Privacy Notice
Last updated: 24 July 2026
Who we are and what this notice covers
Aworka is a cloud-based business management service provided by Tin Cloud Ltd (company number 12151399), whose registered office is Trevethan, The Avenue, Truro, England, TR1 1HR. This notice explains how we use and protect personal information when you visit aworka.com or use Aworka.
Tin Cloud Ltd is the data controller for information used to administer Aworka accounts, subscriptions, billing, security and support. When an Aworka subscriber enters information about their customers, staff or other contacts, the subscriber is normally the data controller and Tin Cloud Ltd processes that information on the subscriber's behalf.
Information we collect
Depending on how you use Aworka, we may process:
- Account and profile information, including business and contact names, postal and email addresses, telephone numbers, VAT registration number, invoice details and account preferences.
- Subscription and billing records, including invoices, payment status and references supplied by payment providers. We do not store full card or bank-account credentials.
- Information you send us in support requests and other communications.
- Authentication, security and technical information, such as password hashes, password-reset records, session information, IP addresses, browser information, application logs and audit information.
- Content entered into Aworka, including customer, job, estimate, invoice, payment, event and task information, uploaded files, notes and geographic coordinates derived from addresses.
- Information and credentials needed for integrations you choose to enable, such as email, SMS, payment, mapping, accounting and tax services.
We obtain this information from you, other authorised users of your account, the content you enter into Aworka, and services you choose to connect to Aworka. Our website and application use essential session cookies needed for functions such as sign-in and security. We do not currently use advertising or analytics cookies.
Why we use information
We use personal information to:
- Create and operate accounts, provide Aworka's features, collect subscription payments and deliver support.
- Authenticate users, protect accounts, investigate suspicious activity, maintain backups and keep the service reliable.
- Send service messages, including invoices, password-reset instructions and password-change notifications.
- Meet tax, accounting and other legal obligations, and establish or defend legal claims.
- Operate integrations and send information to third-party services when an authorised account user requests it.
- Develop, test, troubleshoot and improve Aworka, including controlled use of production-derived information where this is reasonably necessary.
Our lawful bases are performance of our contract with you, compliance with legal obligations, and our legitimate interests in operating, securing and improving Aworka and protecting our users and business. Where we act as a data processor, we rely on the subscriber's instructions and lawful basis. We do not use this information for direct marketing, profiling or decisions made solely by automated means that have legal or similarly significant effects.
Sharing information
We do not sell personal information. We disclose it only to service providers and integrations needed to operate Aworka or selected by an authorised user; to professional advisers where necessary; or where disclosure is required by law or needed to protect legal rights. Service providers may use information only for the relevant service and under appropriate contractual obligations.
Service providers and integrations
| Purpose | Provider | Use |
|---|---|---|
| Hosting and managed database | DigitalOcean | Aworka's application servers and primary database are in DigitalOcean's London region. |
| Cloud storage and backups | Amazon Web Services | Private storage for uploads, temporary imports and exports, and database backups in the London region. |
| Aworka email delivery | SparkPost | Delivery of account and service email and, where selected, email sent to your customers. |
| Connected email (optional) | Google, Microsoft, or your chosen SMTP provider | Sends email when you connect Gmail, Outlook or another mail server. |
| SMS delivery (optional) | Textlocal or Webex Interact | Sends text messages requested by an authorised account user. |
| Payment processing (optional) | GoCardless or PayPal | Processes payments and provides limited payment, mandate and status information to Aworka. |
| Address mapping and routing (optional) | Google Maps or Mapbox | Geocodes addresses and provides maps or routes when those features are used. |
| Accounting (optional) | Intuit QuickBooks Online | Exchanges accounting information when you connect a QuickBooks account. |
| Tax reporting (optional) | HM Revenue & Customs | Submits VAT or income-tax information through Making Tax Digital when requested. |
| Development and technical assistance | OpenAI | Assists authorised Tin Cloud developers with code analysis and troubleshooting. OpenAI is not integrated into the live Aworka service, but limited account, support or diagnostic information may be provided when investigating or developing the service. |
This list is your general authorisation for us to use these sub-processors. We will give reasonable notice of a material addition or replacement so that subscribers have an opportunity to object. If you configure your own provider, such as an SMTP service, you are responsible for assessing that provider.
International transfers
Aworka's application servers, primary database and backup storage are in the United Kingdom. Some providers or optional integrations may process information outside the UK. Where we are responsible for such a transfer, we use an applicable adequacy regulation or contractual safeguards such as the UK International Data Transfer Agreement or UK Addendum. Further information about relevant safeguards is available on request.
How long we keep information
We keep account information while an account is active and then only for as long as it is needed for the purposes described above. Current operational retention periods are:
- Access to an unconverted free trial normally ends one month after expiry. A suspended paid subscription is normally terminated after three months.
