1.Who is responsible for your data
This policy covers two very different relationships, and which one applies to you changes your rights and who you exercise them against.
| If you are… | Our role | What that means |
|---|---|---|
| A visitor to work360.cloud | Controller | We decide what we collect on this website and why. This policy governs it directly. |
| An employee monitored through Work360 | Processor | Your employer is the controller. They decide what is monitored, how long it is kept and who can see it. We process that data on their documented instructions and nothing else. Exercise your rights with your employer first — we will support them in answering you, but we cannot decide on their behalf. |
| An administrator or billing contact | Controller | For account, billing and support data we decide the purposes, so this policy applies directly. |
The controller for website and account data is Legal entity — to be completed, Registered address — to be completed.
2.What the platform processes
Work360 is workplace monitoring software, so it is worth being blunt about what it can capture. Not all of this is on by default, and much of it is controlled by your employer rather than by us.
| Data | Collected when | Notes |
|---|---|---|
| Activity samples — active vs idle time, input intensity | Whenever the agent is running | The basis for productivity and timesheet figures. |
| Application and website usage | Whenever the agent is running | Application name, window title category and duration. |
| Screenshots | On an interval your employer sets | Can be blurred or disabled per plan and per person. Employees can see their own captures. |
| Screen recording and live view | Only when enabled | Off unless your employer turns it on, and recording is enabled per person. |
| Microphone audio | Only when enabled | Off by default; must be switched on at organisation level. |
| Location and geofencing | Consent-based | Requires the employee’s explicit device consent. Withdrawing consent stops collection. |
| Data-loss prevention events | Only when enabled | USB use, printing, file changes, blocked-site attempts and cloud-sync uploads. |
| Device security posture | Hourly while the agent runs | Disk encryption, antivirus, firewall, auto-lock, patch age. No file contents. |
| HR records | Entered by your employer | Profile, employment, leave, payroll and documents, depending on the modules in use. |
| Account and billing data | When you sign up or pay | Name, work email, organisation, plan. Card details go to Stripe, never to us. |
Every monitored employee can see this same list, as it applies to them specifically and with their employer’s actual settings, on the My privacy page inside the product. That page reads the live configuration rather than a static description.
3.Why we process it
As a processor, we process employee monitoring data solely to provide the service to the employer under our contract with them. We do not use it for our own purposes.
As a controller, for website, account, billing and support data, we rely on:
- Contract — to provide the service, bill for it and support it.
- Legitimate interests — to keep the service secure, prevent abuse and improve it, weighed against your interests.
- Consent — for optional cookies and marketing email, which you can withdraw at any time.
- Legal obligation — to keep tax, accounting and statutory records.
We do not sell personal data. We do not share it with advertisers, and we do not use customer content to train machine-learning models.
4.How long data is kept
For monitoring data, your employer sets the retention windows — separately for screenshots, recordings, activity and location — and a scheduled purge enforces them.
These windows default to keep indefinitely. If your employer has not configured them, nothing is automatically deleted. The My privacy page shows the windows actually in force for your organisation, including when the answer is “no automatic deletion”.
Account and billing records are kept for the life of the account and then for as long as tax and accounting law requires. Backups age out on their own cycle, so deletion from live systems can precede deletion from backups by a short period.
6.Where data is stored
Customer data is hosted in Hosting region — to be completed. Customers on Bring-Your-Own-Storage keep screenshots, recordings and uploads in their own object-storage bucket, in a region they choose, and we do not copy that content elsewhere.
Where a transfer leaves the region, we rely on the appropriate safeguards for that route, such as standard contractual clauses.
7.How we protect it
- Encryption in transit (TLS) and at rest.
- Credentials and integration secrets encrypted at the application layer, not merely at the disk.
- Role-based access, tenant isolation and scoped visibility so managers see only their own people.
- Optional two-factor authentication and SAML single sign-on.
- An audit log of administrative actions, retained for the organisation to inspect.
- Continuous internal compliance checks against SOC 2, ISO 27001, GDPR, HIPAA and DPDP control sets.
No system is perfectly secure. If you believe you have found a vulnerability, please report it to Security email — to be completed rather than disclosing it publicly, and we will work with you on a fix.
8.Your rights
Depending on where you live, you may have the right to access your data, correct it, delete it, restrict or object to processing, port it elsewhere, and withdraw consent.
If you are a monitored employee, start with your employer. They are the controller and they hold the decision. Work360 gives them a built-in workflow for handling access, correction and erasure requests with a logged trail, so the request will be tracked rather than lost in an inbox.
For data where we are the controller, contact Privacy email — to be completed. We will respond within the period the applicable law allows.
India — DPDP Act. Our Grievance Officer is Grievance Officer — to be completed, reachable at Grievance email — to be completed. If you are not satisfied with our response you may complain to the Data Protection Board of India.
EEA and UK — GDPR. You may complain to your local supervisory authority.
10.Children
Work360 is workplace software, sold to organisations for use by their workforce. It is not directed at children and we do not knowingly collect data from anyone under 18. If you believe a child’s data has reached us, contact Privacy email — to be completed and we will delete it.
11.Changes to this policy
We will update this page when our practices change, and revise the “last updated” date above. For changes that materially affect your rights we will give customers advance notice by email rather than relying on you to re-read the page.
See also our Terms of Service.
Questions about this document?
Read the Terms of Service →