Skip to content
UploadWerk
Tools FAQ Contact About
Legal

Privacy Policy

How UploadWerk handles workflow files, operational data and enquiries.

1. Controller and contact

UploadWerk is operated by the individual identified in the Imprint. The complete legal name and serviceable address are stated there.

Privacy enquiries can be sent to uploadwerk@gmail.com.

2. Service and roles

UploadWerk is an independent tool for test-data generation, payroll migration preparation, source-report-to-template transport and rule-based troubleshooting of SuccessFactors import files. It does not connect to a SuccessFactors tenant or perform the final import.

For ordinary website, contact and administrator data, the operator is the controller. Where UploadWerk processes personal data in customer files solely on the customer's instructions, UploadWerk acts as processor and the customer normally remains controller.

3. Temporary workflow files

Uploaded templates, source files, job-response files, in-session edits, previews and generated exports are processed to provide the workflow requested by the user.

Public-workflow files and generated exports are not written to the application database or offered as permanent account storage. Temporary workflow state becomes eligible for automatic deletion after 1 hour. The production cleanup job runs every 30 minutes, so deletion may occur shortly after the threshold rather than at an exact second.

Download responses are sent with no-store headers. Users should download required results before the workflow expires.

4. Customer responsibility and instructions

SuccessFactors and migration files may contain personal HR data. Customers may upload such data only where they are authorized to do so, have an applicable legal basis and provide lawful instructions.

Customers remain responsible for data minimization, transparency obligations, tenant-specific configuration, final validation and import decisions.

5. Other data

  • Privacy-minimized usage data: opaque visitor or user reference, workflow and step names, status, request references, and aggregate row, column, warning or error counts.
  • Security and server data: timestamps, IP address, user agent, rate-limit records and technical error information where needed to operate and protect the service.
  • Contact data: name, email address, category and message sent through the contact form.
  • Optional update data: email address and consent status where a visitor chooses to receive updates.
  • Administrator account and authentication data needed to operate the service.

6. Purposes and legal bases

  • Providing a requested workflow or answering a service enquiry: Art. 6(1)(b) GDPR where connected to a contractual or pre-contractual relationship, and otherwise Art. 6(1)(f) GDPR.
  • Operating, protecting, debugging and preventing misuse of UploadWerk: Art. 6(1)(f) GDPR.
  • Optional product updates: Art. 6(1)(a) GDPR. Consent may be withdrawn at any time.
  • Meeting legal obligations: Art. 6(1)(c) GDPR where applicable.

7. Session cookie

UploadWerk uses a technically necessary, signed and HTTP-only session cookie for security, CSRF protection and multi-step workflow state. It is not used for advertising or cross-site tracking.

No advertising cookies are used. Consent controls will be added before any non-essential cookie or comparable tracking technology is introduced.

8. Providers and transfers

UploadWerk uses providers only where needed for hosting, email delivery, backups and optional error monitoring. The current list and known processing locations are published on the Subprocessors page.

Personal data is not sold. Transfers outside the EEA take place only where an applicable transfer mechanism and required supplementary measures are in place.

9. Retention

Temporary workflow data becomes eligible for deletion after 1 hour. Privacy-minimized operational metadata is normally retained for 90 days.

Other current periods, including contact-mailbox, security-log, backup and administrator-account retention, are summarized on the Data Retention page. Records may be kept longer where necessary for a documented security incident, legal claim or statutory duty.

10. Rights and complaints

Subject to the applicable requirements, individuals may request access, rectification, erasure, restriction, portability or object to processing based on legitimate interests. Consent may be withdrawn with effect for the future.

Requests can be sent to uploadwerk@gmail.com. UploadWerk may request information needed to verify identity. Individuals may also complain to a competent data-protection supervisory authority.

11. No external AI processing or automated decisions

The current public service uses deterministic application rules and does not send uploaded workflow files to OpenAI or another external AI provider.

UploadWerk does not make decisions producing legal or similarly significant effects about individuals.

12. Changes

This policy may be updated when workflows, providers, retention rules or legal roles change.

Version date: 2026-07-29

Back to Trust Center
Your temporary workflow will expire soon. Keep working to retain your current uploads and settings.
Trust Center