Privacy Policy
Last updated: August 16, 2026
1. Introduction
This policy explains what workroom collects, why, who we share it with, and what choices you have. It applies to workroom.one, app.workroom.one, the websites we host on onworkroom.one and connected custom domains, our APIs and MCP server, and every related feature (the "Service").
workroom is business software provided over the internet on a subscription basis. It is operated by Hyperleap Software Technologies Private Limited, registered at T-Hub, Phase 2, Madhapur, Hyderabad, Telangana 500081, India.
We will update this policy as our practices change, and will note the date above. For material changes we will notify workspace owners by email or in the product.
2. Who the controller is
- Hyperleap Software Technologies Private Limited (India) is the controller for platform usage, your business content, and service delivery.
- Hyperleap AI Hub Inc. (United States), 8 The Green, Dover, DE 19901, may act as controller for account administration and billing for US customers.
- Paddle.com Market Ltd. is the merchant of record for purchases and is an independent controller of the payment data it collects.
- For visitor data captured on a website built with workroom, the customer who owns that site is the controller and we act as their processor. See section 6.
Enterprise agreements may name a different contracting entity; the agreement governs if so.
3. Information we collect
Account information. Your name, email address, workspace name, role, and authentication details. Sign-in is handled by Clerk; we receive an identifier and profile basics, not your password.
Business content. The descriptions, page text, images, brand assets, verified facts, tone-of-voice settings, uploaded files, and configuration you provide so we can build your site and run routines.
Connected account data. If you connect a third-party service (Google Search Console, Google Analytics, Google Ads, Gmail, Meta/Facebook/Instagram, Bing Webmaster Tools, GitHub, Slack), we store the access and refresh tokens needed to act on your behalf and the data returned within the scopes you grant — for example search performance metrics, ad results, or the drafts we prepare for your approval. You can disconnect any service at any time.
Leads and contacts in your workspace. The enquiries submitted on your site, the contact records built from them, and the AI assessments and follow-up drafts derived from that activity.
Billing information. Plan, subscription status, credit balance, transaction history, and the country and tax status used for invoicing. Card details go directly to Paddle; we never see or store them.
Usage and device data. Pages and features used, actions taken, timestamps, IP address, browser and device type, referring page, and diagnostic logs and error reports.
Communications. Messages you send us by email, in-product chat, or forms, and our replies.
Cookies and similar technologies. See section 10.
We do not deliberately collect special-category data (health, biometrics, political or religious views) and ask that you do not put it into the Service.
4. How we use information, and our legal bases
| Purpose | Legal basis (GDPR) |
|---|---|
| Provide the Service: build and host your site, run routines, capture leads | Performance of a contract |
| Authenticate you and secure accounts | Contract; legitimate interests (security) |
| Process payments, invoices, and tax | Contract; legal obligation |
| Support you and answer your messages | Contract; legitimate interests |
| Monitor, debug, and improve reliability and performance | Legitimate interests |
| Develop and improve product features using aggregated or de-identified usage data | Legitimate interests |
| Send service and security notices | Contract; legal obligation |
| Send product marketing to business contacts | Legitimate interests, or consent where required — opt out any time |
| Prevent fraud, abuse, and prohibited use; enforce our Terms | Legitimate interests; legal obligation |
| Comply with law and respond to lawful requests | Legal obligation |
Where we rely on legitimate interests, we have assessed that our interest does not override your rights, and you may object as described in section 8.
5. How we use AI
We use AI providers — currently Anthropic and Google — to generate websites, content drafts, reports, and analyses from your business content, connected-account data, and workspace activity.
- Drafts that face the outside world are only published or sent after the account owner approves them.
- We do not use your business content, your leads, or your visitors' data to train our own foundation models.
- Our AI providers process this data as our sub-processors under agreements that prohibit using it to train their models.
6. Visitor data on websites we host
Websites built with workroom capture pageviews and form submissions on behalf of the business that owns the site. That business decides what to collect and why; it is the controller, and workroom processes the data on its instructions to provide lead capture, analytics, chatbot answers, and follow-up features.
If you submitted your details on a website built with workroom and want to access, correct, or delete them, contact the business that operates that site. If you contact us instead, we will pass the request on and help that business respond. We do not sell visitor data, and we do not use it for cross-site advertising.
7. When we share information
We share information only in these circumstances:
- Sub-processors who run the Service for us (section 9), under contracts that restrict them to our instructions.
- Paddle, so it can process your purchase, invoice you, and handle tax as merchant of record.
- Third-party services you connect, and only within the scopes you granted.
- Professional advisers (lawyers, accountants, auditors) bound by confidentiality.
- Legal and safety: where required by law, court order, or a valid request from a public authority, or where necessary to investigate fraud or protect the rights and safety of users, the public, or us.
