MobiWork Privacy Policy
Effective Date: September 4, 2026
Version: 10.1.11 (Supersedes all prior versions)
1) Scope of this Policy
This policy covers how MobiWork LLC (collectively, "We", "Us", "Our" or "MobiWork") treats information that personally identifies you ("personal information") that MobiWork collects and receives on our Web site www.mobiwork.com, our cloud solution and through our mobile applications. It describes how we collect, use, share and secure this information. It also describes your choices regarding the use, access and correction of your personal information.The personal information we collect may include, among other information, your name, address, phone number, and e-mail address. Once you provide MobiWork with personal information, you are not anonymous to us.
This Policy does not cover personal data that MobiWork processes solely on behalf of its business Clients as a data processor. Such processing is governed by the applicable Client's own privacy policy and the MobiWork Data Processing Addendum (DPA), available at mobiwork.com/dpa.
2) Types of Information we collect
2.1 Information You Provide
We will collect your name, email address, phone number, company name and billing address if applicable. We also require you to create a login ID and password.
If you wish to add users, customers, or groups we will collect certain personal information about other individuals from you such as name, email address, phone number, mobile number, street address, a login ID and password if applicable. We use this information to create customers, vendors, additional users or contractors within your account so that you may utilize the service. This information is only used for the sole purpose of completing your request or for whatever reason it may have been provided.
| Category | Examples | Purpose |
|---|---|---|
| Account & Identity | Name, email, job title, company name, phone number, login ID | Account creation, authentication, support |
| Billing & Payment | Company billing address, VAT/tax ID (card data handled by payment processor) | Invoicing, subscription management |
| Platform Content | Work orders, customer records, technician profiles, asset data, job notes, photos, forms | Core Service functionality |
| User-Added Contacts | Names, emails, phone/mobile numbers, addresses of customers or employees or contractors added by Client | Service delivery, route optimization, notifications |
| Communications | Support tickets, chat logs, survey responses, feedback | Customer support, solution improvement |
| Marketing Preferences | Messaging (email, SMS…) opt-in/out, communication preferences | Marketing communications (with consent) |
2.2 Information Collected Automatically
When you download and/or log in to our solution after creating an account on our Web site, we automatically collect information on the type of device you use, operating system version, and provide your device a unique ID.
| Category | Examples | Purpose |
|---|---|---|
| Usage & Log Data | Features accessed, work orders created, API calls, session duration, IP address, date/time, HTTP request details | Security, fraud prevention, analytics, debugging |
| Device & Technical | Device type, OS version, browser type, unique device ID, screen resolution, color depth | Compatibility, security, product analytics |
| Location Data | Geotags: GPS coordinates of field technicians (mobile app, with consent) captured only for specific events (form submission, logging in…) | Scheduling, dispatch, route optimization, proof of service performed or that technician was on site to customer. |
| Cookies & Tracking | Session cookies, preference cookies, analytics identifiers | Authentication, UX preferences, analytics |
| Network Data | IP address, TCP/IP packet data, domain name from which you access the internet | Malicious activity detection, network monitoring |
2.3 Information from Third Parties
- Single Sign-On (SSO) providers (e.g., Google, Microsoft): name, email.
- Payment processors (e.g., PayPal, Stripe): tokenized payment confirmation, billing address, last 4 digits of card.
- CRM and ERP integrations: contact and account data as configured by Client.
- Mapping service providers: used solely to provide location-based features within the Service.
3) How We Use Information Collected
3.1 General Uses
When you initially access our website, MobiWork collects personal information when you complete the free demo sign up process and when you purchase a solution from us. Your registration and election to opt-in authorizes MobiWork to use your personal information for the following general purposes:
- To maintain your data and associated information.
- To improve our services, analyze trends, and administer the site.
- To allow you to manage your customers, vendors, users, contractors, access work orders, service contracts, quotes, invoices and manage your employee's daily workloads.
