Skip to content
WorkMentor
FeaturesPricingAboutContact
Get started
FeaturesPricingAboutContactGet started with WorkMentor

Privacy at WorkMentor

Privacy Policy

This policy explains how WorkMentor handles personal data across our public website, customer accounts, workforce tools, recruitment workflows, billing, support, and connected services.

Last updated August 24, 2026
  • We do not sell personal data.
  • Customers control the workforce data they place in WorkMentor.
  • Privacy requests are verified before data is disclosed or changed.

On this page

  1. 01Who we are and when this policy applies
  2. 02Our privacy roles
  3. 03Personal data we process
  4. 04Where data comes from
  5. 05Why we use personal data
  6. 06AI-assisted features
  7. 07Who receives personal data
  8. 08International transfers
  9. 09How long we keep data
  10. 10How we protect data
  11. 11Your choices and rights
  12. 12Children
  13. 13Changes to this policy

This document applies to WorkMentor and the WorkMentor services identified here. Customer contracts can provide additional detail for a specific service or deployment.

01

Who we are and when this policy applies

WorkMentor is a business operations platform that brings together people records, attendance, leave, payroll, projects, timesheets, invoicing, recruitment, performance, expenses, assets, automation, and security controls.

This policy applies to the WorkMentor website, the hosted WorkMentor application, public careers and invoice pages, support interactions, and services that link to this policy. A separate written agreement, order form, or data processing agreement may add terms for a particular customer.

02

Our privacy roles

WorkMentor has different legal roles depending on why data is processed.

Customer data

For employee, contractor, candidate, client, project, attendance, payroll, performance, expense, asset, and similar records submitted by a customer organization, that organization normally decides why and how the data is used. The organization is the controller and WorkMentor acts as its processor or service provider.

WorkMentor business data

WorkMentor acts as controller for website inquiries, customer account ownership, subscription and billing administration, service security, support records, product communications, and our own legal obligations.

03

Personal data we process

The information processed depends on the WorkMentor modules selected by a customer and the way its administrators configure access.

Website, account, and organization data

  • Name, work email, phone number, company name, team size, and messages submitted through website forms.
  • Account identifiers, login records, roles, reporting lines, organization name, subdomain, office locations, billing contacts, subscription status, and support communications.
  • Stripe customer and payment method references, card brand, last four digits, expiry month and year, and billing history. WorkMentor does not store full payment card numbers.

Workforce and HR data

  • Employee names, contact details, profile photos, addresses, emergency contacts, job details, departments, designations, managers, employment dates, working hours, and employment status.
  • Government identity details, date and place of birth, gender, marital status, religion, bank account details, salary, tax, provident fund, loans, allowances, deductions, and final settlement records when a customer chooses to store them.
  • Attendance times, work locations, work-from-home status, check-in images, device and browser details, network data, and IP addresses.
  • Face templates or related biometric descriptors when a customer enables face-based attendance. The customer is responsible for confirming that it has a valid legal basis and has completed any required impact assessment before enabling this feature.

Recruitment and performance data

  • Candidate names, contact details, addresses, resumes, cover letters, education, work experience, salary expectations, applications, interview records, evaluations, discussions, and hiring workflow history.
  • Performance criteria, scores, feedback, attendance and timesheet context, review status, and release history.

Operational and technical data

  • Projects, tasks, timesheets, clients, invoices, payments, accounting records, expenses, supporting documents, assets, maintenance records, and automation logs.
  • IP address, user agent, device type, browser, operating system, security events, authentication sessions, audit trails, API key activity, and diagnostic information.
  • Integration data such as Google account email, granted scopes, calendar identifiers, access tokens, refresh tokens, event details, and timezone when a user connects Google SSO or Google Calendar.
04

Where data comes from

  • You, when you create an account, submit a form, connect an integration, contact support, or use the service.
  • Your employer, customer organization, authorized administrators, managers, payroll staff, recruitment staff, or colleagues.
  • Candidates and other people who submit information through a public careers page.
  • Connected services, such as Google and Stripe, when you or an authorized customer administrator enables them.
  • Browsers, devices, servers, and security systems as part of operating and protecting the service.
05

Why we use personal data

PurposeTypical basis when WorkMentor is controller
Provide and administer WorkMentorContract performance and steps requested before a contract
Secure accounts, investigate abuse, keep audit records, and prevent fraudLegitimate interests and legal obligations
Manage subscriptions, invoices, and payment statusContract performance and legal obligations
Respond to support, sales, and privacy requestsContract performance, legitimate interests, and legal obligations
Improve reliability, diagnose faults, and understand feature useLegitimate interests, with consent where local law requires it
Send service notices and requested product informationContract performance, legitimate interests, or consent as applicable
Important

When WorkMentor acts as a processor, the customer organization determines the purpose and legal basis. Users should direct questions about an employer's HR, payroll, recruitment, or monitoring decision to that organization first.

