WorkMonitor.

Legal and compliance

Every document, published in full

The DPA and its annexes, the sub-processor list, the platform terms and everything incorporated into them. Each at its own address, each dated, each clause numbered. Read them today and forward them to whoever signs off; nothing here waits on a sales call.

Privacy & data protectionEffective September 8, 2026Version 3.1

Data Processing Addendum

This Data Processing Addendum ("DPA") forms part of the Platform Terms of Service or other written agreement between Digital Socket LLC ("WorkMonitor", "we", "us", "Processor") and the customer identified in that agreement ("Customer", "you", "Controller"), governing our processing of Personal Data on your behalf.

This DPA is pre-executed. You do not need to sign or return anything for it to apply: it takes effect automatically when you accept the Platform Terms of Service, and it binds both parties from that moment. If your procurement process requires a countersigned copy, write to legal@workmonitor.ai and we will provide one that matches this text.

Where you and we have signed a negotiated data processing agreement, that agreement applies in place of this one.

1.

Definitions

1.1Terms defined in the Platform Terms of Service have the same meaning here. In addition:

Data Protection Law
All laws applicable to the processing of Personal Data under this DPA, including the EU General Data Protection Regulation (Regulation (EU) 2016/679) ("EU GDPR"), the UK GDPR and the Data Protection Act 2018, the Swiss Federal Act on Data Protection, the California Consumer Privacy Act as amended, and other US state privacy laws, in each case as amended or replaced.
Controller, Processor, Data Subject, Personal Data, Processing, Supervisory Authority
Have the meanings given in the EU GDPR, and their equivalents under other Data Protection Law — including "business", "service provider" and "consumer" under the CCPA.
Customer Personal Data
Personal Data contained in Customer Data that we process on your behalf under the Agreement.
Sub-processor
A third party engaged by us to process Customer Personal Data on our behalf.
Standard Contractual Clauses (SCCs)
The clauses annexed to European Commission Implementing Decision (EU) 2021/914 of 4 June 2021.
UK Addendum
The International Data Transfer Addendum to the SCCs issued by the UK Information Commissioner under section 119A of the Data Protection Act 2018, version B1.0.
Personal Data Breach
A breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to, Customer Personal Data.
2.

Roles of the parties

2.1You are the Controller of Customer Personal Data and we are your Processor. Where you are yourself a processor for another controller, we are a sub-processor, and this DPA applies as though references to Controller were references to that other controller, acting through you.

2.2Under the CCPA, you are the business and we are your service provider. We will not retain, use or disclose Customer Personal Data for any purpose other than performing the Services specified in the Agreement, will not sell or share it, will not retain, use or disclose it outside the direct business relationship between us, and will not combine it with personal information received from another source except as the CCPA permits a service provider to do. We certify that we understand and will comply with these restrictions.

2.3Each party is independently responsible for its own compliance with Data Protection Law in respect of the role it holds.

2.4You acknowledge that you determine what is collected, about whom, at what frequency, with what redaction, and for how long it is kept, and that you alone are responsible for establishing a lawful basis, for giving notice to Data Subjects, and for completing any consultation, works-council agreement, impact assessment or authority notification that the law requires before monitoring begins.

3.

Our processing instructions

3.1We will process Customer Personal Data only on your documented instructions, including for international transfers, unless required to do otherwise by law to which we are subject. Where a law requires us to process without your instruction, we will inform you of that legal requirement before processing, unless the law prohibits us from doing so on important grounds of public interest.

3.2Your instructions are: the Agreement itself, the configuration you set in the Services, and any further written instruction you give us. Using a feature is an instruction to perform the processing that feature performs.

3.3We will tell you if, in our opinion, an instruction infringes Data Protection Law. We may decline to carry out an instruction that we reasonably believe would cause us to breach the law, and we may exercise the refusal and suspension rights set out in the Platform Terms of Service.

3.4We will not process Customer Personal Data for our own purposes, and specifically will not use it to train, fine-tune or improve any generative artificial-intelligence or machine-learning model, whether ours or a third party's, as set out in the AI Features Terms.

4.

Details of the processing

4.1The subject matter, duration, nature and purpose of the processing, the categories of Personal Data and of Data Subjects, and the frequency of transfers are set out in Annex I to this DPA, which forms part of it.

