1. Controller and business users
Workseal is a product of Apphletes, a Dutch VOF established in Den Haag, registered with the Chamber of Commerce under number 42133988. Email hello@apphletes.com with privacy questions.
Workseal is intended for organisations and self-employed professionals. The trade business decides which customer, job and photo data its members record and is generally responsible for that content. Apphletes processes the data to provide and secure Workseal.
2. Data we process
We process account and organisation data such as names, email addresses, organisation, role, invitation status and necessary authentication and security information.
Users may record work documentation including customer details, job details, addresses, notes, before and after photos, annotations and generated reports. Almost all descriptive fields are optional.
We also process operational data such as app version, sync state, storage use, report-generation state, push state and subscription information from Apple, Google or a connected subscription provider.
3. Purposes and legal bases
We use data to manage accounts and team access, securely sync photos, generate reports, enforce subscriptions and seat limits, provide support and investigate abuse or security incidents.
Depending on the context, processing is necessary to perform the agreement with the trade business, comply with law, pursue a legitimate interest in a safe and reliable product or — where required — is based on consent.
4. Platform access and company separation
Workseal separates organisations through roles, server-side checks and database policies. A user in organisation A must not be able to access organisation B's data.
By default, Apphletes platform staff only see aggregate subscription, usage and operational data. The internal console does not provide access to individual photos, customers, addresses, job notes or complete report content. Future support access with explicit customer permission is outside this version.
5. Providers and international transfers
We use selected providers for hosting, database services, authentication, private file storage, email, push notifications, app distribution and subscriptions. The final provider list and regions must be reviewed before release.
Where a provider processes data outside the European Economic Area, the parties use appropriate safeguards such as an adequacy decision or approved standard contractual clauses.
6. Retention and deletion
Active work documentation remains available while the business account and applicable retention period require it. Completed jobs may first enter a recoverable bin before permanent deletion.
When an account ends or is deleted, recovery periods, pending exports or deletion jobs, security, disputes and legal obligations may apply. Final periods must match the production configuration and customer agreements.
7. Security, rights and contact
We use safeguards including encrypted connections, private storage, limited-duration download links, roles, tenant-scoped database controls and audit logs for sensitive platform actions. No security measure can eliminate every risk.
Where applicable, you may request access, correction, deletion, restriction or portability, object to processing, or lodge a complaint with the Dutch Data Protection Authority. Contact the trade business that recorded your data first, or email hello@apphletes.com.