Worka by Asistu Back to Worka

Privacy notice

Your information, explained properly.

This notice explains what Asistu Ltd does with personal information when you visit the Worka website, enquire, buy or use Worka. It also explains the different role we have when Worka handles information for your business.

The short version

We use information to provide, secure, support and improve Worka, administer your account and meet our legal duties. We do not sell personal information or use customer content to train general-purpose AI models. Important actions are designed to wait for your review.

Last updated: 14 August 2026Version 1.0Applies in the United Kingdom

1. Who we are

Worka is a trading name and service of Asistu Ltd, a company registered in England and Wales under company number 13279968 and VAT registration number GB479886892. Our registered office is 3 Frinton Court, Byron Road, London, England, NW7 4AE.

For questions or requests about personal information, email our privacy contact at hello@asistu.ai. We have not appointed a statutory data protection officer.

2. Our data-protection roles

When Asistu is the controller

Asistu decides why and how to use information needed to run our own business. This includes website and enquiry data, account contacts, onboarding and billing information, service administration, security records, support communications and our own business analytics.

When Asistu is the processor

When your Worka handles personal information contained in your emails, messages, files or instructions solely to perform jobs for your business, your business is normally the controller and Asistu is your processor. Our Data Processing Agreement applies to that processing. You remain responsible for giving people any privacy information required about your use of Worka and for having a lawful basis for the instructions and data you provide.

We may act as a controller for limited operational data arising from the service where we have our own legal purpose—for example billing, fraud prevention, security, legal claims and complying with law.

3. Information we collect

We obtain this information from you, authorised users, the systems you choose to send information through, payment and messaging providers, and automatically from your use of our websites and service. Customer content may contain information about your customers, prospects, staff and suppliers.

Sensitive information

Worka is not intended for special-category data, criminal-offence data or children’s data. Do not send that information unless we have expressly agreed the use case and appropriate safeguards in writing. Worka is for business users aged 18 or over.

4. Why we use information and our lawful bases

PurposeInformationLawful basis where Asistu is controller
Respond to enquiries and provide demonstrationsContact, business needs and communicationsSteps at your request before a contract; legitimate interests in responding to business enquiries
Create, configure, deliver and support WorkaAccount, onboarding, configuration, content, usage and support dataPerformance of our contract with an individual customer; legitimate interests in performing a business contract and delivering the service
Take payment and keep accounting recordsIdentity, billing, transaction and subscription dataContract; legal obligations; legitimate interests in collecting sums due
Secure, monitor and troubleshoot the serviceTechnical, audit, usage and limited content where necessaryLegitimate interests in protecting customers, Asistu and the service; legal obligations
Improve reliability and service designFeedback and aggregated or minimised usage dataLegitimate interests in improving Worka. We do not use customer content to train general-purpose AI models
Send service messages and requested communicationsContact, account and service dataContract and legitimate interests
Send optional marketingContact details and preferencesConsent where PECR requires it; otherwise legitimate interests, with a right to object
Handle disputes, enforce terms and comply with lawRelevant account, content, communications and logsLegal obligations and legitimate interests in establishing, exercising or defending legal claims

Where Asistu is your processor, we process customer personal data on your documented instructions under the DPA, rather than choosing a separate lawful basis for your purposes.

If information is required to enter into or perform the contract and you do not provide it, we may be unable to create or operate your Worka. We do not currently make decisions about you based solely on automated processing that produce legal or similarly significant effects.

5. AI processing and meaningful human review

Worka uses AI models to interpret instructions and prepare drafts, summaries, recommendations and actions. Customer content may be sent to approved model providers only as needed to provide the service. We configure business/API services so submitted content is not used to train providers’ general-purpose models, subject to the provider terms applying to our account.

AI output can be wrong. Worka is designed to place important external actions behind a customer review gate. You must carry out a genuine review before approving material that affects another person. Worka must not be used to make solely automated decisions with legal or similarly significant effects about individuals, including employment, credit, eligibility, healthcare or legal rights.

6. Who receives information

Access is limited to authorised Asistu personnel who need it for setup, support, maintenance, security or legal duties. We may share information with:

Our current service-provider register is at Sub-processors and service providers. We do not sell or rent personal information and do not share one customer’s content with another customer.

7. International transfers

Some suppliers may process information outside the UK. Where a restricted transfer takes place, we use a lawful transfer mechanism such as UK adequacy regulations, the UK International Data Transfer Agreement, or the UK Addendum to approved standard contractual clauses, together with a transfer risk assessment and supplementary safeguards where required. Supplier locations and the type of safeguard are summarised in our provider register.

8. How long we keep information

RecordTypical retention
Active customer content and configurationFor the subscription. Live customer environments are deleted or returned after termination in accordance with the DPA; residual backups expire within 30 days unless law requires preservation.
Onboarding sessions not completedNormally 90 days after the last activity.
Enquiries and walkthrough recordsNormally 24 months after the last meaningful contact.
Support records and operational logsNormally up to 24 months; shorter for routine logs where practical, longer where needed for an unresolved dispute or security incident.
Contracts, invoices and tax/accounting recordsNormally six years after the relevant financial year or contract ends.
Suppression recordsMinimal details retained as long as needed to honour an opt-out.

We may retain information longer where reasonably needed for legal claims, regulatory investigation, fraud or a legal preservation duty. When retention ends, we delete or irreversibly anonymise it.

9. How we protect information

We use measures appropriate to the risk, including separation of customer environments, access controls and least privilege, encryption in transit, encryption at rest where supported by the service, secret management, logging, backups, patching, supplier due diligence and incident response. Customer data is stored in a managed cloud database (Supabase) with row-level security so that one customer cannot access another customer’s data. Authentication is handled through secure email-based login with cryptographically verified passwords. No online system can be guaranteed completely secure. Customers must protect their accounts, devices, email and Telegram access and tell us promptly of suspected compromise.

10. Your rights

Depending on the circumstances, you may have the right to ask us for access to your personal information, correction, erasure, restriction, portability, or to object to processing. Where we rely on consent, you may withdraw it at any time without affecting earlier processing. You also have an absolute right to object to direct marketing.

Email hello@asistu.ai. We may need to verify your identity and clarify your request. We normally respond within one month. If your request concerns information a Worka customer controls, we may direct it to that customer and assist them as processor.

11. Cookies and direct marketing

The Worka marketing site does not currently use non-essential cookies or advertising trackers. The customer service application uses strictly necessary technologies for security, authentication, session restoration and payment processing. See our Cookie Notice.

We do not add you to marketing merely because you enquire or buy. If we send marketing, we follow the rules applying to the type of business contact and provide an easy opt-out. Sole traders and some partnerships receive the protections PECR gives to individual subscribers. Service and billing messages are not marketing.

12. Contact, complaints and changes

Contact Asistu Ltd at hello@asistu.ai or by post at 3 Frinton Court, Byron Road, London, England, NW7 4AE.

If you are unhappy with our response, you can complain to the Information Commissioner’s Office at ico.org.uk/make-a-complaint or telephone 0303 123 1113. We would appreciate the opportunity to address the issue first.

We may update this notice as Worka, our suppliers or the law changes. Material changes will be highlighted on this page and, where appropriate, notified to customers.