Legal
Privacy Policy
Last updated: 17 August 2026
This Privacy Policy ("Policy") describes how Workably LLC, a Wyoming limited liability company ("Workably", "we", "us", or "our"), collects, uses, stores, discloses, and protects personal information in connection with the Workably CRM platform and related services (collectively, the "Service"), accessible at workably.app and app.workably.app.
By accessing or using the Service, you acknowledge that you have read and understood this Policy and agree to the collection and use of your information as described herein. If you do not agree, you must discontinue use of the Service.
1. Who We Are and How to Contact Us
Workably LLC is a Wyoming limited liability company, registered in the State of Wyoming, United States. Depending on the type of personal data involved, we act in different roles:
- As a data controller, for personal data relating to your own Workably account — including your registration details, billing information, usage data, and communications with us.
- As a data processor (or "service provider"/"processor" under applicable US state privacy laws), for personal data that you or your organisation submit to the Service about your own contacts, leads, and clients ("Customer Data"). In this role, we process Customer Data only on your documented instructions, and you (or your organisation) remain the controller of that data.
We do not have a formally designated Data Protection Officer (DPO). As a small business primarily offering software tools to other businesses, we are not currently required to appoint a DPO under Article 37 of the GDPR. If this changes, we will update this Policy accordingly. For all data protection enquiries, use the privacy email above.
2. Information We Collect
2.1 Information You Provide Directly
- Account registration: full name, email address, password (stored as a bcrypt hash — we never store your plaintext password), company name, and timezone
- Profile information: job title, avatar image, email signature, and AI personality preference
- CRM data: contacts, companies, deals, notes, tasks, calendar events, email logs, tags, custom fields, and any other content you enter into the Service
- Team data: names and email addresses of team members you invite to your organisation
- Support communications: messages, attachments, and metadata from support requests sent to us
- Payment information: billing address and payment method details entered during checkout. Payment card data is processed directly by our payment processor and is never transmitted to or stored on Workably servers.
2.2 Information Collected Automatically
- Usage data: pages visited, features used, buttons clicked, session duration, and navigation paths within the Service
- Device and technical data: IP address, browser type and version, operating system, screen resolution, device type, and referring URL
- Authentication data: login timestamps, session tokens, and authentication events (login, logout, password reset)
- Error and performance data: application errors, stack traces, and performance metrics collected via our error monitoring service (Sentry). This data may include contextual information about the state of the application at the time of an error, which may include metadata about the current user session.
2.3 Information from Third-Party Integrations
When you enable optional third-party integrations, we receive data from those services solely to provide the integration functionality:
- Google Calendar: calendar event titles, descriptions, start and end times, attendees, and event IDs, for the purpose of two-way calendar synchronisation
- Google Contacts: contact names, email addresses, phone numbers, and company names, for the purpose of contact import into your Workably account
- Inbound email (via Maileroo): sender address, recipient address, subject line, and email body of emails routed to your Workably inbound address, for the purpose of logging them against contact records
We access only the minimum data necessary to provide each integration. Integration access can be revoked at any time from Settings → Integrations.
3. How We Use Your Information
| Purpose |
Data Used |
Legal Basis (GDPR) |
| Providing and operating the Service |
Account data, CRM data, usage data |
Performance of contract (Art. 6(1)(b)) |
| Processing payments and managing subscriptions |
Email, billing address, subscription status |
Performance of contract (Art. 6(1)(b)) |
| Sending transactional emails (receipts, password resets, team invitations, subscription notifications) |
Email address, account status |
Performance of contract (Art. 6(1)(b)) |
| Responding to support requests |
Communications data, account data |
Performance of contract (Art. 6(1)(b)) |
| Sending product updates, feature announcements, and marketing communications |
Email address, plan type |
Legitimate interests (Art. 6(1)(f)); consent where required |
| Improving, analysing, and developing the Service |
Usage data, error data, aggregated analytics |
Legitimate interests (Art. 6(1)(f)) |
| Providing AI-powered features (Auraly AI) |
CRM data you select, messages you send to Auraly |
Performance of contract (Art. 6(1)(b)) |
| Detecting and preventing fraud, abuse, and security incidents |
IP address, usage data, authentication events |
Legitimate interests (Art. 6(1)(f)); legal obligation (Art. 6(1)(c)) |
| Complying with legal obligations |
As required by applicable law |
Legal obligation (Art. 6(1)(c)) |
We do not sell your personal data to third parties. We do not use your data for cross-context behavioural advertising.
