Legal
Privacy Policy
What we collect, why, where it lives, and how to get it removed. Short version: we only collect what we need, we don't sell it, and our website analytics are deliberately limited.
Last updated 25 September 2026.
1. Who is responsible for your data
Wellstreak, operated by Koenig Consulting AB (Swedish company, reg. no. 559116-2267), is the data controller for the personal data described here.
2. What we collect
We collect limited public-site usage data and what you choose to send us through our forms.
When you visit our public website, and only where analytics is allowed (see section 9), we collect page-view and interaction information such as the page path, referrer, clicks, browser and device type, approximate country, and a session recording with every input and all text masked. We do not run analytics inside the migration portal.
When you apply, that’s: your name, work email, company name, country, an optional website, details about your Odoo setup (number of users, version, hosting type), and the free-text you write about your backlog and what you’d like improved.
When you join the waitlist, that’s: your email, and optionally your company name and a short note. For the migration source waitlist, we also collect the source system you select and any comment you choose to add.
When you ask to hear about your market, from inside the migration portal when your company’s country isn’t supported yet, that’s: your email, the country and base currency from your source system’s company card, and any comment you add.
When you tell us about another system, the one you want to move from, that’s: the system you name, your work email, and optionally your company name, a note and the export files you choose to send (such as SIE files, or zip, CSV, PDF or Excel exports). Those files can contain your bookkeeping, including names and details of your customers and suppliers, so send only what you are allowed to share.
During a migration. We process the source-system and Odoo accounting data needed for the agreed project. That can include contact and business-register data about customers and suppliers, invoices, payments, ledger entries, the content of PDFs used as source documents, and files attached to source documents, which are read to be listed and fingerprinted.
We don’t ask for special categories of data, and we’d ask you not to include sensitive personal information in free-text fields.
3. Why we use it
To review your application, get back to you, and — if we work together — to deliver and run the service. Migration-waitlist details are used to contact you about that service and source systems we add, and market requests to tell you when we can migrate companies in your market; requests about another system, and the files sent with them, are used to see what moving from that system takes, to build for it and to write back to you. For each of these we also send a notification to our founder so we can respond — for another system it names the files and their sizes, never their contents. That’s it; we don’t use your information for unrelated marketing.
For applications, waitlists and the commercial relationship, our legal basis is taking steps at your request before entering into a contract, and performing that contract where we have one. For data inside a migration, you are the controller: you determine the lawful basis and we process it only on your documented instructions under our Data Processing Agreement.
4. Where it's stored
Your submissions, the files you send about another system (encrypted), encrypted migration sessions and migration payment journal are stored in a managed PostgreSQL database provided by Supabase, which we use as our data processor. The database is hosted in the EU (AWS eu-north-1, Stockholm, Sweden). Supabase processes the data on our behalf under its own security and data-processing terms. We use Resend to send application and waitlist confirmations, access-recovery emails and founder notifications, including payment alerts; it processes the details needed to send those emails.
The website and the migration portal run on Cloudflare Workers. In a migration, your credentials and the source and Odoo data being worked on pass through Cloudflare’s servers in memory while each request runs, and Worker logs are switched on for troubleshooting. Requests are handled on Cloudflare’s global network, which is not limited to the EU.
We use PostHog’s EU Cloud for limited website analytics. PostHog receives public-site page-view and masked interaction data only; it does not receive form contents or migration-portal activity.
Migration payments are handled by Stripe. If you choose Klarna in Stripe Checkout, Klarna also processes the payment. They receive the billing and payment details needed to complete the transaction. We do not receive your card details. Our own payment journal stores the payment reference, amount, currency, status, time, run reference and customer email so we can reconcile payments and handle refunds or disputes.
5. Data inside your Odoo and migration
For personal data in your Odoo or source system, including migration data, you are the data controller and we act as your processor, on your instructions, under our Data Processing Agreement. That agreement also lists our sub-processors, and our Security and access page describes how we handle access and changes.
Your Business Central credentials and the Odoo logins and API keys you give for the rehearsal and production databases are kept encrypted in the migration session and never logged or shown again. The session, including those credentials, is kept for 30 days after the last activity. PDF text is extracted in memory to make a proposal; neither the PDF nor its text is retained by the portal. Odoo’s own migration log notes remain in your Odoo.
The payment journal is separate from the 30-day migration session. We keep payment records for accounting, tax, fraud-prevention and dispute-handling purposes, normally for seven years after the end of the financial year they relate to where Swedish bookkeeping rules apply.
6. We don't sell your data
We never sell your personal data and we don’t share it with third parties for their own marketing. We share it only with service providers who help us run Wellstreak (such as our hosting and database providers, and our email provider for sending you confirmations), and only as needed to provide the service — or where the law requires it.
7. How long we keep it
We keep application and general waitlist data only as long as needed to evaluate your application, run the service and keep proper business records, then delete or anonymise it. We keep migration-waitlist details until you ask us to delete them, or for 24 months from your signup, whichever comes first. We keep market requests until you ask us to delete them. A request about another system, and every file sent with it, is deleted automatically 90 days after you send it. You can ask us to remove any of this data sooner (see below).
The migration session, including the credentials it holds, is deleted after 30 days without activity. We do not retain PDF content in the portal. Migration records and permanent notes on your company record remain in your Odoo under your control; other extracts are deleted when the work is done, and no later than 30 days after access ends unless law requires retention.
8. Your rights
You can ask us for a copy of the personal data we hold about you, ask us to correct it, or ask us to delete it. Just reach out via the contact page and we’ll take care of it. Depending on where you live, you may also have the right to object to or restrict certain processing, and to lodge a complaint with your local data protection authority.
9. Cookies and tracking
The only cookie we set outside the migration portal remembers your analytics choice (see below); it isn’t an advertising or tracking cookie and nothing is set until you make that choice or it’s made for you as described here.
Whether PostHog runs at all, and how, depends on where you’re visiting from:
- EU/EEA, UK, Switzerland and Canada — PostHog doesn’t load until you accept it in the banner or the analytics preferences control (available on every public page). You can withdraw consent there at any time.
- United States — PostHog loads automatically for first-party analytics, no banner, unless your browser sends Global Privacy Control or Do Not Track, in which case it doesn’t load. You can also turn it off manually from the analytics preferences control.
- Anywhere else, or if we can’t tell — treated the same as the EU/EEA: consent-required, off by default.
Wherever you are, if your browser sends Global Privacy Control or Do Not Track, PostHog doesn’t load — even if you accepted analytics earlier — and it can’t be turned on while that setting is active. Turning analytics off stops it immediately on the page you’re on, including any session recording.
When it does run, we never sell or share the data for advertising, there are no targeted-ad profiles, and person profiles stay off. It counts page views and interface interactions on the public site with every input field and all text masked in any session recording, no request headers, request bodies or console logs recorded, and query strings and URL fragments removed before an event or network request is sent. The migration portal is always excluded from analytics — before the page loads and after any in-app navigation into it.
10. Changes to this policy
As Wellstreak grows we may update this policy. When we make a meaningful change we’ll update the date at the top; significant changes will be communicated to active customers.
11. Contact
Questions about your privacy, or want to exercise a right above? Reach us via the contact page. Data controller: Koenig Consulting AB, reg. no. 559116-2267, Sweden.