WorkCurrent AI Privacy Policy
Effective date: July 23, 2026
This Privacy Policy explains how WorkCurrent AI Inc. ("WorkCurrent," "we," "us," or "our") collects, uses, discloses, retains, and protects personal information in connection with:
- the WorkCurrent AI application made available through the monday.com marketplace;
- the WorkCurrent platform and Claire AI features;
- our website at workcurrent.ai;
- support, sales, onboarding, and business communications; and
- other WorkCurrent products or services that link to this Privacy Policy.
WorkCurrent AI Inc. is a Canadian federal corporation with offices at 150 King St. W, Suite 200, Toronto, Ontario, M5H 1J9, Canada.
The Service is intended for business use by adults. It is not intended for personal, family, household, or consumer use.
1. Our privacy roles
WorkCurrent processes different information in different roles.
Customer Data
When a business customer connects its CRM, boards, communications, meeting information, or other systems to WorkCurrent, the customer generally determines why and how that information is used. For that information, WorkCurrent generally acts as a processor, service provider, or contractor on the customer's behalf. The customer is responsible for providing required notices, obtaining required consents, responding to requests concerning the customer's own records, and ensuring that its use of WorkCurrent complies with applicable law.
WorkCurrent business data
WorkCurrent acts independently when it processes information for its own account administration, website operations, product security, billing administration, support, sales, legal compliance, and business communications.
If a signed data processing addendum applies, it controls to the extent of a conflict concerning the processing of Customer Data.
2. Information we collect
The information we collect depends on how a person interacts with WorkCurrent and which integrations or features a customer enables.
2.1 Account and user information
We may collect:
- name, work email address, telephone number, job title, employer, and business contact details;
- user, account, workspace, and organization identifiers;
- administrator, installer, billing, subscription, and plan information;
- authentication, authorization, and session information;
- support messages, feedback, training participation, and other communications with us; and
- preferences, settings, and consent records.
2.2 monday.com and CRM information
When a customer connects monday.com, we may access and process the boards, workspaces, fields, items, subitems, updates, activities, tasks, contacts, leads, accounts, opportunities, deals, owners, values, notes, files, and other CRM information that the customer authorizes through the permissions granted to the application.
The marketplace application is designed to read connected information when needed and write authorized outputs back to monday.com. We do not maintain a complete standing copy of the customer's CRM. We may store limited identifiers, selected fields, configuration information, context, generated insights, operational history, and other information reasonably necessary to provide and support enabled features.
2.3 Company and sales-process context
We may collect information supplied during onboarding or setup, including:
- company, product, service, buyer, market, and competitor information;
- sales stages, qualification rules, forecast categories, playbooks, approved responses, and operating procedures;
- customer-defined fields, workflows, business rules, and reporting preferences; and
- other answers provided to build the customer's Adaptive Deal Mind or account-specific context.
2.4 Meeting and communications information
Depending on the connected services and enabled features, we may process:
- meeting titles, dates, attendees, and calendar information;
- transcripts, summaries, notes, action items, and key moments created by monday.com NoteTaker or another connected service;
- business emails, messages, and related metadata where a customer has enabled that integration;
- call and meeting metadata; and
- drafts, follow-ups, tasks, proposals, quotes, and other outputs created through the Service.
At launch, the monday.com marketplace application is designed to process meeting transcripts and summaries made available by connected services rather than independently creating a biometric voiceprint or facial-recognition profile.
2.5 AI-generated and inferred information
WorkCurrent may generate or infer:
- deal-health, qualification, risk, and priority scores;
- stakeholder roles, influence, engagement, relationship maps, and buying-group assessments;
- objections, competitors, commitments, concerns, and recommended next actions;
- coaching observations, call-review results, and manager toolkits;
- text-based sentiment and engagement signals;
- conversation-adjusted probabilities, pipeline views, and forecast recommendations; and
- summaries, drafts, CRM updates, and other AI-assisted content.
These inferences may relate to identifiable business contacts or Authorized Users and may be treated as personal information under applicable law.
