Email: support@subworks.co
This Privacy Policy explains how SubWorks processes personal data when you visit our websites, contact us, book meetings with us, request support, create an account, or use our products and related services.
We aim to process personal data carefully, transparently and in accordance with applicable privacy and data protection laws, including the General Data Protection Regulation ("GDPR") where applicable.
1. Definitions
| Term | Meaning |
|---|---|
| Personal data | Any information relating to an identified or identifiable natural person. |
| Processing | Any operation performed on personal data, such as collection, storage, use, disclosure or deletion. |
| Customer | A business customer using one or more SubWorks services or products. |
| User | A natural person using a customer account, such as an admin, manager, employee, receptionist, planner, driver or other staff member. |
| End user data | Data processed in product workflows on behalf of a customer, such as reservations, orders, staffing records, planning data, guest details or operational notes. |
2. Who this applies to
This Privacy Policy applies to:
- visitors of our websites and related pages;
- people who contact us by email, forms, chat or other channels;
- people who request a demo, quote, call or contract;
- users of SubWorks products, including DeskSub, HotelSub, ShuttleSub and WaiterSub;
- individuals whose personal data is processed in our products on behalf of a customer.
3. Roles and responsibilities
Controller: SubWorks acts as controller for personal data we process for our own business purposes, such as website management, account administration, subscriptions, billing, support, communications, analytics, security, contract handling and supplier management.
Processor: for much of the data that customers enter or store in our products, we act as processor on behalf of the relevant customer. In those cases, the customer determines the purpose of the processing and is the controller.
Where we act as processor, our customer is responsible for ensuring that an appropriate legal basis, transparency notice and any required permissions are in place.
4. What personal data we process
- Account and profile data: full name, email address, username, role, company or property name, language preference, linked hotel or location information, hashed login credentials, passkey or SSO identifiers where used, and account settings.
- Company and billing data: company name, address, billing contact details, VAT number, business registration details if provided, subscription plan details, invoice references and customer IDs.
- Product workflow data: data entered by customers into DeskSub, HotelSub, ShuttleSub or WaiterSub, which may include names, booking details, reservation data, staffing data, operational notes, schedules, transport details, room-related data, order data or other workflow information.
- Identity verification data: where identity verification is used, verification-related identifiers, status information and associated metadata may be processed through Stripe Identity. Depending on the implementation and flow, identity documents, selfies or verification results may be collected directly by Stripe or made available to us through Stripe's services.
- Usage and technical data: IP address, browser type, device information, operating system, timestamps, referring URLs, crash information, login attempts, audit trails, security events and system logs.
- Payment and financial data: Stripe customer IDs, payment intent or subscription identifiers, payment status, invoice metadata, quote metadata and accounting references. We do not intentionally store full payment card details on our own systems.
- Support and communication data: support tickets, chat messages, help center interactions, email correspondence, attachments, call booking details and customer service history.
- Uploads and submitted content: attachments, CSV files, logos, documents, templates and other content submitted through our services or support channels.
5. How we obtain personal data
- Directly from you, for example when you contact us, request a quote, create an account, sign a contract, start a trial, submit support requests or use our products.
- From our customers, when they create user accounts, manage teams, import data or use our products in their daily operations.
- Automatically through your use of our websites and services, such as logs, cookies, fraud prevention systems, analytics events and security monitoring.
- From third-party providers and integrations where applicable, such as payment, identity verification, scheduling, support or authentication services.
6. Purposes and legal bases
- Providing our services: to create and manage accounts, enable product functionality, maintain customer environments, and operate DeskSub, HotelSub, ShuttleSub and WaiterSub. Legal basis: contract and, where relevant, legitimate interests.
- Authentication and access control: to manage sign-in, session handling, passkeys, SSO, fraud checks and account security. Legal basis: legitimate interests and contract.
