⚠️ Pre-requisite: Adjusting the automatic journey closure rule and the deletion of administrative data requires activating the right to "Modify platform security policies". This requires having an "Administrator" role.
At Workelo, the protection of personal data is a priority in compliance with the GDPR.
In this article, discover how our solution meets legal requirements and enhances data security!
👮🏻♀️ In compliance with the GDPR, we only retain data necessary for the proper functioning of our services for as long as it is needed. Once it is no longer required, we delete it.
- Journey access: Employees have access to their journey by default for up to 12 months after the arrival date. Once this period is over, the journey will be closed, and access will be blocked.
The accessibility period for a journey can extend up to 24 months after the start date (start_date).
👉 This period can be configured in the "Account" > "Advanced" tab. - Deletion of sensitive data: Administrative data is deleted 6 months after the journey is closed by default. In the meantime, they can still be accessed via the “Follow-up” tab of the journey.
Administrative data can be retained for up to 36 months after the journey closure.
👉 This period can be configured in the "Account" > "Advanced" tab. - Deletion of non-sensitive data: Non-sensitive data is retained as long as the user is present in the employee database. Once they are removed from the database, the associated data is automatically deleted.
👉 Users can be deleted manually by stakeholders with the appropriate rights, via connectors linked to the employee repository, or through the Workelo API.
Important to know 💡
- Sensitive data: Personal information requiring special protection due to its nature or content, which, if disclosed without authorization, could potentially harm individuals or the organization. This may include health information, financial data, or any other protected information revealing private aspects of the individual.
👉 Data collected through paperwork (forms and documents). - Non-sensitive data: General information that, by its nature, does not pose significant privacy or security risks to individuals. This could include anonymized data or publicly available data such as a postal code not directly associated with a person or aggregated statistical data.
👉 Data collected through quizzes, surveys, content, kits, tasks, etc.
⚠️ No sensitive data should be collected via a survey.
💬 For any additional questions, please contact your internal HR team (and if necessary, your project manager). They will reach out to us if needed!