> ## Documentation Index
> Fetch the complete documentation index at: https://help.gowindmill.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Data Privacy and Collection

> How Windmill collects, stores, processes, and protects your data, including encryption, data residency, retention, and how customer information is handled.

At Windmill, privacy and security are at the core of what we do. We act as a central hub for your cloud service providers, integrating them into a single place to help improve company efficiency and operations.

## What Windmill collects

Windmill connects to your authorized business applications through their APIs. We only collect data that's necessary to provide our service and only from systems you explicitly authorize.

**From your HRIS (HR system)** We collect basic organizational data to build your org chart and roster: first and last name, work email, job title, department, manager and reporting structure, start date, employment status, and gender (if your HRIS provides it).

**What we do NOT collect from HRIS** Home addresses, Social Security Numbers, government IDs, dates of birth, phone numbers, pronouns, compensation, payroll, benefits, bank account details, and employment contracts. These fields are never requested or stored, even if your HRIS contains them.

See [Personally Identifiable Information](/security/pii) for the full canonical list of fields and their sources.

**From connected productivity tools** When you connect tools like Slack, Google Workspace, GitHub, Jira, or Linear, we collect activity data that helps Windy understand collaboration patterns and generate insights. The specific data collected depends on which integrations you enable.

## No browser installations

Windmill does NOT install anything on employee computers or in browsers. We only connect with the APIs of explicitly authorized business applications.

* We collect as little or as much as authorized by the business owner
* Windmill simply pieces together data that already exists in your connected systems

## Privacy and access controls

**Connected-content permissions** When connected content has source-level access controls, Windmill keeps that permission context. For example, a private Google document or Slack channel does not become visible to people who cannot access it in the source. Some integrations provide company-level activity or usage data instead. Windmill applies the permissions for that feature to this data.

**Org chart scope** The org chart defines direct and indirect reporting subtrees. Managers can use this scope in supported features. Roles, delegation, source permissions, and feature-specific privacy rules can provide or limit other access.

**Admin visibility** Windmill Admins manage workspace configuration, integrations, billing, and access settings, but admin status alone does not grant unlimited visibility into every employee's content. Source permissions, org-chart scope, delegation, and feature-specific privacy rules still apply. Admins and Data Analysts can view company-wide analytics where the analytics feature provides that access.

**1:1 auditability** 1:1 auditability is an explicit company-level setting for compliance, employee relations, and manager support. When enabled, authorized managers or HR Admins can review shared manager/direct 1:1 notes and history in a read-only audit view. Private Notes, participant-specific prep topics, Catch Me Up reports, and recording access are excluded.

**Access delegation** Admins and HR Admins can give one member supported manager-like visibility into another manager's reporting scope. Delegation does not provide access to the other member's account and does not let the delegated member impersonate that person.

Delegation does not provide all content that the selected manager can see. It excludes 1:1 notes and agendas, does not change Google or Slack permissions, and does not override feature-specific privacy rules. See [Permissions and Access](/permissions-and-access#access-delegation) for all limits.

<Note>
  Delegation changes start an access refresh after you save the rule. Only Admins and HR Admins can add or remove delegation rules.
</Note>

## Historical data

When you connect systems, the amount of historical data varies by integration. For Reviews and 1:1s, Windmill will collect data on a go-forward basis from when the system was connected. If you are interested in capturing more historical data, let us know during onboarding or reach out via your shared support Slack channel.

## Data retention

Windmill retains data from customers as long as they have an active engagement with Windmill. You have the right to request complete data deletion after ending an engagement with Windmill.

## Additional resources

For more detailed information about our privacy practices:

* Read our [Privacy Policy](https://gowindmill.com/p/privacy-policy)
* Visit our [Trust Center](https://app.drata.com/trust/7bd6416b-c1ac-4c6c-afb4-a015fe83db6b)
* Contact us at [support@gowindmill.com](mailto:support@gowindmill.com)
