WorkMonitor.

Legal and compliance

Every document, published in full

The DPA and its annexes, the sub-processor list, the platform terms and everything incorporated into them. Each at its own address, each dated, each clause numbered. Read them today and forward them to whoever signs off; nothing here waits on a sales call.

Privacy & data protectionEffective September 8, 2026Version 3.1

US State Privacy Rights Notice

This notice supplements our Global Privacy Policy for residents of US states with comprehensive privacy laws, including California, Virginia, Colorado, Connecticut, Utah, Texas, Oregon, Montana, Delaware, Iowa, Nebraska, New Hampshire, New Jersey, Minnesota, Maryland, Rhode Island, Tennessee, Indiana and Kentucky, as those laws come into force.

It also serves as our notice at collection under the California Consumer Privacy Act as amended by the California Privacy Rights Act ("CCPA").

Read this together with the Global Privacy Policy, which describes our practices in full. Where this notice and that policy differ for a resident of a covered state, this notice applies to that resident.

A note on roles, because it determines who answers your request. When your employer deploys WorkMonitor, that employer is the business (or controller) and we are its service provider (or processor). Requests about monitoring data go to your employer; the section headed "If you are a monitored worker" explains what we will do if you write to us instead.

01

Categories of personal information we collect

The table uses the statutory categories from the CCPA. It covers the twelve months preceding the effective date of this notice and describes what we collect on an ongoing basis.

CCPA categories, sources, purposes and disclosures
CategoryExamples we collectSourceDisclosed to
A. IdentifiersName, work email, account identifier, IP address, device identifier, single sign-on identifier; and, for a website visitor who accepts advertising cookies, an advertising click identifier and a hash of an email address — either one that visitor typed into one of our own forms, or, when the account they created later pays its first invoice, the address of the person who created itYou, your employer, your identity provider, your deviceSub-processors; destinations your employer configures; and, for that website-visitor subset only, Google as our advertising measurement provider — this is the disclosure that constitutes sharing, and both the browser report and the server report that make it up are described in full below
B. Customer records informationName, employer, job title, billing address, telephone number, payment card type and last four digitsYou, your employerPayment processor; accounting advisers
C. Protected classification characteristicsWe do not intentionally collect these. Our Acceptable Use Policy prohibits customers from configuring the Services to infer or record themNot collected intentionallyNot disclosed
D. Commercial informationPlan, seat count, subscription and invoice history, products consideredYou, our billing systemsPayment processor; accounting advisers; and, where an account was created from a visit that arrived on one of our advertisements and consented to advertising, the amount and currency of that account's first paid invoice, reported once to Google as the value of the conversion — described in full below
E. Biometric informationNone. The Services do not collect biometric identifiers of any kindNot collectedNot disclosed
F. Internet or other network activityApplications and websites in use, active window and page titles, active and idle time, aggregate keystroke and mouse intensity, pages viewed on our website, and the conversion completed on our websiteThe agent on the device, your browserSub-processors; destinations your employer configures; and, for pages viewed and conversions completed on our own website or in the signed-in application by a browser whose user accepted advertising cookies, Google. Nothing collected by the agent on a device — no application, window title, activity figure or screenshot — is ever disclosed for advertising
G. Geolocation dataApproximate location derived from IP address; and, where your employer uses geofenced job sites, the GPS coordinates recorded with a clock-in or clock-out event and whether they fall inside a boundary your employer defined. Recorded at the moment of the event, not as a continuous trailYour device, your employer's configurationSub-processors
H. Audio, electronic, visual or similar informationScreenshots, where your employer enables them; live view frames during an open session. No audio is ever captured, and no continuous video or screen recording is madeThe agent on the deviceHosting and storage sub-processors
I. Professional or employment informationJob title, team, manager, working hours, timesheets, attendance, approvals, projects, deliverables, performance scoresYou, your employer, connected HR systemsSub-processors; destinations your employer configures
J. Education informationOnly where included in a job application you send usYouNot otherwise disclosed
K. InferencesProductivity, focus and engagement scores, activity summaries and AI-generated narratives derived from the aboveGenerated by the ServicesYour employer; AI sub-processors, which are contractually prohibited from training on the data
02

Sensitive personal information

We do not collect or process sensitive personal information for the purpose of inferring characteristics about a consumer.

