LEGAL CENTER

PRIVACY

Privacy Policy

A detailed account of the information Corporate Suite handles, why we handle it, who receives it, how long it remains, and the choices available to individuals and customers.

Effective
August 3, 2026
Last updated
August 3, 2026
01

Scope and our role

This Privacy Policy explains how The Working Company, Inc. (TWC, we, us, or our) handles personal information when you visit corporatesuite.co, create or use a Corporate Suite account, communicate with us, or otherwise interact with our websites, applications, APIs, and services (collectively, the Service).

TWC is the controller or business for account, billing, website, security, support, and direct relationship information. For personal information in workspace content that a customer submits and controls, TWC generally acts as the customer's processor or service provider. In that case, the customer decides why and how the data is used, and requests about that content should normally be directed to the customer. Our Data Processing Addendum governs covered processing on behalf of customers.

This Policy does not govern third-party services that you connect to Corporate Suite or external websites you visit. Their own notices apply to their independent processing.

02

Information we collect

Information you provide

  • Account and profile: name, email address, profile image, time zone, authentication identifiers, organization, role, and preferences.
  • Workspace and Customer Content: tasks, projects, spaces, databases, files, messages, calendars, plans, prompts, agent instructions, generated outputs, comments, and other content you or your organization submit.
  • Billing: plan, seat and usage information, billing contact, tax details, transaction status, and payment-provider references. Complete card details are collected by our payment processor, not stored in our application database.
  • Communications: support requests, feedback, survey responses, sales correspondence, and call or meeting content when you choose to participate.
  • Connected-service data: information you authorize us to receive from email, calendar, identity, communications, storage, or other integrations.

Information collected automatically

  • Device and network: IP address, browser and device type, operating system, language, referring page, approximate location derived from IP, and request headers.
  • Usage: pages and features used, links and buttons selected, event timestamps, workspace and feature identifiers, viewport information, performance, crashes, and diagnostic events.
  • Security and audit: sign-in events, session identifiers, permission changes, administrative actions, request IDs, abuse signals, and security logs.
  • Local device data: essential session cookies and limited local storage, including preferences, consent choices, and demo state as described in our Cookie Notice.
03

Sources of information

  • directly from you when you register, use the Service, purchase a plan, or contact us;
  • from your organization, workspace administrators, coworkers, or people who invite or collaborate with you;
  • from connected services when an authorized user enables an integration;
  • automatically from your browser, device, and interaction with the Service;
  • from payment, identity, infrastructure, security, and support providers; and
  • from public sources or business partners for legitimate business-to-business communications, subject to applicable law.
04

How we use information

  • Provide the Service: authenticate users; provision workspaces; store, synchronize, search, display, and export content; run requested workflows; and operate integrations.
  • AI features: prepare authorized context, process prompts, generate output, measure usage, preserve required lineage, and route requests to configured model or voice providers.
  • Billing: administer trials, subscriptions, Working Credits, invoices, taxes, renewals, refunds, and account status.
  • Security: prevent fraud and abuse, enforce permissions, rate-limit traffic, investigate incidents, preserve audit records, and protect users and the Service.
  • Support and communications: respond to requests, provide service notices, send transactional messages, and communicate about relevant product or account changes.
  • Operate and improve: diagnose failures, understand aggregate usage, improve usability and performance, develop features, and conduct internal research and quality review.
  • Legal and corporate: comply with law, enforce agreements, establish or defend claims, complete audits, and evaluate or carry out a financing, acquisition, reorganization, or sale.
06

AI, automated processing, and voice

When you invoke an AI feature, we may send the prompt, authorized workspace context, selected files or records, and technical metadata to a configured AI provider. We receive generated output and usage metadata. Voice features may transmit audio or transcripts to a configured speech or conversational provider when you intentionally start them.

We do not use Customer Content to train general-purpose AI models unless the customer expressly opts in under a separate agreement. We require human review for proposed actions that are destructive, external, financial, access-changing, or rights-affecting. We do not use Corporate Suite to make solely automated decisions that produce legal or similarly significant effects about you on TWC's own behalf. Customers are responsible for their own lawful configuration and use.

07

How we disclose information

We may disclose personal information to:

  • Customer and workspace participants: according to workspace membership, permissions, sharing choices, and administrator controls.
  • Service providers and subprocessors: for infrastructure, databases, authentication, payments, email, monitoring, customer support, AI, voice, and other functions listed on our Subprocessors page.
  • Integrations: when an authorized user directs us to connect or send data to a third-party service.
  • Professional advisers: including legal, accounting, insurance, security, and audit advisers under confidentiality obligations.
  • Authorities and affected parties: where reasonably necessary to comply with law, protect rights and safety, investigate abuse, or respond to valid legal process.
  • Corporate transaction participants: in connection with a financing, merger, acquisition, reorganization, bankruptcy, or transfer of assets, subject to appropriate protections.

We do not sell personal information for money. We do not share personal information for cross-context behavioral advertising, and we do not use Customer Content for targeted advertising. If that practice changes, we will update this Policy and provide legally required opt-out controls first.

