Privacy & data protectionEffective September 8, 2026Version 3.1
Privacy FAQ
Short answers to the questions we are asked most. Each one points to the document that governs, which is what actually binds us.
If you are a monitored worker, the Worker Privacy Notice is written for you and answers most of this in plain terms.
Do you sell our data?
No. We do not sell personal data, we do not disclose it to data brokers, and we never will: your Customer Data is not a product we have, and the Platform Terms of Service bind us to that rather than leaving it as a promise on a marketing page.
One thing you should know rather than be reassured about, because it changed in September 2026. We advertise WorkMonitor on Google, and where a visitor to our public website accepts advertising cookies we share that visitor's page data with Google, and the conversions we report where a conversion action has been set up in our advertising account, so that we can tell which advertisements worked. California law calls that sharing for cross-context behavioural advertising, and our US State Privacy Rights Notice says so and gives the opt-out.
There is one more piece of it, and it is not a browser thing. If your account came to us from one of our advertisements and then paid its first invoice, we report that payment once to our advertising provider: the click identifier, an internal account reference, the invoice amount, and a hash of the email address of whoever created the account. That is your organization's own commercial relationship with us — you clicked, you bought, the advertising account is told — and it is written into the Platform Terms of Service as an express carve-out rather than left for you to discover.
Everything the platform captures stops here. No activity record, no screenshot, no window title, no timesheet, no score, and no identifier of a monitored worker — in the clear or as a hash — is used for advertising or reaches an advertising system in any form. The Platform Terms of Service state that as a binding commitment with no exception, and the Worker Privacy Notice states it in plain terms to the person being measured.
Do you train AI models on our data?
No. We do not use Customer Data to train, fine-tune or improve any generative model, ours or anyone else's, and we contract with our AI sub-processors on terms that prohibit them from doing so with what we send them.
That commitment is in the AI Features Terms. It is not qualified by the clause allowing aggregated statistics: aggregated data is not used for model training either.
If we ever intended to change this, it would take 30 days' notice, a positive opt-in from your administrators, and it would not apply to data collected before you opted in.
Can you read what our employees type?
No. Keystrokes are counted, not captured. The agent turns keyboard and mouse activity into an intensity number and has no code path that stores the text of a key press. There is no keylogger in the product.
The honest caveat: the active window and page title are recorded, and a title can be revealing — a document name, an email subject, the name of a site. That is why deny lists, blurring and redaction are enforced on the device before anything leaves it, and why configuring them is part of deploying lawfully.
Do you record video, audio or the camera?
No to all three. There is no microphone capture and no camera capture anywhere in the product, and no continuous screen recording.
Where an employer enables screenshots, they are still images at an interval. Where an employer enables live view, frames exist only while a viewer has a session open and are discarded when it closes — they are never added to the stored history.
Who is the controller, you or our company?
Your company. It decides who is monitored, what is collected, how long it is kept and who can see it. We process on its documented instructions as its processor, under the Data Processing Addendum.
We are a controller in our own right for a narrower set of things: the account and billing data of the people who deal with us, our website visitors, our job applicants, and the security and audit records we need to run the platform. The Privacy Policy separates the two.
Where is our data stored?
On infrastructure in the United States. Our sub-processors and the locations in which each processes data are listed on the Sub-processors page.
We do not offer an EU-hosted region today. If that is a requirement for you, tell us before you buy rather than after.
How do you handle EU and UK transfers? Do you have Privacy Shield?
We rely on the European Commission's Standard Contractual Clauses, on the UK International Data Transfer Addendum, and on the Swiss adaptations, together with supplementary measures. They are incorporated into our Data Processing Addendum with the modules, options and annexes filled in.
We do not participate in the EU-US Data Privacy Framework or its UK and Swiss extensions, and Privacy Shield has not existed since 2020. We hold no certification of any kind and we do not claim one.
We maintain a transfer impact assessment and will share our summary with your privacy team on request.
