Data Privacy — CCPA & GDPR
Privacy by design, from collection to deletion.
Every InWork Global platform collects the minimum data required, stores it only as long as necessary, and documents the full data flow. We build CCPA-compliant data handling into every US client website, with GDPR-aware architecture available for clients serving EU customers.

California Consumer Privacy Act
CCPA applies wherever your customers are.
The CCPA gives California consumers rights over their personal data. US businesses with California customers must comply regardless of where the business is headquartered — and that is most of our clients.
InWork designs CCPA practices into every client website we build: a Privacy Policy that explicitly covers CCPA rights, data inventory documentation, a consumer request process, and a "Do Not Sell My Personal Information" link where required.
Consumer rights
The five rights CCPA grants.
We design the workflows that let your customers exercise each of these — and the documentation that proves you honored them.
Right to know
What data is collected, how it's used, and who it's shared with — surfaced through a Privacy Policy that explicitly covers CCPA rights.
Right to delete
Delete personal information on request, with statutory exceptions, through a consumer request process we design (form, email, and response SLA).
Right to opt-out
Opt out of the sale or sharing of personal information, with a "Do Not Sell My Personal Information" link where required.
Right to correct & non-discrimination
Correct inaccurate personal information, with no penalty for exercising CCPA rights.
GDPR-aware architecture
GDPR-aware data handling, available on request.
For InWork clients with EU customers or EU operations, we design GDPR-aware data handling.
Privacy by design
What every InWork platform does by default.
These principles are applied at the architecture level, not added as a Privacy Policy after launch.
GDPR-aware
Architecture available — not overclaimed
InWork provides GDPR-aware architecture for clients serving EU customers, including EU data residency options and DPAs with all sub-processors. We design for awareness; we do not claim a GDPR certification.
