Privacy Policy

As the operators of the Workable websites, www.workable.com and jobs.workable.com (“Website”) Workable Software Limited registered in England and Wales with Company Registration Number 08125469 and having its registered office address at 5 Golden Square, 5th Floor, London, W1F 9BS, United Kingdom (“We”, “Us”, “Workable”), is committed to protecting and respecting your privacy. This Privacy Policy (“Policy”) relates to services provided through our websites and application (“Services”) and sets out the basis on which the Personal Data collected from you, or that you provide to Us will be processed by Us. “Personal Data” means any information that identifies or relates to a particular individual and also includes information referred to as “personally identifiable information” or “personal information” under applicable data privacy laws, rules, or regulations (collectively the “Data Protection Laws”). This Policy does not cover the practices of companies We don’t own or control or people We don’t manage. For clarity, this policy applies when Workable acts as a “Controller” (as defined in the General Data Protection Regulation (the “GDPR”) and the version of the GDPR retained in UK law (the “UK GDPR”) or “Business” as defined under the California Consumer Privacy Act of 2018 , as amended by the California Privacy Rights Act of 2020 (the “CPRA”) (all together the “CCPA”). Note that we may also process Personal Data of our customers’ job applicants in connection with our provision of services to customers, in which case we are the processor of Personal Data. If we are the processor or service provider for your Personal Data (i.e., not the controller or business), please contact the controller/business party in the first instance to address your rights with respect to such data. Please read the following carefully to understand our views and practices regarding your Personal Data and how We will treat it.

If you have a disability, you may access this Privacy Policy in an alternative format by contacting [email protected].

For the purpose of the GDPR and the CCPA:

  • in respect of the Personal Data of visitors of the Website and users of the Services, business contacts and prospects of Workable, the Data Controller or Business under the CCPA is Workable;
  • In respect of the Personal Data of candidates who apply for, or who a Customer of Workable contacts in respect of an Opening (as the term is described in Workable’s Terms) (“Candidates”), or in regard to Customer’s employees data, Workable shall process personal information as a data processor on behalf of its Customers, who use Our Services to assist with their recruitment processes and employee onboarding, or as Service Provider. When you apply for a role with one of Workable’s Customers, our Customer’s privacy policy, rather than this Privacy Policy, will apply to our processing of your personal information.

For the Users of the Workable Job board (as the term is defined in the Workable Job Board Terms), when You create an Account (as the term is defined in the Workable Job Board Terms) and use the Services, We act as a Data Controller. When You to apply to a Job Opening, the Employer is collecting and storing your personal data as a Data Controller.

Sources of Personal Data

We collect Personal Data about you from:

  • You:
    • when you provide such information directly to us,
    • when you set up an Account with us to use the Services, and
    • when Personal Data about you is automatically collected in connection with your use of our Services.
  • Our subsidiaries and affiliates (together, “Affiliates”), when they provide us with Personal Data about you.
  • Third parties, when they provide us with Personal Data about you (“Third Parties”). Third Parties that share your Personal Data with us include:
    • Service providers. For example, we may use analytics service providers to analyze how you interact and engage with the Services, or third parties may help us provide you with customer support.
    • Social networks connected to the services. If you provide your social network account credentials to us or otherwise sign in to the Services through a third-party site or service, you understand some content and/or information in those accounts may be transmitted into your Account with us.
    • Advertising partners. We receive information about you from some of our service providers who assist us with marketing or promotional services related to how you interact with our websites, applications, products, services, advertisements or communications.
    • Other third parties, such as providers of business contact information, who provide us with publicly available information on You, such as mailing addresses, job titles, email addresses, phone numbers, Internet Protocol (IP) addresses, social media profiles, social media URLs and custom profiles for purposes of targeting advertising. We may combine this information with Personal Data provided by You, for targeting advertising purposes. This helps us analyze our records and identify new Customers.

Information we collect from you

We collect and process some or all of the following types of information from you:

  • Information that you provide by filling in forms on the Website. This includes information provided at the time of registering to use the Website, subscribing to our Services, creating an Account to the Job Board, posting material or requesting further information or services. We may also ask you for information when you report a problem with the Website.
  • If you contact Us, We may keep a record of that correspondence.
  • We may also ask you to complete surveys that We use for research purposes, although you do not have to respond to them.
  • Details of all actions that you carry out through the Website and of the provision of services to you.
  • Details of your visits to the Website including, but not limited to, traffic data, location data, weblogs and other communication data, the site that referred you to our site and the resources that you access.

