Privacy Policy
This policy explains what personal data WorkOSync collects, why we collect it, where it is stored, how long we keep it and the rights you have over it. It applies to the WorkOSync website, the web application, the mobile apps and our support channels.
Who we are and what this policy covers
WorkOSync is operated by Sixty Seven Digital FZCO, a company licensed by IFZA (Dubai Integrated Economic Zones) under trade licence 50647, with its registered address at IFZA Business Park, Dubai Silicon Oasis, Dubai, United Arab Emirates. In this policy, “WorkOSync”, “we” and “us” refer to that company.
We process personal data in accordance with the UAE Personal Data Protection Law, Federal Decree-Law No. 45 of 2021 (the “PDPL”), and its executive regulations. Where we serve customers established in the European Economic Area or the United Kingdom, we also meet the requirements of the EU General Data Protection Regulation (GDPR) and the UK GDPR for that data.
WorkOSync acts in two different roles, and your rights depend on which one applies:
- Controller. For the data of website visitors, people who sign up for an account, billing contacts and anyone who writes to us, we decide why and how the data is processed. This policy is the primary document for that data.
- Processor. For the business records a customer enters into their WorkOSync company (its own customers, suppliers, employees, invoices, payroll and documents), the customer is the controller and we process that data only on their instructions. That processing is governed by our Data Processing Addendum. If you are an employee, customer or supplier of a business that uses WorkOSync, please direct requests about your data to that business first.
Personal data we collect
Data you give us
- Account data: your name, work email address, password (stored only as a bcrypt hash), phone number if you add one, preferred language, time zone and two-factor authentication secrets.
- Company data: the legal name, trade licence number, Tax Registration Number (TRN), address, currency and tax region of the company you register, and the roles you assign to your team.
- Billing data: billing contact, billing address, VAT status and plan history. Card numbers are entered directly with our payment gateway (Stripe, Tap, PayPal or Razorpay) and never touch our servers. We keep only the gateway’s token, the card brand and its last four digits.
- Content you upload: files, notes, messages and records that you or your team place in the service.
- Support communications: the emails, chat messages and forms you send to us, and any files you attach to them.
- Bring-your-own AI key: if you connect your own AI provider key, we store it encrypted and use it only to make requests on your behalf.
Data we collect automatically
- Technical and security data: IP address, user agent, request path, timestamps, referring page and the outcome of each request. We use this to run the service, to detect abuse and to keep an audit trail of sign-ins and changes made inside your company.
- Product usage: which modules and features are used and how often, so we can prioritise work and spot problems. This is aggregated per company and is not sold or shared.
- Website analytics: our website analytics are first-party and cookieless. A visitor is counted using a salted hash of IP address and user agent that rotates daily and cannot be reversed. See the Cookie Policy.
We do not ask for, and ask you not to upload, special categories of data such as health, biometric, religious or criminal-record data about yourself unless a module you use requires it (for example, an HR record of a medical fitness certificate). Where a customer stores such data, the customer is the controller and must have a lawful basis for it.
How we use personal data
- To create and administer your account and your company workspace, authenticate you and enforce role-based permissions.
- To provide the features you use, including invoicing, accounting, payroll, inventory, CRM and the AI layer, and to generate the documents you ask for.
- To bill you, issue tax invoices and collect payment through the gateway you choose.
- To send transactional messages: sign-in codes, invoices, approval requests, reminders, security alerts and service notices. These cannot be switched off while you hold an account because the service cannot operate without them.
- To send product news and offers, only where you have opted in, and with an unsubscribe link in every message.
- To provide support, investigate problems and respond to your requests.
- To protect the service: detecting fraud, bots, brute-force attempts, spam and misuse, and banning abusive sources.
- To comply with law, including UAE tax record-keeping obligations, anti-money-laundering rules that apply to our payment partners, and lawful requests from authorities.
- To improve the service using aggregated, de-identified usage statistics.
We do not sell personal data, and we do not use customer data to train AI models, whether ours or a third party’s.
