Legal
Data Processing Agreement
Data Processing Agreement
This Data Processing Agreement (the "DPA") sets out how Internative Yazılım Anonim Şirketi ("Internative Yazılım A.Ş.", "we"), the company behind Worktivity, processes personal data on behalf of the organization that subscribes to Worktivity (the "Customer", "you").
1. Parties and scope
The Customer is the controller of the personal data of its employees and managers that it puts into Worktivity. Internative Yazılım A.Ş., based in Istanbul, Türkiye, is the processor. Contact: privacy@useworktivity.com.
This DPA is an addendum to the Worktivity Terms and Conditions and forms part of your subscription. It takes effect when you subscribe; no separate signature is needed. If you want a signed copy, write to privacy@useworktivity.com.
If this DPA and the Terms and Conditions conflict on a question of personal data, this DPA prevails.
2. Subject matter, duration, nature and purpose
- Subject matter and purpose: providing the Worktivity service to the Customer.
- Duration: the length of the subscription, plus the period needed to delete data afterwards (section 11).
- Nature of processing: collecting, storing, organizing, displaying, analyzing and deleting the data listed in Annex 1, through the Worktivity web panel, desktop and mobile apps and browser extension.
3. Data and people covered
Annex 1 lists the types of personal data and the people they relate to. The data subjects are the Customer's employees and managers. Special categories of personal data are not the aim of the service. Health data is processed only to the extent of the sick leave type that the Customer itself records, and the service also processes performance and behavior assessments (productivity scores). The Customer must not knowingly send any other special categories of personal data (for example political opinions) to Worktivity.
4. Processing on documented instructions
We process personal data only on the Customer's documented instructions. The subscription, this DPA and the settings the Customer chooses in the product are those instructions. If we believe an instruction breaks data protection law, we tell the Customer.
5. Confidentiality
Everyone we authorize to process the Customer's personal data is bound by a duty of confidentiality.
6. Security measures
We protect personal data with the measures in Annex 2. We review them as the service changes.
7. Sub-processors
The Customer gives us general written authorization to use sub-processors. The current list is in Annex 3.
When we add or replace a sub-processor, we give reasonable notice in advance, by email or through a product or website update. The Customer may object on reasonable grounds. If we cannot resolve the objection, the Customer may end the subscription.
Each sub-processor is bound by a data processing agreement with data protection obligations equivalent to those in this DPA.
8. Help with data subject requests
If a data subject contacts us about data we process for the Customer, we pass the request to the Customer without undue delay and do not answer it on the Customer's behalf. We help the Customer respond to such requests, mainly through the tools in the product.
9. Personal data breach
If we become aware of a personal data breach affecting the Customer's data, we notify the Customer without undue delay. The notice describes the nature of the breach, the data affected and the measures taken.
10. Impact assessments and audits
We help the Customer with data protection impact assessments and prior consultation with a supervisory authority, to the extent the help relates to our processing.
The Customer may audit our compliance with this DPA on reasonable written request and reasonable advance notice, in a way that does not disrupt our work. Where it is enough, we answer through documents and written replies.
11. Deletion or return at the end of the service
The Customer can delete its organization inside the product. How that works is described in the account deletion document. Deletion marks the records as deleted; this page does not claim that they are destroyed at that moment.
Screenshots and timelapse videos are deleted nightly once their retention period ends. Activity data, timesheets and manual entries are kept for 12 months on Starter, Growth and Pro. Screenshots and timelapse videos are kept for 2 months on Starter, 4 months on Growth and 6 months on Pro. On a free trial all three windows are 1 month.
We may keep records that the law requires us to keep, for example invoicing and tax records.
If the Customer wants its data returned, it can send a reasonable written request, and we will provide it through the product's export features or through support.
12. International transfers
We operate from Türkiye. Where personal data from the European Economic Area (EEA) is transferred to us, the European Commission's Standard Contractual Clauses apply: Module 2 (controller to processor), or Module 3 (processor to processor) if the Customer itself acts as a processor. They are incorporated into this DPA by reference.
The details the clauses leave to the parties are completed in a signed copy, which we provide on request. Annex 3 states which sub-processors are outside the EEA.
13. Governing law and courts
As in the Terms and Conditions, disputes arising from or related to this DPA fall under the exclusive jurisdiction of the courts of Istanbul Anatolia, Türkiye.
14. Annexes
Annex 1: Data and data subjects
| Item | Detail |
|---|---|
| Data subjects | The Customer's employees and managers |
| Account data | Name, email address, role, team membership |
| Working time | Clock-in and clock-out records |
| Usage data | Application and website usage |
| Screenshots | Only if the organization has switched screenshots on in its settings |
| Other | Leave and permission records (including the sick leave type), projects |
| Assessments | Performance and behavior assessments (productivity scores) |
Annex 2: Security measures
- Data in transit is protected with TLS (HTTPS).
- Customers are separated from each other: every query is filtered by the organization's identifier.
- Administrative access to our servers is closed to the open internet and reachable only over a private network.
- Access is role based. A manager sees only their own teams.
- Sign-in is protected against bots with Cloudflare Turnstile.
- A nightly job deletes data past its retention period, the stored file and the record together.
Annex 3: Sub-processors
| Name | Purpose | Location |
|---|---|---|
| Contabo GmbH | Server hosting (application and database server) | Munich, Germany (EU region) |
| Wasabi Technologies | File storage (screenshots, timelapse videos, uploaded files) | Frankfurt, Germany (EU) |
| Mailgun (Sinch) | Transactional email | EU region |
| OpenAI | AI features (insight summaries, help summaries, generated text). Only what a given summary needs is sent. An owner can switch these features off for the organization. | United States (outside the EEA) |
| Cloudflare | Bot protection (Turnstile) at sign-in and sign-up | Global network |
| OneSignal | Notifications (for example task assignments) | Provider-operated infrastructure, may be outside the EEA |
| Paddle | Payments, merchant of record. For payment data Paddle is responsible in its own right: for subscription billing it acts as an independent controller, not as our processor. | Provider-operated |
AI providers and integrations that the Customer connects itself are not our sub-processors. They are recipients the Customer chooses. Analytics on our marketing website does not process Customer data and is not listed.
15. Contact and changes
Questions about this DPA: privacy@useworktivity.com. When we make a material change to this DPA, we notify the Customer. The date of the current version is at the top of this page.
This document is published in English, Turkish and German. The English version is the binding one; the translations are provided for information only.