2.6 Technical and usage information
We may collect:
- IP address, browser and device type, operating system, language, and approximate location derived from IP address;
- application events, feature usage, timestamps, error information, and performance data;
- authentication and security logs;
- support diagnostics and integration status; and
- website referral and interaction information collected through cookies or similar technologies.
We seek to avoid including Customer Data or secrets in application logs except where necessary for support or security, and we limit access to logs according to role and need.
3. Sources of information
We collect information:
- directly from users, administrators, prospects, and customers;
- from monday.com and other services a customer chooses to connect;
- from other Authorized Users within the same customer account;
- automatically when a person uses our website or Service;
- from marketplace subscription and account information provided by monday.com; and
- from business partners, referrals, public business sources, or service providers where permitted by law.
4. How we use information
We use information to:
- provide, configure, personalize, and operate the Service;
- authenticate users and administer accounts and permissions;
- access and synchronize connected data as directed by the customer;
- create AI-assisted insights, coaching, summaries, recommendations, forecasts, drafts, and CRM updates;
- maintain account-specific context and organizational memory;
- provide onboarding, support, training, and customer success;
- process and administer marketplace subscriptions and plan entitlements;
- monitor reliability, troubleshoot errors, prevent abuse, and protect security;
- understand product usage and improve performance and usability;
- communicate about installation, service operation, security, billing, support, and material changes;
- send marketing communications where permitted and honour opt-out choices;
- enforce agreements, protect rights, and comply with legal obligations; and
- create aggregated or de-identified analytics that do not reasonably identify a customer or individual.
We do not sell Customer Data or personal information. We do not disclose Customer Data or personal information for cross-context behavioural advertising.
5. AI processing and model training
WorkCurrent uses artificial intelligence providers to process the relevant content needed to produce an enabled output. This may include selected CRM fields, company context, transcript text, meeting summaries, notes, and previous account-specific information.
WorkCurrent does not use Customer Data to train generalized or cross-customer AI models. We also configure and contract with our AI providers so that Customer Data submitted through the Service is not used by those providers to train their generalized models, where the provider offers that business or API protection.
When WorkCurrent says that the system learns from prior conversations, this refers to account-specific retrieval, memory, structured context, playbook updates, or similar personalization for that customer. It does not mean that one customer's confidential content is used to train a model for another customer.
WorkCurrent may use aggregated or de-identified telemetry to improve the Service, provided that it does not reasonably identify a customer or individual and is not re-identified.
AI outputs are probabilistic and may be wrong. Customers and users should review outputs before relying on them, sending them, or using them to update a CRM. Some features require user approval before a write occurs; others may perform an action automatically if an administrator expressly enables that configuration.
6. Text analysis, sentiment, and biometrics
The current marketplace Service may infer sentiment, engagement, objections, and deal risk from the text of CRM records, notes, transcripts, and communications.
WorkCurrent does not create a biometric voiceprint, facial-recognition template, or other biometric identifier from meeting content. The current marketplace Service does not analyze facial expressions for identity or emotion recognition. If we introduce materially different audio, video, emotion-recognition, or biometric functionality, we will update this Privacy Policy and provide any notices or choices required by law.
7. How we disclose information
We disclose information only as reasonably necessary for the following purposes.
7.1 Customer and Authorized Users
Information and outputs may be visible to Customer administrators and Authorized Users according to the customer's monday.com permissions, WorkCurrent configuration, and connected-service permissions.
7.2 monday.com and connected services
We exchange information with monday.com and other services a customer chooses to connect so that WorkCurrent can read authorized information, display outputs, and perform authorized writes or actions.
7.3 Service providers and subprocessors
We use service providers for functions such as cloud hosting, storage, artificial intelligence, authentication, email delivery, error monitoring, logging, security, support, and business administration. These providers receive only the information reasonably necessary for their function and are subject to contractual or other appropriate obligations.
