This document is not final. WorkPilot is not yet trading and the company registration details are still to be filled in. Nothing may be sold under it in this state.
WorkPilot
Legal

Privacy Notice

In effect from —

This notice explains what personal data we handle, on what basis, and what rights you have. It covers the WorkPilot application and this website.

1. Two different roles, and why the difference matters

WorkPilot handles personal data in two capacities, and which one applies decides who you should ask about what.

We are the controller
for the people who sign up and run a company on WorkPilot — the owner and managers. Their contact details, billing records and usage of the service are ours to answer for. Ask us directly.
We are a processor
for everything a company records about its own workforce: hours, check-in photographs, locations, pay rates, leave, expenses. The employer is the controller of all of it. If you are a worker asking why your employer records something, ask your employer — and we will help them answer you.

2. Who we are

[LEGAL NAME], [ADDRESS], Italy, VAT number [VAT NUMBER]. For anything in this notice, write to privacy@wrkpilot.com.

We have not appointed a Data Protection Officer. We are not a public authority, we do not monitor people on a large scale, and we do not process special categories of data on a large scale, so Article 37 does not require one.

3. What we hold, and why we are allowed to

Your account — name, email address, language, role
To give you an account and let you sign in. Basis: performance of the contract with your company.
Your company — name, address, VAT number, currency
To identify the customer, invoice correctly and apply the right VAT treatment. Basis: contract, and our legal obligation to keep proper tax records.
Billing — subscription, payments, invoices
To take payment and account for it. Basis: contract, and legal obligation. Card details are handled by Stripe and never reach us.
Workforce records — hours, shifts, check-in photographs, locations, pay rates, leave, expenses, messages
Held on behalf of the employer, who decides why. Basis: whatever the employer has established. We process it only on their instructions.
Technical records — sign-in events, error reports, security logs
To keep the service working and to find out when it breaks. Error reports carry the message, a truncated stack trace, the screen you were on and your user id — not the contents of your records. Basis: our legitimate interest in a service that works and is secure.

4. What we do not do

5. Where it is kept

Your data is stored in Zurich, Switzerland. Switzerland is not in the European Economic Area, but it holds a European Commission adequacy decision, so no additional transfer safeguards are needed for it.

Our payment processor transfers some data to the United States under the EU-US Data Privacy Framework and standard contractual clauses. Every other provider we use keeps the data in Europe. The full list is on our sub-processors page.

6. Who else sees it

Only the providers that make the service run, listed on our sub-processors page, each under a contract that binds them to the same terms. We will also disclose data where the law genuinely requires it — and where we may lawfully tell you that we have been asked, we will.

7. How long we keep it

8. Your rights

You may ask for a copy of your data, ask us to correct it, ask us to delete it, ask us to restrict or stop a particular use, and ask for it in a portable form. Where we rely on legitimate interest, you may object.

Write to privacy@wrkpilot.com. We will answer within one month. If your request is about workforce records, we will pass it to your employer, who is the controller of them, and help them respond.

If you are not satisfied you may complain to a supervisory authority — in Italy the Garante per la protezione dei dati personali, in Sweden Integritetsskyddsmyndigheten (IMY), or the authority where you live.

9. Security

Access to a company's data is enforced in the database itself rather than by hiding screens: one company cannot read another's records, and within a company a worker cannot open a colleague's record or see their pay rate. Data is encrypted in transit and at rest, and administrative access is limited to what is needed to operate the service.

No system is beyond compromise. If a breach occurs that is likely to put people at risk, we will notify the supervisory authority within seventy-two hours and tell affected customers without undue delay.

10. Changes to this notice

If we change this notice materially we will tell account holders by email before the change takes effect. The date it came into force is at the top of this page.