Privacy Policy
Last updated: 8 September 2026
Worklayer, Inc. (“Worklayer,” “we,” “us,” or “our”) provides an AI-powered HR and workforce-management platform that companies use to manage their people operations. This Privacy Policy describes how Worklayer processes personal information that we collect through our digital properties that link to this Privacy Policy, including our website at worklayer.ai (the “Website”), the Worklayer platform at app.worklayer.ai (the “Platform”), and our social media pages, as well as through our marketing, sales, and support activities (collectively, the “Service”).
Employees of companies that use Worklayer: your employer, not Worklayer, decides how your data is used inside the Platform. Section 1 explains this, and Section 5 describes what we process on your employer’s behalf.
California and other US state residents: see the State privacy rights notice in Section 16 for your notice at collection and the rights available to you under applicable state privacy laws.
Individuals in Europe: see the Notice to European users in Section 17 for additional information for individuals located in the European Economic Area or the United Kingdom (which we refer to together as “Europe”, and “European” should be understood accordingly).
Index
- 1. Our two roles: controller and processor
- 2. Personal information we collect
- 3. Cookies and tracking technologies
- 4. AI features on the Platform
- 5. Employee data we process on behalf of Customers
- 6. How we use your personal information
- 7. How long we keep personal information
- 8. How we share your personal information
- 9. Your choices
- 10. Other sites and services
- 11. Security
- 12. International data transfer
- 13. Children
- 14. Changes to this Privacy Policy
- 15. How to contact us
- 16. State privacy rights notice
- 17. Notice to European users
1. Our two roles: controller and processor
How we handle personal information depends on which of two roles we are acting in.
Worklayer as controller. When you visit our Website, book a demo, contact us, or when your company sets up and administers a Worklayer account, we decide how and why your personal information is processed. We are the controller (or, under US state privacy laws, the “business”), and this Privacy Policy describes that processing in full.
Worklayer as processor. When a company (our “Customer,” typically your employer) uses the Platform to manage its workforce, the employee data inside the Platform belongs to that company. The Customer is the controller of its employees’ data; Worklayer processes it only on the Customer’s documented instructions as a processor (Art. 28 GDPR) or “service provider,” under a data processing agreement (“DPA”).
If you are an employee, contractor, or applicant of a company that uses Worklayer, your employer decides what data is entered into the Platform and why. Please direct privacy questions and requests (access, correction, deletion, objection) to your employer in the first instance; we support them in fulfilling those requests under our DPA. Section 5 summarizes, for transparency, what the Platform processes on employers’ behalf. The remaining sections of this Privacy Policy describe the processing for which Worklayer is the controller.
2. Personal information we collect
2.1 Information you provide to us
Personal information you may provide to us through the Service or otherwise includes:
- Contact data, such as your first and last name, work email address, phone number, company name, professional title, and company size, for example when you book a demo on our
/demopage, request information, or otherwise get in touch. - Demo preferences, such as the workflow you choose to explore before booking. We include that choice in the Calendly booking link so we can tailor the demo. It is shared when you allow the embedded scheduler to load or when you open the direct booking link, and it adds no tracking script or cookie to our Website.
- Account data, such as your name, work email address, and the authentication identifiers needed to sign you in when your company creates a Worklayer account and invites you. Sign-in is handled through our identity provider, WorkOS; we never see or store your password. Your role, permissions, and profile settings within your company’s workspace are part of that workspace and are processed on your company’s behalf (Section 5).
- Communications data, based on our exchanges with you, including when you contact us by email, through support channels, or via social media.
- Billing data for the Customer organization, such as a billing reference (Stripe customer ID), subscription status, and invoicing details. Payment card details are entered on pages hosted by our payment processor, Stripe, and processed by Stripe; we never receive full card numbers.
- Marketing data, such as your preferences for receiving our marketing communications and details about your engagement with them.
- Other data not specifically listed here, which we will use as described in this Privacy Policy or as otherwise disclosed at the time of collection.
2.2 Third-party sources
We may combine personal information we receive from you with personal information falling within one of the categories identified above that we obtain from other sources, such as:
- Customers. When your company creates your account or invites you to its workspace, it provides your name and work email address to us. Your company is the source of that data within the meaning of Art. 14 GDPR, and this Privacy Policy is made available to you at your first sign-in.
- Service providers that provide services on our behalf or help us operate the Service or our business, such as our identity provider (authentication identifiers and sign-in events), our payment processor (subscription and payment status), and our scheduling provider (demo booking details).
- Business transaction partners. We may receive personal information in connection with an actual or prospective business transaction, for example from an entity we acquire or are acquired by, a successor, or an assignee, or from any party involved in a merger, acquisition, sale of assets, or similar transaction, or in the context of an insolvency, bankruptcy, or receivership.
