Privacy Policy
Effective date: 4 August 2026 · Last updated: 4 August 2026 · Version 1.0
In short
We collect the minimum data needed to run our website and applications: what you send us when you contact us or create an account, plus technical, usage and diagnostic data that keeps the products working. We use it to operate and improve our products — not to build advertising profiles. We do not sell personal data and we do not share it for targeted advertising. You can ask us for a copy of your data, ask us to correct or delete it, or withdraw your consent at any time.
We serve users in the United States, Canada, the United Kingdom, Australia, Germany and the wider EEA, and Japan. Section 13 sets out the additional rights and disclosures that apply in each of those places.
This summary is for convenience only. The sections below are the operative policy.
1. Who we are
This policy is issued by Works Nicely Ventures ("Works Nicely", "we", "us", "our"), a technology company based in Vietnam that designs, builds and operates mobile applications, SaaS platforms and applied AI products, and provides product and technology consulting.
For the personal data described in this policy, Works Nicely Ventures is the controller (the "business" under US state privacy laws, the "organisation" under Canadian law, the "APP entity" under Australian law, and the "personal information handling business operator" under Japanese law) — the party that decides why and how the data is processed.
Works Nicely Ventures
Registered office: 70 Nguyen Duc Canh, Tuong Mai, Hanoi, Vietnam
Privacy contact / Privacy Officer: hello@worksnicely.ventures
We have designated an individual accountable for privacy compliance, reachable at the address above. You may address any request, question or complaint to that address in English, and we will answer in English unless local law requires otherwise.
2. Scope of this policy
This policy applies to:
- the website worksnicely.ventures and its subdomains;
- the mobile and web applications published by Works Nicely Ventures that link to this policy; and
- business communication with prospective clients, clients, partners and applicants.
This policy does not apply to:
- Products we build for clients. When we develop or operate a product on a client's behalf, the client is the controller (or "business") for end-user data in that product and its own privacy notice governs. We act as a processor or service provider under a written agreement, only on the client's documented instructions, and we do not use that data for our own purposes.
- Third-party services you reach from our products, including the Apple App Store and Google Play, which are governed by their own privacy policies.
Where an individual application collects data beyond what is described here, it publishes an app-specific privacy notice and store privacy label, and that notice prevails for the application concerned.
3. Personal data we collect
3.1 Data you give us
- Enquiries and correspondence: your name, work email address, company, role, the content of your message, and any attachments you choose to send.
- Account data (where an application offers accounts): email address, display name, authentication identifiers, and the settings or preferences you configure.
- Content you create in an application: entries, files, notes or other material you save, with the metadata needed to sync and restore it.
- Support and feedback: what you include in a support request, bug report or survey response.
- Transaction data: purchase and subscription status, product identifiers, currency, country of purchase, and store receipts. Payments are processed by Apple or Google — we never receive your full payment card number.
3.2 Data collected automatically
- Device and application data: device model, operating system and version, application version and build, language, region, time zone, screen characteristics, and pseudonymous installation or app-instance identifiers.
- Usage data: events such as screens viewed, features used, session start and length, actions taken, and how you arrived at the product.
- Diagnostics: crash reports, stack traces, error codes and performance traces.
- Server and hosting logs: IP address, date and time of the request, requested resource, referrer, user agent and response status.
We do not seek to collect sensitive or special category data — such as data revealing health, biometrics, genetics, racial or ethnic origin, religious or philosophical beliefs, political opinions, trade union membership, sex life or sexual orientation, precise geolocation, government identifiers, or financial account credentials — and we ask that you do not send it unless we have specifically requested it. We do not collect precise location unless a specific application feature requires it, in which case we ask your permission first and you can withdraw it in your device settings. We do not collect "consumer health data" as defined by Washington's My Health My Data Act or comparable state laws.
3.3 Data from third parties
- App stores: aggregated and per-transaction reporting on installations, subscriptions, refunds and ratings, and subscription entitlement status.
- Service providers: analytics, crash reporting and infrastructure providers acting on our behalf, as listed in section 7.
- Business sources: information you or your organisation makes publicly available, where relevant to a business relationship.
We do not buy personal data or contact lists, and we do not receive personal data from data brokers.
