PricingCompareSecurityContact
العربيةSign inStart free
ERP core
CRM & LeadsPipeline, deals, follow-upsCustomersAccounts, statements, creditInvoicing & VATFTA tax invoices, online pay linksSales & OrdersQuotes, orders, delivery notesAccountingLedger, banking, reportsInventoryStock, warehouses, valuationProjects & TasksKanban, timesheets, budgets
 
HR & Payroll (WPS)Employees, leave, WPS SIFManufacturingBOMs, work orders, costingProcurementRFQ, PO, goods receipt, billsFixed AssetsRegister, depreciation, maintenanceHelpdesk & ServiceTickets, warranty, AMC visitsPricing & LoyaltyPrice rules, coupons, points tiers
AI Work OS layer
Ask AI & Company MemoryAsk anything about your businessUnified InboxEmail + WhatsApp in one placeOne-Tap ApprovalsApprove from anywhereMeetings & AI NotesNotes, decisions, actionsUAE ComplianceVAT 201, licences, visas
All modules, one system

Switch on what you need today and add the rest as you grow. Everything shares one ledger, one customer record and one login.

A team working in a modern officeExplore all modules
Trading & DistributionImport, stock, sell and get paid, with FTA VAT built in.Retail & POSShops, F&B and ecommerce with one stock across every channel.Construction & ContractingProjects, job costing, procurement and WPS payroll on site.Real Estate & PropertyUnits, leases, rent invoicing and maintenance in one place.
Healthcare & ClinicsPatients, appointments, pharmacy stock and billing.ManufacturingBOMs, work orders, stock and costing end to end.Professional ServicesProjects, timesheets, retainers and billing for agencies.
One platform, your industry

Every sector shares the same core, VAT, payroll and AI layer. Switch on the modules your industry needs and go live in days.

Business district skylineSee all sectors
Start freeSign in
العربية
Explore
PricingCompareSecurityContact
Sectors
Trading & DistributionRetail & POSConstruction & ContractingReal Estate & PropertyHealthcare & ClinicsManufacturingProfessional Services
Modules
CRM & LeadsCustomersInvoicing & VATSales & OrdersAccountingInventoryProjects & TasksHR & Payroll (WPS)ManufacturingProcurementFixed AssetsHelpdesk & ServicePricing & LoyaltyAsk AI & Company MemoryUnified InboxOne-Tap ApprovalsMeetings & AI NotesUAE Compliance
Policies
  • All policies
  • Privacy Policy
  • Terms of Service
  • Cookie Policy
  • Data Processing Addendum
  • Acceptable Use Policy
  • Refund and Cancellation Policy
  • Service Level Agreement
  • Security Overview
HomeLegalPrivacy Policy

Privacy Policy

This policy explains what personal data WorkOSync collects, why we collect it, where it is stored, how long we keep it and the rights you have over it. It applies to the WorkOSync website, the web application, the mobile apps and our support channels.

Effective: 27 September 2026

Who we are and what this policy covers

WorkOSync is operated by Sixty Seven Digital FZCO, a company licensed by IFZA (Dubai Integrated Economic Zones) under trade licence 50647, with its registered address at IFZA Business Park, Dubai Silicon Oasis, Dubai, United Arab Emirates. In this policy, “WorkOSync”, “we” and “us” refer to that company.

We process personal data in accordance with the UAE Personal Data Protection Law, Federal Decree-Law No. 45 of 2021 (the “PDPL”), and its executive regulations. Where we serve customers established in the European Economic Area or the United Kingdom, we also meet the requirements of the EU General Data Protection Regulation (GDPR) and the UK GDPR for that data.

WorkOSync acts in two different roles, and your rights depend on which one applies:

  • Controller. For the data of website visitors, people who sign up for an account, billing contacts and anyone who writes to us, we decide why and how the data is processed. This policy is the primary document for that data.
  • Processor. For the business records a customer enters into their WorkOSync company (its own customers, suppliers, employees, invoices, payroll and documents), the customer is the controller and we process that data only on their instructions. That processing is governed by our Data Processing Addendum. If you are an employee, customer or supplier of a business that uses WorkOSync, please direct requests about your data to that business first.