- To send you newsletter or promotional emails where you have opted in to receive such communications.
- To send you service-related announcements on rare occasions when it is necessary to do so (e.g., temporary service suspension for maintenance). You may generally not opt out of these communications, which are not promotional in nature.
- To communicate with you in response to your inquiries and to manage your account.
In order to improve service on our website, we may collect and maintain statistical information in our site's data logs that show network traffic flow and volume. These logs do not identify individuals who visit MobiWork.com's website. This information is:
- The name of the domain from which the member or visitor accesses the Internet.
- The Internet Protocol (IP) Address from which you access our website.
- The date and time (with time zone) that you access our website.
- The type of browser and operating system used to access our website.
- The Internet address of the website from which you linked directly to our website.
- The web pages on the MobiWork.com site that you visit. This helps to determine which information on our site the public finds most useful and enables us to make it easier to access.
- The Internet address of the Web site from which you linked directly to the MobiWork.com Web site.
- Transmission Control Protocol/Internet Protocol (TCP/IP) packet data. This information is used to detect malicious activity on our website.
- Session cookie ID. This helps us determine which sequences of pages users typically view. We use this information to make the site easier to use.
- Other cookies used to validate voluntary customer survey results.
- Visitor Display Color Depth (e.g., 32 bits, 24 bits, etc.) and Visitor Screen Resolution (e.g., 1024 x 768 pixels, 800 x 600 pixels, etc.). This information helps determine the colors and sizes of graphics and other design elements that work best on our site.
- Number of bytes received helps determine the computer and network capacity required to make the site available to the public.
We do not link this automatically collected data to other information we collect about you. Or we may combine this automatically collected log information with other information we collect about you. We do this to improve services we offer you, to improve marketing, analytics, or site functionality.
3.2 Lawful Basis for Processing (GDPR)
Where EU GDPR or UK GDPR applies, MobiWork processes personal data under the following lawful bases:
| Purpose | Lawful Basis (GDPR Article 6) | Data Categories |
|---|---|---|
| Providing and operating the Service | Contract performance (Art. 6(1)(b)) | Account, platform content, usage data |
| Account authentication & security | Contract / Legitimate interests (Art. 6(1)(f)) | Account data, device data, logs |
| Billing and payment processing | Contract performance (Art. 6(1)(b)) | Billing data, account data |
| Customer support | Contract performance / Legitimate interests | Communications, account data, logs |
| Product improvement & analytics | Legitimate interests (Art. 6(1)(f)) | Usage data, anonymized content |
| Marketing communications | Consent (Art. 6(1)(a)) | Account data, marketing preferences |
| Legal compliance & fraud prevention | Legal obligation (Art. 6(1)(c)) / Legitimate interests | All applicable categories |
| Field technician location tracking | Consent (Art. 6(1)(a)) — separate in-app consent required | GPS / location data |
4) Information Related to Data Collected through the MobiWork Service
MobiWork collects information under the direction of its Clients, and has no direct relationship with the individuals whose personal data it processes on Clients' behalf. In this capacity, MobiWork acts as a data processor and the Client is the data controller.If you are a customer or employee of one of our Clients and have inquiries about the personal data MobiWork processes on that Client's behalf, please direct your query to the relevant MobiWork Client. MobiWork will assist the Client in responding to any access, correction, or deletion requests within 30 days of receiving a valid request from the Client.
