Terms of Service
WORKINSIGHTS.ONLINE PTE. LTD. · Effective 9 September 2026 · Governed by the laws of Singapore
1. This agreement
These Terms of Service (the "Terms") are a contract between WORKINSIGHTS.ONLINE PTE. LTD., a company incorporated in Singapore with its registered office at 160 Robinson Road #14-04, Singapore Business Federation Center, Singapore 068914 ("WorkInsights", "we", "us"), and the organisation that creates a WorkInsights account ("Customer", "you").
WorkInsights is sold to organisations for use in their business. It is not offered to consumers, and it is not intended for personal, family, or household use. By creating an account you confirm that you are acting for an organisation and that you have authority to bind it to these Terms.
These Terms apply together with our Privacy Policy and, where you process personal data through the Service, our Data Processing Addendum (the "DPA"). Where a signed order form or enterprise agreement exists, it prevails over these Terms; where the DPA addresses a data protection matter, the DPA prevails over these Terms.
2. What the Service is, and what it is not
WorkInsights is workforce analytics software. Depending on the settings your administrators choose, it records active and idle time, application and website activity, attendance, timesheets and leave, and optionally device location and periodic screenshots. It presents that information in a dashboard and can generate AI-assisted summaries of it.
The Service describes when and how work was recorded as happening on an enrolled device. It does not measure the quality, value, or diligence of a person's work, and it is not designed or validated as a system for determining performance.
- The Service is not a system of record for payroll, and outputs should be reconciled before being used to calculate pay.
- The Service does not determine whether misconduct has occurred, and its outputs are not represented as forensically sound or admissible evidence.
- The Service does not assess or infer emotion, mood, sentiment, or psychological state, and must not be used or configured in an attempt to do so.
- Using the Service does not by itself make your monitoring lawful, and nothing in the Service constitutes legal advice about your monitoring programme.
Employee monitoring is lawful in many places but is conditional almost everywhere. Deciding whether, whom, and how to monitor is your decision and your legal responsibility, not ours. Section 5 sets out what you are agreeing to when you enable the Service.
3. Accounts, activation and plans
3.1 Creating an account
Creating an account is free. You may explore the dashboard using demonstration data without providing a payment method and without installing anything on any device.
You are responsible for the accuracy of your account information, for the security of your credentials, and for all activity carried out under your account. You must notify us promptly at [email protected] if you believe an account has been compromised.
3.2 Activation
For new activations under this offer, you subscribe to Pro when you approve the US$1.00 activation payment, before downloading or installing an agent. This payment starts your first 30-day billing period and covers the first active device. It is not a refundable card verification.
At the end of those 30 days, we charge US$1.00 for each active device beyond the first. If there are zero or one active devices, no additional first-period payment is due; the activation payment is not refunded. Pro then continues automatically at US$6.00 per active device per month, billed at the end of each monthly cycle, unless you cancel or change your plan. You do not need to select a plan to continue. Existing subscriptions and separately agreed prices are unchanged.
During those first 30 days the Pro plan cannot be switched to another plan, because the introductory period is purchased as a whole. You may cancel at any time under clause 4.3: cancellation takes effect at the end of the 30 days, you keep access until then, and any additional active devices in that period are still charged. Plan changes become available once the introductory period ends.
3.3 Plans
Self-serve plans are Standard and Pro. Standard is US$4.00 per active device per month and Pro is US$6.00 per active device per month. Feature availability differs between plans and is described on our pricing page as updated from time to time.
Enterprise deployments are provided under a separate written agreement and may include dedicated infrastructure, a selected hosting region, custom retention, and agreed support commitments. Where such an agreement exists, it governs.
4. Billing, renewal and cancellation
4.1 How devices are counted
In both the introductory and subsequent periods, fees are calculated from the number of active devices at the end of the billing cycle, not the highest count during the month. A device is active if it is enrolled in your workspace and monitoring is switched on for it. Demonstration devices are excluded.
This is based on the monitoring setting, not on whether the device actually reported data. A device that is enrolled with monitoring switched on is counted even if it sent no activity during the period. To stop being charged for a device, switch monitoring off for it or remove it from your workspace before the next cycle begins.
