Skip to main content

Privacy Policy

Last Updated: June 9, 2026

1. Introduction

Welcome to WorkBuddy ("we," "our," or "us"). We are committed to protecting your privacy and ensuring the security of your information. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use WorkBuddy, a React Native application, or any associated services (collectively, the "Service").

WorkBuddy is a business-to-business ("B2B") AI-powered sales assistant for field sales teams. Access and use of the Service is governed by individual commercial agreements between us and each client organisation. This Privacy Policy applies to all hosting models described herein.

2. Hosting Models and Data Responsibility

WorkBuddy is offered under two hosting models. The allocation of data responsibility differs for each:

2.1 WorkBuddy-Managed Hosting

In the WorkBuddy-managed model, we operate and maintain the application environment on behalf of the client. Commercial terms, support levels, backups, and operational responsibilities are governed by the applicable agreement.

2.2 Customer or Private Infrastructure

WorkBuddy may also be deployed on customer-owned or private infrastructure under a separate commercial agreement. In this model, infrastructure costs, access controls, backups, and local compliance responsibilities are defined in the client agreement.

3. Information We Collect

3.1 Information You Provide

  • Account Information: Name, email address, and organisation details when you register
  • Business Data: Contacts, companies, deals, projects, tasks, notes, and other entities you create within the workspace
  • Communication Data: Messages and interactions through the chat interface, including AI-assisted conversations
  • Sign-In Data: Information used to verify and secure your account

3.2 Automatically Collected Information

  • Usage Data: Features used, actions taken, and interaction patterns to improve the Service
  • Device Information: Browser type, operating system, IP address, device model, and unique device identifiers
  • Cookies: Session cookies strictly for authentication and maintaining user sessions

3.3 Mobile Application Data

When you use our iOS or Android mobile application, we may request access to the following device capabilities. Each permission is optional and requested only when the corresponding feature is used:

  • Contacts: To import and sync your device contacts with your WorkBuddy workspace. Contact data is processed only when you explicitly initiate a sync or import action.
  • Calendar: To display upcoming events and create meetings. Calendar data is read locally and synced to your workspace when you choose to create or link an event.
  • Location: To enable check-ins and geo-tag notes. Location data is captured only when you perform a check-in or geo-tag action; we do not track your location in the background.
  • Biometric Authentication (Face ID / Fingerprint): To secure access to the app after periods of inactivity. Biometric data is processed entirely on your device by the operating system; we never receive, transmit, or store biometric data.
  • Photo Library: To save scanned business card images to your device gallery and to attach images to notes or conversations. We access photos only when you explicitly select or save an image.
  • Camera: To scan business cards and capture images for attachment. Camera access is used only during active capture; no images are taken without your action.
  • Push Notifications: To deliver task reminders, follow-up alerts, and new message notifications. You can disable notifications at any time through your device settings.
  • Microphone: To record voice notes for AI-powered transcription and data extraction. Audio is captured only when you press and hold the record button.

You may revoke any of these permissions at any time through your device's system settings. Revoking a permission will disable the corresponding feature but will not affect the core functionality of the application.

3.4 Payment Information

Payments for subscriptions and passes are handled by a third-party payment processor, which supports UPI, card, and net banking. We do not store full card numbers or complete payment credentials on our systems. The processor may share limited transaction details with us (such as payment status and the last few digits of a card) to confirm and reconcile your purchase.

4. How We Use Your Information

We use your information to:

  • Provide, operate, and maintain WorkBuddy
  • Process AI-powered data extraction, intent classification, and task assignment
  • Send transactional communications such as sign-in codes, system notifications, and reminders
  • Personalise your experience with AI personas and contextual assistance
  • Respond to support enquiries and provide customer service
  • Detect and prevent fraud, abuse, or security threats
  • Comply with legal obligations and enforce our Terms of Service
  • Generate aggregated, anonymised analytics to improve the Service (no individual user data is exposed)

5. AI and Data Processing

WorkBuddy uses AI-assisted processing to power intelligent features such as contact extraction, call summaries, follow-up suggestions, and voice transcription. This section explains how your data is handled when those features are used.

5.1 How AI Processing Works

When you send a message or use an AI-powered feature, WorkBuddy processes only the relevant context needed to complete that request. We do not use customer data to train public AI models.

To power voice and image features, voice audio recordings and business-card or document images are transmitted to a third-party AI provider (for example, Groq) acting as a sub-processor, solely to perform transcription and data extraction. This content is processed strictly to return the requested result and is not used to train public AI models.

5.2 Processing Safeguards

AI-assisted processing follows these safeguards:

  • Your data is not used to train, fine-tune, or improve any AI models
  • Only relevant request context is processed
  • Clients with specific requirements may define additional processing terms in their commercial agreement

5.3 AI Accuracy Disclaimer

AI-generated content (summaries, email drafts, extracted data, classifications) is provided on a best-effort basis. We do not guarantee the accuracy, completeness, or suitability of AI outputs. You are responsible for reviewing and verifying all AI-generated content before acting upon it.

