WorkMonitor.

Legal and compliance

Every document, published in full

The DPA and its annexes, the sub-processor list, the platform terms and everything incorporated into them. Each at its own address, each dated, each clause numbered. Read them today and forward them to whoever signs off; nothing here waits on a sales call.

OverviewEffective Not dated

Legal Overview

This is where Digital Socket LLC publishes the agreements, policies and disclosures that govern how WorkMonitor is sold, used and operated.

It is written for the people who actually open these pages: the administrator accepting terms, the procurement lead comparing them to a template, the security reviewer working through a questionnaire, the privacy officer looking for the DPA, and the monitored worker trying to find out what the software can see.

Everything here is provided for transparency and is not legal advice.

01

How the register is organized

Overview holds this page, the Legal Change Log — the dated record of what changed and when — and our Accessibility Statement.

Privacy and data protection holds the Privacy Policy, the US State Privacy Rights Notice, the Cookie Policy, the Data Processing Addendum with its annexes, the Sub-processor register, the Worker Privacy Notice, our policy on law-enforcement and government requests, and two FAQs that map the longer documents.

Product terms holds the agreements that govern the account: the Platform Terms of Service, the Website Terms of Use, the Acceptable Use Policy, the AI Features Terms, the API and Developer Terms, the Beta and Early Access Terms, the Order Form Terms, the Service Level Agreement, the Support Policy and the Affiliate Programme Terms.

Security and brand holds the Security Policy, the Vulnerability Disclosure Policy, the Copyright and DMCA Policy, and the Brand and Trademark Usage Policy.

There is no legacy-terms group. The register used to publish two archived editions of the Terms of Service, and both were withdrawn rather than superseded because neither had ever governed a subscription — the Legal Change Log records why, and it is the place to look for what an earlier edition said.

02

Which document wins

The Platform Terms of Service is the master agreement, and every other live agreement here is incorporated into it. Where two documents conflict, the order is: a signed master agreement or amendment first; then an Order Form, for the commercial terms it states; then the Data Processing Addendum, for anything about the processing of personal data; then the Platform Terms of Service; then the incorporated policies; then the documentation.

A conflict is resolved only as far as the inconsistency goes — the rest of the lower-ranked document still applies.

A purchase order, a vendor portal's click-through, or any other document issued by a customer adds nothing and is expressly rejected, even where we sign or acknowledge it for administrative purposes.

The Privacy Policy, the Cookie Policy, the US State Privacy Rights Notice and the Worker Privacy Notice are notices rather than commercial terms. They do not vary the agreements, but the commitments we make in them bind us.

03

Where to start, by who you are

Signing up or evaluating: the Platform Terms of Service, then the Acceptable Use Policy — in particular the section on what you must have in place before you monitor anyone.

Running a security or privacy review: the Data Processing Addendum, its Annex II, the Sub-processor register and the Security Policy. Ask us at security@workmonitor.ai for the control inventory, the open gap list and our questionnaire responses.

Rolling monitoring out to a workforce: the Acceptable Use Policy and the Worker Privacy Notice, alongside your own legal advice. Our jurisdiction guides are background reading and are not advice.

Being monitored: the Worker Privacy Notice. It is short, it is written for you, and it says what the software cannot do as well as what it can.

Building on the API or embedding a widget: the API and Developer Terms, and the Beta and Early Access Terms if you are using something not yet generally available.

Referring customers to us: the Affiliate Programme Terms and the Brand and Trademark Usage Policy.

04

What we will not claim

A note on how these documents are written, because it explains some sentences that look unusual for a vendor.

WorkMonitor is pre-launch and holds no security certifications. SOC 2 and ISO 27001 are in preparation. We publish our control inventory with references to the code implementing each control, and our open gap list beside it, rather than a badge we have not earned.

Annex II of the Data Processing Addendum states which technical measures are not in place as well as which are, because a measures annex is a contractual commitment and one that overstates a control is a breach from the day it takes effect.

The Cookie Policy names every cookie both applications actually set, including the analytics cookies and, since September 2026, the advertising cookies that go with measuring our own advertisements — and it names the one consequence a reader is entitled to know about, which is that accepting advertising means sharing for cross-context behavioural advertising under California law. The US State Privacy Rights Notice says the same thing in the statute's own words and gives the opt-out, rather than claiming there is nothing to opt out of.

The Brand and Trademark Usage Policy claims unregistered rights, and uses the ™ symbol rather than ®, because we hold no trademark registration. Where a commitment is not yet complete, it is listed as outstanding in the Legal Change Log rather than written as though it were done.

05

Keeping you informed

Every live document shows its effective date and version at the top. Every change is recorded in the Legal Change Log.

Where a change materially and adversely affects your rights, we give account administrators at least 30 days' notice before it takes effect, and you may terminate the affected subscription before it does. New sub-processors carry the same 30 days' notice and a right to object.

Notices go to the administrator email addresses on your account, so keep them current.

06

Who to write to

Contracts, order forms and formal notices: legal@workmonitor.ai.

Privacy questions and data-subject requests: privacy@workmonitor.ai. Our Data Protection Officer: dpo@workmonitor.ai.

Security reports and vulnerability disclosure: security@workmonitor.ai.

Billing, refunds and support: support@workmonitor.ai. Accessibility: accessibility@workmonitor.ai. Press: press@workmonitor.ai.

By post: Digital Socket LLC, a Delaware limited liability company, 131 Continental Dr, Suite 305, Newark, DE 19713, United States.

If you hold a signed order form or master agreement with us, that agreement controls to the extent it conflicts with anything published here.

Questions about this document:legal@workmonitor.aiBack to the register