4.2 Payment and renewal
Fees are stated and charged in US dollars, are exclusive of any taxes, levies, or duties, and you are responsible for any such amounts other than taxes on our income. Payments are processed by Stripe; your use of that payment flow is also subject to Stripe's terms.
Subscriptions renew automatically each month until cancelled, and your payment method will be charged automatically at each renewal. We will send an invoice or receipt to the billing contact on your account for each charge.
At least seven days before introductory pricing ends, we will send your administrators a reminder stating the renewal date, the normal per-device rate, how the final amount is calculated, and how to cancel. The final amount depends on the active-device count at the end of the applicable cycle.
For as long as your subscription continues, we will send a renewal reminder at least once in every twelve month period, stating the plan, the current rate, and how to cancel.
If a payment fails, we may retry it and will notify your administrators. Access to the Service may be restricted while an account is unpaid.
4.3 Cancelling
You may cancel at any time from within the Service, using an online cancellation route that is at least as simple as the one by which you subscribed. We will not require you to telephone us, email us, or pass through a retention process in order to cancel, and we will confirm your cancellation in writing within seven days.
There is no minimum term and no cancellation fee. Cancellation takes effect at the end of the current billing period, and you retain access until then. Cancellation stops subsequent renewals but does not waive the balance for active devices in the current period, including additional devices in the introductory period.
Fees already paid are not refunded on cancellation, and plan changes are not prorated, except where a refund is required by law. Clause 10 governs what happens to your data after termination.
5. Your responsibilities for lawful monitoring
This clause is the most important one in these Terms. The Service places you in a regulated position, and the obligations it engages fall on you as the employer, not on us as the software supplier.
You represent, warrant, and undertake, for as long as you use the Service, that each of the following is and remains true.
5.1 Lawful basis
- You are the controller, or the equivalent responsible organisation, for all data the Service records about the individuals you monitor.
- You have identified and documented a valid legal basis for the monitoring in every jurisdiction where a monitored individual is located, and you have satisfied yourself that the monitoring you have configured is necessary and proportionate to that basis.
- Where the applicable law is such that employee consent would not be freely given, you do not rely on employee consent as your legal basis.
- Where required, you have completed a data protection impact assessment or equivalent risk assessment before enabling the Service, and you will complete a further assessment before enabling screenshots, location tracking, or AI summaries.
- You have consulted, informed, or obtained approval from works councils, trade unions, or employee representatives where local law requires it.
5.2 Notice to the people you monitor
Notice obligations are yours. Several jurisdictions require notice, posting, or written acknowledgement before electronic monitoring begins, and requirements differ between them.
- You have told every monitored individual, in advance and in plain language, what is collected, for what purpose, who can access it, how long it is kept, and what decisions it will and will not inform.
- You have given any notice, posted any notice, and obtained any written or electronic acknowledgement that applicable law requires, and you have kept records capable of demonstrating this.
- You maintain a monitoring or acceptable-use policy that monitored individuals can readily access.
- You will give fresh notice before enabling a materially more intrusive capability, including screenshots or location tracking.
- Where applicable law requires notice to be repeated periodically, given at interview, or re-issued to existing staff, you meet that requirement on an ongoing basis and not only at the point of hiring.
5.3 Devices and scope
- You own or otherwise lawfully control every device on which you deploy a monitoring agent, and you are authorised to install monitoring software on it.
- You only monitor your own workers, and you have taken reasonable steps to ensure the Service does not capture data about people who are not your workers.
- Where an individual has a right under applicable law to decline installation of monitoring software on their own personal device, you honour that refusal and do not treat it as misconduct.
- Where applicable law restricts audiovisual or screen capture in an individual's home or personal space, you have satisfied yourself that any such capture is genuinely required for the role before enabling it.
- You do not monitor individuals under 18 years of age without additional safeguards appropriate to their age.
- You do not configure the Service to capture special category or sensitive personal data, and you do not direct it at applications or screens where such data is predictably present.
5.4 Per-feature confirmation
Where the Service asks an administrator to confirm, before enabling a capability, that the requirements of this clause 5 have been met for that capability, that confirmation is given on your behalf and we are entitled to rely on it. We record when it was given and by whom.
You will indemnify us against any claim, penalty, or loss arising from a breach of this clause 5, including claims brought by the individuals you monitor and proceedings brought by a regulator.
6. Acceptable use
You must not use the Service, or permit it to be used, in any of the following ways.