5) Your Privacy Rights
Depending on your location, you may have the following rights regarding your personal data. MobiWork honors these rights for all individuals regardless of jurisdiction:| Right | Description | How to Exercise |
|---|---|---|
| Access (Right to Know) | Obtain a copy of personal data we hold about you, including categories, purposes, and recipients. | Email privacy@mobiwork.com |
| Rectification / Correction | Correct inaccurate or incomplete personal data. | Update directly in account settings, or email privacy@mobiwork.com |
| Erasure / Deletion | Request deletion of personal data where no longer necessary, consent withdrawn, or processing unlawful. | Email privacy@mobiwork.com — Subject: Deletion Request |
| Data Portability | Receive personal data in a structured, machine-readable format. | List > Export to Excel, or email privacy@mobiwork.com |
| Restriction of Processing | Request that processing be restricted while a dispute is pending. | Email privacy@mobiwork.com — Subject: Restriction Request |
| Object to Processing | Object to processing based on legitimate interests or for direct marketing. | Opt out of marketing via Opt Out form or unsubscribe link; other objections via privacy@mobiwork.com |
| Withdraw Consent | Withdraw consent at any time where processing is consent-based (e.g., marketing emails, location tracking). | Unsubscribe link in emails, Opt Out form; location opt-out in mobile app Settings |
| Lodge a Complaint | File a complaint with your local supervisory authority. EEA: national DPA. UK: ICO. Switzerland: FDPIC. | EEA National DPAs: https://www.edpb.europa.eu/about-edpb/about-edpb/members_en; UK ICO: https://ico.org.uk/make-a-complaint/; Swiss FDPIC: https://www.edoeb.admin.ch/en/contact-2 |
| DPF Rights (EEA/UK/Swiss) | Invoke DPF recourse mechanisms — BBB National Programs, then Annex I arbitration. | BBB National Programs for full escalation paths |
| CCPA Rights (California) | Know, delete, correct, opt out of sale/sharing, limit use of sensitive PI, non-discrimination. | Email privacy@mobiwork.com — Subject: CCPA Request |
We respond to all verifiable privacy rights requests within 30 days (extendable by 60 days for complex requests, with notice). We do not charge a fee for reasonable requests. We will verify your identity before processing any request that could affect someone else's data.
6) Choice & Opt-Out
We collect information for our Clients. If you are a customer of one of our Clients and would no longer like to be contacted by one of our Clients that use our service, please contact the Client that you interact with directly.MobiWork offers its visitors and customers a means to choose how we may use information provided. If, at any time after registering for information or ordering the Service, you change your mind about receiving communications such as newsletters or marketing emails from us, please opt out using the Opt Out form, or send a request specifying your new choice to privacy@mobiwork.com, or use the unsubscribe link in any marketing email.
If you would like to opt out of having your personal data used for a materially different purpose than originally collected, or opt out of disclosure to non-agent third parties, please contact privacy@mobiwork.com. For Sensitive Data, MobiWork requires explicit opt-in consent, which may be withdrawn at any time.
7) Service Providers, Sub-Processors & Onward Transfer
MobiWork may transfer personal information to companies that help us provide our service. Transfers to subsequent third parties are covered by the provisions in this Policy regarding Notice and Choice, DPF accountability obligations, and the service agreements with our Clients.MobiWork may provide your personal information to companies that provide services to help us with our business activities such as processing your payment and providing mapping services. These companies are authorized to use your personal information only as necessary to provide these services to us.
Key categories of sub-processors and the transfer mechanism applicable to each are listed below. The complete and current sub-processor list is typically updated within 30 days of any change:
| Category | Example Providers | Purpose | Transfer Mechanism |
|---|---|---|---|
| Cloud Infrastructure | Amazon Web Services (AWS) | Hosting, storage, compute | EU-U.S. DPF + SCCs |
| Payment Processing | XPlor (formerly Clearent), Stripe | Billing, subscription management | EU-U.S. DPF |
| Geocoding, Mapping & Geolocation | Google Cloud Maps Platform | Address geocoding, location features, route planning, route optimization | EU-U.S. DPF + SCCs |
| Email Delivery | Amazon SES. Smtp.com | Transactional & marketing email | EU-U.S. DPF |
| SMS / Telephony | RingCentral, Twilio | SMS notifications, voice calls | EU-U.S. DPF + SCCs |
| Sales tax | ZipTax | Sales tax computation | EU-U.S. DPF |
| Documentation | IronPDF | PDF document generation (service report, quotes, invoices…) | EU-U.S. DPF |
| Error Monitoring | Sentry / Datadog | Application monitoring, logging | EU-U.S. DPF + SCCs |
| Identity / SSO | Microsoft Azure Cloud, Google | Authentication, MFA | EU-U.S. DPF |
MobiWork's accountability for personal data that it receives under the DPF and subsequently transfers to a third party is described in the DPF Principles. In particular, MobiWork remains responsible and liable under the DPF Principles if third-party agents that it engages to process the personal data on its behalf do so in a manner inconsistent with the DPF Principles, unless MobiWork proves that it is not responsible for the event giving rise to the damage.