5.

Confidentiality of personnel

5.1We will ensure that every person we authorize to process Customer Personal Data is subject to a binding duty of confidentiality, is trained on their data-protection obligations, and processes it only on our instructions.

5.2We limit access to Customer Personal Data to personnel who need it to provide, secure or support the Services, and we log staff access to customer environments so that it can be reviewed.

6.

Security

6.1We will implement and maintain the technical and organizational measures set out in Annex II, taking into account the state of the art, the costs of implementation, the nature, scope, context and purposes of processing, and the risks to Data Subjects.

6.2Annex II states what is in place today, and it states plainly what is not. We consider a technical-measures annex that overstates a control to be a breach of this DPA from the day it takes effect, so we have written it to be accurate rather than reassuring. You should read it before you deploy, and you should factor what it says into your own impact assessment.

6.3We may update the measures in Annex II from time to time, provided that the update does not materially reduce the overall level of security.

6.4You are responsible for your own security decisions in your use of the Services, including who you grant access to, whether you require single sign-on and multi-factor authentication, what you configure to be captured, and the security of the devices your people use.

7.

Sub-processors

7.1You give us general written authorization to engage Sub-processors to process Customer Personal Data, subject to this section.

7.2Our current Sub-processors, what each is engaged to do, and where each processes data, are published in our Sub-processor list, which forms part of this DPA and is set out in summary in Annex III.

7.3We will give account administrators at least 30 days' notice before a new or replacement Sub-processor begins processing Customer Personal Data. To receive that notice you must keep a current administrator email address on the account; you may also ask us at privacy@workmonitor.ai to add a named recipient.

7.4You may object to a new Sub-processor on reasonable data-protection grounds by writing to privacy@workmonitor.ai within the notice period, giving your reasons. We will work with you in good faith to address the objection, which may include making a change to your configuration, offering an alternative, or explaining measures that address your concern. If we cannot resolve it within a reasonable time, you may terminate the affected subscription without penalty by written notice, and we will refund prepaid, unused fees for the remainder of the Subscription Term.

7.5We will impose data-protection obligations no less protective than those in this DPA on each Sub-processor, by written contract. We remain fully liable to you for a Sub-processor's performance of those obligations, and our liability to you is not reduced by a Sub-processor's failure to perform.

7.6Stated plainly, because it is the kind of thing a customer is entitled to know rather than to discover: written Article 28 terms and Standard Contractual Clauses are not yet executed with every Sub-processor currently engaged. Putting them in place is committed work, tracked in our Legal Change Log. We describe this obligation as one we will meet rather than one already met, because a warranty that contracts exist would be a warranty we cannot presently evidence.

8.

International transfers

8.1We process Customer Personal Data in the United States, and our Sub-processors process it in the locations named in the Sub-processor list.

8.2We do not participate in the EU-US Data Privacy Framework, the UK Extension to it, or the Swiss-US Data Privacy Framework, and we make no claim to any certification we do not hold.

8.3EU transfers. Where we process Customer Personal Data subject to the EU GDPR and transfer it out of the European Economic Area to a country without an adequacy decision, the SCCs are incorporated into this DPA by reference and apply as follows. Module Two (controller to processor) applies where you are a controller. Module Three (processor to processor) applies where you are a processor for another controller. Clause 7, the docking clause, applies. In Clause 9, Option 2, general written authorization, applies with the notice period stated in the Sub-processors section. In Clause 11, the optional independent dispute-resolution paragraph does not apply. In Clause 17, the clauses are governed by the law of Ireland. In Clause 18(b), disputes are resolved before the courts of Ireland. Annex I, Annex II and Annex III of the SCCs are the corresponding annexes to this DPA.

8.4UK transfers. Where the UK GDPR applies, the UK Addendum is incorporated by reference and applies to the SCCs. In Table 1, the parties and their details are as set out in Annex I. In Table 2, the version of the Approved SCCs to which the Addendum applies is the version described above. In Table 3, the appendix information is Annexes I to III to this DPA. In Table 4, neither party may end the Addendum as set out in Section 19.

