Privacy notice
WorkPulse Privacy Notice
How WorkPulse handles account, security and billing information, and how it processes workforce data for its customers.
Last updated: 26 August 2026
1. Scope
This Privacy Notice applies to the WorkPulse website, account registration, subscription administration, applications and support interactions. It also explains the categories of Customer Content that the Service can process for a Customer.
If you are an employee, contractor or other user whose organisation uses WorkPulse, your organisation should give you its own workforce-monitoring notice. Send requests about your work records to that organisation first. WorkPulse will assist the Customer as required by the applicable Data Processing Addendum and law.
2. Information we collect
Account, customer and billing information
- name, business email address, telephone number, company name, postal address and country;
- account credentials, email-verification status, role and workspace membership;
- subscription, plan, user-allocation, storage-allocation, Stripe customer and payment-status information; and
- communications with us, support requests and information supplied in a data-rights request.
Security, device and connection information
- login and logout times, login outcome, IP address, browser or device user agent, session identifier, platform and security flags;
- approximate IP-derived location, country and timezone when security-location features are enabled;
- desktop device identifier, device name, platform, public-key fingerprint, application version and last-seen information; and
- browser-push subscription endpoint and keys, or mobile push token, platform and device information when notifications are enabled.
- if a user enables the dashboard weather feature and grants browser location permission, the browser's current location may be sent to OpenWeather to return local weather information.
Workforce and business information processed for Customers
The exact scope depends on the Customer's subscription, settings and client applications. It can include:
- user identity, job or team context, projects, tasks, work sessions, manual time requests, breaks, idle periods, time reports, wages, payroll-support records and approval notes;
- messages, forum content, files, attachments, profile images and documents uploaded to a Customer workspace;
- desktop activity metrics, individual mouse-click events and individual keyboard events with timestamps. Keyboard event data may contain actual characters or key names, not only a numeric count;
- foreground application, process and browser-window-title context, program-use records and browser-use context. Window titles may disclose page, document, search or other content;
- periodic whole-screen screenshots, including multiple monitors; optional manager-requested screen recordings; and, where a compatible feature is actually enabled, camera images;
- for mobile time tracking, precise latitude, longitude, location accuracy, reverse-geocoded address and timestamps; and
- reports, exports, scheduled report recipients and configured session-alert recipients or webhook endpoints.
3. Why we use information
We use information to create and administer a workspace, authenticate users, provide time tracking and customer-selected features, deliver messages and reports, manage subscriptions, respond to support and rights requests, protect the Service, investigate misuse, comply with law and improve the reliability of the Service.
Where WorkPulse is the controller, our legal bases may include performing a contract, complying with legal obligations, our legitimate interests in operating and securing the Service, and consent where required. Where WorkPulse processes Customer Content, the Customer is responsible for selecting the appropriate lawful basis and giving required notices.
4. Activity scoring and AI-generated reports
The Service calculates activity and idle-time metrics from the events submitted during a tracked session. An authorised Customer may also use the optional AI Time Report feature. The current feature can send a derived prompt to OpenAI containing report-date and activity metrics, leading applications or browser-window-title context, and typed-keyword signals generated from captured keyboard events. OpenAI returns a written report for the Customer's review.
WorkPulse is not designed to make an employment or other materially significant decision without human involvement. A Customer must use human review, test for errors and bias, and meet its own legal obligations before relying on activity scores or AI-generated reports.
5. Who receives information
We do not sell personal information. We may disclose information to the following recipients only as necessary for the purposes described above:
- the Customer and its authorised administrators, managers, team leaders, payroll staff and other users, according to the permissions that Customer configures;
- Stripe for subscription and payment processing. WorkPulse does not receive or store full payment-card numbers through the Service;
- hosting, database, file-storage, backup, security, email-delivery and support providers used in the deployed environment;
- Firebase Cloud Messaging, browser push providers or similar notification services when a user enables notifications;
- OpenAI when an authorised Customer uses an AI Time Report;
- OpenWeather when a user enables the dashboard weather feature and grants browser location permission; and
- recipients or endpoints selected by the Customer for scheduled reports, email notifications, webhooks, white-label integrations or data exports; and
- professional advisers, insurers, regulators, law enforcement or other parties where required or permitted by law.
Customer-selected report recipients, webhooks and export destinations are chosen and controlled by the Customer. The Customer is responsible for ensuring that those disclosures are authorised.
6. International processing
The Service supports deployment-configured local and cloud storage, including S3-compatible storage. The source code does not establish a single hosting country for every deployment. Information may be processed in countries where WorkPulse or its service providers operate. Where UK or EU data-protection law requires a transfer safeguard, we will use an appropriate approved mechanism, such as an adequacy decision or standard contractual clauses.
7. Retention and deletion
We retain information for as long as necessary to provide the Service, follow the Customer's instructions, meet legal obligations, resolve disputes and enforce agreements. Customers should set and apply their own retention rules for workforce data. The current source code does not establish a universal automatic deletion schedule for the information handled by current desktop and mobile clients:
| Information | Current product behaviour |
|---|---|
| Screenshots, thumbnails, camera images and screen recordings | No verified universal automatic deletion period. A pruning task targets some legacy file paths, but it does not establish a retention rule for current desktop capture, two-minute screenshot or recording paths. |
| Tenant backups | Backup retention is deployment-specific and is not a fixed public retention guarantee. A backup or recovery copy may remain after a live record is deleted until it is rotated or deleted under the applicable backup process. |
| Sessions, captures, location, messages, videos, reports and most other Customer Content | The source code does not provide a verified, general automatic deletion period for these categories. Deletion or anonymisation is handled case by case under the Customer's instructions, the agreement and applicable law; historic work or audit records may need to be retained. |
Technical and security records may be retained for a different period where needed to investigate suspicious activity, protect the Service or comply with law. Retention settings and scheduled jobs can change, so this table should be reviewed whenever the application is deployed or materially changed. Customers should not assume that an account or tenant deletion will automatically remove every historic work record, capture file or backup copy.
8. Your rights and how to make a request
Depending on applicable law, you may have rights to access, correct, erase, restrict, object to, or receive a portable copy of personal data, and to complain to a supervisory authority.
- Account, billing or website information: contact WorkPulse at support@workpulse.solutions.
- Employee or Customer workspace information: contact your employer or the Customer organisation first. It controls the purpose and scope of that information.
- Verified account-deletion request: use the data deletion request form. The form verifies your email address and alerts the responsible team; it does not automatically erase all Customer Content.
We may need to verify your identity and may retain limited information where an exception under applicable law applies. If you are dissatisfied with our response, you may complain to the UK Information Commissioner's Office or your local data-protection authority.
9. Security
We use administrative, technical and organisational safeguards designed to protect information. Access is permission-controlled within Customer workspaces, and the Service records security-related activity. No internet service or device can be guaranteed completely secure; Customers and users must protect their credentials and devices.
10. Cookies and local storage
Our Cookie and Local Storage Notice explains the necessary session and security technologies used by the website and Service.
11. Children
The Service is intended for business use and is not directed to children. Customers must not use the Service in a way that unlawfully processes children's personal data.
12. Changes and contact
We may update this Notice when the Service, law or our processing changes. The current version is available on this page.
For privacy questions, contact support@workpulse.solutions.
WorkPulse Solutions, 42 Hamilton Road, London, NW11 9EJ, United Kingdom.