WEEKEYE — PRIVACY POLICY
Effective Date: April 16, 2026
Last Updated: April 16, 2026
WeekEye, operated by WeekEye ("Company", "we", "our", "us"), is committed to protecting your privacy. This Privacy Policy explains how we collect, use, process, disclose, and safeguard your personal information when you use our platform, mobile applications, web applications, and related services (collectively, the "Service").
This policy is designed to comply with applicable global privacy laws including GDPR (EU/EEA), UK GDPR, CCPA (California), LGPD (Brazil), PIPA (Japan), and other applicable regional privacy laws.
1. Introduction
WeekEye is a business-oriented workforce management platform. We process personal data to provide our Services, which include scheduling, personnel management, assignment tracking, and organizational operations. We take your privacy seriously and apply strict controls to protect the data entrusted to us.
By using the Service, you acknowledge and agree to this Privacy Policy. If you use the Service on behalf of an Organization, the Organization is the data controller for data processed in connection with that Organization, and WeekEye acts as a data processor on their behalf.
2. Information We Collect
2.1 Information You Provide
- Account registration information: name, email address, phone number, employee/ID number
- Authentication credentials (passwords stored as secure hashes; we never store plain-text passwords)
- Profile information and preferences
- Organizational data: schedules, assignments, shift information, crew and team data
- Communications sent through the Service
2.2 Information from Third-Party Sign-In
When you use Google Sign-In or Sign in with Apple, we receive:
- Your name and email address (or Apple's private relay email address)
- A unique identifier from the authentication provider
- Email verification status
We do not receive your password from third-party providers.
2.3 Automatically Collected Information
- Device type, operating system, and application version
- IP address and general geographic location (country/region)
- Log data: feature usage, error reports, and performance diagnostics
- Session and authentication tokens (stored securely)
2.4 Biometric Data
If you enable biometric authentication (Face ID / fingerprint), biometric identifiers are processed locally on your device using your operating system's secure enclave. We store only a device enrollment token and a locally-derived credential — we do not store or transmit raw biometric data.
3. Legal Basis for Processing (GDPR)
For users in the EU/EEA and UK, we process personal data based on the following legal grounds:
- Contractual necessity: To provide the Service you or your Organization have contracted for
- Legitimate interests: Security monitoring, fraud prevention, service improvement, and product analytics
- Legal obligation: Compliance with applicable laws and regulatory requirements
- Consent: Where required for specific optional features (e.g., optional analytics cookies)
4. How We Use Your Information
- Service delivery: Manage accounts, scheduling, assignments, and workflows
- Authentication: Verify your identity and maintain secure sessions
- Security: Detect fraud, prevent unauthorized access, monitor system integrity
- Improvement: Analyze usage patterns to improve performance and features
- Communications: Send service-related notifications and updates
- Legal compliance: Meet regulatory obligations and respond to lawful requests
- AI-assisted features: Where you opt in to AI scheduling or recommendation features, your organizational data may be processed by AI models to generate suggestions
5. Information Sharing and Disclosure
We do not sell your personal data.
5.1 Within Your Organization
If you use WeekEye through an Organization, your profile and activity data may be visible to Organization administrators and authorized managers as needed for operational purposes.
5.2 Service Providers
We share data with trusted third-party providers who assist in operating the Service (e.g., cloud hosting, email delivery, analytics). All such providers are contractually bound to process data only as instructed and with appropriate security measures.
5.3 Authentication Providers
When using Google Sign-In or Sign in with Apple, your authentication is handled by those providers under their respective privacy policies. We receive only the information described in Section 2.2.
5.4 Legal Requirements
We may disclose data if required by law, court order, or government request, or to protect the rights, safety, or property of WeekEye, our users, or the public.
5.5 Business Transfers
In the event of a merger, acquisition, or sale of assets, personal data may be transferred. We will notify affected users before data becomes subject to a different privacy policy.
6. Data Security
We implement industry-standard security measures:
- Encryption in transit (HTTPS/TLS) and at rest
- Secure password hashing (bcrypt)
- Role-based access controls (RBAC)
- Session management with automatic expiry
- Security audit logging
- Regular security reviews
No system is completely secure. In the event of a data breach that poses a risk to your rights, we will notify affected users and relevant authorities as required by applicable law.
