Scope and our role
This Privacy Policy explains how The Working Company, Inc. (TWC, we, us, or our) handles personal information when you visit corporatesuite.co, create or use a Corporate Suite account, communicate with us, or otherwise interact with our websites, applications, APIs, and services (collectively, the Service).
TWC is the controller or business for account, billing, website, security, support, and direct relationship information. For personal information in workspace content that a customer submits and controls, TWC generally acts as the customer's processor or service provider. In that case, the customer decides why and how the data is used, and requests about that content should normally be directed to the customer. Our Data Processing Addendum governs covered processing on behalf of customers.
This Policy does not govern third-party services that you connect to Corporate Suite or external websites you visit. Their own notices apply to their independent processing.
Information we collect
Information you provide
- Account and profile: name, email address, profile image, time zone, authentication identifiers, organization, role, and preferences.
- Workspace and Customer Content: tasks, projects, spaces, databases, files, messages, calendars, plans, prompts, agent instructions, generated outputs, comments, and other content you or your organization submit.
- Billing: plan, seat and usage information, billing contact, tax details, transaction status, and payment-provider references. Complete card details are collected by our payment processor, not stored in our application database.
- Communications: support requests, feedback, survey responses, sales correspondence, and call or meeting content when you choose to participate.
- Connected-service data: information you authorize us to receive from email, calendar, identity, communications, storage, or other integrations.
Information collected automatically
- Device and network: IP address, browser and device type, operating system, language, referring page, approximate location derived from IP, and request headers.
- Usage: pages and features used, links and buttons selected, event timestamps, workspace and feature identifiers, viewport information, performance, crashes, and diagnostic events.
- Security and audit: sign-in events, session identifiers, permission changes, administrative actions, request IDs, abuse signals, and security logs.
- Local device data: essential session cookies and limited local storage, including preferences, consent choices, and demo state as described in our Cookie Notice.
Sources of information
- directly from you when you register, use the Service, purchase a plan, or contact us;
- from your organization, workspace administrators, coworkers, or people who invite or collaborate with you;
- from connected services when an authorized user enables an integration;
- automatically from your browser, device, and interaction with the Service;
- from payment, identity, infrastructure, security, and support providers; and
- from public sources or business partners for legitimate business-to-business communications, subject to applicable law.
How we use information
- Provide the Service: authenticate users; provision workspaces; store, synchronize, search, display, and export content; run requested workflows; and operate integrations.
- AI features: prepare authorized context, process prompts, generate output, measure usage, preserve required lineage, and route requests to configured model or voice providers.
- Billing: administer trials, subscriptions, Working Credits, invoices, taxes, renewals, refunds, and account status.
- Security: prevent fraud and abuse, enforce permissions, rate-limit traffic, investigate incidents, preserve audit records, and protect users and the Service.
- Support and communications: respond to requests, provide service notices, send transactional messages, and communicate about relevant product or account changes.
- Operate and improve: diagnose failures, understand aggregate usage, improve usability and performance, develop features, and conduct internal research and quality review.
- Legal and corporate: comply with law, enforce agreements, establish or defend claims, complete audits, and evaluate or carry out a financing, acquisition, reorganization, or sale.
Legal bases in the EEA, UK, and Switzerland
Where those laws apply, we rely on the following legal bases:
- Contract: to create and administer your account, provide requested features, process payments, and deliver support.
- Legitimate interests: to secure and improve the Service, prevent abuse, understand business use, communicate with customers, and operate our business, after considering the impact on your rights.
- Legal obligation: to maintain tax and transaction records, respond to lawful process, and meet compliance duties.
- Consent: for optional cookies, certain marketing, or another purpose we identify when asking. You may withdraw consent at any time without affecting earlier lawful processing.
Where we process Customer Content for a customer, the customer determines the applicable legal basis. We process that content under the customer's documented instructions and our agreement.
AI, automated processing, and voice
When you invoke an AI feature, we may send the prompt, authorized workspace context, selected files or records, and technical metadata to a configured AI provider. We receive generated output and usage metadata. Voice features may transmit audio or transcripts to a configured speech or conversational provider when you intentionally start them.
We do not use Customer Content to train general-purpose AI models unless the customer expressly opts in under a separate agreement. We require human review for proposed actions that are destructive, external, financial, access-changing, or rights-affecting. We do not use Corporate Suite to make solely automated decisions that produce legal or similarly significant effects about you on TWC's own behalf. Customers are responsible for their own lawful configuration and use.
How we disclose information
We may disclose personal information to:
- Customer and workspace participants: according to workspace membership, permissions, sharing choices, and administrator controls.
- Service providers and subprocessors: for infrastructure, databases, authentication, payments, email, monitoring, customer support, AI, voice, and other functions listed on our Subprocessors page.
- Integrations: when an authorized user directs us to connect or send data to a third-party service.
- Professional advisers: including legal, accounting, insurance, security, and audit advisers under confidentiality obligations.
- Authorities and affected parties: where reasonably necessary to comply with law, protect rights and safety, investigate abuse, or respond to valid legal process.
- Corporate transaction participants: in connection with a financing, merger, acquisition, reorganization, bankruptcy, or transfer of assets, subject to appropriate protections.
We do not sell personal information for money. We do not share personal information for cross-context behavioral advertising, and we do not use Customer Content for targeted advertising. If that practice changes, we will update this Policy and provide legally required opt-out controls first.