Do we need to sign your DPA?
No. It is pre-executed and takes effect automatically when you accept the Platform Terms of Service.
If your procurement process needs a countersigned copy, write to legal@workmonitor.ai and we will provide one matching the published text. The DPA FAQ covers this in more detail.
How long do you keep captured data?
Your administrator sets the window, within the cap for your plan: up to 30 days on the free plan, up to 180 days on Team, up to 365 days on Business, and a period you choose on Enterprise.
A sweep runs daily and deletes anything past the window. That deletion is irreversible — neither you nor we can undo it — so set the window before you need the data, not after.
Our own retention periods for account, billing, audit and log data are set out in the retention table in the Privacy Policy.
An employee has asked us for their data. What do we do?
Answer it yourself, using the export and access tools in the platform. You are the controller and the request is properly directed to you.
Where the tools are not enough, write to privacy@workmonitor.ai and we will assist, as the Data Processing Addendum obliges us to. We do not charge for reasonable assistance.
If the employee writes to us instead, we will acknowledge them, explain what we can and cannot do, and pass the request to you without undue delay.
Is our data encrypted?
In transit, yes: TLS 1.2 or better everywhere, with HSTS preloaded.
At rest, partly, and we are precise about this because it is the claim most often overstated in our market. Application-layer AES-256-GCM protects our secrets — integration tokens, single sign-on secrets, multi-factor seeds, signing keys. It does not currently cover monitoring content: screenshots, window titles, activity counts and clock-in coordinates are stored without application-layer encryption, and the deployment does not yet use volume-level encryption.
Verified storage-level encryption is committed work. Until it is in place and tested we will not claim it. The full position, including every gap, is in Annex II of the Data Processing Addendum.
What happens if you have a breach?
We notify the affected customer without undue delay and in any event within 48 hours of becoming aware, with the detail set out in the Data Processing Addendum, and we help you meet your own notification obligations.
Deciding whether to notify a supervisory authority or the affected individuals is yours as controller, because only you know the full context of your deployment.
Notice goes to the administrator addresses on the account, so keep them current.
Can we audit you?
Yes, on the terms in the Audits section of the Data Processing Addendum.
In the first instance we would rather answer with documents: our security questionnaire responses, our control inventory with source references, our open gap list, and our incident-response and continuity summaries. Most reviews are satisfied by those plus written follow-ups.
Where they are not, you may audit on 30 days' notice, once a year, at your expense — and without that limit after a breach affecting your data or where a supervisory authority requires it.
We hold no SOC 2 or ISO 27001 report to send you. When we do, it will satisfy the audit right for its scope and period.
Do you have a DPO?
Yes. Our Data Protection Officer can be reached at dpo@workmonitor.ai, or by post at our registered office marked for their attention.
We are established in the United States and do not have an EU or UK establishment. Representatives under Article 27 of the EU and UK GDPR are in the process of being appointed, and their details will be published in the Privacy Policy and the Legal Change Log once they are. Until then, EU, UK and Swiss individuals and authorities should contact the Data Protection Officer, which is a monitored and answered address.
What if we think our own employer is using this unlawfully?
Tell us at privacy@workmonitor.ai. Our Acceptable Use Policy prohibits monitoring nobody was told about, monitoring outside the working relationship, and monitoring aimed at union activity, whistleblowing or a protected complaint.
We will look at what you tell us. We will be straight with you about the limits: for data your employer holds as controller, the decisions are theirs and the law directs your request to them. We will not identify you to your employer where we are not obliged to and where doing so could expose you to retaliation.
You can also complain to your own data protection authority at any time, without going through anyone.
Who do we contact?
Privacy questions and data-subject requests: privacy@workmonitor.ai. Data Protection Officer: dpo@workmonitor.ai. Security: security@workmonitor.ai. Contracts: legal@workmonitor.ai.
By post: Digital Socket LLC, 131 Continental Dr, Suite 305, Newark, DE 19713, United States.