Snapshot 21515
Normalized text
Scripts and page chrome removed; this is what change detection compares.
Legals Privacy policy –Service use “awork” Status: September 2026 The most important information at a glance The protection of your personal data is very important to us. Below you will find information pursuant to Art. 13, 14 and 21 GDPR on how the data collected through your use of awork is handled. This Privacy Policy applies to the awork WebApp including the awork website, through which the application is accessed and the contract is initiated and concluded. Controller within the meaning of the GDPR awork GmbH Großer Burstah 36-38 20457, Hamburg, Germany +49 40 238 312 301 [email protected] Data Protection Officer PROLIANCE GmbH / https://www.proliance.ai/ Leopoldstr. 21 80802 Munich [email protected] If you are UK customer: awork is registered with ICO Information Commissioner's Office Contact Person for ICO: Jennifer Winter Security number: CSN6055530 Registration reference: ZB867591 General information We process your personal data in accordance with the provisions of the European General Data Protection Regulation (GDPR). Where personal data is required to initiate or perform a contractual relationship or to carry out pre-contractual measures, processing is lawful pursuant to Art. 6(1)(b) GDPR. If you give us your express consent to process personal data for specific purposes (e.g. disclosure to third parties, analysis for marketing purposes or promotional contact by email), the lawfulness of this processing is based on your consent pursuant to Art. 6(1)(a) GDPR. You can withdraw consent you have given at any time with effect for the future. Where necessary and legally permitted, we process your data beyond the actual contractual purposes in order to comply with legal obligations pursuant to Art. 6(1)(c) GDPR. In addition, processing may take place to safeguard legitimate interests of ours or of third parties as well as to defend against and assert legal claims pursuant to Art. 6(1)(f) GDPR. Where required by law, we will inform you separately, stating the legitimate interest concerned. Your rights Below you will find information on the data subject rights that applicable data protection law grants you vis-à-vis the Controller with regard to the processing of your personal data: The right to request information pursuant to Art. 15 GDPR about the personal data of yours that we process. In particular, you may request information about the purposes of processing, the category of personal data, the categories of recipients to whom your data has been or will be disclosed, the planned storage period, the existence of a right to rectification, erasure, restriction of processing or objection, the existence of a right to lodge a complaint, the origin of your data if it was not collected by us, as well as the existence of automated decision-making including profiling and, where applicable, meaningful information about its details. The right to request pursuant to Art. 16 GDPR the immediate rectification of inaccurate personal data or the completion of personal data of yours stored by us. The right to request pursuant to Art. 17 GDPR the erasure of your personal data stored by us, unless the processing is necessary for exercising the right to freedom of expression and information, for compliance with a legal obligation, for reasons of public interest, or for the establishment, exercise or defence of legal claims. The right to request pursuant to Art. 18 GDPR the restriction of the processing of your personal data, where you contest the accuracy of the data, where the processing is unlawful but you object to its erasure, where we no longer need the data but you need it for the establishment, exercise or defence of legal claims, or where you have objected to the processing pursuant to Art. 21 GDPR. The right pursuant to Art. 20 GDPR to receive the personal data you have provided to us in a structured, commonly used and machine-readable format, or to request its transmission to another controller. The right to lodge a complaint with a supervisory authority pursuant to Art. 77 GDPR. As a rule, you can contact the supervisory authority of the federal state of our registered office stated above or, where applicable, that of your habitual residence or place of work. The right to withdraw consent given pursuant to Art. 7(3) GDPR: You have the right to withdraw consent to the processing of data once given at any time with effect for the future. In the event of withdrawal, we will erase the data concerned without delay, unless further processing can be based on a legal basis for processing without consent. The withdrawal of consent does not affect the lawfulness of the processing carried out on the basis of the consent up until its withdrawal. Right to object Where your personal data is processed by us on the basis of legitimate interests pursuant to Art. 6(1)(1)(f) GDPR, you have the right pursuant to Art. 21 GDPR to object to the processing of your personal data on grounds relating to your particular situation. Where the objection is directed against the processing of personal data for direct marketing purposes, you have a general right to object without having to state a particular situation. If you would like to exercise your right of withdrawal or objection, an email to [email protected] is sufficient. Automated decisions pursuant to Art. 22 GDPR The data subject has the right not to be subject to a decision based solely on automated processing – including profiling – which produces legal effects concerning them or similarly significantly affects them. This does not apply if the decision a) is necessary for entering into or performing a contract between the data subject and us, b) is authorised by Union or Member State law to which we are subject and which lays down suitable measures to safeguard the rights and freedoms and legitimate interests of the data subject, or c) is based on the data subject's explicit consent. Such decisions may not be based on special categories of personal data pursuant to Art. 9(1) GDPR, unless Art. 9(2)(a) or (g) GDPR applies and suitable measures to safeguard the rights and freedoms and legitimate interests of the data subject have been taken. In the cases referred to under a) and c), we take suitable measures to safeguard the rights and freedoms and legitimate interests of the data subject, which include at least the right to obtain human intervention on our part, to express their own point of view and to contest the decision. Legal obligations Providing personal data for the decision on entering into a contract, for the performance of a contract or for carrying out pre-contractual measures is voluntary. However, we can only make the decision within the scope of contractual measures if you provide the personal data that is necessary for entering into the contract, performing the contract or carrying out pre-contractual measures. Reservation of the right to make changes We reserve the right to amend or update this Privacy Policy where necessary, in compliance with applicable data protection law. This allows us to adapt it to current legal requirements and to reflect changes to our services, for example when introducing new services. The version in force at the relevant time always applies to your request. How to find your way around this Privacy Policy In the course of registration for and use of our awork WebApp, we process personal data for various purposes, all of which relate exclusively and directly to the use of the service. Some of the processing steps only take effect when you actively make use of them, such as contacting us or using support. Others already take place through registration and use of the software. Many of the data collection steps run automatically within the software. Likewise, the erasure of data also takes place largely automatically. In order to provide our services in the best and most efficient way possible, we use selected software providers for various purposes. We have carefully vetted and deliberately selected all providers Below we list the various purposes of data processing for you. In each case, we first explain the purpose of the processing, the categories of personal data and the legal basis for processing, then name the individual recipients of the data, explain again, where applicable, what we use the respective provider for specifically, address the data protection standard and finally state the retention period of the data collected. Should you have any further questions about data processing in connection with the use of awork, you can contact [email protected] at any time. Registration & user account Purposes of processing On our website we offer the option of registering for the awork service by providing your personal data. The data is entered into an input form, transmitted to us and stored in a user account. Registering a user account is necessary for the performance of a contract with the user or for carrying out pre-contractual measures, since the service can only be used with such an account and the booking process must be carried out within the software itself. The data is used for the