Legal
GDPR Information
Last updated: 16 June 2026
This page provides information for individuals and organizations in the European Economic Area (EEA), United Kingdom, and Switzerland regarding the General Data Protection Regulation (GDPR), UK GDPR, and similar laws. It supplements our Privacy Policy.
1. Roles: controller and processor
ProjectWorks as controller: For account registration, billing, marketing (where consented), website analytics (where used), and platform security logs relating to your identity, ProjectWorks.ai acts as an independent data controller.
ProjectWorks as processor: For workspace content (projects, documents, tasks, AI outputs) submitted by or on behalf of an enterprise customer, your organization is typically the data controller and ProjectWorks processes data according to your instructions and our Data Processing Agreement (DPA).
2. Categories of personal data
- Identity and contact data (name, email, organization)
- Authentication data (user IDs, SSO attributes, SCIM metadata)
- Professional and project content you upload or generate
- Usage, technical, and security logs
- Billing and subscription records
3. Purposes and lawful bases
- Contract (Art. 6(1)(b)): providing the Service, support, and account administration
- Legitimate interests (Art. 6(1)(f)): security, fraud prevention, service improvement, and internal analytics — balanced against your rights
- Consent (Art. 6(1)(a)): optional marketing communications or non-essential cookies where required
- Legal obligation (Art. 6(1)(c)): tax, accounting, and regulatory compliance
Where we process special category data inadvertently submitted in Customer Content, we rely on your organization's lawful basis as controller or explicit consent where applicable.
4. Recipients and subprocessors
We use subprocessors for hosting, authentication, payments, email, and AI inference. They process data only under contract and appropriate safeguards. Enterprise customers may request the current subprocessor list and notification of material changes.
5. International transfers
Personal data may be transferred to the United States and other countries. For EEA/UK transfers, we implement:
- Standard Contractual Clauses (SCCs) approved by the European Commission / UK ICO
- Supplementary technical and organizational measures where required by transfer impact assessments
- Data Processing Agreements with enterprise customers
6. Retention
We retain personal data only as long as necessary for the purposes described in our Privacy Policy, including active account duration, backup cycles, and legal obligations. Workspace deletion requests are handled per our Data Handling procedures.
7. Your rights
Subject to conditions and exceptions in GDPR, you may have the right to:
- Access a copy of your personal data
- Rectify inaccurate data
- Erase data ("right to be forgotten")
- Restrict processing in certain circumstances
- Data portability in a structured, machine-readable format
- Object to processing based on legitimate interests or for direct marketing
- Withdraw consent at any time (without affecting prior lawful processing)
- Lodge a complaint with your local supervisory authority
To exercise rights, email privacy@projectworks.ai. If we act as processor, we may forward your request to your employer as controller. We respond within one month, extendable where permitted.
8. Automated decision-making
The Service uses AI to suggest plans, scores, and actions. These outputs support human decision-making and do not produce legal or similarly significant effects solely through automated processing without human review. You should validate all AI recommendations before acting on them.
9. Data Protection Contact
Data protection inquiries: privacy@projectworks.ai
For enterprise DPAs and subprocessors: legal@projectworks.ai
10. Supervisory authorities
EEA residents may contact their local data protection authority. UK residents may contact the Information Commissioner's Office (ICO) at ico.org.uk.