1. Introduction
This Privacy Policy explains how Worqen OÜ, a private limited company incorporated in Estonia (registry code [REGISTRATION NUMBER], registered address [REGISTERED ADDRESS], Tallinn, Estonia) ("Worqen", "we", "us"), collects, uses, shares and protects personal data when you use the Worqen marketplace, mobile applications, smart contracts and APIs (the "Service").
We are the data controller for personal data we process about Users. This Policy applies in addition to the EU General Data Protection Regulation (GDPR), the Ukrainian Law on Personal Data Protection, the Brazilian Lei Geral de Proteção de Dados (LGPD), the Indian Digital Personal Data Protection Act 2023 (DPDP), and other applicable local laws — see Section 13 for region-specific rights.
2. Data Protection Officer and Contact
Privacy queries, requests to exercise your rights, and complaints can be addressed to our Data Protection Officer at dpo@worqen.com or by post to Worqen OÜ — DPO, [REGISTERED ADDRESS], Tallinn, Estonia.
3. Personal Data We Collect
| Category | Examples | Source |
|---|---|---|
| Identification | Email, password (hashed), name, username, avatar | You, at registration |
| Profile | Bio, professional title, hourly rate, availability, skills, education, employment history, certifications, languages, portfolio entries, video introduction, linked social accounts (LinkedIn / GitHub) | You |
| KYC and identity verification | Legal name, date of birth, nationality, address, government-issued ID document image, proof of address, selfie / facial biometrics, verification status | You, via our processor Sumsub |
| Geolocation | City, country, timezone; precise latitude/longitude when you opt in to job-radius matching | You; your device (with permission) |
| Communications | Chat messages, dispute messages, attachments, reactions, read receipts | You |
| Transactions and wallets | Solana wallet addresses, escrow records, transaction signatures, USD/SOL amounts, commission, Worqs balance and history | You; the Solana blockchain |
| Technical | IP address, approximate location derived from IP, browser, device, operating system, language, referrer, session identifiers, timestamps, error logs | Automatically |
| Cookies / similar | See our Cookie Policy | Automatically, with your consent where required |
Sensitive data: KYC processing involves biometric data (selfie matched to an ID document) and government-issued identifiers. We process this category of data only with your explicit consent and on the basis of compliance with our legal obligations under anti-money-laundering and counter-terrorist-financing law.
4. Purposes and Lawful Bases
| Purpose | Lawful basis (GDPR Art. 6) |
|---|---|
| Creating and managing your account | Performance of a contract |
| Identity verification, sanctions/PEP screening, fraud prevention and AML/CTF compliance | Legal obligation; legitimate interest in fraud prevention |
| Matching Workers and Employers; powering search and discovery | Performance of a contract; legitimate interest |
| Operating chat, notifications and dispute resolution | Performance of a contract |
| Processing escrow deposits, releases and commission | Performance of a contract |
| Geolocation for radius-based job matching | Consent (you can withdraw at any time) |
| Sending transactional emails (verification, password reset, escrow updates) | Performance of a contract |
| Sending marketing communications (newsletters, feature announcements, promotions) | Consent — opt-in; you can opt out at any time |
| Product analytics and A/B testing (when enabled) | Consent (analytics cookies) |
| Securing the Service, detecting abuse, protecting Users | Legitimate interest; legal obligation |
| Screening the content of communications and shared content for spam, abuse, fraud, sanctioned activity and illegal material — using targeted detection tools (including automated and AI-assisted tools) and acting on reports, and detecting and reporting child sexual abuse material where legally required | Legitimate interest in User safety and the prevention of abuse and fraud; legal obligation (detection and reporting of illegal content) |
| Defending legal claims, complying with court orders and lawful requests | Legal obligation; legitimate interest |
Content safety and moderation. We do not generally monitor or pre-moderate your listings, profiles or messages. To keep the Service safe, however, we use targeted detection tools — including automated and AI-assisted tools — to screen communications and shared content for spam, abuse, fraud, sanctioned activity and illegal material, and we act on reports we receive through in-app reporting and trusted-flagger channels. Where the law requires it, this includes detecting and reporting child sexual abuse material to the competent authorities. Our lawful basis is our legitimate interest in protecting Users and preventing abuse and fraud and, for the detection and reporting of illegal content, compliance with a legal obligation. Any resulting adverse decision about your account is reviewed by a person before it takes effect — we do not take such decisions by solely automated means. See our Acceptable Use Policy, our Digital Services Act information and our AI Use Policy for how content moderation and our internal AI tools work.
5. Service Providers and Recipients
We share personal data only with the following categories of recipients, each under written data-processing terms where applicable:
- Sumsub (Sum and Substance Ltd, UK) — KYC and identity verification. Receives ID documents, selfies, biometrics, name, DOB, address.
- Mailgun (Sinch / Mailgun Technologies, USA) — transactional and marketing email delivery. Receives email address and email content.
- Object storage provider (S3-compatible) — file storage for avatars, job photos, CVs and message attachments. Files are stored under URLs that can be guessed only with knowledge of the upload key.
- Sentry (Functional Software, Inc., USA) — error monitoring. Receives stack traces, request metadata and a pseudonymous user identifier.