4. Legal bases for processing
Where the EU GDPR (including in Germany), the UK GDPR, or another law requiring a legal basis applies, we rely on the following.
Where we rely on legitimate interests we have assessed that our interest does not override your rights and freedoms, and you may object at any time (section 12). Where we rely on consent, refusing or withdrawing it never affects your access to features that do not depend on it.
5. How we use personal data
This section is also our statement of the purposes of use required by Japanese law and the collection notice required by Australian law. We use personal data only for the purposes below, and will not use it for a materially different purpose without telling you and, where required, obtaining your consent.
- To provide, operate, authenticate and maintain our website and applications.
- To process purchases and subscriptions and to deliver the entitlements you paid for.
- To diagnose crashes, investigate defects, and monitor performance, stability and availability.
- To understand which features are used, so we can improve them and remove what does not work.
- To communicate with you: service notices, security alerts, replies to enquiries, and — only with your consent where required — product updates.
- To protect our products and users against fraud, abuse, spam and unauthorised access.
- To comply with legal, accounting, tax and app-store obligations, and to establish, exercise or defend legal claims.
We do not use personal data to build advertising profiles, we do not engage in cross-context behavioural advertising, and we do not disclose personal data to third parties for their own marketing.
8. International transfers
We operate from Vietnam and use providers whose infrastructure and support functions are located in other countries, principally the United States and the European Economic Area. Personal data may therefore be transferred to, stored in, or accessed from a country other than your own, including a country whose data protection law differs from the law where you live.
Where such a transfer happens, we apply a lawful transfer mechanism appropriate to the data and the destination:
- EEA and Germany: the European Commission's Standard Contractual Clauses, supplemented by a transfer impact assessment and technical measures such as encryption; or another Chapter V mechanism, including an adequacy decision where one applies to the destination.
- United Kingdom: the UK International Data Transfer Agreement or the UK Addendum to the SCCs.
- Canada: contractual protections comparable to those we apply ourselves; we remain accountable for the data while it is with a service provider, and personal data may be accessible to foreign courts and law enforcement where the provider is located.
- Australia: we take reasonable steps under APP 8 to ensure each overseas recipient handles personal information consistently with the Australian Privacy Principles, and we remain accountable for their acts.
- Japan: before providing personal data to a third party in a foreign country we identify the country, make information about that country's personal data protection regime available, and confirm the measures the recipient takes to protect the data. A current summary is available on request from the contact in section 17.
- Vietnam: the transfer impact assessment and record-keeping required by Vietnamese personal data protection law.
You may request further detail about the safeguards applied to a specific transfer, including a copy of the relevant clauses with commercial terms redacted.
9. How long we keep data
We keep personal data only as long as it serves the purpose it was collected for, then delete or irreversibly anonymise it. The periods below are our normal maximums; we keep data longer only where the law requires it or where it is needed for an active legal claim.
10. Security and breach response
We apply technical and organisational measures proportionate to the risk, including encryption in transit using TLS, encryption at rest by our infrastructure providers, least-privilege access control with multi-factor authentication for administrative accounts, separation of production and development environments, dependency and vulnerability monitoring, code review, logging of administrative access, and data minimisation and deletion by default. We assess our providers' security before engaging them.
No online service can be guaranteed to be completely secure. If a personal data breach occurs, we will assess it promptly and notify:
- the competent EU or German supervisory authority within 72 hours, and affected individuals without undue delay, where the GDPR thresholds are met;
- the UK Information Commissioner's Office on the same basis;
- the Office of the Privacy Commissioner of Canada, the Commission d'accès à l'information du Québec where relevant, and affected individuals, where the breach creates a real risk of significant harm — and we keep records of all breaches for at least 24 months;
- the Office of the Australian Information Commissioner and affected individuals under the Notifiable Data Breaches scheme, following an assessment completed within 30 days;
- Japan's Personal Information Protection Commission and affected individuals, in the cases and within the deadlines the APPI prescribes;
- US state attorneys general and affected residents as required by the applicable state breach notification statute; and
- the competent Vietnamese authority as required by Vietnamese law.
To report a suspected vulnerability or breach, email hello@worksnicely.ventures. We will acknowledge within two business days and will not pursue good-faith security research.
