Privacy Policy
Effective 4 September 2026 · Contact: privacy@groupwork.cloud
Your Talent Pipeline is a succession and promotion-readiness application used by companies to plan who is ready for the next role at each of their locations. This policy explains what personal data flows through it, who is responsible for it, who else processes it, how long it is kept, and how to exercise rights over it.
1. Two different relationships
Most of the personal data in Your Talent Pipeline is about a customer's employees, and the customer decides what goes in and who may see it. For that data the customer organization is the controller and GroupWork LLC is the processor: we hold and process it on the customer's documented instructions and for no other purpose. We do not use it to build profiles, we do not use it to train models, and we do not sell or share it.
A smaller set of data is about the person holding a login — their email address, their name, their sign-in activity. For that, GroupWork LLC is the controller.
If you are an employee whose record appears in Your Talent Pipeline and you want to see, correct or remove it, your employer is the right first contact. We will support them in answering you, and Section 9 explains what to do if that route is not available to you.
2. Who we are
Your Talent Pipeline is published by GroupWork LLC, a Michigan limited liability company (“we”, “us”).
GroupWork LLC
2222 W. Grand River Ave Ste A
Okemos, MI 48864
United States
privacy@groupwork.cloud
3. What the application holds about tracked people
The record is deliberately narrow. A person tracked in a pipeline has:
- Identity within work — first and last name, the location they are assigned to, their level on the customer's ladder, and optionally an employee identifier if the customer chooses to use one.
- Readiness and assessment — how ready they are for the next role, a rating on the customer's talent grid, whether anything on file would block a promotion and the detail behind that, notes on what is holding them back and what is being done about it, follow-up dates.
- Retention-risk assessment — where the customer uses it, an indication that the person may be at risk of leaving, and notes about it. This is treated as a separately permissioned category inside the application.
- Relocation willingness — which locations, if any, the person would move to.
- Optional attachments — a photograph, and assessment documents in PDF form, where the customer chooses to use them.
- Lifecycle events — promotions, transfers and removals, with the date.
It does not hold home addresses, personal phone numbers, personal email addresses, date of birth, government identifiers, compensation, benefits, disciplinary files or performance-review history. That is a design constraint of the product, not a setting.
What a customer actually enters is the customer's decision. Customers are responsible for having a lawful basis for the data they put in, for telling their employees about it, and for not entering categories of data the product is not designed to hold.
4. What we hold about people who sign in
- Account data — email address, display name, and a password handled by our authentication provider. We never store a readable password.
- Position in the organization — where an account sits in the customer's structure and which permission set it has, which is what determines what it can see.
- Activity record — edits are recorded with the account that made them, the time, and which fields changed, so a customer can answer “who changed this”. For the sensitive categories the record deliberately holds field names and not values. Read access is not currently recorded.
- Technical error reports — when the application hits an unexpected error, a technical report (the error and stack trace, tied to an account identifier) is sent to Sentry so we can fix it. It carries no pipeline content.
One sign-in across applications. Your Talent Pipeline uses the same account system as other applications published by GroupWork LLC, so one set of credentials works across them. Your email address and display name are shared by that account system; the data inside each application is not. Being able to sign in does not grant access — access to Your Talent Pipeline is entitled separately, per account.
5. This website
This marketing website (yourtalentpipeline.com) sets no cookies, runs no analytics and loads no third-party scripts — it carries no JavaScript at all. Our hosting provider (Cloudflare) processes standard request metadata (IP address, user agent, requested URL) to serve pages and defend against attack, and its platform reports network-level connection errors back to itself. An IP address is personal data, and we are not pretending otherwise — the point is that none of it is joined to an account, used to identify or profile a visitor, or retained by us.
The application itself (app.yourtalentpipeline.com) sets no advertising cookies and carries no cross-site tracking. It stores your session in your browser so you stay signed in.