The provision of your full name and email address, your employer and/or your place of work and the url of the business that you work for is required from you when you register to use our Services. We will inform you at the point of collecting information from you, whether you are required to provide the information to Us.

Categories of Personal Data We Collect

The following chart details the categories of Personal Data that we collect and have collected over the past twelve (12) months. Throughout this Privacy Policy, we will refer back to the categories of Personal Data listed in this chart (for example, “Category A. Personal identifiers”).

Personal Data Collected (including Categories)Purposes of UseWhat is the source of this Personal Data?Categories of third parties to whom we disclose the information for business purposes
A. Personal identifiers

Real name, postal address, unique personal identifier, online identifier, Internet Protocol address, email address, account name, social profile URL

  • Provide the Services
  • Create your Account at the Job Board
  • Communicate with You and provide customer service
  • Personalize your experience
  • Send You job advertisements, newsletters, or other marketing communications
  • Improve the Services
  • Our Marketing and Third Party Marketing and Advertising Purposes
  • Bug detection and error reporting
  • Auditing Consumer Interactions
  • Security, Fraud and Legal Compliance

You
Affiliates
Third Parties

  • Service Providers
  • Our Affiliates
  • Other Individuals, Services, and Partners at Your Request
  • Entities for Legal Purposes
  • Employers (for Users of the Workable Job Board)

B. Customer records identified by state law (including the California Customer Records statute (Cal. Civ. Code § 1798.80(e)))

Name, signature, address, telephone number, employment.

  • Provide the Services
  • Communicate with You and provide customer service
  • Personalize your experience
  • Improve the Services
  • Our Marketing and Third Party Marketing and Advertising Purposes
  • Bug detection and error reporting
  • Auditing Consumer Interactions
  • Security, Fraud and Legal Compliance

You
Affiliates
Third Parties

  • Service Providers
  • Our Affiliates
  • Other Individuals, Services, and Partners at Your Request
  • Entities for Legal Purposes
  • Entities For Sales or Transfer of Business or Assets

C. Commercial information

History of services purchased through Workable

  • Provide the Services
  • Internal Accounting purposes
  • Provide Customer service
  • Performance of legal obligations

You
Affiliates

  • Service Providers
  • Our Affiliates

D. Internet or other similar network activity information

Browsing history, search history, information interaction with the website or application.

  • Our Marketing and Third Party Marketing and Advertising Purposes
  • Auditing Consumer Interactions
  • Communicate with You and provide customer service
  • Improve the Services
  • Bug detection and error reporting
  • Security, Fraud and Legal Compliance

You
Affiliates
Third Parties

  • Service Providers
  • Our Affiliates

E. Geolocation data

Physical location (calculated from IP address)

  • Provide the Services
  • Security, Fraud and Legal Compliance

You
Affiliates
Third Parties

  • Service Providers
  • Our Affiliates

F. Professional or employment-related information

Current job title and employer, Resume

  • Provide the Services
  • Communicate with You and provide customer service
  • Personalize your experience
  • Improve the Services
  • Our Marketing and Third Party Marketing and Advertising Purposes

You
Affiliates
Third Parties

  • Service Providers
  • Our Affiliates

G. Payment information

All information necessary to complete online payments, such as payment details, bank account information, billing information.

  • Provide the Services
  • Process your payments (for services only that require payment)
  • We don't store any credit card or bank account/paypal number

You

  • Secure third-party payment service providers

The following section provides additional information about how we collect your Personal Data.

Lawful Basis for Processing

Under the GDPR and the UK General Data Protection Regulation (UK GDPR), the lawful bases we rely on for processing of your personal data could be:

Legitimate Interest: We may process your personal data based on our legitimate interest, which includes without limitation our legitimate interest to assist Job applicants find a new job (via the Workable Job Board), our legitimate interest to provide and improve the Services, our legitimate interest to improve the Website, our legitimate interest in advertising our product and services, unless you have provided your prior consent as required.

Contract: We may process personal data, in order for us to provide the services and meet our contractual obligations towards you, when we have a contract with you.

Consent: On a few occasions, we may rely on your consent for the processing of your personal data. In any such case, we will indicate this and ask for your specific informed consent, e.g when you sign up to receive marketing communications etc.

