Privacy Policy
1. Who we are
Worklayer, Inc. (“Worklayer,” “we,” “us,” or “our”) is a Delaware corporation with its registered address at 2810 N Church St, STE 89103, Wilmington, DE 19802, USA.
We operate:
- the website worklayer.ai (the “Website”), and
- the Worklayer platform at app.worklayer.ai, an AI-assisted HR and workforce management platform used by companies to manage their people operations (the “Platform”).
For questions about this policy or your personal data, contact us at privacy@worklayer.ai or by post at the address above.
We are a US-based company that offers its services to companies in the United States and in Europe. The EU General Data Protection Regulation (“GDPR”) applies to our processing of personal data of people in the EU/EEA (Art. 3(2) GDPR).
2. Controller and processor roles
How we handle personal data depends on which of two roles we are acting in:
Worklayer as controller. When you visit our Website, book a demo, or when your company sets up a Worklayer account, we decide how and why the data is processed. We are the controller, and this policy describes that processing in full.
Worklayer as processor. When a company (our Customer, typically your employer) uses the Platform to manage its workforce, the employee data inside the Platform belongs to that company. The Customer is the controller of its employees’ data; Worklayer processes it only on the Customer’s documented instructions as a processor (Art. 28 GDPR), under a data processing agreement (“DPA”).
If you are an employee of a company that uses Worklayer, your employer decides what data is entered into the Platform and why. Please direct privacy questions and requests (access, correction, deletion, objection) to your employer in the first instance; we support them in fulfilling those requests under our DPA. Section 6 summarizes, for transparency, what the Platform processes on employers’ behalf.
3. Data we collect on the Website
3.1 Visiting the Website
When you visit worklayer.ai, our hosting provider (Netlify) automatically processes technical data needed to deliver the site and keep it secure: your IP address, browser type and version, operating system, referring URL, pages requested, and date/time of access. These server logs are kept for a short period (typically no more than 30 days) and are not combined with any other data about you.
Legal basis: legitimate interests (Art. 6(1)(f) GDPR) in providing a functional, secure website.
3.2 Cookies and similar technologies
We use the Cookiebot consent management platform by Usercentrics A/S (Denmark) to obtain and store your cookie choices. On your first visit, a consent banner lets you accept or decline by category (Necessary, Preferences, Statistics, Marketing) before any non-essential technology is loaded, and you can change or withdraw your consent at any time, with effect for the future, via the floating cookie widget in the corner of the Website.
We currently use no statistics and no marketing cookies at all; there is no advertising or analytics tracking on this Website. The complete inventory:
- CookieConsent: stores your cookie consent choices; a first-party HTTP cookie set by Cookiebot (Usercentrics A/S); expires after 12 months (strictly necessary, § 25(2) TDDDG);
- starlight-theme: remembers your light/dark theme choice and is set only when you actively toggle the theme; a first-party localStorage entry that never leaves your device; kept until you delete it (strictly necessary, § 25(2) TDDDG).
Calendly on /demo: the scheduling widget loads only after you give the corresponding consent in our cookie banner; until then, the page does not connect to Calendly. When it loads, Calendly sets cookies needed for security and session handling inside the widget. We are responsible for embedding the widget on our page, and Calendly is responsible for its own subsequent processing (see Calendly’s privacy notice and its help article “Cookies and your Calendly experience”). If you prefer not to load the widget, you can request a demo at privacy@worklayer.ai instead.
Our Website does not respond to browser “Do Not Track” signals; the technologies we actually use are those listed above. Independently of our banner, your browser lets you block or delete cookies and site data for individual sites; note that blocking the strictly necessary items may prevent your consent choice from being saved.
Legal basis: your consent for non-essential technologies (Art. 6(1)(a) GDPR; § 25(1) TDDDG); § 25(2) TDDDG for the strictly necessary items above; our legal accountability obligations and legitimate interests for storing your consent decision (Art. 6(1)(c) and (f) GDPR).
3.3 Booking a demo
Demo appointments on our /demo page are scheduled through Calendly (Calendly LLC, USA), embedded on our page. When you book, you provide your first and last name, email address, phone number, and company size. Calendly processes this data on our behalf to schedule the meeting; we then use it to prepare for, conduct, and follow up on your demo and to respond to your questions. We send further marketing communications only with your consent or as otherwise permitted by law, and you can object to processing for direct-marketing purposes at any time, free of charge (Art. 21(2) GDPR), by emailing privacy@worklayer.ai or using the unsubscribe link in any message.
