Privacy Notice
In effect from —
This notice explains what personal data we handle, on what basis, and what rights you have. It covers the WorkPilot application and this website.
1. Two different roles, and why the difference matters
WorkPilot handles personal data in two capacities, and which one applies decides who you should ask about what.
- We are the controller
- for the people who sign up and run a company on WorkPilot — the owner and managers. Their contact details, billing records and usage of the service are ours to answer for. Ask us directly.
- We are a processor
- for everything a company records about its own workforce: hours, check-in photographs, locations, pay rates, leave, expenses. The employer is the controller of all of it. If you are a worker asking why your employer records something, ask your employer — and we will help them answer you.
2. Who we are
[LEGAL NAME], [ADDRESS], Italy, VAT number [VAT NUMBER]. For anything in this notice, write to privacy@wrkpilot.com.
We have not appointed a Data Protection Officer. We are not a public authority, we do not monitor people on a large scale, and we do not process special categories of data on a large scale, so Article 37 does not require one.
3. What we hold, and why we are allowed to
- Your account — name, email address, language, role
- To give you an account and let you sign in. Basis: performance of the contract with your company.
- Your company — name, address, VAT number, currency
- To identify the customer, invoice correctly and apply the right VAT treatment. Basis: contract, and our legal obligation to keep proper tax records.
- Billing — subscription, payments, invoices
- To take payment and account for it. Basis: contract, and legal obligation. Card details are handled by Stripe and never reach us.
- Workforce records — hours, shifts, check-in photographs, locations, pay rates, leave, expenses, messages
- Held on behalf of the employer, who decides why. Basis: whatever the employer has established. We process it only on their instructions.
- Technical records — sign-in events, error reports, security logs
- To keep the service working and to find out when it breaks. Error reports carry the message, a truncated stack trace, the screen you were on and your user id — not the contents of your records. Basis: our legitimate interest in a service that works and is secure.
4. What we do not do
- We do not sell personal data, and we never will.
- We do not use it for advertising, and we run no advertising or analytics trackers. That is why this site has no cookie banner: the only cookies are the ones that keep you signed in, and those need no consent.
- We do not use your data, or your workers' data, to train AI models. The written insights in the dashboard are generated on request from your own figures and are not retained for training by the provider.
- We do not build profiles of individuals, and no decision with a legal or similarly significant effect on anybody is made automatically.
5. Where it is kept
Your data is stored in Zurich, Switzerland. Switzerland is not in the European Economic Area, but it holds a European Commission adequacy decision, so no additional transfer safeguards are needed for it.
Our payment processor transfers some data to the United States under the EU-US Data Privacy Framework and standard contractual clauses. Every other provider we use keeps the data in Europe. The full list is on our sub-processors page.
6. Who else sees it
Only the providers that make the service run, listed on our sub-processors page, each under a contract that binds them to the same terms. We will also disclose data where the law genuinely requires it — and where we may lawfully tell you that we have been asked, we will.
7. How long we keep it
- Account and workforce records: for as long as the company uses WorkPilot, and ninety days after it stops, so that it can be recovered or exported.
- Invoices and tax records: ten years, because Italian tax law requires it.
- Check-in photographs: as long as the employer's own retention setting says, and no longer than the attendance record they belong to.
- Error and security logs: ninety days.
8. Your rights
You may ask for a copy of your data, ask us to correct it, ask us to delete it, ask us to restrict or stop a particular use, and ask for it in a portable form. Where we rely on legitimate interest, you may object.
Write to privacy@wrkpilot.com. We will answer within one month. If your request is about workforce records, we will pass it to your employer, who is the controller of them, and help them respond.
If you are not satisfied you may complain to a supervisory authority — in Italy the Garante per la protezione dei dati personali, in Sweden Integritetsskyddsmyndigheten (IMY), or the authority where you live.
9. Security
Access to a company's data is enforced in the database itself rather than by hiding screens: one company cannot read another's records, and within a company a worker cannot open a colleague's record or see their pay rate. Data is encrypted in transit and at rest, and administrative access is limited to what is needed to operate the service.
No system is beyond compromise. If a breach occurs that is likely to put people at risk, we will notify the supervisory authority within seventy-two hours and tell affected customers without undue delay.
10. Changes to this notice
If we change this notice materially we will tell account holders by email before the change takes effect. The date it came into force is at the top of this page.