WorkMonitor.

Legal and compliance

Every document, published in full

The DPA and its annexes, the sub-processor list, the platform terms and everything incorporated into them. Each at its own address, each dated, each clause numbered. Read them today and forward them to whoever signs off; nothing here waits on a sales call.

Privacy & data protectionEffective September 8, 2026Version 3.1

Global Privacy Policy

WorkMonitor is a product of Digital Socket LLC, a Delaware limited liability company with its registered office at 131 Continental Dr, Suite 305, Newark, DE 19713, United States ("WorkMonitor", "we", "us" or "our"). We operate the workmonitor.ai website and provide workforce analytics, time tracking and activity-monitoring services.

This Privacy Policy explains what personal data we handle, why, who else sees it, how long we keep it, and what you can ask us to do about it.

It matters a great deal which of two roles we are in. When we decide why and how personal data is processed — about the administrators who buy from us, the visitors to our website, the people who apply for jobs with us — we are a controller, and this policy describes what we do. When an employer deploys WorkMonitor to monitor its workforce, that employer is the controller and we are its processor: it decides who is monitored, what is collected and how long it is kept, and our obligations to it are set out in the Data Processing Addendum. If you are a monitored worker, the Worker Privacy Notice is written for you, and the section below headed "If you are a monitored worker" tells you where to direct a request.

01

Who this policy is for

Visitors to our website, our documentation, our help centre and our public certificate verifier.

Administrators, billing contacts and users of the WorkMonitor platform, and people at organizations who contact us about it.

Individuals whose activity is monitored through the Services by an employer ("Monitored Users"), for the limited purposes described below where we act as a controller in our own right — principally security, fraud prevention and legal compliance.

People who apply for a job with us, and people who deal with us as suppliers, partners or affiliates.

02

The personal data we handle

We group it by where it comes from, because that is what determines what we may do with it.

Account and profile data
Name, work email address, job title, organization, profile photo, language and time zone, authentication credentials in hashed form, single sign-on identifiers, and multi-factor authentication settings. Where you sign in with Google, LinkedIn or GitHub, we receive your name, email address and account identifier from that provider.
Billing data
Billing contact, billing address, tax identifiers, plan, seat count, invoices and payment history. Card numbers are entered on our payment processor's hosted page and never reach our systems; we hold only the card type, the last four digits and the expiry.
Activity data
Where an employer deploys the agent: the applications and websites in use, the titles of active windows and pages, active and idle time, working sessions, and aggregate input intensity — a count of keystrokes and mouse events expressed as an activity level. We do not record the content of what is typed. We are not a keylogger, and the agent has no capability to capture the text of a keystroke.
Screenshots
Where the employer enables them, periodic still images of the screen, at an interval and with the blurring and exclusions the employer configures. We do not record continuous video and we do not make screen recordings.
Live view frames
Where the employer enables live view and an authorized viewer opens a session, the agent sends still frames for that session. These are held transiently to deliver the session to the viewer and are discarded when the session ends; they are not added to the stored screenshot history.
Work records
Timesheets, attendance, projects, tasks, deliverables, approvals, goals, invoices and the certificates and credentials generated from them.
Location data
Where the employer uses geofenced job sites, the GPS coordinates recorded with a clock-in or clock-out event on a device that supports it, and whether that position falls inside a boundary the employer defined. This is recorded at the moment of the event; the Services do not maintain a continuous location trail. Approximate location is also derived from IP address for security and fraud prevention.
Device and log data
IP address, operating system and version, device name and identifier, agent version, browser and user-agent, and the diagnostic and security logs needed to operate the Services.
Audit records
A tamper-evident record of consequential actions in the platform: who changed a setting, who viewed a capture, who exported data, who granted a permission.
Support and correspondence
Messages you send us through the in-product messenger, email, contact forms or demo requests, and our replies.
Website and marketing data
Pages viewed, the action taken, referring page, approximate location derived from IP address, and analytics identifiers — but only where you have accepted analytics cookies. Page addresses are rewritten before they are sent so that identifiers in them are replaced with a placeholder. See the Cookie Policy.
Advertising and conversion data
Where you have accepted advertising cookies: the click identifier carried by an advertisement you arrived through (gclid, gbraid or wbraid), the advertising cookies the Google tag sets on our domain, the conversion you completed, a coarse bucket describing the kind of page you were on — pricing, comparison, legal and ten others, which is what allows a remarketing audience to be built — and, where you typed an email address into our demo request or sign-up form, a SHA-256 hash of that address, computed in your browser so the address itself is never sent. Where an account created from such a visit later pays its first invoice, the same category also covers what we report about that payment from our own servers: the click identifier, an internal account reference, the amount and currency of the invoice, and a SHA-256 hash of the email address of the person who created the account, hashed by us before it is sent. No activity data, screenshot, window title or other data about a monitored worker is used for advertising or reaches an advertising system, and nothing in this category is collected or reported for anyone who declined, was never asked, or whose browser sent a Global Privacy Control signal.
Recruitment data
Where you apply to work with us: your application, CV, correspondence, interview notes and the outcome.
  • We do not knowingly collect special categories of personal data — health, biometric, genetic, racial or ethnic origin, political opinions, religious beliefs, trade-union membership, sex life or sexual orientation — and the Acceptable Use Policy prohibits customers from configuring the Services to infer or record them. Because activity data includes window and page titles, such information can in principle appear incidentally in a capture; that is one reason the platform provides deny lists, blurring and redaction, and one reason employers are required to configure them.
  • We do not sell personal data. We do share one narrow category for advertising: where a visitor to our public website accepts advertising cookies, the conversion data described above is disclosed to Google so that we can measure which of our advertisements worked, and California law calls that sharing for cross-context behavioural advertising. It covers that visitor, and it covers the purchase an account they created later makes — their own commercial dealings with us and nothing beyond them. Everything the platform captures about a monitored worker — activity records, screenshots, window titles, timesheets, scores and their identity — is never sold, never shared for advertising, and never reaches an advertising system in any form.
03

