right to obtain a copy of your Active Information that you previously provided to us in a portable and, to the extent technically feasible, readily usable format that allows you to transmit the data to another controller.
  • Right to Opt Out: The right to opt out of the processing of your Active Information for purposes of targeted advertising and profiling in furtherance of decisions that produce legal or similarly significant effects concerning you.

To submit a request to exercise your rights set forth in this section, and as applicable, to appeal a consumer rights action, you may use privacy@expiwell.com, or you may mail your request to Expimetrics, Inc. d/b/a ExpiWell, 9921 Carmel Mountain Rd. #2, San Diego, CA 92129. We may require that you verify your identity to respond to your request. If you are entitled to a substantive response, we will deliver the requested information to you within 45 days (or will inform you that an extension of such timeframe is necessary). You may make a request up to twice during a 12-month period. We will not discriminate against you for exercising your rights pursuant to applicable state laws.

Please visit or reference the policies of the Maker to submit data rights requests regarding any information controlled by Maker.

13. Do Not Track

Some browsers have incorporated 'Do Not Track' features. Most of these features, when turned on, send a signal or preference to the website or online service that a user visits, indicating that the user does not wish to be tracked. Because there is not yet a common understanding of how to interpret Do Not Track signals, the Services and Websites do not currently respond to Do Not Track signals. ExpiWell business partners and advertising networks that serve interest-based advertisements through the Services and our Websites have limited access to a small amount of information about your profile and your device, which is necessary to serve you advertisements that are tailored to your apparent interests, and it is possible that they may reuse this small amount of information on other websites or services.

14. Third Parties

Unless otherwise expressly stated, this Privacy Policy does not address, and ExpiWell is not responsible for, the privacy, information, or other practices of any third parties, including any links to third party websites or third party promotions or any privacy policies or practices of Makers. Any links to other websites not under the control of or maintained by ExpiWell are for your convenience only and are not an endorsement by ExpiWell of the third party or its products or services.

15. Data and Cookies Collection

Cross-Site Tracking

We do not sell user data to data brokers and we do not link your ExpiWell account data with third-party data sources for the purpose of building advertising profiles. We do, however, use a limited set of analytics and advertising tools to operate our website and measure the effectiveness of our marketing — these are described below and are only activated after you grant consent through our cookie banner.

Cookies

We use cookies in four categories:

  • Essential cookies (always active) — required for the site to function. Includes session authentication, CSRF protection, and the cookie that records your consent preferences.
  • Functional cookies (consent required) — remember your preferences such as language selection.
  • Analytics cookies (consent required) — help us understand how visitors use the site through Google Tag Manager and Google Analytics 4. These cookies are only loaded after you opt in.
  • Marketing cookies (consent required) — measure the effectiveness of our Google Ads campaigns. These cookies are only loaded after you opt in.

You can review and change your cookie preferences at any time through the "Manage Cookies" link in the dashboard footer. See our Cookie Policy for the full list of cookies, providers, and retention periods.

Third-Party Services and Sub-Processors

ExpiWell relies on a limited number of carefully selected service providers (sub-processors) to operate the platform. Each is bound by a Data Processing Agreement under GDPR Article 28 and processes personal data only on our documented instructions. They fall into the following categories:

  • Cloud hosting and infrastructure providers — application hosting, file storage, and email-delivery infrastructure (US regions, with EU regions for EU customers)
  • Database hosting provider — managed hosting of our primary database
  • Transactional email provider — delivery of account-verification, password-reset, and notification emails
  • Payment processor — payment processing for paid plans
  • Error-monitoring service — application error monitoring and crash reporting. Operates under GDPR Article 6(1)(f) legitimate interest for service stability and security; user identifiers are scrubbed before transmission.
  • IP-geolocation service — IP-based geolocation for login-security alerts and region detection. Receives the user's IP address only. Bound by a Data Processing Agreement with Standard Contractual Clauses under GDPR Article 6(1)(f) legitimate interest.
  • Website analytics and advertising-measurement services — loaded only after you opt in via the cookie consent banner, and honoring your consent signals
  • Push-notification service — delivery of push notifications to the mobile applications
  • Customer-support and CRM provider — customer relationship management and support ticketing

A current list of sub-processors is available on request from privacy@expiwell.com. Customers will be notified of material changes to this list in advance where required by their Data Processing Agreement.

AppTrackingTransparency (ATT) — iOS Mobile App

Where the iOS mobile application includes SDKs that fall under Apple's definition of "tracking," the application requests AppTrackingTransparency (ATT) permission and respects the user's choice. Tracking SDKs are not loaded if the user declines.

Data Sharing for Marketing or Advertising

We do not sell personal data. We do not share personal data with third parties for their own independent marketing or advertising purposes. Data shared with the sub-processors listed above is limited to what is necessary for them to deliver their service to us under contract.