We also may be required to disclose an individual's personal information in response to a lawful request by public authorities, including to meet national security or law enforcement requirements. Where permitted by law, MobiWork will provide prior notice to the affected individual or Client.
8) Data Retention
During the subscription term, MobiWork shall retain Client Content necessary to provide the Service.Upon termination:
- Client may export Client Content prior to the termination;
- MobiWork may delete Client Content after applicable retention periods;
- backup copies may remain temporarily.
MobiWork has no obligation to retain Client Content indefinitely.
9) Information Sharing and Disclosure
MOBIWORK DOES NOT RENT, SELL, OR SHARE PERSONAL INFORMATION ABOUT YOU WITH THIRD PARTIES OTHER THAN AS DISCLOSED WITHIN THIS PRIVACY POLICY.We may provide your personal information to companies that provide services to help us with our business activities such as processing your payment and providing mapping services. These companies are authorized to use your personal information only as necessary to provide these services to us.
We may also disclose your personal information:
- As required by law, such as to comply with a subpoena, court order, or similar legal process.
- When we believe in good faith that disclosure is necessary to protect our rights, protect your safety or the safety of others, investigate fraud, or respond to a government request.
- To any other third party with your prior consent to do so.
- If we ever engage in onward transfers of your data with third parties for a purpose other than which it was originally collected or subsequently authorized, we will provide you with an opt-out choice to limit the use and disclosure of your personal data.
- We also may be required to disclose an individual's personal information in response to a lawful request by public authorities, including to meet national security or law enforcement requirements.
10) Tracking Technologies & Cookies
10.1 What Are Cookies
MobiWork may set and access cookies on your computer. A cookie is a small text file that is placed on your hard drive by a Web page server. Cookies cannot be used to run programs or deliver viruses to your computer. Cookies are uniquely assigned to you, and can only be read by a Web server in the domain that issued the cookie to you. One of the primary purposes of cookies is to provide a convenience feature to save you time — for example, to recall your specific information on subsequent visits. We do not link the information we store in cookies to any personally identifiable information you submit while on our site.
10.2 Cookie Categories
| Cookie Type | Purpose | Duration | Can You Opt Out? |
|---|---|---|---|
| Strictly Necessary | Authentication, session management, CSRF protection, security. Required for the Service to function. | Session / up to 1 year | No — required for core functionality |
| Functional / Preference | Language, timezone remembered between sessions. | Up to 1 year | No — required for core functionality |
10.3 Managing Cookies
Users can control the use of cookies at the individual browser level. If you reject cookies, you may still use our site, but your ability to use some features or areas of our site may be limited.
11) SMS, MMS, Telephone & Push Notifications Communications
11.1 Opting In
By opting in from a web form or other medium, you authorize MobiWork and its service providers to contact you by SMS/MMS text message, telephone call (including automated or prerecorded calls), email, and push notification.
This includes SMS messages for user verification, appointment scheduling, appointment reminders, work order status updates, technician ETA notifications, and billing notifications. Message frequency varies. Message and data rates may apply. Message HELP for help. Reply STOP to any message to opt out.
11.2 No Sharing
Opt-in and phone numbers collected for communication purposes will not be shared with any third party and affiliates for marketing or promotional purposes.
