Privacy Policy

Last updated: 5th of January 2026

This Privacy Policy explains how CreateWorker B.V. ("CreateWorker", "we", "us", or "our") processes personal data in connection with the CreateWorker platform and related services (the "Service").

This Privacy Policy applies to business users of the Service and visitors to our website. CreateWorker does not provide consumer services.


1. Who We Are

Controller (for website and account data):

CreateWorker B.V.
Hamerstraat 3D
1135 GA Edam
The Netherlands
Email: [email protected]

For Customer Data processed through the Service, CreateWorker generally acts as a data processor, and the Organization using the Service acts as the data controller.


2. Scope of This Policy

This Privacy Policy covers:

  • Website visitors
  • Account holders and authorized Users
  • Personal data processed within the Service on behalf of Organizations

Processing of Customer Data within the Service is further governed by the Data Processing Agreement (DPA) where applicable.


3. Categories of Personal Data

3.1 Website and Account Data (Controller Role)

We may process:

  • Name, email address, company name
  • Login and authentication data
  • Communication preferences
  • Support requests and correspondence
  • IP address and basic device information

3.2 Customer Data Processed via the Service (Processor Role)

Depending on how an Organization uses the Service, Customer Data may include:

  • User identifiers and role assignments
  • Task inputs and AI-generated Proposals
  • Email content and metadata (subject, sender, recipient, timestamps)
  • Audit logs and activity records
  • Configuration and approval data

CreateWorker does not determine the content of Customer Data.


4. Purposes of Processing

We process personal data for the following purposes:

  • Providing and operating the Service
  • Authenticating Users and managing access
  • Generating AI Proposals and executing approved actions
  • Maintaining audit logs and system security
  • Providing customer support
  • Improving reliability and performance
  • Complying with legal obligations

We do not process personal data for unrelated or incompatible purposes.


5. Legal Bases (GDPR)

5.1 Website and Account Data

Processing is based on:

  • Performance of a contract
  • Legitimate interests (e.g. security, fraud prevention, service improvement)
  • Legal obligations

5.2 Customer Data within the Service

Processing is based on:

  • Performance of a contract with the Organization
  • Instructions from the Organization as data controller

Organizations are responsible for identifying the appropriate legal basis for their use of the Service.


6. AI Processing

AI functionality processes Customer Data only to:

  • Generate Proposals in response to Tasks
  • Support approved executions
  • Maintain auditability and traceability

CreateWorker:

  • Does not use Customer Data to train proprietary AI models by default
  • Does not make automated decisions with legal or similarly significant effects
  • Does not use AI outputs for independent profiling

AI outputs are subject to human review and approval by design.


7. Email Processing

If enabled by the Organization, the Service may access email accounts via Gmail OAuth, IMAP, SMTP, or similar integrations.

Email data is processed solely to:

  • Generate AI Proposals
  • Execute approved actions
  • Maintain audit logs

Email credentials and access tokens are encrypted at rest and not shared with end users.

CreateWorker does not independently initiate communications.


8. Data Sharing and Sub-Processors

We may share personal data with:

  • Cloud infrastructure providers
  • AI model providers
  • Email and integration providers
  • Security and monitoring providers

All sub-processors are subject to appropriate contractual and technical safeguards.

A current list of sub-processors is available upon request or via the DPA.


9. International Data Transfers

Personal data may be processed outside the European Economic Area.

Where applicable, transfers are safeguarded using:

  • Standard Contractual Clauses (SCCs)
  • Equivalent legal mechanisms

10. Data Retention

We retain personal data only for as long as necessary to:

  • Provide the Service
  • Comply with legal obligations
  • Resolve disputes
  • Enforce agreements

Retention periods for Customer Data are governed by the DPA and Organization instructions.


11. Security Measures

We implement appropriate technical and organizational measures, including:

  • Encryption at rest and in transit
  • Role-based access controls
  • Audit logging
  • Environment isolation
  • Secure credential handling

No system is completely secure, but we take data protection seriously.


12. Data Subject Rights

Where CreateWorker acts as a controller, individuals may have rights under GDPR, including:

  • Access
  • Rectification
  • Erasure
  • Restriction
  • Objection
  • Data portability

Requests may be submitted to [email protected].

Where CreateWorker acts as a processor, requests should be directed to the Organization acting as controller.


13. Cookies and Tracking

Our website uses limited cookies and similar technologies necessary for functionality and security.

We do not use tracking cookies for advertising purposes without consent.


14. Changes to This Policy

We may update this Privacy Policy from time to time. Material changes will be communicated through the website or Service.


15. Contact

For privacy questions or requests:

CreateWorker B.V.
Email: [email protected]
Website: https://www.createworker.com

Privacy Policy | CreateWorker