2.3 Automatic data collection
We and our service providers may automatically log information about you, your computer or mobile device, and your interaction over time with the Service, such as:
- Device data, such as your IP address, operating system type and version, browser type and version, language settings, device type, and general location information derived from your IP address (such as city or country).
- Online activity data on the Website, such as the pages you requested, the website you visited before browsing to the Website, and the date and time of access. Our hosting provider, Netlify, records this data in server logs that are needed to deliver the Website and keep it secure; these logs are kept for a short period (typically no more than 30 days) and are not combined with any other data about you.
- Platform activity and diagnostic data, such as sign-in events, administrative actions, audit trails, security events, and error diagnostics, including masked replays of sessions in which a technical error occurred (content is masked before it leaves your browser).
We do not collect precise geolocation data as controller. Where a Customer enables location-based features in the Platform (for example, workplace geofencing used to validate clock-ins), that data is processed on the Customer’s behalf as described in Section 5. For more information about the technologies involved in automatic data collection, see Section 3.
2.4 Data about others
Customers enter personal information about their personnel into the Platform; that data is processed on the Customer’s behalf as described in Section 5. If you provide us with personal information about someone else, for example a colleague’s contact details when booking a demo, please do so only with their permission.
3. Cookies and tracking technologies
Website. We use c15t, an open-source consent manager, to ask for and store your cookie choices. Where opt-in consent is required, a banner appears on your first visit and lets you accept or decline by category (Necessary, Functionality) before any non-essential technology is loaded; accepting and declining are equally easy, and we never treat closing or ignoring the banner as agreement. You can change or withdraw your consent at any time, with effect for the future, via the Cookie preferences link in the footer of every page.
We currently use no statistics, analytics, advertising, or marketing cookies at all on the Website, and no tag manager. The complete inventory is short:
- c15t stores your cookie consent choices (the categories you allowed, and when), as a first-party local-storage entry and a first-party cookie of the same name; it expires after 12 months (strictly necessary);
- starlight-theme remembers your light/dark theme choice and is set only when you actively toggle the theme; a first-party local-storage entry that never leaves your device (strictly necessary);
- Calendly on
/demoloads only after you give the corresponding consent (the Functionality category); until then, the page does not connect to Calendly at all. When it loads, Calendly sets cookies needed for security and session handling inside the widget. If you prefer not to load the widget, the demo page offers a direct link to Calendly’s own site, or you can request a demo at privacy@worklayer.ai instead. If you later withdraw consent, the widget is removed from the page.
Platform. The Platform sets strictly necessary first-party cookies (the hris_session session cookie and a CSRF-protection cookie) to keep you signed in securely. No tracking cookies are used on the Platform.
Do Not Track. Some browsers can send “Do Not Track” signals to the online services you visit. We currently do not respond to “Do Not Track” signals, which have no agreed meaning across browsers; the technologies we actually use are the ones listed above. Global Privacy Control signals are addressed in Section 16.
Our Cookie Policy describes each item in detail, including how to manage your preferences. In Europe, our legal basis for non-essential technologies is your consent (Art. 6(1)(a) GDPR; § 25(1) TDDDG), and for the strictly necessary items § 25(2) TDDDG together with our legitimate interest in a functioning, secure website (Art. 6(1)(f) GDPR); we keep a record of your consent decision to meet our accountability obligations (Art. 6(1)(c) and (f) GDPR).
4. AI features on the Platform
Worklayer’s core feature is AI agents that automate HR workflows (for example, preparing onboarding tasks, answering employee questions, or drafting routine HR communications). In plain terms:
- What happens. When an agent runs or a user chats with the assistant, relevant data from the Customer’s workspace, which can include employee records, is sent together with the conversation or task context to large language models to generate the response or carry out the workflow step.
- Which providers. We access models through OpenRouter, Inc. (USA) as an AI gateway, which routes requests to third-party model providers.
- Model providers. Our AI model providers are contractually prohibited from using your data to train their own models, and we require them to maintain appropriate data protection safeguards.
- Records. Agent runs are logged (including the inputs and outputs of each step) so that Customers can audit what an agent did. These logs are part of the Customer’s workspace data and are controlled by the Customer.
- Human oversight. Customers configure what agents may do and remain responsible for employment decisions. Our Terms of Service require human review of AI output before decisions that significantly affect employees.
Where this processing concerns Customer employee data, it happens on the Customer’s behalf under our DPA (Section 5).
