Version 1.1 · Last updated: September 07, 2026
Work-A-Beez is a workforce-management software service operated by Linton Business Solutions, LLC ("LBS"). This page describes the compliance-support posture of the Service. It is not legal advice, does not make Work-A-Beez a payroll processor, employer, HR consultant, or legal advisor, and does not guarantee that a customer's use of the Service satisfies any particular law.
LBS is responsible for operating the Service and maintaining the security, privacy, and operational controls that are under its control. Customers remain responsible for their employment practices, wage-and-hour rules, overtime settings, payroll review, employee notices and consents, lawful data collection, record retention, user access, and industry-specific obligations.
Work-A-Beez maintains documented security and privacy controls and is developing a more mature assurance program. However, as of the displayed update date:
Roadmap information is available in the Compliance Roadmap, SOC 2 Readiness Statement, and ISO 27001 Roadmap.
Depending on the customer, data, location, and processing activity, privacy laws such as the GDPR/UK GDPR, California Consumer Privacy Act as amended, Texas Data Privacy and Security Act, or other state and national privacy laws may apply. Applicability is fact-specific and should be evaluated by the customer with qualified counsel where appropriate.
For workforce data processed on behalf of a customer, LBS generally acts as a processor, service provider, contractor, or analogous party, while the customer generally determines the purpose and means of the workforce processing. LBS may act independently for limited business-operational data such as billing, security, legal-compliance, and direct support records.
Work-A-Beez provides tools for recording time, scheduling, attendance, PTO, and payroll-related reporting. Those tools may help customers maintain records and apply their configured policies, but Work-A-Beez does not determine whether a worker is exempt or nonexempt, what overtime rule applies, whether a meal or rest period was legally sufficient, whether a deduction is lawful, or whether payroll is legally correct.
Customers must configure rules based on the laws and agreements that apply to them and must review outputs before using them for payroll, discipline, regulatory reporting, or employment decisions.
Current controls include HTTPS/TLS, production browser/session protections, CSRF protection, rate limiting on selected sensitive endpoints, one-way hashing of administrator passwords and employee PINs, logical organization-level tenant separation, authorization checks, environment-managed secrets, selected audit/security logging, managed cloud/database services, and backup/recovery capabilities provided by the hosting architecture.
The Service does not currently represent that customer-facing MFA, SAML/OIDC SSO, customer-managed encryption keys, dedicated per-customer databases, or customer-selected data-residency regions are generally available.
The current production model distinguishes employee access, organization-administrator access, and separate platform-level system administration. Some product features may include manager-like workflows or permissions, but customers should not rely on broad enterprise RBAC role lists unless those roles are visible and configurable in their deployed version.
Customers are responsible for assigning access appropriately and removing access promptly when personnel change roles or leave the organization.
Selected administrative, security, and operational events are logged. Logging supports troubleshooting, security investigations, and accountability. Work-A-Beez does not represent that every event is captured in an immutable or customer-exportable audit log, and customers with specific regulatory logging requirements should confirm their needs before relying on the Service.
Retention varies by data category, active account status, legal obligations, security needs, and backup lifecycle. Organization deletion is a reviewed request process rather than an instantaneous purge. Customers remain responsible for determining how long they must retain employment, payroll, tax, and workforce records. See the Data Retention Summary and Data Deletion Process.
Work-A-Beez uses service providers to operate portions of the platform. Current provider information is maintained in the Subprocessor List. Work-A-Beez is operated primarily from the United States and does not currently provide a general customer-selectable hosting-region feature. See the Data Residency Statement.
LBS maintains documented continuity, recovery, and incident-response practices. Standard self-service subscriptions do not carry a fixed contractual RTO, RPO, or incident-resolution SLA unless a separate written agreement expressly establishes those terms. Customer incident notification is handled according to applicable law and contractual obligations.
Customers evaluating Work-A-Beez may use the Customer Security Questionnaire, Compliance Matrix, and other Trust Center materials as a starting point. Those materials should be read together with the Terms of Service, Privacy Policy, DPA, and any signed Order Form.
Compliance, privacy, and security questions may be sent to info@lbsconnect.net. Work-A-Beez does not currently publish a separate compliance-office mailbox as a contractual notice address unless one is stated in the applicable agreement.
This document is informational and may be updated as controls, laws, providers, and product capabilities evolve.