Legal basis: our legitimate interest in responding to and following up on business inquiries (Art. 6(1)(f) GDPR); where you book on your own behalf as a prospective contract party, also Art. 6(1)(b) GDPR (steps prior to entering into a contract, taken at your request).
3.4 Contacting us
If you contact us (for example, by email to one of the addresses in this policy), we process your name, contact details, and the content of your message to handle your inquiry. We share this data only where necessary to resolve your request, and keep it as described in Section 9.
Legal basis: our legitimate interest in responding to inquiries (Art. 6(1)(f) GDPR); Art. 6(1)(b) GDPR where your inquiry relates to entering into or performing a contract.
4. Data we collect when your company uses the Platform
4.1 Account and user data
When a Customer creates a Worklayer account and invites users, we process, as controller, the data needed to authenticate you and to secure and bill the Service: your name, work email address, and authentication identifiers. Sign-in is handled through our authentication provider, WorkOS; we never see or store your password.
We receive this data from your company when it creates your account (the source of the data within the meaning of Art. 14 GDPR); this policy is made available to you at your first sign-in. Your role, permissions, and profile settings within your company’s workspace are part of that workspace and are processed on your company’s behalf (see Section 6).
The Platform sets strictly necessary first-party cookies (the hris_session session cookie and a CSRF-protection cookie) to keep you signed in securely (§ 25(2) TDDDG); no tracking cookies are used on the Platform. Website cookies are described in Section 3.2.
Legal basis: our legitimate interest in providing and administering the contracted service to the Customer you act for (Art. 6(1)(f) GDPR); Art. 6(1)(b) GDPR where you are yourself our contract party (for example, a sole proprietor).
4.2 Billing data
Subscriptions are billed through Stripe. We store a billing reference (Stripe customer ID) and subscription status for the Customer organization. Payment card details are entered on Stripe-hosted pages and processed by Stripe; we never receive full card numbers.
Legal basis: performance of contract with respect to the Customer (Art. 6(1)(b) GDPR); our legitimate interest in complying with the tax, accounting, and bookkeeping obligations applicable to us (Art. 6(1)(f) GDPR); and Art. 6(1)(c) GDPR where EU or Member State law imposes such obligations on us.
4.3 Security, logs, and support
We process technical logs, audit trails, security events (e.g., sign-in events, administrative actions), and error diagnostics (including masked screen replays of sessions in which a technical error occurred, with content masked before it leaves your browser) to operate the Platform securely and fix defects. We also process the content of your communications with us when you contact support. Resolving a support request may require our staff to view relevant data in your company’s workspace; where that data is employee data, this access takes place on your company’s instructions under our DPA (Section 6). Retention periods are in Section 9.
Legal basis: legitimate interests (Art. 6(1)(f) GDPR) in the security and reliability of the Platform; performance of contract (Art. 6(1)(b) GDPR).
5. AI features: how the Platform uses AI
Worklayer’s core feature is AI agents that automate HR workflows (for example, preparing onboarding tasks, answering employee questions, or drafting routine HR communications). In plain terms:
- What happens: When an agent runs or a user chats with the assistant, relevant data from the Customer’s workspace, which can include employee records, is sent, together with the conversation or task context, to large language models to generate the response or carry out the workflow step.
- Which providers: We access models through OpenRouter, Inc. (USA) as an AI gateway, which routes requests to model providers, currently Anthropic PBC (USA) and Mistral AI SAS (France). The current list of model providers is available on request at privacy@worklayer.ai.
- No training on your data: We do not use your personal data to train AI models, and we contractually require our AI providers not to use it to train theirs.
- Records: Agent runs are logged (including the inputs and outputs of each step) so that Customers can audit what an agent did. These logs are part of the Customer’s workspace data and are controlled by the Customer.
- Human oversight: Customers configure what agents may do and remain responsible for employment decisions. Our Terms of Service require human review of AI output before decisions that significantly affect employees.
Where this processing concerns Customer employee data, it happens on the Customer’s behalf under our DPA (see Section 6). Worklayer does not, as controller, make automated decisions about you that produce legal or similarly significant effects (Art. 22 GDPR).