Legal Obligation: We may process your personal data to comply with a legal or regulatory obligation such as e.g. detecting, preventing or investigating crime or fraud including working with law enforcement agencies.

Your Rights

Subject to local data protection laws and in particular under the General Data Protection Regulation (GDPR) and the UK GDPR, you have a number of important rights free of charge. In summary, those include rights to:

  • access to your Personal Data and to certain other supplementary information that this Policy is already designed to address
  • require Us to correct any mistakes in your information which We hold
  • require the erasure of Personal Data concerning you in certain situations
  • receive the Personal Data concerning you which you have provided to Us, in a structured, commonly used and machine-readable format and have the right to transmit those data to a third party in certain situations
  • object at any time to processing of Personal Data concerning you for direct marketing
  • object to decisions being taken by automated means which produce legal effects concerning you or similarly significantly affect you
  • object in certain other situations to our continued processing of your Personal Data
  • otherwise restrict our processing of your Personal Data in certain circumstances
  • claim compensation for damages caused by our breach of any data protection laws.

For further information on each of those rights, including the circumstances in which they apply, see the General Data Protection Regulation (GDPR) Guidance from the UK Information Commissioner’s Office (ICO) on individuals rights under the UK GDPR.

If you would like to exercise any of those rights, please:

  • contact us using our Contact details below
  • let Us have enough information to identify you,
  • let Us have proof of your identity and address. Where you are a user of our Services you should email us from the email address that you used to register with Workable. Receipt of an email from this address will usually be sufficient to confirm your identity. In all other cases we may request one or more identification documents, such as a copy of your driving license or passport and a recent utility or credit card bill; and
  • let Us know the information to which your request relates.

For clarity the above rights apply to EU, UK and Swiss data subjects, as required under applicable law, but also any user of the Website and the Services, regardless of location may exercise any of these rights.

Google Account Authentication

You may connect your Google account to your Workable account in order to make use of certain Workable features such as Gmail Import and Syncing and scheduling with Google Calendar. This is done through OAuth authentication, a secure mechanism which gives Workable access to your Google account data without letting Workable know your password.

In that case, Workable will require access to your Google account and user data for the following purposes:

  • Upon sign-up or sign-in (“Sign in with Google”) and connect with Google through your Personal Profile:
    • To verify your email address and to create your user account on our servers in order to link your Google account with Workable;
    • To access and read your Google account profile information to retrieve, use, and display your Google account name, first name, last name and account photo or image in Workable;
  • If you choose to connect your Gmail account to your Workable account:
    • To access your Gmail account in order to send email messages to candidates from your account through Workable.
    • To access and retrieve your email messages
      • to manually import email messages sent to and received from a specific candidate
      • to sync email messages, sent to and received from candidates, that belong to threads that were initially sent with Workable or manually imported
      • to mark your inbox items related with email messages as read, unread, archived and unarchived
      • to read, display, retrieve, and download any files attached to your email messages related with candidates
    • If you choose to connect your Google Calendar account to your Workable account:
      • To access your Google Calendar account in order to schedule events from your Google Calendar account through Workable
      • To access and read your Google Calendar and calendar entries
        • to display the calendar entries of your calendar and calendars of other Google users you have the permission to read
        • to check availability of other event attendees and resources (e.g. meeting rooms)
        • to sync the attendance status of other attendees in Workable
        • to sync event updates made externally via Google Calendar in Workable
      • To access and read your Google Contacts in order to suggest email recipients when you compose email messages or events through Workable
      • To access and read your Google Suite resources in order to suggest meeting rooms when you schedule events through Workable

Google API Services

Workable’s use of information received from Google APIs will adhere to Google API Services User Data Policy including the Limited Use requirements.

Uses made of your information when you request assistance from Workable Support

If you request assistance by a representative of Workable, the Workable representative may obtain access to your Workable account for the purposes of resolving your inquiry. Under those circumstances, the Workable representative will assume your role in Workable and view your account as you would when you log in.

Workable reserves the right to assume the role of a user in your account without prior notice in certain situations, for example when it is necessary for security purposes (such as investigating a bug or abuse) or when it is necessary to comply with applicable law.

Uses made of your information

Where you are using our Services on behalf of our Customer, we rely on legitimate interests in performing our contract with our Customer as the lawful basis on which We collect and use your Personal Data.

