Zaloguj się
Jeszcze niedostępne w tym językuCzytasz wersję angielską, tłumaczenie jest w trakcie weryfikacji.

Security and compliance

The architecture is the compliance argument

A promise not to look at individual data is a policy. Not holding it is a property of the system. The second is the one a works council, a DPO and an auditor can each verify independently.

Hero illustration — security

What is in place

ISO 27001

Certificate 0202968, held by Workplaced Technologies Ltd, issued via Intertek under UKAS accreditation. Note which entity: a European customer contracts with Workplaced Technologies Europe B.V., registered with the Dutch Chamber of Commerce under KvK 95622462. Tenders ask for certification of the contracting party, so the scope statement and the relationship between the two entities belong in the tender response — ask and you get both.

Aggregation by design

Measurement is aggregated at collection, not filtered at reporting. Groups below a minimum size are not reported at all.

Data processing agreement

A DPA that describes the architecture the product implements, rather than a broader permission the product happens not to use.

EU hosting

Data stays within the EU. Sub-processors are listed in the DPA and changes are notified.

Access control

Role-based access with no permission level that exposes an individual's behavioural record, because that record is not created.

Retention

Retention periods set per study and stated before collection, which is both the legal requirement and what keeps participation rates up.

Four documents, on request

The ISO 27001 certificate and scope statement, the data processing agreement, the current sub-processor list and the most recent penetration test summary.

They are handed over under confidentiality rather than published, because a sub-processor list and a pen-test summary are a map for anyone who wants one. Ask and you have them within two working days; you do not need to be in a procurement process.

For your works council and your DPIA

Measurement is aggregated at collection, not filtered at reporting. Below a minimum group size — set before the study starts and written into the processing agreement — a group is not reported at all. There is no permission level that unlocks it, because the underlying record was never created.

That is a schema property rather than a setting: ask for the data model in your DPIA and it is checkable before you sign. There is a briefing note written for exactly this meeting on the trust page, and it is yours to forward without rewriting it.

Questions we get asked

  • Do you collect personal data?

    It depends on the product, and the architecture reports patterns rather than people by design. That is a decision taken before the first sensor, not a policy added after a works council asked.

    What is processed, on what basis, who may see it and how long it is kept is settled per project before implementation, and written down.

  • Is Wi-Fi occupancy data anonymous?

    We describe it as aggregated, which is the honest word. It produces utilisation at building, floor and zone level and is not a tool for observing an individual.

    How far that goes depends on the network, the configuration and the contract, so the answer for your building is the one in your agreement rather than the one on this page.

  • What security documentation is available?

    Workplaced Technologies Ltd holds ISO 27001 certificate 0202968, via Intertek under UKAS.

    The certificate, the sub-processor list, the standard data processing agreement and the penetration test summary are handed over after contracting, under confidentiality. They exist and they are current; they are not published on the open web.

  • Who owns the data?

    That is settled in the agreement between you, Workplaced and any partner involved, along with access, permitted use and retention. It is a contractual question and a website is the wrong place to answer it in general terms.

All questions

Send us the questionnaire

Security questionnaires, DPIAs and tender annexes go straight to the person who owns the documentation. Say so in the message and skip the routing.