Skip to main content

Data Processing Agreement

Subject and parties

This agreement sets out the mutual obligations of the customer using Workinno and of Workinno regarding personal data processed while the service is used. The customer is the controller and Workinno is the processor. It falls under Article 28 of the EU General Data Protection Regulation and forms an integral part of the service agreement.

Scope of processing

Workinno processes personal data only to provide the service. The data processed is what the customer enters into their own workspace: employee details, customer and supplier records, communication history, documents and accounting entries. Processing lasts for as long as the customer uses the service.

Acting only on instructions

Workinno does not use this data for its own purposes, does not sell it to third parties and does not process it for advertising. If a legal obligation arises, Workinno informs the customer beforehand, unless the notification itself is prohibited.

Confidentiality

Every Workinno employee with access to the data is bound by confidentiality, and access is limited to what their role requires.

Security measures

TLS 1.2 or higher in transit, Argon2id for passwords, role and permission based access control, isolation of each workspace's data from every other, record level activity history, regular backups and restore drills are in place. Backups are stored encrypted.

Sub-processors

The service is delivered with the providers listed below. When a new sub-processor is added, the customer is informed beforehand and may object.

ProviderUsed forLocation
HetznerServers, database and file storageGermany (Nuremberg)
CloudflareDomain, security and deliveryEuropean Union / USA
StripePaymentsEuropean Union / USA
ResendEmail deliveryEuropean Union / USA
TwilioSMS and voiceEuropean Union / USA
MetaWhatsApp, Instagram, Messenger and lead adsEuropean Union / USA
GoogleCalendar and email connectionEuropean Union / USA
Anthropic, OpenAIAI assistantUSA
SentryError monitoringEuropean Union
MapboxMapsUSA
MaxMindLocation lookupUSA

International transfers

Customer data is held on a server in Germany, and the documents you upload are stored in the same country. Where one of the providers above requires a transfer outside the European Economic Area, the European Commission's standard contractual clauses apply.

Data subject requests

If someone asks for their data to be deleted, corrected or copied, Workinno does not answer that request itself. It passes the request to the customer and provides the technical support the customer needs to fulfil it.

Breach notification

When a personal data breach becomes known, the customer is notified without delay and within 24 hours at the latest. The notice covers the nature of the breach, the types of data affected and the measures taken. The window is deliberately short: the customer has their own 72 hours to notify the supervisory authority.

Deletion and return

A deleted record stays in the trash for 30 days and files for 7 days by default, and can be restored within that time. When the service ends, the customer can export a copy of their data; on request the data is deleted.

Audit and information

The customer may request the information needed to verify compliance with this agreement. Workinno keeps its security measures and sub-processor list up to date.

Data Processing Agreement — Workinno