InWork GlobalIntegrity. Urgency. Ownership.

Data Privacy — CCPA & GDPR

Privacy by design, from collection to deletion.

Every InWork Global platform collects the minimum data required, stores it only as long as necessary, and documents the full data flow. We build CCPA-compliant data handling into every US client website, with GDPR-aware architecture available for clients serving EU customers.

CCPA-compliant handlingGDPR-aware architecture availableEU data residencyPrivacy by design
Data privacy and CCPA / GDPR architecture

California Consumer Privacy Act

CCPA applies wherever your customers are.

The CCPA gives California consumers rights over their personal data. US businesses with California customers must comply regardless of where the business is headquartered — and that is most of our clients.

InWork designs CCPA practices into every client website we build: a Privacy Policy that explicitly covers CCPA rights, data inventory documentation, a consumer request process, and a "Do Not Sell My Personal Information" link where required.

Consumer rights

The five rights CCPA grants.

We design the workflows that let your customers exercise each of these — and the documentation that proves you honored them.

Right to know

What data is collected, how it's used, and who it's shared with — surfaced through a Privacy Policy that explicitly covers CCPA rights.

Right to delete

Delete personal information on request, with statutory exceptions, through a consumer request process we design (form, email, and response SLA).

Right to opt-out

Opt out of the sale or sharing of personal information, with a "Do Not Sell My Personal Information" link where required.

Right to correct & non-discrimination

Correct inaccurate personal information, with no penalty for exercising CCPA rights.

GDPR-aware architecture

GDPR-aware data handling, available on request.

For InWork clients with EU customers or EU operations, we design GDPR-aware data handling.

Data minimization — collect only what is needed
Purpose limitation — use data only for the stated purpose
Storage limitation — retention policies and deletion
Data subject rights — access, correction, erasure, portability, and objection
Lawful basis documentation for each data processing activity
DPA (Data Processing Agreement) with all sub-processors
EU data residency options (AWS EU-West regions)

Privacy by design

What every InWork platform does by default.

These principles are applied at the architecture level, not added as a Privacy Policy after launch.

PrincipleCommon shortcutInWork default
Data collectionCollect everything, decide laterCollects the minimum data required
RetentionKeep data indefinitelyStores data only as long as necessary
AnalyticsPixels that may process PHINo analytics platform processes PHI without a BAA
TransparencyOpaque data flowsDocuments data flows from collection to deletion

GDPR-aware

Architecture available — not overclaimed

InWork provides GDPR-aware architecture for clients serving EU customers, including EU data residency options and DPAs with all sub-processors. We design for awareness; we do not claim a GDPR certification.

Compliance by design

Build on a platform that respects your customers' data.

CCPA-compliant handling, GDPR-aware architecture available, and documented data flows, with US oversight on every engagement. Tell us about the data you collect.

Integrity. Urgency. Ownership.

Schedule a privacy reviewRequest a proposal

40+ US businesses served · 65+ engineers · Zero long-term lock-in

Book a Strategy Call