08

Retention

We keep information only as long as reasonably necessary for the purposes described here:

InformationRetention criteria
Account and workspace recordsFor the account or subscription term and a limited period afterward for recovery, portability, disputes, and legal obligations.
Customer ContentAs directed by the customer and applicable workspace settings; then deleted or de-identified through active-system and backup cycles unless a legal hold applies.
AI context and outputAccording to the feature's documented purpose, workspace retention settings, safety needs, and bounded technical retention; provider retention may differ as disclosed in the Subprocessors page or enterprise agreement.
Billing and tax recordsFor the period required by tax, accounting, anti-fraud, and other applicable laws.
Security, audit, and diagnostic dataFor a risk-based period needed to secure the Service, investigate incidents, preserve integrity, and establish or defend claims.
Support and sales communicationsFor the relationship and a reasonable period afterward to maintain context, improve support, and meet legal obligations.

Retention may be extended for a legal hold, security investigation, unresolved dispute, or customer instruction. When deletion is not immediately possible in encrypted backups, data is isolated from ordinary use and removed as backups expire. We may retain de-identified or aggregated information that cannot reasonably identify a person.

09

Security

We use administrative, technical, and organizational measures designed to protect information, including access controls, tenant authorization, encrypted transport, encryption for production data stores, secret management, logging, backups, vulnerability and dependency checks, and restricted production access. Our Security Statement describes the program in more detail.

No system is perfectly secure. Use a strong, unique authentication method, protect your devices, review workspace permissions, and notify us promptly at [email protected] if you suspect misuse.

10

International data transfers

TWC is based in the United States, and we and our providers may process information in the United States and other countries. Where required for transfers from the EEA, UK, or Switzerland, we use recognized safeguards such as adequacy decisions, the European Commission's Standard Contractual Clauses, the UK Addendum or International Data Transfer Agreement, and supplementary technical and organizational measures. You may request information about the applicable safeguard by contacting us.

11

Your privacy rights

Depending on where you live and subject to legal exceptions, you may have the right to access, know, correct, delete, restrict, or object to processing; receive a portable copy; withdraw consent; opt out of sale, sharing, targeted advertising, or certain profiling; limit certain uses of sensitive information; and appeal a denied request. You may also complain to your local privacy or data-protection authority.

Use available account controls or email [email protected]. Describe your request and the account or workspace involved. We may verify identity and authority by matching account information or requesting additional information proportionate to the request. Authorized agents may submit requests where the law permits; we may require proof of authorization. We will not discriminate against you for exercising a privacy right.

If your request concerns Customer Content controlled by your employer or another customer, contact that customer first. We will assist the customer as required. We may deny or limit a request where an exception applies and will explain available appeal rights.

12

California notice at collection

In the preceding 12 months, we may have collected the categories below. The examples describe our ordinary practices; the data in a particular workspace depends on what the customer submits and enables.

CCPA categoryExamples and purposesDisclosed to
IdentifiersName, email, IP address, account, device, and workspace IDs for accounts, security, support, and operations.Customer, service providers, integrations, authorities as required.
Customer recordsContact, organization, billing, and account information for contracting, billing, and support.Payment, identity, support, and infrastructure providers.
Commercial informationPlan, transactions, Working Credits, and usage for fulfillment, accounting, and fraud prevention.Customer, payment and professional-service providers.
Internet or network activityUsage, logs, pages, actions, browser, and diagnostics for delivery, security, analytics, and improvement.Infrastructure, security, and analytics providers.
GeolocationApproximate location derived from IP and locations a user enters in workspace content.Infrastructure and authorized integrations.
Audio or visual informationProfile images, uploaded media, and optional voice interactions for requested features.Customer participants and configured media or voice providers.
Professional informationCompany, role, team, assignments, and work records for collaboration and administration.Customer participants and service providers.
InferencesAI-generated summaries, classifications, and suggestions for requested product features.Customer participants and configured AI providers.
Sensitive personal informationAccount credentials or tokens and any sensitive data a customer chooses to place in content; used only to deliver, secure, and administer the Service.Identity, infrastructure, and other providers necessary for the requested feature.

We collect these categories from the sources in Section 3, use them for the purposes in Sections 4 and 6, and retain them under Section 8. We do not sell or share these categories for cross-context behavioral advertising and have not done so in the preceding 12 months. We do not knowingly sell or share personal information of people under 16. Because we do not use or disclose sensitive personal information for purposes outside legally permitted business purposes, we do not currently provide a separate “Limit” link.

13

Children

The Service is for adults and business users and is not directed to children under 18. We do not knowingly collect personal information directly from children under 13. If you believe a child has provided personal information in violation of this Policy, contact us so we can investigate and delete it where appropriate. Customers must not use the Service to circumvent child-privacy or parental-consent requirements.

14

Changes to this Policy

We may update this Policy as our Service or legal obligations change. We will post the updated version and revise the “Last updated” date. If a change materially affects how we use personal information, we will provide additional notice through the Service, by email, or as required by law. Earlier versions may be requested from us.

15

Contact us

Submit privacy questions, rights requests, and complaints to [email protected] or:

The Working Company, Inc.
Attn: Privacy
718 Calle Lima
San Clemente, CA 92673
USA

We will respond within the period required by applicable law. If you are in the EEA, UK, or Switzerland, you may also lodge a complaint with the supervisory authority in your place of residence, work, or the location of the alleged violation.