Current key services include:
- monday.com - application platform, marketplace subscription administration, authentication or session context, CRM data access, and, where enabled, monday.com NoteTaker or monday AI functionality;
- OpenAI - artificial intelligence processing used to generate or assist with certain WorkCurrent outputs; and
- other cloud hosting, database, authentication, monitoring, and support providers identified in our current subprocessor list.
The current list of subprocessors and relevant third-party domains is available at https://workcurrent.ai/policies/subprocessors. The list may be updated as our providers change.
7.4 Personnel and shared-service providers
Authorized WorkCurrent employees, contractors, affiliates, and shared-service personnel may access information where necessary to provide, secure, support, or improve the Service. Access is limited according to role and need, and personnel are subject to confidentiality obligations.
7.5 Legal, safety, and corporate transactions
We may disclose information where reasonably necessary to:
- comply with law, legal process, or a binding government request;
- investigate fraud, abuse, security incidents, or violations of our agreements;
- protect the rights, safety, property, or security of WorkCurrent, a customer, a user, or another person;
- establish, exercise, or defend legal claims; or
- complete or evaluate a merger, financing, reorganization, acquisition, sale of assets, or similar corporate transaction, subject to appropriate confidentiality protections.
8. International processing and access
WorkCurrent is based in Canada. Our application backend and storage are hosted in the United States. Information may therefore be processed in Canada and the United States and may be accessed by authorized personnel or service providers in Canada, Mexico, other Latin American locations, and other countries where our service providers operate.
Privacy and government-access laws in those locations may differ from the laws where a person lives. WorkCurrent remains responsible for personal information under its control and uses contractual and organizational measures appropriate to the processing relationship.
The Service is initially intended for business customers in Canada, the United States, and Mexico. We may update this Policy before offering the Service more broadly.
9. Security
WorkCurrent uses reasonable administrative, technical, and organizational safeguards designed to protect personal information against loss, theft, and unauthorized access, use, alteration, or disclosure.
Depending on the relevant system, these safeguards include:
- encryption of data in transit and at rest;
- encryption of monday.com access tokens and other connection credentials;
- access controls and role-based restrictions;
- logical separation of customer environments;
- authentication, monitoring, logging, and vulnerability management practices;
- confidentiality obligations for personnel with access; and
- incident-response and data-deletion procedures.
No method of electronic transmission or storage is completely secure. WorkCurrent does not guarantee that a security incident will never occur. If we confirm a security incident involving personal information, we will investigate, take reasonable steps to contain and remediate it, notify affected customers without undue delay where appropriate, and provide notices required by applicable law or contract.
10. Retention and deletion
We retain personal information only for as long as reasonably necessary for the purposes described in this Policy, including to provide the Service, maintain security, resolve disputes, enforce agreements, and comply with legal obligations.
While an account is active, we may retain account information, configuration, company context, selected operational data, AI history and generated insights, security records, and information necessary to provide enabled features.
For the monday.com marketplace application:
- deauthorization, deactivation, uninstall, or other marketplace termination stops future access to monday.com data;
- WorkCurrent will delete marketplace-derived end-user data and associated metadata within 10 days, unless the customer has provided clear, express written consent for longer retention under a separate active agreement or retention is legally required; and
- uninstalling does not automatically reverse information previously written to the customer's monday.com account.
We may retain limited records that are not marketplace-derived Customer Data where necessary for legal, security, fraud-prevention, tax, accounting, or dispute purposes. Aggregated or de-identified information may be retained where it no longer reasonably identifies a customer or individual.
A customer should export information it wishes to retain before uninstalling the marketplace application.
11. Customer controls
Depending on the current features and permissions, customer administrators may be able to:
- choose which boards, fields, workspaces, and records the Service uses;
- enable or disable supported integrations;
- configure approval or automated-write settings;
- change user access and permissions;
- disconnect boards or integrations;
- export available information; and
- uninstall the marketplace application.
A customer may also contact support@workcurrent.ai or legal@workcurrent.ai for assistance with an account, access, export, or deletion request.
