Prepared for review: 30 September 2026. Status: draft, not effective.
1. Scope and status
This draft describes the StaffWorkspace marketing website. It is separate from the employee application, customer workspaces and any future mobile apps. It must be approved against the actual operating entity, providers and data flows before it becomes an effective notice.
StaffWorkspace is presented as a product of Global Recruit Way. A brand name alone does not identify the legal controller. The owner must insert the full legal entity name, registered address and relevant registration details before launch. For enquiries about this draft, contact info@staffworkspace.com.
2. Information you provide
The contact form requests your name, work email, company, staff count and message. Phone and country are optional. It also records your permission to receive a reply and the type of enquiry. Please provide only information needed to discuss the service.
Do not submit employee files, passport or identity scans, payslips, bank information, medical information, criminal records or passwords through this website. There is no file-upload facility. This website does not create an employee account when you submit an enquiry.
3. Technical and preference information
Your browser and hosting provider exchange technical information necessary to serve a website, which may include IP address, request time, user agent and error information. The actual hosting provider, log fields, locations and retention settings must be recorded in the approved provider inventory. The application code does not deliberately log contact message contents.
This site stores your cookie choice locally and, when you choose one, a display-currency preference. A trusted hosting-country signal may suggest a currency. This does not require GPS permission. Currency requests go from the website server to a reference-rate provider without forwarding your IP address or contact data.
4. Why information is used
The proposed purposes are answering an enquiry, discussing a requested workspace, preventing abuse, operating the website, preserving user-selected preferences and understanding website use through optional analytics. These purposes do not include enrolling you into an unsolicited newsletter, selling an employee list or making automated employment decisions.
For jurisdictions requiring a lawful basis, the operating entity must document the appropriate basis for each purpose before launch. A request for service information may support pre-contractual communications; proportionate security measures may require a legitimate-interest assessment; optional analytics uses the consent controls described in the Cookie Policy. The contact checkbox is permission to reply, not permission for unrelated uses.
5. Email and other recipients
Configured contact delivery uses the Resend email API. The form sends enquiry details to the fixed StaffWorkspace mailbox, with the submitted email set as the reply address. Mailbox administrators and authorised personnel may read the enquiry to respond. Provider acceptance is not a guarantee of inbox delivery.
Other possible recipients are the selected hosting and email providers, optional Google Analytics when explicitly enabled and accepted, professional advisers where needed, and authorities when a valid legal obligation applies. Before launch the owner must list the actual provider entities, processing countries, contractual roles and safeguards. Parent-brand affiliation does not give unrestricted permission to share employee data.
6. Optional analytics
Google Analytics code is not loaded by this implementation until you opt in and the owner has configured a valid measurement ID. Advertising signals and ad personalisation are disabled in the supplied configuration. Only the page path, a page title and a successful-enquiry event are deliberately sent by our code; form values and URL query strings are not included.
Provider-managed information, cookie behaviour and IP handling must still be evaluated against the actual Google account settings and applicable rules. Browser Global Privacy Control suppresses optional analytics in this implementation. Rejecting analytics does not restrict the website or contact form.
7. Retention and deletion
Cookie choices are treated as expired after 180 days. Explicit currency preferences also expire after 180 days. These browser entries may remain physically stored until replaced or cleared, but expired values are ignored. Browser controls can remove them sooner.
A proposed enquiry-retention period is 12 months after the last meaningful interaction, subject to an approved retention schedule, an ongoing relationship or a documented legal need. This is a proposal, not a claim that mailbox deletion is already automated. The owner must configure deletion, backup handling, legal holds and account-level analytics retention before adoption. Security and email-delivery logs require their own shorter, justified schedules.
8. International access and transfers
StaffWorkspace is intended for organisations in different countries. A worldwide website does not mean every provider or employee record remains in the visitor’s country. Hosting, support access, email processing and analytics must be mapped before any local-residency claim is made.
Where a transfer mechanism, assessment, local authorisation or additional safeguard is required, it must actually be executed and maintained. Displaying a privacy notice or naming standard contractual clauses does not itself implement that mechanism. Ask for the approved processing-location and provider information before transferring staff records.
9. Your requests and choices
You may contact info@staffworkspace.com to ask about access, correction, deletion, objection, restriction, portability or consent withdrawal where applicable. State the relationship and type of request without sending unnecessary identity documents. The team should use proportionate verification and a secure channel if additional evidence is genuinely needed.
An employee request concerning a company workspace should normally go to that employer’s HR or privacy contact first. StaffWorkspace should assist the employer under the applicable service agreement rather than change employment records on its own authority. Applicable statutory deadlines and complaint routes must be included in the approved regional supplement. You may also contact the relevant supervisory authority where that right applies.
10. Children and sensitive information
This marketing website is aimed at organisations and their authorised adult representatives. It is not designed for children to create accounts or submit employment data. Any use involving younger workers, students, apprentices or legally sensitive records needs separate assessment and employer authorisation.
This website does not use facial recognition, collect face templates, request a photo or access precise location. Potential photo or location attendance options belong to the separate application and require their own notices, necessity assessment, retention limits and permissions. A photograph is not automatically the same thing as a biometric-identification template.
11. Security and changes
This implementation uses server-side validation, fixed enquiry recipients, output escaping, body limits, basic abuse limits and configurable browser security headers. These controls are not a certification and do not establish the security posture of the separate HR application. See the Security Overview for the verification boundary.
An effective version should state its date and material changes. A change in purpose, providers or tracking may need a fresh notice, consent or agreement. The operator must not silently turn a service enquiry into marketing permission.
Official references for review
ICO: cookies and similar technologies California Attorney General: CCPA informationReferences are provided for verification. They do not endorse StaffWorkspace. Check the current official version and its applicability before adoption.