Personal data we collect

Data you give us

  • Account data: your name, work email address, password (stored only as a bcrypt hash), phone number if you add one, preferred language, time zone and two-factor authentication secrets.
  • Company data: the legal name, trade licence number, Tax Registration Number (TRN), address, currency and tax region of the company you register, and the roles you assign to your team.
  • Billing data: billing contact, billing address, VAT status and plan history. Card numbers are entered directly with our payment gateway (Stripe, Tap, PayPal or Razorpay) and never touch our servers. We keep only the gateway’s token, the card brand and its last four digits.
  • Content you upload: files, notes, messages and records that you or your team place in the service.
  • Support communications: the emails, chat messages and forms you send to us, and any files you attach to them.
  • Bring-your-own AI key: if you connect your own AI provider key, we store it encrypted and use it only to make requests on your behalf.

Data we collect automatically

  • Technical and security data: IP address, user agent, request path, timestamps, referring page and the outcome of each request. We use this to run the service, to detect abuse and to keep an audit trail of sign-ins and changes made inside your company.
  • Product usage: which modules and features are used and how often, so we can prioritise work and spot problems. This is aggregated per company and is not sold or shared.
  • Website analytics: our website analytics are first-party and cookieless. A visitor is counted using a salted hash of IP address and user agent that rotates daily and cannot be reversed. See the Cookie Policy.

We do not ask for, and ask you not to upload, special categories of data such as health, biometric, religious or criminal-record data about yourself unless a module you use requires it (for example, an HR record of a medical fitness certificate). Where a customer stores such data, the customer is the controller and must have a lawful basis for it.

How we use personal data

  • To create and administer your account and your company workspace, authenticate you and enforce role-based permissions.
  • To provide the features you use, including invoicing, accounting, payroll, inventory, CRM and the AI layer, and to generate the documents you ask for.
  • To bill you, issue tax invoices and collect payment through the gateway you choose.
  • To send transactional messages: sign-in codes, invoices, approval requests, reminders, security alerts and service notices. These cannot be switched off while you hold an account because the service cannot operate without them.
  • To send product news and offers, only where you have opted in, and with an unsubscribe link in every message.
  • To provide support, investigate problems and respond to your requests.
  • To protect the service: detecting fraud, bots, brute-force attempts, spam and misuse, and banning abusive sources.
  • To comply with law, including UAE tax record-keeping obligations, anti-money-laundering rules that apply to our payment partners, and lawful requests from authorities.
  • To improve the service using aggregated, de-identified usage statistics.

We do not sell personal data, and we do not use customer data to train AI models, whether ours or a third party’s.

Legal bases for processing

Under the PDPL, and Article 6 of the GDPR where it applies, we rely on the following bases:

PurposeBasis
Providing the service, billing, supportPerformance of a contract with you (PDPL Article 4(1)(a); GDPR Article 6(1)(b))
Tax invoices, accounting records, responding to lawful requestsCompliance with a legal obligation (PDPL Article 4(1)(c); GDPR Article 6(1)(c))
Security, abuse prevention, service improvement, product analyticsOur legitimate interests in running a safe and reliable service, balanced against your rights (PDPL Article 4(1)(b); GDPR Article 6(1)(f))
Marketing emails, optional cookiesYour consent, which you can withdraw at any time (PDPL Article 4 and Article 6; GDPR Article 6(1)(a))
Processing on behalf of a customerThe customer's instructions under the Data Processing Addendum

AI features and bring-your-own key

The AI layer (morning brief, drafting, summaries, natural-language queries and one-tap approvals) sends the specific records needed for a request to an AI model provider and returns the result to you. Two options are available to every company:

  • WorkOSync-managed AI. Requests go to the provider we have contracted as a sub-processor, under terms that prohibit training on your data and require deletion after processing.
  • Bring your own key. You connect your own API key from a provider of your choice. Requests then go directly from our servers to your provider under your own agreement with them. We store the key encrypted and never display it again after entry.

AI features are off until an owner or admin of the company enables them. You can disable them, or restrict them by role, at any time in Settings.

Data hosting and international transfers

WorkOSync is hosted in secure European data centres, and each company's database, uploaded files and backups are stored there, encrypted in transit and at rest and backed up daily.

Some sub-processors operate in other regions, for example a payment gateway or an email delivery service. Where personal data is transferred we rely on appropriate safeguards: a transfer to a country recognised as having adequate protection, or a contract that binds the recipient to equivalent safeguards. For data subject to the GDPR we use the European Commission’s Standard Contractual Clauses, and the UK Addendum where relevant.

