Privacy Policy
Last updated: 23 July 2026
This policy explains how personal data is processed when you use wrkfrcstdio (the "Service"). Controller within the meaning of the GDPR: [company legal name, address, contact email].
1. Data we process
- Account data — your email address and authentication events (sign-in, magic links, password resets).
- Workspace data — organisational and job-architecture content your organisation uploads or creates in the Service (which may include employee-related data your organisation controls).
- Usage and log data — technical logs (IP address, timestamps, actions) needed to operate and secure the Service.
2. Purposes and legal bases
- Providing the Service and authenticating users — Art. 6(1)(b) GDPR (contract) and, for workspace data processed on behalf of your organisation, Art. 28 GDPR (processing on the controller's instructions).
- Security, abuse prevention, and service improvement — Art. 6(1)(f) GDPR (legitimate interests).
- Compliance with legal obligations — Art. 6(1)(c) GDPR.
3. Processors and sub-processors
We use vetted service providers under data-processing agreements, currently including:
- Supabase (authentication and database hosting)
- Render (application hosting)
- OpenAI and Anthropic (large-language-model features; content submitted to assisted features is processed to generate the requested output)
Where providers process data outside the EU/EEA, transfers rely on appropriate safeguards such as EU Standard Contractual Clauses.
4. Cookies
The Service uses only cookies that are strictly necessary for authentication and session management. No advertising or third-party tracking cookies are set.
5. Retention
Account and workspace data are retained for as long as the customer relationship exists or as instructed by your organisation, then deleted or anonymised unless statutory retention periods apply. Security logs are kept for a limited period appropriate to their purpose.
6. Your rights
Under the GDPR you have the right to access, rectification, erasure, restriction of processing, data portability, and to object to processing based on legitimate interests. You may also lodge a complaint with a supervisory authority. Where wrkfrcstdio processes workspace data on behalf of your organisation, please direct requests to your organisation, which controls that data.
7. Security
We apply appropriate technical and organisational measures, including encrypted transport, tenant isolation, and access controls. No method of transmission or storage is completely secure; we continuously review and improve our safeguards.
8. Changes and contact
We will update this policy when our processing changes and announce material updates through the Service. Privacy questions: [contact email]. See also our Terms of Service.