Product terms & conditionsEffective September 8, 2026Version 3.1
Acceptable Use Policy
This Acceptable Use Policy (the "Policy") governs your use of the WorkMonitor Services. It forms part of the Platform Terms of Service, and the capitalized terms used here have the meanings given there.
WorkMonitor records what happens on a device so that an employer can understand how work is going. That is a legitimate purpose, and it is also a capability that can be turned to purposes that are not legitimate. This Policy draws the line, and we enforce it.
A breach of this Policy is a material breach of the Platform Terms of Service. We may suspend or terminate access for a breach, as described at the end of this document.
Monitoring people: the rules that matter most
1.1You may use the Services to monitor an individual only in connection with that individual's working relationship with you, only where you have a valid legal basis, and only after you have given the notices and completed the consultations the law requires.
1.2You must not use the Services to do any of the following.
- Monitor a person who has not been told that monitoring takes place, where the law requires them to be told. Covert monitoring is prohibited on the Services except where it is expressly lawful in the relevant jurisdiction, is authorized in writing by your legal counsel following a documented assessment, and is limited to a specific, time-bound investigation of suspected serious misconduct or criminal activity.
- Monitor a person outside their working time or working context, including on a personal device you have no right to monitor, on a personal account, or during a period the person is not working.
- Monitor a person in a location where monitoring of that kind is prohibited, or where a required works-council agreement, collective agreement, employee-representative approval, regulatory notification or impact assessment has not been completed.
- Use the Services to identify, infer or record a person's trade-union membership or activity, political opinions, religious or philosophical beliefs, health or medical condition, disability, pregnancy, sexual orientation, gender identity, racial or ethnic origin, immigration status, criminal history, or any other special category of personal data, or to act on such information.
- Use the Services to detect, discourage, surveil or retaliate against protected concerted activity, union organizing, whistleblowing, a health-and-safety complaint, a discrimination complaint, or any other legally protected activity.
- Use the Services to monitor a person who is not in a working relationship with you, including a member of the public, a customer, a competitor's staff, a family member, a partner or a former partner.
- Use the Services to monitor a minor, except where the individual is lawfully employed by you and every requirement applying to the employment of minors in that jurisdiction has been met.
- Configure capture in a way that deliberately defeats a privacy control the Services provide, including disabling a deny list in order to capture a category of application or site you have told your workforce is excluded.
- Represent to a monitored workforce that a capability is switched off when it is switched on, or that data is not retained when it is retained.
- If you are unsure whether a deployment is permitted, do not start it. Our jurisdiction guides are background reading, not legal advice, and they are not a defence.
Use of the output
2.1The Services produce measurements, scores, summaries and reports. How you use them is part of your use of the Services.
- You must not take a decision that produces a legal effect for a person, or a similarly significant effect on them — including discipline, dismissal, demotion, a change in pay, the denial of a promotion, or a formal performance rating — based solely on automated processing by the Services, without meaningful review by a person who has the authority and the information to reach a different conclusion.
- You must not present a score, index or summary produced by the Services as an objective measure of a person's worth, effort or honesty. These are measurements of signals from a device, and they carry the limits of that.
- You must not disclose an individual's monitoring data to anyone inside or outside your organization who has no legitimate need for it, and you must not publish it.
- You must not use the Services to build a profile of a person for a purpose unrelated to their work, or to sell, license or otherwise commercialize data about a monitored person.
Prohibited content and conduct
3.1You must not use the Services to store, transmit, generate or make available content that is unlawful, or to engage in the conduct listed below.
- Child sexual abuse material, or any content that sexually exploits a minor. We report such material to the appropriate authorities and terminate the account immediately and permanently.
- Content that is defamatory, harassing, threatening, or that promotes violence, terrorism, self-harm or discrimination against a protected group.
- Content that infringes a third party's intellectual property or privacy rights, or that discloses another person's private information without their permission.
- Malware, ransomware, spyware, keystroke-content loggers, credential harvesters, or any code designed to damage, disable or gain unauthorized access to a system.
