Privacy & data protectionEffective September 8, 2026Version 3.1
Sub-processors
This page lists every sub-processor WorkMonitor engages to help deliver the Services, what each one is engaged to do, and where each processes data. It forms part of our Data Processing Addendum and is Annex III to the Standard Contractual Clauses incorporated by it.
Each sub-processor processes personal data only as needed to provide its service to us. We will impose on each of them, by written contract, data-protection obligations no less protective than those we owe you, and we remain fully liable to you for their performance. Written Article 28 terms are not yet executed with every sub-processor named below; completing them is committed work, tracked in our Legal Change Log, and we would rather say so than warrant contracts we cannot presently evidence.
We give account administrators at least 30 days' notice before a new or replacement sub-processor begins processing, and you may object on reasonable data-protection grounds. How that works is set out at the end of this page.
Infrastructure and hosting
This is where the Services run and where your data lives.
| Sub-processor | Engaged to do | Location | Privacy information |
|---|---|---|---|
| OVHcloud | Bare-metal hosting and S3-compatible object storage. The application, the database and the queue run on this infrastructure, and captured images, activity records and work records are stored on it. | United States | https://us.ovhcloud.com/legal/privacy-policy/ |
Payments and billing
Engaged only for customers on a paid plan.
| Sub-processor | Engaged to do | Location | Privacy information |
|---|---|---|---|
| Stripe | Payment processing, subscription billing and invoicing. Receives the billing contact and the payment method used for the subscription. Card details are entered on Stripe's hosted checkout page and never reach WorkMonitor systems; we hold only the card type, the last four digits and the expiry. Stripe's data-processing terms are at https://stripe.com/legal/dpa. | United States, European Union | https://stripe.com/privacy |
AI processing
Engaged only where an AI provider is configured for a deployment. Where none is configured, every AI feature falls back to a summary computed entirely within our own infrastructure and no data leaves it.
| Sub-processor | Engaged to do | Location | Privacy information |
|---|---|---|---|
| Anthropic | Large-language-model processing for AI features. A prompt containing the named team member and their aggregated activity metrics is sent when a day summary, team digest or written answer is generated, and when a delivered-work narrative names who shipped what. Most run only when someone asks; an organization that enables the scheduled summary agent has them generated automatically on a weekday schedule. Captured screenshots are never sent. Contractually prohibited from using the data to train or improve models, as set out in our AI Features Terms. | United States | https://www.anthropic.com/legal/privacy |
Communications and support
These carry account correspondence and support conversations.
| Sub-processor | Engaged to do | Location | Privacy information |
|---|---|---|---|
| Postmark | Transactional email delivery: invitations, digests, account notices, security alerts and billing notices. Receives the recipient address and the content of the message. | United States | https://postmarkapp.com/privacy-policy |
| Intercom | In-product support messaging. For a signed-in user, receives the account identifier, name, email address and account creation date so a support conversation can be attributed. The messenger also loads before you sign in — on the sign-in, sign-up and password-reset pages — where a visitor who is not signed in still reaches Intercom, which receives their IP address and browser details. It does not load on the public certificate verifier or in embedded views. | United States | https://www.intercom.com/legal/privacy |
Website analytics and advertising measurement
Engaged only for visitors who accept, and for the purpose they accepted. Until a visitor answers, the script is never requested, so nothing at all reaches this processor.
Google appears once on this page and does two things under two separate records of consent. Measurement follows the analytics answer; conversion measurement for our own advertising follows the advertising answer, which is refused by default and is refused without asking where the browser sends a Global Privacy Control signal. The two records can diverge and often do — under that signal, for a visitor who accepted analytics before advertising was ever asked about, and for anyone who has used our "Do Not Sell or Share My Personal Information" control — but our cookie banner itself asks them together, with one Accept and one Decline covering both, so it is not a way of keeping one and dropping the other.