Retention
We keep information only as long as reasonably necessary for the purposes described here:
| Information | Retention criteria |
|---|---|
| Account and workspace records | For the account or subscription term and a limited period afterward for recovery, portability, disputes, and legal obligations. |
| Customer Content | As directed by the customer and applicable workspace settings; then deleted or de-identified through active-system and backup cycles unless a legal hold applies. |
| AI context and output | According to the feature's documented purpose, workspace retention settings, safety needs, and bounded technical retention; provider retention may differ as disclosed in the Subprocessors page or enterprise agreement. |
| Billing and tax records | For the period required by tax, accounting, anti-fraud, and other applicable laws. |
| Security, audit, and diagnostic data | For a risk-based period needed to secure the Service, investigate incidents, preserve integrity, and establish or defend claims. |
| Support and sales communications | For the relationship and a reasonable period afterward to maintain context, improve support, and meet legal obligations. |
Retention may be extended for a legal hold, security investigation, unresolved dispute, or customer instruction. When deletion is not immediately possible in encrypted backups, data is isolated from ordinary use and removed as backups expire. We may retain de-identified or aggregated information that cannot reasonably identify a person.
Security
We use administrative, technical, and organizational measures designed to protect information, including access controls, tenant authorization, encrypted transport, encryption for production data stores, secret management, logging, backups, vulnerability and dependency checks, and restricted production access. Our Security Statement describes the program in more detail.
No system is perfectly secure. Use a strong, unique authentication method, protect your devices, review workspace permissions, and notify us promptly at [email protected] if you suspect misuse.
International data transfers
TWC is based in the United States, and we and our providers may process information in the United States and other countries. Where required for transfers from the EEA, UK, or Switzerland, we use recognized safeguards such as adequacy decisions, the European Commission's Standard Contractual Clauses, the UK Addendum or International Data Transfer Agreement, and supplementary technical and organizational measures. You may request information about the applicable safeguard by contacting us.
Your privacy rights
Depending on where you live and subject to legal exceptions, you may have the right to access, know, correct, delete, restrict, or object to processing; receive a portable copy; withdraw consent; opt out of sale, sharing, targeted advertising, or certain profiling; limit certain uses of sensitive information; and appeal a denied request. You may also complain to your local privacy or data-protection authority.
Use available account controls or email [email protected]. Describe your request and the account or workspace involved. We may verify identity and authority by matching account information or requesting additional information proportionate to the request. Authorized agents may submit requests where the law permits; we may require proof of authorization. We will not discriminate against you for exercising a privacy right.
If your request concerns Customer Content controlled by your employer or another customer, contact that customer first. We will assist the customer as required. We may deny or limit a request where an exception applies and will explain available appeal rights.
California notice at collection
In the preceding 12 months, we may have collected the categories below. The examples describe our ordinary practices; the data in a particular workspace depends on what the customer submits and enables.
| CCPA category | Examples and purposes | Disclosed to |
|---|---|---|
| Identifiers | Name, email, IP address, account, device, and workspace IDs for accounts, security, support, and operations. | Customer, service providers, integrations, authorities as required. |
| Customer records | Contact, organization, billing, and account information for contracting, billing, and support. | Payment, identity, support, and infrastructure providers. |
| Commercial information | Plan, transactions, Working Credits, and usage for fulfillment, accounting, and fraud prevention. | Customer, payment and professional-service providers. |
| Internet or network activity | Usage, logs, pages, actions, browser, and diagnostics for delivery, security, analytics, and improvement. | Infrastructure, security, and analytics providers. |
| Geolocation | Approximate location derived from IP and locations a user enters in workspace content. | Infrastructure and authorized integrations. |
| Audio or visual information | Profile images, uploaded media, and optional voice interactions for requested features. | Customer participants and configured media or voice providers. |
| Professional information | Company, role, team, assignments, and work records for collaboration and administration. | Customer participants and service providers. |
| Inferences | AI-generated summaries, classifications, and suggestions for requested product features. | Customer participants and configured AI providers. |
| Sensitive personal information | Account credentials or tokens and any sensitive data a customer chooses to place in content; used only to deliver, secure, and administer the Service. | Identity, infrastructure, and other providers necessary for the requested feature. |
We collect these categories from the sources in Section 3, use them for the purposes in Sections 4 and 6, and retain them under Section 8. We do not sell or share these categories for cross-context behavioral advertising and have not done so in the preceding 12 months. We do not knowingly sell or share personal information of people under 16. Because we do not use or disclose sensitive personal information for purposes outside legally permitted business purposes, we do not currently provide a separate “Limit” link.
Children
The Service is for adults and business users and is not directed to children under 18. We do not knowingly collect personal information directly from children under 13. If you believe a child has provided personal information in violation of this Policy, contact us so we can investigate and delete it where appropriate. Customers must not use the Service to circumvent child-privacy or parental-consent requirements.
Changes to this Policy
We may update this Policy as our Service or legal obligations change. We will post the updated version and revise the “Last updated” date. If a change materially affects how we use personal information, we will provide additional notice through the Service, by email, or as required by law. Earlier versions may be requested from us.
Contact us
Submit privacy questions, rights requests, and complaints to [email protected] or:
The Working Company, Inc.
Attn: Privacy
718 Calle Lima
San Clemente, CA 92673
USA
We will respond within the period required by applicable law. If you are in the EEA, UK, or Switzerland, you may also lodge a complaint with the supervisory authority in your place of residence, work, or the location of the alleged violation.