Wearable Data — Google User Data (Google Health API and Fitbit)

Some Surveys invite Takers to connect a wearable device account (Google Health API, or the Fitbit Web API until its retirement) so that the Maker of that Survey can receive wearable data alongside Survey responses. Connecting a wearable account is always optional and happens only through Google's (or Fitbit's) own consent screen, where you choose what to share.

  • What we access. Read-only wearable data in three categories, and only these: activity and fitness data (such as steps, calories, distance, altitude, floors, and active zone minutes), health metrics and measurements (such as heart rate, heart-rate variability, oxygen saturation, respiratory rate, and temperature), and sleep data. We do not request write access. Beyond the basic account identity (name, email address) used to link your connection, we do not access your contacts, messages, location history, or any other Google account data.
  • How we use it. Solely to provide the wearable features of the specific Survey you enrolled in: your wearable data is made available to the Maker of that Survey in their dashboards and data exports, together with your Survey responses. We do not use wearable data for advertising, we do not sell it, and we do not use it to develop or train generalized artificial intelligence or machine-learning models.
  • How we store and protect it. Wearable data is encrypted in transit and at rest and stored in the hosting region applicable to your account (see the sub-processor list above and our GDPR page for regional hosting details).
  • Who we share it with. Only the Maker of the Survey you connected your account for, as described in this Policy. We transfer wearable data to third parties only with your consent, for security purposes, or to comply with applicable law.
  • Revoking access. You can disconnect your wearable account at any time in the ExpiWell app, from your Google Account permissions page at myaccount.google.com/permissions, or by contacting privacy@expiwell.com.

ExpiWell's use and transfer to any other application of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

16. Privacy Policy Changes

This Policy may be updated from time to time. Please review it periodically as your use of the Services or Website constitutes your agreement to this Privacy Policy as amended. Changes to the Privacy Policy will become effective when posted online, or when we provide notice to you of such changes when legally required. This Privacy Policy was last updated on July 27, 2026.

17. ExpiWell European Union (EU) and United Kingdom (UK) GDPR Representatives

ExpiWell's EU Representative Ametros Ltd, Address: Unit 3D, North Point House, North Point Business Park, New Mallow Road, Cork Ireland Tel: 0330 223 2246 Email: gdpr@ametrosgroup.com

ExpiWell's UK Representative Ametros Group Ltd Address: Lakeside Offices Thorn Business park Hereford England HR2 6JT Tel: 0330 223 2246 Email: gdpr@ametrosgroup.com

18. Information for EU, UK, and Swiss Users (GDPR)

This section applies to users in the European Economic Area (EEA), the United Kingdom, and Switzerland. Where this section conflicts with any other section of this Privacy Policy, this section controls for those users.

18.1 Data Controller

Expimetrics, Inc. d/b/a ExpiWell (9921 Carmel Mountain Rd. #2, San Diego, CA 92129, USA) is the data controller for personal data collected through our marketing website and the personal data we collect to manage your ExpiWell account (account data). For survey response data collected by Customers (Makers) through their use of the platform, ExpiWell acts as a data processor on the Customer's behalf and the Customer is the data controller.

For all GDPR-related questions, requests, or complaints, please contact our privacy team at privacy@expiwell.com. EU and UK users may also contact our local representatives listed in Section 17.

18.2 Legal Basis for Processing (GDPR Article 6)

Under GDPR, we must have a valid legal basis for every processing activity. The table below describes the legal basis we rely on for each category of processing:

  • Account creation and service delivery — Legal basis: Contract (Article 6(1)(b)). We process your name, email, password hash, and account preferences to create and maintain your account, deliver the service, process payments, and provide customer support.
  • Authentication, security, and fraud prevention — Legal basis: Legitimate Interest (Article 6(1)(f)). We process IP addresses, session tokens, login history, and audit logs to authenticate users, detect unauthorized access, and protect the service. Our legitimate interest is the security and stability of the platform; this is balanced against your right to privacy by minimizing data collection and pseudonymizing IP addresses after 30 days.
  • Error monitoring — Legal basis: Legitimate Interest (Article 6(1)(f)). We use an error-monitoring service to capture application errors and crashes so we can fix bugs. Personal identifiers are scrubbed before transmission to the service. You may object to this processing under Article 21 by contacting privacy@expiwell.com.
  • Analytics and marketing cookies — Legal basis: Consent (Article 6(1)(a)). We only set Google Analytics and Google Ads cookies after you explicitly opt in via our cookie consent banner. You can withdraw consent at any time through the "Manage Cookies" link.
  • Marketing emails (newsletters) — Legal basis: Consent (Article 6(1)(a)). We only send marketing emails to users who have opted in. You can unsubscribe at any time using the link in any marketing email.
  • Survey response data — Legal basis: Determined by the Customer (Maker) as data controller. ExpiWell processes this data only as instructed by the Customer under our Data Processing Agreement.
  • Legal compliance — Legal basis: Legal Obligation (Article 6(1)(c)). We retain certain records (financial transactions, audit logs) for the periods required by tax, accounting, and security compliance laws.

