Last updated: 23 July 2026
This Privacy Policy (the “Policy”) describes the manner in which Proofly AS processes Personal Data in connection with the WorkID website, platform, and browser extension. It is issued in accordance with Regulation (EU) 2016/679 (the “GDPR”) as incorporated into Norwegian law by the Personal Data Act (personopplysningsloven). Capitalised terms have the meanings given to them in Section 2.
1.1 The controller responsible for the processing of Personal Data described in this Policy (the "Controller", "WorkID", "we", "us", or "our") is:
1.2 We have not appointed a statutory Data Protection Officer. All matters relating to data protection are handled through the contact address set out in Section 1.1.
2.1 In this Policy, unless the context requires otherwise:
3.1 This Policy applies to all Processing of Personal Data carried out by the Controller in connection with the Platform, and to all categories of Data Subject identified in Section 2.
3.2 Where an Employer independently determines the purposes and means of Processing Personal Data concerning its own personnel or applicants, that Employer acts as a separate and independent controller in respect of such Processing, and this Policy does not govern that activity.
3.3 The Platform may contain links to third-party websites and services. We are not responsible for the privacy practices of such third parties, and Data Subjects should review the relevant third-party notices.
4.1 We Process the following categories of Personal Data, according to how a Data Subject interacts with the Platform:
Name, email address, and (for password-based accounts) a cryptographically hashed password. Where authentication is performed via a third-party identity provider that you elect to use, we receive limited profile data from that provider in lieu of a password, together with the associated tokens required to maintain the connection.
Full name, professional headline, summary, location, citizenship, gender, relocation preferences, contact email and telephone number, LinkedIn URL, employment history, education, skills, languages, external links, and uploaded documents including diplomas and curriculum vitae. Certain fields may be generated by automated means from documents you submit; you may review, amend, or remove them at any time.
Where identity verification is undertaken, we and our verification Processor Process your legal full name, nationality, government-issued identity document data, biometric matching data as applicable, and the outcome of the verification, including status, review result, and any reject type or reject labels. We retain the verification outcome and a Processor reference identifier and do not retain complete copies of identity documents beyond the period necessary to complete and evidence the verification.
The contact details of Referees, the content of references provided, records of reference requests and related events, telephone verification records, and the resulting Trust Score together with the constituent signals used to derive it. The Processing of identity document data and other special category data (where applicable) is described in Section 6.
Company details, particulars of Employer Users and invitations, job postings, applications received, saved candidate lists, internal notes and comments on applications, and employer verification records.
Where paid features are used, a payment-provider customer identifier and transaction records. Full payment card details are collected and Processed directly by our payment Processor and are not stored on our systems.
IP address, device and browser characteristics, session identifiers, usage and interaction data, records of communications sent to you, and the delivery status of such communications.
The WorkID browser extension operates only on LinkedIn profile pages (linkedin.com). When you view a profile, the extension reads that profile's public URL and displayed name and transmits them to WorkID solely to look up and display the corresponding Trust Score and verification status, and we retain a record of each such check. The extension stores your WorkID session locally in browser storage so that you remain signed in. The extension does not read, collect, or transmit any other page content, browsing history, keystrokes, or data from non-LinkedIn sites. We do not sell data obtained through the extension, transfer it to third parties except as described in Section 7, or use it for advertising or any purpose unrelated to providing the verification features described above.
5.1 We Process Personal Data only where a lawful basis under Article 6 of the GDPR applies. The purposes of Processing and their corresponding legal bases are:
| Purpose of Processing | Legal basis (GDPR) |
|---|---|
| Creating and administering accounts, profiles, applications, and job postings, and otherwise providing the Platform. | Article 6(1)(b) — performance of a contract. |
| Verifying identity, telephone numbers, employers, and references, and calculating the Trust Score. | Article 6(1)(b); Article 6(1)(f) — legitimate interests in preventing fraud and impersonation; Article 9(2)(a) — explicit consent where special category data is involved. |
| Ensuring security, preventing and detecting fraud, and protecting users. | Article 6(1)(f) — legitimate interests; Article 6(1)(c) — legal obligation. |
| Processing payments for paid features. | Article 6(1)(b) — performance of a contract; Article 6(1)(c) — legal obligation (accounting). |
| Sending service communications and, where permitted, updates about the Platform. | Article 6(1)(f) — legitimate interests; Article 6(1)(a) — consent, where required. |
| Analysing and improving the Platform. | Article 6(1)(f) — legitimate interests. |
| Complying with legal obligations and establishing, exercising, or defending legal claims. | Article 6(1)(c) — legal obligation; Article 6(1)(f) — legitimate interests. |
5.2 Where we rely on legitimate interests, we have carried out a balancing assessment to ensure that such interests are not overridden by the interests or fundamental rights and freedoms of the Data Subject. Further details of that assessment are available on request.
