OKWorkD · Privacy
Privacy Policy
This notice explains personal-data processing when you use okworkd.com or the OKWorkD Android application.
1. Who is responsible
OKWorkD provides the workforce and HR platform. For employee records entered and managed by an organization, that organization generally decides why and how the records are used and is normally the primary contact for its workforce. OKWorkD processes platform and service data to provide, secure and support the service. The exact legal role may depend on the relevant agreement and processing activity.
Privacy contact: no-reply@okworkd.com
2. Data we may process
- Account and contact data, such as name, email, telephone number, user ID, company, department and position.
- Employment and HR data, such as shifts, attendance, leave, overtime, salary advances, payroll, tax, benefits, contracts, warnings and related documents.
- Location, photos, uploaded files and device information when an enabled function requires them, including attendance-location and registered-device controls.
- Requests, help messages, notifications, consent/acknowledgement records and audit/security logs.
- Technical data, such as IP address, browser/app details, cookies, session identifiers, timestamps and error logs.
- Commercial records created on the website, including package, quotation, order, invoice and payment-verification data. Package purchasing and Token top-ups are not offered inside the Android app.
3. Purposes and legal grounds
We process data to authenticate users, provide authorized HR functions, record attendance, generate requested documents, communicate notifications, support users, prevent fraud, investigate incidents, maintain auditability, meet contractual obligations and comply with applicable law. Depending on the activity, processing may rely on performance of a contract, legal obligations, legitimate interests, or consent where the law requires it. An employer remains responsible for selecting an appropriate legal ground for employee data it controls.
4. Disclosures and service providers
Data is visible only according to account, company and role permissions. We may use hosting, email, notification, mapping/CDN, security/CAPTCHA, payment/slip-verification and support providers when the relevant feature is enabled. Examples may include LINE, Google reCAPTCHA, EasySlip and infrastructure providers. Providers receive only data needed for their task and may process data in another country; appropriate contractual and security measures should be used where required.
We may disclose information when required by law, a lawful authority, to protect rights and safety, or in a corporate transaction subject to suitable safeguards. We do not state that every third party is an independent recipient; its role depends on the actual service and agreement.
5. Retention and deletion
Data is kept only as long as necessary for the stated purposes, the active service relationship, dispute/security handling and applicable employment, tax, accounting or other legal duties. Different records therefore have different periods. Deleted information may remain temporarily in protected backups until the normal backup cycle expires. Where immediate deletion is not legally permitted, access may be restricted and the data retained only for the required purpose.
6. Security
Measures include role-based access, password hashing, session and request protections, encryption in transit, device/location controls where enabled, logging, backups and restricted administration. No internet service can promise absolute security. Please use a strong unique password, protect your device and notify us or your organization promptly about suspected misuse.
7. Your choices and rights
Subject to applicable law, you may ask for access, a copy, correction, deletion, restriction, objection, data portability, withdrawal of consent, or information about processing. A request may require identity and authority verification. Withdrawing consent does not invalidate earlier lawful processing and some records may still need to be retained.
8. Cookies, children and changes
Essential cookies and local browser/app storage support login, security, language, preferences, installation and notifications. The service is intended for workplace users and is not directed to children. We may update this policy when functions, providers or laws change; the current version and effective date will remain on this public URL.