We use information held about you in the following ways:

  • To ensure that content from the Website is presented in the most effective manner for you and for your computer.
  • To provide you with information, products or services that you request from us or which we feel may interest you or our Customer.
  • To carry out our obligations arising from any contracts entered into between our Customer (on whose behalf you are using the Services) and Us.
  • To notify you about changes to our Services and provide you with information that is relevant to your use of the Services.
  • Where you or your employer are a prospective Customer, to provide you with information about our Services for marketing purposes.

Aggregate Data

We may use anonymised and/or aggregate data collected through your use of the Services and the Website for statistical purposes, for improvement of the Services, to conduct research,or any other lawful purpose. Aggregate Data is not considered personal data.

Disclosure of your information

We may disclose your personal information to any member of our group, which means our subsidiaries, our ultimate holding company and its subsidiaries, as defined in section 1159 of the UK Companies Act 2006 (where applicable). Where any such member of our group is outside the UK or the EU this transfer will be on the basis of a contract, as described below in accordance with the Data Protection Laws.

We may disclose your personal information to third parties:

  • in the event that we sell or buy any business or assets, in which case we may disclose your Personal Data to the prospective seller or buyer of such business or assets;
  • if we or substantially all of our assets are acquired by a third party, in which case Personal Data held by us about our customers will be one of the transferred assets;
  • if we are under a duty to disclose or share your Personal Data in order to comply with any legal obligation or in order to enforce or apply our Website Terms and Conditions and other agreements, but we will endeavour to minimise such disclosure to only that reasonably necessary and, where possible, to provide you with notice of such disclosure; and/or
  • to protect the rights, property, or safety of Workable, the Website, our users and any third party we interact with to provide the Website.

We disclose your Personal Data to service providers and other parties for the following business purposes:

  • Auditing related to a current interaction and concurrent transactions, including, but not limited to auditing compliance with this specification and other standards.
  • Detecting security incidents, protecting against malicious, deceptive, fraudulent, or illegal activity, and prosecuting those responsible for that activity.
  • Debugging to identify and repair errors that impair existing intended functionality.
  • Short-term, transient use of Personal Data that is not used by another party to build a consumer profile or otherwise alter your consumer experience outside the current interaction.
  • Performing services on our behalf, including software hosting and cloud computing, Customer Relationship Management, email sending, logging, storing Customer data, maintaining or servicing accounts, providing customer service, processing or fulfilling orders and transactions, verifying customer information, processing payments, providing financing, providing advertising or marketing services, providing analytic services, or providing similar services on behalf of the business or service provider.
  • Undertaking internal research for technological development and demonstration.
  • Undertaking activities to verify or maintain the quality or safety of a service or functionality that we provide, own, manufacture, or control.

We disclose your Personal Data to the following categories of service providers and other parties:

  • Service providers, including:
    • Payment processors.
    • Ad networks.
    • Security and fraud prevention consultants.
    • Hosting and other technology and communications providers.
    • Analytics providers.
    • CRM software providers.
    • Email sending providers.
    • Logging service providers.
    • Customer Service software providers.
  • Our Affiliates.
  • Parties who acquire your Personal Data through an acquisition or other change of control.
    • Personal Data may be transferred to a third party if we undergo a merger, acquisition, bankruptcy or other transaction in which that third party assumes control of our business (in whole or in part).
  • Other parties at your direction.
    • Other users (where you post information publicly or as otherwise necessary to effect a transaction initiated or authorized by you through the Services).
    • Social media services (if you intentionally interact with them through your use of the Services).
    • Third-party business partners who you access through the Services ( e.g partners accessed through the Workable Marketplace). Workable does not control the use of your data by those third parties and you are advised to check their Privacy Policy as applicable.
    • For Users of the Workable Job board, we will share your personal data directly with the Employer who posted the Job Opening you have applied to.
    • Other parties authorized by you.

Over the past twelve months, we have disclosed the following categories of your Personal Data to service providers or other parties for the business purposes listed above:

  • A. Personal identifiers.
  • B. Customer records identified by state law.
  • C. Commercial information.
  • D. Internet or other similar network activity information.
  • E. Geolocation data.
  • F. Professional or employment-related information.

When we disclose personal information for a business purpose, as described above we enter into a contract with the service provider or other parties, that describes the purpose and requires the recipient to both keep that personal information confidential and not use it for any purpose except performing the contract.

Sales of Personal Data

We haven’t sold your Personal Data over the last twelve months.