11.3 TCPA Consent Requirements
MobiWork's Communications Features (SMS, MMS, automated calling, pre-recorded voice, and push notifications) are subject to the Telephone Consumer Protection Act (47 U.S.C. § 227) ("TCPA") and FCC regulations. When Clients use these features to contact their own customers or employees, the following consent requirements apply:
- Prior Express Written Consent (PEWC) is required for all marketing or promotional messages — a clear and conspicuous written agreement that authorizes autodialed or pre-recorded calls or texts, is not a condition of purchase, and discloses that message and data rates may apply.
- Prior Express Consent is required for informational and transactional messages — including appointment reminders, work order status updates, technician ETAs, and service confirmations. Consent may be obtained orally or in writing but must be documented.
11.4 Opting Out & Revocation
- SMS Standard Opt-Out Keywords: The Service automatically processes STOP. Upon receipt, further messages to that number within the same campaign are suppressed immediately.
- Universal Opt-Out: In compliance with FCC rules effective January 27, 2025, MobiWork honors universal opt-out requests across all campaigns from a given originating number.
- Re-Consent: Opted-out contacts may not be re-enrolled without fresh Prior Express Written Consent obtained through an out-of-band channel (e.g., web form, in-person sign-up).
- Opt-Out Processing Deadline: All opt-out requests must be honored within 10 business days per FCC requirements.
11.5 Prohibited Messaging
Messages sent through MobiWork's Communications Features must not:
- Be sent to numbers listed on the National Do Not Call Registry or applicable state DNC lists (unless a specific exemption applies).
- Be sent outside permitted hours — only between 8:00 AM and 9:00 PM local time of the recipient.
- Contain spoofed caller ID or sender information in violation of the Truth in Caller ID Act.
- Contain content relating to Sex, Hate, Alcohol (to minors), Firearms, or Tobacco/Cannabis ("SHAFT") without applicable carrier approval and required age-gating.
- Contain false, deceptive, or misleading information in violation of FTC regulations or applicable consumer protection laws.
11.6 International SMS
For SMS sent to recipients outside the United States, the Client is solely responsible for compliance with applicable laws in the destination country, including CASL (Canada), PECR / UK Communications Act (United Kingdom), the ePrivacy Directive (EU), TRAI regulations (India), and the Spam Act 2003 (Australia).
12) Single Sign-On
You can log in to our site using sign-in services such as Google or Microsoft Azure Cloud. These services will authenticate your identity and provide you the option to share certain personal information with us such as your name and email address to pre-populate our sign up form.13) Third-Party Sites
MobiWork.com may contain links to other web sites. MobiWork is not responsible for the privacy practices or the content of these other web sites. Customers and visitors will need to check the policy statement of these others web sites to understand their policies. Customers and visitors who access a linked site may be disclosing their private information. It is the responsibility of the user to keep such information private and confidential.14) Security
MobiWork utilizes industry-leading technology for Internet security, ensuring that your data is safe, secure, and available only to registered Users in your organization. We follow generally accepted industry standards to protect the personal and sensitive information submitted to us, both during transmission and once we receive it.Specific measures include:
- Encryption at rest: AES-256 encryption for all stored Customer data.
- Encryption in transit: TLS 1.2 or higher for all data transmitted between your devices and our servers.
- Access controls: Role-based access control (RBAC), principle of least privilege.
- Periodic third-party penetration testing.
- Incident response: Documented incident response plan with defined roles, escalation procedures, and a commitment to notify affected Clients of confirmed personal data breaches within 72 hours of discovery.
- Network security: Secure server environment with firewall and advanced technology to prevent interference or access from outside intruders. Network traffic is monitored to identify unauthorized attempts to add or change information or otherwise cause damage to the website.
- Employee training: mandatory privacy and security training for all staff handling personal data.
When you enter sensitive information (such as login credentials) or when we collect sensitive information (such as address information) on our order forms, site or within our mobile applications, we encrypt the transmission of that information using secure socket layer technology (SSL/TLS).