18.3 Special Category Data (Article 9)

If a Customer uses ExpiWell to collect special category data (as defined in Article 9 — including health, racial or ethnic origin, political opinions, religious beliefs, sexual orientation, or biometric data), the Customer is responsible for obtaining explicit consent from participants under Article 9(2)(a) or relying on another applicable lawful basis. ExpiWell processes such data only as instructed by the Customer.

18.4 Your Rights as a Data Subject

Under GDPR, you have the following rights regarding your personal data. To exercise any of these rights, contact us at privacy@expiwell.com. We will respond within 30 days as required by Article 12(3). In complex cases, we may extend this period by up to two additional months and will notify you of the extension within the initial 30 days.

  • Right of access (Article 15) — You can request a copy of all personal data we hold about you. Logged-in users can also self-serve a complete data export at any time via the Data Subject Access Request (DSAR) endpoint in your account settings.
  • Right to rectification (Article 16) — You can request that we correct any inaccurate personal data we hold about you. Most account data can be edited directly in your profile settings.
  • Right to erasure / right to be forgotten (Article 17) — You can request that we delete your personal data. We will delete your account, associated data, and uploaded files, subject to legal retention requirements (e.g., financial records). Audit logs are retained for 6 years for HIPAA and security compliance.
  • Right to restriction of processing (Article 18) — You can request that we limit how we use your data while a dispute or correction request is being resolved.
  • Right to data portability (Article 20) — You can request your data in a structured, commonly used, machine-readable format (JSON). The DSAR endpoint provides this format.
  • Right to object (Article 21) — You can object to processing based on legitimate interest, including direct marketing and certain analytics. We will stop the processing unless we have compelling legitimate grounds that override your interests.
  • Rights related to automated decision-making (Article 22) — ExpiWell does not make automated decisions that produce legal effects or significantly affect users. If we introduce such processing in the future, we will notify you and obtain explicit consent where required.
  • Right to withdraw consent (Article 7(3)) — Where processing is based on consent, you can withdraw it at any time. Withdrawal does not affect the lawfulness of processing before the withdrawal.
  • Right to lodge a complaint (Article 77) — You have the right to file a complaint with your local data protection supervisory authority. A list of authorities is available at edpb.europa.eu/about-edpb/about-edpb/members_en.

18.5 International Data Transfers (Articles 44–49)

ExpiWell is headquartered in the United States, and many of our sub-processors operate in the United States. When we transfer personal data of EU, UK, or Swiss users to the United States or other countries outside the EEA, we rely on the following safeguards:

  • Standard Contractual Clauses (SCCs) — We have executed the European Commission's 2021 SCCs with all relevant sub-processors. These clauses bind the recipient to GDPR-equivalent protections.
  • EU-US Data Privacy Framework — Where applicable sub-processors are certified under the EU-US Data Privacy Framework, we rely on this adequacy decision in addition to SCCs.
  • UK Addendum and Swiss Addendum — We have signed the UK Addendum to the SCCs and the Swiss Addendum to cover transfers from those jurisdictions.
  • EU Region Hosting — For EU customers, ExpiWell offers EU-region hosting so that personal data remains within the EEA.

A copy of our Standard Contractual Clauses is available on request from privacy@expiwell.com.

18.6 Data Retention

We retain personal data only for as long as necessary for the purposes for which it was collected. Specific retention periods:

  • Account data — retained while your account is active and for 30 days after deletion to allow for account recovery
  • Login history — 90 days, then automatically deleted
  • IP addresses — 30 days in full form, then pseudonymized via SHA-256 hash with secret salt
  • Audit logs — 6 years (HIPAA / SOC 2 requirement), tamper-evident with hash-chain integrity
  • Consent records — 6 years (matching audit log retention) to demonstrate compliance with Article 7(1)
  • Trash (soft-deleted projects) — 30 days, then permanently deleted via daily cron
  • Financial records — 7 years (tax compliance)
  • Survey response data — Retained per the Customer's instructions in their Data Processing Agreement; ExpiWell does not retain this data after Customer deletion

18.7 Data Protection Officer (DPO)

ExpiWell has appointed a privacy contact for GDPR matters reachable at privacy@expiwell.com. ExpiWell does not currently meet the criteria requiring a formal Data Protection Officer under Article 37(1) (we are not a public authority, our core activities do not require large-scale systematic monitoring, and we do not process special category data on a large scale as a controller). However, we voluntarily maintain dedicated privacy contacts and EU/UK representatives (see Section 17).

18.8 Data Breach Notification (Articles 33–34)

In the event of a personal data breach that is likely to result in a risk to the rights and freedoms of individuals, ExpiWell will notify the relevant supervisory authority within 72 hours of becoming aware of the breach, as required by Article 33. Where the breach is likely to result in a high risk to individuals, we will also notify affected users without undue delay as required by Article 34. Notifications will include the nature of the breach, categories and approximate number of users affected, likely consequences, and the measures we have taken or propose to take.