How long we keep data

DataRetention
Account and company dataFor the life of the account, then deleted 90 days after the account is closed or the subscription ends, unless you ask for earlier deletion
Customer business records (as processor)Exported on request for 30 days after termination, then deleted within 90 days; see the DPA
Tax invoices and billing records5 years from the end of the relevant tax period, as required by UAE Federal Tax Authority rules, or longer where the law of your country requires
Security and access logs12 months, then aggregated or deleted
Website analyticsAggregated daily; the hashed visitor identifier is not stored beyond the day it is generated
Support conversations3 years after the ticket is closed
BackupsRolling 35-day window; deleted data ages out of backups within that window
Blocked IP addresses and abuse recordsUntil the block expires or 24 months, whichever is later

Sub-processors and sharing

We share personal data only with providers who need it to deliver the service, under written contracts that limit their use of it:

  • Hosting and infrastructure in the UAE, with optional EU and US regions.
  • Email delivery for transactional and notification email.
  • Payment gateways: Stripe, Tap Payments, PayPal and Razorpay, depending on the method you choose. Each is an independent controller of the payment data it collects, under its own privacy policy.
  • AI model providers, only when the AI layer is enabled by your company, and only for the requests it makes.
  • Professional advisers, auditors and authorities where the law requires or permits it.

The current list of sub-processors is published in the Data Processing Addendum. We give customers 30 days’ notice before adding a new one. If WorkOSync is acquired or merges with another business, personal data may be transferred to the new owner under the same commitments as this policy, and you will be told before that happens.

How we protect data

All traffic is encrypted in transit with TLS and HSTS. Passwords are stored as bcrypt hashes, secrets such as gateway and AI keys are encrypted at rest, sessions are server-side with httpOnly cookies, and every sign-in and change is audited. Access to production systems is limited to named staff with two-factor authentication. Backups are encrypted and restore-tested. Our full set of controls is described on the Security Overview page.

Your rights

Under Chapter 4 of the PDPL, and Chapter 3 of the GDPR where it applies, you have the right to:

  • Access the personal data we hold about you and receive a copy of it.
  • Correct inaccurate or incomplete data. Most account data can be edited directly in Settings.
  • Erase your data where we no longer need it, subject to the retention periods the law requires.
  • Restrict or object to processing based on legitimate interests, including all direct marketing.
  • Portability: receive your data in a structured, machine-readable format. Company owners can export every module to CSV or JSON from Settings at any time.
  • Withdraw consent at any time where consent is the basis, without affecting processing already carried out.
  • Not be subject to a solely automated decision with legal or similarly significant effect. WorkOSync’s AI layer drafts and suggests; approvals are always taken by a person you designate.

To exercise a right, email privacy@workosync.com from the address on your account, or ask your company owner to raise it for you. We respond within 30 days, and sooner where we can. We may ask you to verify your identity first. If you are unhappy with our response you can complain to the UAE Data Office, and, if you are in the EEA or the UK, to your local supervisory authority.

Cookies

We use a small number of strictly necessary cookies to keep you signed in and to protect forms, and no advertising or third-party tracking cookies. Our analytics work without cookies. The full list, and how to control them, is in the Cookie Policy.

Children

WorkOSync is a business tool. It is not directed at, and may not be used by, anyone under 18 years of age. We do not knowingly collect personal data from children. If you believe a child has created an account, contact us and we will delete it.

Changes to this policy

We review this policy at least once a year and whenever the service or the law changes. Small clarifications take effect when published. For material changes we email account owners at least 14 days before the new version takes effect and show a notice in the app. The effective date at the top of the page always tells you which version you are reading, and earlier versions are available on request.

Contact

Our data protection contact handles access, correction and deletion requests, questions about this policy and complaints. Write from the email address on your account so we can verify you quickly.

Write toprivacy@workosync.com
CompanySixty Seven Digital FZCOTrading as WorkOSync. Licence 50647, IFZA (Dubai Integrated Economic Zones).
Registered addressIFZA Business Park, Dubai Silicon Oasis, Dubai, United Arab Emirates

Other addresses: privacy@workosync.com for data protection, support@workosync.com for billing and support, security@workosync.com for vulnerability reports.

The all-in-one Work OS for GCC business. A full ERP core plus an AI layer that runs your daily loop, built in the UAE.

ERP coreCRM & LeadsCustomersInvoicing & VATSales & OrdersAccountingInventory
AI layerAsk AI & Company MemoryUnified InboxOne-Tap ApprovalsMeetings & AI NotesUAE Compliance
CompanyAboutSectorsPricingComparePartnersSecurityContact
ResourcesDocumentationGetting startedUAE complianceSign in
LegalPrivacyTermsCookiesDPARefundsSLA
© 2026 WorkOSync · Sixty Seven Digital FZCO, DubaiPrivacy · Terms · CookiesMade in the UAE · English & العربية