one-time creation of the account, for personalising the service and for sending emails that are necessary for the performance of the contract. Categories of personal data The data collected during registration includes name, email address, a self-selected password, the IP address, a timestamp as well as further optional details about the company, marked as such, such as company size, industry and the intended use of the service. Legal bases for processing The legal basis for processing the data is the necessity for the performance of a contract pursuant to Art. 6(1)(b) GDPR. Recipients of the data The account data is processed by our qualified infrastructure provider on which the awork software service is operated. We use the Microsoft Azure Cloud for hosting our infrastructure components and for storing data. Microsoft Azure Cloud is ISO 27001 certified and guarantees a server location in Germany for hosting the application and storing workspace data. By way of exception, processing in connection with AI-supported features takes place within the EU or the EEA, but not necessarily in Germany; you can find details on this in the section „AI-supported features“. For delivering the application and protecting against cyberattacks, we additionally use Azure Front Door/CDN. In doing so, technical connection data such as IP address and browser information is processed; business data is not stored there permanently. If access takes place from a non-EU country, technical reasons may result in brief processing of this connection data via the nearest server; an adequacy decision or standard contractual clauses (SCC) apply in this case. Technical connection data is stored for a maximum of 30 days. Microsoft Ireland Operations Limited One Microsoft Place, South County Business Park Leopardstown, Dublin 18, Ireland Location: Frankfurt am Main, Germany (Germany West Central) and Berlin, Germany (Germany North) We use the SendGrid service from Twilio Inc. to send transactional emails out of the service, e.g. for password resets or notifications. Twilio Ireland Limited (SendGrid) 25-28 North Wall Quay Dublin 1, Ireland Data processing takes place on servers within the European Union. Data retention period The general data retention period until deletion serves the performance of the contract. Deletion of the account is initiated directly by the user. Login with Google, Apple or Microsoft For registration and login, in addition to the email and password options, there is also the possibility to authenticate yourself and ultimately register or log in with an existing profile at Google, Apple or Microsoft. For this purpose, the registration or login page contains the corresponding buttons with the icons of the respective providers. When you click the respective button, a new window opens in which you have to log in with your login details at the respective provider. After you have successfully logged in with the respective provider, you tell that provider which data will be transmitted to us for authentication in the course of the registration or login process. If this data transfer is agreed to, the fields required for registration with us are filled in with the transmitted data. The data required for registration or login with us are your name, email address and profile picture. Only once we have your explicit consent to the use of the transmitted and necessary data will your data be stored by us and used for the purposes stated above. There is no connection between the user account you are logged into with us and the Google, Apple or Microsoft account that goes beyond the authentication process. In order to carry out the authentication process for registration and login, your IP address is transmitted to the respective provider. We have no influence on the purpose and scope of the data collection and the further processing of the data by the respective provider. You can find further information on this in the privacy notices of the respective provider. Apple Inc. One Apple Park Way Cupertino California 95014 USA https://www.apple.com/de/legal/privacy/de-ww/ Google Ireland Limited Gordon House, Barrow Street Dublin 4, Ireland https://www.google.com/policies/privacy/partners/?hl=de Microsoft Corporation One Microsoft Way Redmond, WA 98052-6399, USA Privacy Policy: https://privacy.microsoft.com/de-de/privacystatement AI-supported features Purposes of processing awork provides AI-supported features to assist with the creation, summarisation, analysis and structuring of content. The AI features of the standard product can be deactivated by workspace administrators; the awork AI add-on is activated only after being booked separately. AI data processing takes place only if a corresponding feature is actually used and the model provided for this purpose is enabled in the workspace. The results serve as support and must be reviewed by users. The AI features do not make any solely automated decisions with legal or similarly significant effect within the meaning of Art. 22 GDPR. Categories of personal data Depending on the feature used, prompts and other inputs, the workspace context required for the request, selected project, task, time, contact, document or file content, as well as the text, image or other outputs generated from them are processed. Scope and content depend on the feature invoked and on the data selected or provided by the user. Legal bases for processing The processing takes place in order to provide the contractually agreed features pursuant to Art. 6(1)(b) GDPR. Insofar as awork processes workspace data on behalf of a business customer, that customer remains responsible for the lawfulness of the processing; awork processes the data in accordance with that customer's instructions and on the basis of the data processing agreement (DPA) concluded. Recipients of the data and model provision Which provider is used depends on the model selected or assigned for the respective feature. Only providers whose models are available and enabled for the workspace and are actually used are engaged. Microsoft Ireland Operations Limited – Azure AI Foundry One Microsoft Place, South County Business Park, Leopardstown, Dublin 18, Ireland Provision of selected OpenAI models within the EU Data Zone; primarily Germany West Central, fallback resource Sweden Central. OpenAI does not receive any direct access to prompts or model outputs via this processing path. Google Cloud EMEA Limited – Vertex AI 70 Sir John Rogerson’s Quay, Dublin 2, Ireland Provision of selected Google and Gemini models in Belgium (Google Cloud region europe-west1). Amazon Web Services EMEA SARL – Amazon Bedrock 38 Avenue John F. Kennedy, L-1855 Luxembourg Provision of selected Anthropic models exclusively via geographically restricted EU inference profiles. No global processing takes place; Anthropic does not receive access to prompts or model outputs via the Bedrock processing path. TensorX Ltd. Unit 25, Classon House, Dundrum Business Park, Dublin 14, Ireland Provision of selected AI models on TensorX's own hardware in Dublin and Helsinki. Prompts and model outputs are processed exclusively in volatile memory and are not passed on to the respective model providers. Data protection and safeguards Data processing agreements (DPAs) are in place with all providers. Transmission is encrypted and inference processing is limited to the respective regions stated within the EU or the EEA. Unlike the hosting of the awork application, which takes place exclusively in Germany, model inference therefore also takes place in other EU/EEA regions. Prompts and model outputs are not used to train general AI models. Depending on the provider, additional content and security filters or guardrails are used. The use of individual models can be deactivated by authorised workspace administrators. Data retention period The model inference services do not store the transmitted prompts and model outputs permanently. Insofar as chat histories or generated content are stored within awork, they remain exclusively in the awork infrastructure on Microsoft Azure and are subject to the storage and deletion rules applicable to the workspace. AI connectors Users can optionally connect awork’s AI agents to external services, including Google Workspace services such as Google Drive, Gmail and Google Calendar, as well as Microsoft 365, Slack, GitHub, Notion and other connectors available in awork. Connecting a service requires separate authorization by the user and access is limited to the permissions granted during that authorization. Depending on the connected service, the permissions granted and the tools enabled, an agent may: Access account and profile information. Search, read, create, edit, organize, upload or delete files and documents. Read, create or manage calendar events. Read, draft, organize or send messages or emails. Search, read, create or update other content in the connected service. Access to and actions within a connected service take place only as requested by an authorized user or through a workflow configured by that user. Data retrieved from a connected service is used only to provide the requested connector or AI functionality. Where