LEGAL

Privacy Policy

Last updated: February 23, 2026

1. Introduction and Data Controller

Creative Digital BV (besloten vennootschap), registered with the Dutch Chamber of Commerce (Kamer van Koophandel) under number 94498156, with its registered office in Amsterdam, the Netherlands ("Creative Digital," "we," "us," or "our"), operates the LetWorkFlow.io platform (the "Service").

This Privacy Policy explains how we collect, use, disclose, store, and protect your Personal Data when you visit our website at www.letworkflow.io and use our Service. We are committed to protecting your privacy and processing your Personal Data in compliance with the General Data Protection Regulation (EU) 2016/679 ("GDPR"), the Dutch GDPR Implementation Act (Uitvoeringswet AVG), and other applicable data protection legislation.

For the purposes of the GDPR, Creative Digital BV is the Data Controller for the Personal Data we collect directly from you (e.g., account registration, billing, website usage). Where you use our Service to process Personal Data of your own clients, employees, or other individuals, you are the Data Controller and Creative Digital acts as the Data Processor on your behalf, governed by our Data Processing Agreement (DPA).

Data Protection Contact

For any questions or concerns about this Privacy Policy or our data practices, you may contact us at:

Creative Digital BV
Attn: Data Protection
Amsterdam, the Netherlands
Email: privacy@letworkflow.io

2. Definitions

3. Information We Collect

We collect and process the following categories of Personal Data:

3.1 Account and Registration Data

When you create an account or sign up for our Service, we collect:

3.2 Billing and Payment Data

When you subscribe to a paid plan, we collect:

Important: We do not store full credit card numbers, CVV/CVC codes, or other sensitive payment card data. All payment processing is handled by our PCI DSS-compliant payment processor, Stripe, Inc. See Section 7 for details.

3.3 Service Usage Data

When you use our Service, we may collect:

3.4 Technical and Device Data

When you visit our website or use our Service, we automatically collect:

3.5 Communication Data

When you contact us or interact with our communications, we collect:

3.6 Interactive Tools and Calculator Data

When you use interactive tools on our website, such as the ROI Calculator, we collect:

Calculator responses are stored locally in your browser session (sessionStorage) and are automatically cleared when you close your browser tab. If you provide your email address, your results and contact information are transmitted to our email service provider (ConvertKit) for delivery of your personalised report. No raw financial figures are sent to analytics services; only banded categories (e.g., "€20k-50k") are used for aggregate analysis.

Legal basis: Consent (Article 6(1)(a) GDPR) for marketing emails; Legitimate interest (Article 6(1)(f) GDPR) for transactional result delivery. You may request deletion of your calculator data at any time by contacting privacy@letworkflow.io.

3.7 Data You Process Through the Service

As a work management platform, you may use our Service to process Personal Data of your own clients, employees, and contacts. You are the Data Controller for this data, and our processing of it is governed by our Data Processing Agreement. We process this data solely on your instructions and for the purpose of providing the Service.

4. Legal Basis for Processing

Under the GDPR, we process your Personal Data based on the following legal grounds (Article 6(1) GDPR):

4.1 Performance of a Contract (Article 6(1)(b))

We process your Personal Data as necessary to perform our contractual obligations to you, including:

4.2 Legitimate Interests (Article 6(1)(f))

We process certain Personal Data based on our legitimate interests, where those interests are not overridden by your data protection rights. Our legitimate interests include:

4.3 Consent (Article 6(1)(a))

Where required by law, we process your Personal Data based on your explicit consent, including:

You may withdraw your consent at any time without affecting the lawfulness of processing carried out prior to withdrawal. See Section 9 for how to exercise this right.

4.4 Legal Obligation (Article 6(1)(c))

We process Personal Data where necessary to comply with our legal obligations, including tax and accounting requirements, regulatory compliance, and responding to lawful requests from public authorities.

5. How We Use Your Information

We use the Personal Data we collect for the following purposes:

6. Data Sharing and Disclosure

We do not sell, rent, or trade your Personal Data to third parties. We may share your Personal Data only in the following limited circumstances:

6.1 Sub-Processors and Service Providers

We share Personal Data with trusted third-party service providers who assist us in operating the Service. These sub-processors are contractually bound to process Personal Data only on our instructions and in compliance with the GDPR. Our current sub-processors include:

A complete and current list of our sub-processors is available upon request by contacting privacy@letworkflow.io. We will notify you of any material changes to our sub-processor list.