5. Employee data we process on behalf of Customers
Customers use the Platform to manage their workforce and decide which data they enter. Depending on the features and fields a Customer enables, this typically includes, but is not limited to:
- Identity and contact data: name, date of birth, nationality, contact details, address, emergency contacts;
- Employment data: position, department, manager, contract type and dates, workplace, employment status and history;
- Compensation and payroll data: salary, additional pay and benefits, bank details, and payroll identifiers required by applicable law (for example, in Germany: tax class, tax ID (Steuer-ID), social insurance number, and health insurance details);
- Special categories of data where employment law requires them (Art. 9 GDPR): for example church tax status (which can reveal religious affiliation) and health-related absence data such as sick leave; these are processed under the employment-law provisions of Art. 9(2)(b) GDPR in conjunction with § 26(3) BDSG, on the Customer’s responsibility;
- Time and absence data: working time entries including clock-in/clock-out records, schedules, vacation and other leave, and, where the Customer enables it, workplace geofencing settings used to validate clock-ins;
- Documents and signatures: employment documents and acknowledgment/signature records, including technical signature evidence such as timestamp and IP address;
- Expense data: receipts, amounts, trip details, and names of third-party attendees where entered;
- Integration data: data exchanged with third-party products the Customer connects to its workspace (for example, Slack);
- Custom fields the Customer defines, and records of AI agent activity in the Customer’s workspace (Section 4).
This list is not exhaustive. Customers may enter other personal data about their personnel, and the categories processed may expand as the Platform gains features.
For all of this data, your employer is the controller. Worklayer processes it under a DPA that implements Art. 28 GDPR (and the service-provider requirements of US state privacy laws), including confidentiality, security measures, sub-processor controls, and assistance with data subject rights. Resolving a support request may require our staff to view relevant data in your company’s workspace; this access takes place on your company’s instructions under the DPA. Our DPA and current sub-processor list are available to Customers and prospective Customers on request at privacy@worklayer.ai.
6. How we use your personal information
We may use your personal information for the following purposes or as otherwise described at the time of collection.
Service delivery and operations. We may use your personal information to:
- provide the Website and the Platform, including creating and maintaining your account and authenticating you;
- bill Customers for the Service and manage subscriptions;
- enable security features of the Service, including sign-in protection and audit logging;
- communicate with you about the Service, including by sending Service-related announcements, updates, security alerts, and support and administrative messages; and
- provide support for the Service and respond to your requests, questions, and feedback.
Demo requests, sales, and direct marketing. When you book a demo or contact us, we use your contact data to schedule, prepare for, conduct, and follow up on the demo and to respond to your inquiry. We may also send you direct marketing communications about Worklayer, where permitted by law or with your consent. You may opt out of marketing communications at any time as described in Section 9.
Compliance and protection. We may use your personal information to:
- comply with applicable laws, lawful requests, and legal process, such as to respond to subpoenas, investigations, or requests from government authorities;
- protect our, your, or others’ rights, privacy, safety, or property (including by making and defending legal claims);
- audit our internal processes for compliance with legal and contractual requirements or our internal policies;
- enforce the terms and conditions that govern the Service; and
- prevent, identify, investigate, and deter fraudulent, harmful, unauthorized, unethical, or illegal activity, including cyberattacks and identity theft.
Corporate events. We may share certain personal information in the context of actual or prospective corporate events; for more information, see Section 8.
To create aggregated, de-identified, or anonymized data. We may create aggregated, de-identified, or anonymized data from your personal information and that of other individuals whose personal information we collect. We make personal information into de-identified or anonymized data by removing information that makes the data identifiable to you, and we will not attempt to re-identify any such data. We may use this aggregated, de-identified, or anonymized data, and share it with third parties, for our lawful business purposes.
Further uses. In some cases, we may use your personal information for further purposes, in which case we will ask for your consent if those purposes are not compatible with the initial purpose for which the information was collected.
We do not use personal information for interest-based advertising.
7. How long we keep personal information
We generally retain personal information to fulfill the purposes for which we collected it, including for the purposes of satisfying any legal, accounting, or reporting requirements, establishing or defending legal claims, or for fraud prevention purposes. To determine the appropriate retention period, we consider the amount, nature, and sensitivity of the personal information, the potential risk of harm from unauthorized use or disclosure, the purposes for which we process it and whether we can achieve those purposes through other means, and the applicable legal requirements. Our current retention periods are:
- Website server logs: a short period, typically no more than 30 days;
- Cookie consent records: 12 months for the consent entry stored in your browser; consent logs kept by our consent backend for as long as needed to demonstrate that consent was given (Art. 7(1) GDPR);
- Demo and sales contact data: up to 24 months after our last interaction with you, unless you ask us to delete it sooner or we enter into a contract;
- Customer account data: for the duration of the Customer’s contract; after termination, available for export during a 30-day window and deleted no later than 90 days after termination (see our Terms of Service);
- Platform security and audit logs: up to 12 months, then deleted or anonymized;
- Billing and tax records: as required by applicable tax and commercial law (typically up to 10 years);
- Support and inquiry correspondence: up to 24 months after the matter is resolved;
- Data subject request records: 2 years after the request is completed (accountability, Art. 5(2) GDPR);
- Customer employee data (processor role): as instructed by the Customer and per the DPA; on contract termination, deleted or returned per the DPA.