We collect account credentials, which are sensitive personal information under the CCPA, solely to authenticate users and secure accounts. We do not use or disclose them for any other purpose, and we therefore do not offer a right to limit their use — there is nothing to limit beyond providing the Services and keeping them secure.

Precise geolocation is sensitive personal information under the CCPA, and we handle it in one narrow case: where an employer uses geofenced job sites, GPS coordinates are recorded with a clock-in or clock-out event so that the event can be matched against a boundary the employer defined. We say so plainly rather than claiming we collect no precise location. It is recorded at the moment of the event, not continuously, we process it only as the employer's service provider and only to provide the Services, and we never use it to infer characteristics about anyone.

Because that processing is carried out on your employer's instructions, the right to limit the use of sensitive personal information runs against your employer, which decides whether job sites are used at all. Ask your employer to turn the feature off or to remove you from its scope; we will act on its instruction.

03

Why we collect it

We use each category for the business purposes described in the Global Privacy Policy: to provide and secure the Services, to bill for them, to support customers, to detect and prevent fraud and abuse, to improve the product, to comply with law, and to establish or defend legal claims.

We retain each category for the periods set out in the retention table in the Global Privacy Policy. Where a period cannot be stated exactly, we retain the data only for as long as is reasonably necessary for the purpose it was collected for.

We will not collect additional categories of personal information, or use what we have collected for a materially different purpose, without first giving you notice. This edition is that notice for one new purpose: measuring our own advertising, described in the three sections that follow. It reaches a visitor to our website who accepts it, and the record of a purchase made by an account created from such a visit — and nobody else.

04

We do not sell personal information, and we share one narrow category for advertising

We do not sell personal information, we have never sold it, and we have not sold it in the preceding twelve months. No consideration of any kind is received for personal information, and there is no arrangement under which any could be.

Sharing is a different question and the honest answer is yes, in one place. We advertise WorkMonitor on Google. Where a visitor to our public website accepts advertising cookies, that visitor's browser is given an advertising identifier, and each page they open is reported to our advertising account as one of thirteen coarse buckets describing the kind of page it was — pricing, comparison, legal and ten others. We build remarketing audiences from those buckets, and Google may use what it receives to select our advertisements for that visitor across other sites. That is sharing for cross-context behavioural advertising as the CCPA defines it, and we call it that rather than calling it analytics.

The same permission covers conversion measurement, which is the reason we ask for it: telling Google that a sign-up, a demo request, a download or a first payment followed an advertisement click, so that we can stop paying for the advertisements that bring nobody. We say what that permission covers rather than describing a stream of conversions as though every one of them were already flowing. A conversion is reported only for a conversion action that has been created in our advertising account, and those are created one at a time, so on any given day some are reporting and others are not yet. Nothing else changes when one is switched on — the same permission, the same identifiers, the same limits described in the next section.

The lookback, stated as a lookback: we did not share personal information for cross-context behavioural advertising in the twelve months preceding this edition. The sharing described above begins with this edition and no earlier.

What is not shared, and will not be. Nothing an employer's deployment produces is shared for advertising: no application or window title, no activity figure, no screenshot, no timesheet, no score, no inference, and no identity of a monitored worker. The advertising processing described here concerns visitors to our own website and the commercial relationship an account holder has with us, and our Platform Terms of Service commit us to that boundary in the section on Customer Data.

We do not knowingly sell or share the personal information of consumers under 16 years of age. The Services are not directed to children.

