Privacy & data protectionEffective September 8, 2026Version 3.1
Global Privacy Policy
WorkMonitor is a product of Digital Socket LLC, a Delaware limited liability company with its registered office at 131 Continental Dr, Suite 305, Newark, DE 19713, United States ("WorkMonitor", "we", "us" or "our"). We operate the workmonitor.ai website and provide workforce analytics, time tracking and activity-monitoring services.
This Privacy Policy explains what personal data we handle, why, who else sees it, how long we keep it, and what you can ask us to do about it.
It matters a great deal which of two roles we are in. When we decide why and how personal data is processed — about the administrators who buy from us, the visitors to our website, the people who apply for jobs with us — we are a controller, and this policy describes what we do. When an employer deploys WorkMonitor to monitor its workforce, that employer is the controller and we are its processor: it decides who is monitored, what is collected and how long it is kept, and our obligations to it are set out in the Data Processing Addendum. If you are a monitored worker, the Worker Privacy Notice is written for you, and the section below headed "If you are a monitored worker" tells you where to direct a request.
Who this policy is for
Visitors to our website, our documentation, our help centre and our public certificate verifier.
Administrators, billing contacts and users of the WorkMonitor platform, and people at organizations who contact us about it.
Individuals whose activity is monitored through the Services by an employer ("Monitored Users"), for the limited purposes described below where we act as a controller in our own right — principally security, fraud prevention and legal compliance.
People who apply for a job with us, and people who deal with us as suppliers, partners or affiliates.
The personal data we handle
We group it by where it comes from, because that is what determines what we may do with it.
- Account and profile data
- Name, work email address, job title, organization, profile photo, language and time zone, authentication credentials in hashed form, single sign-on identifiers, and multi-factor authentication settings. Where you sign in with Google, LinkedIn or GitHub, we receive your name, email address and account identifier from that provider.
- Billing data
- Billing contact, billing address, tax identifiers, plan, seat count, invoices and payment history. Card numbers are entered on our payment processor's hosted page and never reach our systems; we hold only the card type, the last four digits and the expiry.
- Activity data
- Where an employer deploys the agent: the applications and websites in use, the titles of active windows and pages, active and idle time, working sessions, and aggregate input intensity — a count of keystrokes and mouse events expressed as an activity level. We do not record the content of what is typed. We are not a keylogger, and the agent has no capability to capture the text of a keystroke.
- Screenshots
- Where the employer enables them, periodic still images of the screen, at an interval and with the blurring and exclusions the employer configures. We do not record continuous video and we do not make screen recordings.
- Live view frames
- Where the employer enables live view and an authorized viewer opens a session, the agent sends still frames for that session. These are held transiently to deliver the session to the viewer and are discarded when the session ends; they are not added to the stored screenshot history.
- Work records
- Timesheets, attendance, projects, tasks, deliverables, approvals, goals, invoices and the certificates and credentials generated from them.
- Location data
- Where the employer uses geofenced job sites, the GPS coordinates recorded with a clock-in or clock-out event on a device that supports it, and whether that position falls inside a boundary the employer defined. This is recorded at the moment of the event; the Services do not maintain a continuous location trail. Approximate location is also derived from IP address for security and fraud prevention.
- Device and log data
- IP address, operating system and version, device name and identifier, agent version, browser and user-agent, and the diagnostic and security logs needed to operate the Services.
- Audit records
- A tamper-evident record of consequential actions in the platform: who changed a setting, who viewed a capture, who exported data, who granted a permission.
- Support and correspondence
- Messages you send us through the in-product messenger, email, contact forms or demo requests, and our replies.
- Website and marketing data
- Pages viewed, the action taken, referring page, approximate location derived from IP address, and analytics identifiers — but only where you have accepted analytics cookies. Page addresses are rewritten before they are sent so that identifiers in them are replaced with a placeholder. See the Cookie Policy.
- Advertising and conversion data
- Where you have accepted advertising cookies: the click identifier carried by an advertisement you arrived through (gclid, gbraid or wbraid), the advertising cookies the Google tag sets on our domain, the conversion you completed, a coarse bucket describing the kind of page you were on — pricing, comparison, legal and ten others, which is what allows a remarketing audience to be built — and, where you typed an email address into our demo request or sign-up form, a SHA-256 hash of that address, computed in your browser so the address itself is never sent. Where an account created from such a visit later pays its first invoice, the same category also covers what we report about that payment from our own servers: the click identifier, an internal account reference, the amount and currency of the invoice, and a SHA-256 hash of the email address of the person who created the account, hashed by us before it is sent. No activity data, screenshot, window title or other data about a monitored worker is used for advertising or reaches an advertising system, and nothing in this category is collected or reported for anyone who declined, was never asked, or whose browser sent a Global Privacy Control signal.
