1. Who we are
WorkStream is a time-tracking, approvals, reporting and invoicing service made up of this website, the web app at workstream-app.hanaplatform.com and the WorkStream desktop app. It is operated by Hana Platform (“we”, “us”).
This policy explains what personal data we handle, why, who can see it, and the choices you have.
2. Your organisation and us
Most people use WorkStream because their employer or client set up a workspace and invited them. For the data inside a workspace, that organisation decides what is collected and why — it is the data controller, and we process the data on its behalf and on its instructions.
For this website, the contact form and our own business relationship with customers, we are the controller.
If you have questions about how your organisation uses WorkStream — for example whether screenshots are switched on — please ask your workspace Owner or Admin first. We will help them answer you.
3. What we collect
Account details.
- Your name, email address and password. Passwords are stored only as a one-way hash, never in readable form.
- Optional profile photo, time zone, date and time format and language preferences.
- If you turn on two-factor sign-in, the secret used to check your authenticator codes.
Workspace content that you and your colleagues enter:
- Time entries, timers, timesheets and their approval history.
- Clients, projects, tasks, tags, budgets, billable and cost rates.
- Invoices, payments, expenses and uploaded receipts.
- Schedules, time-off requests, holidays, roles and reporting lines.
From the desktop app.
- A device identifier (your operating system's machine ID, or a random ID we create once), your platform and the app version — so your workspace can approve devices and the app can offer updates.
- Idle detection: the app notices when the keyboard or mouse was last used so it can ask whether to keep idle time. It records only how long you've been inactive — never which keys you pressed, what you typed or where the pointer was.
- Activity screenshots, only if your workspace turns them on — see the next section.
Security and service records.
- An audit log of important changes in a workspace (such as edits, approvals and permission changes), with who made them and when.
- Technical data our servers record when you connect, such as IP address, browser or app version and timestamps.
On this website.
- What you send us through the contact form: your name, email, company, team size and message.
- If analytics are enabled, anonymous usage statistics (see Cookies and analytics).
4. Activity screenshots
Screenshots are off by default. Only a workspace Owner or Admin can turn them on, and they choose how often captures are taken. Organisations that enable them are responsible for telling their people and for having a lawful basis to do so.
- When enabled, the desktop app captures your screen at the chosen interval while you are signed in to it. The web app never captures anything.
- Each image is resized and compressed on your device before upload. A capture taken while a timer is running is linked to that time entry.
- You can always see your own screenshots.
- The workspace Owner can see everyone's. Admins can see other people's screenshots only when they were taken during tracked time, and not those of people marked as core team.
- Managers and other roles cannot see anyone else's screenshots.
5. How we use data
- To provide the service: tracking time, approvals, reports, invoices and the other features your workspace uses.
- To keep accounts and workspaces secure, including device approval, two-factor sign-in and investigating misuse.
- To send service emails such as invitations, password resets, notifications and invoices your workspace sends.
- To answer contact-form messages and support requests.
- To understand, fix and improve the product.
- To meet legal obligations.
We do not sell personal data, and we do not use workspace content for advertising.
7. How long we keep it
- Workspace content is kept while the workspace is active, and deleted when the workspace Owner asks us to delete it — except where the law requires us to keep records for longer.
- Audit-log records are deleted automatically after two years.
- Password-reset and email-verification links are deleted once they expire.
- Contact-form messages are kept only as long as needed to handle your enquiry and any follow-up.
8. Security
- Traffic between you and our servers is encrypted in transit.
- Passwords are hashed; optional two-factor sign-in adds a second check.
- Access inside a workspace is limited by role, and the desktop app keeps its sign-in token in your operating system's secure credential store.
- No system is perfectly secure. If we become aware of a breach affecting your data, we will tell the affected organisations without undue delay.
9. Your choices and rights
Depending on where you live, you may have the right to access, correct, export or delete your personal data, to object to or restrict some uses, and to complain to a data-protection authority.
For data in a workspace, contact your workspace Owner or Admin — they control it and can act quickly. For anything else, or if you can't reach them, contact us.
11. Children
WorkStream is a workplace tool and is not intended for anyone under 16.
12. Changes to this policy
We will update this page when our practices change and revise the date at the top. If a change is significant, we will tell workspace Owners before it takes effect.