Skip to content

Effective: 25 September 2026

Polska wersja

Privacy Policy

This policy explains how Binary Brain Technologies sp. z o.o. processes personal data when you visit www.worklog.click and use WorkLog, as required by Articles 13 and 14 of the General Data Protection Regulation (EU) 2016/679 (“GDPR”). WorkLog collects only what it needs to work: no analytics, no advertising, no tracking, no selling of data.

1.Who is responsible

The controller of your personal data is:

Company
Binary Brain Technologies sp. z o.o.
Legal form
limited liability company (spółka z ograniczoną odpowiedzialnością)
Registered office
Abramowice Prywatne, Poland
Registry court
Sąd Rejonowy Lublin-Wschód w Lublinie z siedzibą w Świdniku, VI Wydział Gospodarczy Krajowego Rejestru Sądowego
KRS
0001207918
NIP
7133142056
Share capital
PLN 5,000.00

For anything about your personal data, write to support@worklog.click. We have not appointed a data protection officer, as the law does not require one for our processing; the email address above reaches the people responsible.

2.Our two roles

  • Controller. We decide how and why your account data, sign-in data, security logs, our correspondence with you and visits to the website are processed. This policy covers that processing.
  • Processor. Time entries, clients, projects and other content in a Workspace are processed on behalf of the Workspace Owner, who is the controller of the personal data in it (for example the time records of team members or a client’s contact details). We process it only on the Owner’s instructions, under the Data Processing Agreement. If you are a member of someone else’s Workspace, the Owner is your first point of contact for that data; we will pass your request on and help them answer it.

3.What data we process

  • Account data: your name, email address and, if you sign in with Google or GitHub, your profile picture and the provider’s account identifier. If you use an email and password, the password is stored by our authentication provider only as a one-way cryptographic hash; we never see it.
  • Preferences: time zone, language and date settings, week start, daily target and notification choices.
  • Workspace data you enter: time entries and their descriptions, clients (and any contact details you add), projects, tasks, tags, rates, budgets, saved reports, timesheet approvals, memberships, roles and invitations (including the invited email address). Imported CSV files are read to create entries and are not kept.
  • Sign-in and security data: sessions with the IP address and browser information of the device used, one-time email codes (stored only as hashes and valid for a few minutes), and an activity log of sensitive Workspace changes (membership, roles, rates, approvals).
  • Technical data: when you use the website, our hosting provider processes your IP address, browser information and the requested address to deliver pages and protect the service. We do not use analytics or advertising tools.
  • Correspondence: the content of emails you send us and our replies.

We receive account data from you, or from Google or GitHub when you choose to sign in with them. Data about you in a Workspace may come from the Owner or other members (for example an invitation to your email address).

4.Purposes and legal bases

PurposeLegal basis (GDPR)
Creating your account, signing you in, and providing WorkLog under the Terms of ServiceArt. 6(1)(b) — performing the agreement
Sending service emails: sign-in and verification codes, password resets, notices of changes to the terms or the serviceArt. 6(1)(b) — performing the agreement; Art. 6(1)(c) where the law requires the notice
Keeping the service secure: session management, preventing abuse, investigating incidents, security logsArt. 6(1)(f) — our legitimate interest in a secure service
Answering your messages, complaints and requestsArt. 6(1)(b) where it concerns the agreement; otherwise Art. 6(1)(f)
Handling notices of illegal content and cooperating with authorities (Digital Services Act)Art. 6(1)(c) — legal obligation
Establishing, pursuing or defending legal claimsArt. 6(1)(f) — our legitimate interest in protecting our rights
Processing Workspace content on behalf of the OwnerThe Owner’s legal basis; we act under the Data Processing Agreement (Art. 28)

We do not send marketing emails, do not build profiles of you, and do not use your data to train AI models.

