Who we are
WorkWiser (wiser.works) is a workspace for small service teams: time tracking, projects, invoicing, and a shared client inbox in one place. It is operated by Brainy Works Mimari Proje Stüdyosu LTD. ŞTİ. (trading as Brawo Studio, Türkiye), the data controller for the personal data described here. This policy explains what personal data we collect when you use WorkWiser, why we collect it, and the choices you have.
Questions about this policy or your data can be sent to hello@wiser.works.
What we collect
Account data. Your name, email address, and role inside your organization, provided when your workspace admin invites you or when you sign up.
Workspace content. The data your team creates while working: clients and contacts, projects, deliverables, time entries, invoices, comments, notifications, and uploaded files. This content belongs to your organization, not to us.
Connected email. If your team connects an email account (Google, Microsoft, or IMAP), WorkWiser syncs messages from that mailbox into your shared inbox and can send replies on its behalf. Connection happens through the provider’s own authorization flow; we store the resulting access credentials encrypted and you can disconnect an account at any time, which deletes its credentials.
Technical data. Server logs (including IP addresses), error reports, and anonymous usage analytics that help us keep the service fast and reliable.
How we use your data
- To provide the service: storing and displaying your workspace content, syncing connected mailboxes, generating invoices, and sending notifications you have asked for.
- To secure the service: authentication, fraud and abuse prevention, audit logging, and rate limiting.
- To improve the service: aggregate, privacy-respecting analytics and error monitoring.
- To communicate with you: transactional emails such as invitations, password resets, and notifications. We do not send marketing email without consent.
We never sell personal data, and we never use your workspace content for advertising.
Legal bases (GDPR)
Where the GDPR applies, we process personal data on these bases: performance of a contract (running your workspace), legitimate interests (security, preventing abuse, improving the service), and consent where required (for example, optional integrations you choose to connect). You can withdraw consent at any time.
Where your data lives
Your workspace database, authentication records, and uploaded files are hosted with Supabase in the European Union (AWS region eu-west-1, Ireland). Application hosting and content delivery run on Vercel and Cloudflare, whose edge networks operate globally; transactional email and error monitoring may involve processing outside the EU under standard contractual clauses with those providers.
Subprocessors
We use a small set of infrastructure providers to run WorkWiser:
- Supabase (database, authentication, file storage; EU region)
- Vercel (application hosting, content delivery, cookieless analytics)
- Cloudflare (DNS, security, and traffic filtering)
- Resend (transactional email delivery)
- Sentry (error monitoring)
If your team connects an email account, the relevant provider (Google, Microsoft, or your IMAP host) processes that mailbox under its own terms; WorkWiser only accesses it with the permissions you grant.
Cookies
WorkWiser uses essential cookies only: a session cookie that keeps you signed in. We do not use advertising or cross-site tracking cookies. Our usage analytics (Vercel Analytics) are cookieless and do not identify individual visitors.
Retention and deletion
Workspace content uses an archive-first model: records you archive are hidden but recoverable by your team. Your organization’s admins control its data. When an organization asks us to delete its workspace, we remove its content from production systems within 30 days, with encrypted backups expiring on their own rolling schedule. You can also ask us to delete your personal account data at any time.
Security
All traffic is encrypted in transit (TLS) and data is encrypted at rest. Every organization’s data is isolated with row-level security enforced by the database itself, and email credentials are stored encrypted. Access to production systems is restricted and audited.
Your rights
Depending on where you live, you may have the right to access, correct, export, restrict, object to the processing of, or delete your personal data. Write to us and we will respond within 30 days. If you are in the EU or EEA, you also have the right to lodge a complaint with your local supervisory authority.
Children
WorkWiser is a business tool and is not directed at children under 16. We do not knowingly collect personal data from children.
Changes to this policy
When we make material changes to this policy, we will update the date at the top and notify workspace admins by email or in the app before the changes take effect.