WorkDuty Privacy Policy & Data Protection Framework
Privacy Policy – WorkDuty Platform
Effective Date: January 1, 2024
Last Updated: January 15, 2024
Version: 3.1
1. Overview & Commitment
WorkDuty (“we,” “our,” or “us”) is committed to protecting your privacy and complying with global data protection regulations, including:
- South Africa: Protection of Personal Information Act (POPIA)
- European Union: General Data Protection Regulation (GDPR)
- United Kingdom: UK GDPR
- United States: CCPA/CPRA (California), VCDPA (Virginia), CPA (Colorado), etc.
- Canada: Personal Information Protection and Electronic Documents Act (PIPEDA)
- Australia: Privacy Act 1988 including Australian Privacy Principles
- Brazil: Lei Geral de Proteção de Dados (LGPD)
- Singapore: Personal Data Protection Act (PDPA)
We implement the highest common standard across all jurisdictions, ensuring POPIA compliance for South African users while meeting international requirements.
2. Definitions
| Term | Definition |
|---|---|
| Data Subject | Individual whose personal information is processed |
| Responsible Party | WorkDuty (determines purpose/manner of processing) |
| Operator | Third parties processing data on our behalf |
| Personal Information | Information relating to identifiable natural/jurisdictional person |
| Special Personal Information | Racial/ethnic origin, health, biometrics, etc. |
| Processing | Any operation on personal information |
3. Information We Collect
3.1 Information You Provide
- Account Information: Name, email, phone, company details
- Content Data: Tasks, projects, comments, files you upload
- Payment Information: Billing details (processed by PCI-DSS compliant providers)
- Communication Data: Support tickets, feedback, survey responses
3.2 Information Collected Automatically
- Usage Data: Features used, time spent, navigation patterns
- Device Information: Browser type, IP address, operating system
- Location Data: Country/region (for compliance purposes only)
- Cookies & Tracking: For functionality and analytics (with consent)
3.3 Information from Third Parties
- Integration Data: From connected services (Google, Microsoft, etc.)
- Client Data: When invited to client workspaces
- Marketing Data: From legitimate business sources (with consent)
4. Lawful Processing Conditions (POPIA Section 11)
We process personal information only under these lawful conditions:
4.1 Accountability (Section 8)
- Appointed Information Officer: privacy@workduty.com
- Regular POPIA compliance audits
- Employee training on data protection
4.2 Processing Limitation (Section 9)
- Minimality: Collect only what’s necessary
- Consent: Explicit consent obtained where required
- Direct Collection: From data subject when possible
4.3 Purpose Specification (Section 10)
We process data only for these specified purposes:
- Service provision and improvement
- Billing and account management
- Legal compliance
- Security and fraud prevention
- With additional consent: Marketing communications
4.4 Further Processing Limitation (Section 11)
Any further processing must be compatible with original purpose.
4.5 Information Quality (Section 12)
We maintain accurate, complete, and updated information.
4.6 Openness (Section 13)
This policy and related documents are publicly available.
4.7 Security Safeguards (Section 14)
- Technical: Encryption, access controls, regular testing
- Organizational: Data protection policies, employee training
- Physical: Secure data center access controls
4.8 Data Subject Participation (Section 15)
You have rights to:
- Access your personal information
- Request correction/deletion
- Object to processing
- File complaints with Information Regulator
5. International Data Transfers
5.1 Data Location
- Primary Storage: Chosen region during sign-up (ZA, EU, US, etc.)
- Backups: Within same region or approved jurisdictions
- Processing: Limited to countries with adequate protection
5.2 Transfer Mechanisms
- EU/UK: Standard Contractual Clauses (SCCs)
- South Africa: POPIA Section 72 compliance
- Other Regions: Adequacy decisions or binding corporate rules
5.3 Subprocessors
All subprocessors undergo security assessments and sign DPAs. Current list available at: subprocessors.workduty.online
6. Data Security Measures
6.1 Technical Security
- Encryption: AES-256 at rest, TLS 1.3 in transit
- Access Controls: Role-based, multi-factor authentication
- Network Security: Firewalls, intrusion detection, DDoS protection
- Application Security: Regular penetration testing, code reviews
- Backup & Recovery: Daily encrypted backups, disaster recovery plans
6.2 Organizational Security
- Employee Screening: Background checks for relevant roles
- Training: Annual data protection training
- Policies: Comprehensive security policies and procedures
- Incident Response: Documented breach response plan
6.3 Physical Security
- Data Centers: SOC 2 Type II certified facilities
- Access Controls: Biometric, 24/7 monitoring, visitor logs
- Redundancy: Multiple power, cooling, and network paths
7. Data Retention & Deletion
7.1 Retention Periods
| Data Type | Retention Period | Legal Basis |
|---|---|---|
| Active Accounts | Duration + 30 days | Contract |
| Inactive Accounts | 2 years after inactivity | Legitimate Interest |
| Financial Records | 7 years (tax compliance) | Legal Requirement |
| Audit Logs | 3 years | Legal/Compliance |
| Deleted Content | 30 days (recoverable) | Service Operation |
7.2 Deletion Procedures
- User-Initiated: Immediate soft delete, permanent after 30 days
- Account Closure: Complete deletion after retention period
- Legal Requests: Processed within 30 days
- Backup Rotation: Aligned with deletion schedules