11. Automated decisions and AI features
We do not make decisions about you based solely on automated processing that produce legal effects or similarly significantly affect you, and we do not carry out profiling for that purpose. This means the Quebec, GDPR and US state law rules on automated decision-making do not currently result in a decision you need to contest — if that ever changes, we will tell you beforehand, explain the logic and the main factors involved, and give you a route to human review.
Some applications include features that use AI models to generate suggestions or summaries. Where such a feature transmits your input to a model provider, the application says so at the point of use and the provider appears in section 7. We do not use your content to train general-purpose AI models unless we have described that use and obtained your consent where required, and our model providers are contractually barred from training on data we send them.
12. Your rights and choices
Subject to the law that applies to you, you have the right to:
- Know and access — obtain confirmation of whether we process your personal data, learn the categories, sources, purposes and recipients, and receive a copy of the specific data we hold.
- Correct — have inaccurate or incomplete data rectified.
- Delete — have your data erased where we no longer have a valid ground to keep it.
- Restrict or suspend — ask us to pause processing while a dispute about accuracy or legitimacy is resolved (including the "cease dissemination and de-index" right under Quebec law).
- Object — object to processing based on legitimate interests, and to direct marketing at any time.
- Port — receive the data you provided in a structured, commonly used, machine-readable format, or have it sent to another organisation where technically feasible.
- Withdraw consent — at any time, without affecting processing already carried out lawfully.
- Opt out — of any sale or sharing of personal data, of targeted advertising, and of profiling with significant effects. We do none of these, and we honour opt-out preference signals as described in section 6.
- Non-discrimination — receive the same price and service quality whether or not you exercise a right.
- Complain — to us, and to your data protection authority (see section 13).
12.1 How to exercise a right
Email hello@worksnicely.ventures stating which right you wish to exercise and which product it concerns. You may also submit a request through the in-app support link where an application provides one.
- Verification. We may need to verify your identity before acting, and will request only what is necessary for that purpose. Data supplied for verification is used for nothing else and is deleted afterwards.
- Authorised agents. You may use an authorised agent — including a parent or guardian, or an agent under a US state privacy law — where the law allows. We will ask for proof of authorisation and may still verify your identity directly.
- Timing. We respond within 30 days. Where the law allows an extension — for example a further 45 days under California law or a further two months under the GDPR for complex requests — we will tell you within the initial period and explain why.
- Cost. Exercising a right is free. We may charge a reasonable fee, or decline, only where a request is manifestly unfounded, excessive or repetitive, and we will explain our reasoning.
- Appeals. If we refuse a request, we will tell you why and how to challenge it. Where a US state privacy law provides a right of appeal, you may appeal by replying to our decision within 60 days; we will decide the appeal within 45 days and, if we uphold the refusal, tell you how to complain to your state attorney general.
12.2 Choices you can make yourself
You can adjust or revoke device permissions in your operating system settings, turn off diagnostics sharing where an application offers that switch, manage or cancel subscriptions in your App Store or Google Play account, unsubscribe from any email we send using the link in the message, and delete your account from within the application where accounts are offered. Where lawful and practicable — for example when reading our website or reporting a bug — you may deal with us anonymously or under a pseudonym.
13. Region-specific disclosures
The rights in section 12 apply to everyone we can practically extend them to. The disclosures below add what specific laws require, and prevail over anything inconsistent elsewhere in this policy for people in the region concerned.
13.1 United States
United StatesWe comply with the state privacy laws that apply to us, including the California Consumer Privacy Act as amended by the CPRA and the comprehensive privacy laws of states such as Colorado, Connecticut, Delaware, Florida, Indiana, Iowa, Kentucky, Maryland, Minnesota, Montana, Nebraska, New Hampshire, New Jersey, Oregon, Rhode Island, Tennessee, Texas, Utah and Virginia.
- Categories collected, sources, purposes and recipients are described in sections 3, 5 and 7. In California terms, we collect identifiers, internet or network activity information, commercial information (purchase and subscription records), and the content you choose to store.
- No sale, no sharing, no targeted advertising. In the preceding twelve months we have not sold personal information, shared it for cross-context behavioural advertising, or used it for targeted advertising. We therefore have no "Do Not Sell or Share My Personal Information" mechanism to offer, but we honour opt-out preference signals as described in section 6.