8.5Swiss transfers. Where the Swiss Federal Act on Data Protection applies, the SCCs apply with these adaptations: references to the GDPR are to the Swiss Act, the competent authority is the Federal Data Protection and Information Commissioner, references to a member state do not prevent a Data Subject in Switzerland from suing in their place of habitual residence, and the term "personal data" covers data about legal entities until Swiss law provides otherwise.

8.6Other transfer mechanisms. Where a valid alternative transfer mechanism becomes available and applies to a transfer, it applies in place of the mechanism above, and we will update this DPA.

8.7Transfer impact assessment. We maintain an assessment of the laws and practices of the destination country relevant to these transfers, together with the supplementary measures we apply. We will provide our summary of it, and reasonable assistance with your own assessment, on request to privacy@workmonitor.ai.

8.8Government access. We have received no national-security order requiring us to disclose Customer Personal Data, and no order prohibiting us from saying so. Our commitments on challenging and disclosing government requests are in the Law Enforcement and Government Requests policy, and they apply as obligations under this DPA.

9.

Assistance with Data Subject rights

9.1The Services give you the tools to access, correct, export and delete Customer Personal Data yourself. In most cases that is the fastest route and no request to us is needed.

9.2Taking into account the nature of the processing, we will assist you by appropriate technical and organizational measures, insofar as possible, in fulfilling your obligation to respond to requests from Data Subjects exercising their rights. Where the tools in the Services are not sufficient, write to privacy@workmonitor.ai and we will help.

9.3If a Data Subject contacts us directly about Customer Personal Data, we will not respond to the substance of the request other than to acknowledge it and to direct the person to you, and we will notify you of the request without undue delay, unless we are legally prohibited from doing so or the person is exercising a right against us as controller.

9.4We do not charge for reasonable assistance under this section.

10.

Personal Data Breach

10.1We will notify you without undue delay, and in any event within 48 hours, after becoming aware of a Personal Data Breach affecting Customer Personal Data.

10.2The notification will describe, to the extent known at the time: the nature of the breach, the categories and approximate number of Data Subjects and records concerned, the likely consequences, the measures taken or proposed to address it and to mitigate its effects, and a contact point for more information. Where we cannot provide all of that at once, we will provide it in phases without undue further delay.

10.3We will take reasonable steps to contain and investigate the breach, will preserve evidence, and will cooperate with you and provide the information you reasonably need to meet your own notification obligations to a Supervisory Authority or to Data Subjects.

10.4Notification of a breach is not an admission of fault or liability by us.

10.5You are responsible for deciding whether a breach must be notified to a Supervisory Authority or to Data Subjects, and for making that notification, because you are the Controller and only you know the full context of your deployment.

10.6We maintain an incident-response plan and will make a summary of it available to you on request. We record every incident and its outcome.

11.

Impact assessments and prior consultation

11.1Employee monitoring is high-risk processing. Under Article 35 of the EU GDPR, a Data Protection Impact Assessment is effectively mandatory for systematic monitoring of employees, and equivalent obligations exist in other jurisdictions. Carrying it out is your obligation as Controller.

11.2Taking into account the nature of the processing and the information available to us, we will provide reasonable assistance with your impact assessment and with any prior consultation with a Supervisory Authority. In practice that means giving you accurate information about how the Services work, what they collect, what the controls do, and where our security position has gaps — Annex II is written with this use in mind.

11.3We will make available the information reasonably necessary to demonstrate compliance with the obligations in this DPA.

12.

Audits

12.1We will make available to you the information reasonably necessary to demonstrate compliance with Article 28 of the EU GDPR and equivalent obligations, and will allow for and contribute to audits, including inspections, conducted by you or an auditor you mandate.

12.2In the first instance, you may satisfy an audit right by reviewing the documentation we publish and maintain: our Security Policy, this DPA and its annexes, our Sub-processor list, our control inventory with source references, our open gap list, and our completed security-questionnaire responses. We will answer reasonable follow-up questions in writing.

12.3Where that is not sufficient for a specific, identified concern, you may request an audit by giving at least 30 days' written notice. An audit will be at your expense, during business hours, subject to confidentiality obligations, conducted so as not to disrupt our operations or the security of other customers, limited to information relevant to your processing, and no more than once in any 12-month period — unless a Supervisory Authority requires otherwise, or unless there has been a Personal Data Breach affecting your Customer Personal Data, in which case you may audit as reasonably necessary in response.