We may retain specific data for longer where the law requires it or, until the expiry of applicable limitation periods, where necessary to establish, exercise, or defend legal claims. When we no longer require personal information, we delete it, anonymize it, or, if that is not immediately possible (for example, because it is stored in routine backups), isolate it from further processing until it is removed in the ordinary rotation of those backups.
8. How we share your personal information
We do not sell personal information. We may share your personal information with the following parties, or as otherwise described in this Privacy Policy or at the time of collection.
Service providers. Third parties that provide services on our behalf or help us operate the Service or our business. They process personal information under data processing agreements (as processors under Art. 28 GDPR or service providers under US state privacy laws), except where marked below as independent controllers. Where these providers handle Customer employee data, they act as sub-processors under our DPA with the Customer (Section 5).
Website:
- Netlify, Inc. (USA): website hosting and serverless infrastructure (processor);
- Inth (c15t consent backend): cookie consent management and consent records (processor);
- Calendly LLC (USA): demo scheduling (processor).
Platform:
- WorkOS, Inc. (USA): sign-in and identity management (processor);
- Stripe, Inc. (USA): subscription billing and payments (independent controller for payment processing; see Stripe’s privacy notice);
- Resend, Inc. (USA): transactional email delivery (processor);
- OpenRouter, Inc. (USA): AI gateway that routes language-model requests to our third-party model providers (processor);
- Amazon Web Services (S3) (per deployment region): file and document storage (processor);
- Functional Software, Inc. (Sentry) (USA): error monitoring and diagnostics, including masked screen replays of sessions in which an error occurred (processor);
- Google LLC (Maps) (USA): optional address autocomplete and distance calculation, invoked from your browser when you use address fields (independent controller; see Google’s privacy notice);
- OpenStreetMap Foundation (Nominatim) (UK/EU): optional map display and geocoding, invoked from your browser (independent controller; see OSMF’s privacy notice).
Payment processor. Any payment card information used to pay for the Service is collected and processed directly by Stripe, which may use your payment data in accordance with its privacy policy at https://stripe.com/privacy.
Affiliates. Any current or future parent, subsidiaries, and affiliates of Worklayer, for the purposes described in this Privacy Policy.
Third parties designated by you. We may share personal information with third parties where you or your Customer have instructed us or provided consent to do so, for example third-party products that a Customer connects to its workspace (such as Slack). The third party’s use of the information is governed by its own privacy policy.
Professional advisors. Professional advisors, such as lawyers, auditors, bankers, and insurers, in the course of the professional services that they render to us.
Authorities and others. Law enforcement, government authorities, and private parties, as we believe in good faith to be necessary or appropriate for the compliance and protection purposes described in Section 6. We limit any disclosure to what is necessary for the specific purpose and, where a request comes from a non-European authority concerning data of individuals in Europe, we assess it against our GDPR obligations before responding.
Business transferees. We may disclose personal information in the context of actual or prospective business transactions (for example, investments in or financing of Worklayer, or the sale, transfer, or merger of all or part of our business, assets, or shares). We may need to share certain personal information with prospective counterparties and their advisers, and we may disclose your personal information to an acquirer, successor, or assignee of Worklayer as part of any merger, acquisition, sale of assets, or similar transaction, or in the event of an insolvency, bankruptcy, or receivership in which personal information is transferred as one of our business assets. We would notify you before your personal information becomes subject to a different privacy policy.
Other users in your Customer’s workspace. Your name, role, and profile information in the Platform are visible to other users of your Customer’s workspace as configured by the Customer. There are no public profiles on the Service.
9. Your choices
In this section, we describe the rights and choices available to all users. Users located in certain US states and in Europe can find additional information about their rights in Sections 16 and 17.
Access or update your information. If you have a Platform account, you can review and update certain profile information by signing in. Where your information is part of your employer’s workspace, your employer controls it and can update it for you.
Opt out of marketing communications. You may opt out of marketing-related emails by following the unsubscribe instructions at the bottom of the email or by contacting us at privacy@worklayer.ai. You may continue to receive Service-related and other non-marketing emails.