- Payments, subscriptions and identity verification: to process payments, manage subscriptions, prevent fraud, verify identities where required, and maintain records relating to contracts and transactions. Legal basis: contract, legitimate interests and legal obligation where applicable.
- Support and customer communication: to answer questions, provide help center content, run chat support, and send service-related notices. Legal basis: contract and legitimate interests.
- Security, monitoring and abuse prevention: to protect our services, detect suspicious behaviour, investigate incidents and maintain logs and audit trails. Legal basis: legitimate interests and legal obligation where applicable.
- Analytics and improvement: to understand service usage, improve our sites and products, test changes and troubleshoot problems. Legal basis: legitimate interests and consent where required.
- Sales, contracting and administration: to prepare quotes, contracts, invoices and other administrative records. Legal basis: contract, legitimate interests and legal obligation.
- Marketing and product updates: to send relevant updates or offers where permitted. Legal basis: legitimate interests or consent, depending on the message and applicable law.
If we intend to process personal data for a purpose that is materially incompatible with the original purpose, we will seek consent or identify another lawful basis before doing so.
9. Retention
We retain personal data only for as long as necessary for the purposes for which it was collected, unless a longer retention period is required or permitted by law.
- Account and customer relationship data: during the active relationship and for a reasonable period afterwards for support, security, continuity and record-keeping.
- Customer product data: as instructed by the customer, subject to contract terms, deletion workflows, backup cycles and legal obligations.
- Security logs and audit trails: for a limited period appropriate to security, fraud prevention, troubleshooting and compliance needs.
- Support records: for as long as reasonably necessary to handle requests, maintain context and resolve disputes.
- Financial, tax and invoice records: for the period required by applicable accounting and tax laws.
- Backups: in accordance with rolling backup and recovery schedules.
10. Security
We take appropriate technical and organisational measures designed to protect personal data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure or access.
- encrypted transport using TLS where appropriate;
- role-based or need-to-know access controls;
- hashed passwords and secure authentication practices;
- logging, monitoring and incident handling;
- backups and continuity measures;
- vendor selection and security-minded system design.
No system can be guaranteed to be completely secure, but we work to maintain a level of protection appropriate to the risks involved.
11. Automated decision-making
We do not intentionally make decisions based solely on automated processing that produce legal effects concerning you or similarly significantly affect you, unless such processing is specifically disclosed, authorised by law, or based on your explicit consent where required.
Security and fraud prevention systems may use automated signals or scoring to help identify suspicious activity, but these are generally used as safeguards or inputs into broader review processes.
12. Your rights
Subject to applicable law, you may have rights including:
- the right to access your personal data;
- the right to correct inaccurate or incomplete data;
- the right to request deletion of your data;
- the right to restrict certain processing;
- the right to object to certain processing;
- the right to data portability where applicable;
- the right to withdraw consent where processing is based on consent.
You can submit a request via support@subworks.co. Where we act as processor on behalf of a customer, we may direct your request to the relevant customer as controller.
13. Minors
Our services are generally intended for business use and are not directed to children. If a customer uses our services in a way that involves data relating to minors, that customer is responsible for ensuring that an appropriate legal basis and required notices are in place.
14. Questions or complaints
For privacy questions, requests or complaints, contact us at support@subworks.co.
If you are located in the Netherlands or the EEA, you may also have the right to lodge a complaint with your local supervisory authority, including the Dutch Data Protection Authority where applicable.
15. Changes
We may update this Privacy Policy from time to time. The latest version will always be published on this page. If a change is material, we may notify you through the website, within the product, by email or by another appropriate method.
16. Data Processing Agreement
Customers who use our services in a way that involves processor services may request a Data Processing Agreement ("DPA"). Our DPA is intended to cover, where applicable, topics such as subject matter and duration of processing, categories of data, confidentiality, security measures, sub-processors, breach cooperation, deletion or return of data, international transfers and audit-related provisions.
For the latest version, contact support@subworks.co.