12.4An auditor you mandate must not be a competitor of ours, and must sign a confidentiality undertaking before the audit begins.

12.5We do not currently hold a SOC 2 or ISO 27001 report. When we do, we will make it available under confidentiality, and providing it will satisfy the audit right for the scope and period it covers. We say this here rather than referring you to a report that does not exist.

13.

Deletion and return

13.1You may export Customer Personal Data at any time during the Subscription Term using the export functions in the Services.

13.2On termination or expiry of the Agreement, we will, at your choice, delete or return Customer Personal Data. Unless you tell us otherwise, we will make it available for export for 30 days after termination, and then delete it.

13.3We will delete or irreversibly de-identify Customer Personal Data within 90 days of the end of that export window, and will procure that our Sub-processors do the same.

13.4We may retain Customer Personal Data where required by law, and copies present in routine backups are deleted as those backups expire on their normal cycle. Anything retained remains subject to this DPA and is not processed for any purpose other than the one requiring its retention.

13.5Retention deletion carried out during the Subscription Term — the daily sweep that removes captures past the window you configured — is irreversible by design and cannot be undone by us or by you.

13.6We will certify deletion in writing on request.

14.

Liability

14.1Each party's liability arising out of or relating to this DPA, including under the SCCs, is subject to the exclusions and limitations of liability in the Platform Terms of Service.

14.2Nothing in this DPA limits a Data Subject's rights under Data Protection Law, or a party's liability to a Data Subject or a Supervisory Authority. Where the SCCs give a Data Subject a right against us directly, that right is not limited by the Agreement.

15.

Order of precedence and changes

15.1If this DPA conflicts with the Platform Terms of Service or any other part of the Agreement on the processing of Personal Data, this DPA prevails. If this DPA conflicts with the SCCs, the SCCs prevail.

15.2We may update this DPA where necessary to reflect a change in Data Protection Law, a decision of a Supervisory Authority, a new transfer mechanism, or a change in the Services, provided the update does not reduce your protections. Material changes are notified as described in the Platform Terms of Service and recorded in the Legal Change Log.

15.3This DPA takes effect on the date you accept the Agreement and continues for as long as we process Customer Personal Data.

16.

Annex I — Details of the processing

16.1This Annex is Annex I to the SCCs and to the UK Addendum.

A. List of parties
RoleDetails
Data exporterThe Customer identified in the Agreement, acting as controller (or as processor for its own controller). Contact details are those held on the account. Activities relevant to the transfer: deploying the Services to measure work in its own organization. Signature and date: effective on acceptance of the Agreement. Role: controller, or processor where Module Three applies.
Data importerDigital Socket LLC, 131 Continental Dr, Suite 305, Newark, DE 19713, United States. Contact: Data Protection Officer, dpo@workmonitor.ai. Activities relevant to the transfer: providing the WorkMonitor workforce-analytics platform. Signature and date: effective on acceptance of the Agreement. Role: processor.
B. Description of the transfer
ItemDescription
Categories of data subjectsThe Customer's employees, workers, contractors, freelancers and agency staff whose activity is monitored or whose working time is recorded; the Customer's administrators, managers and other authorized users; and, where the Customer enables it, the Customer's own clients who are given restricted visibility of work done for them.
Categories of personal dataIdentification and contact data (name, work email, job title, team, manager, profile photo, account identifier). Authentication data (hashed credentials, single sign-on identifiers, multi-factor seeds). Activity data (applications and websites used, active window and page titles, active and idle time, aggregate keystroke and mouse intensity). Captured images (periodic screenshots, and live view frames during an open session, where the Customer enables them). Working-time and work records (timesheets, attendance, shifts, projects, tasks, deliverables, approvals, goals, invoices). Location data (GPS coordinates recorded with a clock-in or clock-out event where geofenced job sites are used; approximate location from IP address). Device and technical data (IP address, operating system, device name and identifier, agent version, browser). Derived data (productivity, focus and engagement scores, and AI-generated summaries). Records imported from systems the Customer connects.
Sensitive dataNone is intentionally processed, and the Acceptable Use Policy prohibits the Customer from configuring the Services to infer or record special categories of personal data. Two categories nonetheless require the Customer's attention in its own assessment: precise geolocation, where geofenced job sites are used; and the possibility that a window or page title captured incidentally reveals information falling into a special category. Restrictions and safeguards applied: per-application and per-site deny lists enforced on the device before capture, blurring and redaction modes, private-time pause, configurable capture intervals, configurable retention with automated deletion, role-based access scoped to the organization, and a tamper-evident log of every access to captured material.
Frequency of the transferContinuous, for as long as the Services are in use.
Nature and purpose of the processingCollection, recording, organization, structuring, storage, retrieval, consultation, use, analysis, aggregation, transmission to destinations the Customer configures, erasure and destruction, for the purpose of providing workforce analytics, time and attendance tracking, activity monitoring, project and financial reporting, and the related security, support and billing functions.
Duration of the processingFor the term of the Agreement, plus the retention and deletion periods set out in the Deletion and return section. Captured images are retained for the window the Customer configures, subject to the cap for its plan: up to 30 days on the free plan, up to 180 days on Team, up to 365 days on Business, and a Customer-defined period on Enterprise.
Transfers to sub-processorsAs set out in Annex III and in the published Sub-processor list, for the subject matter, nature and duration stated there.
Competent supervisory authorityDetermined under Clause 13 of the SCCs by reference to the exporter's establishment or, where the exporter is not established in the EEA, its Article 27 representative or the member state where the data subjects are located. For UK transfers, the Information Commissioner's Office. For Swiss transfers, the Federal Data Protection and Information Commissioner.
17.