6. Who else processes the data
Personal data is processed only by the providers below, acting on our behalf. We do not sell data, and we do not share it for advertising. We disclose it otherwise only where legally required.
| Sub-processor | What it receives | Location |
|---|---|---|
| Supabase (Supabase Inc.) | The database and the authentication system: all pipeline records and account data | United States |
| Cloudflare (Cloudflare, Inc.) | Photographs (Cloudflare Images) and assessment documents (R2) — the file content and an opaque identifier only, never a name or an account. Also serves this site and the application. | United States |
| Resend (Resend, Inc.) | Recipient email address and the message body, for transactional account email such as password resets | United States |
| Sentry (Functional Software, Inc.) | Technical error reports tied to an account identifier. No pipeline content. | United States |
| Microsoft (Microsoft Corporation) | Off-machine storage for the nightly database backup, which is a full copy of the database. Storage only — Microsoft does not read or process the contents. | United States |
We will update this list before adding a sub-processor that processes customer personal data.
7. How long it is kept
- Active records are kept for as long as the customer's organization is active and the record is in the pipeline.
- Removed people are taken out of every view immediately and move to an archived list that an administrator can restore from, so an accidental removal is not final.
- Promotion counts survive the individual record as counts, without identifying anyone, so a location's history is not rewritten by turnover.
- The activity record is retained for the life of the customer organization, and entries survive the deletion of the person they refer to — an accountability record that vanishes with its subject is not one. A customer can ask us to purge it sooner.
- Account deletion is available from the account screen and carries a 30-day recoverable window before permanent erasure.
- Backups are the exception, and we would rather say so than imply otherwise. A nightly database backup is taken and kept for 30 days; beyond that, one snapshot per calendar month is retained indefinitely for disaster recovery. A record deleted from the live database therefore persists in a monthly snapshot taken before the deletion. Backups are never used to serve the application or to restore a single record; they exist only to rebuild the whole database after a loss. If you need a deletion propagated into backups, ask us and we will tell you honestly what is possible.
When a customer organization ends its relationship with us, its data is deleted or returned on request, per the Terms.
8. If something goes wrong
If we become aware of a security incident affecting personal data we hold, we will notify the affected customer organization without undue delay and within 72 hours of becoming aware, with what we know at the time: what happened, which data and roughly how many people are affected, what we are doing about it, and what we recommend the customer do. We will keep the customer updated as we learn more, and we will support them in meeting their own notification obligations. We will not wait until an investigation is complete to make the first notification.
Report a suspected problem to questions@groupwork.cloud.
9. Rights
Depending on where you live, you may have rights to access, correct, delete, restrict or object to the processing of your personal data, and to receive it in a portable form.
- If your record is in a customer's pipeline, ask your employer — they control that data. If you cannot reach them, or they do not respond, contact us at privacy@groupwork.cloud and we will route it and assist the controller.
- If it is about your login — your email, your name, your sign-in and activity record — contact privacy@groupwork.cloud directly.
We do not charge for this, and we do not require an account to ask. For requests about your own login data we will respond within 30 days. For a request about a record in a customer's pipeline, we will acknowledge you within 30 days and route it to that customer — the decision is theirs to make, because the data is theirs.
10. Security
Traffic runs over TLS; data at rest is encrypted by our providers; photographs and documents are served only through short-lived links re-checked against the requester's permissions; and who may see which categories of information is enforced in the database rather than in the interface. The Security page sets this out in full, including what we do not claim.
11. International transfers
Data is stored and processed in the United States. If you are in a region whose law restricts transfers out of it, tell us before you load data — we would rather say what we can and cannot support than have you find out afterwards.
12. Children
This is a workplace application, not directed to children, and it should not be used to hold records about anyone under 16.
13. Changes
If this policy changes materially we will update the effective date above and notify customer organizations. Continued use after a change means the updated policy applies.
14. Contact
Privacy questions and data requests: privacy@groupwork.cloud.
Everything else: questions@groupwork.cloud.
By post: GroupWork LLC, 2222 W. Grand River Ave Ste A, Okemos, MI 48864, USA.