- Solana RPC providers — used to broadcast and read on-chain transactions. Receives wallet addresses and transaction data (which is, by design, public on the blockchain).
- Hosting and infrastructure providers — operate the servers that run the Service.
- Professional advisers — lawyers, auditors, accountants, on a confidential basis as needed.
- Authorities — courts, law-enforcement and regulators, where we are legally required to disclose data.
- Buyers and successors — in the event of a merger, acquisition, reorganisation or insolvency, subject to appropriate confidentiality obligations.
Public profile. Information you choose to put on your public profile, listings or reviews is visible to other Users and, where listings are public, to anyone on the internet.
On-chain data. Transactions you sign with your Solana wallet — including wallet addresses, amounts, escrow program interactions and timestamps — are recorded on a public blockchain. We cannot delete or alter on-chain data. You should not transact on- chain with information you wish to remain private.
6. International Data Transfers
Worqen is established in the European Economic Area. Some of our service providers (such as Mailgun, Sentry) are established outside the EEA, primarily in the United States. To protect your data when it is transferred outside the EEA, the United Kingdom, Brazil or India, we rely on:
- European Commission adequacy decisions where available;
- EU Standard Contractual Clauses (SCCs) and the UK International Data Transfer Addendum;
- Supplementary measures, including encryption in transit and at rest where appropriate;
- For Brazil, ANPD-approved contractual safeguards under LGPD; for India, the notifications issued under the DPDP Act in respect of cross-border transfer.
You can request a copy of the safeguards in place by contacting our DPO.
7. Retention
| Data | Retention period |
|---|---|
| Account data while account is active | Until you delete the account |
| Account data after deletion | Anonymised within 30 days, except as below |
| Chat messages | 2 years after the last activity in the chat |
| Dispute records | 7 years (tax, audit and limitation periods) |
| KYC: ID-document image, selfie, biometric template (held by Sumsub) | 30 days from verification decision, then deleted |
| KYC: verification result, applicant ID, decision metadata, sanctions screening outcome | 5 years from the end of the business relationship (AML) |
| Server logs (security, error monitoring) | 30 days |
| Escrow transaction records | Permanent (also recorded on the public Solana blockchain) |
| Marketing-consent records | Until consent is withdrawn + 3 years (proof of consent) |
What anonymisation means. When we anonymise account data, we irreversibly strip or one-way hash the direct identifiers that link that data to you — such as your name, email address, username, avatar and profile details — so that the remaining data can no longer be attributed to you, whether by us or, using means reasonably likely to be used, by anyone else. Once data is anonymised it is no longer personal data, and we may retain it in aggregate or de-identified form for statistical, security and product-improvement purposes.
No re-identification. We do not attempt to re-identify data that has been anonymised, and we require our service providers not to do so, except to verify that the anonymisation process is working as intended or where we are required to re-identify data by law.
On-chain and legally-retained data. Anonymisation applies to off-chain account data only. Information recorded on the public Solana blockchain — wallet addresses, escrow interactions, transaction signatures and amounts — is permanent and public by design and cannot be anonymised, altered or deleted by us or anyone else (see the "On-chain data" note in Section 5 and the "Escrow transaction records" row above). Data we must keep for anti-money-laundering, tax, audit or the establishment, exercise or defence of legal claims is likewise retained in identifiable form for the periods set out above rather than anonymised.
8. Security
We use technical and organisational measures designed to protect personal data against accidental or unlawful destruction, loss, alteration or unauthorised access. These include TLS encryption in transit, encryption of sensitive credentials at rest (AES-256/Fernet), role-based access control, audit logging, multi-factor authentication for our staff, vendor due diligence, and a documented incident response plan.
No system is perfectly secure. You are responsible for keeping your account credentials and any self-custodial wallet keys safe. If you suspect your account or wallet has been compromised, contact us immediately at security@worqen.com.
9. Breach Notification
If a personal data breach is likely to result in a risk to your rights and freedoms, we will notify the competent supervisory authority within 72 hours where required, and we will inform affected Users without undue delay where the breach is likely to result in a high risk to those Users.
10. Your Rights
Subject to local law, you have the right to:
- access the personal data we hold about you and obtain a copy;
- have inaccurate or incomplete data corrected;
- have your data deleted, subject to retention required for AML, tax, audit, on-chain immutability and the establishment, exercise or defence of legal claims;
- receive your data in a portable, machine-readable format and request transmission to another controller where technically feasible;
- restrict or object to processing, including processing based on legitimate interest and direct marketing;
- withdraw consent at any time without affecting the lawfulness of processing carried out before withdrawal;
- not be subject to a decision based solely on automated processing that produces legal or similarly significant effects on you (we do not currently engage in such automated decision-making);
- lodge a complaint with a supervisory authority (see Section 13).
To exercise any of these rights, contact our DPO at dpo@worqen.com. We will respond within one month and without undue delay; the period may be extended by two further months where the request is complex or numerous.
