Until today, WorkAdventure had one privacy policy. One document, written by us, covering everybody: the world administrators who buy WorkAdventure, and the people who walk into their worlds.
Starting today, that changes. Each world now has its own privacy policy, generated from the configuration you choose, and naming you as the data controller for your world.
Why we are doing this
The single-policy model worked as long as WorkAdventure was the only party doing anything with your users’ data. That is no longer true.
Alongside our new release, world administrators can now see the list of visitors who registered on their world, and export it. Tomorrow, we will add analytics that administrators can enable on their own worlds. Both are features people have asked us for, repeatedly, and both have the same characteristic: they let you do something with your users’ personal data that WorkAdventure does not do on its own behalf.
WorkAdventure does not send marketing emails to the members of your world. You might want to — and that is a perfectly legitimate thing to do. But the people who registered on your world have the right to know it before it happens. Since we cannot know what you intend to do with that data, we cannot write that part of the policy for you.
NOTE
To make it obvious we need to separate the two relationships, let’s take an example. If you build a website with WordPress, you don’t expect the WordPress privacy policy to apply to your visitors. You write your own, and you are responsible for it. In WorkAdventure, it’s the same. WorkAdventure gives you the tools to run your world, including tools to add code to your maps and hence collect and manage user data, but you are responsible for what you do with the data of the people who use it.
So we split the relationship in two.
The two-layer model
Being European, I’ll use the GDPR as a reference point. But wherever you are, the principle is the same: the relationship WorkAdventure has with you (the world administrator) is different from the relationship you have with your users (the people who use your world).
In the terms of the GDPR:
- You are the data controller for your world. You decide who can register, what you do with their data, and why.
- WorkAdventure is your data processor for the platform: we host the world, store the accounts, relay the video streams, and run the chat server — on your instructions.
- For a narrow set of platform-wide activities (security, abuse prevention, infrastructure monitoring), WorkAdventure acts as an independent controller, because those are our decisions, not yours.
So we now have 2 privacy policies: one between WorkAdventure and you, and one between you and your users.
The privacy policy between you and your users is generated. It states all three, in plain language, in a single document your users can read.
What the generated policy contains
Go to Settings → Privacy / Compliance in your dashboard and you will find a list of checkboxes describing what you intend to use personal data for: newsletters, event updates, feedback surveys, customer support, community engagement, and so on. There is a free-text field for anything we did not anticipate.

Tick what applies. Save. Your world’s privacy policy is generated instantly at:
https://<your-member-domain>/@/<organization>/<world>/privacy-policy
The document is built from your world’s actual configuration. It knows whether you allow anonymous users, whether the chat is enabled, whether you run bots, and which video conferencing backend you use — and it lists the corresponding sub-processors, retention periods, and international transfer safeguards accordingly. You can find more about the configuration screen in the documentation.
You will find it linked from the registration page your visitors see, and from inside the game.
Prefer your own lawyers?
Some of you have legal departments and existing policies. Tick “Use your own privacy policy and legal links” and give us the URLs to your own privacy policy, terms of use and cookie policy. We will link to those instead.
WARNING
If you do this, your policy has to cover the processing WorkAdventure performs on your behalf — the Matrix chat server, the video relays, the moderation logs, the retention periods. Please read the generated policy first and copy across the parts that apply to you. It is easier than writing them from scratch.
Asking for consent
If you tick a purpose that requires consent under EU law — marketing emails, surveys, or sharing data with third parties — WorkAdventure will help you collect consent from your visitors. When a visitor registers, we will ask your visitors for their consent by displayed checkboxes. The answers are recorded and shown in the Visitors page, so you can prove who agreed to what, and when.
What this means for you, concretely
- Configure your privacy policy today. Settings → Privacy / Compliance. It takes two minutes. Until you do, any privacy-sensitive WorkAdventure feature stays locked.
- Only tick what you actually do. The checkboxes are disclosures, not aspirations. If you are not sure you will ever send a newsletter, leave it unticked — you can always add it later.
- Fill the contact email that will be referenced in your privacy policy. Settings → Privacy / Compliance. If you do not, the default is the mail of the user who created the organization.
A note on what we are not
We are engineers, not your lawyers. The generated privacy policy is a solid, informed starting point built on how WorkAdventure actually works. You remain responsible for the accuracy of the document published in your name. If your organization is in a regulated sector, or you serve users with special privacy statutes, have your counsel read it. And do not forget you can replace it with your own policy if you prefer.
Where we are going next
We are not building a privacy policy generator for the sake of it. This feature is the one that allows us to unlock the next set of features that people have been asking for, and that we have been wanting to build for a long time:
- access to the visitors who registered on your world, which can allow you to turn WorkAdventure in a lead magnet.
- advanced analytics, with metrics allowing you to know how an event went, how many people attended, talked to each other or to sponsors, …