Privacy Policy
Last updated: 5th of January 2026
This Privacy Policy explains how CreateWorker B.V. ("CreateWorker", "we", "us", or "our") processes personal data in connection with the CreateWorker platform and related services (the "Service").
This Privacy Policy applies to business users of the Service and visitors to our website. CreateWorker does not provide consumer services.
1. Who We Are
Controller (for website and account data):
CreateWorker B.V.
Hamerstraat 3D
1135 GA Edam
The Netherlands
Email: [email protected]
For Customer Data processed through the Service, CreateWorker generally acts as a data processor, and the Organization using the Service acts as the data controller.
2. Scope of This Policy
This Privacy Policy covers:
- Website visitors
- Account holders and authorized Users
- Personal data processed within the Service on behalf of Organizations
Processing of Customer Data within the Service is further governed by the Data Processing Agreement (DPA) where applicable.
3. Categories of Personal Data
3.1 Website and Account Data (Controller Role)
We may process:
- Name, email address, company name
- Login and authentication data
- Communication preferences
- Support requests and correspondence
- IP address and basic device information
3.2 Customer Data Processed via the Service (Processor Role)
Depending on how an Organization uses the Service, Customer Data may include:
- User identifiers and role assignments
- Task inputs and AI-generated Proposals
- Email content and metadata (subject, sender, recipient, timestamps)
- Audit logs and activity records
- Configuration and approval data
CreateWorker does not determine the content of Customer Data.
4. Purposes of Processing
We process personal data for the following purposes:
- Providing and operating the Service
- Authenticating Users and managing access
- Generating AI Proposals and executing approved actions
- Maintaining audit logs and system security
- Providing customer support
- Improving reliability and performance
- Complying with legal obligations
We do not process personal data for unrelated or incompatible purposes.
5. Legal Bases (GDPR)
5.1 Website and Account Data
Processing is based on:
- Performance of a contract
- Legitimate interests (e.g. security, fraud prevention, service improvement)
- Legal obligations
5.2 Customer Data within the Service
Processing is based on:
- Performance of a contract with the Organization
- Instructions from the Organization as data controller
Organizations are responsible for identifying the appropriate legal basis for their use of the Service.
6. AI Processing
AI functionality processes Customer Data only to:
- Generate Proposals in response to Tasks
- Support approved executions
- Maintain auditability and traceability
CreateWorker:
- Does not use Customer Data to train proprietary AI models by default
- Does not make automated decisions with legal or similarly significant effects
- Does not use AI outputs for independent profiling
AI outputs are subject to human review and approval by design.
7. Email Processing
If enabled by the Organization, the Service may access email accounts via Gmail OAuth, IMAP, SMTP, or similar integrations.
Email data is processed solely to:
- Generate AI Proposals
- Execute approved actions
- Maintain audit logs
Email credentials and access tokens are encrypted at rest and not shared with end users.
CreateWorker does not independently initiate communications.
8. Data Sharing and Sub-Processors
We may share personal data with:
- Cloud infrastructure providers
- AI model providers
- Email and integration providers
- Security and monitoring providers
All sub-processors are subject to appropriate contractual and technical safeguards.
A current list of sub-processors is available upon request or via the DPA.
9. International Data Transfers
Personal data may be processed outside the European Economic Area.
Where applicable, transfers are safeguarded using:
- Standard Contractual Clauses (SCCs)
- Equivalent legal mechanisms
10. Data Retention
We retain personal data only for as long as necessary to:
- Provide the Service
- Comply with legal obligations
- Resolve disputes
- Enforce agreements
Retention periods for Customer Data are governed by the DPA and Organization instructions.
11. Security Measures
We implement appropriate technical and organizational measures, including:
- Encryption at rest and in transit
- Role-based access controls
- Audit logging
- Environment isolation
- Secure credential handling
No system is completely secure, but we take data protection seriously.
12. Data Subject Rights
Where CreateWorker acts as a controller, individuals may have rights under GDPR, including:
- Access
- Rectification
- Erasure
- Restriction
- Objection
- Data portability
Requests may be submitted to [email protected].
Where CreateWorker acts as a processor, requests should be directed to the Organization acting as controller.
13. Cookies and Tracking
Our website uses limited cookies and similar technologies necessary for functionality and security.
We do not use tracking cookies for advertising purposes without consent.
14. Changes to This Policy
We may update this Privacy Policy from time to time. Material changes will be communicated through the website or Service.
15. Contact
For privacy questions or requests:
CreateWorker B.V.
Email: [email protected]
Website: https://www.createworker.com