- Sensitive personal information. We do not collect it for the purpose of inferring characteristics, and we do not use or disclose it beyond the purposes permitted without a right to limit. Where a state requires opt-in consent for sensitive data, we obtain it before collecting.
- Rights. Know, access, delete, correct, portability, opt out of sale/sharing/targeted advertising/profiling, limit use of sensitive information, non-discrimination, and appeal — see section 12. We do not offer financial incentives for personal information.
- Minors. We do not knowingly sell or share the personal information of consumers under 16. See section 14 for our COPPA position.
- Notice at collection. This policy, together with each application's store privacy label, is our notice at collection; it is provided at or before the point of collection.
13.2 Canada
CanadaWe handle personal information in accordance with PIPEDA, the substantially similar provincial laws of Alberta, British Columbia and Quebec, and Quebec's Law 25.
- Accountability. The individual accountable for our privacy compliance is reachable at hello@worksnicely.ventures. That is also the address for access, correction and complaint requests.
- Consent. We obtain meaningful consent for the collection, use and disclosure of personal information, in a form appropriate to the sensitivity of the data, and you may withdraw it at any time subject to legal and contractual restrictions we will explain. Consent for profiling, tracking or identification technologies is requested separately and such technologies are off by default.
- Quebec specifics. You have the rights of access, correction, portability, de-indexing and withdrawal described in section 12. Personal information is not disclosed outside Quebec without a privacy impact assessment confirming adequate protection. You may ask us to provide this policy and our responses in French, and we will do so.
- Commercial email. Under CASL, we send commercial electronic messages only with your express or implied consent, always identify ourselves and provide a working unsubscribe mechanism honoured within 10 business days, and we keep records of consent.
- Complaints. Contact us first. You may then complain to the Office of the Privacy Commissioner of Canada, or to the Commission d'accès à l'information du Québec, the Alberta or British Columbia Information and Privacy Commissioner, as applicable.
13.3 United Kingdom
United Kingdom- We process personal data under the UK GDPR and the Data Protection Act 2018, on the legal bases in section 4, and use of cookies or similar device storage follows the Privacy and Electronic Communications Regulations (PECR).
- Our UK representative under Article 27 is identified in section 1.
- Transfers out of the UK use the International Data Transfer Agreement or the UK Addendum, as described in section 8.
- Marketing email is sent only with your consent, or on the soft opt-in basis PECR permits for existing customers, and every message carries an unsubscribe link.
- You may complain to the Information Commissioner's Office (ico.org.uk) at any time, and you have a right to an effective judicial remedy.
13.4 Australia
Australia- We handle personal information in accordance with the Privacy Act 1988 (Cth) and the Australian Privacy Principles. This document is our openly available APP 1 privacy policy, and sections 3 and 5 are our APP 5 collection notice.
- Anonymity. Where it is lawful and practicable, you may interact with us without identifying yourself (APP 2).
- Overseas disclosure. We disclose personal information to overseas recipients as described in section 8, principally in Vietnam and the United States, and we take the reasonable steps APP 8 requires. You accept that an overseas recipient may not be subject to the Privacy Act, and we remain accountable for their handling of your information.
- Government identifiers. We do not adopt, use or disclose government-related identifiers such as tax file numbers.
- Direct marketing. You may opt out of direct marketing at any time (APP 7), and we comply with the Spam Act 2003 by sending commercial electronic messages only with consent, identifying ourselves, and including a functional unsubscribe facility.
- Access, correction and complaints. Requests under APP 12 and APP 13 go to the contact in section 17 and are answered within 30 days. If you are not satisfied with our response, you may complain to the Office of the Australian Information Commissioner (oaic.gov.au). Notifiable breaches are handled as described in section 10.
13.5 Germany and the European Economic Area
Germany & EEA- We process personal data under the EU GDPR, and in Germany additionally under the Bundesdatenschutzgesetz (BDSG). Access to information stored on your device follows § 25 TDDDG (formerly TTDSG): anything beyond what is strictly necessary requires your prior consent.
- Our EU representative under Article 27 is identified in section 1. We have not appointed a data protection officer because we do not meet the thresholds in Art. 37 GDPR or § 38 BDSG; the accountable contact in section 1 handles all data protection matters.