How we store your Personal Data

Security

We take appropriate measures to ensure that all Personal Data is kept secure including security measures to prevent Personal Data from being accidentally lost, or used or accessed in an unauthorised way, for the duration of your use of our Services. We limit access to your Personal Data to those who have a genuine business need to know it. Those processing your information will do so only in an authorised manner and are subject to a duty of confidentiality.

We also have procedures in place to deal with any suspected data security breach. We will notify you and any applicable regulator of a suspected data security breach where We are legally required to do so.

Unfortunately, the transmission of information via the internet is not completely secure. Although we will do our best to protect your Personal Data, we cannot guarantee the security of your data transmitted to the Website, therefore any transmission remains at your own risk. Once we have received your information, we will use strict procedures and security features in order to prevent unauthorised access.

Keeping your Personal Data up to date

If your personal details change you may update them by accessing the relevant page of the Website, or by contacting Us at [email protected].

We will endeavour to update your Personal Data within thirty (30) days of any new or updated Personal Data being provided to Us, in order to ensure that the Personal Data We hold about you is as accurate and up to date as possible.

Where we store your Personal Data

The data that We collect from you and process as a result of your use of the Services may be transferred to, and stored at, a destination outside the UK, Switzerland or the European Economic Area ("EEA"). It may also be processed by staff operating outside the UK, Switzerland or the EEA who work for Us or for one of our suppliers. Such staff maybe engaged in, among other things, the fulfilment of your orders, the processing of your payment details and the provision of support services. By submitting your Personal Data, you agree to this transfer, storing or processing.

In particular, your data may be accessible to i) Workable’s staff in the USA or ii) may be stored by Workable’s hosting service provider on servers in the USA as well as in the EEA. The USA does not have the same data protection laws as the United Kingdom and the EEA. A Data Processing and Transfer Agreement has been signed between the entities of the Workable Group of Companies, and between Workable and each of its data processors. These Data Processor Agreements that are designed to help safeguard your privacy rights and give you remedies in the unlikely event of a misuse of your Personal Data. A full list of Workable's sub-processors can be found here.

If you would like further information please contact Us (see ‘Contact’ below). We will not otherwise transfer your Personal Data outside of the United Kingdom or EEA or to any organisation (or subordinate bodies) governed by public international law or which is set up under any agreement between two or more countries.

How long we keep your Personal Data

We will hold all the data for so long as we have an obligation to You to provide you with the Services, as long as we have an obligation to the Customer to provide the Services, or as long as necessary to fulfill the purpose for which was initially collected and thereafter until such time as we delete the Customer’s account in accordance with our Customer Terms and Conditions. We will retain and use your Personal Data to the extent necessary to comply with any legal/accounting/reporting obligation.

Your personal information will be deleted on one of the following occurrences:

  • deletion of your personal information by You (or by another person engaged by the Customer); or
  • receipt of a written request by You (or another person engaged by the Customer) to us.
Personal Data of Children

We do not knowingly collect or solicit Personal Data from children under 16; if you are a child under 16, please do not attempt to register for or otherwise use the Services or send us any Personal Data. If we learn we have collected Personal Data from a child under 16, we will delete that information as quickly as possible. If you believe that a child under 16 may have provided us Personal Data, please contact us at [email protected].

Your California Privacy Rights

If you are a California resident, you have the rights outlined in this section. Please see the “Exercising Your Rights” section below for instructions regarding how to exercise these rights. If there are any conflicts between this section and any other provision of this Policy and you are a California resident, the portion that is more protective of Personal Data shall control to the extent of such conflict. If you have any questions about this section or whether any of the following applies to you, please contact us at [email protected].

Right of Access

You have the right to request certain information about our collection and use of your Personal Data over the past 12 months. We will provide you with the following information:

  • The categories of Personal Data that we have collected about you.
  • The categories of sources from which that Personal Data was collected.
  • The business or commercial purpose for collecting your Personal Data.
  • The categories of third parties with whom we have shared your Personal Data.
  • The specific pieces of Personal Data that we have collected about you.

If we have disclosed your Personal Data for a business purpose over the past 12 months, we will identify the categories of Personal Data shared with each category of third party recipient.

Right of Deletion

You have the right to request that we delete the Personal Data that we have collected from you. Under the CCPA, this right is subject to certain exceptions: for example, we may need to retain your Personal Data to provide you with the Services or complete a transaction or other action you have requested. If your deletion request is subject to one of these exceptions, we may deny your deletion request.

