WorkComposer Privacy Policy
Last modified: July 8, 2026
WorkComposer Inc (“WorkComposer”, “we”, “us”, or “our”) provides business software for workforce time-tracking and activity monitoring. This Privacy Policy explains how we handle Personal Data in connection with our websites, applications, and related services (collectively, the “Services”).
This Policy is written for a business-to-business (B2B) product, and it is important to understand the two very different roles we play with respect to data. Please read Section 2 (“Our Two Roles”) carefully — it determines which parts of this Policy apply to you.
Defined terms used throughout: “Customer” means the business or organization that subscribes to the Services (for example, an employer). “Authorized Users” means individuals the Customer permits to administer or access its WorkComposer account (for example, admins and managers). “Monitored Users” means the individuals whose work activity is tracked through the Services (typically the Customer's employees or contractors). “Personal Data” means any information relating to an identified or identifiable natural person. “Subprocessor” means a third party we engage to process Personal Data on our behalf.
1. Definitions
- Personal Data — any information relating to an identified or identifiable natural person (a “data subject”). This includes information that can identify someone directly (such as a name or email) or indirectly (such as an online identifier).
- Usage Data — data collected automatically from the use of the Services or generated by the Services' infrastructure (for example, the duration of a page visit, or diagnostic logs).
- Cookies — small data files stored on a device. See our separate Cookie Policy.
- Controller — the party that determines the purposes and means of processing Personal Data.
- Processor — a party that processes Personal Data on behalf of, and under the instructions of, a Controller.
- Data Subject — the living individual to whom Personal Data relates.
- Monitoring Data — screenshots, application and website activity, keyboard/mouse activity levels, tracked time, and similar activity information collected by our desktop application about Monitored Users, as configured by the Customer.
2. Our Two Roles — Please Read First
WorkComposer processes Personal Data in two distinct capacities, and different sections of this Policy apply to each:
(a) Data we process on behalf of Customers (WorkComposer is the Processor)
This is Monitoring Data and related account data that a Customer uploads to or generates within the Services about its Monitored Users — for example, screenshots, application and website names visited during tracking, activity levels, and tracked time.
For this data, the Customer is the Controller and WorkComposer is the Processor. The Customer decides what to monitor, whom to monitor, on what legal basis, and whether to enable any covert (“Silent” or “Silent-Extended”) monitoring modes. WorkComposer processes this data only on the Customer's documented instructions, under a data processing agreement (see Section 11).
If you are a Monitored User (for example, an employee whose device runs WorkComposer): your employer — not WorkComposer — is the Controller of your Monitoring Data and is responsible for telling you what is collected, why, and on what legal basis, and for honoring your rights. See Section 10 (“How Monitored Users Exercise Their Rights”). WorkComposer cannot lawfully release your Monitoring Data directly to you without your employer's authorization.
(b) Data we process for our own purposes (WorkComposer is the Controller)
- Customer account and billing data — the contact and payment details of the Customer and its Authorized Users;
- Website visitor data — information about people who visit our marketing website (Usage Data, cookies, advertising-attribution data); and
- Support and communications data — information you provide when you contact us.
Sections 3–9 below describe this Controller-role processing. Section 2(a) data (Processor role) is governed principally by our data processing agreement with the Customer (Section 11), with the summary in this Policy provided for transparency.