Cookies and other technologies. You can change or withdraw your cookie choices at any time via the Cookie preferences link in the footer of every page of the Website; see Section 3 and our Cookie Policy. Independently of our banner, your browser lets you block or delete cookies and site data for individual sites; note that clearing the strictly necessary items also erases the record of your consent choice, so the banner will ask again on your next visit.
Declining to provide information. Providing personal information to us is voluntary; you are under no legal or contractual obligation to provide it. Without it, however, we cannot do the related thing: schedule your demo, answer your inquiry, or give you access to the Platform. For Platform accounts, your company decides which data it provides under its contract with us.
Closing your account. Customer administrators can deactivate user accounts and close the Customer’s account in the Platform settings or by contacting us. If you are an employee of a Customer, please ask your employer’s administrator.
Linked third-party products. Customers control which third-party products are connected to their workspace and can disconnect them at any time in the Platform settings. Disconnecting an integration does not affect information the third party has already received.
10. Other sites and services
The Service may contain links to websites and online services operated by third parties. These links are not an endorsement of, or a representation that we are affiliated with, any third party. We do not control websites or online services operated by third parties, and we are not responsible for their actions. We encourage you to read the privacy policies of the other websites and online services you use.
We also operate a company page on LinkedIn. When you visit or interact with it, LinkedIn processes your data under LinkedIn’s privacy policy. For the aggregated page statistics LinkedIn provides to us (“Page Insights”), we and LinkedIn Ireland Unlimited Company are joint controllers under LinkedIn’s Page Insights Joint Controller Addendum; we receive only aggregated statistics, never profiles of individual visitors. Please direct requests concerning your LinkedIn data to LinkedIn in the first instance; you can also contact us at privacy@worklayer.ai and we will forward or answer what we can.
11. Security
We employ technical, organizational, and physical safeguards designed to protect the personal information we collect, including encryption in transit (TLS), tenant isolation between Customer workspaces, role-based access controls, authentication via a dedicated identity provider, audit logging, and the principle of least privilege for our own staff access. However, security risk is inherent in all internet and information technologies, and we cannot guarantee the security of your personal information. If we become aware of a personal data breach affecting you, we will notify you and the competent authorities as required by applicable law (including Art. 33 and 34 GDPR).
If you believe you have found a security vulnerability, please report it to privacy@worklayer.ai.
12. International data transfer
We are headquartered in the United States and use service providers that operate in the United States and other countries. Your personal information may be transferred to the United States or other locations where privacy laws may not be as protective as those in your state, province, or country. Users in Europe should read the important information about transfers of personal information outside Europe in Section 17.
13. Children
The Website is not intended for use by anyone under 18 years of age, and we do not knowingly collect personal information from children through it. The Platform is used by Customers to manage their personnel, which in some countries may include working minors (for example, apprentices); that data is processed on the Customer’s instructions as described in Section 5. If you are a parent or guardian of a child from whom you believe we have collected personal information in a manner prohibited by law, please contact us, and we will comply with applicable legal requirements to delete the information.
14. Changes to this Privacy Policy
We reserve the right to modify this Privacy Policy at any time, for example when we add features or service providers. If we make material changes, we will notify you by updating the date at the top of this Privacy Policy and posting it on the Service, and, for material changes affecting Platform users, by notifying Customers. Modifications are effective upon posting (or as otherwise indicated at the time of posting), and your use of the Service after the effective date indicates that you acknowledge that the modified Privacy Policy applies. Significant new processing purposes will not be applied to previously collected data without a valid legal basis. Previous versions of this Privacy Policy are available from us on request.
15. How to contact us
If you have questions about our practices or would like to exercise any privacy-related right that may be available to you, please contact us:
Worklayer, Inc.
2810 N Church St, STE 89103
Wilmington, DE 19802, USA
Email: privacy@worklayer.ai
16. State privacy rights notice
Except as otherwise provided, this section applies to residents of US states to the extent they have privacy laws applicable to us that grant their residents the rights described below (collectively, the “State Privacy Laws”). It describes how we collect, use, and share the personal information of residents of these states and the rights these users may have with respect to it. Not all rights listed below may be afforded to all users; if you are not a resident of a state with an applicable State Privacy Law, you may not be able to exercise them. We may not be able to process your request if you do not provide us with sufficient detail to confirm your identity or to understand and respond to it.
For purposes of this section, “Personal Information” has the meaning given to “personal data,” “personal information,” or similar terms, and “Sensitive Personal Information” has the meaning given to “sensitive personal information,” “sensitive data,” or similar terms in the State Privacy Laws, except that neither term includes information exempted from the scope of the State Privacy Laws. When we process Personal Information on behalf of a Customer (Section 5), we act as a “service provider” or “processor” under the State Privacy Laws; please direct requests concerning that data to the Customer.