6.2 Legal Requirements

We may disclose your Personal Data if required to do so by law or in the good faith belief that such disclosure is necessary to: (a) comply with a legal obligation, court order, or regulatory requirement; (b) protect and defend the rights, property, or safety of Creative Digital, our users, or the public; (c) detect, prevent, or address fraud, security, or technical issues; or (d) respond to a lawful request from a public authority.

6.3 Business Transfers

In the event of a merger, acquisition, corporate reorganization, bankruptcy, or sale of all or a portion of our assets, your Personal Data may be transferred as part of that transaction. We will notify you via email and/or a prominent notice on our website of any change in ownership or uses of your Personal Data, as well as any choices you may have regarding your Personal Data.

6.4 With Your Consent

We may share your Personal Data with third parties when you give us explicit consent to do so.

7. International Data Transfers

Creative Digital is based in the Netherlands, and your Personal Data is primarily stored and processed within the European Economic Area (EEA). However, some of our sub-processors are located in the United States or other countries outside the EEA.

When we transfer Personal Data outside the EEA, we ensure that appropriate safeguards are in place as required by Chapter V of the GDPR, including:

You may request information about the specific safeguards applied to transfers of your Personal Data by contacting privacy@letworkflow.io.

8. Data Retention

We retain your Personal Data only for as long as necessary to fulfill the purposes for which it was collected, as described in this Privacy Policy, or as required by applicable law. Our specific retention periods are:

When Personal Data is no longer needed, it is securely deleted or anonymized in accordance with our data destruction procedures.

9. Your Rights Under the GDPR

As a Data Subject under the GDPR, you have the following rights regarding your Personal Data. You may exercise these rights at any time by contacting us at privacy@letworkflow.io or by using the tools provided within the Service.

9.1 Right of Access (Article 15)

You have the right to request confirmation of whether we process your Personal Data and to obtain a copy of the Personal Data we hold about you. We will respond to your request within thirty (30) days.

9.2 Right to Rectification (Article 16)

You have the right to request the correction of inaccurate Personal Data and the completion of incomplete Personal Data. You can update most of your information directly through your Account settings.

9.3 Right to Erasure (Article 17)

You have the right to request the deletion of your Personal Data when: (a) it is no longer necessary for the purposes for which it was collected; (b) you withdraw your consent and no other legal basis exists; (c) you object to the processing and no overriding legitimate grounds exist; or (d) the data has been unlawfully processed. This right is subject to our legal obligations to retain certain data (e.g., financial records).

9.4 Right to Restriction of Processing (Article 18)

You have the right to request restriction of processing of your Personal Data when: (a) you contest the accuracy of the data; (b) the processing is unlawful and you oppose erasure; (c) we no longer need the data but you need it for legal claims; or (d) you have objected to processing pending verification.

9.5 Right to Data Portability (Article 20)

You have the right to receive your Personal Data in a structured, commonly used, and machine-readable format, and to transmit that data to another controller. The Service provides built-in data export functionality to facilitate this right.

9.6 Right to Object (Article 21)

You have the right to object to the processing of your Personal Data based on legitimate interests or for direct marketing purposes. Where you object to processing for direct marketing, we will cease processing without exception. For objections based on other grounds, we will cease processing unless we demonstrate compelling legitimate grounds that override your interests.

9.7 Right to Withdraw Consent (Article 7(3))

Where processing is based on your consent, you have the right to withdraw that consent at any time. Withdrawal of consent does not affect the lawfulness of processing carried out before the withdrawal. You can withdraw consent by:

9.8 Right Not to Be Subject to Automated Decision-Making (Article 22)

You have the right not to be subject to a decision based solely on automated processing, including profiling, which produces legal effects or similarly significantly affects you. Creative Digital does not currently engage in solely automated decision-making that produces legal or similarly significant effects on individuals.