Where we get it

Directly from you, when you create an account, contact us, buy a subscription or apply for a job.

From your employer, where it invites you to an account or configures monitoring for your device.

From the WorkMonitor agent and extensions installed on a device, at the configuration the employer has set.

From your identity provider, where you sign in with Google, LinkedIn, GitHub or a corporate single sign-on.

From our own systems, in the form of logs, audit records and usage telemetry.

From third parties you connect, where an employer configures an HR, payroll, identity or project integration that sends us records about people.

05

Automated decision-making

We do not make decisions about you based solely on automated processing that produce a legal effect for you or similarly significantly affect you.

The platform produces scores, indices and AI-generated summaries about work. These are inputs for a manager, not decisions. Under our Acceptable Use Policy and our AI Features Terms, a customer may not use them as the sole basis for a decision about discipline, dismissal, pay, promotion or a formal performance rating without meaningful human review. If your employer has made such a decision about you, the decision and the obligation to explain it are theirs.

06

Who we share it with

We share personal data only in the situations set out here.

  • Your organization. If you use the Services under an employer's account, that employer — and the administrators and managers it authorizes — can see the data the platform holds about you, within the scope it has configured.
  • Sub-processors. Service providers that process personal data on our behalf under written terms, listed in full, with what each one does and where, in our Sub-processor list. We give at least 30 days' notice before adding or replacing one.
  • Destinations you configure. Where a customer connects an HR, payroll, accounting, chat, project, warehouse or payout system, we transmit data to it on the customer's instruction. That provider is the customer's own processor and its agreement with the customer governs what happens next.
  • Our advertising measurement provider. Where a visitor to our public website accepts advertising cookies, Google receives the conversion data described in the "Advertising and conversion data" entry above, so that we can measure our own advertising. Two things reach it: what that visitor's browser reports, and — once, if an account they created pays its first invoice — what our servers report about that payment, which includes a hash of the account creator's email address. Nothing about a Monitored User reaches it: no activity data, no screenshot, no window title, no timesheet, no score, and no identity or address of a monitored worker, hashed or otherwise.
  • Professional advisers. Our lawyers, accountants, auditors and insurers, under duties of confidentiality.
  • Authorities, where required. Only as described in our Law Enforcement and Government Requests policy, which sets out what we require before we disclose anything and when we tell you about it.
  • A corporate transaction. If we are involved in a merger, acquisition, financing or sale of assets, personal data may be transferred as part of it, subject to this policy and to notice to affected customers. A buyer would take the data on terms no less protective than these.
  • We do not sell personal data, and we do not disclose Customer Data to a model developer or use it to train generative models — see the AI Features Terms.
  • The one disclosure that needs stating rather than denying: with a website visitor's consent, we share that visitor's conversion data with Google for cross-context behavioural advertising, and where an account created from that visit pays its first invoice we report that purchase to Google as well, as described above and in the Cookie Policy. That is the whole of it, and what it amounts to is the account holder's own commercial relationship with us. It never includes activity data, screenshots, window titles or anything else the platform captured about a person monitored through the Services, and no employer's monitoring data is used to advertise anything to anyone.
07

Where your data is processed, and international transfers

The Services run on infrastructure located in the United States, and our sub-processors are listed with the locations in which each processes data.

If you are in the European Economic Area, the United Kingdom or Switzerland, this means your personal data is transferred outside your country to a jurisdiction that has not received an adequacy decision.

We do not participate in the EU-US Data Privacy Framework, the UK Extension, or the Swiss-US Data Privacy Framework. We do not claim any certification we do not hold.