We disclose personal information to sub-processors for business purposes only, under written contracts that limit them to processing it on our instructions and prohibit them from selling it or using it for their own purposes.

05

What a conversion report contains, in your browser and from our servers

Two different reports can carry a conversion to Google, and they are not the same thing, so both are set out here rather than one standing in for the other.

The first is sent by your browser. Where you have accepted advertising cookies and you then complete something we count on our own website — a demo request, a sign-up, a download — the tag reports the conversion, the click identifier of the advertisement you arrived through, and, where you typed an email address into that same form at that moment, a SHA-256 hash of that address. The hashing happens in your browser before anything is sent, so the address itself never leaves it, and it is only ever the address you just typed: never one we hold for somebody else, never one read out of a link, and never the address of a person monitored through the platform.

The second is sent by our own servers, and it exists because a purchase usually happens days or weeks after the advertisement was clicked, often in a different browser, where a cookie can no longer connect the two. Where an organization was created from a visit that carried an advertisement click identifier and that recorded an advertising consent, and that organization later pays its first invoice, we report that payment once to our advertising account, through a conversion action created in that account like any other and subject to the same qualification stated in the previous section. That report carries the click identifier, an internal reference we use to make sure the same payment is never reported twice, the amount and currency of the invoice, and a SHA-256 hash of the email address of the person who created the account. The address is hashed by us before it is sent and is never sent in the clear, and no report of this kind is sent for an organization whose visit recorded no advertising consent.

What that second report is, stated plainly because the distinction is the whole of it: a record of an account holder's own commercial relationship with us — they clicked our advertisement, they bought our product, and we are telling the advertising account that paid for the click. It is not monitoring data and it never contains any. No application or window title, no activity figure, no screenshot, no timesheet, no score, no inference, and no identity or email address of any person monitored through the Services — hashed or otherwise — is in it or can be put in it. That limb is absolute, and our Platform Terms of Service make it an express term rather than a description.

Both reports depend on a recorded advertising consent and both stop when it is withdrawn. Withdrawing also deletes the click identifier we stored, and cancels any conversion that has been queued and not yet sent.

06

How to opt out of sharing for advertising

The right to opt out of sharing is real here now, so this section describes a control rather than explaining why one is unnecessary.

Advertising is off unless you turn it on. It is refused by default, and a visitor who never answers our cookie banner is treated as one who refused, so for most readers there is nothing to opt out of because nothing was ever opted in.

If you did accept and want to stop: use the "Do Not Sell or Share My Personal Information" link in the footer of every page on our website. One click is the whole of it. It records a refusal of advertising, deletes the advertising cookies already set — ours and Google's — tells our servers to delete the advertisement click identifier stored against your account if we hold one, and stops any further conversion measurement. It does not open a banner, does not ask you to confirm, and does not disturb your analytics decision, because analytics is a different permission and refusing one is not refusing the other.

The cookie banner is a different control and we would rather say so than let you go looking for something it does not offer. It asks analytics and advertising as one question, with one Accept and one Decline, each covering both. So Decline there refuses analytics as well, and there is no button on it that accepts advertising while leaving analytics off. The Cookie Settings link in our footer reopens that same question. The advertising-only paths are the footer control described above and the browser signal described next.

We honour the Global Privacy Control signal as an opt-out of sharing. A browser that sends it is never asked about advertising: the refusal is recorded for that browser without a click, it overrides an advertising acceptance already recorded in that browser, and the banner tells you the signal was honoured rather than acting on it silently. Because the signal is browser-specific, it does not carry to your other devices, and neither does a refusal recorded in a private window you have since closed.

An authorized agent may exercise this right for you, and you may also write to privacy@workmonitor.ai with the subject line "US privacy request". We do not require an account to honour an opt-out of sharing, and we do not ask for more information than is needed to act on it.

07

Your rights

Depending on your state of residence, you may have the rights below. Where a state gives a right we have not listed, we will honour it.

  • Know and access — to know what personal information we have collected about you, the categories, the sources, the purposes, the categories of third parties it was disclosed to, and to receive a copy of the specific pieces.
  • Delete — to ask us to delete personal information we collected from you, subject to the exceptions the statute allows.
  • Correct — to ask us to correct inaccurate personal information.
  • Opt out of sale, sharing and targeted advertising — we do not sell, and we share only as described above. The opt-out is the "Do Not Sell or Share My Personal Information" link in the footer of every page of our website, which on one click refuses advertising, deletes the advertising cookies already set and deletes the click identifier we stored. We honour the Global Privacy Control signal as the same opt-out. The section headed "How to opt out of sharing for advertising" explains both, and explains why the cookie banner is not a third one.
  • Limit the use of sensitive personal information — as explained above, we use it only to authenticate and secure, which the statute does not require us to limit.
  • Opt out of profiling in furtherance of decisions producing legal or similarly significant effects — we do not carry out such profiling as a controller. Where your employer does, the right is exercised against your employer.
  • Portability — to receive personal information you provided in a portable, readily usable format where technically feasible.
  • Appeal — where your state provides it, to appeal a decision we make about your request. We will respond to an appeal within the period your state's law allows and will tell you how to contact your Attorney General if we deny it.
  • Non-discrimination — we will not deny you goods or services, charge you a different price, or give you a different level of quality because you exercised a right. We offer no financial incentives for personal information.
08

How to make a request

Write to privacy@workmonitor.ai with the subject line "US privacy request", telling us which right you want to exercise and the state you live in. You may also write to Digital Socket LLC, 131 Continental Dr, Suite 305, Newark, DE 19713, United States.

We will verify your identity before acting, using information already associated with your account. For a request to know the specific pieces of personal information we hold, we apply a higher standard of verification, because the consequence of getting it wrong is disclosing your data to someone else.

We will confirm receipt within 10 business days and respond within 45 days. If we need more time, we will tell you within the first 45 days and take no more than a further 45 days.

You may use an authorized agent. We will ask for written permission signed by you, and we may still ask you to verify your own identity directly.

Requests are free unless they are manifestly unfounded or excessive, in which case we will tell you why before charging anything or declining.

09

If you are a monitored worker

California's privacy law covers employees, applicants and contractors, and several other states are moving in the same direction.

Your employer is the business with respect to your monitoring data. It decides what is collected and how long it is kept, and it is the party that must answer your request. We act as its service provider, and we are contractually and legally restricted from disclosing, correcting or deleting its data on the instruction of anyone else.

Send your request to your employer. If you send it to us, we will acknowledge it, tell you plainly what we can and cannot do, and forward it to your employer without undue delay unless doing so would be unlawful.

Nothing here prevents you from contacting your state Attorney General or the California Privacy Protection Agency directly.

10

Requests we received

We will publish annual metrics on the requests we receive, as California requires of businesses that meet the applicable threshold, once we have a full reporting year to report on. This document is dated September 8, 2026 and no full reporting year has yet closed, so no figures are stated here rather than figures being invented.

11

Other US notices

Shine the Light. California Civil Code section 1798.83 allows California residents to ask about disclosures of personal information to third parties for their direct marketing purposes. We make no such disclosures.

Do Not Track. There is no common standard for how a website should respond to a browser Do Not Track signal, and we do not respond to it. The Global Privacy Control signal is different and we do honour it: a browser that sends it has advertising refused for it without being asked, which is the opt-out of sharing that this notice describes.

Nevada. Nevada residents may direct a business not to sell certain covered information. We do not sell it. You may still send a request to privacy@workmonitor.ai.

12

Contact

Privacy requests and questions: privacy@workmonitor.ai. Our Data Protection Officer can be reached at dpo@workmonitor.ai.

By post: Digital Socket LLC, 131 Continental Dr, Suite 305, Newark, DE 19713, United States.

Questions about this document:legal@workmonitor.aiBack to the register