WorkDuty Privacy Policy & Data Protection Framework

Privacy Policy – WorkDuty Platform

Effective Date: January 1, 2024

Last Updated: January 15, 2024
Version: 3.1


1. Overview & Commitment

WorkDuty (“we,” “our,” or “us”) is committed to protecting your privacy and complying with global data protection regulations, including:

  • South Africa: Protection of Personal Information Act (POPIA)
  • European Union: General Data Protection Regulation (GDPR)
  • United Kingdom: UK GDPR
  • United States: CCPA/CPRA (California), VCDPA (Virginia), CPA (Colorado), etc.
  • Canada: Personal Information Protection and Electronic Documents Act (PIPEDA)
  • Australia: Privacy Act 1988 including Australian Privacy Principles
  • Brazil: Lei Geral de Proteção de Dados (LGPD)
  • Singapore: Personal Data Protection Act (PDPA)

We implement the highest common standard across all jurisdictions, ensuring POPIA compliance for South African users while meeting international requirements.


2. Definitions

TermDefinition
Data SubjectIndividual whose personal information is processed
Responsible PartyWorkDuty (determines purpose/manner of processing)
OperatorThird parties processing data on our behalf
Personal InformationInformation relating to identifiable natural/jurisdictional person
Special Personal InformationRacial/ethnic origin, health, biometrics, etc.
ProcessingAny operation on personal information

3. Information We Collect

3.1 Information You Provide

  • Account Information: Name, email, phone, company details
  • Content Data: Tasks, projects, comments, files you upload
  • Payment Information: Billing details (processed by PCI-DSS compliant providers)
  • Communication Data: Support tickets, feedback, survey responses

3.2 Information Collected Automatically

  • Usage Data: Features used, time spent, navigation patterns
  • Device Information: Browser type, IP address, operating system
  • Location Data: Country/region (for compliance purposes only)
  • Cookies & Tracking: For functionality and analytics (with consent)

3.3 Information from Third Parties

  • Integration Data: From connected services (Google, Microsoft, etc.)
  • Client Data: When invited to client workspaces
  • Marketing Data: From legitimate business sources (with consent)

4. Lawful Processing Conditions (POPIA Section 11)

We process personal information only under these lawful conditions:

4.1 Accountability (Section 8)

  • Appointed Information Officer: privacy@workduty.com
  • Regular POPIA compliance audits
  • Employee training on data protection

4.2 Processing Limitation (Section 9)

  • Minimality: Collect only what’s necessary
  • Consent: Explicit consent obtained where required
  • Direct Collection: From data subject when possible

4.3 Purpose Specification (Section 10)

We process data only for these specified purposes:

  • Service provision and improvement
  • Billing and account management
  • Legal compliance
  • Security and fraud prevention
  • With additional consent: Marketing communications

4.4 Further Processing Limitation (Section 11)

Any further processing must be compatible with original purpose.

4.5 Information Quality (Section 12)

We maintain accurate, complete, and updated information.

4.6 Openness (Section 13)

This policy and related documents are publicly available.

4.7 Security Safeguards (Section 14)

  • Technical: Encryption, access controls, regular testing
  • Organizational: Data protection policies, employee training
  • Physical: Secure data center access controls

4.8 Data Subject Participation (Section 15)

You have rights to:

  • Access your personal information
  • Request correction/deletion
  • Object to processing
  • File complaints with Information Regulator

5. International Data Transfers

5.1 Data Location

  • Primary Storage: Chosen region during sign-up (ZA, EU, US, etc.)
  • Backups: Within same region or approved jurisdictions
  • Processing: Limited to countries with adequate protection

5.2 Transfer Mechanisms

  • EU/UK: Standard Contractual Clauses (SCCs)
  • South Africa: POPIA Section 72 compliance
  • Other Regions: Adequacy decisions or binding corporate rules

5.3 Subprocessors

All subprocessors undergo security assessments and sign DPAs. Current list available at: subprocessors.workduty.online


6. Data Security Measures

6.1 Technical Security

  • Encryption: AES-256 at rest, TLS 1.3 in transit
  • Access Controls: Role-based, multi-factor authentication
  • Network Security: Firewalls, intrusion detection, DDoS protection
  • Application Security: Regular penetration testing, code reviews
  • Backup & Recovery: Daily encrypted backups, disaster recovery plans

6.2 Organizational Security

  • Employee Screening: Background checks for relevant roles
  • Training: Annual data protection training
  • Policies: Comprehensive security policies and procedures
  • Incident Response: Documented breach response plan

6.3 Physical Security

  • Data Centers: SOC 2 Type II certified facilities
  • Access Controls: Biometric, 24/7 monitoring, visitor logs
  • Redundancy: Multiple power, cooling, and network paths

7. Data Retention & Deletion

7.1 Retention Periods

Data TypeRetention PeriodLegal Basis
Active AccountsDuration + 30 daysContract
Inactive Accounts2 years after inactivityLegitimate Interest
Financial Records7 years (tax compliance)Legal Requirement
Audit Logs3 yearsLegal/Compliance
Deleted Content30 days (recoverable)Service Operation

7.2 Deletion Procedures

  • User-Initiated: Immediate soft delete, permanent after 30 days
  • Account Closure: Complete deletion after retention period
  • Legal Requests: Processed within 30 days
  • Backup Rotation: Aligned with deletion schedules

8. Data Subject Rights

8.1 Access & Portability (POPIA Section 23)

  • Right to confirm if we hold your information
  • Right to access your information
  • Right to receive in structured, commonly used format

