Workzy privacy notice

How Workzy handles personal data

Last updated: 24 August 2026

If you are a member of a coworking space that uses Workzy, this is probably not the notice you want. The space itself decides what happens to your data, and publishes its own notice — you will find it linked in the footer of that space’s booking pages.

Who we are

Workzy is booking software for coworking spaces. Spaces use it to publish their locations, take bookings and email their members.

Where Workzy is the controller

Workzy decides the purposes and means of processing — and is therefore the controller — for a narrow set of data:

  • Accounts belonging to the staff of a coworking space that uses Workzy.
  • Billing and contract details for the spaces themselves.
  • Anything you send when you contact Workzy directly.

Where Workzy is only a processor

For everything a member of a coworking space does — their account, their bookings, their event registrations, their consent decisions — the space is the controller and Workzy is only the processor. Workzy stores and handles that data on the space’s written instructions, under the terms of a data processing agreement, and does not use it for its own purposes. It is never sold, and never used to build a profile or advertise anything.

That means requests about that data — access, correction, deletion — go to the space, not to Workzy. If you send one to Workzy anyway, it will be passed to the space rather than acted on directly, because acting on it would be acting outside the space’s instructions.

Sub-processors

Workzy uses these providers to run the service. Each is under a written contract and each only does what it is instructed to do:

WhoWhat they doWhere
MyWindowsHostingServers and databaseAmsterdam, Netherlands
Microsoft AzureStorage of uploaded photosEuropean Union
Brevo (Sendinblue)Email deliveryFrance

Data is stored in the European Union.

How long data is kept

Staff accounts are kept while the space’s contract runs, and for 24 months after it ends. Billing records are kept for eleven years, as Croatian accounting law requires. Support correspondence is kept for 24 months. Sign-in sessions are deleted 90 days after they expire.

Security

Passwords are stored as one-way hashes. Everything travels over encrypted connections. Sign-in sessions are single-use and rotate, and a replayed session token ends every session on that account. Access to production data is limited to those who need it.

Your rights

Where Workzy is the controller, you have the rights of access, correction, deletion, restriction, objection and portability, and you can withdraw consent at any time. Requests are free and answered within one month. You can also complain to the supervisory authority:

Agencija za zaštitu osobnih podataka (AZOP)
Selska cesta 136, 10000 Zagreb, Croatia
azop@azop.hr — azop.hr

Cookies

No cookies are used for advertising, analytics or tracking, so there is no cookie banner. The only things stored on your device are a sign-in token, your language choice, and an offline cache — all strictly necessary to deliver the service.

Workzy privacy notice

© 2026 Workzy