Privacy policy
GDPR-aligned privacy notice for SMS Work. This notice explains how we process personal data when you use our platform within the European Union and European Economic Area.
1. Data controller and contact
The data controller for personal data processed through this website and the SMS Work platform is SMS Work).
- Registered address: Available on request — contact us using the details on our Contact page.
- Privacy and data protection contact: privacy@smswork.site
- General contact: Contact form or support@smswork.site
2. Scope and roles
SMS Work is a business-to-business platform. SMS Work acts as the data controller for platform administration data (accounts, billing, security logs, and support communications). For operational data entered by customer organizations (workstation profiles, phone-number sessions, inbound SMS metadata, and earnings), organization administrators are typically independent controllers for their organization's users, while SMS Work may act as a processor on their documented instructions when hosting and operating the service.
Workstation users should contact their organization administrator first for access, correction, erasure, or export requests relating to day-to-day operational data.
3. Categories of personal data
- Identity and account data: name, email address, phone number, postal address, country, role, account status, and authentication metadata.
- Operational data: phone-number sessions, carrier and application selections, inbound SMS metadata, OTP extraction results, audit events, and usage timestamps.
- Billing data: earnings, invoices, payout account details (where enabled), payout requests, and payment transaction records.
- Technical and security data: IP addresses, device and browser identifiers, session and refresh-token metadata (stored hashed), push notification endpoints, and server logs.
- Communications: messages you send through our contact form, support correspondence, and transactional email delivery records.
We do not intentionally collect special categories of personal data (Article 9 GDPR).
4. Purposes and legal bases (Article 6 GDPR)
- Contract performance (Art. 6(1)(b)): providing accounts, authentication, phone-number workflows, reporting, billing, and support you request.
- Legitimate interests (Art. 6(1)(f)): securing the platform, preventing abuse, maintaining audit trails, improving reliability, and responding to contact inquiries — balanced against your rights.
- Legal obligation (Art. 6(1)(c)): tax, accounting, and regulatory record-keeping where applicable.
- Consent (Art. 6(1)(a)): optional browser push notifications and non-essential cookies where required by the ePrivacy Directive — you may withdraw consent at any time without affecting lawfully processed data before withdrawal.
5. Recipients and processors
We disclose personal data only where necessary to operate the service, including to:
- cloud infrastructure and database hosting providers;
- email delivery providers (platform SMTP or organization-configured SMTP);
- upstream OTP and telecommunications providers configured by each organization;
- payment, banking, or payout partners where billing features are used;
- professional advisers or authorities when required by law.
Processors are bound by written agreements with appropriate Article 28 GDPR terms. Organization data is logically isolated; access across organizations is prohibited by application policy except for documented platform operations required to host and support the service.
6. International transfers
Where personal data is transferred outside the European Economic Area, we rely on appropriate safeguards such as European Commission adequacy decisions or Standard Contractual Clauses (SCCs), together with supplementary measures where required by supervisory guidance.
7. Retention
We retain personal data only for as long as necessary for the purposes above, including:
- active account lifetime and a reasonable period after closure for disputes and security;
- administrator-configured purge windows for phone-number sessions and related messages;
- billing and audit records for statutory limitation and accounting periods;
- contact form submissions for up to 24 months unless a longer period is required to handle your request or defend legal claims.
8. Your rights under the GDPR
Subject to conditions in the GDPR, you have the right to:
- request access to your personal data (Art. 15);
- request rectification of inaccurate data (Art. 16);
- request erasure ("right to be forgotten") (Art. 17);
- request restriction of processing (Art. 18);
- data portability (Art. 20);
- object to processing based on legitimate interests (Art. 21);
- withdraw consent at any time where processing is consent-based (Art. 7(3)).
To exercise these rights, contact privacy@smswork.site or use our contact form (subject: Privacy and data rights). We respond within one month, extendable by two further months where permitted by Article 12(3) GDPR.
9. Right to lodge a complaint
You have the right to lodge a complaint with the competent data protection supervisory authority in your EU/EEA member state if you believe our processing infringes the GDPR. We encourage you to contact us first so we can address your concern promptly.
10. Cookies and similar technologies
We use strictly necessary cookies and similar technologies for authentication, CSRF protection, session security, and PWA functionality. Optional analytics or marketing cookies, if introduced, will be presented with granular consent controls in line with the ePrivacy Directive and national implementing laws.
11. Security
We implement appropriate technical and organizational measures including encryption of sensitive credentials, hashed authentication tokens, role-based access controls, rate limiting, structured audit logging, and data isolation boundaries between organizations.
12. Children
SMS Work is a business platform not directed at children under 16. We do not knowingly collect personal data from children. Contact us if you believe a child has provided personal data.
13. Automated decision-making
We do not use solely automated decision-making, including profiling, that produces legal or similarly significant effects within the meaning of Article 22 GDPR.
14. Changes to this notice
We may update this privacy policy to reflect product, legal, or regulatory changes. Material updates will be published on this page with a revised effective date. Where required by law, we will provide additional notice.