4. Auraly AI — How Your CRM Data Is Used in AI Features
Workably offers an AI assistant called Auraly AI, powered by Anthropic's Claude language model. When you interact with Auraly AI, the following occurs:
- Your messages and selected CRM data (such as deal records, contact summaries, and task lists relevant to your query) are transmitted to Anthropic's API to generate a response.
- This data is sent over an encrypted HTTPS connection and is subject to Anthropic's data processing terms and privacy policy, available at anthropic.com/privacy.
- Anthropic processes this data solely to generate responses and does not use it to train its models without separate agreement.
- We do not store Auraly AI conversation history beyond the current session. Conversations are not persisted to your account or accessible to other users.
- Auraly AI responses are generated by a machine learning model and may be inaccurate, incomplete, or inappropriate. Responses do not constitute professional business, legal, financial, or other advice. You are solely responsible for evaluating and acting on any AI-generated output.
- AI action limits apply per plan per calendar month. Usage is tracked at the user level.
By using Auraly AI features, you consent to the transmission of the relevant CRM data to Anthropic as described above. You may choose not to use Auraly AI features if you do not wish your data to be processed in this manner.
5. Data Storage, Infrastructure, and Security
5.1 Infrastructure
Your data is stored on Supabase's managed PostgreSQL infrastructure. Our primary database region is ap-northeast-1 (Tokyo, Japan). Supabase replicates data for availability and disaster recovery purposes. Supabase's privacy policy is available at supabase.com/privacy.
5.2 Security Measures
- Encryption in transit: all data transmitted between your browser and our servers is encrypted using TLS 1.2 or higher
- Encryption at rest: all data stored in our database is encrypted at rest by Supabase
- Row-level security: database access is enforced at the row level, ensuring that each organisation's data is strictly isolated from other organisations
- Authentication: passwords are hashed using bcrypt; two-factor authentication (TOTP) is available and recommended
- Access controls: internal access to production data is restricted to authorised personnel only, on a need-to-know basis
- Error monitoring: application errors are captured by Sentry (sentry.io) for debugging purposes. Sentry may capture session context including user ID and recent actions. We configure Sentry to minimise the capture of personally identifiable information.
Despite these measures, no system is completely secure. We encourage you to use a strong, unique password and to enable two-factor authentication on your account.
5.3 Data Breach Notification
In the event of a confirmed personal data breach that is likely to result in a risk to your rights and freedoms, we will notify affected users without undue delay and within the timeframes required by applicable law (72 hours under GDPR where applicable). Notification will be provided by email to the address associated with your account and, where required, to the relevant supervisory authority.
6. Third-Party Sub-Processors
We use the following third-party services to operate and deliver the Service. Each sub-processor processes only the data necessary for its function:
| Sub-Processor |
Purpose |
Data Processed |
Location |
| Supabase |
Database, authentication, real-time, storage |
All account and CRM data |
Japan (ap-northeast-1) |
| Anthropic |
AI language model (Auraly AI features) |
Messages and CRM data sent to Auraly AI |
United States |
| Paddle |
Payment processing, subscription billing, tax compliance (Merchant of Record) |
Email, billing address, payment method, subscription status |
United Kingdom |
| PostHog |
Product analytics |
Usage data, page views, feature interactions |
United States |
| Meta (Meta Pixel) |
Advertising/conversion tracking, used to measure ad campaign performance when ad campaigns are active |
Technical and usage data related to ad campaign measurement |
United States |
| Maileroo |
Transactional and account email delivery; inbound email routing |
Email address, email content for transactional sends and inbound routing |
European Union |
| Google LLC |
Optional calendar sync and contact import (Google Calendar, Google Contacts) |
Calendar events, contact records — only when integration is enabled |
United States and international |
| Sentry |
Error monitoring and application performance |
Error logs, stack traces, session context (user ID, page, recent actions) |
United States |
| Vercel |
Frontend hosting and CDN |
IP address, request headers, page requests |
Global CDN (United States primary) |
| Telnyx |
Voice calling, SMS, AI Receptionist, call recording and transcription |
Phone numbers, call audio recordings, call transcripts, SMS content, call metadata |
United States |
We review our sub-processors periodically and will update this list when sub-processors change. We enter into data processing agreements with sub-processors where required by applicable law.