- Covert monitoring: deploying or operating an agent without giving the monitored individual the notice required by law, or taking steps to conceal that monitoring is running.
- Disabling or circumventing any indicator, notice, or control that the Service provides to make monitoring visible to the person being monitored.
- Installing an agent on a device you do not own or lawfully control, or on an individual's personal device without their informed authorisation and a lawful basis.
- Attempting to infer emotion, sentiment, mood, or psychological state from any data in the Service. This is prohibited outright and is not a supported use.
- Using an output of the Service as the sole basis for dismissal, discipline, demotion, pay, or promotion without meaningful review by a person who has the authority and the information to reach a different conclusion.
- Using the Service to discriminate unlawfully, to retaliate against protected activity, or to interfere with rights to organise.
- Deliberately capturing the content of private communications, including personal webmail, banking, medical, or legal services.
- Monitoring individuals outside their working hours, or tracking their location while off duty, unless a specific and documented legal basis supports it.
- Reselling, sublicensing, or providing the Service to a third party, or using it to build a competing product.
- Reverse engineering, decompiling, probing, or load-testing the Service without our written permission, or interfering with its security or integrity.
7. Data protection roles
For the data the Service records about the individuals you monitor, you are the controller and we are the processor. Under the Singapore Personal Data Protection Act 2012 we act as your data intermediary, and these Terms together with the DPA are the written contract that relationship requires.
For your own account, billing, support, and website data, we act as the controller, and our Privacy Policy explains that processing.
We process monitored individual data only on your documented instructions, which comprise these Terms, the DPA, your written instructions, and the settings your administrators configure in the Service. We will tell you if, in our opinion, an instruction you give would breach applicable data protection law.
We do not use monitored individual data for our own purposes. We do not sell it, and we do not use it to train or improve generalised machine learning models.
7.1 Assisting you
Taking account of the nature of the processing and the information available to us, we will provide reasonable assistance with your obligations in respect of security, impact assessments, and prior consultation, and with requests from individuals to access, correct, or erase their data. Requests from your workers should be directed to you as the controller; if one reaches us we will refer it to you rather than answer it, unless you instruct us otherwise or we are independently required to respond.
7.2 Confidentiality of personnel
Our personnel who are authorised to process customer data are bound by written confidentiality obligations, and access is limited to those who need it to operate or support the Service.
7.3 Audit
We will make available the information reasonably necessary to demonstrate our compliance with our processor obligations, and will contribute to audits conducted by you or an auditor you appoint. We will respond first with our security documentation. Where that is not sufficient for your purpose, an on-site or remote inspection may be carried out no more than once in any twelve month period, on at least thirty days' notice, during business hours, subject to confidentiality, at your cost, and without unreasonable disruption. Where an inspection follows a security incident affecting your data, the notice period and frequency limit do not apply and we bear our own costs.
8. Subprocessors and international transfers
You give us general authorisation to engage subprocessors. We maintain a current list of subprocessors, including what each one does and the countries in which it processes data, and we will make that list available to you on request and publish material changes to it.
We will give you at least thirty days' notice before adding or replacing a subprocessor that processes monitored individual data. You may object on reasonable data protection grounds within that period. If we cannot resolve your objection, you may terminate the affected part of the Service without penalty and receive a pro rata refund of fees paid for the unused period.
We impose data protection obligations on each subprocessor that are equivalent to those in the DPA, and we remain fully liable to you for a subprocessor's performance of those obligations.
The Service is hosted in Singapore by default. Enterprise deployments may be provisioned in another agreed region. Where a transfer of personal data requires a specific safeguard, we will put an appropriate mechanism in place, including the European Commission's standard contractual clauses where they apply, and will execute any replacement clauses the Commission adopts within a reasonable period of their adoption.
9. Security
We maintain technical and organisational measures designed to protect customer data against unauthorised access, disclosure, alteration, and loss, appropriate to the risk. These include encryption of data in transit and at rest through our infrastructure providers, access scoped by role and by department, restricted administrative access, and logging of administrative changes.
Our security measures will not be materially reduced during your subscription. Where we describe a certification, audit report, or security control to you, that description is accurate as at the date given; we do not represent that we hold a certification we have not obtained.
