Privacy & data protectionEffective September 8, 2026Version 3.1
DPA FAQs
Answers for the person reviewing our Data Processing Addendum. The DPA itself governs; this page is a map to it.
Do we need to sign the DPA?
No. It is pre-executed. It takes effect automatically when you accept the Platform Terms of Service and binds both parties from that moment, with no signature, countersignature or return required.
If your process requires a signed copy for your records, write to legal@workmonitor.ai. We will provide a countersigned copy that matches the published text word for word. We will not, as a rule, sign a version with negotiated changes for a self-serve subscription; for an Enterprise agreement, changes are handled in the Order Form or a written amendment.
Can we use our own DPA template instead?
For an Enterprise agreement, we will review one. Send it to legal@workmonitor.ai with your redlines and we will tell you which points we can accept.
Two things we will not agree to, in any template: a technical-measures annex describing controls we do not operate, and an unlimited liability carve-out for data protection. The first would make us in breach on day one; the second is addressed by the position in the Platform Terms of Service.
Where you use your own template, its annexes still have to describe what actually happens, and we will correct them where they do not.
Which Standard Contractual Clauses do you use?
The clauses annexed to Commission Implementing Decision (EU) 2021/914. Module Two applies where you are a controller; Module Three applies where you are a processor for someone else. The docking clause applies. Clause 9 uses Option 2, general written authorization, with the 30-day notice period in the Sub-processors section. The optional independent dispute-resolution paragraph in Clause 11 does not apply. Irish law governs and the Irish courts are the forum.
For the UK, the ICO's International Data Transfer Addendum, version B1.0, applies to those clauses, with the tables completed in the DPA. For Switzerland, the SCCs apply with the Swiss adaptations set out there.
Annexes I, II and III to our DPA are the SCC annexes. You do not need to complete anything.
Do you rely on the Data Privacy Framework?
No. We do not participate in the EU-US Data Privacy Framework, the UK Extension, or the Swiss-US Framework, and we hold no certification of any kind. Standard Contractual Clauses are our transfer mechanism.
We maintain a transfer impact assessment and will share our summary of it, and the supplementary measures we apply, on request to privacy@workmonitor.ai.
How do we hear about a new sub-processor?
WorkMonitor will notify account administrators by email at least 30 days before a new sub-processor begins processing. Keep those addresses current, and ask us at privacy@workmonitor.ai if you want a named recipient added for these notices.
You may object on reasonable data-protection grounds within the notice period. We will work with you in good faith; if we cannot resolve it in a reasonable time, you may terminate the affected subscription without penalty and we refund prepaid, unused fees.
The current list, with what each sub-processor does and where, is published on the Sub-processors page, which forms part of the DPA. Changes are also recorded in the Legal Change Log.
What is your breach notification commitment?
Notification to you without undue delay and in any event within 48 hours of us becoming aware, with the nature of the breach, the categories and approximate numbers affected, the likely consequences, the measures taken, and a contact point — supplied in phases if we cannot give it all at once.
We help you meet your own obligations. Deciding whether to notify an authority or the individuals is yours, as controller.
Can we audit you? Do you have a SOC 2 report?
You can audit, on the terms in the Audits section: documentation first, then an on-notice audit once a year at your expense, and without that limit after a breach affecting your data or where a supervisory authority requires it.
We hold no SOC 2 or ISO 27001 report. WorkMonitor is pre-launch; both are in preparation. When a report exists we will share it under confidentiality and it will satisfy the audit right for its scope and period.
What you can have today: our security questionnaire responses, our control inventory with references to the code implementing each control, our open gap list, and our incident-response and continuity summaries.
What does Annex II actually commit you to?
Read it rather than assuming it. It is more candid than most technical-measures annexes, deliberately.
It commits us to TLS 1.2 or better in transit, AES-256-GCM field encryption of secrets, role-based access with tenant isolation enforced in the data layer, a hash-chained audit trail, point-in-time recovery, dependency and container scanning, and 48-hour breach notification.
It also states what is not in place: no blanket encryption at rest for monitoring content, no KMS or bring-your-own-key, no independent penetration test yet, no enforced multi-factor authentication for administrators, no database row-level security, and session tokens that survive a user deactivation until they expire.
We disclose those because a measures annex is a contractual commitment. One that overstates a control puts us in breach from the day it takes effect, and it would make your own impact assessment worthless.
What happens to our data when we leave?
You can export throughout the term. After termination we keep the data available for export for 30 days, then delete or irreversibly de-identify it within 90 days, and require our sub-processors to do the same.
Copies in routine backups go as those backups expire on their normal cycle. Anything we must keep for a legal obligation stays subject to the DPA and is used for nothing else.
We will certify deletion in writing on request.
Who is the controller for the monitoring itself?
You are. You decide who is monitored, what is collected, at what frequency, with what redaction, and how long it is kept.
That also means the lawful basis, the employee notices, the works-council or employee-representative process, the impact assessment and any authority notification are yours. The Platform Terms of Service set this out as express warranties, and employee monitoring is high-risk processing for which an impact assessment is effectively mandatory under Article 35.
We will assist with your assessment by giving you accurate information about how the software works and where our controls fall short. Annex II is written with that use in mind.
Are our integrations your sub-processors?
No. Where you connect an HR, payroll, accounting, chat, project, warehouse or payout system, we transmit to it on your instruction using credentials you supply. That provider is your processor, and your agreement with it governs what happens next.
So adding one is not a change to our sub-processor list and does not trigger the notice process — you are the one adding it, and you are the one who needs terms in place with them.
Who do we talk to?
Data Protection Officer: dpo@workmonitor.ai. Privacy operations: privacy@workmonitor.ai. Countersigned copies, redlines and contractual questions: legal@workmonitor.ai.
By post: Digital Socket LLC, 131 Continental Dr, Suite 305, Newark, DE 19713, United States.