Privacy Policy
Effective date: 16 August 2026
This policy describes how Worklifted ("we", "us", "our") handles information in connection with this website, our automation service, and the ongoing care plans under which we maintain what we build.
1. Information we handle
- Enquiries. When you use the form on this site we receive the name, email address and description of the work you submit, plus which page you sent it from. That is the whole form; we do not ask for anything else.
- Correspondence. Emails and messages you send us, and our replies.
- Client engagement information. Once we are working together: the scope documents, the details of the process being automated, and the credentials or access needed to build it.
- Operational and monitoring data. Where we maintain an automation for you, we receive its error reports, run failures and health alerts. These can contain fragments of the data the automation was processing when it failed. Section 2 explains this properly, because it is the part of this policy most worth reading.
- Website analytics. Aggregate, privacy-preserving usage statistics — pages viewed, referrer, approximate country. No cookies are set for this, and no individual visitor is profiled or tracked across sites.
We do not run advertising pixels, we do not sell personal information, and we do not add you to a mailing list because you contacted us.
2. Where your data sits, and what reaches us
Building and maintaining an automation means connecting to the tools your team already uses. Three things about that matter for your privacy. The third is the one people miss, so it is written out in full rather than softened.
- Automations run on your own instance and your own accounts, by default. That is how we recommend it, and it is how nearly every engagement is set up. In normal operation the data moving through a finished automation moves between your systems — it does not route through ours, and we hold no copy of it. If you have nowhere to run it and ask us to host it instead, we say so in the scope document before you agree to anything, and then it does run on our infrastructure. That is an exception we name in writing, never a default you discover later.
- Our access lasts as long as the arrangement does. For a build, we ask for the narrowest access that will do the job and ask you to revoke or rotate it at handover. On a care plan that access continues for the life of the plan, because we cannot repair what we cannot reach, and it ends when the plan ends. You can revoke it at any time; if doing so stops us monitoring something, we will tell you what stops rather than let it fail quietly.
- Failures are reported to us, and a failure carries data with it. Monitoring an automation means its errors arrive in our systems, not just yours. An error report usually contains the thing that failed — the invoice that would not parse, the row that was rejected, the message that could not be delivered. A copy of that fragment therefore does sit with us until we clear it. This is a genuine exception to the first bullet above, and we would rather write it down here than have you find it out.
We keep error reports only as long as we need them to fix the fault and to see whether it is recurring — no longer than 90 days — and we use them for nothing else. If you would rather no failure data left your systems at all, tell us before we build: alerts can be routed to a channel of yours instead, and we work from whatever you choose to send us. Faults take longer to catch that way, and that is the trade you would be making.
While building, testing and maintaining, we will see real data from the process being automated — that is the point of testing on real data rather than invented samples. We treat everything we see inside your business as confidential, and we do not use it for anything except the work you engaged us for.
3. How we use information
- To reply to your enquiry.
- To scope, build, test and hand over the automation you engaged us for.
- To monitor, repair and maintain automations under a care plan.
- To keep our own records of engagements, invoices and correspondence.
- To understand, in aggregate, which parts of this site are useful.
We do not use your content or your business data to train AI models, and we do not pass it to anyone who would.
4. Who else is involved
A few service providers process information on our behalf so that the site, the enquiry pipeline and our monitoring work:
- n8n — self-hosted and operated by us, receives the enquiry form submission.
- Our monitoring and alerting tools — self-hosted or operated under contract by us, receive the error reports described in section 2.
- Email and hosting providers — deliver our correspondence and serve this website.
- Analytics — aggregate, cookieless website statistics.
Where an automation we build for you connects to a third-party service, that service handles your data under its own terms, not ours. We will tell you which services an automation touches before you approve the scope.
5. How long we keep things
- Enquiries that do not become engagements — up to 24 months, then deleted.
- Engagement records (scopes, invoices, correspondence) — retained while we work together and for as long afterwards as tax and accounting law requires.
- Error reports and monitoring data — up to 90 days, then deleted. We do not keep an archive of what your automations processed.
- Credentials and access — held for the life of the build or the care plan, and revoked or handed back when it ends. We do not retain client credentials after an engagement ends.
- Aggregate website statistics — retained indefinitely in a form that does not identify anyone.
6. Your rights
You can ask us what information we hold about you, ask for it to be corrected, or ask us to delete it. Email contact@worklifted.com and we will respond within 30 days. If we have to keep something to meet a legal obligation, we will tell you what and why rather than quietly keeping it.
7. Security
We keep access to client systems on a need-to-do-the-work basis, use unique credentials per engagement, and do not share client access outside the people building and maintaining your automation. No system is perfectly secure; if a breach affects your information we will tell you promptly and tell you what happened.
8. International working
We are based in Tamil Nadu, India, and work with clients worldwide. Information you send us is handled in India and in the countries where our service providers operate.
9. Children
This site and this service are for businesses. They are not directed at children, and we do not knowingly collect information from them.
10. Changes to this policy
We may update this policy. Material changes are reflected by updating the effective date above.