required for an AI request, relevant data may be used as context for the selected AI model and may become part of an awork conversation or generated result. Processing by AI providers is described under “AI-supported features”. awork does not sell data obtained through connected services, use it for advertising, or use data obtained through Google Workspace APIs to develop, improve or train generalized or non-personalized AI or machine-learning models. awork’s use of information received from Google Workspace APIs complies with the Google API Services User Data Policy, including the Limited Use requirements. Authorization credentials are stored encrypted and are removed when the connection is deleted. Content that is stored in awork as part of a conversation or generated result follows awork’s regular retention and deletion rules. Subscription & billing Purposes of processing In connection with the subscription and billing, we process master data as well as contract data in order to fulfil our contractual obligations and to enable self-management of the subscription booked. For this purpose we use the subscription management service Chargebee as well as the payment provider Stripe. Categories of personal data Master data includes names and contact details of contact persons as well as contract data, e.g. for services used, data for payment transactions and invoice dispatch. In order to embed the booking process and the self-management of the subscription, we integrate a script application from Chargebee within awork. To enable it to load, your IP address and further browser information are automatically transmitted to Chargebee's servers and necessary cookies are set. Legal bases for processing The legal basis for processing the data is the necessity for the performance of a contract pursuant to Art. 6(1)(b) GDPR. Recipients of the data Chargebee is a service for managing software subscriptions and handles digital contract management as well as automated invoicing for us. Chargebee Inc. 340 S Lemon Ave # 1537 Walnut, California 91789, USA Privacy Policy: https://www.chargebee.com/privacy/ Chargebee provides an adequate level of protection and we have concluded a contract with Chargebee containing so-called standard contractual clauses (SCC), in which they undertake to process user data only in accordance with our instructions and to comply with the EU level of data protection. For data transfers to the USA there is an adequacy decision of the EU Commission pursuant to Art. 45(1) GDPR with regard to companies certified under the EU-U.S. Data Privacy Framework. Chargebee Inc. is certified under the EU-U.S. Data Privacy Framework and thereby undertakes to comply with adequate data protection standards, which can be viewed at the following link: https://www.dataprivacyframework.gov/list. For payment processing, SEPA direct debit or credit card payment, we use the payment service provider Stripe. Stripe Payments Europe Ltd. 1 Grand Canal Street Lower Grand Canal Dock, Dublin, Ireland Privacy Policy: https://stripe.com/de/privacy Data retention period Termination and deletion of the account, and thus also of the payment information stored in it, is initiated by the user, unless legal requirements call for longer retention periods. Marketing performance measurement Purposes of processing In order to run our marketing activities for our online offering economically, we use marketing services. These help us to deliver advertisements according to actual interests and to make the success of our marketing activities measurable. Processing for marketing and retargeting purposes takes place exclusively while awork is used in a free trial version or within a trial period. As soon as a paid contract has been concluded, the marketing services used are deactivated for the workspace concerned; no further processing for these purposes then takes place. You can learn more about how to opt out of receiving interest-based advertising from other companies at http://optout.aboutads.info/#!/ and http://www.networkadvertising.org/choices. When browsing the internet, you can also deactivate Google Analytics by installing the https://tools.google.com/dlpage/gaoptout from Google, and deactivate interest-based Google ads https://adssettings.google.com/u/0/authenticated. Categories of personal data This concerns the following personal data, which is transmitted automatically by your browser: IP address, time stamp, content of the request (which page was accessed), access status, volume of data transferred, website from which the request comes, cookies with markers of clicked advertising campaigns, browser, operating system, language and browser version. Legal bases for processing The processing of this personal data takes place on the basis of consent pursuant to Art. 6(1)(a) GDPR given when you are asked about the use of cookies for marketing & retargeting. Recipients of the data Google marketing services Google Ireland Limited Gordon House, Barrow Street Dublin 4, Ireland Privacy Policy: https://policies.google.com/privacy Google marketing services allow us to display advertisements for and on our website in a more targeted way, in order to present users only with ads that potentially match their interests. If, for example, a user is shown ads for products they have shown interest in on other websites, this is referred to as „remarketing“. For these purposes, when our website and other websites on which Google marketing services are active are accessed, code from Google is executed directly by Google and so-called (re)marketing tags (invisible graphics or code, also referred to as “web beacons”) are integrated into the website. With their help, an individual cookie, i.e. a small file, is stored on the user's device (instead of cookies, comparable technologies may also be used). The cookies can be set by various domains, including google.com, invitemedia.com, admeld.com, googlesyndication.com or googleadservices.com. This file records which websites the user has visited, which content they are interested in and which offers they have clicked on, as well as technical information about the browser and operating system, referring websites, visit time and further details on the use of the online offering. The user's IP address is also recorded, whereby we state, in the context of Google Analytics, that the IP address is truncated within member states of the European Union or in other contracting states of the Agreement on the European Economic Area and only in exceptional cases transferred in full to a Google server in the USA and truncated there. The IP address is not merged with data of the user within other Google offerings. Google may also combine the aforementioned information with such information from other sources. If the user subsequently visits other websites, ads tailored to their interests can be displayed to them. Users' data is processed in pseudonymised form within the Google marketing services. This means that Google does not store and process, for example, the name or email address of users, but processes the relevant data on a cookie-related basis within pseudonymous user profiles. In other words, from Google's point of view, the ads are not managed and displayed for a specifically identified person, but for the cookie holder, regardless of who that cookie holder is. This does not apply if a user has expressly permitted Google to process the data without this pseudonymisation. The information collected about users by Google marketing services is transmitted to Google and stored on Google's servers in the USA. The Google marketing services we use include, among others, the online advertising programme „Google AdWords“. In the case of Google AdWords, each AdWords customer receives a different „conversion cookie“. Cookies can therefore not be tracked across the websites of AdWords customers. The information obtained with the help of the cookie is used to create conversion statistics for AdWords customers who have opted for conversion tracking. AdWords customers learn the total number of users who clicked on their ad and were forwarded to a page with a conversion tracking tag. However, they do not receive any information that allows users to be personally identified. On the basis of the Google marketing service „AdSense“ we may integrate third-party advertisements. AdSense uses cookies which enable Google and its partner websites to serve ads based on users' visits to this website or other websites on the internet. Since the IP address is transferred to Google in the USA, additional safeguards are required to ensure the level of data protection of the GDPR. To ensure this, we have agreed standard contractual clauses with the provider pursuant to Art. 46(2)(c) GDPR. For data transfers to the USA, an adequacy decision of the EU Commission pursuant to Art. 45(1) GDPR exists with regard to companies certified under the EU-U.S. Data Privacy Framework. Google is certified under the EU-U.S. Data Privacy Framework and therefore undertakes to comply with adequate data protection standards, which can be verified at the following link: https://www.dataprivacyframework.gov/list You can find further