Right to Correct

You have a right to request correction of inaccurate personal information.

Right to Opt out of selling your personal Information

Workable does not sell your personal information

Right to Opt out of sharing your personal Information

Although Workable does not sell your personal information, we may share in a few instances your personal information with third parties. “Sharing” under the CCPA, is broadly defined to cover the disclosing personal information for purposes of cross-context behavioral advertising, as for example targeting advertising based on personal information obtained from a consumer’s activity across distinctly-branded websites or services.

You can request to opt out of sharing your personal information as defined above by using our cookies preference banner.

Right to Limit the Use of Sensitive Personal Information

Workable does not use or disclose Sensitive Personal Information for reasons other than permitted under the CCPA.

Non discrimination for Exercising Your CCPA Rights

We will not discriminate against you for exercising your rights under the CCPA. We will not deny you our goods or services, charge you different prices or rates, or provide you a lower quality of goods and services if you exercise your rights under the CCPA.

Right to Opt-out of Automated Decision-Making Technology (Profiling)

Workable does not engage in automated decision-making or profiling.

Exercising Your Rights

To exercise the rights described above, you must send us a request that (1) provides sufficient information to allow us to verify that you are the person about whom we have collected Personal Data, and (2) describes your request in sufficient detail to allow us to understand, evaluate, and respond to it. Each request that meets both of these criteria will be considered a “Valid Request.” We may not respond to requests that do not meet these criteria. We will only use Personal Data provided in a Valid Request to verify you and complete your request. You do not need an account to submit a Valid Request.

We will work to respond to your Valid Request within 45 days of receipt. We will not charge you a fee for making a Valid Request unless your Valid Request(s) is excessive, repetitive, or manifestly unfounded. If we determine that your Valid Request warrants a fee, we will notify you of the fee and explain that decision before completing your request.

You may submit a Valid Request using the following methods:

Other State Law Privacy Rights

Other California Resident Rights

Under California Civil Code Sections 1798.83-1798.84, California residents are entitled to contact us to prevent disclosure of Personal Data to third parties for such third parties’ direct marketing purposes; in order to submit such a request, please contact us at [email protected].

Your browser may offer you a “Do Not Track” option, which allows you to signal to operators of websites and web applications and services that you do not wish such operators to track certain of your online activities over time and across different websites. Our Services do not support Do Not Track requests at this time. To find out more about “Do Not Track,” you can visit www.allaboutdnt.com.

Nevada Resident Rights

If you are a resident of Nevada, you have the right to opt-out of the sale of certain Personal Data to third parties who intend to license or sell that Personal Data. You can exercise this right by contacting us at [email protected] with the subject line “Nevada Do Not Sell Request” and providing us with your name and the email address associated with your account. Please note that we do not currently sell your Personal Data as sales are defined in Nevada Revised Statutes Chapter 603A.

Transfers of Personal Data

The Services are hosted and operated in the United States (“U.S.”) through Workable, Inc. and its service providers, and if you do not reside in the U.S., laws in the U.S. may differ from the laws where you reside. By using the Services, you acknowledge that any Personal Data about you, regardless of whether provided by you or obtained from a third party, is being provided to Workable, Inc. in the U.S. and will be hosted on U.S. servers, and you authorize Workable to transfer, store and process your information to and in the U.S., and possibly other countries. You hereby acknowledge and agree with the transfer of your data to the U.S.

For transfers of data outside the EEA, Switzerland and the UK to the US, We rely i) on the European Commission Standard Contractual Clauses ( “EE “SCCs”) and the UK DTIA as approved by the ICO (all together the “SCCs”), as our data transfer mechanism, or ii) the Data Privacy Frameworks if the recipient of the data adheres to the Data Privacy Framework principles.

Data Privacy Framework compliance

Workable Inc. is self-certified under the EU-U.S. Data Privacy Framework (“EU-U.S. DPF”), the Swiss-U.S. Data Privacy Framework (“Swiss-U.S. DPF”) and the UK Extension to the EU-U.S. DPF as set forth by the U.S. Department of Commerce regarding the collection, use, and retention of personal information from European Union member countries, the UK and Switzerland that have been transferred to the United States pursuant to the Data Privacy Framework. Workable has certified that it adheres to the Data Privacy Framework Principles with respect to such data. If there is any conflict between the terms of this privacy policy and data subject rights under the Data Privacy Framework Principles, the Data Privacy Framework Principles shall govern. To learn more about the Data Privacy Framework program, and to view our certification page, please visit https://www.dataprivacyframework.gov/.

