Privacy Policy — Works Nicely
works  nicely. ← Home
LEGAL

Privacy Policy

Effective date: 4 August 2026 · Last updated: 4 August 2026 · Version 1.0

In short

We collect the minimum data needed to run our website and applications: what you send us when you contact us or create an account, plus technical, usage and diagnostic data that keeps the products working. We use it to operate and improve our products — not to build advertising profiles. We do not sell personal data and we do not share it for targeted advertising. You can ask us for a copy of your data, ask us to correct or delete it, or withdraw your consent at any time.

We serve users in the United States, Canada, the United Kingdom, Australia, Germany and the wider EEA, and Japan. Section 13 sets out the additional rights and disclosures that apply in each of those places.

This summary is for convenience only. The sections below are the operative policy.

1. Who we are

This policy is issued by Works Nicely Ventures ("Works Nicely", "we", "us", "our"), a technology company based in Vietnam that designs, builds and operates mobile applications, SaaS platforms and applied AI products, and provides product and technology consulting.

For the personal data described in this policy, Works Nicely Ventures is the controller (the "business" under US state privacy laws, the "organisation" under Canadian law, the "APP entity" under Australian law, and the "personal information handling business operator" under Japanese law) — the party that decides why and how the data is processed.

Works Nicely Ventures

Registered office: 70 Nguyen Duc Canh, Tuong Mai, Hanoi, Vietnam

Privacy contact / Privacy Officer: hello@worksnicely.ventures

We have designated an individual accountable for privacy compliance, reachable at the address above. You may address any request, question or complaint to that address in English, and we will answer in English unless local law requires otherwise.

2. Scope of this policy

This policy applies to:

  • the website worksnicely.ventures and its subdomains;
  • the mobile and web applications published by Works Nicely Ventures that link to this policy; and
  • business communication with prospective clients, clients, partners and applicants.

This policy does not apply to:

  • Products we build for clients. When we develop or operate a product on a client's behalf, the client is the controller (or "business") for end-user data in that product and its own privacy notice governs. We act as a processor or service provider under a written agreement, only on the client's documented instructions, and we do not use that data for our own purposes.
  • Third-party services you reach from our products, including the Apple App Store and Google Play, which are governed by their own privacy policies.

Where an individual application collects data beyond what is described here, it publishes an app-specific privacy notice and store privacy label, and that notice prevails for the application concerned.

3. Personal data we collect

3.1 Data you give us

  • Enquiries and correspondence: your name, work email address, company, role, the content of your message, and any attachments you choose to send.
  • Account data (where an application offers accounts): email address, display name, authentication identifiers, and the settings or preferences you configure.
  • Content you create in an application: entries, files, notes or other material you save, with the metadata needed to sync and restore it.
  • Support and feedback: what you include in a support request, bug report or survey response.
  • Transaction data: purchase and subscription status, product identifiers, currency, country of purchase, and store receipts. Payments are processed by Apple or Google — we never receive your full payment card number.

3.2 Data collected automatically

  • Device and application data: device model, operating system and version, application version and build, language, region, time zone, screen characteristics, and pseudonymous installation or app-instance identifiers.
  • Usage data: events such as screens viewed, features used, session start and length, actions taken, and how you arrived at the product.
  • Diagnostics: crash reports, stack traces, error codes and performance traces.
  • Server and hosting logs: IP address, date and time of the request, requested resource, referrer, user agent and response status.

We do not seek to collect sensitive or special category data — such as data revealing health, biometrics, genetics, racial or ethnic origin, religious or philosophical beliefs, political opinions, trade union membership, sex life or sexual orientation, precise geolocation, government identifiers, or financial account credentials — and we ask that you do not send it unless we have specifically requested it. We do not collect precise location unless a specific application feature requires it, in which case we ask your permission first and you can withdraw it in your device settings. We do not collect "consumer health data" as defined by Washington's My Health My Data Act or comparable state laws.

3.3 Data from third parties

  • App stores: aggregated and per-transaction reporting on installations, subscriptions, refunds and ratings, and subscription entitlement status.
  • Service providers: analytics, crash reporting and infrastructure providers acting on our behalf, as listed in section 7.
  • Business sources: information you or your organisation makes publicly available, where relevant to a business relationship.