- You have the rights in Articles 15 to 22 GDPR as set out in section 12, including the right to object under Art. 21 and the right to withdraw consent under Art. 7(3).
- Right to lodge a complaint (Art. 77). You may complain to the supervisory authority of your habitual residence, place of work or the place of the alleged infringement. In Germany that is the data protection authority of the relevant federal state, or the Federal Commissioner for Data Protection and Freedom of Information. You also have the right to an effective judicial remedy and, under Art. 82, to compensation for damage caused by unlawful processing.
- Where we rely on consent from a person under 16 in Germany, we obtain the authorisation of the holder of parental responsibility, as § 8(1) of the German implementation requires.
13.6 Japan
Japan- We handle personal information in accordance with the Act on the Protection of Personal Information (APPI) and the guidelines of the Personal Information Protection Commission ("PPC").
- Purpose of use. Publicly announced in section 5. We will not use personal information beyond that scope without your consent, and we will notify you before changing it.
- Provision to third parties. We provide personal information to third parties only as described in section 7 — that is, to entrusted service providers acting on our behalf and in the other cases the APPI permits without consent. We do not use the opt-out provision scheme, and we do not provide personal data to third parties for their own purposes.
- Cross-border provision. Handled as described in section 8: we identify the destination country, make information about its data protection regime available, confirm the recipient's protective measures, and obtain your consent where the APPI requires it.
- Requests about retained personal data. You may request disclosure (including in electronic form), correction, addition, deletion, suspension of use, or suspension of third-party provision, and disclosure of records of third-party provision. Send requests to the contact in section 17.
- Security and supervision. We take the necessary and appropriate measures described in section 10 and supervise our employees and entrusted parties accordingly.
- Complaints. Please contact us first; we handle complaints promptly. You may also contact the PPC (ppc.go.jp). Japanese-language correspondence is welcome and we will arrange a response in Japanese.
13.7 Vietnam
We process personal data in accordance with Vietnamese personal data protection law, including its requirements on consent, notice, purpose limitation, data subject rights, records of processing, impact assessment, and cross-border transfer. Vietnamese data subjects may exercise the rights in section 12 using the same contact route, and may complain to the competent Vietnamese authority.
13.8 Other jurisdictions
If the law of your country, state or province grants you rights beyond those described above, we will honour them to the extent they apply to our processing. Tell us which law you are relying on and we will treat your request accordingly.
14. Children's privacy
Unless an application's store listing states that it is designed for children and participates in the relevant App Store or Google Play family programme, our products are not directed at children and we do not knowingly collect personal data from a child below the applicable age without the verifiable consent of a parent or guardian.
We do not knowingly sell or share the personal data of anyone under 16, we do not serve targeted advertising to children, and where a product is intended for children we design it to the applicable App Store, Google Play and age-appropriate design standards.
If you believe a child has provided us with personal data, contact hello@worksnicely.ventures and we will verify and delete it promptly.
15. App stores and external links
Our applications are distributed through the Apple App Store and Google Play. Those platforms collect their own data about downloads, purchases and device activity under their own privacy policies, over which we have no control. Each application also publishes a store privacy label describing the data types associated with it; that label and any app-specific notice should be read together with this policy.
Our website and applications may link to third-party websites and services. We are not responsible for their content or privacy practices, and we recommend reading their notices before providing personal data.
16. Changes to this policy
We may update this policy to reflect changes in our products, our service providers or the law. The current version is always published on this page with an updated effective date and version number, and we keep previous versions available on request.
If a change materially affects how we use personal data, we will give at least 14 days' notice before it takes effect — by notice on this website, an in-application message, or email where we hold your address — and, where the change requires it, we will ask for your consent rather than relying on your continued use.
17. How to contact us
For any question, request or complaint about privacy or personal data:
Works Nicely Ventures — Privacy Officer
Email: hello@worksnicely.ventures
Website: worksnicely.ventures
Postal address: 70 Nguyen Duc Canh, Tuong Mai, Hanoi, Vietnam
EU / UK representatives: as set out in section 1
We aim to resolve every concern directly and will acknowledge your message within two business days. If you are not satisfied with our response, you may complain to the authority named for your region in section 13.
See also our Terms of Use.