Skip to content

Legal

Data Processing Agreement

Data Processing Agreement

This Data Processing Agreement (the "DPA") sets out how Internative Yazılım Anonim Şirketi ("Internative Yazılım A.Ş.", "we"), the company behind Worktivity, processes personal data on behalf of the organization that subscribes to Worktivity (the "Customer", "you").

1. Parties and scope

The Customer is the controller of the personal data of its employees and managers that it puts into Worktivity. Internative Yazılım A.Ş., based in Istanbul, Türkiye, is the processor. Contact: privacy@useworktivity.com.

This DPA is an addendum to the Worktivity Terms and Conditions and forms part of your subscription. It takes effect when you subscribe; no separate signature is needed. If you want a signed copy, write to privacy@useworktivity.com.

If this DPA and the Terms and Conditions conflict on a question of personal data, this DPA prevails.

2. Subject matter, duration, nature and purpose

  • Subject matter and purpose: providing the Worktivity service to the Customer.
  • Duration: the length of the subscription, plus the period needed to delete data afterwards (section 11).
  • Nature of processing: collecting, storing, organizing, displaying, analyzing and deleting the data listed in Annex 1, through the Worktivity web panel, desktop and mobile apps and browser extension.

3. Data and people covered

Annex 1 lists the types of personal data and the people they relate to. The data subjects are the Customer's employees and managers. Special categories of personal data are not the aim of the service. Health data is processed only to the extent of the sick leave type that the Customer itself records, and the service also processes performance and behavior assessments (productivity scores). The Customer must not knowingly send any other special categories of personal data (for example political opinions) to Worktivity.

4. Processing on documented instructions

We process personal data only on the Customer's documented instructions. The subscription, this DPA and the settings the Customer chooses in the product are those instructions. If we believe an instruction breaks data protection law, we tell the Customer.

5. Confidentiality

Everyone we authorize to process the Customer's personal data is bound by a duty of confidentiality.

6. Security measures

We protect personal data with the measures in Annex 2. We review them as the service changes.

7. Sub-processors

The Customer gives us general written authorization to use sub-processors. The current list is in Annex 3.

When we add or replace a sub-processor, we give reasonable notice in advance, by email or through a product or website update. The Customer may object on reasonable grounds. If we cannot resolve the objection, the Customer may end the subscription.

Each sub-processor is bound by a data processing agreement with data protection obligations equivalent to those in this DPA.

8. Help with data subject requests

If a data subject contacts us about data we process for the Customer, we pass the request to the Customer without undue delay and do not answer it on the Customer's behalf. We help the Customer respond to such requests, mainly through the tools in the product.

9. Personal data breach

If we become aware of a personal data breach affecting the Customer's data, we notify the Customer without undue delay. The notice describes the nature of the breach, the data affected and the measures taken.

10. Impact assessments and audits

We help the Customer with data protection impact assessments and prior consultation with a supervisory authority, to the extent the help relates to our processing.

The Customer may audit our compliance with this DPA on reasonable written request and reasonable advance notice, in a way that does not disrupt our work. Where it is enough, we answer through documents and written replies.

11. Deletion or return at the end of the service

The Customer can delete its organization inside the product. How that works is described in the account deletion document. Deletion marks the records as deleted; this page does not claim that they are destroyed at that moment.

Screenshots and timelapse videos are deleted nightly once their retention period ends. Activity data, timesheets and manual entries are kept for 12 months on Starter, Growth and Pro. Screenshots and timelapse videos are kept for 2 months on Starter, 4 months on Growth and 6 months on Pro. On a free trial all three windows are 1 month.

We may keep records that the law requires us to keep, for example invoicing and tax records.

If the Customer wants its data returned, it can send a reasonable written request, and we will provide it through the product's export features or through support.

12. International transfers

We operate from Türkiye. Where personal data from the European Economic Area (EEA) is transferred to us, the European Commission's Standard Contractual Clauses apply: Module 2 (controller to processor), or Module 3 (processor to processor) if the Customer itself acts as a processor. They are incorporated into this DPA by reference.

The details the clauses leave to the parties are completed in a signed copy, which we provide on request. Annex 3 states which sub-processors are outside the EEA.

13. Governing law and courts

As in the Terms and Conditions, disputes arising from or related to this DPA fall under the exclusive jurisdiction of the courts of Istanbul Anatolia, Türkiye.

14. Annexes

Annex 1: Data and data subjects

ItemDetail
Data subjectsThe Customer's employees and managers
Account dataName, email address, role, team membership
Working timeClock-in and clock-out records
Usage dataApplication and website usage
ScreenshotsOnly if the organization has switched screenshots on in its settings
OtherLeave and permission records (including the sick leave type), projects
AssessmentsPerformance and behavior assessments (productivity scores)

Annex 2: Security measures

  • Data in transit is protected with TLS (HTTPS).
  • Customers are separated from each other: every query is filtered by the organization's identifier.
  • Administrative access to our servers is closed to the open internet and reachable only over a private network.
  • Access is role based. A manager sees only their own teams.
  • Sign-in is protected against bots with Cloudflare Turnstile.
  • A nightly job deletes data past its retention period, the stored file and the record together.

Annex 3: Sub-processors

NamePurposeLocation
Contabo GmbHServer hosting (application and database server)Munich, Germany (EU region)
Wasabi TechnologiesFile storage (screenshots, timelapse videos, uploaded files)Frankfurt, Germany (EU)
Mailgun (Sinch)Transactional emailEU region
OpenAIAI features (insight summaries, help summaries, generated text). Only what a given summary needs is sent. An owner can switch these features off for the organization.United States (outside the EEA)
CloudflareBot protection (Turnstile) at sign-in and sign-upGlobal network
OneSignalNotifications (for example task assignments)Provider-operated infrastructure, may be outside the EEA
PaddlePayments, merchant of record. For payment data Paddle is responsible in its own right: for subscription billing it acts as an independent controller, not as our processor.Provider-operated

AI providers and integrations that the Customer connects itself are not our sub-processors. They are recipients the Customer chooses. Analytics on our marketing website does not process Customer data and is not listed.

15. Contact and changes

Questions about this DPA: privacy@useworktivity.com. When we make a material change to this DPA, we notify the Customer. The date of the current version is at the top of this page.

This document is published in English, Turkish and German. The English version is the binding one; the translations are provided for information only.