We do not buy personal data or contact lists, and we do not receive personal data from data brokers.

5. How we use personal data

This section is also our statement of the purposes of use required by Japanese law and the collection notice required by Australian law. We use personal data only for the purposes below, and will not use it for a materially different purpose without telling you and, where required, obtaining your consent.

  • To provide, operate, authenticate and maintain our website and applications.
  • To process purchases and subscriptions and to deliver the entitlements you paid for.
  • To diagnose crashes, investigate defects, and monitor performance, stability and availability.
  • To understand which features are used, so we can improve them and remove what does not work.
  • To communicate with you: service notices, security alerts, replies to enquiries, and — only with your consent where required — product updates.
  • To protect our products and users against fraud, abuse, spam and unauthorised access.
  • To comply with legal, accounting, tax and app-store obligations, and to establish, exercise or defend legal claims.

We do not use personal data to build advertising profiles, we do not engage in cross-context behavioural advertising, and we do not disclose personal data to third parties for their own marketing.

6. Cookies, SDKs and tracking technologies

Our website is a static, content-only site. It sets no advertising or cross-site tracking cookies and uses only the technical storage strictly necessary to deliver pages. Requesting a page necessarily transmits your IP address and user agent to our hosting provider, which records them in server logs (see section 9).

Web fonts. Our pages currently load typefaces from Google's font service, which means your IP address is transmitted to Google when a page loads. If you are in the EEA, the UK or Switzerland, you can avoid this by blocking third-party font requests in your browser.

Our applications do not use browser cookies but may use local device storage and pseudonymous SDK identifiers for the purposes in section 5.

Consent. Where we introduce analytics, measurement or marketing technologies that are not strictly necessary, we will request your consent before they are placed or read — as required by the EU ePrivacy rules and § 25 of the German TDDDG, the UK PECR, and comparable rules elsewhere — list them on this page, and let you change your choice at any time. Consent is never bundled with acceptance of these terms.

Opt-out preference signals. We honour the Global Privacy Control and comparable browser-level opt-out signals as a valid opt-out of sale, sharing and targeted advertising for the browser that sends them. Because we do not sell or share personal data, the signal does not change our processing, but we treat it as an instruction not to start. We also respect the App Tracking Transparency permission on Apple platforms and the advertising ID controls on Android.

7. Sharing and service providers

We do not sell personal data, and we do not share it for cross-context behavioural advertising. We have not done so in the preceding twelve months. We disclose personal data only in the circumstances below.

Recipient category Examples Purpose
Hosting and cloud infrastructure Google (Firebase Hosting, Google Cloud) Serving the website and application back ends; server logs
App distribution and payment processing Apple (App Store), Google (Google Play) Distributing applications, processing purchases, managing subscriptions and refunds
Product analytics and crash reporting The providers named in each application's privacy notice and store privacy label Measuring usage; diagnosing crashes and performance issues
Communication and business tools Email, calendar, document and helpdesk providers Receiving and answering enquiries; running the business
Professional advisers Accountants, auditors, lawyers Accounting, tax and legal advice

Every provider acting on our behalf is engaged under a written agreement that limits it to processing personal data on our instructions, requires appropriate security and confidentiality, restricts onward transfer, and prohibits use of the data for its own purposes — meeting the requirements for processors under the GDPR, service providers under US state privacy laws, and accountable outsourcing under Canadian, Australian and Japanese law.

We may also disclose personal data where legally required, to respond to a valid request from a competent authority, to enforce our Terms of Use, to protect the rights, safety or property of Works Nicely Ventures or others, or in connection with a merger, acquisition or transfer of assets — in which case we will notify you before your data becomes subject to a different privacy policy. Where the law allows, we will tell you about a government request for your data before responding.

8. International transfers

We operate from Vietnam and use providers whose infrastructure and support functions are located in other countries, principally the United States and the European Economic Area. Personal data may therefore be transferred to, stored in, or accessed from a country other than your own, including a country whose data protection law differs from the law where you live.