3. Personal Data We Collect and Why
3.1 As Controller (account, billing, website, support)
| Category | Examples | Purpose | Legal basis (GDPR Art. 6) |
|---|---|---|---|
| Account & identity | Name, email, phone, company, job title | Create and administer the account; authenticate Authorized Users | Contract — Art. 6(1)(b); Legitimate interests — Art. 6(1)(f) (account security) |
| Billing | Billing address, plan, invoices; card data is handled directly by Stripe and not stored by us | Process subscriptions and payments; tax/accounting | Contract — Art. 6(1)(b); Legal obligation — Art. 6(1)(c) (tax records) |
| Usage & device (of our web/app surfaces) | IP address, browser type/version, pages viewed, timestamps, device identifiers, diagnostic logs | Operate, secure, debug, and improve the Services | Legitimate interests — Art. 6(1)(f) |
| Approximate location | Country/region/city inferred from IP address | Localization, fraud prevention, analytics | Legitimate interests — Art. 6(1)(f) |
| Marketing & attribution | Advertising click identifiers and campaign parameters (see the Cookie Policy), email preferences | Measure advertising effectiveness; send marketing where permitted | Consent — Art. 6(1)(a) (where required); Legitimate interests — Art. 6(1)(f) |
| Support communications | Content of your messages to us | Respond to and resolve requests | Legitimate interests — Art. 6(1)(f); Contract — Art. 6(1)(b) |
We determine approximate geographic location from IP addresses using a locally-hosted database provided by DB-IP (https://db-ip.com), licensed under the Creative Commons Attribution 4.0 International License (CC BY 4.0). This lookup is performed entirely on our own servers using the bundled database; your IP address is not transmitted to DB-IP.
3.2 As Processor (Monitoring Data — controlled by the Customer)
- Screenshots of the Monitored User's screen during active tracking;
- Application and website names in use during tracking;
- Activity levels derived from keyboard and mouse input during tracking (we collect activity levels, not keystroke content);
- Tracked time and related timesheet data.
The Customer configures whether tracking is visible or operates in a Silent / Silent-Extended (covert) posture. The Customer — as Controller — is solely responsible for establishing a lawful basis for this monitoring and for providing any legally required notice to Monitored Users (see Section 11 and our Terms). WorkComposer provides an in-application notice surface (the desktop “About” screen remains reachable to Monitored Users) but does not, and cannot, determine the Customer's lawful basis on the Customer's behalf.
4. How We Use Data (Controller Role)
- provide, maintain, secure, and improve the Services;
- create and administer accounts and authenticate Authorized Users;
- process payments and manage subscriptions;
- provide customer support and respond to inquiries;
- detect, prevent, and investigate fraud, abuse, and technical issues;
- comply with legal obligations and enforce our agreements; and
- send service communications and, where permitted, marketing (you can opt out of marketing at any time via the unsubscribe link or by contacting us).
We do not sell Personal Data. See the California section (Section 12) for how “sale” and “sharing” are defined there.
5. Legal Bases (EEA/UK)
Where the GDPR or UK GDPR applies to our Controller-role processing, we rely on the legal bases identified in the table in Section 3.1: performance of a contract (Art. 6(1)(b)), compliance with a legal obligation (Art. 6(1)(c)), our legitimate interests (Art. 6(1)(f)), and consent (Art. 6(1)(a)) where required (for example, non-essential cookies and certain marketing). Where we rely on legitimate interests, we have balanced those interests against your rights and freedoms. You may object to legitimate-interests processing as described in Section 9.
For Monitoring Data, the legal basis is determined and documented by the Customer as Controller, not by WorkComposer.
6. Retention
- Monitoring Data (screenshots, activity, application/website, and related tracking data) is automatically and permanently deleted one (1) year after collection, or on account deletion, whichever occurs first. The one-year purge runs automatically on a daily basis. A Customer may configure shorter behavior or request earlier deletion through its account or its agreement with us.
- Account and billing data is retained for as long as the account is active and thereafter as needed to comply with legal, tax, and accounting obligations, resolve disputes, and enforce our agreements. Billing and tax records are retained for seven (7) years as required by applicable tax and accounting law.
- Support communications are retained for approximately two (2) years. Website analytics and lead data are retained for approximately fourteen (14) months.
- Website Usage Data and cookies are retained per the periods described in the Cookie Policy (for example, advertising-attribution cookies are retained for 90 days).
- Voluntary account deletion. When an Owner-role user confirms an account-deletion request, we purge that account's data promptly through our self-service deletion process and our automated deletion routines; deletion is irreversible and access is lost immediately. Residual copies in backups are overwritten in the ordinary backup rotation.
- Non-payment / abandonment. An account whose invoices remain unpaid for more than approximately two (2) months may be deleted, following at least fourteen (14) days' advance warning notice.
