Skip to content
Work360

Privacy Policy

Work360 is workplace monitoring software, so we would rather be specific than reassuring. This page sets out exactly what the platform can collect, who decides, and what you can do about it.

Effective:
Effective date — to be completed
Last updated:
Date — to be completed

This document is a draft. 5 required details (such as the legal entity, address and governing law) are still to be completed, and it has not been reviewed by a lawyer. Do not rely on it as a binding policy yet.

1.Who is responsible for your data

This policy covers two very different relationships, and which one applies to you changes your rights and who you exercise them against.

If you are…Our roleWhat that means
A visitor to work360.cloudControllerWe decide what we collect on this website and why. This policy governs it directly.
An employee monitored through Work360ProcessorYour employer is the controller. They decide what is monitored, how long it is kept and who can see it. We process that data on their documented instructions and nothing else. Exercise your rights with your employer first — we will support them in answering you, but we cannot decide on their behalf.
An administrator or billing contactControllerFor account, billing and support data we decide the purposes, so this policy applies directly.

The controller for website and account data is Legal entity — to be completed, Registered address — to be completed.

2.What the platform processes

Work360 is workplace monitoring software, so it is worth being blunt about what it can capture. Not all of this is on by default, and much of it is controlled by your employer rather than by us.

DataCollected whenNotes
Activity samples — active vs idle time, input intensityWhenever the agent is runningThe basis for productivity and timesheet figures.
Application and website usageWhenever the agent is runningApplication name, window title category and duration.
ScreenshotsOn an interval your employer setsCan be blurred or disabled per plan and per person. Employees can see their own captures.
Screen recording and live viewOnly when enabledOff unless your employer turns it on, and recording is enabled per person.
Microphone audioOnly when enabledOff by default; must be switched on at organisation level.
Location and geofencingConsent-basedRequires the employee’s explicit device consent. Withdrawing consent stops collection.
Data-loss prevention eventsOnly when enabledUSB use, printing, file changes, blocked-site attempts and cloud-sync uploads.
Device security postureHourly while the agent runsDisk encryption, antivirus, firewall, auto-lock, patch age. No file contents.
HR recordsEntered by your employerProfile, employment, leave, payroll and documents, depending on the modules in use.
Account and billing dataWhen you sign up or payName, work email, organisation, plan. Card details go to Stripe, never to us.

Every monitored employee can see this same list, as it applies to them specifically and with their employer’s actual settings, on the My privacy page inside the product. That page reads the live configuration rather than a static description.

3.Why we process it

As a processor, we process employee monitoring data solely to provide the service to the employer under our contract with them. We do not use it for our own purposes.

As a controller, for website, account, billing and support data, we rely on:

  • Contract — to provide the service, bill for it and support it.
  • Legitimate interests — to keep the service secure, prevent abuse and improve it, weighed against your interests.
  • Consent — for optional cookies and marketing email, which you can withdraw at any time.
  • Legal obligation — to keep tax, accounting and statutory records.

We do not sell personal data. We do not share it with advertisers, and we do not use customer content to train machine-learning models.

4.How long data is kept

For monitoring data, your employer sets the retention windows — separately for screenshots, recordings, activity and location — and a scheduled purge enforces them.

These windows default to keep indefinitely. If your employer has not configured them, nothing is automatically deleted. The My privacy page shows the windows actually in force for your organisation, including when the answer is “no automatic deletion”.

Account and billing records are kept for the life of the account and then for as long as tax and accounting law requires. Backups age out on their own cycle, so deletion from live systems can precede deletion from backups by a short period.

5.Who else processes it

We use a small number of sub-processors. Several are optional — they only come into play for an organisation that has switched that feature on, often using its own credentials.

Sub-processorAlways on?Purpose
Object storage (S3-compatible)AlwaysStores screenshots, screen recordings and uploaded files. Customers on Bring-Your-Own-Storage keep this in their own bucket, which we never copy out of.
Email delivery (SMTP)AlwaysSends invitations, alerts, reports and password resets using the SMTP server the organisation configures.
StripeOptionalProcesses subscription payments. Card details go directly to Stripe — they never reach our servers.
Anthropic (Claude)OptionalGenerates report summaries and answers data questions. Off unless an administrator enables AI features and supplies an API key; only the aggregated figures needed for the answer are sent.
Web push servicesOptionalDelivers browser and mobile push notifications through the browser vendor’s push service.
Jitsi (meet.work360.cloud)OptionalHosts in-app video meetings. Runs on infrastructure we operate.

We may also disclose data where we are legally compelled to, or to establish or defend legal claims. Where the law allows, we will tell the affected customer first.

6.Where data is stored

Customer data is hosted in Hosting region — to be completed. Customers on Bring-Your-Own-Storage keep screenshots, recordings and uploads in their own object-storage bucket, in a region they choose, and we do not copy that content elsewhere.

Where a transfer leaves the region, we rely on the appropriate safeguards for that route, such as standard contractual clauses.

7.How we protect it

  • Encryption in transit (TLS) and at rest.
  • Credentials and integration secrets encrypted at the application layer, not merely at the disk.
  • Role-based access, tenant isolation and scoped visibility so managers see only their own people.
  • Optional two-factor authentication and SAML single sign-on.
  • An audit log of administrative actions, retained for the organisation to inspect.
  • Continuous internal compliance checks against SOC 2, ISO 27001, GDPR, HIPAA and DPDP control sets.

No system is perfectly secure. If you believe you have found a vulnerability, please report it to Security email — to be completed rather than disclosing it publicly, and we will work with you on a fix.

8.Your rights

Depending on where you live, you may have the right to access your data, correct it, delete it, restrict or object to processing, port it elsewhere, and withdraw consent.

If you are a monitored employee, start with your employer. They are the controller and they hold the decision. Work360 gives them a built-in workflow for handling access, correction and erasure requests with a logged trail, so the request will be tracked rather than lost in an inbox.

For data where we are the controller, contact Privacy email — to be completed. We will respond within the period the applicable law allows.

India — DPDP Act. Our Grievance Officer is Grievance Officer — to be completed, reachable at Grievance email — to be completed. If you are not satisfied with our response you may complain to the Data Protection Board of India.

EEA and UK — GDPR. You may complain to your local supervisory authority.

9.Cookies

This website uses only the cookies needed to make it work — chiefly keeping you signed in and remembering interface preferences. We do not use advertising or cross-site tracking cookies.

The application stores a session token and small interface preferences in your browser. Clearing site data signs you out and resets those preferences.

10.Children

Work360 is workplace software, sold to organisations for use by their workforce. It is not directed at children and we do not knowingly collect data from anyone under 18. If you believe a child’s data has reached us, contact Privacy email — to be completed and we will delete it.

11.Changes to this policy

We will update this page when our practices change, and revise the “last updated” date above. For changes that materially affect your rights we will give customers advance notice by email rather than relying on you to re-read the page.

See also our Terms of Service.

Questions about this document?

Read the Terms of Service