- Corporate transactions: in a merger, acquisition, financing, or sale of assets, subject to this policy continuing to apply.
We do not sell your personal information, and we do not share it for cross-context behavioural advertising.
8. Your rights
Subject to your local law, you may:
- access the personal data we hold about you and get a copy;
- correct data that is inaccurate or incomplete;
- delete your data ("right to be forgotten");
- restrict or object to processing, including profiling and direct marketing;
- port your data to another provider in a structured, machine-readable format;
- withdraw consent at any time, without affecting processing already carried out;
- not be subject to a decision based solely on automated processing that has legal or similarly significant effects — we do not make such decisions.
Much of this is self-service: you can edit your profile, export leads and content, disconnect integrations, and delete sites or your whole workspace from the dashboard.
EEA and UK residents may lodge a complaint with their supervisory authority. California residents have the rights to know, delete, correct, and opt out of sale or sharing under the CCPA/CPRA — we do not sell or share personal information as those terms are defined — and will not discriminate against you for exercising them. Indian residents have the rights of a Data Principal under the Digital Personal Data Protection Act, 2023, including access, correction, erasure, nomination, and grievance redressal.
To exercise a right, email [email protected] from the address on your account. We respond within 30 days, or sooner where the law requires, and may ask for information to verify your identity. Requests are free unless they are manifestly unfounded or excessive.
9. Sub-processors
We use a small set of providers to run the Service, including:
- Vercel and Cloudflare — application hosting, edge delivery, DNS, and SSL
- Supabase — primary database and storage
- Clerk — authentication and user management
- Paddle — payments, invoicing, and tax as merchant of record
- Anthropic and Google — AI model inference and embeddings
- PostHog — product analytics
- MillionVerifier — email verification for prospect research
We require each to protect personal data to a standard at least as strong as this policy. An up-to-date list, and notice of changes, is available on request from [email protected].
10. Cookies
We use cookies and similar technologies in three categories:
- Necessary — sign-in sessions, security, and load balancing. These are set without consent because the Service cannot work without them.
- Analytics — how the product is used, so we can improve it.
- Marketing — measuring the effectiveness of our own campaigns.
Analytics and marketing cookies are set only with your consent where the law requires it, and you can change your choice at any time. Most browsers also let you block or delete cookies; blocking necessary cookies will break sign-in.
Websites built with workroom set a first-party cookie or identifier to attribute pageviews and enquiries for the business that owns the site. That business controls its own cookie notice.
11. International transfers
We are based in India and use providers located in India, the United States, and the European Economic Area, so your information may be transferred to and processed in countries other than your own.
Where we transfer personal data out of the EEA or the UK, we rely on the European Commission's Standard Contractual Clauses (with the UK Addendum where applicable) together with encryption in transit and at rest and access controls. You can request a copy of the relevant clauses from [email protected].
12. Security
We use technical and organisational measures appropriate to the risk: encryption in transit and at rest, tenant isolation (a request can only ever reach the workspace it belongs to), scoped API keys, least-privilege access for our staff, audit logging, and regular dependency and infrastructure patching. Generated customer sites are served from separate origins from the application so site content can never read application credentials.
No system is perfectly secure, and transmission over the internet is never risk-free. Keep your credentials and API keys confidential and tell us at [email protected] if you suspect a compromise. Where a breach is likely to result in a risk to your rights, we will notify you and the relevant regulator within the time limits the law sets.
13. Retention
We keep personal data only as long as we need it:
- Account and workspace data — for the life of the account, then deleted within 30 days of workspace deletion (personal data within 90 days).
- Leads and contacts — until you delete them or delete the workspace.
- Billing and tax records — as long as tax and accounting law requires, typically seven years.
- Security and diagnostic logs — usually up to 12 months.
- Backups — purged on their normal rotation schedule after deletion from production.
We may keep aggregated or de-identified data that cannot reasonably be linked to you.
14. Children
The Service is for business use and is not directed at anyone under 18. We do not knowingly collect personal data from children. If you believe a child has provided us data, write to [email protected] and we will delete it.
15. Third-party websites
The Service links to sites we do not control, including our customers' published websites and third-party integrations. This policy does not apply to them, and we are not responsible for their practices. Read their policies before providing information.
16. Governing law
This policy is governed by the laws of India, without regard to conflict-of-laws rules, and the courts of Hyderabad, Telangana have exclusive jurisdiction — without removing any right you have to bring a claim or complain to a regulator where you live.
17. Contact
- Privacy, data requests, and grievances: [email protected]
- Support: [email protected]
- India (registered office): Hyperleap Software Technologies Private Limited, T-Hub, Phase 2, Madhapur, Hyderabad, Telangana 500081, India
- United States: Hyperleap AI Hub Inc., 8 The Green, Dover, DE 19901, United States