Your privacy rights. The State Privacy Laws may provide residents with some or all of the rights listed below. These rights are not absolute, and some State Privacy Laws do not provide all of them, so we may decline a request in certain cases as permitted by law.
- Information. You can request information about how we have collected and used your Personal Information, including the categories of Personal Information we have collected, the categories of sources, the business or commercial purposes for collecting it, the categories of third parties with which we share it, and the categories of Personal Information sold or disclosed for a business purpose.
- Access. You can request a copy of the Personal Information that we have collected about you.
- Correction. You can ask us to correct inaccurate Personal Information that we have collected about you.
- Deletion. You can ask us to delete the Personal Information that we have collected from you.
- Appeal. You can appeal our denial of any request validly submitted.
- Opt-out of targeted advertising, sales, and profiling. We do not process Personal Information for targeted advertising and do not sell Personal Information within the meaning of the State Privacy Laws. Where a State Privacy Law gives you the right to opt out of profiling in furtherance of decisions that produce legal or similarly significant effects, you may submit a request as described below.
- Sensitive Personal Information. We do not collect Sensitive Personal Information as a business, and we do not use Personal Information to infer characteristics about consumers. Sensitive employee data that Customers enter into the Platform is processed by us only as a service provider on the Customer’s instructions (Section 5).
- Consumers under 16. We do not have actual knowledge that we collect, sell, or share the Personal Information of consumers under 16 years of age.
- Nondiscrimination. You are entitled to exercise the rights described above free from discrimination as prohibited by the State Privacy Laws.
Global Privacy Control. Because we do not sell or share Personal Information or process it for targeted advertising, opt-out preference signals such as the Global Privacy Control (“GPC”) do not change how we process your data. Should our practices change, we will honor GPC signals as valid opt-out requests as required by applicable law. For more information about GPC, visit https://globalprivacycontrol.org/.
Exercising your rights. You may submit requests to exercise the rights listed above by emailing privacy@worklayer.ai or by writing to the postal address in Section 15. We will respond within the time required by the applicable State Privacy Law.
Verification of identity; authorized agents. We may need to verify your identity in order to process your request, and we reserve the right to confirm your residency. Where we can, we verify requests by matching the information you provide against the account and contact information we already hold, for example by asking you to respond from the email address associated with your account. Under some State Privacy Laws, you may enable an authorized agent to make a request on your behalf; we may need to verify your agent’s identity and authority to act for you, for example by requesting a copy of a valid power of attorney or your written and signed permission, and we may contact you directly to confirm that you have given the agent permission to submit the request.
Information practices. The following describes our practices currently and during the past 12 months:
- Sources and purposes. We collect the categories of Personal Information described in Section 2 from the sources described there and use them for the business and commercial purposes described in Section 6.
- Retention. The criteria for deciding how long to retain Personal Information are described in Section 7.
- De-identification. We do not attempt to re-identify de-identified information derived from Personal Information, except for the purpose of testing whether our de-identification processes comply with applicable law.
Personal Information that we collect, use, and disclose. The chart below summarizes the Personal Information we collect, the purposes for which we collect it, and the categories of third parties to whom we may disclose it, by reference both to the categories in Section 2 and to the categories of Personal Information specified in the California Consumer Privacy Act (Cal. Civ. Code § 1798.140). We do not sell Personal Information or share it for cross-context behavioral advertising. Information you voluntarily provide to us, such as in free-form messages, may contain other categories of Personal Information not described below.
| Personal Information we collect | CCPA statutory categories | Purposes (Section 6) | Categories of third parties to whom we disclose it for a business purpose |
|---|---|---|---|
| Contact data (name, work email, phone, company, title, company size) | Identifiers; professional or employment-related information | Service delivery; demo requests, sales, and direct marketing; compliance | Service providers (hosting, scheduling, email delivery); professional advisors; authorities; business transferees |
| Account data (name, work email, authentication identifiers, role) | Identifiers; professional or employment-related information | Service delivery; security; compliance | Service providers (identity, hosting, email delivery, error monitoring); professional advisors; authorities; business transferees |
| Billing data (billing reference, subscription status, invoicing details) | Identifiers; commercial information | Service delivery (billing); compliance | Payment processor; professional advisors; authorities; business transferees |
| Communications data (content of support requests and inquiries) | Identifiers; personal information described in Cal. Civ. Code § 1798.80(e) | Service delivery (support); compliance | Service providers (hosting, email delivery); professional advisors; authorities; business transferees |
| Device, online activity, and diagnostic data (IP address, browser and OS, pages requested, timestamps, sign-in and audit events, error diagnostics) | Identifiers; internet or other electronic network activity information; geolocation data (general, derived from IP only) | Service delivery; security; compliance | Service providers (hosting, identity, error monitoring); professional advisors; authorities; business transferees |
| Marketing data (communication preferences) | Identifiers; commercial information | Demo requests, sales, and direct marketing | Service providers (email delivery); professional advisors; business transferees |
Additional information for California residents. Under California’s “Shine the Light” law (Cal. Civ. Code § 1798.83), California residents may ask companies with which they have a business relationship primarily for personal, family, or household purposes for the names of third parties to which they have disclosed certain personal information for those third parties’ own direct marketing purposes. We do not disclose personal information to third parties for their own direct marketing purposes. You may send us requests for this information at privacy@worklayer.ai with the statement “Shine the Light Request” and your name and mailing address; we reserve the right to require additional information to confirm your identity and California residency.