8. Data Subject Rights
8.1 Access & Portability (POPIA Section 23)
- Right to confirm if we hold your information
- Right to access your information
- Right to receive in structured, commonly used format
8.2 Correction & Deletion (POPIA Section 24)
- Right to request correction of inaccurate information
- Right to request deletion (subject to legal requirements)
- Right to withdraw consent
8.3 Objections & Complaints (POPIA Section 25)
- Right to object to processing
- Right to lodge complaint with Information Regulator
- Right to institute civil proceedings
8.4 Automated Decision Making
- No solely automated decision-making with legal effects
- Human review available for all automated processes
8.5 Request Process
Submit requests to: privacy@workduty.online
Response time: 30 days (extendable with notice)
9. Special Categories of Information
9.1 Health Information (POPIA Section 26)
- Only processed with explicit consent
- Additional security measures applied
- Limited to necessary healthcare integrations
9.2 Children’s Information (POPIA Section 34)
- Not knowingly collected from under-18s
- Parental consent required if identified
- Immediate deletion upon discovery
9.3 Criminal Information (POPIA Section 30)
- Only processed by public bodies or with legal authorization
- Additional safeguards when permitted
10. Incident Response & Breach Notification
10.1 Internal Procedures
- Detection: 24/7 security monitoring
- Assessment: Impact analysis within 24 hours
- Containment: Immediate action to limit exposure
- Investigation: Root cause analysis
- Remediation: Corrective actions implemented
10.2 Notification Requirements
- Information Regulator (ZA): Within 72 hours of awareness
- Data Subjects: Without undue delay if high risk
- Other Authorities: As required by applicable laws
- Documentation: All breaches recorded per POPIA Section 22
11. Marketing & Communications
11.1 Consent Requirements
- Opt-in required for marketing communications
- Clear unsubscribe mechanism in all communications
- Preference centers for communication control
11.2 Direct Marketing Rules (POPIA Section 69)
- Notify data subject of right to object
- Maintain suppression lists
- Validate consent every 24 months
12. AI & Automated Processing
12.1 Our AI Approach
- No content analysis of sensitive business information
- Metadata-only processing for task suggestions
- No third-party AI data sharing
- Complete opt-out capabilities
12.2 Transparency
- AI decision explanations available
- Human override options
- Regular algorithmic bias testing
13. Third-Party Integrations
13.1 Integration Controls
- OAuth 2.0 authentication (no credential storage)
- Minimal permission scope
- User-controlled connection management
- Regular security assessments of major integrations
13.2 Shared Responsibility
- WorkDuty: Platform security and data protection
- Customer: Data classification and access management
- Integration Partners: Their own security and compliance
14. International Compliance Mapping
| Regulation | WorkDuty Compliance Feature |
|---|---|
| POPIA (ZA) | Information Officer, Section 11 compliance, Regulator reporting |
| GDPR (EU) | Data Protection Officer, Article 30 records, SCCs |
| CCPA/CPRA (US) | “Do Not Sell” option, consumer request portal |
| LGPD (BR) | Legal bases mapping, ANPD compliance |
| PIPEDA (CA) | Accountability, consent management |
| PDPA (SG) | Data protection officer appointment |
| APP (AU) | Cross-border disclosure controls |
15. Changes to This Policy
15.1 Update Process
- Review at least annually
- Significant changes: 30-day advance notice
- Current version always available at workduty.com/privacy
15.2 Notification Methods
- In-app notifications
- Email to account administrators
- Website banner for 30 days
- Revision history maintained
16. Contact Information
16.1 Data Protection Contacts
| Region | Contact | Responsibilities |
|---|---|---|
| Global | privacy@workduty.online | General privacy inquiries |
| South Africa | popia@workduty.online | POPIA-specific matters |
| European Union | dpo@workduty.online | GDPR compliance |
| Legal Requests | legal@workduty.online | Law enforcement requests |
16.2 Information Regulator (South Africa)
- Address: JD House, 27 Stiemens Street, Braamfontein, Johannesburg, 2001
- Complaints: complaints.IR@justice.gov.za
- General: inforeg@justice.gov.za
16.3 Physical Address
WorkDuty (Pty) Ltd
The Workspace
10 Fricker Road
Illovo, Johannesburg, 2196
South Africa
17. Acceptance & Consent
By using WorkDuty, you acknowledge that:
- You have read and understood this policy
- You consent to processing per this policy
- You will ensure team members comply
- You will maintain accurate account information
For EU/UK Users: Your continued use constitutes acceptance of our Data Processing Addendum (DPA) available at: workduty.online/data-processing-addendum-dpa/
18. Supplemental Policies
The following documents supplement this Privacy Policy:
- Data Processing Addendum (DPA): workduty.online/data-processing-addendum-dpa/
- Security Whitepaper: workduty.com/security
- Subprocessor List: workduty.com/subprocessors
- Cookie Policy: workduty.com/cookies
- Terms of Service: workduty.com/terms
19. Jurisdiction & Governing Law
This policy is governed by South African law for POPIA matters, with additional provisions for other jurisdictions as required. Any disputes shall be subject to the jurisdiction of South African courts, without prejudice to your rights under local laws.
Document Control:
Version: 3.1
Approved By: Legal & Compliance Committee
Review Date: July 1, 2024
Applicable To: All WorkDuty users globally
This response is AI-generated and for reference purposes only.