6. Employee data we process on behalf of Customers (processor role)
Customers use the Platform to manage their workforce and decide which data they enter. Depending on the features and fields a Customer enables, this typically includes:
- Identity and contact data: name, date of birth, nationality, contact details, address, emergency contacts;
- Employment data: position, department, manager, contract type and dates, workplace, employment status and history;
- Compensation and payroll data: salary, additional pay and benefits, bank details, and payroll identifiers required by applicable law (for example, in Germany: tax class, tax ID (Steuer-ID), social insurance number, and health insurance details);
- Special categories of data where employment law requires them (Art. 9 GDPR): for example church tax status (which can reveal religious affiliation) and health-related absence data such as sick leave; these are processed under the employment-law provisions of Art. 9(2)(b) GDPR in conjunction with § 26(3) BDSG, on the Customer’s responsibility;
- Time and absence data: working time entries including clock-in/clock-out records, schedules, vacation and other leave, and, where the Customer enables it, workplace geofencing settings used to validate clock-ins;
- Documents and signatures: employment documents and acknowledgment/signature records, including technical signature evidence such as timestamp and IP address;
- Expense data: receipts, amounts, trip details, and names of third-party attendees where entered;
- Custom fields the Customer defines, and records of AI agent activity in the Customer’s workspace.
For all of this data, your employer is the controller. Worklayer processes it under a DPA that implements Art. 28 GDPR, including confidentiality, security measures, sub-processor controls, and assistance with data subject rights. Our DPA and current sub-processor list are available to Customers and prospective Customers on request at privacy@worklayer.ai.
7. Who we share data with
We do not sell personal data. We share personal data with service providers that process it for us as processors under Art. 28 GDPR data processing agreements and, in a small number of cases marked below, with providers that act as independent controllers of the data they receive. We also disclose data where required by law (Section 7.3).
7.1 Website service providers
- Netlify, Inc. (USA): website hosting and serverless infrastructure (processor);
- Usercentrics A/S (Cookiebot) (Denmark, EU): cookie consent management (processor);
- Calendly LLC (USA): demo scheduling (processor).
7.2 Platform service providers
Where these providers handle Customer employee data, they act as sub-processors under our DPA with the Customer (see Section 6); where they handle data for which we are the controller, they act as our processors or, where marked, as independent controllers.
- WorkOS, Inc. (USA): sign-in and identity management (processor);
- Stripe, Inc. (USA): subscription billing and payments (independent controller for payment processing; see Stripe’s privacy notice);
- Resend, Inc. (USA): transactional email delivery (processor);
- OpenRouter, Inc. (USA): AI gateway for language-model requests (processor);
- Anthropic PBC (USA) and Mistral AI SAS (France, EU): AI model providers, engaged via OpenRouter (sub-processors);
- Amazon Web Services (S3) (per deployment region): file and document storage (processor);
- Functional Software, Inc. (Sentry) (USA): error monitoring and diagnostics, including masked screen replays of sessions in which an error occurred (processor);
- Google LLC (Maps) (USA): optional address autocomplete and distance calculation, invoked from your browser when you use address fields (independent controller; see Google’s privacy notice);
- OpenStreetMap Foundation (Nominatim) (UK/EU): optional map display and geocoding, invoked from your browser (independent controller; see OSMF’s privacy notice).
7.3 Other disclosures
We may disclose personal data if required by law, court order, or governmental request; to establish, exercise, or defend legal claims; or, in the event of a merger, acquisition, or asset sale, to the parties involved (we would notify you before your data becomes subject to a different privacy policy). In each case we limit any disclosure to what is necessary for the specific purpose and, where a request comes from a non-EU authority, we assess it against our GDPR obligations before responding.
8. International data transfers
We are based in the United States, and several of our service providers process data there. Where personal data of people in the EU/EEA is transferred to the US or other countries without an EU adequacy decision, we rely on:
- the European Commission’s adequacy decisions, including the EU–U.S. Data Privacy Framework for providers certified under it, and
- otherwise the EU Standard Contractual Clauses (SCCs) or other appropriate safeguards under Art. 46 GDPR.
Details of the mechanism applicable to a specific provider, and copies of the relevant safeguards, are available via privacy@worklayer.ai.
9. How long we keep data
- Website server logs: a short period, typically no more than 30 days (hosting provider log retention);
- Cookie consent records: 12 months (consent cookie); consent logs as required for accountability;
- Demo and sales contact data: up to 24 months after our last interaction with you, unless you ask us to delete it sooner or we enter into a contract;
- Customer account data: for the duration of the Customer’s contract; after termination, available for export during a 30-day window and deleted no later than 90 days after termination (see our Terms of Service);
- Platform security and audit logs: up to 12 months, then deleted or anonymized;
- Billing and tax records: as required by applicable tax and commercial law (typically up to 10 years);
- Support and inquiry correspondence: up to 24 months after the matter is resolved;
- Data subject request records: 2 years after the request is completed (accountability, Art. 5(2) GDPR);
- Customer employee data (processor role): as instructed by the Customer and per the DPA; on contract termination, deleted or returned per the DPA.
