SOC2C

Is this your company? Buyers are checking Welcomeworkdays here. Claim welcomeworkdays.com free to control the listing, earn the badge buyers trust, and see who's evaluating you.

Claim free
Welcomeworkdays logo

Welcomeworkdays

Trust level
Listed
Unverified

Sourced from public information. Not yet verified by the company.

Welcomeworkdays is SOC 2 compliant. Welcomeworkdays also holds GDPR, and ISO 27001.

Framework
SOC 2
Auditor
Last report
Renewal
View official trust center ↗

About

Welcome to Welcome Workdays Trust Center, where our commitment to data privacy and security is central to our operations. Welcome Workdays makes every day easier for everyone who owns, operates, leases or uses an office building. This Trust Center offers detailed insights into our security practices, including the specific controls and policies implemented by our teams. You can explore our compliance standards, request access to comprehensive security documentation, and gain a clear understanding of how we safeguard your data. Additionally, we invite you to subscribe for updates to stay inform

Compliance & infrastructure

Hosting
GCP
Data handled
Customer personally identifiable informationCredit card informationPersonal health informationPublic IP adressesEnd User Activity DataSensitive personal informationEnd User order historyUser communicationPassword Secrets

Subprocessors

8
  • G
    Google Cloud Platform · Cloud provider for our application. Welcome Workdays uses GCP as the storage and
    EU
  • S
    Sharry · Provide deep integrations to Access Control Systems and Mobile Credential Provid
    EU
  • I
    Intercom · Provide a platform for customer support which enables chat and communication
    EU
  • L
    LINK Mobility Poland Sp. z o.o. · SMS Provider to allow for sending messages to users phone
    EU
  • P
    Poly API Corporation · Integration platform as a service used to integrate all services
    EU
  • H
    HubSpot · Marketing and communication towards customers
    EU
  • B
    Brevo · Secure Email Provider to send emails to users from Welcome Workdays
    EU
  • B
    Beamer · Customer Communication and NPS
    EU

Compliance leadership

The person who leads Welcomeworkdays's SOC 2 isn't listed yet. Claim this profile to add it.

Penetration test

Unknown. Welcomeworkdays's penetration test vendor isn't listed yet.

Claim this profile to add it.

Recent updates

Update to our privacy policyFeb 2026

We have updated our privacy policy with minor changes. What's been changed? - Lunch and catering orders. We've added a section describing how order data (menu selections, pickup times, and transaction details) is processed when you use the lunch or catering service in your building. Welcome Workdays does not process payment card information — all card payments are handled directly by our third-party payment provider. We store transaction data, transaction IDs, and receipts as required by applicable bookkeeping regulations. - Technical app data. We now explicitly list the technical data the Welcome Access app collects for stability and troubleshooting, such as your device type, operating system, and app version.

Welcome Workdays ISO 27001:2022 certifiedMar 2025

Welcome Workdays is now ISO 27001 certified! 🎉 We are proud to announce that we have achieved ISO 27001 certification, the internationally recognized standard for information security management. This certification reflects our commitment to safeguarding customer data, ensuring compliance, and maintaining the highest security standards across our platform. At Welcome Workdays, we take security seriously, and this milestone reinforces our dedication to providing a reliable and trusted solution for our customers. Thank you for your trust and support! 🚀

This listing is partial

6/11 details · 55%

SOC2C shows the verified essentials. 5 details are not yet provided by the company. Trust centers list more, so we invite the owner to fill the gaps here.

  • Auditorraises trust
    Add the CPA firm that issued your SOC 2 so buyers can verify who signed it.
  • Report dateraises trust
    Add your most recent report period so buyers see how current your SOC 2 is.
  • Renewal date
    Add your renewal window so buyers know your coverage is active.
  • Documents
    List the documents you share (SOC 2 report, SOC 3, pen-test summary, DPA) and whether each is public or on request.
  • Security controls
    Confirm key controls (encryption, MFA/SSO, annual pen test, BCP/DR) buyers screen for.
Claim free to control your listing

Verify your work email to take ownership, earn the badge buyers trust, and add the details that win deals.

