Protecting your data and privacy
Worksphere is committed to ensuring the security and privacy of the data we are entrusted to protect
We are strongly committed to transparency in how we collect and use your personal information.
Where applicable, a separate agreement may govern the delivery, access, and use of the Platform, Services and Mobile Apps (the “Client Agreement”), including the processing of Personal Information and data submitted through employer-based accounts (“Clients”). The Client that entered into the Client Agreement with Worksphere may authorize us to collect, process, and store your personal information and associated Client data. If you have any questions about specific Platform settings or what information Worksphere has been authorized by Client to process on your behalf, you may contact Worksphere at the contact information in this notice or your Client administrator for the Platform you use.
- Personal Information. When using the Site, Platform, or Services, you or your employer may choose to provide us with certain Personal Information, such as your name, photograph, employment details, email address, phone number, date of birth and other contact information. This information is used to: (i) provide login information to the Platform as well as to carry out Platform processing functions and the Services Worksphere has been contracted to provide by Client; (ii) communicate with you by responding to your requests, comments and questions; (iii) improve the Site; and (iv) perform various account functions provided by Worksphere. The GDPR legal basis for processing this information is: (a) the legitimate interest in communicating with you and improving our Site; and (b) the contractual obligation to perform the Services.
- Contact Information. When you express an interest in obtaining additional information about the Site, Platform, or Services, Worksphere may ask you or your employer to provide your personal contact information, such as your name, email address, and phone number. This information is used to communicate with you by responding to your requests, comments, and questions. The GDPR legal basis for processing this information is the legitimate interest in communicating with you and answering your questions.
- Health Information. When using the Site, Platform, or Services, you or your employer may choose to provide us with certain Health Information, such as your general health situation, and your health related to COVID-19, including vaccination status. This information is used to: (i) carry out Platform processing functions and the Services Worksphere has been contracted to provide by Client; (ii) communicate with you by responding to your requests, comments, and questions. The GDPR legal basis for processing this information is: (a) the legitimate interest in communicating with you and improving our Site; and (b) the contractual obligation to perform the Services. Health Information in addition to Personal Information is collectively referred to as “Personal Information.”
- Location Information. Worksphere may also request access to or otherwise receive information about your device location when you access the Services. Your location data may be based on your IP address and other location-aware technologies. Personally identifiable location data is only used with your consent. The GDPR legal basis for processing this information is the legitimate interest in providing location-based Services and in improving the relevance of our Site.
- Log Data. As is true of most websites and platforms, we gather certain information automatically. This information may include Internet protocol (IP) addresses, browser type, Internet service provider (ISP), referring/exit pages, the files viewed on our site (e.g., HTML pages, graphics, etc.), operating system, date/time stamp, and/or clickstream data to analyze trends in the aggregate and administer the site. The GDPR legal basis for processing this information is the legitimate interest in improving the relevance of our Site.
- Single Sign-On. You can log in to our Platform using sign-in services such as Log in With Google. These services will authenticate your identity and provide you the option to share certain Personal Information with us such as your name and email address to pre-populate our sign-up form.
- Blog, Testimonials, and Referrals. Our Site offers publicly accessible blogs or community forums. You should be aware that any information you provide in these areas may be read, collected, and used by others who access them. We display personal testimonials of satisfied customers on our Site in addition to other endorsements. With your consent, we may post your testimonial along with your name. In addition to your other rights, if you wish to update or delete your testimonial, you can contact us at [email protected] If you choose to use our referral service to tell a friend about our Site, we will ask you for your friend’s name and email address. You must have the consent of your friend before using this service. We will automatically send your friend a one-time email inviting them to visit the Site. Worksphere stores this information for the sole purpose of sending this one-time email and tracking the success of our referral program In addition to their other rights, your friend may contact us at [email protected] to request that we remove this information from our database. The GDPR legal basis for processing this information is your consent.
- Information Related to Data Collected for Our Clients Collection and use in Providing the Services. When acting as a service provider, Worksphere collects information under the direction of its Clients. The Client Agreement may govern the delivery, access, and use of the Platform and Services, including the processing of Personal Information and data submitted through Client accounts. The Client (e.g., your employer) controls their Platform and any associated Client data. If you have any questions about specific Platform settings, the processing of Personal Information in the Platform, or its privacy practices, please contact the Client administrator of the Platform you use.
- Worksphere also uses other information in furtherance of our legitimate interests in operating our Site, Platform, and Services.
Worksphere is not in the business of selling your information. We consider this information to be a vital part of our relationship to you. There are, however, certain circumstances in which we may share your Personal Data with certain third parties without further notice to you, as set forth below:
- Third Party Services. At times, you may be able to access other Third-Party Services through the Site, for example by clicking on links to those Third-Party Services from within the Site. Worksphere is not responsible for the privacy policies and/or practices of these Third-Party Services, and you or your employer acting as a Worksphere Client are responsible for reading and understanding those Third-Party Services’ privacy policies.