Annex II — Technical and organizational measures

17.1This Annex is Annex II to the SCCs and to the UK Addendum. It describes the measures in place at the effective date of this DPA.

17.2It also states, in the row on encryption at rest and in the row on known limitations, where our measures fall short of what a reviewer might assume. We publish those rather than omitting them, because a measure described here is a measure we are contractually bound to have, and because your own impact assessment is worthless if it is built on our optimism.

Measures in place
MeasureWhat is in place
Encryption in transitTLS 1.2 or better with AEAD-only cipher suites for all traffic between clients, agents and our edge. HTTP is permanently redirected to HTTPS; no plaintext HTTP is served. HSTS is set with a two-year max-age, includeSubdomains and preload. Certificates are issued and renewed automatically. Traffic between components inside the host runs on an internal-only network with no published ports and is not separately encrypted; internal TLS is committed work.
Encryption at restApplication-layer AES-256-GCM authenticated encryption, with a fresh random 96-bit initialization vector per value and a self-describing ciphertext envelope, protects integration credentials and OAuth tokens, single sign-on client secrets and identity-provider certificates, multi-factor seeds, provisioning tokens, and per-organization signing keys. The master key is mandatory in production and the platform refuses to start without it. This does not extend to monitoring content: screenshots, application and window titles, activity counts and clock-in coordinates are stored without application-layer encryption, and the deployment does not currently use volume-level or database-level encryption. Verified, asserted storage-level encryption and application-level encryption of the highest-sensitivity columns are committed work. We will not claim encryption we do not perform.
Pseudonymization and minimizationInput activity is captured as an aggregate intensity value rather than as content; the platform has no capability to record the text of a keystroke. Capture policy — deny lists by application and by site, blurring, redaction mode and private-time pause — is enforced on the device before an image leaves it. Capture intervals, retention windows and the scope of monitoring are configurable by the Controller.
Access controlRole-based access with least privilege. Tenant isolation is derived from the credential itself and enforced in the data layer rather than by application convention, so a request cannot reach another organization's data by changing an identifier. Permissions can be scoped to a node of the organization, so a regional manager cannot see beyond their boundary. Single sign-on and multi-factor authentication are available; multi-factor is not currently enforced by default for customer administrators, and we recommend you enable it.
Staff accessAccess to customer environments is limited to personnel who need it, is role-based, and is recorded on an audit trail available to the Controller. Staff are bound by confidentiality obligations and receive data-protection training. The staff administration console is restricted at the network edge in addition to authentication.
Logging and auditabilityConsequential actions — configuration changes, permission grants, access to captured material, exports and staff actions — are recorded on a hash-chained, tamper-evident audit trail that the Controller can inspect and re-verify. Application and security logs are collected centrally on infrastructure we operate.
Data segregationCustomer data is logically segregated by organization at the data layer. We do not operate shared mutable state across customers.
Resilience and recoveryContinuous archiving with point-in-time recovery for the primary database, automated backup scheduling, and documented restore procedures. Restores are tested; recovery objectives are set out in our business continuity and disaster recovery plan, available on request.
Secure developmentVersion-controlled changes with peer review, automated test suites gating merges, dependency and container vulnerability scanning in the build pipeline, and secrets held in an encrypted store rather than in the repository.
