Privacy Policy
Your privacy is fundamental to our mission. This policy explains how we collect, use, and protect your information in compliance with GDPR, CCPA, and global privacy standards.
Last Updated: May 21, 2026 | Effective Date: January 1, 2024
Contents
1. Definitions
For purposes of this Privacy Policy:
- "Company" (referred to as either "the Company", "We", "Us" or "Our") refers to Workings.me.
- "Website" refers to Workings.me, accessible from https://workings.me
- "You" means the individual accessing or using the Website.
- "Personal Data" is any information that relates to an identified or identifiable individual.
- "Usage Data" refers to data collected automatically when using the Website.
- "Cookies" are small files placed on Your computer or device.
2. Information We Collect
2.1 Personal Data
We collect minimal personal data. Specifically:
- Email Address: Only if you voluntarily subscribe to our newsletter
- Name: Optional, only if provided during newsletter signup
- IP Address: Anonymized and hashed for analytics purposes
2.2 Usage Data
Usage Data is collected automatically and may include:
- Pages visited and time spent on each page
- Referrer URLs (how you found our site)
- Browser type and version
- Device type and operating system
- Date and time of visits
- Anonymized IP address (last octet removed)
2.3 What We Do NOT Collect
Privacy-First Design
- Our assessment tools (Career Pulse, Income Architect, Skill Audit) run entirely in your browser
- No answers, scores, or personal information from tools are sent to our servers
- No account registration required to use core features
- No social media login options that would share your profile data
3. How We Use Your Information
We use the collected data for the following purposes:
| Purpose | Data Used | Legal Basis |
|---|---|---|
| Provide and maintain our Website | Usage Data, Technical Data | Legitimate Interest |
| Send newsletter updates | Email, Name (optional) | Consent |
| Analyze usage patterns | Anonymized Usage Data | Legitimate Interest |
| Improve user experience | Usage Data, Feedback | Legitimate Interest |
| Comply with legal obligations | As required by law | Legal Obligation |
Note: We do not use your data for automated decision-making or profiling that produces legal effects.
4. Legal Basis for Processing (GDPR)
Under the General Data Protection Regulation (GDPR), we process personal data based on the following legal grounds:
- Consent: When you voluntarily subscribe to our newsletter
- Legitimate Interests: For website analytics, security, and service improvement
- Legal Obligation: When required to comply with applicable laws
You have the right to withdraw consent at any time by unsubscribing from our newsletter or contacting us.
7. Data Security
We implement appropriate technical and organizational measures to protect your personal data:
- Encryption: All data transmission uses TLS 1.3 encryption (HTTPS)
- Anonymization: IP addresses are anonymized before storage
- Access Controls: Limited staff access to personal data
- Regular Audits: Security assessments and penetration testing
- Data Minimization: We collect only what is necessary
No method of transmission over the Internet is 100% secure. While we strive to protect your data, we cannot guarantee absolute security.
8. Data Retention
We retain your personal data only as long as necessary:
- Newsletter Subscribers: Until you unsubscribe or we discontinue the service
- Analytics Data: 26 months (standard Google Analytics retention)
- Server Logs: 30 days, then automatically deleted
- IP Address Hashes: Rotated monthly, irreversible
After retention periods expire, data is automatically deleted or anonymized.
9. Your Privacy Rights
9.1 GDPR Rights (EU/EEA Residents)
If you are a resident of the European Economic Area, you have the following rights:
Right to Access
Request copies of your personal data
Right to Rectification
Request correction of inaccurate data
Right to Erasure
Request deletion of your personal data
Right to Restriction
Request limited processing of your data
Right to Portability
Receive data in a structured format
Right to Object
Object to processing based on legitimate interests
9.2 CCPA Rights (California Residents)
If you are a California resident, you have the following rights under the California Consumer Privacy Act (CCPA) and California Privacy Rights Act (CPRA):
- Right to Know: Request disclosure of categories and specific pieces of personal information collected
- Right to Delete: Request deletion of personal information collected
- Right to Opt-Out: Opt-out of the "sale" of personal information (we do not sell data)
- Right to Non-Discrimination: We will not discriminate against you for exercising your privacy rights
- Right to Correct: Request correction of inaccurate personal information
- Right to Limit: Limit use and disclosure of sensitive personal information
9.3 Exercising Your Rights
To exercise any of these rights, please contact us at privacy@workings.me. We will respond within:
- GDPR: 30 days
- CCPA: 45 days (with possible 45-day extension)
We may need to verify your identity before processing your request. We will not charge a fee unless requests are manifestly unfounded or excessive.