- Unsolicited bulk messaging, phishing, spoofing, or any deceptive practice designed to make a person disclose credentials or personal information.
- Any activity that violates export control, sanctions, anti-bribery, anti-money-laundering or anti-fraud law.
Platform integrity and security
4.1The Services are shared infrastructure. Conduct that degrades them for other customers is prohibited.
- Do not attempt to gain unauthorized access to the Services, to another customer's data, to an account you do not control, or to any system or network connected to the Services.
- Do not probe, scan or test the vulnerability of the Services, or breach or circumvent any authentication, authorization, rate limit, entitlement or security measure, except under our Vulnerability Disclosure Policy and within the scope it sets.
- Do not interfere with the Services or with any user's use of them, including by denial-of-service attack, resource exhaustion, deliberate flooding of the API, or deliberate generation of excessive load.
- Do not use the Services to distribute or operate a botnet, a proxy or anonymization service, a cryptocurrency mining operation, or any workload unrelated to workforce analytics.
- Do not falsify data submitted to the Services, tamper with an audit record, forge a work credential or certificate, or misrepresent the origin or integrity of a record produced by the Services. The integrity of what the platform attests to is the product.
- Do not impersonate another person or organization, or misrepresent your affiliation with one, in your use of the Services.
- Do not share credentials between individuals, or use one Seat for more than one person, in order to avoid Seat fees.
- Do not create multiple accounts to obtain repeated free trials, to evade a suspension, or to circumvent a usage limit.
Agent and endpoint software
5.1The desktop agents and extensions run on devices. Installing software on someone's device carries its own obligations.
- Install the agent only on a device you own or are lawfully entitled to manage, and only for an individual you are entitled to monitor.
- Do not repackage, rename, re-sign, obfuscate or otherwise modify the agent, or distribute it in a way designed to conceal from the person using the device that it is running.
- Do not bundle the agent with other software so that it is installed without the deploying organization's knowledge.
- Do not use the agent, or any part of the Services, as a component of a product you offer to others, except under a written agreement with us.
Fair use of capacity
6.1Plans are sized for normal business use of workforce analytics. We may apply reasonable rate limits, storage limits and concurrency limits, and we publish the ones that apply to the public API in the API and Developer Terms.
6.2If your usage is materially and persistently beyond what your plan contemplates, and it affects the Services for others, we will contact you to agree a plan that fits before taking any other step.
Reporting a breach of this Policy
7.1If you believe someone is using the Services in breach of this Policy, write to legal@workmonitor.ai with the detail you have. If you are a monitored worker and you believe your employer's use of WorkMonitor is unlawful, you may write to privacy@workmonitor.ai.
7.2We will look at every report. There are limits on what we can do: for data your employer holds as controller, the decisions are theirs and the law generally directs your request to them. We will tell you plainly what we can and cannot do, and we will not tell your employer who reported something where we are not obliged to and where doing so could expose you to retaliation.
7.3To report a security vulnerability, use the Vulnerability Disclosure Policy rather than this address.
How we enforce this Policy
8.1Where we believe this Policy has been breached, we may investigate, ask you for information, require you to change a configuration, suspend a feature, suspend an account, or terminate the Agreement.
8.2We will normally contact you first and give you an opportunity to fix the problem. We may act without prior notice where the breach is serious and ongoing, where a person is at risk of harm, where there is an active security incident, where we are required to act by law or by a competent authority, or where notice would defeat the purpose of acting.
8.3We may report unlawful activity to the appropriate authorities, and we may preserve and disclose information where the Law Enforcement and Government Requests policy permits.
8.4Suspension or termination for breach of this Policy does not entitle you to a refund.
Changes to this Policy
9.1We may update this Policy as the Services change and as we learn how they are being used. Where an update materially restricts a use you are actively making of the Services, we will give you at least 30 days' notice before it applies to you, as described in the Platform Terms of Service. Every change is recorded in our Legal Change Log.