- Termination does not immediately erase every record. Account and operational data is ordinarily anonymised or deleted after a further retention period of up to two years, allowing account recovery, support, fraud prevention and the resolution of disputes.
- Subscription invoices and associated contact information are retained for seven years for tax, accounting and legal purposes.
- Temporary account-export archives are deleted after seven days. Their signed download links are short-lived.
- Daily database backups are automatically deleted after 365 days. Information deleted or anonymised in the live service may therefore remain in protected backups until the relevant backup expires. It will not normally be restored to the live service except for disaster recovery.
- Production-derived development copies are retained only while reasonably needed for development, testing or troubleshooting and are replaced or deleted when no longer required.
- Support communications and security or application logs are retained for only as long as reasonably necessary for support, service reliability, security and legal purposes.
You can ask us to close an account or erase information earlier. Some information may have to be retained where the law requires it or where it is needed to establish, exercise or defend legal claims.
Customer data entered by subscribers
Subscribers decide what customer information to enter and how long it is needed. Aworka includes tools to view, edit, export and anonymise customer records. Subscribers can configure automatic anonymisation periods separately for deleted customer and invoice records. Because financial reports depend on historical transactions, deleting a customer does not by itself immediately remove every linked record; anonymisation removes personal information while preserving the required accounting history.
Security
We use technical and organisational safeguards appropriate to the nature of the service and information processed. No internet service can guarantee absolute security, but Aworka's current protections include:
- HTTPS for the application, HTTP Strict Transport Security, and protective browser headers.
- Encrypted and signed application session cookies, marked HttpOnly and SameSite, together with per-form cross-site request forgery tokens and request-origin checks.
- One-way SCrypt hashing of Aworka account passwords. We cannot retrieve a user's original password.
- A requirement to enter the existing password before changing it from a signed-in account.
- An email to the account's registered address whenever its password is successfully changed, whether from within the account or through password recovery.
- Password-reset links sent only to the registered email address and valid for two hours.
- Role-based access controls and filtering of passwords from normal application logs.
- TLS connections with certificate verification between Aworka and its managed database.
- Private-key SSH administration with password authentication disabled, active host firewalls, and automatic operating-system security updates.
- Daily database backups transferred over TLS to private cloud storage in the AWS London region, encrypted at rest using AES-256 and automatically deleted after 365 days.
- Ongoing software maintenance and review of security practices.
The registered email account is part of Aworka's password-recovery security. Account holders should protect it with a strong, unique password and multi-factor authentication where their email provider offers it. Aworka users should also use a unique password, keep sign-in details confidential, sign out on shared devices, and tell us promptly about suspicious activity or an unexpected password-change email.
Your data-protection rights
Depending on the circumstances, you may have rights to be informed; access your personal information; correct inaccurate information; request erasure; restrict processing; receive information in a portable format; and object to processing based on legitimate interests. These rights are not absolute. For customer data entered by a subscriber, you should normally contact that subscriber first because they are the data controller.
We normally respond to a rights request within one month. We may ask for information needed to verify identity, and the law permits an extension in some complex cases. Account owners can also request an export containing account data in commonly used CSV files.
When we process data for subscribers
When Tin Cloud Ltd acts as a data processor, we will:
- Process personal information only on the subscriber's documented instructions, including instructions given through their configuration and use of Aworka, unless the law requires otherwise.
- Ensure people authorised to process it are bound by confidentiality.
- Maintain appropriate technical and organisational security measures.
- Impose equivalent data-protection obligations on sub-processors.
- Assist subscribers, taking account of the nature of the processing, with data-subject requests, security, breach notification and data-protection impact assessments.
- At the end of the service, delete or return personal information as requested, subject to legal retention duties and the normal expiry of protected backups.
- Provide information reasonably needed to demonstrate compliance with applicable processor obligations and permit audits on reasonable notice, subject to appropriate confidentiality and security controls.
- Inform the subscriber if, in our opinion, an instruction infringes applicable data-protection law.
Personal data breaches
If we discover a personal data breach affecting information we process for a subscriber, we will notify that subscriber without undue delay and provide reasonable assistance. Where Tin Cloud Ltd is the controller, we will notify the Information Commissioner's Office within 72 hours of becoming aware of a breach when the law requires it, and notify affected individuals without undue delay where the breach is likely to result in a high risk to them.
Changes to this notice
We review this notice regularly and will post revisions on this page. We will give account holders reasonable notice before a material change takes effect where appropriate.
Contact and complaints
To exercise a right, ask a privacy question or report a concern, contact:
- Email: privacy@tincloud.com
- The Contact button in Aworka
- Tin Cloud Ltd, Trevethan, The Avenue, Truro, England, TR1 1HR
You also have the right to complain to the UK Information Commissioner's Office. Details are available at ico.org.uk/make-a-complaint .