Where such a transfer happens, we apply a lawful transfer mechanism appropriate to the data and the destination:

  • EEA and Germany: the European Commission's Standard Contractual Clauses, supplemented by a transfer impact assessment and technical measures such as encryption; or another Chapter V mechanism, including an adequacy decision where one applies to the destination.
  • United Kingdom: the UK International Data Transfer Agreement or the UK Addendum to the SCCs.
  • Canada: contractual protections comparable to those we apply ourselves; we remain accountable for the data while it is with a service provider, and personal data may be accessible to foreign courts and law enforcement where the provider is located.
  • Australia: we take reasonable steps under APP 8 to ensure each overseas recipient handles personal information consistently with the Australian Privacy Principles, and we remain accountable for their acts.
  • Japan: before providing personal data to a third party in a foreign country we identify the country, make information about that country's personal data protection regime available, and confirm the measures the recipient takes to protect the data. A current summary is available on request from the contact in section 17.
  • Vietnam: the transfer impact assessment and record-keeping required by Vietnamese personal data protection law.

You may request further detail about the safeguards applied to a specific transfer, including a copy of the relevant clauses with commercial terms redacted.

9. How long we keep data

We keep personal data only as long as it serves the purpose it was collected for, then delete or irreversibly anonymise it. The periods below are our normal maximums; we keep data longer only where the law requires it or where it is needed for an active legal claim.

Category Retention
Account data and content you create While the account is active; deleted within 30 days of a verified deletion request, except backups which expire within 90 days
Enquiries and business correspondence Up to 24 months after our last exchange
Support tickets Up to 24 months after the ticket is closed
Crash reports and diagnostics Up to 90 days
Usage and analytics events Up to 14 months, in pseudonymised form
Web and application server logs Up to 30 days, other than entries retained for a security investigation
Consent and opt-out records For as long as needed to evidence compliance, and at least 24 months where Canadian or EU law requires proof of consent
Purchase, subscription and accounting records For the period required by applicable tax and accounting law

10. Security and breach response

We apply technical and organisational measures proportionate to the risk, including encryption in transit using TLS, encryption at rest by our infrastructure providers, least-privilege access control with multi-factor authentication for administrative accounts, separation of production and development environments, dependency and vulnerability monitoring, code review, logging of administrative access, and data minimisation and deletion by default. We assess our providers' security before engaging them.

No online service can be guaranteed to be completely secure. If a personal data breach occurs, we will assess it promptly and notify:

  • the competent EU or German supervisory authority within 72 hours, and affected individuals without undue delay, where the GDPR thresholds are met;
  • the UK Information Commissioner's Office on the same basis;
  • the Office of the Privacy Commissioner of Canada, the Commission d'accès à l'information du Québec where relevant, and affected individuals, where the breach creates a real risk of significant harm — and we keep records of all breaches for at least 24 months;
  • the Office of the Australian Information Commissioner and affected individuals under the Notifiable Data Breaches scheme, following an assessment completed within 30 days;
  • Japan's Personal Information Protection Commission and affected individuals, in the cases and within the deadlines the APPI prescribes;
  • US state attorneys general and affected residents as required by the applicable state breach notification statute; and
  • the competent Vietnamese authority as required by Vietnamese law.

To report a suspected vulnerability or breach, email hello@worksnicely.ventures. We will acknowledge within two business days and will not pursue good-faith security research.

11. Automated decisions and AI features

We do not make decisions about you based solely on automated processing that produce legal effects or similarly significantly affect you, and we do not carry out profiling for that purpose. This means the Quebec, GDPR and US state law rules on automated decision-making do not currently result in a decision you need to contest — if that ever changes, we will tell you beforehand, explain the logic and the main factors involved, and give you a route to human review.

Some applications include features that use AI models to generate suggestions or summaries. Where such a feature transmits your input to a model provider, the application says so at the point of use and the provider appears in section 7. We do not use your content to train general-purpose AI models unless we have described that use and obtained your consent where required, and our model providers are contractually barred from training on data we send them.

