WorkMonitor.

Legal and compliance

Every document, published in full

The DPA and its annexes, the sub-processor list, the platform terms and everything incorporated into them. Each at its own address, each dated, each clause numbered. Read them today and forward them to whoever signs off; nothing here waits on a sales call.

OverviewEffective September 8, 2026

Legal Change Log

Every material change to the agreements and notices published here is recorded on this page, with the date it took effect and what changed.

Where a change materially and adversely affects a customer's rights or obligations, we give account administrators at least 30 days' notice before it takes effect, as the Platform Terms of Service require. This page is the durable record of that.

01

Version 3.1 — September 8, 2026

WorkMonitor began advertising on Google, and a Google Ads conversion tag now runs on our website and in the signed-in application for visitors who accept it. This edition says so everywhere it is relevant. Version 3.0 stated in eight documents that we ran no advertising, set no advertising cookie, and did not share personal information for cross-context behavioural advertising. All three were true when they were written. None of them survives an advertising tag, so all three have been replaced rather than softened.

On the effective date, which is the same day as version 3.0 and is deliberate. Version 3.0 took effect on September 8, 2026 and this amendment was made later the same day, in the release that carried the advertising tag itself — because the Cookie Policy commits us to updating it before a new non-essential cookie is set, and that is a sequencing promise rather than a formality. A date in the future would have published a Cookie Policy describing cookies while its own masthead said it was not yet in force; a date in the past would have backdated an amendment nobody could have read. A same-day amendment is the only one of the three that is true, and no visitor was ever shown the version 3.0 text while an advertising cookie could be set: the tag writes nothing until a visitor accepts a banner that names advertising and conversion measurement in terms.

The boundary this edition draws, because it is the load-bearing part, and it has two limbs rather than one. Nothing the platform captures about a monitored person, and no identifier of one — in the clear or as a hash — is disclosed to an advertising provider, used to build an audience, or used to target an advertisement. That limb is absolute and admits no exception. Alongside it sits one narrow disclosure that is described rather than denied: where an account came to us from one of our advertisements and pays its first invoice, we report that payment once to our advertising account, with the click identifier, an internal account reference, the invoice amount and a hash of the email address of the person who created the account. That is an account holder's own commercial relationship with us. The Platform Terms of Service carry both limbs as express terms, and the Worker Privacy Notice states them in plain terms to the person being measured.

Where the corpus was corrected against the code before this edition took effect, because these are the sentences a reader is most entitled to have right. Three things were described from the design of the change rather than from what shipped, and all three are now written the other way round. The footer "Do Not Sell or Share My Personal Information" control performs an advertising-only refusal directly on one click; the cookie banner asks both permissions together, with one Accept and one Decline covering both, and is described as the coarse control it is instead of as a per-purpose one. The hashing of an email address happens in two places, not one — in your browser on a form you submitted, and on our servers when a first invoice is paid — so both are described. And conversion reporting is described as what advertising consent permits, because a conversion is only reported for a conversion action created in our advertising account and those are created one at a time; on the day this edition takes effect the only thing reaching that account is the remarketing page view.

What withdrawal now reaches, which is the other half of a promise this corpus had been making about cookies alone. Refusing advertising deletes the advertising cookies in your browser and sends a request to our servers to delete the advertisement click identifier stored against your account, cancelling any conversion queued and not yet reported. The stored identifier has no automatic expiry yet; an automatic purge once it passes the ninety-day window Google itself applies is listed below as committed work rather than described as though it already runs.

