Skip to content

Privacy policy

Last updated 1 September 2026

The short version: we collect what WorkOne needs to plan where people work, keep it in the EU, never sell it or use it for advertising, and help you see, export or delete it. The details are below.

1.Who we are

Welyne builds and operates Welyne WorkOne (“WorkOne”), a service organisations use to plan desks, remote days, business trips, visitors and the carbon impact of work. You can reach us about anything in this policy at contact@welyne.com.

We play two different roles under the EU General Data Protection Regulation (GDPR):

Controller
For this website, demo requests, and the contact details of people at our customers we deal with for contracts and billing. We decide why and how that data is used.
Processor
For the data an organisation puts into its WorkOne workspace — its employees' bookings, requests, trips and so on. The organisation (usually your employer) is the controller; we process that data only on its instructions, under a data processing agreement.

If you use WorkOne through your employer, your employer's own privacy notice explains how it uses your data. Questions about that are best sent to them first; we'll help them answer.

2.What we collect

Website visitors
Standard server logs (IP address, browser, pages requested, time) kept for security and troubleshooting. We don't use advertising cookies or cross-site trackers.
Demo requests
What you type into the contact form: name, work e-mail, company, company size, role, the modules you're interested in and your message, plus the page you came from.
Workspace users
Name, work e-mail, role, team, manager, site and job title, as set up by your organisation; your sign-in times; and the device type used, to keep the service secure.
Workplace activity
Where you plan to work each day (office, home, client site, travelling or off), desk, room and parking bookings and check-ins, remote-work requests and approvals, visitors you host and workplace requests you report.
Business travel
Trip requests (destination, dates, transport, hotel), estimates, travel documents and receipts you upload, and expense amounts.
Commute profile
Optional: the distance and usual way you travel to the office, used only to estimate the emissions avoided on remote days.
Visitors
The name, company and visit details a host enters when registering a guest, and check-in and check-out times.

We don't collect keystrokes, screen activity, online status, location tracking or anything that measures how long someone works. WorkOne records where people plan to work, not what they do.

3.How we use it, and why we're allowed to

To provide WorkOne
Running the service for our customers, as our contract with them requires (GDPR art. 6(1)(b), and art. 28 as processor).
To reply to demo requests
Contacting you about the request you made and preparing a demo — steps you asked for before a possible contract, and our legitimate interest in answering.
To keep things secure
Detecting abuse, investigating incidents and protecting accounts — our legitimate interest, and our customers'.
To bill and keep records
Invoicing customers and keeping accounting records — a legal obligation.
To improve the product
Understanding which features are used, from aggregated statistics that don't identify individuals — our legitimate interest.

We never sell personal data, never use it for advertising, and never make decisions with legal or similarly significant effects about anyone by automated means. Automatic approval of remote days applies your organisation's own rules; a manager can always review and change the outcome.

4.Cookies

We use one essential cookie: a signed session cookie that keeps you signed in to WorkOne. It's set only when you sign in and is removed when you sign out or it expires. The installable app also stores a small offline cache on your device so pages open without a connection.

The public website sets no advertising or analytics cookies, which is why you don't see a cookie banner. If that ever changes, we'll ask for your consent first and update this page.

5.Who we share it with

Only with service providers that help us run WorkOne — hosting, e-mail delivery and customer support tools — under contracts that bind them to the same standards. The current list of sub-processors is available to customers on request, and we give notice before adding a new one.

Inside a workspace, what colleagues can see is set by your organisation's roles: teammates see where you plan to work, managers see requests to approve, the travel desk sees the trips it arranges, admins see the organisation. We may also disclose data if the law requires it, and we'll tell the customer concerned unless we're legally prevented from doing so.

6.Where your data is stored

Workspaces are hosted in data centres in the European Union. If a provider ever needs to access data from outside the European Economic Area, we rely on an adequacy decision or the European Commission's standard contractual clauses, with additional safeguards where needed.

7.How long we keep it

  • Demo requests: up to 24 months after our last exchange, unless you become a customer or ask us to delete them sooner.
  • Workspace data: for as long as the customer's contract runs. Admins can delete people and records at any time, and set how long schedules and bookings are kept.
  • After a contract ends: the customer has 30 days to export its data, then we delete it. Backups roll over and are gone within a further 35 days.
  • Server logs: 30 days.
  • Invoices and accounting records: as long as accounting law requires.

8.How we protect it

  • Encryption in transit (TLS) and at rest.
  • Passwords stored only as salted hashes; single sign-on available on Enterprise.
  • Role-based access in every workspace, and changes to policies and permissions recorded in an audit log.
  • Access to customer data by Welyne staff limited to what's needed for support, on request, and logged.
  • Regular backups and a documented incident process. If a breach affects personal data, we inform the customers concerned without undue delay so they can meet their own obligations.

9.Your rights

You have the right to access your personal data, correct it, have it deleted, restrict or object to its use, and receive it in a portable format. Where we rely on consent, you can withdraw it at any time.

For data in a workspace, your organisation is the controller, so contact its admin or HR team first — admins can export or delete a person's data from WorkOne directly. For anything we control, write to contact@welyne.com. We answer within one month.

You can also complain to a data protection authority — in France, the CNIL (cnil.fr), or the authority where you live or work.

10.Children

WorkOne is a workplace tool and isn't meant for anyone under 16. We don't knowingly collect data about children.

11.Changes to this policy

We'll update this page when our practices change and show the date at the top. For significant changes, we'll e-mail customer admins at least 30 days before they take effect.

12.Contact

Questions, requests or concerns about privacy: contact@welyne.com, with “Privacy” in the subject line. A person on our team will reply.