Data Processing Agreement
Subject and parties
This agreement sets out the mutual obligations of the customer using Workinno and of Workinno regarding personal data processed while the service is used. The customer is the controller and Workinno is the processor. It falls under Article 28 of the EU General Data Protection Regulation and forms an integral part of the service agreement.
Scope of processing
Workinno processes personal data only to provide the service. The data processed is what the customer enters into their own workspace: employee details, customer and supplier records, communication history, documents and accounting entries. Processing lasts for as long as the customer uses the service.
Acting only on instructions
Workinno does not use this data for its own purposes, does not sell it to third parties and does not process it for advertising. If a legal obligation arises, Workinno informs the customer beforehand, unless the notification itself is prohibited.
Confidentiality
Every Workinno employee with access to the data is bound by confidentiality, and access is limited to what their role requires.
Security measures
TLS 1.2 or higher in transit, Argon2id for passwords, role and permission based access control, isolation of each workspace's data from every other, record level activity history, regular backups and restore drills are in place. Backups are stored encrypted.
Sub-processors
The service is delivered with the providers listed below. When a new sub-processor is added, the customer is informed beforehand and may object.
| Provider | Used for | Location |
|---|---|---|
| Hetzner | Servers, database and file storage | Germany (Nuremberg) |
| Cloudflare | Domain, security and delivery | European Union / USA |
| Stripe | Payments | European Union / USA |
| Resend | Email delivery | European Union / USA |
| Twilio | SMS and voice | European Union / USA |
| Meta | WhatsApp, Instagram, Messenger and lead ads | European Union / USA |
| Calendar and email connection | European Union / USA | |
| Anthropic, OpenAI | AI assistant | USA |
| Sentry | Error monitoring | European Union |
| Mapbox | Maps | USA |
| MaxMind | Location lookup | USA |
International transfers
Customer data is held on a server in Germany, and the documents you upload are stored in the same country. Where one of the providers above requires a transfer outside the European Economic Area, the European Commission's standard contractual clauses apply.
Data subject requests
If someone asks for their data to be deleted, corrected or copied, Workinno does not answer that request itself. It passes the request to the customer and provides the technical support the customer needs to fulfil it.
Breach notification
When a personal data breach becomes known, the customer is notified without delay and within 24 hours at the latest. The notice covers the nature of the breach, the types of data affected and the measures taken. The window is deliberately short: the customer has their own 72 hours to notify the supervisory authority.
Deletion and return
A deleted record stays in the trash for 30 days and files for 7 days by default, and can be restored within that time. When the service ends, the customer can export a copy of their data; on request the data is deleted.
Audit and information
The customer may request the information needed to verify compliance with this agreement. Workinno keeps its security measures and sub-processor list up to date.