Additional information for Nevada residents. Nevada residents have the right to opt out of the sale of certain personal information for monetary consideration. We do not engage in such sales; if you are a Nevada resident and would like to make a request to opt out of any potential future sales, please email privacy@worklayer.ai.
Other states. Residents of other states with State Privacy Laws (for example, Colorado, Connecticut, Virginia, Texas, Oregon, Montana, Utah, Iowa, Indiana, or Tennessee) may exercise the rights listed above by contacting us as described in this section.
17. Notice to European users
Where this notice applies. The information provided in this section applies only to individuals located in the European Economic Area and the United Kingdom (together, “Europe,” as defined at the top of this Privacy Policy). References to “personal information” in this Privacy Policy should be understood to include “personal data” as defined in the GDPR, that is, information about individuals from which they are either directly identified or can be identified. We are a US-based company that offers its services to companies in Europe; the GDPR applies to our processing of personal data of people in Europe under Art. 3(2) GDPR.
Controller. Worklayer, Inc. is the controller in respect of the processing of your personal information covered by this Privacy Policy for purposes of European data protection legislation (the EU GDPR and the UK GDPR, as and where applicable, together the “GDPR”). See Section 15 for our contact details. Where your personal information is in your employer’s Worklayer workspace, your employer is the controller and we act as its processor (Sections 1 and 5).
Our legal bases for processing. In respect of each of the purposes for which we use your personal information, the GDPR requires us to have a “legal basis” for that use. Our legal bases are:
- Contractual necessity: where we need to perform a contract we are about to enter into or have entered into with you (Art. 6(1)(b) GDPR).
- Legitimate interests: where it is necessary for our legitimate interests and your interests and fundamental rights do not override those interests (Art. 6(1)(f) GDPR). The specific legitimate interests are set out in the table below.
- Compliance with law: where we need to comply with a legal or regulatory obligation (Art. 6(1)(c) GDPR).
- Consent: where we have your specific consent to carry out the processing for the purpose in question (Art. 6(1)(a) GDPR; § 25(1) TDDDG for storing or accessing information on your device).
The table below sets out the legal bases we rely on for the purposes described in Section 6.
| Purpose | Categories of personal information involved (Section 2) | Legal basis |
|---|---|---|
| Service delivery and operations (Platform accounts) | Account data; communications data; device data; Platform activity and diagnostic data | Contractual necessity where you are yourself our contract party (for example, a sole proprietor). Legitimate interests in providing and administering the contracted Service to the Customer you act for, where the Customer is our contract party. |
| Billing | Billing data; account data | Contractual necessity with respect to the Customer. Compliance with law and legitimate interests in meeting the tax, accounting, and bookkeeping obligations applicable to us. |
| Demo requests and inquiries | Contact data; communications data | Legitimate interests in responding to and following up on business inquiries. Contractual necessity where you contact us on your own behalf as a prospective contract party (steps prior to entering into a contract, taken at your request). |
| Direct marketing | Contact data; marketing data | Consent where required by applicable law. Otherwise legitimate interests in promoting our business; you can object at any time (Art. 21(2) GDPR). |
| Website delivery and cookies | Device data; online activity data | Legitimate interests in providing a functional, secure website (server logs and strictly necessary items; § 25(2) TDDDG). Consent for non-essential technologies (§ 25(1) TDDDG). Compliance with law and legitimate interests in keeping a record of your consent decision (Art. 7(1) GDPR). |
| Security | Account data; device data; Platform activity and diagnostic data | Legitimate interests in ensuring the ongoing security and proper operation of the Service and associated IT systems and networks. Compliance with law where applicable. |
| Compliance and protection | Any and all data types relevant in the circumstances | Compliance with law. Where compliance with law is not applicable, legitimate interests in participating in, supporting, and following legal process and requests, including cooperation with authorities, and in ensuring the protection, maintenance, and enforcement of our and others’ rights, property, and safety. |
| Corporate events | Any and all data types relevant in the circumstances | Legitimate interests in providing information to third parties involved in an actual or prospective corporate event (including to enable them to investigate and, where relevant, continue to operate our business), while minimizing the amount and sensitivity of the personal information shared. |
| Aggregated, de-identified, or anonymized data | Any and all data types relevant in the circumstances | Legitimate interests in producing aggregated, de-identified, or anonymized data that no longer identifies you. |
| Further uses | Any and all data types relevant in the circumstances | The original legal basis relied upon, if the further use is compatible with the initial purpose. Consent, if it is not. |
Retention. We retain personal information for as long as necessary to fulfill the purposes for which we collected it, as described in Section 7. When we no longer require it, we delete or anonymize it or, if this is not possible (for example, because it is stored in backup archives), we securely store it and isolate it from further processing until deletion is possible. If we anonymize your personal information so that it can no longer be associated with you, we may use that information indefinitely without further notice to you.