- Recruitment data
- Where you apply to work with us: your application, CV, correspondence, interview notes and the outcome.
- We do not knowingly collect special categories of personal data — health, biometric, genetic, racial or ethnic origin, political opinions, religious beliefs, trade-union membership, sex life or sexual orientation — and the Acceptable Use Policy prohibits customers from configuring the Services to infer or record them. Because activity data includes window and page titles, such information can in principle appear incidentally in a capture; that is one reason the platform provides deny lists, blurring and redaction, and one reason employers are required to configure them.
- We do not sell personal data. We do share one narrow category for advertising: where a visitor to our public website accepts advertising cookies, the conversion data described above is disclosed to Google so that we can measure which of our advertisements worked, and California law calls that sharing for cross-context behavioural advertising. It covers that visitor, and it covers the purchase an account they created later makes — their own commercial dealings with us and nothing beyond them. Everything the platform captures about a monitored worker — activity records, screenshots, window titles, timesheets, scores and their identity — is never sold, never shared for advertising, and never reaches an advertising system in any form.
Where we get it
Directly from you, when you create an account, contact us, buy a subscription or apply for a job.
From your employer, where it invites you to an account or configures monitoring for your device.
From the WorkMonitor agent and extensions installed on a device, at the configuration the employer has set.
From your identity provider, where you sign in with Google, LinkedIn, GitHub or a corporate single sign-on.
From our own systems, in the form of logs, audit records and usage telemetry.
From third parties you connect, where an employer configures an HR, payroll, identity or project integration that sends us records about people.
Why we use it, and our legal basis
Where the GDPR, the UK GDPR or a comparable law applies, we rely on the legal bases set out below for the processing we carry out as a controller. Where we act as a processor for an employer, the legal basis for the monitoring itself is that employer's to establish, not ours.
| What we do | Why | Legal basis |
|---|---|---|
| Provide the Services, create and administer accounts, deliver the features an organization has configured | To perform the agreement with the customer | Contract; legitimate interests in providing a service to our customer |
| Bill for the Services, collect payment, keep accounting records | To get paid and to meet tax and accounting obligations | Contract; legal obligation |
| Authenticate users, detect and prevent fraud, abuse and unauthorized access, keep audit records | To keep the platform and the data in it secure | Legitimate interests in security; legal obligation |
| Provide support and respond to correspondence | To answer the person who contacted us | Contract; legitimate interests in supporting our customers |
| Monitor performance, diagnose faults and improve the Services | To keep the product working and make it better | Legitimate interests in operating and improving our product |
| Send service and administrative messages about the account | To tell administrators about changes, incidents and renewals | Contract; legal obligation for some notices |
| Send marketing email about our products | To tell business contacts about what we do | Consent, where required; otherwise legitimate interests, subject to an opt-out in every message |
| Set analytics and other non-essential cookies | To understand how the website is used | Consent |
| Set advertising cookies, measure conversions from our advertisements, and match a conversion to a click using an email address hashed in your browser | To find out which of our advertisements bring people to us, and to stop paying for the ones that do not | Consent, given separately from the consent above and refused by default, including where a Global Privacy Control signal is present |
| Comply with law, respond to lawful requests, establish or defend legal claims | Because we must, or to protect our position | Legal obligation; legitimate interests in defending claims |
| Assess a job application | To decide whether to make an offer | Steps prior to entering a contract; legitimate interests in recruiting |
- Where we rely on legitimate interests, we have considered whether our interest is overridden by your interests and rights, and we have recorded that assessment. You may object to processing based on legitimate interests, as described in the rights section below.
Automated decision-making
We do not make decisions about you based solely on automated processing that produce a legal effect for you or similarly significantly affect you.
The platform produces scores, indices and AI-generated summaries about work. These are inputs for a manager, not decisions. Under our Acceptable Use Policy and our AI Features Terms, a customer may not use them as the sole basis for a decision about discipline, dismissal, pay, promotion or a formal performance rating without meaningful human review. If your employer has made such a decision about you, the decision and the obligation to explain it are theirs.