Free of charge. Exercising these rights is free of charge. Where a request is manifestly unfounded or excessive, in particular because of its repetitive character, we may either charge a reasonable fee reflecting the administrative cost of responding, or refuse to act on the request. If we do, we will tell you why, and you can complain to a supervisory authority (see Section 13) or seek a judicial remedy.
Confirming your identity. Where we have reasonable doubts about the identity of the person making a request, we may ask for additional information to confirm it before we disclose, correct or delete any data. This protects you: a request can unlock KYC records, biometric data and wallet information, and we will not release or erase that data for anyone who cannot show that the account is theirs.
Deleting your account yourself. You can delete your account at any time from your account settings, without contacting us. Deletion is subject to the retention and on- chain-immutability limits described in the list above and in Section 7; see our Terms of Service for details.
11. Children
The Service is intended for users 18 years and older, or 16 and older with verifiable parental consent where local law permits. We do not knowingly collect personal data from younger children. If you believe a child has provided us with personal data, please contact us and we will delete it.
12. Cookies and Similar Technologies
See our Cookie Policy for full details. You can manage cookie preferences at any time through the cookie banner or your browser settings.
13. Region-Specific Information
13.1 European Economic Area, United Kingdom and Switzerland
The lead supervisory authority for cross-border processing is the Estonian Data Protection Inspectorate (Andmekaitse Inspektsioon) aki.ee. You may also lodge a complaint with the supervisory authority of your habitual residence or place of alleged infringement. UK users may complain to the Information Commissioner's Office (ICO) ico.org.uk.
13.2 Ukraine
Processing complies with the Law of Ukraine "On Personal Data Protection". Complaints may be made to the Ukrainian Parliament Commissioner for Human Rights (Verkhovna Rada Commissioner) at ombudsman.gov.ua.
13.3 Brazil
Processing complies with the Lei Geral de Proteção de Dados (Law No. 13.709/2018). The national authority is the Autoridade Nacional de Proteção de Dados (ANPD) gov.br/anpd. Brazilian Users have the rights of confirmation, access, correction, anonymisation, blocking, deletion, portability, information about sharing, withdrawal of consent and review of automated decisions, in addition to the rights set out in Section 10.
13.4 India
Processing complies with the Digital Personal Data Protection Act 2023. Indian Data Principals have rights to access, correction, completion, updating, erasure of personal data, and grievance redressal. Grievances should first be raised with our DPO at dpo@worqen.com; you may then escalate to the Data Protection Board of India established under the DPDP Act.
13.5 United States
This sub-section applies to residents of United States states that have comprehensive privacy laws (such as California under the CCPA/CPRA), and only where and to the extent those laws apply to Worqen. Where they apply, you have the right to know what personal data we collect and how we use and disclose it, to request a copy, to have inaccurate data corrected, and to request deletion — subject to the same anti-money-laundering, tax, audit, on-chain immutability and legal-claim exceptions described in Section 10.
We do not sell your personal data, and we do not share it for cross-context behavioural advertising, as those terms are defined under United States state privacy law. We do not use advertising cookies, analytics run only with your consent (see our Cookie Policy), and we have not sold or shared personal data in the preceding twelve months.
Sensitive personal information. The government-issued identifiers and facial biometrics collected during identity verification (see Section 3) are used only to confirm your identity and to meet our anti-money-laundering and counter-terrorist-financing obligations. We do not use this data to infer characteristics about you, and we do not sell or share it. You may ask us to limit its use to these purposes at any time.
We will not discriminate against you for exercising any of these rights. To make a request, contact our DPO at dpo@worqen.com; we will verify your request against the information we hold and respond within the time limits set by applicable law, and you may use an authorised agent where the law permits. Because we honour the Global Privacy Control (GPC) browser signal where applicable (see our Cookie Policy), enabling GPC communicates your opt-out preference to us automatically.
13.6 UK and Brazil Representatives
Worqen is established in the European Economic Area, so under the EU GDPR we are not required to appoint an Article 27 representative in the EEA. Because we offer the Service to data subjects in the United Kingdom without being established there, Article 27 of the UK GDPR requires us to designate a UK representative. In accordance with that requirement we have appointed [UK REPRESENTATIVE] as our representative in the United Kingdom. UK Users and the Information Commissioner's Office (ICO) may contact the representative on UK data-protection matters at [UK REPRESENTATIVE ADDRESS], in addition to contacting our Data Protection Officer at dpo@worqen.com. The UK representative is a separate role from, and does not replace, our Data Protection Officer, and appointing one does not affect your right to complain to the ICO (see Section 13.1).
For Brazil, our Data Protection Officer (encarregado) at dpo@worqen.com acts as the point of contact for Brazilian Users and the Autoridade Nacional de Proteção de Dados (ANPD). Where the LGPD or ANPD guidance requires us to appoint a representative established in Brazil, we will designate one and update this Policy with their details.
14. Changes to this Policy
We may update this Policy from time to time. If changes are material, we will provide notice in the Service and, where appropriate, by email at least 14 days before the changes take effect.
15. How to Contact Us
Worqen OÜ — Tallinn, Estonia
Data Protection Officer: dpo@worqen.com
General privacy enquiries: privacy@worqen.com
Postal address: [REGISTERED ADDRESS], Tallinn, Estonia