Scope and our roles
This policy applies to WorkIM product services, including applications, web services, the console and the product website. Where you join a workspace created by an enterprise customer, that enterprise generally decides why and how member and workspace data is handled; WorkIM provides services under its agreement and instructions. WorkIM is responsible for processing where it independently decides the purpose, such as account security, service operations and direct support.
Personal data we collect
We may collect or receive account and contact data such as name, phone number, email address and avatar; enterprise workspace data such as organisation, department, role and administrator-assigned information; content and service data that you submit or generate, including messages, files, schedules, approvals, service records and settings; device, network, login and usage logs; data you actively provide or authorise when using a feature, such as camera, microphone, calendar, contacts or location permissions; and information provided to support. We request device permissions only when a feature needs them.
How we use personal data
Where permitted by applicable law, we use personal data to provide, maintain and improve the services; establish and protect accounts; support enterprise workspaces and administrator configuration; provide customer support; detect, prevent and investigate security, abuse, fraud and technical issues; comply with legal obligations; and send communications you have agreed to receive.
Enterprise administrators and service providers
Enterprise customers and their authorised administrators may access, manage, export or delete data connected with their workspace according to its configuration. We may also use hosting, infrastructure, communications, security, support and professional service providers bound by confidentiality and data-protection obligations. We do not sell personal data except that we may disclose it as described here, with your or the enterprise customer’s authorisation, to meet legal obligations, protect rights and safety, or complete a corporate transaction.
International transfers
To provide global services, data may be processed outside Singapore by WorkIM, enterprise customers or contracted service providers. When data is transferred internationally, we take reasonable steps to ensure that the recipient provides a standard of protection comparable to the requirements of Singapore’s Personal Data Protection Act (PDPA), or another protection permitted by applicable law.
Retention and security
We retain data for as long as needed to provide services, meet enterprise-customer instructions, resolve disputes, enforce agreements or meet legal and business-record obligations. Enterprise workspace retention may be controlled by customer settings and our agreement with that customer. We use reasonable administrative, technical and organisational safeguards, including access controls, transport protections, logging and security operations. No system can guarantee absolute security.
Your choices and rights
Where applicable law permits, you may request access to or correction of personal data in WorkIM’s possession or control, and information about how it was used or disclosed in the preceding year. You may withdraw consent with reasonable notice. Withdrawal does not affect prior lawful processing but may affect feature availability. For enterprise workspace data, contact your enterprise customer or administrator first; where appropriate, we will assist in routing the request.
Cookies, notifications and product permissions
The product website uses necessary cookies for basic functionality and handles preference or analytics cookies according to the cookie notice and your choices. You can manage cookies through your browser. App permissions, including notifications, camera, microphone, calendar, contacts and location, are controlled in your device settings. Disabling a permission can prevent the relevant feature from working.
Children, breaches and changes
WorkIM is not directed to children below the minimum age in the User Agreement. If a data breach is likely to result in significant harm or reaches a legally significant scale, we will assess, manage and, where required, notify the relevant authorities and affected individuals under the PDPA and other applicable law. We may update this policy and publish the revised version in the product or website; continued use means acceptance of the updated policy.
For data-protection questions or access and correction requests, contact:
hello@work.im