Where your data is processed, and international transfers
The Services run on infrastructure located in the United States, and our sub-processors are listed with the locations in which each processes data.
If you are in the European Economic Area, the United Kingdom or Switzerland, this means your personal data is transferred outside your country to a jurisdiction that has not received an adequacy decision.
We do not participate in the EU-US Data Privacy Framework, the UK Extension, or the Swiss-US Data Privacy Framework. We do not claim any certification we do not hold.
For those transfers we rely on the European Commission's Standard Contractual Clauses, on the UK International Data Transfer Addendum for UK transfers, and on the Swiss adaptations for Swiss transfers, together with supplementary technical and organizational measures. The clauses, the modules that apply and the measures are set out in our Data Processing Addendum, and we will provide a copy on request to privacy@workmonitor.ai.
We have carried out and maintain a transfer impact assessment covering these transfers, and we will share our summary of it with a customer's privacy team on request.
How long we keep it
Where we act as a processor, the customer sets the retention period within the limits of its plan, and we delete on that schedule and on the customer's instruction.
| Data | How long |
|---|---|
| Screenshots and captured images | The window the customer configures, capped by plan: up to 30 days on the free plan, up to 180 days on Team, up to 365 days on Business. Enterprise customers may configure a longer or unlimited window. A daily sweep deletes anything past the window, and deletion is irreversible. |
| Live view frames | Discarded when the live session ends. They are never added to the stored history. |
| Activity records, timesheets and work records | For the life of the account, unless the customer deletes them sooner, then deleted or irreversibly de-identified within 90 days of the account ending. |
| Account and profile data | For the life of the account, then deleted within 90 days of the account ending. |
| Billing records and invoices | Seven years from the end of the relevant tax year, to meet accounting and tax obligations. |
| Audit records | Retained as a tamper-evident chain for up to ten years, because their value is that they cannot be quietly edited or trimmed. They record actions and actors, not captured content. |
| Security and diagnostic logs | Up to 12 months, then deleted. |
| Support correspondence | Three years from the last message in the thread. |
| Website analytics data | Up to 14 months, where you consented to analytics cookies. |
| Advertising and conversion data | Three things with three different lives, because one figure would have been wrong about two of them. The wm_gclid cookie in your browser lasts 90 days from the click, and the advertising cookies the Google tag sets last up to 90 days. The click identifier we store in our own database when an account is created from an advertisement has no fixed expiry today: it stops being usable after 90 days, which is the limit Google itself applies to a conversion, but nothing yet sweeps it away, and it is deliberately not deleted with the workspace, because it explains a payment our accounting records have to keep. An automatic purge once it passes that window is committed work, listed in our Legal Change Log, and we would rather say that than publish a period we do not enforce. Refusing advertising deletes all three at once, along with any conversion queued and not yet reported. Conversion records held by Google are kept under its own retention schedule, which we do not control and do not represent as ours. |
| Recruitment data | Twelve months after the outcome of the application, unless you ask us to keep it longer for future roles or a longer period is required by law. |
- We may retain data for longer where we must to comply with a legal obligation, to establish or defend a legal claim, or to enforce our agreements — and where we do, we keep only what is needed for that purpose and keep protecting it.
- Backups are kept for disaster recovery and are cycled out on their own schedule. Data deleted from the live systems is removed from backups as those backups expire.
Your rights
Depending on where you are, you may have the following rights. We honour them for everyone we can, whether or not the law where you live requires it.
- Access — to be told whether we hold personal data about you and to receive a copy.
- Rectification — to have inaccurate data corrected and incomplete data completed.
- Erasure — to have data deleted, where there is no overriding reason for us to keep it.
- Restriction — to have us pause processing while a dispute about accuracy or legitimacy is resolved.
- Portability — to receive data you gave us in a structured, commonly used, machine-readable format, and to have it sent to another controller where technically feasible.
- Objection — to object to processing based on legitimate interests, and to object at any time to direct marketing, which we will always honour.
- Withdraw consent — where we rely on consent, at any time, without affecting processing already carried out.
- Complain — to your local supervisory authority or data protection regulator. We would rather you came to us first, but you are not required to.