What changed
DocumentChange
Cookie PolicyA new section on advertising and conversion measurement, and the advertising cookies added to the first-party table: wm_consent_ads, which records the advertising decision separately from the analytics one; wm_gclid, which holds the click identifier of the advertisement you arrived through for 90 days; and Google's _gcl_au, _gcl_aw, _gcl_dc, _gcl_gb, _gcl_gs and _gac_* cookies, which are set on our own domain. Corrects the claim that advertising and personalization storage stay denied whatever you choose, and the claim that Google's script is never requested — there is one script and the two purposes are configured from two separate answers. Describes both routes by which an email address of yours can reach Google as a hash: one you typed into our own form, hashed in your browser, and the account creator's address, hashed on our servers when a first invoice is paid. Says plainly that remarketing audiences are built, from a coarse page bucket rather than from the page address, because "we build no audiences" was one of the sentences this edition had to retract; and states that the page's own address, path, query string and fragment are not sent to the advertising account at all. Separates the two footer controls: Cookie Settings reopens a banner that asks both permissions together, and "Do Not Sell or Share My Personal Information" refuses advertising alone on one click. Records that refusing advertising also asks our servers to delete the stored click identifier.
US State Privacy Rights NoticeThe section that said we neither sell nor share is now headed and written as what it is: we do not sell, and we share one narrow category — website-visitor identifiers, the kind of page viewed, the conversion completed and a hashed email address — with Google for cross-context behavioural advertising, where the visitor accepted it. The twelve-month lookback is kept as a lookback rather than deleted. The claim that a "Do Not Sell or Share My Personal Information" link would be pointless is replaced by a section describing that link, which performs the refusal on one click, and the Global Privacy Control signal, which refuses advertising for a browser that sends it without asking and overrides an acceptance already recorded there. The same section says outright that the cookie banner is not a third, per-purpose control. A new section sets out what a conversion report contains along each of its two routes, the browser one and the server one. The CCPA category table now names the advertising disclosure against categories A, D and F, and records that nothing the agent collects on a device is ever disclosed for advertising.
Global Privacy PolicyA new category of personal data for advertising and conversion data, an advertising row in the legal-basis table with consent as the basis, an advertising recipient in the sharing list, a retention row for the click identifier and the advertising cookies, and a rewritten cookies section covering both permissions and both footer controls. The two sentences denying any sharing for cross-context behavioural advertising are replaced by a disclosure with a boundary: a website visitor's data and the purchase their account later makes, yes; anything the platform captured about a monitored person, never. The retention row states three different lives rather than one, and says plainly that the click identifier stored in our database has no automatic expiry yet.
Sub-processorsThe analytics section is now "Website analytics and advertising measurement", and Google stays a single row doing two jobs under two consents rather than becoming a second row in a second section. The row states what each purpose sends along each of its two routes — the browser tag, and the server-side report made when an account acquired from an advertisement pays its first invoice — what none of them sends, and that with advertising accepted Google may use what it receives to select advertisements on other sites. The notice-of-changes section no longer says that nothing about the new purpose could concern a customer.
Platform Terms of ServiceThe Customer Data section now states the advertising boundary expressly, in two limbs. Nothing captured from or about a Monitored User, and no identifier of one in the clear or as a hash, is disclosed to an advertising, remarketing or conversion-measurement provider, used to build an advertising audience, or used to target an advertisement — absolute, with no exception. Carved out of it, and described rather than implied, is the first-payment report we make to our advertising provider for an account acquired through one of our advertisements: the click identifier, an internal account reference, the invoice amount, and a hash of the account creator's address, with a route to stop it. Widening that carve-out is a material change requiring notice.
Worker Privacy NoticeThe sentence "We do not use it for advertising" is replaced by a paragraph that says we do advertise, explains that the measurement uses data about visitors to our website, and states that nothing the software records on your device is used to advertise anything to anyone or reaches an advertising system. A second paragraph covers the case where the person reading it is also the person who bought the subscription, since the first-payment report concerns that purchase.
Privacy FAQThe answer to "Do you sell our data?" no longer claims we set no advertising cookie. It answers the sale question, states the advertising change and where the opt-out is, names the first-payment report made for an account acquired through an advertisement, and then states the boundary that everything the platform captures stops here.
Legal OverviewCorrects a stale line that said the Cookie Policy describes no analytics cookie, which had been untrue since analytics shipped, and removes the reference to a legacy-terms group that has not existed since version 3.0 withdrew the two archived editions.
02

Version 3.0 — September 8, 2026

A full replacement of the published corpus. The previous edition was written when WorkMonitor was a smaller product, and it had stopped describing either the software or the company accurately.

Twelve documents were added and every existing one was rewritten. Live agreements now carry clause numbers so that a paragraph can be cited in a contract or a redline.

What changed
DocumentChange
Platform Terms of ServiceRewritten and expanded. New: dispute resolution by individual arbitration with class-action and jury-trial waivers, an opt-out, and express carve-outs for consumers in the EEA, the UK and Switzerland; a limitation of liability capped at twelve months of fees; mutual indemnities; a section on the customer's responsibility for deploying monitoring lawfully; our express right to refuse or suspend a deployment we reasonably believe unlawful; export control and sanctions; a one-year limitation period; and an order-of-precedence clause covering the whole corpus.
Billing termsNow stated in full: automatic renewal, fees non-refundable except under a new 14-day money-back guarantee on a first paid subscription term, 30 days' notice before any price increase, pro-rata charging for seats added mid-term, suspension after 10 days' non-payment, and interest on overdue invoices.
Data Processing AddendumRewritten with Annexes I, II and III. The EU Standard Contractual Clauses are now incorporated by reference with the modules, options and annexes completed, together with the UK International Data Transfer Addendum and the Swiss adaptations. Adds CCPA service-provider terms, a 48-hour breach-notification commitment, audit rights, and deletion and return obligations.
Annex II, technical measuresNew, and deliberately candid. It states the controls in place and the ones that are not: no blanket encryption at rest for monitoring content, no key-management service or bring-your-own-key, no independent penetration test to date, no enforced multi-factor authentication for administrators, no database row-level security, and session tokens that outlive a user deactivation until they expire.
Privacy PolicyRewritten against what the software actually does. Corrects an earlier edition that described session recordings the product has never had and a company address that was not ours. Adds a legal-basis table, a retention table, a description of the location data recorded at clock-in, and an explicit statement that we do not participate in the Data Privacy Framework.
Sub-processorsRestated as tables with a privacy-policy link for every named vendor, and a clear separation between our sub-processors and the destinations a customer configures for itself. Google is listed for analytics, with what is sent, what is rewritten before it is sent, and what is never sent at all.
Cookie PolicyRewritten as a table of the cookies actually set, each with its real lifetime read from the code: wm_consent at 180 days, wm_hero_cta at 30, and the wm_ref attribution cookie at the referring partner's window, 90 days by default — the previous edition said 30, which matched neither the code nor the Affiliate Terms. Google Analytics 4 is described as it behaves: nothing is requested from Google until you accept, advertising and personalization storage stay denied whatever you choose, and withdrawing consent deletes the cookies already set. Records that the dashboard session is a token in local storage rather than a cookie.
Service Level AgreementA measurable commitment for the first time: 99.5% monthly availability for paid plans, a three-tier service-credit schedule, a defined measurement method, exclusions, a 30-day claim window, and a chronic-failure termination right.
Acceptable Use PolicyExpanded, with the monitoring-specific prohibitions first: no covert monitoring outside narrow lawful circumstances, no monitoring outside the working relationship, no monitoring aimed at union activity or protected complaints, and no inference of special categories of personal data.
Worker Privacy NoticeRewritten for the person being measured, stating what the software cannot do — no keystroke content, no audio, no camera, no continuous recording, no location trail — and where to take a request or a complaint.
New documentsWebsite Terms of Use, US State Privacy Rights Notice, AI Features Terms, API and Developer Terms, Beta and Early Access Terms, Support Policy, Security Policy, Vulnerability Disclosure Policy, Copyright and DMCA Policy, Brand and Trademark Usage Policy, Law Enforcement and Government Requests, and this Legal Change Log.
03

