Last updated —
Privacy Policy
What we do with personal data — ours to answer for on this website, and the customer’s to answer for inside a workspace.
1 Two different roles
On this website and in our dealings with prospective customers, we are the controller: we decide what to collect and why, and this policy explains it.
Inside a customer’s workspace, we are the processor. The customer decides what goes in and how long it stays; we act on their instructions. If you are someone’s employee or contractor and you want your data corrected or removed, ask them — we will forward your request, but we cannot act on it alone.
2 What this website collects
If you write to us, we keep your name, your address and what you wrote, so we can reply and remember the conversation.
Our servers log the request: an IP address, a browser identifier, a timestamp and the page. We use it to keep the site up and to spot abuse.
We set only the cookies the site needs to work — a session cookie and a cross-site request forgery token. There is no analytics, no advertising network and no third-party embed on this site, so there is nothing here to opt out of.
3 Why we are allowed to
- To answer you and to take steps toward a contract you asked for.
- Our legitimate interest in running, securing and improving the site, weighed against your interests.
- Legal obligations we are subject to, such as keeping accounting records.
4 What a workspace holds
A customer’s installation typically holds, about their staff and contractors: identity and contact details, contract and payment details, hours and tasks, signed documents, absences, and probation, grade and review records.
Each customer runs on their own database. One customer’s data is not mixed with another’s, and there is no shared table to leak across.
5 Who else sees it
Our hosting and infrastructure providers, and the payout, accounting and communication services a customer chooses to connect. Each is bound by a written agreement, and we name them all in the data processing agreement.
We will tell customers before adding a new subprocessor, so there is time to object.
We do not sell personal data, and we do not share it for advertising.
6 Where it lives, and how long
Hosting region is agreed with each customer. Where data leaves the European Economic Area, it moves under Standard Contractual Clauses or an adequacy decision.
Enquiries are kept for twenty-four months after the last contact. Server logs are kept for ninety days. Workspace data is kept as long as the customer’s contract runs, and is deleted thirty days after it ends.
7 Your rights
You can ask for a copy of your data, ask us to correct or erase it, ask us to restrict or stop a particular use, and ask for it in a portable form. Where we rely on legitimate interest, you can object.
Write to privacy@wos.io and we will answer within thirty days. If our answer does not satisfy you, you can complain to your data protection authority.
8 How it is kept safe
Traffic is encrypted in transit. Each customer is isolated at the database level. Inside the product every permission is granted by an explicit rule and every access is recorded with the rule that allowed it, so an access question has an answer rather than a theory.
If a breach puts anyone at risk, we notify the affected customers and the relevant authority within seventy-two hours of becoming aware.
9 Changes
When this policy changes we update the date at the top, and we email customers about anything material rather than expecting them to notice.
10 Contact
Privacy questions and rights requests: privacy@wos.io