6.1 To the extent that identity verification involves the Processing of special category data within the meaning of Article 9 of the GDPR, such Processing is carried out solely on the basis of the Data Subject's explicit consent, which may be withdrawn at any time without affecting the lawfulness of Processing carried out prior to withdrawal.
6.2 The Trust Score is generated by automated means from verification signals. It constitutes an indicator of the extent to which a profile has been verified and does not, in and of itself, produce legal effects concerning a Data Subject or similarly significantly affect a Data Subject within the meaning of Article 22 of the GDPR; all hiring decisions are made by Employers exercising independent human judgement. A Data Subject may request information about the signals contributing to the Trust Score and may contest a score that is based on inaccurate data by contacting us.
7.1 We do not sell Personal Data. We disclose Personal Data only to the categories of recipient set out below, and only to the extent necessary for the relevant purpose:
| Recipient / category | Role | Purpose of disclosure |
|---|---|---|
| Employers and Candidates | Controller / recipient | Displaying a Candidate’s profile and application to an Employer to whom the Candidate applies, and displaying employer verification status to Candidates. |
| Cloud hosting and database providers | Processor | Hosting and delivery of the Platform and its data. |
| Identity verification (KYC) provider | Processor | Verification of Candidate identity. |
| Payment services provider | Processor | Processing of payments for paid features. |
| Communications providers | Processor | Delivery of SMS verification codes and transactional and service email. |
| Third-party authentication providers | Independent controller | Authentication where the Data Subject elects to sign in via that provider. |
| Competent authorities and professional advisers | Recipient | Where required by law, or to establish, exercise, or defend legal claims. |
7.2 Each Processor is engaged under a written agreement that complies with Article 28 of the GDPR and requires the Processor to Process Personal Data only on our documented instructions and to implement appropriate technical and organisational measures.
8.1 We seek to Process Personal Data within the European Economic Area (the "EEA"). Where a Processor Processes Personal Data outside the EEA, such transfer is carried out only where an adequacy decision of the European Commission applies, or subject to appropriate safeguards within the meaning of Article 46 of the GDPR, including the European Commission's Standard Contractual Clauses, supplemented by additional measures where necessary.
8.2 A copy of the relevant safeguards may be obtained by contacting us at the address set out in Section 1.1.
9.1 We retain Personal Data only for as long as necessary to fulfil the purposes for which it was collected, including to satisfy any legal, accounting, or reporting requirements. In particular:
9.2 We may retain Personal Data for a longer period where required to comply with a legal obligation or where necessary for the establishment, exercise, or defence of legal claims.
10.1 Subject to the conditions and exceptions provided by the GDPR, a Data Subject has the right to:
10.2 A Data Subject may exercise these rights by contacting us at support@workid.ai. We will respond within the period prescribed by the GDPR. We may request information reasonably necessary to verify the identity of the requester.
10.3 A Data Subject has the right to lodge a complaint with a supervisory authority, in particular in the Member State of their habitual residence, place of work, or place of the alleged infringement. The competent supervisory authority in Norway is the Norwegian Data Protection Authority (Datatilsynet), www.datatilsynet.no.
11.1 We implement appropriate technical and organisational measures to ensure a level of security appropriate to the risk, including encryption of data in transit, hashing of authentication credentials, access controls, and the engagement of vetted Processors. Notwithstanding these measures, no method of transmission or storage is entirely secure, and we cannot guarantee absolute security.
11.2 In the event of a personal data breach likely to result in a risk to the rights and freedoms of Data Subjects, we will notify the competent supervisory authority and, where required, affected Data Subjects, in accordance with Articles 33 and 34 of the GDPR.
12.1 We use strictly necessary cookies to authenticate sessions and to preserve the security and integrity of the Platform, and we may use analytics technologies to understand how the Platform is used. Non-essential technologies are used only with consent where required, and may be managed through browser settings or any cookie controls we provide.
13.1 The Platform is intended for persons of working age who are at least 18 years old. We do not knowingly Process the Personal Data of children. Where we become aware that Personal Data of a child has been provided, we will delete it without undue delay.
14.1 We may amend this Policy from time to time. Where an amendment is material, we will update the "Last updated" date and, where appropriate, provide notice through the Platform or by email. Continued use of the Platform following the effective date of an amendment constitutes acceptance of the amended Policy.
15.1 Enquiries concerning this Policy or the Processing of Personal Data should be addressed to Proofly AS, Nedre Dalgate 56, 4013 Stavanger, Norway, or by email to support@workid.ai.