Privacy Policy
Last updated: 30 May 2026
Less Work ("we", "us") provides AI workflow consulting services. This policy explains what personal data we collect when you visit less-work.com or interact with us, how we use it, who we share it with, how long we keep it, and the rights you have under the EU General Data Protection Regulation (GDPR), the UK GDPR, and the California Consumer Privacy Act as amended by the CPRA.
1. Who we are
Less Work is operated by Endre Adam, an independent consultant based in Budapest, Hungary. The controller for the data described here is Endre Adam.
Direct contact for any privacy question or data subject request: privacy@less-work.com. Our contact page works as a fallback if you prefer a form.
2. What data we collect
- Audit responses. The operational audit is anonymous until you opt in. The quiz answers themselves (questions 1 through 10) are submitted to our server so we can score them and improve the audit. If you click "Email me the report" and provide your email, we additionally store that email and tie it to your answers.
- Email correspondence. If you email us, we receive your email address and the contents of your message.
- IP address and request metadata. Our hosting provider (Vercel) records short term server logs containing your IP address, user agent, and the URL you requested. These are used for security, abuse prevention, and reliability.
- Analytics. If (and only if) you give consent through the cookie banner, Google Analytics 4 records standard usage data (anonymised IP address, pages viewed, approximate location, browser and device type, referrer). See our Cookie Policy for the full list.
- Booking details. If you book a discovery call, Cal.com collects the data you enter on their form (typically name, email, and meeting time). That data is processed by Cal.com under their own privacy terms; we receive the resulting calendar invite.
3. How we use it
- To deliver the audit results we promised you (contract, legitimate interest).
- To reply to your messages and follow up on consulting enquiries (contract, legitimate interest).
- To create or update a contact record in our CRM when you opt in to receive the audit by email (legitimate interest).
- To understand which pages and content are useful, where you consented to analytics (consent).
- To keep the site secure and operational (legitimate interest).
- To share data with the sub-processors listed in section 4, under contract, only where necessary to deliver the purposes above.
We do not sell personal data, we do not share it for cross-context behavioural advertising, and we do not run cross-site tracking.
4. Who processes data on our behalf
We use a small set of service providers to run the site and deliver the service. The current list is below. The authoritative live list, with locations and transfer mechanisms, lives at less-work.com/subprocessors.
- Vercel Inc. (United States, with EU edge): hosting, edge functions, and server logs. Transfers covered by the EU Commission's Standard Contractual Clauses.
- Resend (Resend, Inc.) (United States): transactional email delivery, including the audit result email and admin notifications. Transfers covered by SCCs.
- Attio (Attio Ltd.) (United Kingdom and United States): contact management. When you opt in to receive the audit by email, we create or update a person record in Attio with your email and audit result. Transfers covered by the UK adequacy regulations and SCCs.
- Cal.com, Inc. (United States, with EU regions): discovery-call booking. Cal.com processes the data you enter into the booking form under their own privacy terms. Transfers covered by SCCs.
- Supabase Inc. (EU region selected): admin authentication and storage for the playbook generator (operator side only, not used for visitor data).
- Google LLC (Google Analytics 4) (United States): analytics, only after you consent. IP anonymisation is enabled and ad features are disabled. Transfers covered by SCCs.
- Google LLC (Google Fonts) (United States): font delivery via fonts.googleapis.com and fonts.gstatic.com. Your IP address is transmitted to Google when fonts are loaded. We plan to self-host fonts in a future site update; see our Cookie Policy for details.
- jsDelivr (operated through Cloudflare and Fastly CDNs): delivery of the cookie consent library. Your IP address is transmitted to the CDN when the page loads.
5. How long we keep it
- Audit responses with email: 24 months from the date of submission, unless you ask us to delete them sooner.
- Anonymous audit answers (no email captured): up to 24 months in aggregate form to improve the audit.
- Email correspondence: up to 36 months, then deleted unless an active engagement requires longer retention.
- CRM contact records in Attio: until you ask us to delete them, or 36 months after the last interaction, whichever comes first.
- Server logs at Vercel: managed by Vercel under their own retention policy (typically 30 days).
- Analytics: per Google Analytics retention settings, currently 14 months, anonymised.
6. Your rights (EU and UK)
Under GDPR and UK GDPR you have the right to access the personal data we hold about you, to correct it, to delete it, to restrict or object to processing, to receive a portable copy, and to withdraw consent at any time. To exercise any of these rights, email privacy@less-work.com and we will respond within 30 days.
You also have the right to lodge a complaint with your local supervisory authority. For Hungary that is the National Authority for Data Protection and Freedom of Information (NAIH).
7. California residents (CCPA / CPRA)
If you are a California resident, you have additional rights under the California Consumer Privacy Act as amended by the California Privacy Rights Act.
Categories of personal information collected in the last 12 months: identifiers (email address, IP address), commercial information (services requested), internet or other electronic network activity information (pages viewed, where you consented to analytics), and inferences drawn from audit responses (your "archetype" classification).
Sources: directly from you (forms, email, audit submissions) and automatically from your device (server logs, analytics where consented).
Business purposes: delivering and improving the service, responding to enquiries, security, and analytics.
No sale, no sharing. We do not sell personal information and we do not share it for cross-context behavioural advertising as defined by the CPRA. We have not done so in the preceding 12 months.
Sensitive personal information. We do not knowingly collect sensitive personal information as defined by the CPRA.
Your CCPA rights: to know, to delete, to correct, to portability, to limit use of sensitive information (not applicable, as we do not collect it), to non-discrimination for exercising your rights, and to designate an authorised agent. We offer no financial incentives.
To exercise these rights, email privacy@less-work.com from the email address associated with your interaction, or have your authorised agent contact us with written authorisation. We will verify the request and respond within 45 days.
8. B2B clients and our Data Processing Agreement
When Less Work processes personal data on behalf of a business client under a paid engagement (for example, when we build automations that read your customer data), Less Work acts as a processor and the client is the controller. Our published Data Processing Agreement applies and is incorporated by reference into every engagement letter unless replaced by a client paper.
To countersign or request a copy with named annexes, email privacy@less-work.com.
9. International transfers
Some sub-processors operate outside the European Economic Area and the United Kingdom. Where this happens, the transfer is covered by:
- the European Commission's Standard Contractual Clauses (Commission Implementing Decision (EU) 2021/914, Module Two controller-to-processor and Module Three processor-to-sub-processor as relevant), with the United Kingdom International Data Transfer Addendum where the UK GDPR applies; or
- an applicable adequacy decision (for example, the UK adequacy regulations for transfers between the EEA and the United Kingdom).
10. Security
We use industry-standard technical and organisational measures to protect personal data, including encryption in transit (TLS) and at rest where supported by our sub-processors, access controls with multi-factor authentication on administrative accounts, and the principle of least privilege. No system is perfectly secure; if we become aware of a personal data breach affecting you, we will notify you and the relevant supervisory authority in line with GDPR Article 33 and 34.
11. Changes
We will update this page when our practices change. The "last updated" date above always reflects the current version. Material changes will be flagged on the page; B2B clients with an active DPA will receive direct notice.
12. Contact
For any privacy question or request, email privacy@less-work.com. Our contact page is also available as a fallback.