12. Your rights and choices

Subject to the law that applies to you, you have the right to:

  • Know and access — obtain confirmation of whether we process your personal data, learn the categories, sources, purposes and recipients, and receive a copy of the specific data we hold.
  • Correct — have inaccurate or incomplete data rectified.
  • Delete — have your data erased where we no longer have a valid ground to keep it.
  • Restrict or suspend — ask us to pause processing while a dispute about accuracy or legitimacy is resolved (including the "cease dissemination and de-index" right under Quebec law).
  • Object — object to processing based on legitimate interests, and to direct marketing at any time.
  • Port — receive the data you provided in a structured, commonly used, machine-readable format, or have it sent to another organisation where technically feasible.
  • Withdraw consent — at any time, without affecting processing already carried out lawfully.
  • Opt out — of any sale or sharing of personal data, of targeted advertising, and of profiling with significant effects. We do none of these, and we honour opt-out preference signals as described in section 6.
  • Non-discrimination — receive the same price and service quality whether or not you exercise a right.
  • Complain — to us, and to your data protection authority (see section 13).

12.1 How to exercise a right

Email hello@worksnicely.ventures stating which right you wish to exercise and which product it concerns. You may also submit a request through the in-app support link where an application provides one.

  • Verification. We may need to verify your identity before acting, and will request only what is necessary for that purpose. Data supplied for verification is used for nothing else and is deleted afterwards.
  • Authorised agents. You may use an authorised agent — including a parent or guardian, or an agent under a US state privacy law — where the law allows. We will ask for proof of authorisation and may still verify your identity directly.
  • Timing. We respond within 30 days. Where the law allows an extension — for example a further 45 days under California law or a further two months under the GDPR for complex requests — we will tell you within the initial period and explain why.
  • Cost. Exercising a right is free. We may charge a reasonable fee, or decline, only where a request is manifestly unfounded, excessive or repetitive, and we will explain our reasoning.
  • Appeals. If we refuse a request, we will tell you why and how to challenge it. Where a US state privacy law provides a right of appeal, you may appeal by replying to our decision within 60 days; we will decide the appeal within 45 days and, if we uphold the refusal, tell you how to complain to your state attorney general.

12.2 Choices you can make yourself

You can adjust or revoke device permissions in your operating system settings, turn off diagnostics sharing where an application offers that switch, manage or cancel subscriptions in your App Store or Google Play account, unsubscribe from any email we send using the link in the message, and delete your account from within the application where accounts are offered. Where lawful and practicable — for example when reading our website or reporting a bug — you may deal with us anonymously or under a pseudonym.

13. Region-specific disclosures

The rights in section 12 apply to everyone we can practically extend them to. The disclosures below add what specific laws require, and prevail over anything inconsistent elsewhere in this policy for people in the region concerned.

13.1 United States

United States

We comply with the state privacy laws that apply to us, including the California Consumer Privacy Act as amended by the CPRA and the comprehensive privacy laws of states such as Colorado, Connecticut, Delaware, Florida, Indiana, Iowa, Kentucky, Maryland, Minnesota, Montana, Nebraska, New Hampshire, New Jersey, Oregon, Rhode Island, Tennessee, Texas, Utah and Virginia.

  • Categories collected, sources, purposes and recipients are described in sections 3, 5 and 7. In California terms, we collect identifiers, internet or network activity information, commercial information (purchase and subscription records), and the content you choose to store.
  • No sale, no sharing, no targeted advertising. In the preceding twelve months we have not sold personal information, shared it for cross-context behavioural advertising, or used it for targeted advertising. We therefore have no "Do Not Sell or Share My Personal Information" mechanism to offer, but we honour opt-out preference signals as described in section 6.
  • Sensitive personal information. We do not collect it for the purpose of inferring characteristics, and we do not use or disclose it beyond the purposes permitted without a right to limit. Where a state requires opt-in consent for sensitive data, we obtain it before collecting.
  • Rights. Know, access, delete, correct, portability, opt out of sale/sharing/targeted advertising/profiling, limit use of sensitive information, non-discrimination, and appeal — see section 12. We do not offer financial incentives for personal information.
  • Minors. We do not knowingly sell or share the personal information of consumers under 16. See section 14 for our COPPA position.
  • Notice at collection. This policy, together with each application's store privacy label, is our notice at collection; it is provided at or before the point of collection.