MobiWork provides each User in your organization with a unique user name and password that must be entered each time a User logs on. MobiWork issues a session cookie only to record encrypted authentication information for the duration of a specific session. The session cookie does not include either the username or password of the user.
No method of transmission over the Internet, or method of electronic storage, is 100% secure. Therefore, we cannot guarantee absolute security.
15) Security Incident Notification
In the event of a confirmed Security Incident involving Client Personal Data, MobiWork shall notify Client without undue delay — and in any event within 72 hours of becoming aware.Such notice may include:
- nature of the incident;
- categories of affected data;
- mitigation efforts;
- corrective actions.
MobiWork makes no representation that every attempted intrusion can be detected or prevented.
16) Settings & Account Controls
You have the ability to control the settings for yourself as well as other users of the platform. You may control the settings for notifications, forms, reports, customers, work orders, sales orders, tasks, activities, devices, payment options, and access. If you wish to change any of your settings, simply log in to your account and select the "Settings" tab.17) Protection of Children's Personal Information
MobiWork is a general audience site and does not knowingly collect any personal information from children under the age of 13. By participating in the registration process, all registrants represent that they are over the age of 18 or are under the direct supervision of a parent or guardian whenever using this site. If a child under 13 submits personal information to MobiWork and we learn that such personal information is the information of a child under 13, we will attempt to delete the information as soon as possible. If you believe we may have inadvertently collected information from a child under 13, please contact privacy@mobiwork.com immediately.18) California Privacy Rights
18.1 California Consumer Privacy Act (CCPA) & CPRA
If you are a California resident, you have the following rights under the California Consumer Privacy Act of 2018 (CCPA) as amended by the California Privacy Rights Act of 2020 (CPRA):
| CCPA / CPRA Right | Description | How to Exercise |
|---|---|---|
| Right to Know | Request disclosure of the categories and specific pieces of personal information collected, sources, purposes, and third parties with whom we share it. | Email privacy@mobiwork.com — Subject: CCPA Know Request |
| Right to Delete | Request deletion of personal information we have collected, subject to certain exceptions. | Email privacy@mobiwork.com — Subject: CCPA Delete Request |
| Right to Correct | Request correction of inaccurate personal information. | Email privacy@mobiwork.com — Subject: CCPA Correct Request |
| Right to Opt Out of Sale / Sharing | Opt out of the "sale" or "sharing" (for cross-context behavioral advertising) of your personal information. MobiWork does not sell or share personal information. | Automatic — no action needed as MobiWork does not sell or share PI for advertising |
| Right to Non-Discrimination | You will not receive discriminatory treatment for exercising any CCPA rights. MobiWork does not condition service on waiver of privacy rights. | Automatic — no action needed |
We will respond to verifiable CCPA requests within 45 days. We may extend this period by an additional 45 days where reasonably necessary, with prior notice. We do not charge a fee for reasonable requests, but may charge a reasonable fee for manifestly unfounded or excessive requests.
18.2 Shine the Light (California Civil Code Section 1798.83)
A California resident who has provided personal information to a business with whom he/she has established a business relationship for personal, family, or household purposes is entitled to request information about whether the business has disclosed personal information to any third parties for the third parties' direct marketing purposes. As stated in this Privacy Policy, MobiWork does not share personal information with third parties for their direct marketing purposes. Accordingly, MobiWork qualifies for the exception under California Civil Code Section 1798.83 and is not required to provide the disclosure described therein.