5.4 Custom AI Configuration

For clients with specific data sovereignty or compliance requirements, custom processing arrangements may be agreed separately.

6. Data Storage and Security

We implement commercially reasonable security measures to protect your data:

  • Protected access: Users access WorkBuddy through verified accounts and organisation-level permissions
  • Role controls: Administrators can manage user access and team visibility
  • Secure transmission: WorkBuddy uses secure communication channels for app traffic
  • Operational safeguards: Backup, retention, and support responsibilities are governed by the applicable hosting model and client agreement

7. Data Sharing and Disclosure

We do NOT sell, rent, or trade your personal data. For complete legal terms, see our Terms of Service. We may share your information only in the following limited circumstances:

  • With Your Consent: When you or your organisation's administrator explicitly authorise data sharing
  • AI Processing: Relevant context may be processed as described in Section 5, strictly to provide requested features
  • Service Providers: Trusted service providers may support hosting, communication, notifications, and related operations under appropriate obligations
  • Legal Requirements: When required by law, court order, subpoena, or to protect our legal rights, safety, or property
  • Business Transfers: In connection with a merger, acquisition, or sale of assets, with prior notice to affected clients

8. Third-Party Services

The Service may use trusted service providers to operate product features. Use of optional integrations is subject to their respective terms and privacy policies:

  • Communication services: Used for transactional messages, reminders, and notifications
  • AI-assisted processing: Used to provide voice, summary, extraction, and assistant features
  • Hosting and operations: Used where WorkBuddy-managed hosting is selected

We evaluate all third-party providers for adequate security and data protection practices. Clients with specific compliance requirements may request a list of all sub-processors under their commercial agreement.

9. Your Rights and Choices

Depending on your jurisdiction, you have the following rights regarding your personal data:

  • Access: Request a copy of the personal data we hold about you
  • Correction: Request correction of inaccurate or incomplete data
  • Deletion: Request deletion of your account and associated data
  • Export: Request your data in a structured, machine-readable format
  • Restriction: Request that we restrict processing of your data in certain circumstances
  • Objection: Object to processing of your data for specific purposes
  • Withdraw Consent: Withdraw consent for any processing based on consent, without affecting the lawfulness of prior processing

To exercise any of these rights, contact us at: ashish@theworkbuddy.app. For common questions about data handling, visit our FAQ.

For enterprise clients, data requests should be directed through your organisation's designated administrator, in accordance with your commercial agreement.

10. Data Retention

We retain your data for as long as your account or your organisation's subscription is active, or as needed to provide the Service.

  • Upon account deletion, we permanently delete your personal data within 30 days, except where retention is required by law or for legitimate business purposes (e.g., billing records, dispute resolution).
  • Aggregated, anonymised data that cannot identify individuals may be retained indefinitely for analytics and service improvement.
  • For customer/private infrastructure deployments, data retention responsibilities are governed by the applicable client agreement.

11. Children's Privacy

WorkBuddy is a B2B platform intended for use by businesses and professionals. The Service is not directed at individuals under the age of 18. We do not knowingly collect personal information from minors. If you believe we have inadvertently collected information from a minor, please contact us immediately and we will take steps to delete it.

12. International Data Transfers

Your data may be processed in countries outside your country of residence, including where our infrastructure providers and AI processing services operate. We ensure appropriate safeguards are in place, including contractual protections with our sub-processors, to protect your data in accordance with applicable data protection laws.

For clients with data residency requirements, WorkBuddy may be deployed on customer-owned or private infrastructure under a separate agreement.

13. GDPR Compliance (EU/EEA Users)

If you are located in the European Economic Area (EEA), you have the following additional rights under the General Data Protection Regulation (GDPR):

  • Right to data portability
  • Right to restrict processing
  • Right to object to processing based on legitimate interests
  • Right to lodge a complaint with your local data protection supervisory authority

Our lawful bases for processing include: contract performance (providing the Service), legitimate interests (security, fraud prevention, service improvement), and consent (where explicitly obtained for specific processing activities).

For enterprise clients requiring a Data Processing Agreement (DPA), please contact us to arrange one as part of your commercial agreement.

14. Changes to This Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, technology, or legal requirements. We will notify you of material changes by email or through the Service at least 14 days before the changes take effect. Continued use of the Service after the effective date constitutes acceptance of the updated policy.

15. Contact Us

If you have questions about this Privacy Policy, our data practices, or wish to exercise your rights, contact us:

Looking for more information? Check our homepage, documentation, FAQ, or Terms of Service for additional details.