Legal bases for processing
Under the PDPL, and Article 6 of the GDPR where it applies, we rely on the following bases:
| Purpose | Basis |
|---|---|
| Providing the service, billing, support | Performance of a contract with you (PDPL Article 4(1)(a); GDPR Article 6(1)(b)) |
| Tax invoices, accounting records, responding to lawful requests | Compliance with a legal obligation (PDPL Article 4(1)(c); GDPR Article 6(1)(c)) |
| Security, abuse prevention, service improvement, product analytics | Our legitimate interests in running a safe and reliable service, balanced against your rights (PDPL Article 4(1)(b); GDPR Article 6(1)(f)) |
| Marketing emails, optional cookies | Your consent, which you can withdraw at any time (PDPL Article 4 and Article 6; GDPR Article 6(1)(a)) |
| Processing on behalf of a customer | The customer's instructions under the Data Processing Addendum |
AI features and bring-your-own key
The AI layer (morning brief, drafting, summaries, natural-language queries and one-tap approvals) sends the specific records needed for a request to an AI model provider and returns the result to you. Two options are available to every company:
- WorkOSync-managed AI. Requests go to the provider we have contracted as a sub-processor, under terms that prohibit training on your data and require deletion after processing.
- Bring your own key. You connect your own API key from a provider of your choice. Requests then go directly from our servers to your provider under your own agreement with them. We store the key encrypted and never display it again after entry.
AI features are off until an owner or admin of the company enables them. You can disable them, or restrict them by role, at any time in Settings.
Data hosting and international transfers
WorkOSync is hosted in secure European data centres, and each company's database, uploaded files and backups are stored there, encrypted in transit and at rest and backed up daily.
Some sub-processors operate in other regions, for example a payment gateway or an email delivery service. Where personal data is transferred we rely on appropriate safeguards: a transfer to a country recognised as having adequate protection, or a contract that binds the recipient to equivalent safeguards. For data subject to the GDPR we use the European Commission’s Standard Contractual Clauses, and the UK Addendum where relevant.
How long we keep data
| Data | Retention |
|---|---|
| Account and company data | For the life of the account, then deleted 90 days after the account is closed or the subscription ends, unless you ask for earlier deletion |
| Customer business records (as processor) | Exported on request for 30 days after termination, then deleted within 90 days; see the DPA |
| Tax invoices and billing records | 5 years from the end of the relevant tax period, as required by UAE Federal Tax Authority rules, or longer where the law of your country requires |
| Security and access logs | 12 months, then aggregated or deleted |
| Website analytics | Aggregated daily; the hashed visitor identifier is not stored beyond the day it is generated |
| Support conversations | 3 years after the ticket is closed |
| Backups | Rolling 35-day window; deleted data ages out of backups within that window |
| Blocked IP addresses and abuse records | Until the block expires or 24 months, whichever is later |
How we protect data
All traffic is encrypted in transit with TLS and HSTS. Passwords are stored as bcrypt hashes, secrets such as gateway and AI keys are encrypted at rest, sessions are server-side with httpOnly cookies, and every sign-in and change is audited. Access to production systems is limited to named staff with two-factor authentication. Backups are encrypted and restore-tested. Our full set of controls is described on the Security Overview page.
Your rights
Under Chapter 4 of the PDPL, and Chapter 3 of the GDPR where it applies, you have the right to:
- Access the personal data we hold about you and receive a copy of it.
- Correct inaccurate or incomplete data. Most account data can be edited directly in Settings.
- Erase your data where we no longer need it, subject to the retention periods the law requires.
- Restrict or object to processing based on legitimate interests, including all direct marketing.
- Portability: receive your data in a structured, machine-readable format. Company owners can export every module to CSV or JSON from Settings at any time.
- Withdraw consent at any time where consent is the basis, without affecting processing already carried out.
- Not be subject to a solely automated decision with legal or similarly significant effect. WorkOSync’s AI layer drafts and suggests; approvals are always taken by a person you designate.
To exercise a right, email privacy@workosync.com from the address on your account, or ask your company owner to raise it for you. We respond within 30 days, and sooner where we can. We may ask you to verify your identity first. If you are unhappy with our response you can complain to the UAE Data Office, and, if you are in the EEA or the UK, to your local supervisory authority.
Children
WorkOSync is a business tool. It is not directed at, and may not be used by, anyone under 18 years of age. We do not knowingly collect personal data from children. If you believe a child has created an account, contact us and we will delete it.
Changes to this policy
We review this policy at least once a year and whenever the service or the law changes. Small clarifications take effect when published. For material changes we email account owners at least 14 days before the new version takes effect and show a notice in the app. The effective date at the top of the page always tells you which version you are reading, and earlier versions are available on request.
Contact
Our data protection contact handles access, correction and deletion requests, questions about this policy and complaints. Write from the email address on your account so we can verify you quickly.
Other addresses: privacy@workosync.com for data protection, support@workosync.com for billing and support, security@workosync.com for vulnerability reports.