For full detail, see our Data Retention Policy.
7. International Data Transfers
WorkComposer hosts and processes data on Amazon Web Services infrastructure located in the United States (AWS region us-east-1). If you access the Services from outside the United States, your Personal Data will be transferred to and processed in the United States, where data-protection laws may differ from those in your jurisdiction.
Where we transfer Personal Data of individuals in the EEA, UK, or Switzerland to the United States, we rely on appropriate safeguards, including the Standard Contractual Clauses approved by the European Commission (and the UK International Data Transfer Addendum where applicable). For Monitoring Data processed on a Customer's behalf, these safeguards are incorporated into the data processing agreement between the Customer and WorkComposer (Section 11). Further detail is in our International Data Transfers note. A copy of the relevant transfer mechanism is available on request at privacy@workcomposer.com.
8. Disclosure of Data
- To Subprocessors — third parties that process data on our behalf under contract (see Section 13);
- For legal reasons — where we believe in good faith that disclosure is necessary to comply with a legal obligation or valid request from a public authority (such as a court or government agency), to protect and defend our rights or property, to prevent or investigate possible wrongdoing in connection with the Services, to protect the personal safety of users or the public, or to protect against legal liability;
- In a business transfer — in connection with a merger, acquisition, financing, or sale of assets, subject to this Policy or a successor policy of comparable protection; and
- With your direction or consent — including, for Monitoring Data, on the instruction of the Customer that controls it.
We do not sell your Personal Data.
9. Your Rights (EEA/UK and Similar Jurisdictions)
- access the Personal Data we hold about you and receive a copy;
- rectify inaccurate or incomplete Personal Data;
- erase your Personal Data (“right to be forgotten”);
- restrict or object to processing, including processing based on legitimate interests and processing for direct marketing;
- data portability — receive certain Personal Data in a structured, commonly used, machine-readable format;
- withdraw consent at any time where processing is based on consent (without affecting prior processing); and
- lodge a complaint with your local supervisory authority.
Authorized Users can update much of their account Personal Data directly in account settings. To exercise any right regarding data we hold as Controller, contact us at privacy@workcomposer.com. We may need to verify your identity before responding. We will respond within the timeframes required by applicable law (generally one month under the GDPR).
For Personal Data we process as Processor (Monitoring Data), see Section 10.
10. How Monitored Users Exercise Their Rights
- Requests to access, correct, delete, or object to the processing of your Monitoring Data should be directed to your employer, who decides how to respond as the Controller.
- WorkComposer, as Processor, will assist the employer in responding to such requests but cannot release, alter, or delete your Monitoring Data without the employer's authorization.
- Your employer is responsible for informing you about the monitoring it has configured (including any covert “Silent” mode), the categories of data collected, and the legal basis for that monitoring.
If you contact WorkComposer directly, we will, where we can identify your employer, forward your request to them and let you know we have done so. See our Employee Privacy Notice for a plain-language overview.
11. Data Processing Agreement (Customers)
- limits our processing to the Customer's documented instructions;
- requires the Customer to warrant it has a lawful basis for the monitoring it configures and has given any legally required notice to Monitored Users;
- imposes confidentiality, security, breach-notification, subprocessor, deletion/return, and audit-assistance obligations on WorkComposer; and
- incorporates the EU Standard Contractual Clauses for international transfers.
Customers can review our current Data Processing Agreement, request it at privacy@workcomposer.com, or access it via their account.
12. California Privacy Rights (CCPA/CPRA)
This section applies to California residents and supplements the rest of this Policy. It describes how we handle Personal Information (as defined by the California Consumer Privacy Act, as amended by the CPRA) that we process as a business (our Controller-role data). For Monitoring Data, WorkComposer acts as a service provider to the Customer, and the Customer is the business responsible for California rights requests from its Monitored Users.
