Purple Willow Consulting, LLC
Privacy Policy
Willow Workbench handles UKG configuration that belongs to you and your clients. This page explains what we keep, what we don't, and how we protect it.
Last updated 9 October 2026
Credentials sealed
UKG passwords and secrets are encrypted with AES-256-GCM using a key unique to you.
Files not kept
Uploads are read in memory and discarded. We log only a file's name and size.
No tracking
No advertising, no analytics scripts, and we never sell or share your data.
You're in control
Download your personal data at any time, or ask us to delete your account.
Who we are
Willow Workbench is a set of tools for UKG Pro Workforce Management implementers, run by Purple Willow Consulting, LLC ("we", "us"). Accounts are by invitation only: a platform or customer administrator invites you, and your account belongs to that customer organization.
When you use the tools on a client's UKG environment, the client data stays the client's. We process it only to give you the results you asked for.
What we collect
| Data | Why we have it |
|---|---|
| Account details Name, email, customer organization, role, whether you hold one of its licenses, hashed password, and two-factor settings (your authenticator key, encrypted, and recovery codes, stored only as one-way hashes) |
To sign you in, send your invitation and password emails, decide which tools you can open, and email customer administrators reminders when their license is ending. |
| Billing For organizations that pay online: your organization's Stripe customer and subscription IDs, plan, number of licenses and renewal date. We send Stripe your organization's name and the subscribing administrator's email. Card details, billing address and tax ID are entered on Stripe's pages and held by Stripe, not by us |
To keep your organization's licenses and renewal date in step with what it pays for. |
| UKG environment settings Environment name, URLs, app key, client ID, user name, and the encrypted password, client secret and organization |
To connect to UKG on your behalf when you run a tool. |
| Terms acceptance Which version of the Terms of Service you agreed to, when, your email and IP address at the time |
To keep a record of the agreement between us. |
| Usage log Which tool you ran, when, on which environment, uploaded file names and sizes, duration, and any error |
To support you, fix problems and understand how the tools are used. |
| Bug reports What you write, an optional screenshot, the page and tool, your browser and IP address |
To investigate and answer the problem you reported. |
| Technical data IP address, browser, request times in server logs |
To keep the service secure, limit sign-in attempts and diagnose faults. |
Your UKG credentials
- Passwords, client secrets and organization values are encrypted with AES-256-GCM before they are stored.
- Each user has their own encryption key, and the keys are not stored in the database, so a copy of the database alone can't unlock them.
- Only the person who added an environment can use it. Secrets are never shown again after you save them, not even to administrators.
- We only connect to UKG over HTTPS and refuse private or internal network addresses.
Files and client data
Tools read SDM exports you upload, or configuration fetched from the selected UKG environment. That data is processed in memory to build your results. We don't store uploaded files or the configuration we fetch.
Results you can download (such as an Excel workbook) are held in server memory for up to one hour so the Download button works, then discarded. They are cleared sooner if the service restarts.
Usage log
Each tool run is recorded with your user, customer, the tool, the environment name, uploaded file names and sizes, how long it took and whether it succeeded. The log never contains file contents or UKG data.
You can see your own runs on the Usage page. Customer administrators see the runs for their organization, and Purple Willow Consulting's platform administrators can see all runs.
Bug reports
When you use Report a bug, we send what you wrote, any screenshot you attach, and context (your name and email, customer, page, tool, UKG environment name, browser and app version) to our support desk at [email protected], where it becomes a support ticket. Only attach screenshots you're allowed to share with us.
Service providers
We don't sell your data or share it for marketing. A few providers handle data so we can run the service:
-
Cloudflare sits in front of the site to provide HTTPS and protect it from attacks. Your traffic passes through its network.
-
Microsoft 365 sends invitation, password and notification emails, and receives bug reports.
-
Stripe processes subscription payments and invoices. When your administrator subscribes or manages billing, they're sent to Stripe's own pages, and Stripe tells us the plan, number of licenses and renewal date.
-
Our help desk, which we host ourselves, holds support tickets created from bug reports.
-
UKG receives the requests our tools make to the environments you connect, under your own credentials.
The application and its database run on infrastructure operated by Purple Willow Consulting.
Security
The site is served only over HTTPS. Sign-in attempts are rate-limited and accounts lock after repeated failures, and you can turn on two-factor authentication with an authenticator app from your account page. Access to each tool depends on your role and your organization's plan. No system is perfectly secure. If a security breach affects your personal data, we will notify you as required by applicable law.
How long we keep data
- Account details are kept while your account exists.
- UKG environments are kept until you delete them, or your account is removed.
- Downloadable results are discarded within one hour.
- Terms acceptances are kept as a record of what was agreed, including after an account is removed.
- The usage log is kept to support you and your organization. Entries keep the email address used at the time.
- Support tickets are kept in our help desk for as long as needed to resolve and follow up on them.
Your choices
You can update your name, email and password, and download a copy of your personal data, from your account's Personal data page. To correct something else, or to have your account and data deleted, contact your organization's administrator or email us. Depending on where you live you may have further rights, such as to object to processing or complain to a regulator; we'll help with any request.
Changes to this policy
We'll update this page when the service changes how it handles data, and change the date at the top. For significant changes we'll let account holders know by email.
Contact us
Questions about privacy or your data? Email [email protected].