information on the use of data for marketing purposes by Google on the overview page: https://policies.google.com/technologies/ads. If you would like to object to interest-based advertising by Google marketing services, you can use the settings and opt-out options provided by Google: https://adssettings.google.com/authenticated. Meta (Facebook) Custom Audiences and Meta marketing services Meta Platforms Ireland Limited Merrion Road Dublin 4, D04 X2K5, Ireland Privacy Policy: https://www.facebook.com/policy.php On our website we use "Meta Custom Audiences" (formerly "Facebook Custom Audiences"), a remarketing tool of Meta Platforms Ireland Limited, Merrion Road, Dublin 4, D04 X2K5, Ireland (hereinafter referred to as „Meta"). Meta Custom Audiences enables us to display interest-based advertisements, so-called “Facebook Ads“, to visitors of our website while they visit the social network Facebook or other websites that also use Meta Custom Audiences. Through the use of „Meta Custom Audiences", your web browser automatically establishes a direct connection with Meta's server. We have no influence on the scope and further use of the data collected by Meta through the use of Meta Custom Audiences. To our knowledge, Meta receives the information that you have accessed the relevant part of our website or clicked on an advertisement of ours. If you have a user account with Facebook and are registered, Meta can assign the visit to your user account. Even if you are not registered with Facebook or are not logged in, there is a possibility that Meta will obtain and store your IP address and, where applicable, further identifying characteristics. We use Meta Custom Audiences for marketing and optimisation purposes, in particular to display advertisements that are relevant and interesting for you and thus to improve our offering and make it more interesting for you as a user. The legal basis is Art. 6(1)(1)(a) GDPR (consent). We have concluded a data processing agreement (DPA) with our service provider Meta, in which we oblige it to protect our customers' data and not to pass it on to third parties. Since personal data is transferred to the USA, additional safeguards are required to ensure the level of data protection of the GDPR. To ensure this, we have agreed standard contractual clauses with the provider pursuant to Art. 46(2)(c) GDPR. These oblige the recipient of the data in the USA to process the data in accordance with the level of protection in Europe. In cases where this cannot be ensured even by this contractual extension, we endeavour to obtain additional arrangements and commitments from the recipient in the USA. You can find further information from Meta on data protection on the following Meta website: https://www.facebook.com/about/privacy Logged-in users can deactivate Meta Custom Audiences at https://www.facebook.com/settings/?tab=ads#_. Please note that this setting will also be deleted if you delete your cookies. X (formerly Twitter) Tailored Audiences Twitter International Unlimited Company One Cumberland Place, Fenian Street Dublin 2, D02 AX07, Ireland Privacy Policy: https://twitter.com/de/privacy OptOut: https://help.x.com/de/safety-and-security/privacy-controls-for-tailored-ads Our website uses the remarketing tool "Tailored Audiences" (also known as "Twitter Custom Audiences") of the platform X (formerly Twitter). For this purpose, the Twitter pixel or the Twitter website tag is implemented on our website. When you visit our website, a direct connection is established between your browser and X's server. X thereby receives the information that you have visited our site with your IP address. This enables X to assign your visit to our website to your X account (if you have one) and enables us to deliver targeted advertising to you on X. With the help of the Twitter website tag we can in particular analyse the success of our campaigns within X or define target groups for them on the basis of users' interaction with our online offering. Since personal data is transferred to the USA, additional safeguards are required to ensure the level of data protection of the GDPR. To ensure this, we have agreed standard contractual clauses with the provider pursuant to Art. 46(2)(c) GDPR. These oblige the recipient of the data in the USA to process the data in accordance with the level of protection in Europe. In cases where this cannot be ensured even by this contractual extension, we endeavour to obtain additional arrangements and commitments from the recipient in the USA. You can find further information from X on data protection on the following X website: https://twitter.com/de/privacy Please note that this setting will also be deleted if you delete your cookies. LinkedIn Insight Tag LinkedIn Corporation 2029 Stierlin Court Mountain View, CA 94043, USA Privacy Policy: https://www.linkedin.com/legal/privacy-policy OptOut: https://www.linkedin.com/psettings/guest-controls/retargeting-opt-out Within our online offering we use the marketing functions (so-called „LinkedIn Insight Tag“) of the LinkedIn network. Each time one of our pages containing LinkedIn functions is accessed, a connection to LinkedIn servers is established. LinkedIn is informed that you have visited our web pages with your IP address. With the help of the LinkedIn Insight Tag we can in particular analyse the success of our campaigns within LinkedIn or define target groups for them on the basis of users' interaction with our online offering. If you are registered with LinkedIn, LinkedIn is able to assign your interaction with our online offering to your user account. Also, if you click LinkedIn's “Recommend button” while logged into your LinkedIn account, LinkedIn is able to assign your visit to our website to you and your user account. We use the LinkedIn Insight Tag for marketing and optimisation purposes, in particular to display advertisements that are relevant and interesting for you and thus to improve our offering and make it more interesting for you as a user. The legal basis is Art. 6(1)(1)(a) GDPR (consent). We have concluded a data processing agreement (DPA) with our service provider LinkedIn, in which we oblige it to protect our customers' data and not to pass it on to third parties. For data transfers to the USA, an adequacy decision of the EU Commission pursuant to Art. 45(1) GDPR exists with regard to companies certified under the EU-U.S. Data Privacy Framework. Linkedin is certified under the EU-U.S. Data Privacy Framework and therefore undertakes to comply with adequate data protection standards, which can be verified at the following link: https://www.dataprivacyframework.gov/list. You can find further information on data protection on the following LinkedIn website: https://www.linkedin.com/legal/privacy-policy Logged-in users can deactivate the LinkedIn Insight Tag at https://www.linkedin.com/psettings/guest-controls/retargeting-opt-out. Please note that this setting will also be deleted if you delete your cookies. Outbrain Inc. 39 West 13th Street, 3rd Floor, New York, NY 10011, USA Privacy Policy: http://www.outbrain.com/legal/privacy On our website we use the Outbrain pixel of Outbrain Inc. This enables us to provide analytics in connection with our campaigns (advertisements) and advanced targeting functions. The pixel records which UUID (Unique User ID) has interacted on pages on which the pixels are installed, as well as the relevant timestamp, the referring source and the fact that a conversion has taken place. The pixel only tracks activity on an anonymised basis. The pixel does not track or collect any personal data, but merely checks whether a UUID is stored in the user's browser. If this is the case, we can deliver our advertisements to such UUIDs within the Outbrain network (retargeting). If no UUID is detected, the Outbrain pixel does not collect any information. In the case of Outbrain services, a transfer of data to the USA cannot be ruled out. For data transfers to the USA, an adequacy decision of the EU Commission pursuant to Art. 45(1) GDPR exists with regard to companies certified under the EU-U.S. Data Privacy Framework. Outbrain is certified under the EU-U.S. Data Privacy Framework and therefore undertakes to comply with adequate data protection standards, which can be verified at the following link: https://www.dataprivacyframework.gov/list. You can find further information on data protection at Outbrain in Outbrain's privacy information at http://www.outbrain.com/legal/privacy Bing Ads Microsoft Corporation One Microsoft Way Redmond, WA 98052-6399, USA Privacy Policy: https://privacy.microsoft.com/de-de/privacystatement Provided that you have given us your consent pursuant to Art. 6(1)(1)(a) GDPR, we use technologies of Bing Ads on the website, which are provided and operated by Microsoft Corporation. In this process, Microsoft sets a cookie on your device if you have reached our website via a Microsoft Bing advertisement. In this way, Microsoft and we can recognise that someone clicked on an advertisement, was forwarded to our website and reached a previously determined target page (“Conversion Site”). We only learn the total number of users who clicked on a