Vulnerability managementAutomated scanning of dependencies and images, a published vulnerability disclosure route with safe-harbour terms, and defined remediation targets by severity. No independent penetration test has yet been performed; commissioning one is committed work, and we disclose its absence rather than implying an assurance we have not obtained.
Physical securityThe Services run in data centres operated by our hosting sub-processor, which maintains physical access control, environmental controls and its own certifications. We hold no physical infrastructure of our own that processes Customer Personal Data.
Incident responseA documented incident-response plan with severity classification, containment, investigation, notification and post-incident review. Breach notification to the Controller within 48 hours of awareness, as set out in this DPA.
Sub-processor managementWritten data-protection terms with each Sub-processor before it processes Customer Personal Data, a published register, and 30 days' notice with a right to object before a new one is engaged.
DeletionAutomated daily retention sweeps that delete captures past the configured window, irreversibly. Deletion on instruction, and deletion or irreversible de-identification within 90 days of the end of the post-termination export window.
CertificationsNone held. WorkMonitor is pre-launch; SOC 2 Type II and ISO/IEC 27001 are in preparation. We publish our control inventory with references to the code implementing each control, together with our open gap list, in place of a badge.
Known limitations we discloseNo blanket encryption at rest for monitoring content, as described above. No database row-level security; isolation is enforced by schema constraints and by the credential. No key-management service and no bring-your-own-key; do not accept a BYOK claim from us today. No enforced multi-factor authentication for customer administrators. No independent penetration test to date. Deactivating a user does not immediately invalidate an already-issued session token. Each of these is tracked in our gap register with an owner and a remediation commitment, and each is available to your security reviewer in writing.
18.

Annex III — Sub-processors

18.1This Annex is Annex III to the SCCs. The authoritative and current list, with the detail of what each Sub-processor is engaged to do, is published as our Sub-processor list, which forms part of this DPA. The summary below is correct at the effective date of this DPA.

Authorized sub-processors
Sub-processorProcessing carried outLocation
OVHcloudHosting and object storage. The Services run on this infrastructure, and captured images, activity records and the application database are stored on it.United States
AnthropicLarge-language-model processing for AI features. Receives a prompt containing a named team member and their aggregated activity metrics when a summary, digest or written answer is generated. Contractually prohibited from training on the data. Not engaged where no AI provider is configured.United States
StripePayment processing, subscription billing and invoicing. Receives the billing contact and payment method. Engaged only for customers on a paid plan. Card details are entered on Stripe's hosted page and never reach our systems.United States, European Union
PostmarkTransactional email delivery: invitations, digests and account notices.United States
IntercomIn-product support messaging. For a signed-in user, receives the account identifier, name, email address and account creation date.United States
  • Destinations a Customer configures — HR, payroll, accounting, chat, project, warehouse and payout systems — are not our Sub-processors. We transmit to them on the Customer's instruction, using credentials the Customer supplies, and the Customer's own agreement with that provider governs what happens next.
19.

How to reach us about this DPA

19.1Data Protection Officer: dpo@workmonitor.ai. General privacy matters: privacy@workmonitor.ai. Contractual matters, including a countersigned copy: legal@workmonitor.ai.

19.2By post: Digital Socket LLC, 131 Continental Dr, Suite 305, Newark, DE 19713, United States, marked for the attention of the Data Protection Officer.

19.3We are established in the United States and are in the process of appointing representatives under Article 27 of the EU GDPR and the UK GDPR. Their details will be published here and in our Legal Change Log once appointed. Until then, contact the Data Protection Officer at the address above.

Questions about this document:legal@workmonitor.aiBack to the register