1. Controller and contact
UploadWerk is operated by the individual identified in the Imprint. The complete legal name and serviceable address are stated there.
Privacy enquiries can be sent to uploadwerk@gmail.com.
How UploadWerk handles workflow files, operational data and enquiries.
UploadWerk is operated by the individual identified in the Imprint. The complete legal name and serviceable address are stated there.
Privacy enquiries can be sent to uploadwerk@gmail.com.
UploadWerk is an independent tool for test-data generation, payroll migration preparation, source-report-to-template transport and rule-based troubleshooting of SuccessFactors import files. It does not connect to a SuccessFactors tenant or perform the final import.
For ordinary website, contact and administrator data, the operator is the controller. Where UploadWerk processes personal data in customer files solely on the customer's instructions, UploadWerk acts as processor and the customer normally remains controller.
Uploaded templates, source files, job-response files, in-session edits, previews and generated exports are processed to provide the workflow requested by the user.
Public-workflow files and generated exports are not written to the application database or offered as permanent account storage. Temporary workflow state becomes eligible for automatic deletion after 1 hour. The production cleanup job runs every 30 minutes, so deletion may occur shortly after the threshold rather than at an exact second.
Download responses are sent with no-store headers. Users should download required results before the workflow expires.
SuccessFactors and migration files may contain personal HR data. Customers may upload such data only where they are authorized to do so, have an applicable legal basis and provide lawful instructions.
Customers remain responsible for data minimization, transparency obligations, tenant-specific configuration, final validation and import decisions.
UploadWerk uses a technically necessary, signed and HTTP-only session cookie for security, CSRF protection and multi-step workflow state. It is not used for advertising or cross-site tracking.
No advertising cookies are used. Consent controls will be added before any non-essential cookie or comparable tracking technology is introduced.
UploadWerk uses providers only where needed for hosting, email delivery, backups and optional error monitoring. The current list and known processing locations are published on the Subprocessors page.
Personal data is not sold. Transfers outside the EEA take place only where an applicable transfer mechanism and required supplementary measures are in place.
Temporary workflow data becomes eligible for deletion after 1 hour. Privacy-minimized operational metadata is normally retained for 90 days.
Other current periods, including contact-mailbox, security-log, backup and administrator-account retention, are summarized on the Data Retention page. Records may be kept longer where necessary for a documented security incident, legal claim or statutory duty.
Subject to the applicable requirements, individuals may request access, rectification, erasure, restriction, portability or object to processing based on legitimate interests. Consent may be withdrawn with effect for the future.
Requests can be sent to uploadwerk@gmail.com. UploadWerk may request information needed to verify identity. Individuals may also complain to a competent data-protection supervisory authority.
The current public service uses deterministic application rules and does not send uploaded workflow files to OpenAI or another external AI provider.
UploadWerk does not make decisions producing legal or similarly significant effects about individuals.
This policy may be updated when workflows, providers, retention rules or legal roles change.
Version date: 2026-07-29