Bing advertisement and were then forwarded to the Conversion Site. Via the cookie, Microsoft collects, processes and uses information from which usage profiles are created using pseudonyms. These usage profiles serve to analyse visitor behaviour and are used to deliver advertisements. No personal information about the identity of the user is processed. If you do not want information about your behaviour to be used by Microsoft as explained above, you can refuse the setting of the cookie required for this – for example via a browser setting that generally deactivates the automatic setting of cookies. In addition, you can prevent the collection of the data generated by the cookie and relating to your use of the website as well as the processing of this data by Microsoft by declaring your objection at the following link https://choice.microsoft.com/de-DE/opt-out. AdTriba GmbH Hoheluftchaussee 112 20253 Hamburg Germany Privacy Policy: https://www.adtriba.com/ On this website, data is collected and stored using AdTriba technologies, from which usage profiles are created using pseudonyms. These usage profiles serve to analyse visitor behaviour and are evaluated in order to improve our offering and design it in line with demand. Cookies may be used for this purpose. These are small text files that are stored locally on the device of the site visitor and thus enable recognition when our website is visited again. The pseudonymised usage profiles are not combined with personal data about the bearer of the pseudonym without separately granted, explicit consent. This website collects and uses cross-app and cross-device information for reporting purposes. This is expressly not personal data from which information about individual users could be viewed or traced back to specific users. Techniques are used that make it possible to track users across apps and devices, including cookie and ID synchronisation. You can object to the collection and storage of data at any time with effect for the future by switching off tracking by Adtriba (Opt-out from Adtriba Tracking) at the URL https://www.adtriba.com/privacy-policy. In addition, we use the service Segment of Twilio, Inc. on our website. Segment is an analytics and tracking service that helps us collect data on our website and forward it to the relevant evaluation services. Segment serves as a central interface for the collection and forwarding of user data. This enables us to improve your user experience, optimise our services and offer more relevant content. Data processing takes place primarily on servers within the European Union; for this we use Segment's "EU Data Residency" option. Processing in the USA within the Twilio infrastructure cannot be entirely ruled out, for example when forwarding to destination services configured by us. For data transfers to the USA, an adequacy decision of the EU Commission pursuant to Art. 45(1) GDPR exists with regard to companies certified under the EU-U.S. Data Privacy Framework; in addition, we have agreed standard contractual clauses with Twilio pursuant to Art. 46(2)(c) GDPR. The forwarded data is limited to what is necessary for the respective purpose. We use Segment in two separate contexts: firstly for the marketing performance measurement described above, which is limited to the test period, and secondly for the technical forwarding of usage and context data to Intercom in order to provide customer support (see section „Support & Help"). The two processing contexts are not combined. Twilio Ireland Limited 25-28 North Wall Quay Dublin, Ireland Privacy Policy: https://www.twilio.com/en-us/legal/privacy Support & Help As part of our service, we offer users various forms of assistance so that they can work efficiently with the software and resolve problems as quickly as possible. For the various support services, personal data is collected which is used exclusively to fulfil the request as well as for statistical analyses of support usage. Intercom – Support Chat Within the service, we offer our users the option of chatting with our support team in order to clarify questions and concerns as quickly as possible. For this purpose we use the chat of the service Intercom. When the awork service is loaded, a script application from Intercom is loaded automatically. In this process, the IP address and further browser information are automatically processed on Intercom's servers. When a chat is started, account information such as name, email address, language, associated customer, etc., as well as the content submitted as part of the request, is automatically processed by our support team and by Intercom. The legal basis for the processing of the data is the necessity for the performance of a contract pursuant to Art. 6(1)(b) GDPR, since support is an essential component of our software service. Intercom Inc. 55 2nd Street, 4th Floor, San Francisco, CA 94105 USA Privacy Policy: https://www.intercom.com/legal/terms-and-policies#privacy Intercom meets an adequate level of protection and we have concluded a contract with Intercom containing so-called standard contractual clauses, in which it undertakes to process user data only in accordance with our instructions and to comply with the EU level of data protection. For data transfers to the USA, an adequacy decision of the EU Commission pursuant to Art. 45(1) GDPR exists with regard to companies certified under the EU-U.S. Data Privacy Framework. Intercom is certified under the EU-U.S. Data Privacy Framework and therefore undertakes to comply with adequate data protection standards, which can be verified at the following link: https://www.dataprivacyframework.gov/list. Requests are deleted once the matter has been resolved. User profiles remain in Intercom until the customer terminates and deletes the account. HappySupport – Help Center We use HappySupport to maintain and provide our help center at https://support.awork.com. The help center is hosted in Germany. When the help center is accessed, technical data is processed, in particular IP address, browser type and version, operating system, pages accessed, referrer and time of access. When you use the search or feedback functions, the search query you entered, interactions and ratings are also processed. Workspace, account or support content is not automatically transferred from awork to HappySupport. The processing serves to provide, secure and improve the help center. The legal basis is Art. 6(1)(b) GDPR insofar as the help center forms part of the contractual service, and Art. 6(1)(f) GDPR for secure and trouble-free operation. The search function can generate AI-assisted answers. For this purpose, HappySupport uses OpenAI, L.L.C. as a sub-processor. Search queries may be processed in the USA. The transfer is safeguarded by a data processing agreement (DPA) and the EU-U.S. Data Privacy Framework; according to HappySupport, the data is not used to train the models. HappySupport UG (haftungsbeschränkt) c/o Campus Founders Bildungscampus 11 74076 Heilbronn, Germany Privacy Policy: https://www.happysupport.ai/en/privacy A data processing agreement (DPA) is in place with HappySupport. According to HappySupport, server logs including IP addresses are generally stored for 90 days; interaction data is processed according to the retention periods defined by awork. Intercom – Onboarding messages We use the service Intercom to deliver emails and guides (small “speech bubbles” within the software explaining individual features) that support you when taking your first steps with the software. For this purpose, usage profiles of users are created and the features used as well as the onboarding messages received are recorded, so that these are only shown to relevant users. These profiles include account information such as name, email address, associated customer, language, booked plan, as well as usage statistics regarding certain features of the service and messages already received. The legal basis for processing the data is the necessity for the performance of a contract pursuant to Art. 6(1)(b) GDPR. Intercom Inc. 55 2nd Street, 4th Floor, San Francisco, CA 94105 USA Privacy Policy: https://www.intercom.com/legal/terms-and-policies#privacy Intercom provides an adequate level of protection and we have concluded a contract with Intercom containing what are known as standard contractual clauses (SCC), in which they undertake to process user data only in accordance with our instructions and to comply with the EU level of data protection. In addition, Intercom is certified under the EU-U.S. Data Privacy Framework and therefore commits to complying with adequate data protection standards, which can be verified at the following link: https://www.dataprivacyframework.gov/list. You can find further information about the data processing by Intercom in Intercom's Privacy Policy. Intercom – Update news & training material We use the service Intercom to deliver news about updates to the service as well as the availability of new training material by email. For this purpose, existing account information such as name, email address, associated customer, language, booked plan, as well as usage statistics regarding certain