One flow on this page does not come from a browser at all, and it is set out here rather than only in the row below. Where an organization was created from a visit that carried an advertisement click identifier and recorded an advertising consent, and that organization pays its first invoice, our own servers report that payment once to our advertising account. Nothing about that report passes through the visitor's browser, so no cookie setting and no browser control describes it; the way to stop it is to refuse advertising, which deletes the stored click identifier and cancels anything queued.
| Sub-processor | Engaged to do | Location | Privacy information |
|---|---|---|---|
| Google (Google Analytics 4 and Google Ads conversion measurement) | Two purposes under two records of consent, one processor. ANALYTICS: measurement of how our public website and the signed-in application are used, as two separate properties, where you accept analytics cookies. What is sent is the page viewed and the action taken. Page addresses are rewritten before they are sent, so an identifier in a path — a team member, a certificate reference — is replaced with a placeholder, and query strings and fragments from the signed-in application are removed entirely rather than filtered. ADVERTISING, where you accept advertising cookies, and it reaches Google along two different routes. From your browser: a coarse bucket for the kind of page it was — pricing, comparison, legal and ten others — with the site's origin and never the page address, path, query string or fragment; the click identifier of the advertisement you arrived through; the conversion completed, for each conversion action we have created in the advertising account, which we create one at a time; and, only where you typed one into our demo request or sign-up form, a SHA-256 hash of that email address, computed in your browser so the address itself never leaves it. From our servers, once, if an organization created from such a visit pays its first invoice: the click identifier, an internal account reference, the amount and currency of that invoice, and a SHA-256 hash of the email address of the person who created the account, hashed by us before it is sent. With advertising accepted we build remarketing audiences from those page buckets and Google may use what it receives to select our advertisements for you on other sites, which California law calls sharing for cross-context behavioural advertising. Neither purpose and neither route receives a raw email address, an organization name, or any captured activity, window title or screenshot data, and none of them receives anything about a person monitored through the Services — no identifier of a monitored worker, hashed or otherwise. Neither is loaded on our staging environment or on the public certificate verifier. Advertising storage stays denied for a visitor who declined, who was never asked, or whose browser sent a Global Privacy Control signal, and no server-side report is made for an organization whose visit recorded no advertising consent. | United States | https://business.safety.google/privacy/ |
Services that receive no personal data
Named for completeness, because a security reviewer will find them in a network trace and should not have to wonder.
| Service | What it does | What it receives |
|---|---|---|
| Cloudflare | Hosts the DNS zone for our domains so that TLS certificates can be issued. | DNS records are not proxied, so no application traffic and no personal data pass through it. |
| jsDelivr and fonts.scalar.com | Serve the viewer and fonts for our public API reference page, which needs no login. | Opening that one page sends your IP address and browser details to those hosts. The script is pinned to a specific version and checked against a cryptographic hash, so it cannot be swapped for different code. No account data and no captured data is present on that page. Nothing else on our site or in the product loads from either host. |
Destinations you configure
Where you configure a data-warehouse export, an HR-system integration, a chat notification, a project-tool time entry, or a payroll, accounting or payout connector, data is sent to a destination the customer selects and contracts with directly, using credentials you supplied.
Those destinations do receive personal data. They are your own processors rather than WorkMonitor sub-processors: we transmit to them on your instruction, and your agreement with that provider governs what happens next. They are therefore not listed here, and adding one does not trigger the notice process below — you are the one adding it.
The full catalogue of connectors the Services can talk to is published in our integrations directory.
Notification of changes
We will give account administrators at least 30 days' notice before a new or replacement sub-processor begins processing personal data. Notice goes to the administrator email addresses on the account, so keep them current; you may also ask us at privacy@workmonitor.ai to add a named recipient for these notices.
You may object on reasonable data-protection grounds by writing to privacy@workmonitor.ai within the notice period, giving your reasons. We will work with you in good faith — which may mean a configuration change, an alternative, or an explanation of measures that address the concern. If we cannot resolve it in a reasonable time, you may terminate the affected subscription without penalty and we will refund prepaid, unused fees.
In an emergency — where a sub-processor must be replaced immediately to keep the Services running or to close a security risk — we may act first and notify you as soon as we can, with the same right to object afterwards.
One case this process does not cover, said plainly so that nobody has to guess. Adding advertising measurement to the analytics row in September 2026 did not trigger the notice period, because that processor was already disclosed here and the new purpose adds no new one. What the new purpose does reach, beyond website-visitor data, is one narrow thing that belongs to the customer rather than to a visitor: when an account pays its first invoice, the amount of that invoice and a hash of the email address of the person who created the account are reported to the advertising account, as the row above sets out. That is the account's own commercial relationship with us and no part of what the platform captures about anyone. It is recorded in the Legal Change Log, and a customer who would rather it were not reported for their organization can say so at privacy@workmonitor.ai, which deletes the click identifier we hold and stops it.
Every change to this list is recorded in our Legal Change Log, so you can see what changed and when.
Questions
Questions about a sub-processor, or a request for the data-processing terms we hold with one: privacy@workmonitor.ai, or our Data Protection Officer at dpo@workmonitor.ai.