19) International & Regional Privacy Compliance
MobiWork's privacy practices are designed to support compliance with the following data protection frameworks:| Regulation | Jurisdiction | Key MobiWork Commitments |
|---|---|---|
| EU GDPR (2016/679) | European Union / EEA | DPA available, EU SCCs (fallback), DPF (primary), 72-hr breach notice, data subject rights tooling, GDPR-compatible lawful basis documentation |
| UK GDPR + DPA 2018 | United Kingdom | UK IDTA (fallback), UK Extension to the EU-U.S. DPF (primary), ICO registration, UK-specific DSR flows |
| Swiss FADP (revised) | Switzerland | Swiss-U.S. DPF, FDPIC notification support, Swiss-amended SCCs as fallback |
| CCPA / CPRA | California, USA | Right to know, delete, correct; opt-out of sale; no sale of PI; non-discrimination |
| PIPEDA | Canada | Consent management, breach reporting to Office of the Privacy Commissioner |
| CAN-SPAM Act | USA | Opt-out honored within 10 days, clear sender identification, no deceptive subjects |
| TCPA / TCIR | USA | Consent management for SMS/calls, STOP keyword processing, 10DLC compliance |
20) EU-U.S. Data Privacy Framework (DPF) & International Data Transfers
20.1 DPF Certification & Scope
MobiWork LLC complies with the EU-U.S. Data Privacy Framework (EU-U.S. DPF), the UK Extension to the EU-U.S. DPF, and the Swiss-U.S. Data Privacy Framework as set forth by the U.S. Department of Commerce regarding the collection, use, and retention of personal information transferred from the European Union (including Iceland, Liechtenstein, and Norway), the United Kingdom, and Switzerland to the United States. MobiWork has certified to the U.S. Department of Commerce that it adheres to the EU-U.S. Data Privacy Framework Principles ("DPF Principles") with regard to the processing of personal data received from the European Union and the United Kingdom in reliance on the EU-U.S. DPF and the UK Extension to the EU-U.S. DPF. MobiWork has also certified to the U.S. Department of Commerce that it adheres to the Swiss-U.S. Data Privacy Framework Principles (Swiss-U.S. DPF Principles) with regard to the processing of personal data received from Switzerland in reliance on the Swiss-U.S. DPF. If there is any conflict between the terms in this Privacy Policy and the DPF Principles, the DPF Principles shall govern. To learn more about the Data Privacy Framework Program (DPF Program), and to view our certification, please visit https://www.dataprivacyframework.gov/.
20.2 DPF Principles — How MobiWork Applies Them
| DPF Principle | How MobiWork Applies It |
|---|---|
| Notice | We inform individuals about our data practices through this Privacy Policy, in-product disclosures, and at the point of collection. We identify data types collected, purposes, third-party disclosures, and individual rights before or at the time of collection. |
| Choice | Individuals may opt out of: (1) disclosure of personal data to non-agent third parties; and (2) use for materially different purposes than originally collected. |
| Accountability for Onward Transfer | Before disclosing personal data to sub-processors or third-party controllers, we enter contracts requiring equivalent DPF-level protection. MobiWork remains liable if a downstream recipient processes data inconsistently with DPF Principles, except where we prove we bear no responsibility for the damage. |
| Security | We implement technical and organizational measures including AES-256 encryption at rest, TLS 1.2+ in transit, role-based access controls, SOC 2 Type II controls, and annual third-party penetration testing to protect personal data against loss, misuse, and unauthorized access. |
| Data Integrity & Purpose Limitation | We process personal data only in ways compatible with the purposes for which it was collected. We take reasonable steps to ensure data is accurate, complete, and current for its intended use. |
| Access | Individuals may access, correct, amend, or delete their personal data by contacting privacy@mobiwork.com. Requests are fulfilled within 30 days. Limited exceptions apply where access would harm others or conflict with legal obligations. |
| Recourse, Enforcement & Liability | See section 20.4 |
20.3 International Transfer Mechanisms
MobiWork's primary infrastructure is hosted in the United States. When personal data from the EEA, UK, or Switzerland is transferred to the U.S., MobiWork relies on the following mechanisms in order of priority:
- Primary — EU-U.S. DPF / UK Extension to the EU-U.S. DPF / Swiss-U.S. DPF: MobiWork's active certification covers all personal data received from these jurisdictions in connection with the Service.