features of the service and messages already received are processed. The legal basis for processing the data is the necessity for the performance of a contract pursuant to Art. 6(1)(b) GDPR. Intercom Inc. 55 2nd Street, 4th Floor, San Francisco, CA 94105 USA Privacy Policy: https://www.intercom.com/legal/terms-and-policies#privacy Intercom provides an adequate level of protection and we have concluded a contract with Intercom containing what are known as standard contractual clauses (SCC), in which they undertake to process user data only in accordance with our instructions and to comply with the EU level of data protection. In addition, Intercom is certified under the EU-U.S. Data Privacy Framework and therefore commits to complying with adequate data protection standards, which can be verified at the following link: https://www.dataprivacyframework.gov/list. You can find further information about the data processing by Intercom in Intercom's Privacy Policy. You can stop receiving these emails at any time via the Unsubscribe link at the end of every email. Intercom - Support request management We process support requests using the service Intercom. In Intercom, requests can be handled by our support team in the form of “tickets” and used to correspond with users. Account information such as name, email address, language, associated customer, etc., as well as the content submitted as part of the request, is processed by our support team and by Intercom. If required, a separate account can be created with Intercom in order to manage your own support requests clearly. Intercom's privacy provisions apply here. The legal basis for processing the data is the necessity for the performance of a contract pursuant to Art. 6(1)(b) GDPR, as support is an essential component of our software service. Intercom Inc. 55 2nd Street, 4th Floor, San Francisco, CA 94105 USA Privacy Policy: https://www.intercom.com/legal/terms-and-policies#privacy Intercom provides an adequate level of protection and we have concluded a contract with Intercom containing what are known as standard contractual clauses (SCC), in which they undertake to process user data only in accordance with our instructions and to comply with the EU level of data protection. In addition, Intercom is certified under the EU-U.S. Data Privacy Framework and therefore commits to complying with adequate data protection standards, which can be verified at the following link: https://www.dataprivacyframework.gov/list. Requests are deleted once the matter has been resolved. User profiles remain in Intercom until the customer terminates and deletes the account. Birdie – Error reports from within the application For error reports made from within the application we use the service Birdie. Birdie only becomes active if you report an error yourself, for example using a screen recording. In doing so, your error description and comments, automatically collected technical data such as browser, operating system and console logs, screenshots or screen recordings optionally added by you, as well as basic user data such as name and email address for follow-up responses are processed. Business data from your workspace is not transferred automatically. The legal basis for processing the data is the necessity for the performance of a contract pursuant to Art. 6(1)(b) GDPR, as handling reported errors is an essential component of providing the service. Philo Labs (Birdie) 46 quai Henri IV 75004 Paris, France Privacy Policy: https://www.birdie.so/legals/privacy-policy A data processing agreement (DPA) is in place with Birdie, with guaranteed processing exclusively within the European Union (Paris, France); no transfer to a third country takes place. The transmission is encrypted and the data collected is limited to bug-relevant information. The data is automatically deleted 90 days after the ticket has been handled. Atlassian – Status Page In order to make the current availability of the service transparent, we use the service Status Page from Atlassian. The current and past status of the service can be viewed at https://status.awork.com/. The page is hosted and operated on Atlassian's servers. When the status page is accessed, the IP address and further browser data are automatically transmitted to Atlassian. On the status page you have the option to sign up for email notifications. Your email address is collected in the process. The legal basis for processing the data is the necessity for the performance of a contract pursuant to Art. 6(1)(b) GDPR. When registering for email notifications, the legal basis is the user's consent pursuant to Art. 6(1)(a) GDPR. Atlassian is a provider of software services relating to software development and operations. Atlassian Inc. 350 Bush Street Floor 13 San Francisco, CA 94104 USA Privacy Policy: https://www.atlassian.com/de/legal/privacy-policy Atlassian provides an adequate level of protection and we have concluded a contract with Atlassian containing what are known as standard contractual clauses (SCC), in which they undertake to process user data only in accordance with our instructions and to comply with the EU level of data protection. In addition, Atlassian is certified under the EU-U.S. Data Privacy Framework and therefore commits to complying with adequate data protection standards, which can be verified at the following link: https://www.dataprivacyframework.gov/list. Atlassian stores your email address only until consent to the processing is withdrawn, unless longer storage is legally required or permitted. You can find further information about the data processing by Atlassian in Atlassian's Privacy Policy. Analytics for product improvement Purposes of processing As part of the use of the service, we collect usage data from users for the ongoing improvement of the service. It serves to understand which features are used. Categories of personal data Event data is collected about the use of certain features and the pages on which this takes place. In addition to the pseudonymized account information, this includes the respective event, a timestamp, the IP address, and browser-specific information. Legal bases for processing The legal basis for processing the data is our legitimate interest within the meaning of Art. 6(1)(f) GDPR in the ongoing improvement of our service. Recipients of the data The data is processed by Mixpanel, a platform for product analytics. The data is processed in pseudonymized form on Mixpanel's servers and prepared for statistical analyses. Mixpanel Inc. 405 Howard St., 2nd Floor San Francisco, CA 94105 USA Mixpanel provides an adequate level of protection and we have concluded a contract with Mixpanel containing what are known as standard contractual clauses (SCC), in which they undertake to process user data only in accordance with our instructions and to comply with the EU level of data protection. For data transfers to the USA, an adequacy decision of the EU Commission pursuant to Art. 45(1) GDPR exists with regard to companies certified under the EU-U.S. Data Privacy Framework. Mixpanel is certified under the EU-U.S. Data Privacy Framework and therefore commits to complying with adequate data protection standards, which can be verified at the following link: https://www.dataprivacyframework.gov/list. Data retention period The data is automatically deleted after 12 months. If the user account is actively deleted by the user, the data is deleted along with it. Contact and sales activities Purposes of processing As part of the registration process, in addition to the account data we also collect data used to qualify companies for our sales activities. The data is processed by the service Hubspot. Hubspot is a customer relationship management software (CRM) for contact and deal management. Categories of personal data Contact information (name, email), information about the company (industry, size, intended use) as well as notes taken during the conversation and email correspondence are collected and processed on Hubspot's servers. Legal bases for processing The legal basis for processing the data is a legitimate interest within the meaning of Art. 6(1)(f) GDPR in handling user enquiries efficiently and quickly, in managing existing customers and in new customer business. Recipients of the data HubSpot Germany GmbH Am Postbahnhof 17 10243 Berlin Privacy Policy: https://legal.hubspot.com/de/privacy-policy We only process the data for as long as contract initiation is ongoing. You can object to the processing at any time by sending an email to: [email protected] Performance measurement Purposes of processing To ensure the operation of the system, we measure the performance of the individual infrastructure components of the service. In order to be able to draw conclusions about causes, such as increased request loads caused by users of the service, personal data in the form of server requests is processed here. The pseudonymised processing of the data is carried out by the service Datadog. Categories of personal data The personal data processed includes the address and type of the respective server request, time stamp, transferred data, notification of successful retrieval, browser