Legal
External Processors
Last revised on: 2 February, 2026
Our Approach to Data Processing
At WorkSpark, we take a deliberate approach to protecting your data. We avoid third-party tools wherever possible and never use tracking cookies on our platform, which is why you won't see a cookie consent banner on our site. Your data stays yours.
That said, running a modern platform means we do work with a small number of trusted external processors to keep things running smoothly. Below is a transparent account of who they are, what they do, and why we use them.
Infrastructure & Hosting
Google Cloud Platform
Our entire infrastructure runs on Google Cloud Platform, hosted within the European Union. Google Cloud provides the compute, storage, and networking foundation that powers WorkSpark.
- Data processed: All platform data, including user accounts, organization data, and application content
- Purpose: Infrastructure hosting and cloud computing
- Location: European Union
- Website: cloud.google.com
Cloudflare
We use Cloudflare for networking infrastructure, content delivery (CDN), DDoS protection, and bot protection on our authentication endpoints. Cloudflare sits between you and our servers to ensure fast, reliable, and secure access to WorkSpark.
- Data processed: Network traffic metadata, IP addresses, request headers, and Turnstile tokens on public endpoints
- Purpose: CDN, DNS, network security, DDoS and bot protection
- Website: cloudflare.com
Authentication
Microsoft
WorkSpark supports Microsoft Entra ID as an optional single sign-on (SSO) option. Where an organization enables it, authentication is handled by the customer's own Microsoft identity provider.
- Data processed: Authentication assertions only, where a customer enables Microsoft SSO
- Purpose: Optional single sign-on authentication
- Website: microsoft.com
AI & Intelligence
Google Gemini
WorkSpark uses Google Gemini to power our AI features, such as generating insights and summaries. When you interact with AI-powered features, relevant content is sent to Gemini for processing.
- Data processed: Content submitted to AI-powered features (e.g., accomplishment summaries, review insights)
- Purpose: Large language model capabilities for AI features
- Data usage: WorkSpark uses the paid tier of Google's Gemini API. Under Google's paid-tier terms, content submitted to the API is not used to train or improve Google's models
- Website: ai.google.dev
Analytics
Umami
We use Umami for privacy-focused website analytics on our marketing site. Umami does not use cookies, does not track personal data, and is fully GDPR compliant. It helps us understand how visitors use our site without compromising their privacy.
- Data processed: Anonymized page views, referrer URLs, browser/device type, and country-level location
- Purpose: Privacy-friendly website analytics
- Website: umami.is
Observability & Error Reporting
Sentry
We use Sentry for system observability and error reporting. When something goes wrong in the platform, Sentry helps us identify and fix the issue quickly. This may include technical information about the error and limited contextual data.
- Data processed: Error reports, stack traces, browser/device metadata, and limited contextual data
- Purpose: Application monitoring and error tracking
- Website: sentry.io
Honeycomb
We use Honeycomb for application performance monitoring. It helps us understand request latency and error rates so we can keep the platform fast and reliable.
- Data processed: Request routes, timings, and error classes. No query parameters or customer content
- Purpose: Application performance monitoring
- Website: honeycomb.io
Communications
Postmark
Postmark handles our transactional emails, such as password resets, invitation emails, and notification digests. We only send emails that are directly related to your use of the platform.
- Data processed: Email addresses, email content for transactional messages
- Purpose: Transactional email delivery
- Website: postmarkapp.com
Slack
Our team uses Slack for internal communication. Some system notifications about activity on your account, for example that your organization has launched a review cycle, are routed through Slack for our operational visibility.
- Data processed: Organization name and, in some notifications, an individual's name, from operational notifications. Review content and survey responses are never included
- Purpose: Internal team communication and operational awareness
- Retention: Messages are subject to approximately 90 days' retention
- Website: slack.com
Billing & Payments
Stripe
Stripe processes all payments and billing for WorkSpark. When you subscribe to a paid plan, your payment information is handled directly by Stripe, and we never store your card details on our servers.
- Data processed: Payment information, billing details, transaction history
- Purpose: Payment processing and subscription management
- Website: stripe.com
Integrations
BambooHR
BambooHR is not a sub-processor. Where a customer connects BambooHR, WorkSpark performs a one-way inbound synchronisation from the customer's own HR system. No customer data is sent to BambooHR beyond authentication. Integration credentials and OAuth tokens are protected with AES-256-GCM field-level encryption.
- Data processed: Employee directory data received one-way from your own BambooHR account
- Purpose: Inbound synchronisation from the customer's HR system
- Website: bamboohr.com
Your Rights
Under the GDPR, you have the right to know how your data is processed and by whom. If you have questions about any of the processors listed above, or if you'd like to exercise your data rights, please contact us at [email protected].
We review our external processors regularly and will update this page whenever changes are made.