10. International Data Transfers
Your information may be transferred to — and maintained on — computers located outside of your state, province, country, or other governmental jurisdiction where data protection laws may differ.
If you are located outside the United States and choose to provide information to us, please note that we transfer the data to the United States and process it there.
We ensure appropriate safeguards are in place for international transfers, including:
- Standard Contractual Clauses (SCCs) for EU data transfers
- Adequacy decisions where applicable
- Data Processing Addendums with all service providers
11. Children's Privacy
Our Website is not intended for use by children under the age of 13. We do not knowingly collect personally identifiable information from children under 13.
If you are a parent or guardian and you are aware that your child has provided us with Personal Data, please contact us at privacy@workings.me. If we become aware that we have collected Personal Data from children under 13 without verification of parental consent, we take steps to remove that information from our servers.
For California residents: We do not sell the personal information of consumers under 16 years of age.
12. Third-Party Links and Services
Our Website may contain links to third-party websites or services that are not owned or controlled by Workings.me. We have no control over and assume no responsibility for:
- The content, privacy policies, or practices of any third-party websites
- Any damages or losses caused by or in connection with use of or reliance on any such content, goods, or services available on or through any such websites
- The security of any information you transmit to third-party websites
We strongly advise you to read the terms of service and privacy policies of any third-party websites you visit. Your use of third-party websites is at your own risk.
13. User Responsibilities
You are responsible for:
- Maintaining the confidentiality of any information you submit through our Website
- Using the Website in compliance with all applicable laws and regulations
- Not using the Website for any unlawful purpose or in any way that could damage, disable, overburden, or impair our services
- Not attempting to gain unauthorized access to any portion of the Website or any systems or networks connected to it
- Not using any automated systems or software to extract data from the Website without our express written consent
14. Disclaimer of Warranties
Important Legal Notice
THE WEBSITE AND ALL INFORMATION, CONTENT, MATERIALS, PRODUCTS, AND SERVICES INCLUDED ON OR OTHERWISE MADE AVAILABLE TO YOU THROUGH THE WEBSITE ARE PROVIDED ON AN "AS IS" AND "AS AVAILABLE" BASIS, UNLESS OTHERWISE SPECIFIED IN WRITING.
WE MAKE NO REPRESENTATIONS OR WARRANTIES OF ANY KIND, EXPRESS OR IMPLIED, AS TO THE OPERATION OF THE WEBSITE OR THE INFORMATION, CONTENT, MATERIALS, PRODUCTS, OR SERVICES INCLUDED ON OR OTHERWISE MADE AVAILABLE TO YOU THROUGH THE WEBSITE, INCLUDING BUT NOT LIMITED TO:
- IMPLIED WARRANTIES OF MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE, OR NON-INFRINGEMENT
- WARRANTIES THAT THE WEBSITE WILL BE UNINTERRUPTED, TIMELY, SECURE, OR ERROR-FREE
- WARRANTIES THAT THE RESULTS OBTAINED FROM THE USE OF THE WEBSITE WILL BE ACCURATE OR RELIABLE
- WARRANTIES REGARDING THE QUALITY OF ANY PRODUCTS, SERVICES, INFORMATION, OR OTHER MATERIAL OBTAINED THROUGH THE WEBSITE
NO ADVICE OR INFORMATION, WHETHER ORAL OR WRITTEN, OBTAINED BY YOU FROM WORKINGS.ME OR THROUGH THE WEBSITE SHALL CREATE ANY WARRANTY NOT EXPRESSLY STATED HEREIN.
15. Limitation of Liability
TO THE FULLEST EXTENT PERMITTED BY APPLICABLE LAW, IN NO EVENT SHALL WORKINGS.ME, ITS DIRECTORS, EMPLOYEES, PARTNERS, AGENTS, SUPPLIERS, OR AFFILIATES BE LIABLE FOR ANY:
- INDIRECT, INCIDENTAL, SPECIAL, CONSEQUENTIAL, OR PUNITIVE DAMAGES
- LOSS OF PROFITS, REVENUE, DATA, USE, GOODWILL, OR OTHER INTANGIBLE LOSSES
- DAMAGES RESULTING FROM (i) YOUR ACCESS TO OR USE OF OR INABILITY TO ACCESS OR USE THE WEBSITE; (ii) ANY CONDUCT OR CONTENT OF ANY THIRD PARTY ON THE WEBSITE; (iii) ANY CONTENT OBTAINED FROM THE WEBSITE; OR (iv) UNAUTHORIZED ACCESS, USE, OR ALTERATION OF YOUR TRANSMISSIONS OR CONTENT
THIS LIMITATION OF LIABILITY APPLIES WHETHER THE ALLEGED LIABILITY IS BASED ON CONTRACT, TORT, NEGLIGENCE, STRICT LIABILITY, OR ANY OTHER BASIS, EVEN IF WORKINGS.ME HAS BEEN ADVISED OF THE POSSIBILITY OF SUCH DAMAGE.