Frequently asked

Is Welcomeworkdays SOC 2 compliant?
Welcomeworkdays is SOC 2 compliant. On SOC2C this listing is Listed.
Is Welcomeworkdays GDPR compliant?
According to Welcomeworkdays's public trust center, Welcomeworkdays is GDPR compliant. On SOC2C this listing is Listed.
Is Welcomeworkdays ISO 27001 certified?
According to Welcomeworkdays's public trust center, Welcomeworkdays is ISO 27001 certified. On SOC2C this listing is Listed.
Can I use Welcomeworkdays's SOC 2 for a vendor risk assessment?
Yes. Welcomeworkdays's SOC 2 status, frameworks, auditor, and renewal timing are on SOC2C for vendor risk and security reviews. Request the underlying report through SOC2C to complete your third-party risk file.
Is Welcomeworkdays penetration tested?
Welcomeworkdays hasn't listed its penetration testing on SOC2C yet. SOC 2 Type II programs typically include periodic third-party penetration tests; the company can add who performed theirs.

Answers published by Welcomeworkdays

Reproduced from Welcomeworkdays's own trust center. These are the company's statements about its security practices — SOC2C has not tested or verified them, and they may have changed since we last read the page. Check the source ↗

Welcome Workdays is ISO 27001:22 certified. What does that actually mean?
ISO 27001:2022 is the latest international standard for information security management systems (ISMS). This certification ensures that Welcome Workdays has implemented a robust framework to protect sensitive data, manage cybersecurity risks, and maintain compliance with global security best practices.
What data is collected by the Welcome Access App specifically?
The Welcome Access App collects personal data necessary to provide secure building access and a smooth user experience. Below is a complete overview of the data collected. User profile data When you register or are registered as a user, the app stores the following information that is visible and editable in your profile: - First name and last name - Email address / login name - Profile photo (optional – if uploaded by the user) - Related company name - Assigned building and floor - Access PIN (sent directly to the access control system, not stored by Welcome) This data is used to identify you as a user and manage your access rights within the building. Access-related data To manage and secure physical access to the building, the app processes the following: - Approximate GPS location (conditional): GPS location data is only requested if you activate the Bluetooth-based mobile access functionality and explicitly grant location permission on your device. This data is required by the BLE card provider when generating your digital access card. The location data does not leave your device and is not stored on Welcome's or our technology partner Sharry.tech's servers. We classify this as processing under GDPR as the app technically requests the permission, even though no location data is transmitted or stored externally. Technical and device data In order to ensure the app functions correctly and to improve the service, the following technical data is collected in the background: - IP address (processed as part of standard internet protocol communication) - Authentication and session tokens - Device operating system - Device type - Language settings - App version installed This technical data may be linked to your user account. It is used to facilitate secure communication between your device and our servers, and to gain statistical insights into how the app is used so we can improve the service.
Why does the Welcome Workdays app request location permission?
The Welcome Workdays app may request location permission on your device when you activate a Bluetooth-based (BLE) access credential. This is not because the app tracks your location. Both Android and iOS classify Bluetooth scanning as a location-related capability. The reason is that proximity to a known Bluetooth device — such as an access control reader installed at a door — can theoretically be used to infer a user's physical position. Because of this, the operating system requires apps to hold location permission before they can communicate with BLE devices like door readers. Key facts: • The location permission is an operating system requirement for Bluetooth functionality — it is not initiated by Welcome Workdays. • The approximate location data obtained through this process remains on your device. It is not transmitted to, stored on, or processed by Welcome Workdays or any third party. • This permission is only requested when activating a BLE access credential. Users who exclusively use NFC-based credentials (Apple Wallet / Google Wallet) are never prompted for location permission. • On Android 12 and later, Google introduced dedicated Bluetooth permissions (BLUETOOTH_SCAN, BLUETOOTH_CONNECT) separate from location. However, the underlying hardware vendor SDKs used by access control readers may still require the legacy location permission to function. For more details, see Android's Bluetooth permission documentation at developer.android.com and Apple's Bluetooth privacy guidance at support.apple.com.