8.2 Correction & Deletion (POPIA Section 24)

  • Right to request correction of inaccurate information
  • Right to request deletion (subject to legal requirements)
  • Right to withdraw consent

8.3 Objections & Complaints (POPIA Section 25)

  • Right to object to processing
  • Right to lodge complaint with Information Regulator
  • Right to institute civil proceedings

8.4 Automated Decision Making

  • No solely automated decision-making with legal effects
  • Human review available for all automated processes

8.5 Request Process

Submit requests to: privacy@workduty.online
Response time: 30 days (extendable with notice)


9. Special Categories of Information

9.1 Health Information (POPIA Section 26)

  • Only processed with explicit consent
  • Additional security measures applied
  • Limited to necessary healthcare integrations

9.2 Children’s Information (POPIA Section 34)

  • Not knowingly collected from under-18s
  • Parental consent required if identified
  • Immediate deletion upon discovery

9.3 Criminal Information (POPIA Section 30)

  • Only processed by public bodies or with legal authorization
  • Additional safeguards when permitted

10. Incident Response & Breach Notification

10.1 Internal Procedures

  • Detection: 24/7 security monitoring
  • Assessment: Impact analysis within 24 hours
  • Containment: Immediate action to limit exposure
  • Investigation: Root cause analysis
  • Remediation: Corrective actions implemented

10.2 Notification Requirements

  • Information Regulator (ZA): Within 72 hours of awareness
  • Data Subjects: Without undue delay if high risk
  • Other Authorities: As required by applicable laws
  • Documentation: All breaches recorded per POPIA Section 22

11. Marketing & Communications

11.1 Consent Requirements

  • Opt-in required for marketing communications
  • Clear unsubscribe mechanism in all communications
  • Preference centers for communication control

11.2 Direct Marketing Rules (POPIA Section 69)

  • Notify data subject of right to object
  • Maintain suppression lists
  • Validate consent every 24 months

12. AI & Automated Processing

12.1 Our AI Approach

  • No content analysis of sensitive business information
  • Metadata-only processing for task suggestions
  • No third-party AI data sharing
  • Complete opt-out capabilities

12.2 Transparency

  • AI decision explanations available
  • Human override options
  • Regular algorithmic bias testing

13. Third-Party Integrations

13.1 Integration Controls

  • OAuth 2.0 authentication (no credential storage)
  • Minimal permission scope
  • User-controlled connection management
  • Regular security assessments of major integrations

13.2 Shared Responsibility

  • WorkDuty: Platform security and data protection
  • Customer: Data classification and access management
  • Integration Partners: Their own security and compliance

14. International Compliance Mapping

RegulationWorkDuty Compliance Feature
POPIA (ZA)Information Officer, Section 11 compliance, Regulator reporting
GDPR (EU)Data Protection Officer, Article 30 records, SCCs
CCPA/CPRA (US)“Do Not Sell” option, consumer request portal
LGPD (BR)Legal bases mapping, ANPD compliance
PIPEDA (CA)Accountability, consent management
PDPA (SG)Data protection officer appointment
APP (AU)Cross-border disclosure controls

15. Changes to This Policy

15.1 Update Process

  • Review at least annually
  • Significant changes: 30-day advance notice
  • Current version always available at workduty.com/privacy

15.2 Notification Methods

  • In-app notifications
  • Email to account administrators
  • Website banner for 30 days
  • Revision history maintained

16. Contact Information

16.1 Data Protection Contacts

RegionContactResponsibilities
Globalprivacy@workduty.onlineGeneral privacy inquiries
South Africapopia@workduty.onlinePOPIA-specific matters
European Uniondpo@workduty.onlineGDPR compliance
Legal Requestslegal@workduty.onlineLaw enforcement requests

16.2 Information Regulator (South Africa)

  • Address: JD House, 27 Stiemens Street, Braamfontein, Johannesburg, 2001
  • Complaints: complaints.IR@justice.gov.za
  • General: inforeg@justice.gov.za

16.3 Physical Address

WorkDuty (Pty) Ltd
The Workspace
10 Fricker Road
Illovo, Johannesburg, 2196
South Africa


17. Acceptance & Consent

By using WorkDuty, you acknowledge that:

  1. You have read and understood this policy
  2. You consent to processing per this policy
  3. You will ensure team members comply
  4. You will maintain accurate account information

For EU/UK Users: Your continued use constitutes acceptance of our Data Processing Addendum (DPA) available at: workduty.online/data-processing-addendum-dpa/


18. Supplemental Policies

The following documents supplement this Privacy Policy:

  1. Data Processing Addendum (DPA): workduty.online/data-processing-addendum-dpa/
  2. Security Whitepaper: workduty.com/security
  3. Subprocessor List: workduty.com/subprocessors
  4. Cookie Policy: workduty.com/cookies
  5. Terms of Service: workduty.com/terms

19. Jurisdiction & Governing Law

This policy is governed by South African law for POPIA matters, with additional provisions for other jurisdictions as required. Any disputes shall be subject to the jurisdiction of South African courts, without prejudice to your rights under local laws.


Document Control:
Version: 3.1
Approved By: Legal & Compliance Committee
Review Date: July 1, 2024
Applicable To: All WorkDuty users globally

This response is AI-generated and for reference purposes only.

Select the fields to be shown. Others will be hidden. Drag and drop to rearrange the order.
  • Image
  • SKU
  • Rating
  • Price
  • Stock
  • Availability
  • Add to cart
  • Description
  • Content
  • Weight
  • Dimensions
  • Additional information
Click outside to hide the comparison bar
Compare