6.1 Google API Services — Limited Use Disclosure
Workably's use and transfer of information received from Google APIs, including any raw or derived user data obtained through Google Workspace APIs, will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
Workably uses Google APIs (Google Calendar and Google Contacts) solely to provide calendar synchronisation and contact import features that are visible and prominent within the application. We do not sell, rent, share, or transfer this data to third parties except as necessary to provide these features. We do not use Google API data for serving advertisements, retargeted advertising, or personalised advertising of any kind. We do not use Google Calendar or Google Contacts data to train, fine-tune, or improve generalised AI or machine-learning models. Human access to Google API data occurs only with your explicit consent, for security or abuse investigation purposes, or to comply with applicable law.
7. Cookies and Local Storage
We use the following technologies to maintain your session and remember your preferences:
- Authentication tokens: stored in browser local storage to keep you logged in across sessions. These are essential to the operation of the Service and cannot be disabled without preventing login.
- Session preferences: UI preferences such as sidebar state and selected views are stored in local storage for convenience.
- Essential cookies: we may set cookies required for security and session integrity.
We use PostHog for privacy-conscious product analytics to understand how the Service is used (see Section 8.1). We do not use Google Analytics. We use the Meta Pixel to measure the performance of our advertising campaigns. This may involve sharing limited technical and usage data with Meta. We do not sell your personal data, and the Meta Pixel is not used for cross-site profiling beyond standard ad campaign measurement.
8. Additional Cookie Details
We use a small number of cookies and similar technologies to operate Workably, including the Meta Pixel for advertising campaign measurement when campaigns are active (see Section 8.1). We do not sell your data to ad networks.
8.1 Cookies We Use
- Authentication cookies (Supabase): essential session tokens that keep you logged in. Without these, Workably cannot function. These are deleted when you sign out or your session expires.
- Error tracking (Sentry): Sentry uses a session identifier to group error reports from the same user session. This helps us diagnose bugs. No personally identifiable information is attached unless you are already signed in.
- Performance (Vercel): if Vercel Analytics is active on your request, Vercel may collect anonymised page load metrics. No cross-site tracking occurs.
- Product analytics (PostHog): PostHog sets a cookie/local storage identifier to record page views and feature usage, helping us understand how the Service is used and improve it. This data is not sold or shared with advertisers.
- Advertising measurement (Meta Pixel): the Meta Pixel is used to measure the performance of our advertising campaigns when active. This may involve sharing limited technical and usage data with Meta. We do not sell your personal data, and the Meta Pixel is not used for cross-site profiling beyond standard ad campaign measurement.
8.2 What We Do Not Use
Aside from the Meta Pixel described in Section 8.1, we do not use advertising cookies, tracking pixels, or third-party analytics that follow you across other websites. We do not use Google Analytics.
8.3 Managing Cookies
You can block or delete cookies through your browser settings. Blocking authentication cookies will prevent you from signing in to Workably.
9. Your Rights
9.1 Rights for All Users
Regardless of your location, you may:
- Access your data: request a copy of the personal data we hold about you
- Correct your data: update or correct inaccurate information directly in your account settings, or by contacting us
- Delete your account: delete your account and associated personal data from Settings → Account → Delete Account. Deletion is processed within 30 days.
- Export your data: export your contacts, deals, and other CRM data from Settings → Data
- Unsubscribe from marketing: opt out of non-transactional emails at any time using the unsubscribe link in any marketing email, or by contacting us
9.2 Additional Rights for EEA and UK Residents (GDPR / UK GDPR)
If you are located in the European Economic Area or United Kingdom, you have the following additional rights under the General Data Protection Regulation (GDPR) or UK GDPR:
- Right to erasure ("right to be forgotten"): request that we delete your personal data where there is no legitimate reason for us to continue processing it
- Right to restriction of processing: request that we restrict processing of your personal data in certain circumstances (e.g. if you contest the accuracy of data while we verify it)
- Right to data portability: receive your personal data in a structured, commonly used, machine-readable format (JSON or CSV) and transmit it to another controller
- Right to object: object to processing based on legitimate interests or for direct marketing purposes
- Right not to be subject to automated decision-making: we do not make solely automated decisions that produce legal or similarly significant effects about you
- Right to lodge a complaint: you have the right to lodge a complaint with your local data protection supervisory authority. In the EU, find your authority at edpb.europa.eu. In the UK, contact the Information Commissioner's Office (ICO) at ico.org.uk.
