Skip to content
FuzeWork
HomeGuidesHow it works
HomeGuidesHow it worksContact
FuzeWork · Version 2026-01

Personal Data Processing Notice

How FuzeWork and your company handle personal and work data.

Version
2026-01
Effective from
13 August 2026
Last updated
13 August 2026
LEGAL REVIEW

Draft for legal and operational review

The structure follows common SaaS terms and GDPR transparency requirements. Before use in the app, the operator must add its legal identity, contacts, governing law, exact retention periods and processor list, and obtain review by a qualified lawyer.

Contents

1. Who is responsible for processing2. Data that may be processed3. Purposes and legal bases4. Sources5. Camera, photos and location6. Recipients and service providers7. Transfers outside the EEA8. Retention9. Security10. Individual rights11. Consent in employment12. Automated decision-making13. Children14. Changes and versions15. Controller, DPO and contact16. Sources used for this draft
Current wording →

1. Who is responsible for processing

For work data placed in a company workspace, your company or employer is normally the controller: it decides why data is used, who may access it and how long it is retained. The FuzeWork operator processes that data as a processor on the company’s instructions.

For data needed to operate its own accounts, secure the service, invoice, provide support and meet legal duties, the FuzeWork operator may be an independent controller. Its exact legal identity must be added in section 15 before publication.

2. Data that may be processed

  • identity and contact data, account UID, company, role, language and settings;
  • team and project assignments, permissions and join requests;
  • check-ins, checkouts, work intervals, corrections, comments and audit records;
  • photos, captions, file metadata and location where enabled and permitted;
  • quality issues, status, comments, photos and linked attendance adjustments;
  • receipts, expenses, attachments and optional automated extraction results;
  • technical and security data, device type, app version, diagnostics and error records;
  • version, time, source and state of consent or acknowledgement.

3. Purposes and legal bases

  • account and requested functions: performance of a contract or pre-contract steps;
  • attendance and workforce/project management: the company determines the basis, typically employment contract, legal obligation or legitimate interests;
  • security, abuse prevention, audit and stability: legitimate interests or legal obligation;
  • billing, accounting and legal claims: contract and legal obligations;
  • optional marketing: separate, withdrawable consent;
  • camera, library and location: device permission enables technical access; the company must determine the legal basis for workplace use.

4. Sources

Data comes from the user, company administrators and team leads, device functions, work records created in the service and automatic technical operation. The company may add or correct information within its permissions.

5. Camera, photos and location

Camera and photo-library access occurs only after a user action or project rule and system permission. Location is processed only for a function that requires it and within the device permission. Disabling permission may limit that function without disabling unrelated features.

A device permission is not consent to workplace surveillance. The company must assess necessity, proportionality, worker information and local employment-law requirements.

6. Recipients and service providers

Authorised users of the relevant company have role-based access. Hosting, authentication, database, storage, delivery, monitoring and support providers may technically process data; an explicitly enabled document-analysis provider may also process receipt data.

TODO before publication: publish the exact current processor list and purposes. The current implementation primarily uses Firebase and Google Cloud services; any AI analysis must be listed separately.

7. Transfers outside the EEA

Some providers may process data outside the European Economic Area. Such transfers must rely on an adequacy decision, Standard Contractual Clauses or another lawful safeguard. Information about the specific safeguard can be requested.

8. Retention

TODO before publication: the company and operator must add exact periods or sufficiently precise criteria for each category.

  • company work data: under the company’s instructions, employment/accounting regime and agreement with FuzeWork;
  • account and profile: while active and afterwards as needed for deletion, disputes and legal duties;
  • audit, security and operational logs: only as reasonably necessary for security, diagnostics and claims;
  • backups: until securely overwritten in the regular cycle;
  • consent records and versions: as needed to demonstrate compliance and defend claims.

9. Security

Risk-appropriate technical and organisational measures include authentication, tenant separation, role controls, encrypted transfer, access rules, audit records and restricted support access. No system can guarantee absolute security.

10. Individual rights

For work data, contact your company or employer first. FuzeWork will reasonably assist it as processor. For data where the operator is controller, use section 15.

  • information and access;
  • rectification of inaccurate data;
  • erasure or restriction where legal conditions apply;
  • portability for relevant processing;
  • objection to legitimate-interest processing;
  • withdrawal of consent at any time without affecting earlier lawfulness;
  • complaint to the competent supervisory authority.

11. Consent in employment

The required in-app acknowledgement primarily records that the user received this information. It does not itself determine the legal basis for all employee attendance and monitoring.

Because of the employer–worker power imbalance, consent may not be freely given. The company must identify a suitable basis for each processing activity and must not make work conditional on optional consent unless necessary and lawful. Marketing consent remains separate and withdrawable.

12. Automated decision-making

FuzeWork is not intended to make decisions with legal or similarly significant effects based solely on automated processing. Automatic totals, filters, alerts or receipt extraction are supporting outputs and must be reviewed by a person where material.

13. Children

The service is intended for organisations and people legally entitled to work under local law. A company must not create an account without a lawful basis and any required authorisation.

14. Changes and versions

Each notice has a version and permanent URL. Material changes to purposes, bases, recipients or rights will be communicated and may require renewed acknowledgement. Earlier notices remain archived.

15. Controller, DPO and contact

TODO before publication: FuzeWork operator’s legal identity and contact, EU representative where required, DPO contact where appointed and rights-request contact.

For work data, the primary contact is the company or employer shown in the user profile. A complaint may be made to the authority for the place of residence, work or alleged infringement.

16. Sources used for this draft

  • European Commission: information that must be provided ↗
  • European Commission: individual rights under GDPR ↗
  • EUR-Lex: Regulation (EU) 2016/679 ↗
Version 2026-01·Current wording
FuzeWork

One workspace for teams, projects, and every workday.

Terms of UsePersonal Data ProcessingContact
© 2026 FuzeWork. All rights reserved.Draft · W1