Workzy privacy notice
How Workzy handles personal data
Last updated: 24 August 2026
If you are a member of a coworking space that uses Workzy, this is probably not the notice you want. The space itself decides what happens to your data, and publishes its own notice — you will find it linked in the footer of that space’s booking pages.
Who we are
Workzy is booking software for coworking spaces. Spaces use it to publish their locations, take bookings and email their members.
Where Workzy is the controller
Workzy decides the purposes and means of processing — and is therefore the controller — for a narrow set of data:
- Accounts belonging to the staff of a coworking space that uses Workzy.
- Billing and contract details for the spaces themselves.
- Anything you send when you contact Workzy directly.
Where Workzy is only a processor
For everything a member of a coworking space does — their account, their bookings, their event registrations, their consent decisions — the space is the controller and Workzy is only the processor. Workzy stores and handles that data on the space’s written instructions, under the terms of a data processing agreement, and does not use it for its own purposes. It is never sold, and never used to build a profile or advertise anything.
That means requests about that data — access, correction, deletion — go to the space, not to Workzy. If you send one to Workzy anyway, it will be passed to the space rather than acted on directly, because acting on it would be acting outside the space’s instructions.
Sub-processors
Workzy uses these providers to run the service. Each is under a written contract and each only does what it is instructed to do:
| Who | What they do | Where |
|---|---|---|
| MyWindowsHosting | Servers and database | Amsterdam, Netherlands |
| Microsoft Azure | Storage of uploaded photos | European Union |
| Brevo (Sendinblue) | Email delivery | France |
Data is stored in the European Union.
How long data is kept
Staff accounts are kept while the space’s contract runs, and for 24 months after it ends. Billing records are kept for eleven years, as Croatian accounting law requires. Support correspondence is kept for 24 months. Sign-in sessions are deleted 90 days after they expire.
Security
Passwords are stored as one-way hashes. Everything travels over encrypted connections. Sign-in sessions are single-use and rotate, and a replayed session token ends every session on that account. Access to production data is limited to those who need it.
Your rights
Where Workzy is the controller, you have the rights of access, correction, deletion, restriction, objection and portability, and you can withdraw consent at any time. Requests are free and answered within one month. You can also complain to the supervisory authority:
Selska cesta 136, 10000 Zagreb, Croatia
azop@azop.hr — azop.hr
Cookies
No cookies are used for advertising, analytics or tracking, so there is no cookie banner. The only things stored on your device are a sign-in token, your language choice, and an offline cache — all strictly necessary to deliver the service.