Privacy Policy
Draft template — last edited [add date]. Not yet reviewed by counsel.
1. Who this policy covers
This policy explains how [Company legal name] ("we", "us", "Worklucent AI") collects, uses, and protects data through the Worklucent AI platform, for two audiences: (a) the companies ("customers") who deploy Worklucent AI to monitor their own workforce, and (b) the employees of those customers whose devices run the Worklucent AI agent.
2. What data we collect
Through the Windows agent and dashboard, Worklucent AI processes:
- Account and company data: admin/employee names, email addresses, company details, roles.
- Device activity metadata: active/idle time, application and window titles in use, keyboard/mouse event counts (not keystroke content), device identifiers, and timestamps.
- Device and enrollment data: device name, OS version, agent version, enrollment key usage, last-seen timestamps.
- Optional, off-by-default data: screenshots and AI-generated insights, only if a customer explicitly enables these features for their workspace.
We do not capture raw keystroke content, clipboard contents, or personal message/email content under any plan.
3. How we use data
- To provide the core monitoring, reporting, and dashboard functionality the customer has subscribed to.
- To generate aggregated productivity reports and, where enabled, AI-generated narrative summaries.
- To secure the platform (authentication, audit logging, fraud/abuse prevention).
- To communicate service updates, billing, and support information to customer admins.
4. Legal basis and employer responsibilities
Worklucent AI is provided as a tool for the customer (the employer) to monitor its own workforce. The customer is responsible for establishing a valid legal basis for monitoring under applicable law — including providing employees clear notice and, where required, obtaining consent — before enabling the agent on any device. [Company legal name] acts as a data processor/service provider for activity data on the customer's behalf, and as a controller for account and billing data related to the customer relationship itself.
5. Data sharing
We do not sell personal data. Data may be shared with:
- Sub-processors who help us operate the platform (cloud hosting, email delivery, optional AI providers) — listed on request.
- Law enforcement or regulators, where legally required.
- A successor entity in the event of a merger, acquisition, or asset sale, subject to equivalent privacy commitments.
6. Data retention
Activity data is retained for [retention period — define per plan/contract] unless the customer configures a different retention window. Account data is retained for the duration of the customer relationship plus any period required for legal, tax, or audit purposes.
7. Security
We use encrypted transport, token-based device authentication, per-tenant data isolation, and audit logging for sensitive actions. See our Security & Compliance page for more detail. No system is completely secure; we will notify affected customers of any confirmed data breach as required by applicable law.
8. Data subject / principal rights
Employees whose activity is monitored may have rights under applicable law (e.g. the DPDP Act, 2023) to access, correct, or request erasure of their personal data, subject to the employer's records-retention obligations. Requests should generally be directed to the employee's employer (the customer); we support customers in fulfilling these requests.
9. International transfers
[Describe where data is hosted, e.g. India-only hosting vs. cross-border transfer, and the safeguards used if data leaves India.]
10. Changes to this policy
We will update this page when our practices change and will note the date of the most recent revision above.
11. Contact us
Questions about this policy can be sent to privacy@[your-domain] or [registered office address].