Privacy policy
Last updated 29 September 2026
How Workhal handles website, account and workplace information.
1. Who is responsible
Workhal is operated by Lukas Jääger. For privacy requests, contact lukasjaager@gmail.com. This policy covers workhal.com, app.workhal.com, enquiries and the beta waitlist. Lukas is the controller for website enquiries, account administration, service security and communications. Your employer or other workplace operator normally determines why employee and workplace information is used and is the controller for that information; Workhal processes it on that organization’s instructions. Ask your workplace administrator about its own purposes, legal basis and retention rules. A separate data-processing agreement is needed where required by law; this policy does not replace it.
2. Information we receive
You may provide a name, email address, profile image, sign-in information, organization membership and support messages. Workplace administrators may enter employee names, email addresses, departments, job titles, roles and invitation status before an employee registers. Workplace content can include guides, files, links, events, schedules, assignments, announcements, acknowledgements, questions, shared worker notes and shift-trade proposals and reasons. Activity records identify actions, actors and times. Do not enter sensitive health, identity-document, payment-card or other unnecessary personal information.
3. Where information comes from
Information comes from you, workplace owners and colleagues, your sign-in provider, and integrations enabled by a workplace owner. If Deputy is connected, Workhal imports employee and area identifiers and roster details, including assigned people, times and publication status. Approved shift trades may update assignments in Deputy. Technical providers also process connection information such as IP addresses, browser details, request times and errors.
4. Why information is used
We use information to operate accounts and workplaces, authenticate access, display content and schedules, deliver invitations and notifications, process approved shift trades, respond to requests and prevent misuse. Contractual necessity applies to providing services you request as a contracting user. Legitimate interests apply to reliable operation, security and responding to ordinary enquiries, balanced against your rights. Legal obligations apply when we must retain or disclose information by law. Waitlist and optional update emails are based on your consent; you can withdraw it by email. Your workplace determines the legal basis for its employment-related processing.
5. Who can see workplace information
Visibility depends on the workplace’s access settings and your role. Published content in a public workplace can be read by anyone with its address. A join code or private link gives accountless access to shared published content; anyone receiving a forwarded credential may use it. Members can see additional member content, including shared worker notes and permitted schedules. Notes are shared within the workplace, not a private personal diary. Owners and authorized managers can see staff information and activity appropriate to their roles. Files already downloaded and information copied by others cannot be recalled by changing a setting.
6. Service providers and integrations
We use Vercel for web hosting, Clerk for authentication, accounts, organizations and invitations, Convex for application functions, database and file storage, and Resend for delivery of website contact and waitlist messages. The receiving email provider processes correspondence; messages sent to our Gmail address are handled by Google. Deputy processes integration data when a workplace connects it. These providers receive information needed for their functions and may process some service and security information under their own policies. We may disclose information when legally required or to protect rights and service security. We do not sell personal information.
7. Cookies and browser storage
Clerk uses authentication cookies and related storage to keep sessions secure. Language preferences are remembered for up to one year. The application stores the selected workplace, theme and, if used, a guest access credential in the browser. Remembered guest access expires after 30 days; leaving the workplace clears its saved access. On shared devices, sign out and leave the workplace when finished. Clearing cookies or local storage may sign you out or reset preferences. The current application code does not include advertising trackers; hosting and authentication services still process necessary technical information.
8. International processing
Providers may process information outside your country, including outside the European Economic Area. Where the GDPR applies, transfers must use a valid mechanism such as an adequacy decision or appropriate contractual safeguards. Contact us for information about the safeguards and providers applicable to your data. A regional database location does not mean every provider or support operation is confined to that region.
9. Retention and deletion
Account and workplace information is retained while needed to operate the service and for the workplace’s instructed purposes. Deactivating an employee removes access but preserves the workplace profile and historical links; it does not delete the global Clerk account. Removing a profile and deleting an account are different actions. Some history or workplace content may remain where needed for organizational records or legal claims. Temporary worker-note lines expire 24 hours after the last relevant save; lines marked with ! remain until edited or deleted. Enquiries are retained as needed to reply and follow up, and waitlist details until withdrawal or the list is no longer needed. Backups and provider logs may persist according to their applicable retention cycles. Contact us to arrange deletion or obtain the retention information relevant to your request.
10. Your rights and choices
Where applicable, you can request access, correction, deletion, restriction and portability of your personal data, object to processing based on legitimate interests, and withdraw consent without affecting earlier lawful processing. We may need to verify your identity. Contact your workplace first for employment and workplace records; we will assist it with requests concerning data processed on its behalf. For our own processing, email lukasjaager@gmail.com. You may complain to your local data protection authority; in Estonia this is Andmekaitse Inspektsioon (aki.ee). GDPR requests are normally answered within one month, subject to permitted extensions.
11. Security, automated decisions and children
We use authentication, workplace permissions and other technical controls to limit access. No online service can guarantee absolute security. Report suspected unauthorized access to us and your workplace owner. Workhal does not itself make solely automated decisions with legal or similarly significant effects about employees. The service is intended for workplace use, not directed to children; organizations must ensure lawful use by any young workers and appropriate supervision.
12. Updates and contact
We update this policy when processing or the service changes and display the revision date here. Where required, we will give additional notice or seek consent. Contact Lukas Jääger at lukasjaager@gmail.com for privacy questions or assistance.