13.2 Canada

Canada

We handle personal information in accordance with PIPEDA, the substantially similar provincial laws of Alberta, British Columbia and Quebec, and Quebec's Law 25.

  • Accountability. The individual accountable for our privacy compliance is reachable at hello@worksnicely.ventures. That is also the address for access, correction and complaint requests.
  • Consent. We obtain meaningful consent for the collection, use and disclosure of personal information, in a form appropriate to the sensitivity of the data, and you may withdraw it at any time subject to legal and contractual restrictions we will explain. Consent for profiling, tracking or identification technologies is requested separately and such technologies are off by default.
  • Quebec specifics. You have the rights of access, correction, portability, de-indexing and withdrawal described in section 12. Personal information is not disclosed outside Quebec without a privacy impact assessment confirming adequate protection. You may ask us to provide this policy and our responses in French, and we will do so.
  • Commercial email. Under CASL, we send commercial electronic messages only with your express or implied consent, always identify ourselves and provide a working unsubscribe mechanism honoured within 10 business days, and we keep records of consent.
  • Complaints. Contact us first. You may then complain to the Office of the Privacy Commissioner of Canada, or to the Commission d'accès à l'information du Québec, the Alberta or British Columbia Information and Privacy Commissioner, as applicable.

13.3 United Kingdom

United Kingdom
  • We process personal data under the UK GDPR and the Data Protection Act 2018, on the legal bases in section 4, and use of cookies or similar device storage follows the Privacy and Electronic Communications Regulations (PECR).
  • Our UK representative under Article 27 is identified in section 1.
  • Transfers out of the UK use the International Data Transfer Agreement or the UK Addendum, as described in section 8.
  • Marketing email is sent only with your consent, or on the soft opt-in basis PECR permits for existing customers, and every message carries an unsubscribe link.
  • You may complain to the Information Commissioner's Office (ico.org.uk) at any time, and you have a right to an effective judicial remedy.

13.4 Australia

Australia
  • We handle personal information in accordance with the Privacy Act 1988 (Cth) and the Australian Privacy Principles. This document is our openly available APP 1 privacy policy, and sections 3 and 5 are our APP 5 collection notice.
  • Anonymity. Where it is lawful and practicable, you may interact with us without identifying yourself (APP 2).
  • Overseas disclosure. We disclose personal information to overseas recipients as described in section 8, principally in Vietnam and the United States, and we take the reasonable steps APP 8 requires. You accept that an overseas recipient may not be subject to the Privacy Act, and we remain accountable for their handling of your information.
  • Government identifiers. We do not adopt, use or disclose government-related identifiers such as tax file numbers.
  • Direct marketing. You may opt out of direct marketing at any time (APP 7), and we comply with the Spam Act 2003 by sending commercial electronic messages only with consent, identifying ourselves, and including a functional unsubscribe facility.
  • Access, correction and complaints. Requests under APP 12 and APP 13 go to the contact in section 17 and are answered within 30 days. If you are not satisfied with our response, you may complain to the Office of the Australian Information Commissioner (oaic.gov.au). Notifiable breaches are handled as described in section 10.

13.5 Germany and the European Economic Area

Germany & EEA
  • We process personal data under the EU GDPR, and in Germany additionally under the Bundesdatenschutzgesetz (BDSG). Access to information stored on your device follows § 25 TDDDG (formerly TTDSG): anything beyond what is strictly necessary requires your prior consent.
  • Our EU representative under Article 27 is identified in section 1. We have not appointed a data protection officer because we do not meet the thresholds in Art. 37 GDPR or § 38 BDSG; the accountable contact in section 1 handles all data protection matters.
  • You have the rights in Articles 15 to 22 GDPR as set out in section 12, including the right to object under Art. 21 and the right to withdraw consent under Art. 7(3).
  • Right to lodge a complaint (Art. 77). You may complain to the supervisory authority of your habitual residence, place of work or the place of the alleged infringement. In Germany that is the data protection authority of the relevant federal state, or the Federal Commissioner for Data Protection and Freedom of Information. You also have the right to an effective judicial remedy and, under Art. 82, to compensation for damage caused by unlawful processing.
  • Where we rely on consent from a person under 16 in Germany, we obtain the authorisation of the holder of parental responsibility, as § 8(1) of the German implementation requires.