Sensitive personal information. We ask that you not provide us with any special categories of personal data (for example, information related to racial or ethnic origin, political opinions, religion or other beliefs, health, biometrics or genetic characteristics, criminal background, or trade union membership) through the Website or otherwise to us as controller. Special categories of employee data that your employer enters into the Platform are processed on your employer’s behalf under the employment-law provisions described in Section 5.
Your rights. European data protection laws give you certain rights regarding your personal information. If you are located in Europe, you may ask us to take the following actions in relation to your personal information that we hold as controller:
- Access (Art. 15): provide you with information about our processing of your personal information and give you access to it.
- Correct (Art. 16): update or correct inaccuracies in your personal information.
- Delete (Art. 17): delete your personal information where there is no good reason for us to continue processing it, including where you have exercised your right to object.
- Transfer (Art. 20): transfer a machine-readable copy of your personal information to you or a third party of your choice.
- Restrict (Art. 18): restrict the processing of your personal information, for example while we establish its accuracy or the reason for processing it.
- Object (Art. 21): object to our processing of your personal information where we rely on legitimate interests, and at any time where we process it for direct marketing purposes.
- Withdraw consent (Art. 7(3)): where we use your personal information based on your consent, withdraw that consent at any time, with effect for the future.
Exercising these rights. You may submit these requests by email to privacy@worklayer.ai or to our postal address in Section 15. We will respond within one month (Art. 12(3) GDPR) and may request specific information from you to confirm your identity. Exercising your rights is free of charge; only for manifestly unfounded or excessive requests, in particular because of their repetitive character, may we charge a reasonable fee or decline to act (Art. 12(5) GDPR). If we reject a request in whole or in part, we will let you know our grounds for doing so, subject to any legal restrictions. If your personal information is in your employer’s Worklayer workspace, these rights apply against your employer as controller; please contact them first, and we will assist them under our DPA.
Your right to lodge a complaint with your supervisory authority. If you are not satisfied with our response to a request or with how we process your personal information, you can make a complaint to the data protection regulator in your habitual place of residence, place of work, or place of the alleged infringement:
- For users in the European Economic Area, the contact information for the data protection regulator in your place of residence can be found at https://www.edpb.europa.eu/about-edpb/about-edpb/members_en; in Germany, the authorities of the federal states (Länder) are competent.
- For users in the United Kingdom, the regulator is the Information Commissioner’s Office, Wycliffe House, Water Lane, Wilmslow, Cheshire SK9 5AF, telephone +44 303 123 1113, https://ico.org.uk/make-a-complaint/.
Data processing outside Europe. We are a US-based company, and many of our service providers, advisers, and other recipients of data are also based in the United States. This means that, if you use the Service, your personal information will necessarily be accessed and processed in the United States, and it may also be provided to recipients in other countries outside Europe. Where we transfer personal information to countries outside Europe, we ensure that a similar degree of protection is afforded to it through one of the following mechanisms:
- Transfers to territories with an adequacy decision. We may transfer your personal information to countries or territories whose laws have been deemed to provide an adequate level of protection by the European Commission or the UK Government, including to US providers certified under the EU–U.S. Data Privacy Framework (and its UK extension) for as long as the relevant adequacy decisions remain in force.
- Transfers to territories without an adequacy decision. Otherwise, we use appropriate safeguards designed to give personal information effectively the same protection it has in Europe, in particular the EU Standard Contractual Clauses (and, for the UK, the International Data Transfer Addendum) under Art. 46 GDPR, together with any supplementary measures needed. In limited circumstances, we may rely on a derogation under Art. 49 GDPR, for example your explicit consent to a specific transfer.
You may contact us at privacy@worklayer.ai if you want further information on the specific mechanism used when transferring your personal information out of Europe, and you may have the right to receive a copy of the appropriate safeguards under which it is transferred.