- Fallback — Standard Contractual Clauses (SCCs): To the extent DPF certification is unavailable or invalidated, MobiWork relies on the European Commission's SCCs (Decision (EU) 2021/914, Module 2, Controller-to-Processor) for EEA transfers; the UK International Data Transfer Addendum (IDTA) for UK transfers; and Swiss-amended SCCs for Swiss transfers.
- Transfer Impact Assessment (TIA): MobiWork maintains a TIA covering U.S.-bound transfers, available to Clients upon written request to privacy@mobiwork.com.
- Sub-Processors: All sub-processors receiving personal data from Covered Jurisdictions are subject to DPF certification or SCCs. The sub-processor list is published at mobiwork.com/subprocessors.
20.4 Independent Recourse & Dispute Resolution
In compliance with the DPF Principles, MobiWork commits to resolve complaints about our collection or use of your personal information. EU, UK, and Swiss individuals with inquiries or complaints should first contact MobiWork at:
- Email: privacy@mobiwork.com
- Mail: MobiWork LLC, Attn: Privacy Team, 6501 Congress Avenue, Suite 330, Boca Raton, FL 33487, USA
MobiWork will respond within 45 days. If your complaint is not resolved to your satisfaction, the following no-cost escalation paths are available:
In compliance with the DPF Principles, MobiWork LLC commits to resolve DPF Principles-related complaints about your privacy and our collection or use of your personal information. European Union, United Kingdom, and Swiss individuals with inquiries or complaints regarding our handling of personal data in reliance on the DPF should first contact MobiWork LLC at: privacy@mobiwork.com.
MobiWork LLC has further committed to refer unresolved DPF Principles-related complaints to a U.S.-based independent dispute resolution mechanism, BBB NATIONAL PROGRAMS. If you do not receive timely acknowledgment of your complaint, or if your complaint is not satisfactorily addressed by us, please visit www.bbbprograms.org/dpf-complaints for more information and to file a complaint. This service is provided free of charge to you.
If your DPF complaint cannot be resolved through the above channels, under certain conditions, you may invoke binding arbitration for some residual claims not resolved by other redress mechanisms. See https://www.dataprivacyframework.gov/framework-article/ANNEX-I-introduction for more information on this process.
20.5 Sensitive Personal Data
Under the DPF, certain categories of personal data are treated as sensitive and require explicit opt-in consent. MobiWork treats the following as sensitive: health or medical information; financial account credentials; and racial or ethnic origin or religious beliefs (if voluntarily provided). MobiWork does not collect sensitive personal data as part of its standard Service and will only process such data where the individual has provided explicit, informed, opt-in consent or where required by law.
20.6 DPF Certification Lapse
If MobiWork's DPF certification lapses or is revoked for any reason, MobiWork will: (i) notify affected Clients within 90 business days; (ii) immediately activate Standard Contractual Clauses as the fallback transfer mechanism; and (iii) continue to apply DPF Principles to previously received personal data for as long as it is retained.
21) Changes to This Privacy Policy
We may update this privacy policy to reflect changes to our information practices. We encourage you to periodically review this page for the latest information on our privacy practices. Your continued use of the Service after the effective date of updates constitutes acceptance of the revised Policy.22) Feedback and Information
If you have any questions, comments, or suggestions about this Privacy Policy, or if you find any errors in our information about you, please contact our Privacy Officer at: privacy@mobiwork.com orMobiWork LLC
Attn: Privacy Officer
6501 Congress Avenue, Suite 330
Boca Raton, FL 33487 USA
If you reach out to us with any questions regarding the Personal Information we process on behalf of one of our Account Owners, we will forward your request to the Account Owner. We encourage you to review their applicable privacy policy. Any feedback you provide at this Web site shall be deemed to be non-confidential. MobiWork reserves the right to freely use such information on an unrestricted basis.