- To exercise a right, write to privacy@workmonitor.ai. We will verify your identity before we act, so that we do not disclose someone's data to the wrong person, and we will respond within one month, or tell you within one month if we need longer and why. There is no charge unless a request is manifestly unfounded or excessive.
- If you are in the United States, additional and differently named rights may apply to you. They are set out in our US State Privacy Notice.
If you are a monitored worker
Where your employer deploys WorkMonitor, your employer is the controller of the data about you and we are its processor. The law generally requires us to direct your request to it, and we are not permitted to hand over, correct or delete an employer's data on the say-so of someone else.
So: send your request to your employer first. It has the tools in the platform to answer it, and the Data Processing Addendum obliges us to assist it in doing so.
If you write to us at privacy@workmonitor.ai instead, we will acknowledge you, tell you plainly what we can and cannot do, and pass the request to the employer without undue delay unless doing so would be unlawful.
Two things are not limited by any of that. If you believe your employer's use of WorkMonitor is unlawful, you may tell us and we will look at it, as described in the Acceptable Use Policy. And you may complain to your own supervisory authority at any time, without going through your employer or through us.
The Worker Privacy Notice describes in plain terms what the software can and cannot see.
Security
We protect personal data with technical and organizational measures appropriate to the risk, described in detail in our Security Policy and in Annex II of the Data Processing Addendum.
In summary: traffic is encrypted in transit with TLS 1.2 or better and preloaded HSTS; access is role-based, least-privilege and scoped to an organization by the credential itself; staff access to customer environments is limited, logged and reviewable; and consequential actions land on a tamper-evident audit chain.
On encryption at rest we are deliberately precise, because this is the claim most often overstated in our market. Application-layer AES-256-GCM encryption covers our secrets — integration tokens, single sign-on secrets, multi-factor seeds, signing keys. It does not currently cover monitoring content: screenshots, application and window titles, activity counts and clock-in coordinates are stored without application-layer encryption, and the deployment does not yet use volume-level encryption. Verified storage-level encryption is a committed piece of work, and until it is in place and tested we will not claim it. The full position, including the gaps, is set out in Annex II of our Data Processing Addendum.
We are pre-launch and hold no security certifications. SOC 2 and ISO 27001 are in preparation. Rather than a badge, we publish our control inventory with references to the code that implements each control, and our open gap list beside it. If a certificate is a hard requirement in your procurement, this is the honest place to find that out.
No system is perfectly secure. If we become aware of a personal-data breach affecting Customer Data, we will notify the affected customer without undue delay in accordance with the Data Processing Addendum. Where we are the controller of affected data, we will notify the relevant supervisory authority and affected individuals where the law requires.
To report a vulnerability, use our Vulnerability Disclosure Policy.
Children
The Services are for business use and are not directed to children. We do not knowingly collect personal data from anyone under 16.
An employer may only monitor a minor where that minor is lawfully employed by it and every requirement applying to the employment of minors has been met, as required by the Acceptable Use Policy.
If you believe we hold data about a child in error, write to privacy@workmonitor.ai and we will delete it.
Marketing
We send marketing email only to business contacts, and only where we may lawfully do so. Every marketing message has an unsubscribe link that works, and unsubscribing takes effect promptly.
Unsubscribing from marketing does not stop service messages about your account — invoices, security notices, changes to these documents — because those are part of providing the Services.
Data protection roles and how to reach them
We have appointed a Data Protection Officer, who can be reached at dpo@workmonitor.ai or by post at the registered office below, marked for their attention.
We are established in the United States and do not currently have an establishment in the European Union or the United Kingdom. We are in the process of appointing representatives under Article 27 of the EU GDPR and Article 27 of the UK GDPR, and we will publish their details in this policy and in our Legal Change Log as soon as they are appointed. Until then, individuals and authorities in the EU, the UK and Switzerland should contact our Data Protection Officer at dpo@workmonitor.ai, which is monitored and answered.
General privacy questions: privacy@workmonitor.ai. Postal address: Digital Socket LLC, 131 Continental Dr, Suite 305, Newark, DE 19713, United States.
Changes to this policy
We may update this policy. The effective date at the top of the page always shows when the current version took effect, and every change is recorded in our Legal Change Log.
Where a change materially affects how we handle personal data, we will give notice to account administrators before it takes effect, and we will obtain consent where the law requires it.