For those transfers we rely on the European Commission's Standard Contractual Clauses, on the UK International Data Transfer Addendum for UK transfers, and on the Swiss adaptations for Swiss transfers, together with supplementary technical and organizational measures. The clauses, the modules that apply and the measures are set out in our Data Processing Addendum, and we will provide a copy on request to privacy@workmonitor.ai.

We have carried out and maintain a transfer impact assessment covering these transfers, and we will share our summary of it with a customer's privacy team on request.

08

How long we keep it

Where we act as a processor, the customer sets the retention period within the limits of its plan, and we delete on that schedule and on the customer's instruction.

Retention periods
DataHow long
Screenshots and captured imagesThe window the customer configures, capped by plan: up to 30 days on the free plan, up to 180 days on Team, up to 365 days on Business. Enterprise customers may configure a longer or unlimited window. A daily sweep deletes anything past the window, and deletion is irreversible.
Live view framesDiscarded when the live session ends. They are never added to the stored history.
Activity records, timesheets and work recordsFor the life of the account, unless the customer deletes them sooner, then deleted or irreversibly de-identified within 90 days of the account ending.
Account and profile dataFor the life of the account, then deleted within 90 days of the account ending.
Billing records and invoicesSeven years from the end of the relevant tax year, to meet accounting and tax obligations.
Audit recordsRetained as a tamper-evident chain for up to ten years, because their value is that they cannot be quietly edited or trimmed. They record actions and actors, not captured content.
Security and diagnostic logsUp to 12 months, then deleted.
Support correspondenceThree years from the last message in the thread.
Website analytics dataUp to 14 months, where you consented to analytics cookies.
Advertising and conversion dataThree things with three different lives, because one figure would have been wrong about two of them. The wm_gclid cookie in your browser lasts 90 days from the click, and the advertising cookies the Google tag sets last up to 90 days. The click identifier we store in our own database when an account is created from an advertisement has no fixed expiry today: it stops being usable after 90 days, which is the limit Google itself applies to a conversion, but nothing yet sweeps it away, and it is deliberately not deleted with the workspace, because it explains a payment our accounting records have to keep. An automatic purge once it passes that window is committed work, listed in our Legal Change Log, and we would rather say that than publish a period we do not enforce. Refusing advertising deletes all three at once, along with any conversion queued and not yet reported. Conversion records held by Google are kept under its own retention schedule, which we do not control and do not represent as ours.
Recruitment dataTwelve months after the outcome of the application, unless you ask us to keep it longer for future roles or a longer period is required by law.
  • We may retain data for longer where we must to comply with a legal obligation, to establish or defend a legal claim, or to enforce our agreements — and where we do, we keep only what is needed for that purpose and keep protecting it.
  • Backups are kept for disaster recovery and are cycled out on their own schedule. Data deleted from the live systems is removed from backups as those backups expire.
09

Your rights

Depending on where you are, you may have the following rights. We honour them for everyone we can, whether or not the law where you live requires it.

  • Access — to be told whether we hold personal data about you and to receive a copy.
  • Rectification — to have inaccurate data corrected and incomplete data completed.
  • Erasure — to have data deleted, where there is no overriding reason for us to keep it.
  • Restriction — to have us pause processing while a dispute about accuracy or legitimacy is resolved.
  • Portability — to receive data you gave us in a structured, commonly used, machine-readable format, and to have it sent to another controller where technically feasible.
  • Objection — to object to processing based on legitimate interests, and to object at any time to direct marketing, which we will always honour.
  • Withdraw consent — where we rely on consent, at any time, without affecting processing already carried out.
  • Complain — to your local supervisory authority or data protection regulator. We would rather you came to us first, but you are not required to.
  • To exercise a right, write to privacy@workmonitor.ai. We will verify your identity before we act, so that we do not disclose someone's data to the wrong person, and we will respond within one month, or tell you within one month if we need longer and why. There is no charge unless a request is manifestly unfounded or excessive.
  • If you are in the United States, additional and differently named rights may apply to you. They are set out in our US State Privacy Notice.
10

If you are a monitored worker

Where your employer deploys WorkMonitor, your employer is the controller of the data about you and we are its processor. The law generally requires us to direct your request to it, and we are not permitted to hand over, correct or delete an employer's data on the say-so of someone else.

So: send your request to your employer first. It has the tools in the platform to answer it, and the Data Processing Addendum obliges us to assist it in doing so.

If you write to us at privacy@workmonitor.ai instead, we will acknowledge you, tell you plainly what we can and cannot do, and pass the request to the employer without undue delay unless doing so would be unlawful.

Two things are not limited by any of that. If you believe your employer's use of WorkMonitor is unlawful, you may tell us and we will look at it, as described in the Acceptable Use Policy. And you may complain to your own supervisory authority at any time, without going through your employer or through us.

The Worker Privacy Notice describes in plain terms what the software can and cannot see.

