Summary: WorkBee is a field service management platform for UK trade businesses. We collect data to provide the service, we never sell it, and you can request deletion at any time. Contact us at
privacy@getworkbee.com.
1. Who we are
WorkBee is operated by Xymel Ltd, a company registered in England and Wales (Company No. 17252809). For the purposes of UK GDPR, Xymel Ltd is the data controller for data collected on this website and the WorkBee platform.
Contact: privacy@getworkbee.com
2. What data we collect
2.1 Account and business data
- Name, email address, and password (hashed) when you register
- Business name, trading address, VAT number, and company registration number
- Billing information (processed by Stripe — we do not store card numbers)
- Profile photo (if uploaded)
2.2 Service data you enter
When you use WorkBee to run your business, you enter data about your customers, jobs, invoices, certificates, and team members. This data belongs to you. We process it on your behalf as a data processor under UK GDPR Article 28.
2.3 Usage and analytics data
- Pages visited, features used, and session duration (with your consent, via Google Analytics 4)
- Error reports and crash data (via Sentry) to help us fix bugs
- Device type, browser, and approximate location (country/region)
- IP address (anonymised in analytics)
2.4 Communications
- Emails you send to our support address
- Feedback you submit through the platform
3. Legal basis for processing
- Contract performance — processing your account data and service data to deliver WorkBee to you
- Legitimate interests — security monitoring, fraud prevention, product improvement, and crash diagnostics
- Consent — analytics cookies (Google Analytics 4). You can withdraw consent at any time via the cookie banner or by emailing us
- Legal obligation — where we are required to retain data by law (e.g., financial records)
4. How we use your data
- To create and manage your WorkBee account and subscription
- To provide, maintain, and improve the WorkBee platform
- To send transactional emails (account activation, password reset, invoice notifications)
- To send product updates and announcements (you can unsubscribe at any time)
- To detect and prevent fraud, abuse, and security incidents
- To comply with legal and regulatory obligations
5. Who we share data with
We do not sell your data. We share it only with the following sub-processors to deliver the service:
- Supabase — database and authentication (EU data centres)
- Vercel — web application hosting (EU/UK edge)
- Resend — transactional email delivery
- Stripe — payment processing and subscription management
- GoCardless — Direct Debit collection
- Twilio — SMS notifications
- Mapbox — mapping and geocoding
- Sentry — error monitoring and crash reporting
- PostHog — product analytics (with your consent)
- Google Analytics — website analytics (with your consent)
- Anthropic / OpenAI — AI features (voice note transcription and structuring). Audio and text is processed transiently and not retained by these providers beyond the request
All sub-processors are bound by data processing agreements and comply with UK GDPR or provide adequate safeguards for international transfers.
6. How long we keep your data
- Account data — retained for the duration of your subscription plus 12 months after cancellation, then deleted
- Financial records — retained for 7 years to comply with UK tax law
- Analytics data — aggregated, anonymised, retained for 26 months (Google Analytics default)
- Error logs — retained for 90 days then automatically deleted (Sentry)
- Backups — retained for 30 days then automatically deleted
7. Your rights under UK GDPR
You have the right to:
- Access — request a copy of all personal data we hold about you
- Rectification — ask us to correct inaccurate data
- Erasure — ask us to delete your data ("right to be forgotten")
- Portability — receive your data in a machine-readable format
- Restriction — ask us to pause processing while a dispute is resolved
- Objection — object to processing based on legitimate interests
- Withdraw consent — withdraw analytics consent at any time via the cookie banner
To exercise any right, email privacy@getworkbee.com. We will respond within 30 days.
8. Cookies
We use cookies for authentication (essential) and analytics (with consent). See our Cookie Policy for full details.
9. Data security
We use industry-standard security measures including encryption in transit (TLS), encryption at rest, row-level security on all database tables, and role-based access controls. We conduct regular security reviews and monitor for vulnerabilities.
10. International transfers
Some of our sub-processors are based in the United States. Where data is transferred outside the UK, we ensure adequate safeguards are in place — either through the UK International Data Transfer Agreement (IDTA), Standard Contractual Clauses, or adequacy decisions.
11. Children
WorkBee is a business-to-business service and is not directed at children under 18. We do not knowingly collect data from children.
12. Complaints
If you have a concern about how we handle your data, please contact us first at privacy@getworkbee.com. If you are not satisfied, you have the right to lodge a complaint with the Information Commissioner's Office (ICO) at ico.org.uk or by calling 0303 123 1113.
13. Changes to this policy
We may update this policy from time to time. We will notify registered users of material changes by email at least 14 days before they take effect. The "Last updated" date at the top of this page always reflects the current version.