Skip to main content
Wellspring Worldwide logo

Wellspring Worldwide

GDPR evidence

GDPR mark, CertReports state No public evidenceNo public evidence

Wellspring Worldwide and GDPR

CertReports found no public GDPR evidence for Wellspring Worldwide as of unknown date. This does not mean the vendor is non-compliant. It means CertReports found no public evidence at the last check.

Evidence

VerifiedActive: EU-US Certification, SW-US Certification, UK Extension Certification
as of 17 Sep 2026 · confidence 100%
Kind
listing
Issued or listed
5 Oct 2018
Expires or valid through
20 May 2027
Scope
Purpose of data processing: Wellspring processes data submitted by clients, who are the Controllers, for the purpose of providing our online services in accordance with the contracts we have with such customers. In accordance with contracts with have with clients all data would typically be located in the region of the primary location of the client. While Wellspring is the provider of these tools and assists clients to process data, clients remain Controllers of the data they store with us and are solely responsible for managing it. Client responsibilities include deciding what Data Subject Personal Data will be stored, how the information will be used, how the information will be categorized, to whom information will be disclosed, and for what purposes. Wellspring staff will, from time to time, and within the scope of our services and as requested by customers, access or transfer client data. Such access or transfer of client data may include Personal Data associated with the Data Subjects of our clients to potentially update or correct records, provide reports, or help solve technical or service problems. Wellspring does control and store limited Personal Data about our software system end users, such as emails and requests for help through contact with our organization. We also collect data on user activities within our products to enhance system performance. Accountability for Onward Transfer and Third-Party Agents: Third parties may receive Personal Data in cases when Wellspring has subcontracted with specific individuals or parties to provide services for our clients. In such cases all consultants, contractors, or other parties are required to have confidential agreements in place along with procedures for training those personal on Wellspring specific policies for handling client data and Data Subject rights. Controllers would be notified about any third parties involved in providing services and the Personal Data would only be provided for the purpose of providing contractually obligated services for the Controller. We do not provide personal data to third parties for any other purposes other than those the Controller has defined and they would be acting as agents of Wellspring. Wellspring uses a limited number of third-party vendors and hosting partners to provide the necessary hardware, software, networking, storage, and related technology required to provide clients access to software and services. All vendors are reviewed and evaluated for appropriate security and data handling procedures to ensure highly restricted access and compliance with our Data Privacy Framework obligations for any personal data. The storage of Personal Data on servers and/or on software made available or hosted by third party vendors shall not be considered disclosures of any Personal Data so long as the vendor does not have direct access to the Personal Data stored or hosted. Wellspring is potentially liable should any issues or concerns arise with the Data Subject information provided to these services.
SourceCapturedQuoteLinks
Data Privacy Framework list
Official registry · HTTP 200
17 Sep 2026Wellspring Worldwide, Incorporated: Active: EU-US Certification, SW-US Certification, UK Extension Certification
Live pagesha256 1ee12284ee
What GDPR means, and what it does not

"GDPR compliant" is a claim, not a certification. The verifiable facts are a public DPA, SCC usage, an EU representative, data residency options and a Data Privacy Framework listing.

Read the GDPR guide and browse all vendors with evidence

Questions buyers ask

Is Wellspring Worldwide GDPR compliant?

There is no GDPR certification in general use. The verifiable facts are a public data processing agreement, standard contractual clauses, an EU representative and a Data Privacy Framework listing. See the legal artefacts and the DPF row on this page, each with its capture date.

How does CertReports verify this?

Every state carries a capture date, a source and a snapshot link. Registry rows come from the official registry data; vendor statements come from the vendor’s own page or trust centre; nothing is inferred. Vendors can dispute any row and corrections ship within two business days.

Alternatives with GDPR evidence

Similar vendors (shared product tags or the Life sciences and biotech category) whose GDPR row is verified or vendor-stated, ranked by similarity.

No Life sciences and biotech vendor has GDPR evidence in the index yet.