Legal
Privacy Policy
Last updated: June 23, 2026
1. Who we are
Workdex ("we", "our", "us") is a human resources management platform for growing teams. When you use Workdex, you trust us with your organisation's employee data. This policy explains what we collect, why we collect it, and how we protect it.
2. Data we collect
We collect only what is necessary to operate the platform:
- Account data — company name, workspace slug, admin email address, and hashed password. Never stored in plain text.
- Employee records — name, job title, department, employment dates, salary information, leave balances, and attendance records. This data is entered by your organisation's administrators.
- Documents — files uploaded by your team (contracts, payslips, certificates). Stored on Cloudflare R2 with access restricted to your tenant.
- Audit logs — a record of who did what and when, for compliance purposes. Retained for the life of the account.
- Usage data — anonymous request logs (timestamp, endpoint, HTTP status). No personal identifiers. Retained for 30 days.
3. How we use your data
- To provide and improve the Workdex platform
- To send transactional emails (leave approvals, password resets, notifications)
- To enforce your organisation's access controls and audit trail
- To diagnose errors and investigate security incidents
We do not sell your data, use it for advertising, or share it with third parties except where required by law or necessary to operate the service (e.g., email delivery via Resend, file storage via Cloudflare R2).
4. Data storage and security
- All data is stored in a PostgreSQL database with row-level tenant isolation — your organisation's data is logically separated from all other tenants.
- Files are stored on Cloudflare R2 (S3-compatible object storage) with server-side encryption at rest.
- All traffic is encrypted in transit using TLS 1.2+.
- Passwords are hashed with bcrypt (cost factor 12) before storage.
- Authentication uses short-lived JWT access tokens (15 minutes) and rotating refresh tokens (7 days) stored in HTTP-only cookies, inaccessible to JavaScript.
5. Data retention
Your data is retained for as long as your account is active. When an account is cancelled:
- Employee records and audit logs are soft-deleted immediately and hard-deleted after 30 days.
- Uploaded documents are deleted from storage within 7 days of account closure.
- You can request immediate deletion by contacting us at hello@workdex.io.
6. Your rights (GDPR)
If you are based in the EEA, UK, or another jurisdiction with data protection laws, you have the right to:
- Access — request a copy of your personal data
- Rectification — correct inaccurate data
- Erasure — request deletion of your data
- Portability — receive your data in a machine-readable format
- Object — object to processing in certain circumstances
To exercise any of these rights, email hello@workdex.io and we will respond within 30 days.
7. Cookies
Workdex uses only functional cookies required to operate the platform — specifically, HTTP-only cookies for authentication tokens. We do not use advertising, analytics, or tracking cookies.
8. Changes to this policy
We may update this policy from time to time. When we do, we will update the "Last updated" date at the top of this page. Continued use of Workdex after changes constitutes acceptance of the updated policy.
9. Contact
Questions about this policy? Reach us at hello@workdex.io.