06

AI-assisted features

WorkMentor can use machine-assisted tools to extract structured information from resumes, compare candidate information with job criteria, and support analysis in selected workflows. These tools can produce incomplete or inaccurate results and are intended to assist authorized users, not replace their judgment.

WorkMentor does not make final hiring, employment, payroll, disciplinary, or performance decisions for customers. Customer organizations must review outputs, provide appropriate notices, avoid unlawful discrimination, and make any legally significant decision through qualified people.

07

Who receives personal data

We share data only where needed to provide the service, follow customer instructions, protect WorkMentor, complete a transaction, or meet a legal requirement. We do not sell personal data.

  • Authorized users within the relevant customer organization, according to roles, reporting hierarchy, and module permissions.
  • Cloud hosting, database, cache, queue, file storage, email delivery, monitoring, and support providers working under contractual restrictions.
  • Wasabi for private file storage, Stripe for subscription and invoice payments, Google for enabled SSO, Calendar, Maps, or AI-assisted features, and Bugsnag for error diagnostics.
  • Professional advisers, auditors, insurers, prospective transaction parties, courts, regulators, and law enforcement where legally permitted or required.
  • Other services selected and authorized by a customer or user. Their own terms and privacy notices also apply.
08

International transfers

WorkMentor and its providers may process data in countries other than the country where the user or customer is located. Where data protection law requires safeguards for a transfer, we use an approved transfer mechanism, contractual protections, and appropriate technical and organizational measures. Customers may request information relevant to their deployment and agreement.

09

How long we keep data

We keep data only while it is reasonably needed for the purpose described in this policy, the customer agreement, security, dispute resolution, or law. Because customers configure different modules and may have their own employment, payroll, tax, recruitment, and records-management duties, one retention period does not fit every customer record.

  • Customer data is retained for the active service period and then returned or deleted according to the customer agreement, customer instructions, backup cycles, and legal exceptions.
  • Authentication sessions expire or are revoked. Expired refresh-token records are automatically removed through database expiry controls.
  • Billing, tax, transaction, and contract records may be kept for statutory accounting and dispute periods.
  • Security logs, audit trails, and diagnostic records are kept for a period proportionate to security, accountability, and operational needs.
  • A scheduled organization deletion removes tenant records after the configured notice period unless the deletion is cancelled or a legal hold applies.
10

How we protect data

WorkMentor uses tenant separation, role-based permissions, audit trails, session controls, password policies, optional two-factor authentication, Google SSO controls, scoped API keys, IP restrictions, encrypted transport, private object storage, monitoring, backups, and restricted operational access. No online service can guarantee absolute security, so customers and users must also protect credentials, configure roles carefully, and report suspected misuse promptly.

11

Your choices and rights

Depending on location and context, you may have rights to be informed, access personal data, correct inaccurate data, request deletion, restrict processing, receive portable data, object to certain processing, withdraw consent, and ask for human review of certain automated decisions.

For workforce or candidate data controlled by a customer organization, contact that organization first. WorkMentor will assist the customer as required by contract and applicable law. For data controlled directly by WorkMentor, submit a request through our contact page. We may verify identity and authority before acting on a request.

12

Children

WorkMentor is a business service and is not directed to children. Customers must not use WorkMentor to process a child's data unless they have a lawful and appropriate reason, suitable notices, and any consent required by local law.

13

Changes to this policy

We may update this policy when the service, providers, or legal requirements change. We will post the revised date here and provide additional notice when a change materially affects how personal data is used.

Questions and requests

Contact the right team.

For workforce or candidate data, contact the organization that collected it. For WorkMentor account, website, billing, or policy questions, contact WorkMentor.

Contact WorkMentor

Related documents

Cookie PolicyGDPR and Data RightsTerms of Service

Your next operating system

Bring the work together.

Get started
WorkMentor

Run people operations, attendance, payroll, projects, hiring, performance, and business workflows from one connected workspace.

Product

People operationsAttendance and leavePayrollProjects and timesheetsClient invoicing

Company

AboutPricingContact

© 2026 WorkMentor. All rights reserved.

PrivacyTermsCookiesGDPR