5.Who receives the data

We use a small number of providers who process data on our behalf, under data processing agreements:

ProviderWhat forWhere
Neon, Inc.Database (all account and Workspace data) and the Neon Auth sign-in service (accounts, password hashes, sessions)AWS region eu-central-1, Frankfurt, Germany
Vercel, Inc.Hosting of the website and application; delivery of pagesApplication servers in Frankfurt (fra1); content delivered through Vercel’s global network
ResendSending sign-in, verification and password-reset emailsMay process email data in the United States

Google and GitHub act as independent controllers when you choose to sign in with them; their own privacy policies apply. Other members of your Workspace see the data the Workspace shows them according to their role. We may also disclose data to public authorities when the law requires it. We do not sell or rent personal data.

6.Transfers outside the EEA

Our providers are companies based in the United States, and some data (in particular email delivery through Resend, and support access by providers’ staff) may be processed outside the European Economic Area. Such transfers rely on the European Commission’s adequacy decision for the EU–U.S. Data Privacy Framework where the provider is certified under it, and otherwise on the Standard Contractual Clauses adopted by the Commission (Decision (EU) 2021/914), together with the providers’ additional safeguards. You can ask us at support@worklog.click for information about these safeguards and a copy of them.

7.How long we keep it

DataRetention
Account data and preferencesUntil you delete your account. Then your profile is anonymised (name and email removed) and your sign-in record, linked accounts and sessions are deleted.
Workspaces where you are the only memberDeleted with all their data when you delete the Workspace or your account.
Your entries in other people’s WorkspacesRemain in that Workspace as its records, credited to “Deleted user”, until the Owner deletes them or the Workspace.
Deleted time entriesHidden at once and kept, marked as deleted, so an accidental deletion can be undone; removed when the Workspace is deleted.
InvitationsExpire after 14 days; the record (email, role, status) stays in the Workspace history until the Workspace is deleted.
SessionsUntil you sign out or the session expires.
Email codesA few minutes; they can be used once.
Workspace activity logFor the life of the Workspace.
Hosting and email delivery logsFor the limited period set by Vercel and Resend for their logs; not used for any other purpose.
BackupsDatabase history for point-in-time recovery, for no more than 30 days; deleted data leaves backups when that period passes.
Correspondence, complaints, illegal-content noticesAs long as needed to handle them, then until any related claims are time-barred.

8.Your rights

Under the GDPR you have the right to:

  • access your data and receive a copy (Article 15) — you can also export it yourself in Settings → Your data;
  • have inaccurate data corrected (Article 16) — most data can be edited directly in WorkLog;
  • have your data erased (Article 17) — you can delete your account yourself in Settings;
  • restrict processing (Article 18);
  • data portability, in a structured, machine-readable format (Article 20) — the CSV and JSON exports;
  • object at any time, on grounds relating to your particular situation, to processing based on our legitimate interests (Article 21);
  • lodge a complaint with the supervisory authority: in Poland, the President of the Personal Data Protection Office (Prezes Urzędu Ochrony Danych Osobowych, ul. Stawki 2, 00-193 Warszawa, uodo.gov.pl), or the authority where you live or work.

Write to support@worklog.click to use a right. We answer within one month; if a request is complex we may extend this by two months and will tell you why. We may ask you to confirm your identity, usually by writing from your account’s email address.

9.Is providing data required?

Providing data is voluntary, but without your name and email address (or a Google or GitHub sign-in) we cannot create an account or provide WorkLog. Everything else you enter is up to you.

10.Automated decisions

We do not make decisions producing legal or similarly significant effects about you solely by automated means, and we do not profile you.

11.Security

All connections use HTTPS. Workspace data is separated in the database with row-level security, so one Workspace cannot read another’s even if an application check fails. Passwords, invitation tokens and email codes are stored only as hashes. Details are on the security page. If a personal data breach is likely to result in a risk to you, we notify the supervisory authority within 72 hours and, where the risk is high, you as well.

12.Children

WorkLog is not intended for anyone under 16, and we do not knowingly process their data. If you believe a child has created an account, write to support@worklog.click.

13.Cookies

WorkLog uses only strictly necessary cookies and one local storage entry. See the Cookie Policy.

14.Changes

We update this policy when our processing changes. The date at the top shows the current version; we tell account holders about significant changes by email or in the app before they apply. This policy is available in English and Polish.