Privacy Policy
This policy describes how WebHealth handles personal information. See also our Terms of Service and Security pages.
Introduction
WebHealth ("we", "us", or "our") operates the WebHealth Digital Health Platform at webhealth.pro and app.webhealth.pro. This Privacy Policy explains how we collect, use, disclose, and protect personal information when you visit our marketing website, use our free public health check, create an account, or use our paid services.
By using WebHealth, you agree to the collection and use of information in accordance with this policy. If you do not agree, please do not use our services.
Information we collect
We collect information you provide directly, information generated through your use of the service, and limited technical information from our marketing site.
- Account information: name, email address, organization name, and password (stored hashed).
- Billing information: processed by Paddle, our payment processor. We receive subscription status, plan identifiers, and transaction references — not full card numbers.
- Monitored assets: domains, URLs, and configuration you connect for monitoring.
- Public health check submissions: domain or URL you enter on webhealth.pro/check, check results, and timestamps. Results expire after seven days.
- Advisor queries: questions you ask the public Help Advisor or authenticated in-app Advisor.
- Communications: support messages and email delivery metadata via Brevo.
- Usage and analytics: optional privacy-focused analytics on our marketing site (Plausible) when enabled — no cross-site tracking cookies by default.
- Technical data: IP address, browser type, device information, and server logs for security, rate limiting, and abuse prevention.
How we use your information
- Provide, operate, and improve the WebHealth platform and public health check.
- Authenticate users, enforce entitlements, and maintain tenant isolation.
- Process subscriptions, trials, and billing through Paddle.
- Send transactional email (account verification, morning health reports, service notifications) via Brevo.
- Respond to Advisor questions using AI providers, grounded in your data and our knowledge base where applicable.
- Detect, prevent, and address fraud, abuse, and security incidents.
- Comply with legal obligations and enforce our Terms of Service.
Legal bases (EEA/UK)
Where GDPR applies, we process personal data on the following bases: contract performance (providing the service you signed up for), legitimate interests (security, fraud prevention, product improvement), consent (where required for optional communications), and legal obligation.
Free public health check
The free public audit at webhealth.pro/check runs limited, non-invasive checks against domains you submit. We rate-limit submissions (three audits per IP per day; one re-audit per domain per 24 hours). Results are stored temporarily (seven days) and presented without collecting personal information beyond the domain and technical findings. Share links expose only a redacted, public-safe view — never internal evidence or customer PII.
Data retention
- Account and monitoring data: retained while your account is active and for a reasonable period after closure to meet legal and backup obligations.
- Public audit results: seven days, then deleted or anonymized.
- Server logs and security audit trails: retained per our security operations schedule, typically 90–365 days unless longer retention is required for an investigation.
- Billing records: retained as required by tax and accounting law.
Security
We implement technical and organizational measures including tenant isolation at the application layer, encrypted sessions, CSRF protection on mutating requests, rate limiting, and security monitoring. No method of transmission or storage is 100% secure; we cannot guarantee absolute security.
For more detail, see our Security page.
Your rights
Depending on your location, you may have rights to access, correct, delete, restrict, or port your personal data, and to object to or withdraw consent for certain processing. California residents may have additional rights under the CCPA.
To exercise your rights, contact us at the email below. We will respond within the timeframe required by applicable law. You may also lodge a complaint with your local data protection authority.
International transfers
WebHealth may process data in the European Union and through subprocessors that operate globally. Where data is transferred outside your jurisdiction, we rely on appropriate safeguards such as Standard Contractual Clauses where required.
Children
WebHealth is a business service not directed at children under 16. We do not knowingly collect personal information from children.
Changes to this policy
We may update this Privacy Policy from time to time. We will post the revised policy on this page and update the effective date. Material changes will be communicated through the application or email where appropriate.
Contact us
Privacy questions: privacy@webhealth.pro
General support: use the Help Advisor at webhealth.pro/help or sign in to the application.