7. Data Classification
We classify data into the following categories:
- Public: Information intentionally made available (e.g., public organization profiles)
- Internal: Operational data accessible to authorized organizational members
- Confidential: Personal identifiers, scheduling data, personnel records — access restricted by role
- Sensitive: Authentication credentials, biometric enrollment tokens — strictly controlled access
8. Your Privacy Rights
Depending on your jurisdiction, you may have the following rights:
- Access: Request a copy of the personal data we hold about you
- Correction: Request correction of inaccurate or incomplete data
- Deletion: Request deletion of your personal data (right to erasure). You may also delete your account directly in the app (Settings → Account → Delete Account)
- Restriction: Request restriction of processing in certain circumstances
- Portability: Receive your data in a structured, machine-readable format
- Objection: Object to processing based on legitimate interests
- Withdrawal of consent: Withdraw consent for consent-based processing at any time
To exercise these rights, contact us at support@weekeye.com. We will respond within 30 days (or as required by applicable law).
10. Third-Party Services
The Service integrates with third-party services including:
- Google: Sign-In, analytics (web only, optional). Google Privacy Policy: policies.google.com/privacy
- Apple: Sign in with Apple, iOS native features. Apple Privacy Policy: apple.com/privacy
- Cloud Infrastructure: Hosting and database services
We are not responsible for the privacy practices of third-party services. We encourage you to review their privacy policies.
11. Data Retention
- Active accounts: Data retained for the duration of the account
- Deleted accounts: Personal data is anonymized within 30 days of deletion; some data may be retained longer for legal compliance (typically up to 7 years for financial/audit records)
- Organizational data: Retained according to the Organization's data retention policy and applicable law
- Security logs: Retained for up to 12 months for security monitoring purposes
12. Children's Privacy
The Service is not intended for children under the age of 16 (or 13 in the United States). We do not knowingly collect personal data from children. If we become aware that a child has provided personal data, we will delete it promptly. If you believe a child has provided data to us, please contact us at support@weekeye.com.
13. International Data Transfers
Your data may be processed in countries other than your country of residence. When transferring data from the EU/EEA to third countries, we ensure appropriate safeguards are in place, including Standard Contractual Clauses (SCCs) approved by the European Commission, adequacy decisions, or other lawful transfer mechanisms.
14. Monitoring and Auditing
To maintain security and service integrity, we log authentication events, account changes, and system access. These logs are retained for security audit purposes and are not used for advertising or profiling. Organizational administrators may have access to audit logs related to their organization's usage.
15. Data Breach Response
In the event of a personal data breach that poses a risk to user rights and freedoms, we will:
- Notify relevant supervisory authorities within 72 hours as required by GDPR
- Notify affected users without undue delay
- Provide details about the nature of the breach, data affected, and steps taken
- Take immediate remediation steps
16. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of material changes by posting the updated policy with a new effective date and, where appropriate, by email or in-app notification. Continued use of the Service after changes take effect constitutes your acceptance of the updated policy.
17. Contact Us
For privacy-related questions, requests, or complaints:
- Email: support@weekeye.com
- Privacy: privacy@weekeye.com
- Support: support@weekeye.com
For EU/EEA users, you also have the right to lodge a complaint with your local data protection authority.
18. Limitation of Liability
To the maximum extent permitted by applicable law, WeekEye shall not be liable for any indirect, incidental, or consequential damages arising from privacy incidents outside our reasonable control, provided we have implemented reasonable security measures and complied with applicable law.
19. Your Responsibilities
You are responsible for:
- Keeping your account credentials secure and not sharing them
- Ensuring that data you input about third parties (e.g., other personnel) complies with applicable privacy laws
- Notifying us of any security incidents or suspected unauthorized access to your account
- Keeping your contact information up to date for notifications
20. Governing Law
This Privacy Policy is governed by applicable law. For EU/EEA users, GDPR applies. For California residents, CCPA applies. For users in other jurisdictions, the applicable local privacy laws govern. Where conflicts arise, the law providing the greater protection to the individual will apply.