Categories of Personal Information we collect (as Controller): identifiers (name, email, IP address); commercial information (subscription and billing records); internet/network activity (usage and diagnostic data on our web/app surfaces); geolocation (approximate, from IP); and inferences drawn from the above. We collect these for the business purposes described in Section 4 and disclose them to the Subprocessors listed in Section 13.
We do not sell your Personal Information, and we do not “share” it for cross-context behavioral advertising as those terms are defined under the CPRA, except that our use of advertising-attribution and analytics technologies (see the Cookie Policy) may constitute “sharing.” You can opt out of these technologies via the cookie consent banner or the “Do Not Sell or Share My Personal Information” control where offered. We do not knowingly sell or share the Personal Information of consumers under 16.
Your California rights: to know/access the categories and specific pieces of Personal Information we collect; to delete Personal Information (subject to exceptions); to correct inaccurate Personal Information; to opt out of any sale or sharing; and to limit the use of sensitive Personal Information (we do not use sensitive Personal Information for purposes requiring an opt-out). We will not discriminate against you for exercising these rights.
To exercise California rights, contact us at privacy@workcomposer.com. You may use an authorized agent, and we will verify requests as required by law.
13. Subprocessors
We engage the following categories of Subprocessors to provide the Services. Card payment data is provided directly to Stripe and is not stored by us.
| Subprocessor | Purpose | Data location |
|---|---|---|
| Amazon Web Services (AWS) | Cloud hosting and storage (S3), transactional email (SES), message queues (SQS) | United States (us-east-1) |
| Stripe | Payment processing (PCI-DSS Level 1) | United States / global |
| reCAPTCHA Enterprise (bot/abuse prevention), OAuth sign-in, and Google Analytics / Google Ads (website analytics and advertising measurement) | United States / global | |
| Usercentrics | Cookie consent management | European Union |
We maintain contracts requiring each Subprocessor to protect Personal Data consistent with this Policy and applicable law. Our current Subprocessor list is published for our Processor-role services, and we will provide reasonable advance notice of new Subprocessors as set out in the DPA.
14. Security
We use commercially reasonable administrative, technical, and physical measures designed to protect Personal Data against unauthorized access, use, alteration, loss, or disclosure. These include encryption of data in transit (TLS/HTTPS), access controls that restrict internal access to Customer Data to a limited set of personnel and only where necessary (for example, to troubleshoot an issue you report), regular backups to a separate location, and network protections. No method of transmission or storage is completely secure, and we cannot guarantee absolute security. We do not currently hold SOC 2, ISO 27001, or PCI certifications; payment card data is handled directly by our PCI-compliant payment processor (Stripe) and is not stored by us.
15. Cookies and Similar Technologies
We use cookies and similar technologies on our websites and in the Services. Details of each category (necessary, functional, analytics, marketing), what each does, and how to withdraw consent are set out in our separate Cookie Policy. Where required by law, we obtain consent through our cookie consent banner before setting non-essential cookies.
16. Do Not Track
Some browsers offer a “Do Not Track” (DNT) setting. There is no consistent industry standard for how to respond to DNT signals, and we do not currently respond to DNT signals. Where the law requires it, we honor recognized opt-out preference signals (such as Global Privacy Control) as an opt-out of sale/sharing (see Section 12). You can control cookies through our cookie consent banner and your browser settings.
17. Children's Privacy
The Services are B2B tools not directed to children. We do not knowingly collect Personal Data from anyone under the age of 16. If you believe a child has provided us Personal Data, contact us and we will take steps to delete it.
18. Links to Other Sites
The Services may contain links to sites we do not operate. We are not responsible for the privacy practices of those sites and encourage you to review their policies.
19. Changes to This Policy
We may update this Policy from time to time. We will post the updated Policy here with a revised “Last updated” date and, where required, provide additional notice. Your continued use of the Services after an update constitutes acceptance of the revised Policy to the extent permitted by law.
20. Contact Us
- Privacy inquiries and rights requests: privacy@workcomposer.com
- General support: support@workcomposer.com
- Postal address: WorkComposer Inc (a Delaware corporation), 9450 SW Gemini Dr, PMB 94875, Beaverton, OR 97008-7105, United States