Privacy Policy
Last updated: June 2026
Introduction
At Workkeeping, we take your privacy seriously. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our service.
Information We Collect
We collect information that you provide directly to us, including:
- Account information (name, email, company name)
- Usage data (jobs created, time entries logged)
- Technical data (IP address, browser type, device information)
How We Use Your Information
We use the information we collect to provide, maintain, and improve our services, to communicate with you, and to comply with legal obligations.
Data Protection
We implement appropriate technical and organisational measures to protect your personal data against unauthorised access, alteration, disclosure, or destruction.
Opt out of marketing analytics
Under Article 21(1) of the GDPR you have the right to object to the processing of your personal data carried out under our legitimate interest. The Data Protection Commission (DPC) oversees GDPR enforcement in Ireland. Clicking the button below records your objection in a signed browser cookie (1-year lifetime).
This opt-out is separate from the cookie banner. Even if you declined analytics cookies, we still count your visits aggregately; clicking the button below stops that too.
After opting out, our site will no longer count or track your visits. The opt-out is honoured before any consent, bot, or authentication check in our tracking pipeline.
Sub-processors
In addition to our own infrastructure we rely on a small set of sub-processors for operational purposes:
- Cloudflare — we use Cloudflare as a CDN and DDoS-protection layer. Cloudflare infers a country code (ISO 3166-1 alpha-2) from the visitor IP and passes it as the `CF-IPCountry` request header. We store only the 2-letter country code, never the IP.
- Rate limiting — we apply a per-IP request limit (60 requests per minute) on our marketing pages as a defence against abuse. This limit may occasionally affect visitors sharing an IP (office, school, or carrier-grade NAT egress); when triggered it returns an HTTP 429 response with a `Retry-After` header.
AI assistant access (MCP)
If you connect an AI assistant to Workkeeping through the Model Context Protocol (MCP), it can read and write your firm's data on your behalf. Access is always bounded and revocable.
- Access is limited to the single firm you consent to, your membership within it, and the specific OAuth scopes you grant. Read-only by default; write access requires explicit consent.
- Through an AI assistant, the data accessed covers your firm's clients and contacts, jobs, tasks, time entries, documents, and the statistics derived from them. No payment card data, government identifiers, or login credentials are ever exposed.
- Every AI action is recorded in an audit log retained for 180 days.
- We store only a SHA-256 digest of request parameters, never the raw parameters you or the assistant send.
- Results are returned to the third-party AI client you chose to connect. That client's own privacy terms govern what it does with the data it receives.
- You can revoke any AI connection at any time via Settings → Integrations → AI Assistants. Revocation takes effect immediately and stops future access (it does not erase past audit records).
Cookies
We use cookies and similar technologies to provide functionality and to understand how you use our service. You can control cookies through your browser settings.
| Cookie name | Category | Purpose | Duration |
|---|---|---|---|
| _workkeeping_session | Essential | Maintains your login session | Session |
| cookie_consent | Essential | Stores your cookie consent choices | 180 days |
| locale | Essential | Remembers your preferred language | 1 year |
| theme | Essential | Remembers your dark/light theme preference | 1 year |
| visitor_uuid | Analytics | Anonymous identifier for site usage analytics | 1 year |
| marketing_opt_out | Essential | Honours your opt-out from marketing analytics | 1 year |
You can change your choices at any time via our cookie preferences.
Contact Us
If you have questions about this Privacy Policy, please contact us at [email protected]