13.6 Japan

Japan
  • We handle personal information in accordance with the Act on the Protection of Personal Information (APPI) and the guidelines of the Personal Information Protection Commission ("PPC").
  • Purpose of use. Publicly announced in section 5. We will not use personal information beyond that scope without your consent, and we will notify you before changing it.
  • Provision to third parties. We provide personal information to third parties only as described in section 7 — that is, to entrusted service providers acting on our behalf and in the other cases the APPI permits without consent. We do not use the opt-out provision scheme, and we do not provide personal data to third parties for their own purposes.
  • Cross-border provision. Handled as described in section 8: we identify the destination country, make information about its data protection regime available, confirm the recipient's protective measures, and obtain your consent where the APPI requires it.
  • Requests about retained personal data. You may request disclosure (including in electronic form), correction, addition, deletion, suspension of use, or suspension of third-party provision, and disclosure of records of third-party provision. Send requests to the contact in section 17.
  • Security and supervision. We take the necessary and appropriate measures described in section 10 and supervise our employees and entrusted parties accordingly.
  • Complaints. Please contact us first; we handle complaints promptly. You may also contact the PPC (ppc.go.jp). Japanese-language correspondence is welcome and we will arrange a response in Japanese.

13.7 Vietnam

We process personal data in accordance with Vietnamese personal data protection law, including its requirements on consent, notice, purpose limitation, data subject rights, records of processing, impact assessment, and cross-border transfer. Vietnamese data subjects may exercise the rights in section 12 using the same contact route, and may complain to the competent Vietnamese authority.

13.8 Other jurisdictions

If the law of your country, state or province grants you rights beyond those described above, we will honour them to the extent they apply to our processing. Tell us which law you are relying on and we will treat your request accordingly.

14. Children's privacy

Unless an application's store listing states that it is designed for children and participates in the relevant App Store or Google Play family programme, our products are not directed at children and we do not knowingly collect personal data from a child below the applicable age without the verifiable consent of a parent or guardian.

Region Age below which parental consent is required
United States Under 13 (COPPA); we also apply extra care to users under 16
Canada Under 14 in Quebec; elsewhere, where the child cannot give meaningful consent
United Kingdom Under 13
Australia Under 15, unless the individual has the capacity to consent
Germany / EEA Under 16 in Germany; 13 to 16 depending on the member state
Japan Under 15

We do not knowingly sell or share the personal data of anyone under 16, we do not serve targeted advertising to children, and where a product is intended for children we design it to the applicable App Store, Google Play and age-appropriate design standards.

If you believe a child has provided us with personal data, contact hello@worksnicely.ventures and we will verify and delete it promptly.

15. App stores and external links

Our applications are distributed through the Apple App Store and Google Play. Those platforms collect their own data about downloads, purchases and device activity under their own privacy policies, over which we have no control. Each application also publishes a store privacy label describing the data types associated with it; that label and any app-specific notice should be read together with this policy.

Our website and applications may link to third-party websites and services. We are not responsible for their content or privacy practices, and we recommend reading their notices before providing personal data.

16. Changes to this policy

We may update this policy to reflect changes in our products, our service providers or the law. The current version is always published on this page with an updated effective date and version number, and we keep previous versions available on request.

If a change materially affects how we use personal data, we will give at least 14 days' notice before it takes effect — by notice on this website, an in-application message, or email where we hold your address — and, where the change requires it, we will ask for your consent rather than relying on your continued use.

17. How to contact us

For any question, request or complaint about privacy or personal data:

Works Nicely Ventures — Privacy Officer

Email: hello@worksnicely.ventures

Website: worksnicely.ventures

Postal address: 70 Nguyen Duc Canh, Tuong Mai, Hanoi, Vietnam

EU / UK representatives: as set out in section 1

We aim to resolve every concern directly and will acknowledge your message within two business days. If you are not satisfied with our response, you may complain to the authority named for your region in section 13.

See also our Terms of Use.