We may retain specific data for longer where the law requires it or, until the expiry of applicable limitation periods, where necessary to establish, exercise, or defend legal claims. Where deleted data persists in routine system backups, it is removed in the ordinary rotation of those backups and is not used for any other purpose in the meantime. When data is no longer needed, we delete or irreversibly anonymize it.
10. How we protect data
We apply technical and organizational measures appropriate to the risk, including encryption in transit (TLS), tenant isolation between Customer workspaces, role-based access controls, authentication via a dedicated identity provider, audit logging, and the principle of least privilege for our own staff access. No system is perfectly secure; if we become aware of a personal data breach affecting you, we will notify you and the competent authorities as required by Art. 33–34 GDPR.
If you believe you have found a security vulnerability, please report it to privacy@worklayer.ai.
11. Your rights
If you are in the EU/EEA, you have the following rights under the GDPR regarding personal data for which we are the controller:
- Access (Art. 15): obtain a copy of your data and information about its processing;
- Rectification (Art. 16): have inaccurate data corrected;
- Erasure (Art. 17): have your data deleted where the conditions are met;
- Restriction (Art. 18): restrict processing in certain cases;
- Data portability (Art. 20): receive your data in a structured, commonly used, machine-readable format;
- Objection (Art. 21): object to processing based on legitimate interests, and to direct marketing at any time;
- Withdraw consent (Art. 7(3)): at any time, with effect for the future, wherever processing is based on consent;
- Automated decisions (Art. 22): not to be subject to a decision based solely on automated processing, including profiling, that produces legal or similarly significant effects. As explained in Section 5, we do not make such decisions in our controller role; for decisions within your employer’s workspace, your employer is responsible (Section 6).
To exercise these rights, email privacy@worklayer.ai. We will respond within one month (Art. 12(3) GDPR) and may need to verify your identity first. Exercising your rights is free of charge; only for manifestly unfounded or excessive requests (in particular because of their repetitive character) may we charge a reasonable fee or decline to act (Art. 12(5) GDPR). We keep records of data subject requests and how we resolved them to demonstrate compliance (Art. 5(2), Art. 6(1)(c) and (f) GDPR); see Section 9 for the retention period.
Voluntary provision: providing personal data to us is voluntary; you are under no legal or contractual obligation to provide it. Without it, however, we cannot do the related thing: schedule your demo or answer your inquiry. For Platform accounts, your company decides which data it provides under its contract with us; without that data, we cannot give you access.
Right to complain: You can lodge a complaint with a data protection supervisory authority, in particular in the EU member state of your habitual residence or workplace. A list of EU authorities is available at edpb.europa.eu; in Germany, the authorities of the federal states (Länder) are competent.
If your data is in your employer’s Worklayer workspace, these rights apply against your employer as controller; contact them first; we assist them under our DPA.
If you are located outside the EU/EEA, you may have similar rights under your local law; contact us at privacy@worklayer.ai and we will handle your request accordingly.
12. Children
Our Website and Platform are business tools intended for use by companies and their personnel. They are not directed at children, and we do not knowingly collect data from anyone under 16 outside an employment context managed by a Customer.
13. Third-party links and our social media presence
The Website contains links to third-party sites. Their privacy practices are governed by their own policies, which we encourage you to read.
We also operate a company page on LinkedIn. When you visit or interact with it, LinkedIn processes your data under LinkedIn’s privacy policy. For the aggregated page statistics LinkedIn provides to us (“Page Insights”), we and LinkedIn Ireland Unlimited Company are joint controllers under LinkedIn’s Page Insights Joint Controller Addendum; we receive only aggregated statistics, never profiles of individual visitors. Please direct requests concerning your LinkedIn data to LinkedIn in the first instance; you can also contact us at privacy@worklayer.ai and we will forward or answer what we can.
14. Changes to this policy
We may update this policy from time to time, for example when we add features or service providers. We will post the updated version on this page and revise the “Last updated” date; for material changes affecting Platform users, we will notify Customers. Significant new processing purposes will not be applied to previously collected data without a valid legal basis. Previous versions of this policy are available from us on request.
15. Contact
Worklayer, Inc.
2810 N Church St, STE 89103
Wilmington, DE 19802, USA
Email: privacy@worklayer.ai