We require all third parties to respect the security of your Personal Information and to treat it in accordance with applicable laws. We may share your data with third-party vendors, service providers, contractors or agents who perform services for us or on our behalf and require access to such information to do that work. Examples include: payment processing, data analysis, email delivery, hosting services, customer service and marketing efforts. We may allow selected third parties to use tracking technology on the Website, which will enable them to collect data on our behalf about how you interact with our Website over time. This information may be used to, among other things, analyze and track data, determine the popularity of certain content, pages or features, and better understand online activity. Unless described in this notice, we do not share, sell, rent or trade any of your information with third parties for their promotional purposes. We have contracts in place with our data processors, which are designed to help safeguard your personal information. This means that they cannot do anything with your personal information unless we have instructed them to do it. They will also not share your personal information with any organization apart from us. They also commit to protect the data they hold on our behalf and to retain it for the period we instruct.
We will retain your Personal Information and the Personal Information we process on behalf of our Clients for as long as your account is active or as needed to provide Services to our Clients in accordance with Worksphere data retention policies, and as necessary to comply with our legal obligations, resolve disputes, and enforce our agreements.
The security of your Personal Information and our Clients’ information is important to us. We put in place appropriate technical and organizational measures to ensure your Personal Information is kept secure and protected from unauthorized access, use, disclosure, alteration or destruction, in accordance with applicable laws and regulations. When you enter sensitive information (such as login credentials), we encrypt the transmission of that information using Transport Layer Security (TLS). We follow generally accepted standards to protect the Personal Information submitted to us, both during transmission and once we receive it. When we share your Personal Information with Sub-Processors or other third-party service providers, we base our selection on said parties having adequate safeguards in place that meet our data protection standards. We may audit their compliance with such standards and incorporate contractual provisions ensuring compliance with (i) such standards and (ii) applicable data privacy laws and regulations.
If you have any questions about security on our Site, you can contact us at [email protected]
In addition to the lawful transfer, processing and storage of your Personal Information, the GDPR gives certain European Union members additional rights over our use of your Personal Information. Worksphere respects your control over your information and, in the event that you have provided Personal Information to us in your use of the Site, we will provide you with information about whether we hold any of your Personal Information as we detail below. You may access, correct, or request deletion of your Personal Information by contacting us at [email protected] if applicable. We will respond to your request within a reasonable timeframe.
As a preliminary matter, when acting as a service provider of our Clients, Worksphere may have no direct relationship with the individuals whose Personal Information is provided to Worksphere through the Platform and Services. An individual who is or was employed by one of our Clients and who seeks access to, or who seeks to correct, amend, object to the processing or profiling of, or to delete their Personal Information in the Platform, should direct the query to their employer’s HR department if they cannot make the appropriate changes via its access to the Platform provided by the Client.
In some regions (like the European Economic Area “EEA”), you have certain rights under applicable data protection laws. These may include:
- Right of Access. You can request details of your Personal Information we hold. We will confirm whether we are processing your Personal Information and we will disclose additional information including the types of Personal Information, the sources it originated from, the purpose and legal basis for the processing, the expected retention period and the safeguards regarding data transfers to non-EEA countries, subject to the limitations set out in applicable laws and regulations. We will provide you free of charge with a copy of your Personal Information but we may charge you a fee to cover our administrative costs if you request further copies of the same information.
- Right of correction. At your request, we will correct incomplete or inaccurate parts of your Personal Information, although we may need to verify the accuracy of the new information you provide to us.
- Right to be forgotten. At your request, we will delete your Personal Information if:
- it is no longer necessary for us to retain your Personal Information;
- you withdraw the consent which formed the legal basis for the processing of your Personal Information;
- you object to the processing of your Personal Information (see below) and there are no overriding legitimate grounds for such processing;
- the Personal Information was processed illegally;
- the Personal Information must be deleted for us to comply with our legal obligations.
We will decline your request for deletion if processing of your Personal Information is necessary: (i) for us to comply with our legal obligations; (ii) for the establishment, exercise or defense of legal claims; or (iii) for the performance of a task in the public interest.
- Right to restrict processing. At your request, we will restrict the processing of your Personal Information if:
- you dispute the accuracy of your Personal Information;
- your Personal Information was processed illegally and you request a limitation on processing rather than the deletion of your Personal Information;
- we no longer need to process your Personal Information, but you need your Personal Information in connection with the establishment, exercise or defense of a legal claim; or
- you object to the processing of your Personal Information (see below) pending verification as to whether an overriding legitimate ground for such processing exists.
- We may continue to store your Personal Information to the extent required to ensure that your request to restrict processing is respected in the future.
- Right to data portability. If applicable, at your request, we will provide you free of charge with your Personal Information in a structured, commonly used and machine readable format, if:
- you provided us with your Personal Information;
- the processing of your Personal Information is required for the performance of a contract; or
- the processing is carried out by automated means.
