WorqSphere supports organizations with governance controls, role-based access, retention practices, and administrative workflows that can be aligned with GDPR and similar data protection requirements.
1. Roles under GDPR
When a customer organization uses WorqSphere to process identity and security information, that customer generally acts as the controller because it determines the purposes and means of processing. WorqSphere generally acts as a processor or service provider by processing information on behalf of the customer according to contractual instructions.
For information collected directly through our website, sales, support, billing, and product administration channels, WorqSphere may act as a controller for those limited processing purposes.
2. Lawful bases for processing
Depending on the context, processing may rely on contractual necessity, legitimate interests, legal obligations, consent, or other lawful bases recognized by applicable data protection law. Customer organizations are responsible for identifying and documenting the lawful basis for workplace processing they configure in the platform.
3. Data subject rights
Depending on location and context, individuals may have the following rights:
Right of access
Request confirmation of whether personal data is processed and obtain access to applicable information.
Right to rectification
Request correction of inaccurate or incomplete personal data.
Right to erasure
Request deletion of personal data where applicable legal conditions are met.
Right to restriction
Request restriction of processing in certain circumstances.
Right to portability
Request a copy of applicable personal data in a structured, commonly used format.
Right to object
Object to certain processing activities where applicable law provides this right.
4. How to submit a request
Individuals should generally contact the customer organization first for requests involving its records because that organization controls most processing decisions. Customers may contact WorqSphere for assistance in responding to valid requests.
Requests involving WorqSphere-controlled website, sales, support, or billing data can be sent to privacy@worqsphere.com.
5. Processor commitments
Where WorqSphere acts as a processor, we process customer data according to documented instructions, apply appropriate security measures, support customer compliance obligations where reasonably possible, and use approved subprocessors subject to contractual safeguards.
6. Security measures
WorqSphere applies administrative, technical, and organizational controls designed to protect personal data. These may include controlled access, encryption in transit, monitoring, audit logging, secure infrastructure practices, and internal governance procedures.
7. Retention and deletion
Personal data is retained according to customer configuration, contractual obligations, legal requirements, and operational needs. Customers may request deletion or export of certain records subject to applicable retention requirements and technical limitations.
8. International transfers
Where personal data is transferred internationally, WorqSphere uses appropriate safeguards where required, which may include contractual commitments, transfer risk assessment practices, and security controls.
9. Contact and supervisory authority
For GDPR or data protection questions, contact privacy@worqsphere.com. Individuals may also have the right to lodge a complaint with a competent supervisory authority.
Need a data protection review?
Contact WorqSphere to discuss GDPR alignment, processor support, and customer data governance requirements.