Data Protection: EEA / UK Supplement
Effective date: June 5, 2026
Last updated: June 5, 2026
Canonical URL: /dataprotection/
Entity: We’ll Do It LLC, 2321 E. University Dr., Phoenix, AZ 85034, United States.
This page supplements our Privacy Policy with information specific to GDPR, UK GDPR, and the Payment Card Industry Data Security Standard (PCI DSS). Where this page and the Privacy Policy differ, the Privacy Policy controls.
1. GDPR and UK GDPR
We’ll Do It LLC (“WDI”) is a data controller for personal data we collect through welldoit.solutions and the Monocle SaaS where included in your plan. For processing performed on behalf of clients under a service agreement, we act as a data processor under that client’s instructions.
1.1 Legal reasons we use your information
We rely on the legal reasons described in Privacy Policy § 2: contract, legal obligation, legitimate interests (balanced against your rights), and consent.
1.2 Your rights
EEA and UK data subjects have the rights described in Privacy Policy § 8, including the rights to access, rectification, erasure, restriction, objection, portability, and withdrawal of consent.
1.3 EEA and UK contact
If you are in the EEA or the UK, you may contact We’ll Do It LLC directly at specialist@welldoit.solutions or by mail at the address above.
1.4 Right to lodge a complaint
- UK users may complain to the Information Commissioner’s Office (ICO) at https://ico.org.uk/make-a-complaint/.
- EEA users may complain to their local data protection authority. The full list is at https://edpb.europa.eu/about-edpb/about-edpb/members_en.
1.5 International transfers
For personal data transferred from the EEA or UK to the United States, we rely on:
- (a) the EU US Data Privacy Framework adequacy decision and its UK Extension where the recipient is actively self-certified to the Framework; or
- (b) the EU Standard Contractual Clauses and the UK International Data Transfer Addendum, supplemented by a transfer-risk assessment, where no adequacy mechanism applies.
See Privacy Policy § 7.
2. California (CCPA and CPRA)
See Privacy Policy § 9. Our honor of Global Privacy Control, the Your Privacy Choices footer link, and the verification and authorized-agent procedures described there apply.
3. Payment card data (PCI DSS)
We do not store, process, or transmit full payment card numbers on our own systems. Card data is collected directly by our payment processors (Intuit QuickBooks Payments, and Stripe when active) using their hosted payment forms and iframes. Those processors handle card processing under their own PCI DSS attestations. We complete and retain the appropriate Self-Assessment Questionnaire (SAQ A) with our acquirer, as required by PCI DSS.
This is a scope statement. It is not an assertion of independent PCI DSS certification beyond the SAQ scope appropriate to our merchant configuration.
4. Security
We protect personal data using a layered set of technical and organizational measures, including encryption in transit, access controls and strong authentication, vendor due diligence, edge protection (CDN and web application firewall), and application hardening, patching, and monitoring.
We do not publish the specific tools or vendors that make up our security stack, because doing so would help attackers. We are happy to share our security overview under a non-disclosure agreement with enterprise clients on request.
For delegated credentials clients provide to us, see Privacy Policy § 3 (Delegated access data).
5. Contact
Privacy inquiries and rights requests: specialist@welldoit.solutions
General: mgmt@welldoit.solutions
Phone: 480-631-4324
We’ll Do It LLC, 2321 E. University Dr., Phoenix, AZ 85034, United States.
© We’ll Do It LLC · Privacy Policy · Terms & Conditions · DMCA