With respect to Personal Data that have been received or transferred pursuant to the Privacy Framework, Workable Inc. is subject to the regulatory and enforcement powers of the U.S. Federal Trade Commission.

Pursuant to the Data Privacy Framework, EU, United Kingdom and Swiss individuals have the right to obtain our confirmation of whether we maintain personal information relating to you in the United States. Upon request, we will provide you with access to the personal information that we hold about you. You may also correct, amend, or delete the personal information we hold about you. An individual who seeks access, or who seeks to correct, amend, or delete inaccurate data transferred to the United States under the Data Privacy Framework, should direct their query to [email protected]. If requested to remove data, we will respond within a reasonable timeframe.

We will provide an individual opt-out choice, or opt-in for sensitive data, before we share your data with third parties other than our agents, or before we use it for a purpose other than which it was originally collected or subsequently authorized. To request to limit the use and disclosure of your personal information, please submit a written request to [email protected].

In certain situations, we may be required to disclose Personal Data in response to lawful requests by public authorities, including to meet national security or law enforcement requirements.
In compliance with the Data Privacy Framework Principles, Workable commits to resolve complaints about your privacy and our collection or use of your personal information transferred to the United States pursuant to Data Privacy Framework. Please contact us at [email protected] with any questions, concerns or complaints relating to our Data Privacy Framework Certification.

We are committed to cooperate with the panel established by the EU data protection authorities (DPAs), the Swiss Federal Data Protection and Information Commissioner (FDPIC) and the UK ICO, with regard to unresolved complaints concerning data received in reliance on the EU-U.S. DPF, the Swiss-U.S. DPF and the UK Extension to the EU-U.S. DPF and you may have the possibility to engage in binding arbitration through the Data Privacy Framework Panel. More information can be found here.

In regard to onward transfers of personal data to third parties, Workable is responsible for ensuring that the third parties process such personal data in a manner consistent with the DPF Principles. Workable remains liable for the third party’s failure to comply with the DPF Principles, unless Workable can prove that it is not responsible for the event giving rise to the damage.

Representatives

Workable Inc. is based in the USA and it has appointed Workable Software Single Member Private Company to be its representative within the EEA and Workable Software Limited as its representative in the UK.

Workable Software Single Member Private Company is the EU representative of Workable Software Limited within the EEA and likewise Workable Software Limited is the UK representative of Workable Software Single Member Private Company.

Workable Software Single Member Private Company is registered in Greece with its office located at Leof. Kifisias 95-97, Marousi 151 25, Greece. Contact via the email: [email protected].
Workable Software Limited is registered in England and Wales with Company Registration Number 08125469 and having its registered office address at 5 Golden Square, 5th Floor, London, W1F 9BS, United Kingdom. Contact via the email: [email protected].

Third Party Websites

The Website may, from time to time, contain links to and from the websites of our partner networks, advertisers and affiliates. If you follow a link to any of these websites, please note that these websites have their own privacy policies and terms of use and that we do not accept any responsibility or liability for these policies and terms of use. Please check these policies before you submit any Personal Data to these websites.

How to complain

We hope that We can resolve any query or concern you raise about our use of your information.

The General Data Protection Regulation and the UK GDPR also give you right to lodge a complaint with a supervisory authority, in particular (under the GDPR) in the European Union (or European Economic Area) state where you work, normally live or where any alleged infringement of data protection laws occurred. The supervisory authority in the UK is the Information Commissioner who may be contacted at https://ico.org.uk/concerns/ or telephone: 0303 123 1113.
The supervisory authority in Greece is the Hellenic Data Protection Authority, which may be contacted at Call Centre: +30-210 6475600 or E-mail: [email protected]

Changes to our privacy policy

We reserve the right to modify this Privacy Policy at any time. Any changes we may make to our Policy in the future will be notified and made available to you using the Website. Your continued use of the Services and the Website shall be deemed your acceptance of the varied Privacy Policy.

Contact

If you have any questions about this Privacy Policy or want to report a potential data breach please reach out to [email protected]. Please note that Workable’s Data Protection Officer (DPO) responds to any requests submitted to [email protected], attention Workable’s DPO.

Last updated 12 March 2024.

You may print a copy of the previous version of Privacy Policy by clicking here.