9.9 Right to Lodge a Complaint

You have the right to lodge a complaint with a supervisory authority if you believe that our processing of your Personal Data violates the GDPR. The lead supervisory authority for Creative Digital BV is:

Autoriteit Persoonsgegevens (Dutch Data Protection Authority)
Bezuidenhoutseweg 30
2594 AV The Hague, the Netherlands
Website: autoriteitpersoonsgegevens.nl
Phone: +31 (0)70 888 85 00

You may also lodge a complaint with the supervisory authority in the EU member state where you reside or work, or where the alleged infringement occurred.

9.10 How to Exercise Your Rights

To exercise any of the rights described above, please contact us at privacy@letworkflow.io. We may need to verify your identity before fulfilling your request. We will respond to your request within thirty (30) days. If the request is complex or we receive a large number of requests, we may extend this period by an additional sixty (60) days, in which case we will notify you of the extension and the reasons for it.

There is no fee for exercising your rights, unless your request is manifestly unfounded or excessive, in which case we may charge a reasonable fee or refuse to act on the request.

10. Additional Rights for United States Residents

10.1 California Residents (CCPA/CPRA)

If you are a California resident, the California Consumer Privacy Act (CCPA) and the California Privacy Rights Act (CPRA) provide you with additional rights regarding your Personal Information:

To exercise your CCPA/CPRA rights, contact us at privacy@letworkflow.io. We will verify your identity and respond within forty-five (45) days.

10.2 Other US State Privacy Laws

Residents of other US states with comprehensive privacy legislation (including Virginia, Colorado, Connecticut, Utah, and others) may have similar rights. Please contact us at privacy@letworkflow.io to exercise any applicable rights under your state's privacy law.

11. Cookies and Tracking Technologies

11.1 What Are Cookies

Cookies are small text files placed on your device when you visit a website. They are widely used to make websites work efficiently and to provide information to website owners.

11.2 Cookies We Use

We use the following categories of cookies:

We do not use advertising or targeting cookies. We do not engage in cross-site tracking or behavioral advertising.

11.3 Managing Your Cookie Preferences

When you first visit our website, you are presented with a cookie consent banner that allows you to accept or reject non-essential cookies. You can change your preferences at any time by:

Please note that disabling certain cookies may affect the functionality of our website.

12. Data Security

Creative Digital implements comprehensive technical and organizational security measures to protect your Personal Data against unauthorized access, alteration, disclosure, destruction, and loss. Our security measures include:

12.1 Technical Measures

12.2 Organizational Measures

While we take extensive measures to protect your data, no method of electronic transmission or storage is completely secure. We cannot guarantee absolute security, but we commit to promptly notifying affected parties and the relevant supervisory authority in the event of a Personal Data breach, as required by the GDPR.

13. Data Breach Notification

In the event of a Personal Data breach, Creative Digital will:

14. Children's Privacy

Our Service is designed for business use and is not intended for children. We do not knowingly collect Personal Data from children under the age of sixteen (16), which is the applicable age of digital consent under the Dutch GDPR Implementation Act. If you are a parent or guardian and believe that your child has provided us with Personal Data, please contact us at privacy@letworkflow.io. If we discover that we have collected Personal Data from a child under 16 without appropriate parental consent, we will take steps to delete that information promptly.

15. Third-Party Links and Services

Our website and Service may contain links to third-party websites, services, or applications that are not operated by Creative Digital. We are not responsible for the privacy practices, content, or security of these third-party sites. We encourage you to review the privacy policies of any third-party services you access through our website or Service. This Privacy Policy applies solely to information collected by Creative Digital through our website and Service.

16. Data Processing Agreement

Where you use our Service to process Personal Data and Creative Digital acts as your Data Processor, the terms of our Data Processing Agreement (DPA) apply in addition to this Privacy Policy. The DPA addresses:

To request a copy of our DPA, please contact legal@letworkflow.io.

17. Changes to This Privacy Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or other factors. When we make changes:

We encourage you to review this Privacy Policy periodically to stay informed about how we protect your data.

18. Contact Us

If you have any questions, concerns, or requests regarding this Privacy Policy or our data processing practices, please contact us:

Creative Digital BV
Attn: Data Protection
Amsterdam, the Netherlands
Chamber of Commerce (KvK): 94498156

We aim to respond to all privacy-related inquiries within thirty (30) days of receipt.