Pre-launch notice. Accounts and operational Coworker services are not active yet. This draft must be completed against the actual product, vendors, and legal entity before personal information is collected through the service.
The public site now
The current site presents product information. Its hosting and security providers may receive technical request information such as IP address, browser and device data, requested pages, timestamps, and diagnostic events needed to deliver and protect the site.
The public site does not currently provide an account, connected Coworker, payment flow, contact form, or marketing subscription. If analytics or other optional tracking is added, this notice and any required consent controls must be updated first.
The product later
An operational service is expected to handle categories such as:
- account, identity, organization, membership, and support information;
- conversations, instructions, files, work items, results, and feedback;
- roles, responsibilities, capabilities, approvals, and decision receipts;
- connected-channel identifiers and credentials held through purpose-bound secret storage;
- usage, reliability, security, and billing information where applicable.
Purposes and legal bases
Before launch, each processing purpose will be mapped to a legal basis. Expected purposes include providing the requested service, authenticating users, enforcing permissions, preserving accountable work records, securing the platform, supporting customers, meeting legal duties, and improving reliability. Consent will be used where the law requires a genuine choice rather than as a blanket basis for operating the service.
Retention
Retention periods are not yet fixed. They must distinguish account data, active work, immutable decision and evidence records, security logs, backups, billing records, and customer-directed deletion. The final notice will explain the periods or the criteria used to determine them.
Your rights
Depending on where you live and the processing involved, you may have rights to information, access, correction, deletion, restriction, portability, objection, withdrawal of consent, and human review of certain solely automated decisions. The effective notice will explain how to exercise those rights and how to contact the relevant supervisory authority.
Before this notice becomes effective
The final version still needs to identify and verify:
- the controller’s legal name, address, privacy contact, and any data protection officer;
- the production data inventory, purposes, legal bases, recipients, and subprocessors;
- international transfer mechanisms, retention schedules, and deletion behavior;
- cookie and analytics behavior, children’s access rules, and incident contacts;
- the exact process for rights requests and complaints.
See the European Commission’s overview of individual data-protection rights.