11

Security

We protect personal data with technical and organizational measures appropriate to the risk, described in detail in our Security Policy and in Annex II of the Data Processing Addendum.

In summary: traffic is encrypted in transit with TLS 1.2 or better and preloaded HSTS; access is role-based, least-privilege and scoped to an organization by the credential itself; staff access to customer environments is limited, logged and reviewable; and consequential actions land on a tamper-evident audit chain.

On encryption at rest we are deliberately precise, because this is the claim most often overstated in our market. Application-layer AES-256-GCM encryption covers our secrets — integration tokens, single sign-on secrets, multi-factor seeds, signing keys. It does not currently cover monitoring content: screenshots, application and window titles, activity counts and clock-in coordinates are stored without application-layer encryption, and the deployment does not yet use volume-level encryption. Verified storage-level encryption is a committed piece of work, and until it is in place and tested we will not claim it. The full position, including the gaps, is set out in Annex II of our Data Processing Addendum.

We are pre-launch and hold no security certifications. SOC 2 and ISO 27001 are in preparation. Rather than a badge, we publish our control inventory with references to the code that implements each control, and our open gap list beside it. If a certificate is a hard requirement in your procurement, this is the honest place to find that out.

No system is perfectly secure. If we become aware of a personal-data breach affecting Customer Data, we will notify the affected customer without undue delay in accordance with the Data Processing Addendum. Where we are the controller of affected data, we will notify the relevant supervisory authority and affected individuals where the law requires.

To report a vulnerability, use our Vulnerability Disclosure Policy.

12

Cookies, tracking and advertising

Our website uses cookies and similar technologies. Strictly necessary cookies are set without consent because the site cannot work without them. Everything else is asked for first, and until you answer, Google's script is never requested — so nothing is written and your visit is not disclosed to Google in any form.

Two permissions are asked, and recorded separately. Analytics — Google Analytics 4 — measures how the website and the application are used. Advertising — Google Ads conversion measurement — tells us which of our advertisements led to a sign-up, and it is the processing that constitutes sharing for cross-context behavioural advertising under California law.

Advertising is refused unless you accept it. It is also refused, without asking, where your browser sends a Global Privacy Control signal, and for anyone who accepted analytics under an edition of our Cookie Policy that never put the advertising question. Two footer controls change a decision and they are not interchangeable: Cookie Settings reopens the banner, which asks both permissions together and cannot keep one while dropping the other, and "Do Not Sell or Share My Personal Information" beside it refuses advertising alone on one click and leaves your analytics decision untouched. Either way, withdrawing deletes the cookies already set, and refusing advertising also deletes the click identifier stored on our servers.

Nothing captured about a monitored worker is used for advertising. The advertising tag runs on our public website and in the signed-in application, and it receives page and conversion data about the person using the browser. Separately, after a first invoice is paid, our servers report that purchase to Google with a hash of the buying account creator's email address, which is described in full in the Cookie Policy and in our US State Privacy Rights Notice. Neither path receives activity data, screenshots, window titles, timesheets, scores, or the identity or address of any monitored worker.

The full list, what each one does and how long it lasts, is in the Cookie Policy.

13

Children

The Services are for business use and are not directed to children. We do not knowingly collect personal data from anyone under 16.

An employer may only monitor a minor where that minor is lawfully employed by it and every requirement applying to the employment of minors has been met, as required by the Acceptable Use Policy.

If you believe we hold data about a child in error, write to privacy@workmonitor.ai and we will delete it.

14

Marketing

We send marketing email only to business contacts, and only where we may lawfully do so. Every marketing message has an unsubscribe link that works, and unsubscribing takes effect promptly.

Unsubscribing from marketing does not stop service messages about your account — invoices, security notices, changes to these documents — because those are part of providing the Services.

15

Data protection roles and how to reach them

We have appointed a Data Protection Officer, who can be reached at dpo@workmonitor.ai or by post at the registered office below, marked for their attention.

We are established in the United States and do not currently have an establishment in the European Union or the United Kingdom. We are in the process of appointing representatives under Article 27 of the EU GDPR and Article 27 of the UK GDPR, and we will publish their details in this policy and in our Legal Change Log as soon as they are appointed. Until then, individuals and authorities in the EU, the UK and Switzerland should contact our Data Protection Officer at dpo@workmonitor.ai, which is monitored and answered.

General privacy questions: privacy@workmonitor.ai. Postal address: Digital Socket LLC, 131 Continental Dr, Suite 305, Newark, DE 19713, United States.

16

Changes to this policy

We may update this policy. The effective date at the top of the page always shows when the current version took effect, and every change is recorded in our Legal Change Log.

Where a change materially affects how we handle personal data, we will give notice to account administrators before it takes effect, and we will obtain consent where the law requires it.

Questions about this document:legal@workmonitor.aiBack to the register