version and the IP address. Legal bases for processing The legal basis for processing the data is the necessity for the performance of a contract pursuant to Art. 6(1)(b) GDPR. Recipients of the data The data is processed by the provider Datadog. Datadog is an observability platform for operating software applications. Datadog, Inc. 620 8th Avenue 45th Floor New York, NY 10018-1741 USA Datadog provides an adequate level of protection and we have concluded a contract with Datadog containing what are known as standard contractual clauses (SCC), in which they undertake to process user data only in accordance with our instructions and to comply with the EU level of data protection. For data transfers to the USA, there is an adequacy decision of the EU Commission pursuant to Art. 45(1) GDPR with regard to companies certified under the EU-U.S. Data Privacy Framework. Datadog is certified under the EU-U.S. Data Privacy Framework and therefore undertakes to comply with appropriate data protection standards, which can be viewed at the following link: https://www.dataprivacyframework.gov/list. Data retention period The general data retention period until deletion serves the performance of the contract. Deletion of the account is initiated by the user. Error tracking Purposes of processing During system operation, we record errors occurring in the application in order to detect disruptions early and to fix errors in the software applications efficiently. The pseudonymised processing of the data is carried out by the service Sentry. Categories of personal data The personal data processed includes the address and type of the respective server request, time stamp, transferred data, notification of successful retrieval, the error message, the stack trace, browser version and the IP address. Legal bases for processing The legal basis for processing the data is our legitimate interest within the meaning of Art. 6(1)(f) GDPR in ensuring error-free system operation. Recipients of the data The data is processed by the provider Sentry. Sentry is an error tracking platform for software applications used to record and categorise messages, deliver alerts to operators and make it easier for developers to trace and correct errors. Functional Software Inc. (Sentry) 32 Hawthorne Street San Francisco, CA 94107 USA Sentry provides an adequate level of protection and we have concluded a contract with Sentry containing what are known as standard contractual clauses (SCC), in which they undertake to process user data only in accordance with our instructions and to comply with the EU level of data protection. For data transfers to the USA, there is an adequacy decision of the EU Commission pursuant to Art. 45(1) GDPR with regard to companies certified under the EU-U.S. Data Privacy Framework. Sentry is certified under the EU-U.S. Data Privacy Framework and therefore undertakes to comply with appropriate data protection standards, which can be viewed at the following link: https://www.dataprivacyframework.gov/list. Data retention period The data is deleted automatically as soon as it is no longer required to solve the problem or for statistical analyses. Log files Purposes of processing We collect what are known as server log files for every server request on the servers on which the service is hosted. These serve security purposes, the traceability of data changes and the identification of problems in the course of operating the service and developing the product. The data is processed in pseudonymised form by the service Datadog. Categories of personal data The data processed includes the address and type of the respective server request, time stamp, transferred data, notification of successful retrieval, browser version and the IP address. Legal bases for processing The legal basis for processing the data is the necessity for the performance of a contract pursuant to Art. 6(1)(b) GDPR. Recipients of the data The data is processed by the log management service Datadog. Datadog enables our developers to collect and analyse logs and to detect and resolve anomalies and problems. Datadog, Inc. 620 8th Avenue 45th Floor New York, NY 10018-1741 USA Datadog provides an adequate level of protection and we have concluded a contract with Datadog containing what are known as standard contractual clauses (SCC), in which they undertake to process user data only in accordance with our instructions and to comply with the EU level of data protection. Data retention period Log file information is stored for a maximum of three months for statistical analysis and for security reasons and is deleted thereafter. Data whose further retention is necessary for evidentiary purposes is exempt from deletion until the respective incident has been finally clarified. Other services hCaptcha On our website we use the service hCaptcha provided by Intuition Machines Inc. hCaptcha is a service that protects input forms against spam and misuse through automated access (bots). When hCaptcha is used, a connection is established to the servers of Intuition Machines. The following data is processed in this context: the user's IP address, information about your browser and device, time spent on the website, mouse movements in the area of the hCaptcha, information about your operating system, solved CAPTCHAs. The data processing takes place on the basis of Art. 6(1)(f) GDPR (legitimate interest). Our legitimate interest lies in protecting our website and web app against abusive automated access and spam. You can prevent hCaptcha from running by deactivating JavaScript in your browser. Please note that in this case you may no longer be able to use our forms in full. Intuition Machines, Inc. 2443 Fillmore St #380-7571 San Francisco CA 94115 United States https://www.hcaptcha.com/privacy Intuition Machines Inc. provides an adequate level of protection. For data transfers to the USA, there is an adequacy decision of the EU Commission pursuant to Art. 45(1) GDPR with regard to companies certified under the EU-U.S. Data Privacy Framework. Intuition Machines Inc. is certified under the EU-U.S. Data Privacy Framework and therefore undertakes to comply with appropriate data protection standards, which can be viewed at the following link: https://www.dataprivacyframework.gov/list. Adobe fonts (Typekit) To ensure fonts are displayed consistently, we use so-called web fonts provided by Adobe. When you open a page, your browser loads the required web fonts into its cache in order to display texts and fonts correctly. For this purpose, the browser you use must connect to Adobe's servers. This gives Adobe knowledge that our website was accessed via your IP address. Adobe Fonts is used in the interest of a consistent and appealing presentation of our online offerings. The legal basis is Art. 6(1)(f) GDPR. You can configure your browser so that the fonts are not loaded from Adobe's servers (for example by installing add-ons such as NoScript or Ghostery). If your browser does not support Adobe Fonts or if you block access to Adobe's servers, the text will be displayed in the system's default font. Adobe Inc. 345 Park Avenue San Jose CA 95110 United States Privacy Policy: https://www.adobe.com/de/privacy/policies/adobe-fonts.html Google Fonts In addition to the Adobe fonts, we use Google Fonts to display fonts consistently. When you open the application, your browser loads the required font files from Google's servers. In doing so, your IP address is transmitted to Google; Google thereby receives the information that the application was accessed via your IP address. The legal basis is our legitimate interest within the meaning of Art. 6(1)(f) GDPR in a consistent and technically flawless presentation of our offering. We do not store this data beyond that. Google Ireland Limited Gordon House, Barrow Street Dublin 4, Ireland Privacy Policy: https://policies.google.com/privacy Where data is transferred to the USA in this context, there is an adequacy decision of the EU Commission pursuant to Art. 45(1) GDPR with regard to companies certified under the EU-U.S. Data Privacy Framework; Google is certified accordingly. YouTube – embedded videos In our application we embed videos from the YouTube platform, in particular instructional and training videos on individual features. The provider is Google Ireland Limited. When a video is played, a connection to YouTube's servers is established. In doing so, your IP address, information about your browser and device as well as the video accessed are transmitted; YouTube may use cookies or comparable technologies in this context. If you are logged in to YouTube or Google at the same time, YouTube can associate the video access with your user account. The legal basis for the processing is your consent pursuant to Art. 6(1)(a) GDPR. The video content is only loaded once you agree to playback; you can withdraw your consent at any time with effect for the future. Google Ireland Limited Gordon House, Barrow Street Dublin 4, Ireland Privacy Policy: https://policies.google.com/privacy Where data is transferred to the USA in this context, there is an adequacy decision of the EU Commission pursuant to Art. 45(1) GDPR with