Privacy policy
Local workspace data stays under your control.
This notice explains how Security Compliance Workspace handles information in the Windows app and on this public website.
1. Scope of this notice
This privacy policy covers the Security Compliance Workspace Windows application and the public informational website used to describe the product and its release status.
The app is designed for organisations and professionals preparing practical security and compliance working documents. It is not directed at children, even though content-rating systems may classify its content as suitable for all ages.
2. Information handled by the Windows app
Depending on what a user enters, the app may handle organisation and personal information such as:
- organisation name, size, systems, suppliers, and security practices;
- document owner names, roles, action owners, review dates, and workflow notes;
- questionnaire answers, findings, evidence references, decisions, and reassessment history;
- generated Word documents, spreadsheets, JSON records, and backup files.
This information is supplied by the user and is used only to provide the app's local assessment, document-generation, findings, actions, evidence, comparison, backup, and restore functions.
3. Local storage and transmission
The Windows app stores workspace content locally on the user's computer. For the Microsoft Store package, the normal workspace folder is:
C:\Users\<user>\Security Compliance Workspace\generated_documents
The publisher does not receive, host, analyse, sell, or use this workspace content. The app does not require a publisher-operated account, remote database, cloud sync service, advertising service, telemetry service, or generative AI service.
The app runs a local browser service on the user's own computer. Opening the workspace, a local file, or a local folder may involve Windows and the user's default browser, which operate under their own privacy terms.
4. User control, retention, and deletion
Workspace data remains until the user or the organisation managing the computer deletes it. Users can manage assessments and backups through the app and can also remove the local files directly.
Uninstalling the Store package may leave the visible user-owned workspace folder in place so that assessments and generated documents are not lost unexpectedly. To remove the remaining app data, delete the Security Compliance Workspace folder from the user's Windows profile after keeping any required backup.
The user or their organisation is responsible for choosing suitable retention periods, access controls, backups, and secure deletion for information entered into the workspace.
5. Public website data and analytics
This website is a static informational site. It does not provide user accounts, a contact form, behavioural advertising, or marketing profiling.
The website is hosted using Cloudflare Pages. When a visitor requests a page, Cloudflare may process technical request information such as the IP address, browser or device information, requested page, time of request, and security-related signals to deliver and protect the site. Cloudflare handles that information under its own privacy and data-processing terms.
Cloudflare Web Analytics is enabled to provide the publisher with aggregate information about visits, page views, referring sources, browser and device categories, and page-performance measurements. Cloudflare Pages automatically adds the analytics beacon to the deployed website.
Cloudflare states that its Web Analytics beacon does not use cookies or browser storage, does not fingerprint individual visitors, and does not access visitor IP addresses. The beacon collects performance and usage information relating to the current webpage and does not receive assessment answers, generated documents, workflow notes, evidence records, backups, or other content stored in the Windows app.
The publisher uses these aggregate measurements to understand whether the public pages are being found, which pages are viewed, how visitors reach the site, and whether the website performs reliably. The publisher does not intentionally use marketing cookies or sell website visitor information.
6. Sharing and disclosure
The publisher does not sell personal information. App workspace content is not routinely disclosed to the publisher or to third parties.
Technical website information may be processed by the hosting provider as described above. Information may also be disclosed where required by law or necessary to protect the security and lawful operation of the website or product.
7. Business-user responsibilities
An organisation using the app decides what information to enter and why it is processed. That organisation remains responsible for its own data-protection obligations, including providing appropriate notices to its staff or other individuals, limiting access, setting retention periods, and responding to data-rights requests.
The generated documents are working drafts and do not provide legal advice, regulatory approval, certification, or independent assurance.
8. Questions and privacy requests
For questions about this policy, the Windows app, or the publisher's handling of website-related information, email scworkspaceapp@outlook.com.
For information stored only inside a local workspace, the user or the organisation controlling that computer should normally handle access, correction, export, retention, and deletion because the publisher does not hold a copy.
9. Changes to this policy
This policy may be updated when the product, website, hosting arrangements, or legal requirements change. The latest version will remain available at this page and will show its last-updated date.