Two archived editions were withdrawn, not superseded

Until this version, the register published a "Terms of Service, 2024 Edition" and a "Terms of Service, 2023 Edition", each stating the period of subscriptions it had governed.

Neither had governed anything. Digital Socket LLC registered workmonitor.ai in July 2026 and the platform first served production traffic in September 2026, so there were no subscriptions in 2023 or 2024 and no terms that applied to them. Those two pages were template residue that arrived with a purchased layout and was never removed.

They have been deleted rather than corrected, and this entry is left in their place. A published contract that claims a history the company does not have is not a harmless page: it is a document that, once noticed, invites a reader to discount every other document beside it.

If you believe you held a subscription under an earlier edition of our terms, write to legal@workmonitor.ai and we will tell you exactly what applied and when.

04

Commitments we have made and not yet completed

Statements elsewhere in this corpus that describe something we are going to do are collected here, so that they are findable in one place and cannot quietly lapse. Each will be updated on this page when it is done.

CommitmentWhere it is statedStatus
Appoint representatives under Article 27 of the EU GDPR and the UK GDPR, and publish their detailsPrivacy Policy; Data Processing AddendumIn progress. Until appointed, EU, UK and Swiss individuals and authorities should contact the Data Protection Officer at dpo@workmonitor.ai.
Complete designation of a copyright agent in the US Copyright Office directoryCopyright and DMCA PolicyIn progress. Notices sent to the address in that policy reach us and are acted on in the meantime.
Verified storage-level encryption at rest for monitoring content, with an automated check on the resulting stateAnnex II of the Data Processing Addendum; Security PolicyCommitted, not yet in place. Disclosed rather than implied.
Commission an independent penetration testAnnex II of the Data Processing Addendum; Security PolicyCommitted, not yet performed.
Delete a stored advertisement click identifier automatically once it passes the ninety-day window in which a conversion can still be reportedGlobal Privacy Policy, retention tableCommitted, not yet in place. Today such a record is deleted when advertising consent is refused, and on request. Nothing yet removes one that simply grows old, and it is deliberately not tied to the life of the workspace, because it explains a payment the accounting record has to keep. Stated rather than covered over by publishing a period we do not enforce.
Publish an annual transparency report on government and law-enforcement requestsLaw Enforcement and Government RequestsNo requests have been received, so there is nothing to report. The first report will cover the first calendar year in which a request is received.
Publish annual request metrics under California lawUS State Privacy Rights NoticeNo full reporting year has closed since this notice took effect. Figures will be published rather than estimated.
Complete SOC 2 Type II and ISO/IEC 27001Security Policy; Data Processing Addendum; across the siteIn preparation. No certification is held today, and the control inventory and open gap list are published in place of a badge.
05

How we tell you about a change

A change that materially and adversely affects your rights or obligations: at least 30 days' notice to account administrators by email or in-product notice, taking effect at the end of that period or at the start of your next Subscription Term, whichever is later. If you do not accept it you may terminate the affected subscription before it takes effect and receive a pro-rata refund.

A new or replacement sub-processor: at least 30 days' notice, with a right to object on reasonable data-protection grounds.

A change required by law, by a regulator, or to address a security risk: effective immediately, with notice as soon as we reasonably can.

Everything else: effective when posted, and recorded here.

Notices go to the administrator email addresses on your account. Keep them current — a notice sent to an address you have not updated is still effective.

06

Questions

Questions about a change, or a request for a copy of a superseded version that is not published here: legal@workmonitor.ai.

Questions about this document:legal@workmonitor.aiBack to the register