IN JURISDICTIONS THAT DO NOT ALLOW THE EXCLUSION OR LIMITATION OF LIABILITY FOR CONSEQUENTIAL OR INCIDENTAL DAMAGES, OUR LIABILITY SHALL BE LIMITED TO THE MAXIMUM EXTENT PERMITTED BY LAW, WHICH SHALL NOT EXCEED THE GREATER OF (A) THE AMOUNT YOU HAVE PAID TO US IN THE PAST 12 MONTHS, OR (B) ONE HUNDRED UNITED STATES DOLLARS (US$100.00).
16. Indemnification
You agree to defend, indemnify, and hold harmless Workings.me and its licensee and licensors, and their employees, contractors, agents, officers, and directors, from and against any and all claims, damages, obligations, losses, liabilities, costs or debt, and expenses (including but not limited to attorney's fees), resulting from or arising out of:
- Your use and access of the Website
- Your violation of any term of this Privacy Policy
- Your violation of any third-party right, including without limitation any copyright, property, or privacy right
- Any claim that your use of the Website caused damage to a third party
This indemnification obligation will survive the termination of your use of the Website and this Privacy Policy.
17. Data Breach Notification
In the event of a data breach affecting your personal information, we will:
- Notify affected users without undue delay and in any case within 72 hours of becoming aware of the breach, where feasible
- Notify supervisory authorities in accordance with GDPR Article 33 requirements
- Provide clear information about the nature of the breach, the categories and approximate number of individuals concerned, and the likely consequences
- Describe measures taken or proposed to address the breach and mitigate potential adverse effects
- Comply with California law by notifying California residents whose personal information was subject to unauthorized access and acquisition, theft, or disclosure
Notification will be provided via email or prominent posting on our Website, depending on the scale and severity of the breach.
18. Governing Law and Jurisdiction
This Privacy Policy and any dispute arising from or relating to it shall be governed by and construed in accordance with the laws of the State of Delaware, United States, without regard to its conflict of law provisions.
Any legal action or proceeding arising under this Privacy Policy will be brought exclusively in the federal or state courts located in Delaware, and the parties hereby irrevocably submit to the personal jurisdiction and venue of such courts.
If you are a consumer residing in the European Union, you may also bring proceedings in the courts of your country of residence, and nothing in this section shall limit any mandatory consumer protection rights under the laws of your country of residence.
19. Severability
If any provision of this Privacy Policy is held to be invalid, illegal, or unenforceable by a court of competent jurisdiction, such provision shall be severed and the remainder of the Privacy Policy shall continue in full force and effect. The invalid provision shall be replaced by a valid provision that most closely achieves the original intent of the invalid provision.
20. Entire Agreement
This Privacy Policy, together with our Terms of Service, constitutes the entire agreement between you and Workings.me regarding your use of the Website and supersedes all prior agreements, understandings, and communications, whether written or oral, relating to such subject matter.
No waiver of any term of this Privacy Policy shall be deemed a further or continuing waiver of such term or any other term, and our failure to assert any right or provision under this Privacy Policy shall not constitute a waiver of such right or provision.
21. Changes to This Privacy Policy
We may update our Privacy Policy from time to time. We will notify you of any changes by:
- Posting the new Privacy Policy on this page
- Updating the "Last Updated" date at the top of this page
- Notifying newsletter subscribers via email for material changes
Changes are effective immediately upon posting unless otherwise stated.
We encourage you to review this Privacy Policy periodically for any changes.
13. Contact Us
If you have any questions about this Privacy Policy, or to exercise your privacy rights, please contact us:
Data Protection Officer
Email: privacy@workings.me
Response Time: Within 30 days (GDPR) or 45 days (CCPA)
Address: Workings.me, Data Protection Office
Supervisory Authority: If you are an EU resident and believe we have not adequately addressed your concerns, you have the right to lodge a complaint with your local data protection authority.