12. Individual privacy rights
Privacy rights vary by location and may include the right to request access to, correction of, deletion of, or information about the use and disclosure of personal information, and to object to or restrict certain processing.
Information controlled by a WorkCurrent customer
If personal information appears in a customer's CRM, communications, meeting records, or other Customer Data, the customer generally controls that information. Individuals should ordinarily direct a request to the relevant customer. WorkCurrent will provide reasonable assistance to the customer where required by law or a data processing agreement.
Information controlled by WorkCurrent
For information WorkCurrent controls directly, a person may submit a request to legal@workcurrent.ai. We may need to verify the request and may decline or limit a request where permitted by law.
Canada
Individuals may have rights under Canada's Personal Information Protection and Electronic Documents Act and applicable provincial privacy laws, including rights to access and challenge the accuracy of personal information and to raise a concern with our Privacy Officer.
Quebec
Where Quebec privacy law applies, individuals may have rights concerning access, correction, deletion in certain circumstances, withdrawal of consent where applicable, and information about processing and cross-border communication. Requests may be submitted to our Privacy Officer.
United States and California
Residents of certain US states may have rights to know, access, correct, delete, or obtain a copy of personal information, and to opt out of certain sale, sharing, or targeted-advertising activities. WorkCurrent does not sell personal information or share it for cross-context behavioural advertising. WorkCurrent will not discriminate against a person for exercising an applicable privacy right.
Mexico
Individuals in Mexico may have applicable rights of access, rectification, cancellation, and opposition concerning their personal data, subject to the requirements and exceptions of Mexican law. Requests may be submitted to legal@workcurrent.ai.
A person may also complain to the privacy regulator having jurisdiction where permitted by law.
13. Cookies and similar technologies
The marketplace application may use essential session or authentication technologies necessary to operate within monday.com. It is not designed to use Customer Data for advertising or cross-site behavioural tracking.
Our public website may use essential cookies and, where enabled, analytics or similar technologies to understand website performance, remember preferences, prevent abuse, and measure marketing effectiveness. Where required by law, we will provide notice or obtain consent before using non-essential technologies. Browser settings may allow a person to block or delete cookies, although some website functions may not operate properly.
14. Communications
We may contact the person who installs the application, customer administrators, Authorized Users, and business contacts for:
- installation and onboarding;
- account, authentication, support, and customer-success purposes;
- billing and subscription administration;
- security, privacy, legal, and incident notices;
- service operation, availability, and material product changes;
- product education and adoption; and
- other transactional communications necessary to provide the Service.
We may send marketing or promotional communications where permitted by applicable law. Promotional emails will identify WorkCurrent and include an unsubscribe mechanism. An opt-out from marketing does not apply to essential service, billing, support, security, or legal messages.
15. Sensitive information
Unless WorkCurrent has expressly agreed otherwise in writing, customers and users should not intentionally submit protected health information, government identification numbers, full payment-card or bank-account information, passwords, consumer credit reports, biometric identifiers, criminal records, children's information, or other highly sensitive or specially regulated information that is not reasonably necessary for ordinary business sales and CRM activity.
16. Children
The Service is intended only for business users who are at least 18 years old. WorkCurrent does not knowingly collect personal information from children through the Service.
17. Third-party services
Our Service may contain links to or interoperate with third-party services. Their collection and use of information is governed by their own privacy policies and agreements. WorkCurrent is not responsible for the independent privacy practices of a third party.
18. Changes to this Privacy Policy
We may update this Privacy Policy to reflect changes in the Service, our practices, providers, or applicable law. We will post the updated Policy with a revised effective date. If a change materially affects how we use personal information, we will provide additional notice where required or reasonably appropriate.
19. Contact and Privacy Officer
WorkCurrent has designated a Privacy Officer responsible for overseeing its privacy program.
- Privacy Officer, WorkCurrent AI Inc.
- 150 King St. W, Suite 200, Toronto, Ontario M5H 1J9, Canada
- Privacy and legal requests: legal@workcurrent.ai
- Support and security reports: support@workcurrent.ai