- Right to object. Where we rely on our legitimate interests (or that of a third party) to process your Personal Information, you have the right to object to this processing on grounds relating to your particular situation if you feel it impacts on your fundamental rights and freedoms. we will comply with your request unless we have compelling legitimate grounds for the processing which override your rights and freedoms, or where the processing is in connection with the establishment, exercise or defense of legal claims. We will always comply with your objection to processing your Personal Information for direct marketing purposes.
- Right not to be subject to decisions based solely on automated processing.
You will not be subject to decisions with a legal or similarly significant effect (including profiling) that are based solely on the automated processing of your Personal Information, unless you have given us your explicit consent or where they are necessary for the performance of a contract with us.
- Right to withdraw consent. You have the right to withdraw any consent you may have previously given us at any time. In order to exercise your rights in this section we may ask you for certain identifying information to ensure the security of your Personal Information. To request to exercise any of the above rights, please contact us at [email protected]. We will respond to your request within 30 days or provide you with reasons for the delay.
Usually, we will not charge you any fees in connection with the exercise of your rights. If your request is manifestly unfounded or excessive, for example, because of its repetitive character, we may charge a reasonable fee, taking into account the administrative costs of dealing with your request. If we refuse your request we will notify you of the relevant reasons.
In so far as practicable, we will notify our Clients and third parties to whom we have disclosed your Personal Information with any correction, deletion, and/or restriction to the processing of your Personal Information. Please note that we cannot guarantee our Clients or other third parties will comply with your requests and we encourage you to contact them directly.
Please note that if you decide to exercise some of your rights, we may be unable to perform the actions necessary to achieve the purposes set out above or you may not be able to use or take full advantage of the Site, Platform, and Services.
If you are a resident of the European Economic Area and are not satisfied with our response, you also have the right to complain or seek advice from your local data protection supervisory authority.
You may choose to opt in to receive occasional email and other communications from us, such as communications relating to promotions. You may opt out of receiving such communications at any time by using the “Unsubscribe” link found in such emails, or by emailing us at [email protected] In the context of us providing you marketing, we may analyze your preferences to make sure the information we provide you is relevant.
California residents have certain privacy rights as specified under California law, including the California Consumer Privacy Act of 2018 (“CCPA”). If you are a resident of California, you have the right to know what personal information has been collected about you, and to access that information. You have the right to request deletion of your personal information, though exceptions under the CCPA may allow Worksphere to retain and use certain personal information notwithstanding your deletion request.
Worksphere collects various categories of personal information when you or your employer use the Worksphere Platform or Services, including log data, health information, and personal information related to your employment. A more detailed description of the information Worksphere collects and how we use it is provided above in the sections entitled: ‘Information We Collect’ and ‘How, and With Whom, Your Information Is Shared.’
In addition to our collection of your Personal Information, Worksphere may engage certain third parties to perform a function or provide services to you on behalf of Worksphere including hosting and maintenance, error monitoring, debugging, performance monitoring, billing, customer and account relationship management, database storage and management, and direct marketing campaigns. Worksphere may share your Personal Information with these third parties, but only to the extent necessary to perform these functions and provide such services. Worksphere requires these third parties to maintain the privacy and security of the Personal Information they process on our behalf.
Worksphere does not sell your Personal Information when you use the Worksphere Platform or when you use a Worksphere Service and will not do so in the future without providing you with notice and an opportunity to opt-out of such sale as required by law. Worksphere does not offer financial incentives associated with the collection, use, or disclosure of your personal information.
Worksphere will not discriminate against you for exercising any of your CCPA rights. To this end, unless permitted by the CCPA, Worksphere will not:
- Deny you access to the Worksphere Platform or Services;
- Charge you a different price or rate for the Platform or Services, including the granting of discounts or other incentives;
- Provide a different or downgraded Platform or Service;
- Suggest that you may receive a different price or rate for the Worksphere Platform or its Services or a different or downgraded Platform or Service;
To exercise your rights under the CCPA please submit a verifiable consumer request to Worksphere by emailing us at [email protected] Only you, or a person registered with the California Secretary of State that you authorize to act on your behalf, may make a verifiable consumer request related to your personal information. You may only make a verifiable consumer request for access to your data twice within a twelve (12) month period. Your verifiable consumer request must:
- Be made by a natural person;
- Provide sufficient information to allow Worksphere to reasonably verify your identity and that you are the person about whom we collected personal information, or you are an authorized representative;
- Describe your request with sufficient detail that allows Worksphere to properly understand, evaluate, and respond to your request.
In certain cases, Worksphere collects and processes personal information on you at the contractual obligation of your employer. In order to respond to a verified request, Worksphere may be required to provide notice to your employer of your request, and to follow your employer’s instructions as they relate to carrying out your request. Worksphere cannot respond to your request or provide you with personal information if we cannot verify your identity or authority to make the request and confirm that the personal information relates to you. Making a verifiable request does not require you to create an account, but we may ask you to verify your request by logging into your account if you have one. We will only use personal information provided by a verifiable consumer request to verify the requestor’s identity or authority to make the request.