regard to companies certified under the EU-U.S. Data Privacy Framework; Google is certified accordingly. You can find further information in Google's Privacy Policy. LaunchDarkly We use the LaunchDarkly service in our app. LaunchDarkly is a feature management system that enables us to make specific features of our app available to, or hide them from, certain user groups. We use LaunchDarkly in particular to show or hide features according to the pricing model you have chosen. This ensures that you can only access the features included in your respective subscription. When you use our app, a pseudonymised user ID, information about your subscription/pricing model, information about your subscription/pricing model, and usage statistics on the various features are transmitted to LaunchDarkly. The data processing takes place on the basis of Art. 6(1)(b) GDPR (performance of a contract), as managing features in line with your subscription is necessary for the performance of our contract with you. The data processed in LaunchDarkly is stored for the duration of your use of our app and updated regularly. After you stop using it, the data is deleted after 90 days at the latest. LaunchDarkly, Inc. 101 Montgomery Street, Suite 550 San Francisco CA 94104 United States Privacy Policy: https://launchdarkly.com/privacy-policy/ Launch Darkly provides an adequate level of protection. For data transfers to the USA, there is an adequacy decision of the EU Commission pursuant to Art. 45(1) GDPR with regard to companies certified under the EU-U.S. Data Privacy Framework. LaunchDarkly is certified under the EU-U.S. Data Privacy Framework and thereby commits to complying with adequate data protection standards, which can be viewed at the following link: https://www.dataprivacyframework.gov/list. Google Drive & OneDrive storage Within our service we offer the option of linking files from Google Drive or Microsoft OneDrive with awork. awork does not store any data in the respective cloud storage. Conversely, the cloud storage does not receive any personal data from awork. If you authenticate with Google Drive or OneDrive from within awork, you do so directly with the provider. The data collected in this process, such as the IP address resulting from the access, is processed in accordance with the respective provider's terms. awork does not process or store the user name and password. Google Drive or OneDrive only returns a link, the type, the size and the name of the file to awork so that a link can be created. Cloud storage is used on the basis of Art. 6(1)(b) GDPR as part of the contractually agreed provision of the service. You can find further information on the handling of user data in Google's or Microsoft's Privacy Policy. Google Calendar, Apple Calendar & Microsoft Calendar Within our service we offer the option of displaying calendar entries from Google Calendar, Apple Calendar or Microsoft Calendar in awork. We also offer the option of creating calendar entries in Google Calendar, Apple Calendar or Microsoft Calendar from within awork. awork limits the use of the data to what is necessary to provide the features described. awork only stores, transfers, views or uses the user data received from these services in order to provide, improve and maintain the features. The use and transfer to other apps of information received from Google APIs is subject to the https://developers.google.com/terms/api-services-user-data-policy#additional_requirements_for_specific_api_scopes, including the limited use requirements. Cloud storage is used on the basis of Art. 6(1)(b) GDPR as part of the contractually agreed provision of the service. You can find further information on the handling of user data in Google's, Apple's or Microsoft's Privacy Policy. Microsoft Teams & Slack chat integrations As part of our service we offer the option of connecting Microsoft Teams and Slack chat with awork. awork sends project-related information such as project name, task name and comments to the respective providers. awork receives user messages from these providers when users mention the respective awork app directly. If you authenticate your awork via Microsoft or Slack, you do so directly with the provider. The data collected in this way through the access, such as the IP address, is processed in accordance with the respective provider's terms. awork does not process or store the user name and password. Microsoft Teams and Slack only return a URL and a few selected user profile details to awork that are necessary to provide this feature. Cloud storage is used on the basis of Art. 6(1)(b) GDPR as part of the contractually agreed provision of the service. You can find further information on the handling of user data in Microsoft's or Slack's Privacy Policy. Google Ireland Limited Google Building Gordon House, 4 Barrow St., Dublin, Ireland Privacy Policy: https://policies.google.com/privacy Microsoft Corporation One Microsoft Way Redmond, WA 98052-6399, USA Privacy Policy: https://privacy.microsoft.com/en-us/privacystatement Apple Inc. 1 Apple Park Way Cupertino, CA 95014, USA Privacy Policy: https://www.apple.com/legal/privacy/en-ww/ Slack Technologies Limited Salesforce Tower 60 R801, North Dock, Dublin, Ireland Privacy Policy: https://slack.com/trust/privacy/privacy-policy BoldSign – conclusion of contracts We use the service of BoldSign for creating and transmitting digital signatures for the purpose of concluding data processing agreements or our team-on-board guarantee. BoldSign supports users in setting up transactions digitally or electronically, in carrying them out or in proving their validity – for example by signing a data processing agreement electronically. The data collected using BoldSign is stored and processed in BoldSign’s EU data region (Netherlands). BoldSign is operated by Syncfusion, Inc., based in the USA. To ensure appropriate safeguards for any transfers to the USA, we have agreed standard contractual clauses with Syncfusion, Inc. pursuant to Art. 46(2)(c) GDPR; a data processing agreement is also in place. The legal basis for processing the personal data is the conclusion of a contract or the performance of pre-contractual measures under Art. 6(1)(b) GDPR and our legitimate interest in the associated evidence and documentation purposes under Art. 6(1)(f) GDPR. You can find further information on the handling of user data in BoldSign's Privacy Policy. Syncfusion, Inc. (BoldSign) 2501 Aerial Center Pkwy #111 Morrisville, NC 27560, USA Privacy Policy: https://boldsign.com/privacy-policy/ Data retention period We store the data for as long as it is needed for the performance of the contract, unless longer statutory retention obligations apply. All legal information Trust center The full overview of awork GmbH's security, compliance, governance, and trust documentation. Open General General Information about how your data is being processed on our pages and in our services. Open AGB (German version) Our General Terms & Conditions for awork, in the original German version. Download GT&C (English translation) The English translation of our General Terms & Conditions, provided for reference alongside the German original. Download AI Terms Additional terms governing the use of AI features within awork. Download AI Product Description A detailed description of how awork's AI features work and what data they use. Download Data processing addendum (‘DPA’) This contract governs how we process your data while using awork according to the EU’s General Data Protection Regulation (GDPR). Download While using awork Privacy policy for awork (the application, not this website). Open Website Privacy policy for our websites (including this one). Open Newsletter Privacy policy for our newsletters. Open Social media Privacy policy for our pages on Facebook, Instagram, LinkedIn etc. Open Partners Applies when you support us as an awork partner. Open Applicants Applies when you apply for a job with us. Open Market research Applies when you participate in our usability tests. Open Contact forms Applies when you contact us and arrange an appointment with us. Open How we bill An explanation of the rules we use to bill awork. Open Imprint Legal information for this website. Open Organise your agency with awork Try it for free – no credit card required. Thank you! Check your email for verification! Oops! Something went wrong while submitting the form. awork is ISO 27001 certified, fully compliant with the EU General Data Protection Regulation (GDPR) and hosted on ISO 27001 certified server locations in Europe. The awork app is available for desktop and mobile devices. awork is part of the German Association for the Digital Economy, shaping the future through creative solutions and state-of-the-art technologies. Product Our approachCustomer storiesPricingRoadmapIntegrations Features awork AIProject managementCapacity planningTime trackingawork Connectawork Docs Company About usJobsPressLegal & dataPrivacy policyImprint Ressources Work Happiness ReportAgency Happiness ClubAgency solutionsBlogTemplatesPartner Program Support WebinarsCommunityHelp centerDeveloper portalSystem status +49 40 238 312 300 [email protected]