You are responsible for security within your own control: who you invite into your workspace, what role and department access you grant them, whether you enable multi-factor authentication, how you configure retention, and the security of the devices on which agents are installed.
10. Security incidents
If we become aware of a security incident affecting the personal data we process for you, we will notify you without undue delay and in any event within forty-eight hours of becoming aware of it.
Our notification will include the information reasonably available to us about the nature of the incident, the categories and approximate number of individuals and records affected, the likely consequences, and the measures taken or proposed. We will provide further information as it becomes available, and will co-operate with you in investigating and remediating the incident.
Determining whether an incident is notifiable to a regulator or to affected individuals is your decision as controller, and applicable deadlines are short. We will not notify a regulator or an affected individual on your behalf without your instruction, except where we are independently required to do so.
11. Data export and deletion
You may export your data from the Service in a machine-readable format at any time during your subscription.
For thirty days after termination or expiry, we will continue to make your data available for export. You may instruct us at any time during that period to return or delete it. This export window applies regardless of the reason for termination, including termination by us.
At the end of that period, and at your choice, we will delete or return the personal data we process for you and delete existing copies, other than copies we are required by law to retain. Data held in routine backups is deleted on our ordinary backup cycle. We will confirm deletion in writing on request.
If you are switching to another provider or to your own infrastructure, we will co-operate with that switch. You may end the agreement for that purpose on no more than two months' notice; we will maintain a transitional period of at least thirty days from the switching date during which the Service continues; and you will have at least thirty days after that period to retrieve your data. We will erase your data at the end of the retrieval period unless you ask us to keep it.
We do not charge a penalty for switching away from the Service, and any charges associated with a switch will be disclosed to you before you enter into the agreement.
During your subscription, retention periods for workforce data are configured by you within the limits of your plan, and we will delete data in accordance with those settings.
12. AI features
The Service uses a third-party large language model provider to generate summaries and insights. Producing those summaries involves sending workforce data, which may include names, application and window titles, website addresses, and working-time figures, to that provider. The provider is named in our subprocessor list, and content we send on our paid tier is not used by the provider to train its models.
AI outputs are probabilistic. They may be incomplete, out of date, or wrong. They are a summary of recorded data, not a finding of fact about any individual, and in particular an AI-generated flag, risk indicator, or score is not a determination that any person has done anything wrong.
You must not use an AI output as the sole basis for a decision that has a legal or similarly significant effect on a person, including a decision about employment, discipline, pay, or promotion. Where such a decision is informed by the Service, a person with the authority and the information to reach a different conclusion must review the underlying data and make the decision.
13. Availability and support
We will provide the Service with reasonable care and skill, and will use commercially reasonable efforts to keep it available. We do not guarantee uninterrupted or error-free operation.
We may carry out maintenance, and will give reasonable advance notice of planned maintenance likely to cause material disruption, except where an urgent fix is needed to protect the security or integrity of the Service.
Support is provided by email at [email protected] during Singapore business hours. Enterprise agreements may include agreed response times and service credits.
We are not responsible for unavailability caused by your network or devices, your configuration, a third-party service you direct us to integrate with, or an event outside our reasonable control.
14. Intellectual property
We own the Service, including the software, the agents, the dashboards, and all associated intellectual property. We grant you a non-exclusive, non-transferable right to use the Service during your subscription for your own internal business purposes, subject to these Terms.
You own your data. You grant us the limited right to host, process, and transmit it as necessary to provide the Service and to comply with your instructions.
We may use aggregated, anonymised statistics about how the Service is used to operate and improve it, provided those statistics cannot identify you, any individual, or any customer.
If you send us feedback or suggestions, we may use them without obligation to you.
15. Confidentiality
Each party may receive information from the other that is marked confidential or that a reasonable person would understand to be confidential. Each party will use the other's confidential information only to perform this agreement, will protect it with at least reasonable care, and will not disclose it except to personnel and advisers who need it and are bound by equivalent obligations.
These obligations do not apply to information that is public through no fault of the recipient, was already known to the recipient without a duty of confidence, or is independently developed. A party may disclose confidential information where legally compelled, and will give the other party notice where it is lawful to do so.
16. Warranties and disclaimers
We warrant that we will provide the Service with reasonable care and skill, and that we have the right to grant the rights we grant in these Terms.
Other than as stated in these Terms, and to the fullest extent permitted by law, we make no warranties, whether express or implied, about the Service.
