Privacy Policy

Last updated: July 12, 2026

This Privacy Policy explains how To Work & Keep, LLC (“To Work & Keep,” “we,” “us”), which operates the Typing Insights platform (the “Services”), collects, uses, and protects personal information. It covers both our business clients (“Customers”) and the individuals who take assessments (“Participants”).

1. Our Roles: Controller and Processor

Our role depends on the data:

  • We are the “controller” for the personal information of our Customers and their Authorized Users — for example, account registration details, billing information, and how they use the Services.
  • We are a “processor” (a “service provider” under U.S. law) for Participant data. When a Customer administers assessments, the Customer is the controller and determines why and how that data is processed; we process it on the Customer’s behalf and under our Data Processing Addendum. Participants who want to access, correct, or delete their data should contact the organization that invited them; we will assist that organization as required.

2. Information We Collect

  • Account and profile data: name, company, email, role, and credentials of Customers and Authorized Users.
  • Participant data (entered by Customers): a Participant’s first name, last name, and email. This information is encrypted at the field level and stored in encrypted form.
  • Assessment results: typing metrics such as words per minute and accuracy, and related assessment activity.
  • Billing data: processed by our payment provider (Stripe). We do not store full payment-card numbers.
  • Usage and technical data: log data, device and browser type, IP address, and similar information used to operate and secure the Services and, on our marketing website, for analytics.

3. How We Use Information and Legal Bases

We use personal information to provide, maintain, secure, and improve the Services; to manage accounts and billing; to communicate with you; to generate analytics that help hiring teams make informed decisions; and to comply with law. Where the EU/UK GDPR applies to data for which we are the controller, we rely on these legal bases: performance of a contract (providing the Services); our legitimate interests (securing and improving the Services, preventing fraud); consent (for non-essential cookies and certain communications); and compliance with legal obligations. For Participant data, the Customer is responsible for establishing the legal basis. We do not sell personal information, and we do not “share” it for cross-context behavioral advertising as those terms are defined under California law.

4. Data Ownership

As between us and our Customers, Customers own the Participant and assessment data created under their organization’s account. We process that data as a service provider on the Customer’s behalf and only as permitted by our agreements.

5. Sharing and Sub-processors

We share personal information with trusted service providers who help us operate the Services (for hosting, payments, email delivery, and analytics). These providers are bound by contract to protect the data and to use it only to provide services to us. A current list is on our Sub-processors page. We may also disclose information to comply with law, enforce our agreements, protect rights and safety, or in connection with a merger, acquisition, or sale of assets (subject to this Policy).

6. International Data Transfers

We and our sub-processors are located primarily in the United States. If you access the Services from outside the United States, your information will be transferred to and processed in the United States and other countries. Where required, we use appropriate safeguards for such transfers, including the European Commission’s Standard Contractual Clauses (and the UK Addendum), as described in our Data Processing Addendum.

7. Security

We use administrative, technical, and physical safeguards to protect personal information, including encryption in transit and at rest, field-level encryption of Participant identity data, role-based access controls, and managed portal credentials for Participants that are separate from any personal accounts. No system is completely secure, and we cannot guarantee absolute security. If we become aware of a personal data breach affecting Participant data we process for a Customer, we will notify the affected Customer without undue delay so they can meet their own obligations.

8. Data Retention

We retain personal information for as long as needed to provide the Services and to meet our legal and contractual obligations. Customers can configure how long assessment data is retained for their organization, and can request export or deletion. When a retention period ends or a deletion request is fulfilled, we delete or de-identify the relevant data, except where retention is required by law.

9. Cookies and Analytics

We use cookies and similar technologies that are strictly necessary to authenticate sessions and operate the Services. On our marketing website we also use analytics to understand aggregate usage and improve the site. Where required by law, we obtain consent for non-essential cookies and analytics, and you can manage preferences through the cookie controls we provide or your browser settings. For details, see our Cookie Policy.

10. Your Privacy Rights

Depending on where you live, you may have rights over your personal information. For data where we are the controller, you may exercise these rights by contacting us (see Section 13). For Participant data, please contact the organization that invited you; we will assist as a processor.

  • EU/UK (GDPR): rights to access, correct, delete, restrict or object to processing, data portability, and to withdraw consent. You may also lodge a complaint with your local supervisory authority.
  • California (CCPA/CPRA): rights to know, access, correct, and delete your personal information, and to opt out of “sale” or “sharing” — although we do not sell or share personal information as those terms are defined. We will not discriminate against you for exercising your rights.

We will verify requests and respond within the timeframes required by applicable law. You may use an authorized agent where the law permits.

11. Children’s Data

The Services are intended for business use and are not directed to children under 16. Customers must not submit a minor’s personal information unless they have obtained all legally required consents (for example, verifiable parental or guardian consent) and have a lawful basis to do so; that responsibility rests with the Customer as controller. If you believe a child’s data has been provided to us without proper authorization, contact us and we will work with the relevant Customer to address it.

12. Changes to This Policy

We may update this Privacy Policy from time to time. We will post the updated version with a revised “Last updated” date and, for material changes, provide additional notice where required.

13. Contact Us

For privacy questions or to exercise your rights, contact us at privacy@typinginsights.com or by mail at To Work & Keep, LLC, 27943 Seco Cyn Rd, Unit 503, Santa Clarita, CA 91350.