9.3 California Privacy Rights (CCPA / CPRA)
If you are a California resident, the California Consumer Privacy Act as amended by the California Privacy Rights Act provides you with the following rights:
- Right to know: the categories and specific pieces of personal information we collect, the purposes for which we use it, and the categories of third parties with whom we share it
- Right to delete: request deletion of personal information we hold about you, subject to certain exceptions
- Right to correct: request correction of inaccurate personal information
- Right to opt out of sale or sharing: we do not sell your personal information and do not share it for cross-context behavioural advertising. No opt-out is therefore required, but you may contact us to confirm.
- Right to limit use of sensitive personal information: we do not collect sensitive personal information as defined by the CPRA for purposes beyond those permitted by law
- Right to non-discrimination: we will not deny you service, charge you different prices, or provide a different level of quality for exercising your CCPA rights
- Authorised agents: you may use an authorised agent to submit requests on your behalf. We may require verification of your identity and confirmation of the agent's authority.
To exercise any California privacy right, contact us at privacy@workably.app. We will respond within 45 days, with one 45-day extension where reasonably necessary.
9.4 How to Submit a Privacy Request
To exercise any right described above, email privacy@workably.app from the email address associated with your account. Include your full name, account email, and a clear description of your request. We may ask you to verify your identity before processing the request. We will respond within 30 days (or within the timeframe required by applicable law, whichever is shorter).
10. International Data Transfers
Workably LLC is incorporated and based in the United States. Your data is stored primarily in Japan (Supabase) and processed by sub-processors in the United States, European Union, and other regions as described in Section 6.
If you are located in the European Economic Area, United Kingdom, or Switzerland, your personal data may be transferred to countries that do not provide the same level of data protection as your home country. Where such transfers occur, we rely on appropriate safeguards, including:
- Standard Contractual Clauses (SCCs) approved by the European Commission, where applicable
- The UK International Data Transfer Agreement (IDTA), where applicable for UK transfers
- Sub-processor participation in recognised data transfer frameworks where available
By using the Service, you acknowledge and consent to the international transfer and processing of your personal data as described in this Policy.
11. Data Retention
We retain your personal data for as long as your account is active and as necessary to provide the Service. Specific retention periods are as follows:
- Account and CRM data: retained for the duration of your account. Upon account deletion, your personal data is removed within 30 days, except where retention is required by law.
- Billing records: retained for a minimum of 7 years to comply with tax and accounting obligations, even after account deletion. These records are anonymised where possible.
- Support communications: retained for up to 3 years after resolution to support quality assurance and dispute resolution.
- Error and log data: application error logs are retained for up to 90 days. Server access logs may be retained for up to 12 months for security purposes.
- Backup data: database backups may persist for up to 30 days after account deletion before being overwritten.
- Call recordings, transcripts, and AI-generated call summaries: retained for 12 months from the date of the call, after which they are automatically and permanently deleted. Call metadata (date, duration, participants, outcome) is retained for the duration of your account, consistent with other CRM data, as described above.
12. Children's Privacy
The Service is intended for use by businesses and professionals and is not directed to individuals under the age of 18. We do not knowingly collect personal information from anyone under 18. If we become aware that we have inadvertently collected personal data from a minor, we will delete it promptly. If you believe a minor has provided us with personal information, contact us at privacy@workably.app.
13. Links to Third-Party Websites
The Service may contain links to third-party websites or services. We are not responsible for the privacy practices of those third parties. We encourage you to review the privacy policies of any third-party sites you visit.
14. Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, legal requirements, or new features. We will notify you of material changes by:
- Sending an email to the address associated with your account at least 14 days before the change takes effect, and/or
- Displaying a prominent notice within the Service
The "Last updated" date at the top of this Policy reflects the most recent revision. Continued use of the Service after the effective date of a change constitutes acceptance of the updated Policy.
15. Contact Us
For questions, concerns, or requests related to this Privacy Policy or your personal data, contact us at: