WorkInsights

Privacy Policy

The WorkInsights Privacy Policy explains how the platform collects, uses, stores, protects, and processes customer and workforce data. It covers data provided by users, client-controlled workforce data, automatically collected data, security controls, AI-assisted analysis, retention, international transfers, cookies, and the rights available to users depending on jurisdiction.

WorkInsights states that customer workforce data is controlled by the employer, while the platform acts as a processor. The policy also explains that WorkInsights does not sell personal data and provides support contact details for privacy requests.

Who controls the data

Where a customer uses WorkInsights to process data about its own employees, the customer is the controller of that data and WorkInsights acts as its processor, working on the customer's instructions. For the customer's own account, billing, support and website data, WorkInsights is the controller. An employee whose activity is recorded should contact their employer first, because the employer decides what is collected and why.

What is collected

Account details provided by the customer, workforce data recorded on the customer's instructions including device and user activity, time tracking and productivity metrics, and optional location data and screenshots where a customer enables them, plus automatically collected technical data such as IP address, device type and usage logs. When the desktop agent registers it also sends the computer name, operating system, timezone, MAC address and local network IP.

AI processing

AI summaries involve sending workforce data, including employee names, application names, window titles and website addresses, to a third-party large language model provider named in the policy. The data sent is not used to train or improve that provider's models, and screenshot images are never sent to it. AI outputs are assistive and must not be the sole basis for an employment decision.

Service providers

Categories of recipient include cloud hosting and database providers, a payment processor, email providers, an AI provider, identity and directory providers, mapping and geocoding services, security and anti-abuse services, and legal authorities where disclosure is required by law. WorkInsights imposes data protection obligations on each provider processing personal data on its behalf and remains responsible for how they perform them. A current list naming each provider and the countries in which it processes data is available on request.

Security, retention and incidents

Controls include encryption in transit and at rest through cloud infrastructure providers, access scoped by role and department, an audit log of administrative changes, optional two-factor authentication, and rate limiting. WorkInsights holds no security certification at this time; SOC 2 Type II and ISO 27001 are planned. Customers set their own retention period within plan limits, up to six months on Standard and twelve on Pro. Security incidents affecting customer data are notified to the customer without undue delay and within forty-eight hours of becoming aware.

Transfers and rights

The platform is operated from Singapore and hosted in Singapore by default, with other regions available for enterprise deployments. Where a transfer requires a specific safeguard, an appropriate mechanism is used, including the European Commission's standard contractual clauses where they apply. Individuals may have rights to access, correct, delete, object to processing, or request portability, depending on their jurisdiction.

Read the terms of service or contact the team.