Privacy Policy
This is how WorkSense collects, uses, stores and protects your personal data — and what rights you have over it.
Effective: 18 September 2026 · Last updated: 18 September 2026
1. Who we are
WorkSense is a revenue-performance consultancy operating in the United Kingdom. In UK GDPR terms, WorkSense is the data controller for any personal data collected through this website (worksenseconsulting.co.uk and any preview/staging subdomains).
For all data-protection questions, contact us at nicr_999@hotmail.com.
Note on entity: WorkSense is currently a trading name. We will update this policy with our registered operating entity, trading address, and (where applicable) ICO registration number as they are finalised.
2. What we collect
We only collect what you actively give us via our forms. We do not track you across the web, we don't set advertising cookies, and we don't use analytics scripts that identify individuals.
| Where | Data |
|---|---|
| Contact form | Your name, company, email, phone (optional), how you heard of us, and your enquiry message. |
| Free Health Check (self-serve audit) | Your name, business name, email, industry, company size, business description, your answers to the 20 diagnostic questions, and a timestamp of your consent. |
| Consultant-led audit | The same fields as above, entered by a WorkSense consultant during a consulting session with you. |
| Server logs | Your IP address and browser type are logged temporarily by our hosting provider (Netlify) for security and abuse prevention. These logs are automatically discarded on Netlify's schedule. |
3. Why we collect it — and our lawful basis
We only use your data for these purposes:
- To reply to your enquiry — if you use the contact form.
- To give you your audit result — if you complete the Free Health Check.
- To follow up with a short conversation about the audit findings and how we might help — only if you've asked for it or ticked the consent box.
- To operate and secure the site — e.g. rate-limiting abusive traffic.
Our lawful basis under UK GDPR Article 6 is your consent (Art 6(1)(a)), which you give by ticking the consent box on the relevant form. For server-log data collected for security purposes, we rely on legitimate interests (Art 6(1)(f)) — namely, protecting the site from abuse.
We do not sell your data. We do not use it for automated decisions or profiling that has legal or similarly significant effects on you.
4. Who we share it with
Your data is stored and processed by two third parties acting as our data processors:
| Processor | What they do | Where |
|---|---|---|
| Notion Labs, Inc. | Stores audit submissions in our WorkSense Audits database. | United States |
| Netlify, Inc. | Hosts the website and runs the serverless function that saves audit data to Notion. | United States (edge cache: global) |
Both have signed data-processing agreements with us and follow strict security standards. Neither uses your data for their own purposes.
We do not share your data with any other third party, unless we're legally required to (e.g. by a court order).
5. International transfers
Notion and Netlify are US-based. Under UK GDPR, transfers to the US are permitted via the UK-US Data Bridge (a UK-recognised extension of the EU-US Data Privacy Framework). Both processors have committed to this framework. Additional contractual safeguards (Standard Contractual Clauses) are in place via their processor agreements as a backstop.
6. How long we keep it
| Data type | Retention period |
|---|---|
| Contact form enquiries | 12 months from the date of enquiry, unless you become a customer (in which case it becomes part of our client records — see below). |
| Audit submissions | 24 months from the date of submission. |
| Client engagement records | 6 years after the end of the engagement (required for UK tax and accounting obligations). |
| Server logs | Automatically discarded by Netlify on their rolling schedule (typically 30 days). |
At the end of the retention period, we delete the record from Notion. You can ask us to delete it sooner — see "Your rights" below.
7. Your rights
Under UK GDPR you have the right to:
- Access — request a copy of the personal data we hold about you.
- Rectification — ask us to correct anything inaccurate.
- Erasure — ask us to delete your data (subject to our legal record-keeping obligations for existing clients).
- Restriction — ask us to pause processing while you contest accuracy or object.
- Portability — get your data in a machine-readable format so you can move it elsewhere.
- Object — object to us processing your data for legitimate-interest purposes.
- Withdraw consent — where we rely on consent, you can withdraw it at any time. Withdrawal doesn't affect the lawfulness of processing before withdrawal.
- Not be subject to automated decisions — we don't make significant decisions about you by automated means.
8. How to exercise your rights
Email us at nicr_999@hotmail.com with the subject line "Data request — [your request type]". We will respond within one calendar month, in line with our UK GDPR obligation. There is no charge for reasonable requests.
To help us find your record quickly, please tell us the email address you originally used and roughly when you contacted us.
9. Cookies and similar technologies
We do not use tracking cookies, advertising cookies, or third-party analytics scripts that identify individual visitors. There is no cookie banner because there is nothing to consent to.
Our hosting provider (Netlify) may set a strictly necessary session cookie to enforce security policies. Under PECR, strictly-necessary cookies do not require consent.
Our booking widget (Calendly, loaded only when you click "Book a call") sets its own cookies when active. If you use that widget you will be subject to Calendly's own privacy policy.
10. Security
We take reasonable technical and organisational measures to protect your data:
- HTTPS everywhere (HSTS enforced)
- Content-Security-Policy, X-Frame-Options and other browser-level security headers
- Rate-limiting on our data-submission endpoint
- Origin restrictions and CORS controls on our serverless functions
- API tokens stored as environment variables, never in code
- All third-party processors (Notion, Netlify) audited to SOC 2 or equivalent standards
No system is 100% secure. If a data incident occurs that presents a risk to you, we will notify you and the ICO within 72 hours as required by UK GDPR.
11. Changes to this policy
We will update this policy when our practices change. Material changes will be communicated to existing customers by email; the "Last updated" date at the top will always reflect the most recent revision.
12. Complaints
If you're unhappy with how we've handled your data, please contact us first at nicr_999@hotmail.com — we'd like the chance to put it right.
You also have the right to complain to the UK's data-protection regulator, the Information Commissioner's Office:
Information Commissioner's Office
Wycliffe House, Water Lane, Wilmslow, Cheshire SK9 5AF
Helpline: 0303 123 1113 · ico.org.uk/make-a-complaint
13. Contact
WorkSense
Email: nicr_999@hotmail.com
Country: United Kingdom