In particular, and without limiting clause 2, we do not warrant that the Service will detect misconduct, prove or disprove productivity, accurately reflect the value of any person's work, be sufficient to satisfy any legal obligation of yours, or produce results admissible in any proceeding.
17. Indemnity
You will defend and indemnify us against third-party claims, and against regulatory fines and penalties, arising from your breach of clause 5 (lawful monitoring) or clause 6 (acceptable use), from your use of the Service in breach of law, or from the content of the data you choose to collect.
We will defend and indemnify you against third-party claims that the Service, used in accordance with these Terms, infringes that third party's intellectual property rights. If such a claim is made we may modify the Service, obtain a licence, or terminate the affected part and refund fees paid for the unused period.
In each case the indemnified party must notify the other promptly, allow the indemnifying party to control the defence, and give reasonable co-operation. No settlement that admits liability or imposes an obligation on the indemnified party may be made without its consent.
18. Limitation of liability
Nothing in these Terms limits or excludes either party's liability for death or personal injury caused by negligence, for fraud or fraudulent misrepresentation, or for any liability that cannot lawfully be limited or excluded.
Subject to that, neither party is liable for loss of profit, loss of revenue, loss of anticipated savings, loss of business opportunity, or for indirect or consequential loss, in each case however arising.
Subject to the first paragraph of this clause, each party's total aggregate liability arising out of or in connection with this agreement, whether in contract, tort including negligence, or otherwise, is limited to the total fees paid or payable by you for the Service in the twelve months immediately preceding the event giving rise to the liability.
The limit in the preceding paragraph does not apply to your obligations to pay fees, to your indemnity under clause 17, or to either party's breach of clause 15 (confidentiality).
Each party is responsible for taking reasonable steps to mitigate its loss. Neither party excludes any right you have to bring a claim within the ordinary limitation period, and nothing in these Terms shortens that period.
These limits are agreed in the context of the fees charged. If your organisation requires a higher limit of liability, contact us before purchase and we will discuss enterprise terms priced accordingly.
19. Suspension and termination
19.1 By you
You may terminate at any time by cancelling in the Service, effective at the end of the current billing period.
19.2 By us
We may suspend all or part of the Service immediately where you have not paid an amount that is due and it remains unpaid after we have asked you to pay it, where clause 6 has been breached, where continued operation presents a security or legal risk, or where we are required to do so by law. Where it is practicable and lawful, we will tell you first and give you an opportunity to put the matter right.
We may terminate for material breach that is not remedied within thirty days of written notice, or immediately on insolvency.
We may terminate for convenience on ninety days' written notice, in which case we will refund a pro rata share of any fees you have paid for a period after termination.
Suspension or termination does not affect your rights under clause 11 to export your data.
20. Changes to these Terms
We may change these Terms. We will give at least thirty days' notice of a material change by email to your administrators and by posting the updated Terms with a revised effective date.
If a material change is not acceptable to you, you may terminate before it takes effect and receive a pro rata refund of fees paid for the unused period. Continuing to use the Service after the change takes effect means you accept it.
Changes required by law or necessary for security may take effect on shorter notice, and we will explain why when we notify you.
21. Governing law and general
These Terms are governed by the laws of Singapore. The courts of Singapore have exclusive jurisdiction, save that either party may seek injunctive relief in any court of competent jurisdiction to protect its confidential information or intellectual property.
Neither party may assign this agreement without the other's consent, except to an affiliate or in connection with a merger or sale of substantially all its business, on notice.
If any provision is held unenforceable, it is modified to the minimum extent necessary to make it enforceable, or if that is not possible it is severed, and the rest of the agreement continues in force.
A failure to enforce a provision is not a waiver of it. There is no partnership, agency, or employment relationship between the parties. A person who is not a party has no right to enforce these Terms.
These Terms, the Privacy Policy, the DPA, and any order form together form the entire agreement between the parties about the Service and replace any earlier understanding, except that nothing excludes liability for fraudulent misrepresentation.
22. Contact
WORKINSIGHTS.ONLINE PTE. LTD., 160 Robinson Road #14-04, Singapore Business Federation Center, Singapore 068914.
Questions about these Terms, requests for the DPA or the subprocessor list, and data protection enquiries: [email protected].