logo
  • Home
  • Features
  • How It Works
  • Pricing
  • Contact
  • Login
  • Register Now
Legal

Privacy Policy

Effective: 22 July 2026 Last updated: 22 July 2026 Version: 1.0
On this page
  1. Who we are
  2. Our role: processor vs. controller
  3. What data we collect
  4. Notice to monitored employees
  5. Why we process data
  6. Customer privacy controls
  7. Who we share data with
  8. Storage & location
  9. How long we keep data
  10. Security
  11. Your rights
  12. Children's data
  13. Cookies
  14. Changes to this policy
  15. Grievance Officer

In plain English

eWorkPulse is workforce-analytics software that organisations install on computers they own or control, to understand how work time is spent. It can capture application usage, window titles, browser activity, periodic screenshots, idle time and device information.

When your employer uses eWorkPulse, your employer decides what is collected, who sees it and how long it is kept. We hold and process that data on their behalf — we do not sell it, we do not use it to train AI models, and we do not use it for advertising.

If you are an employee with a question about monitoring at your workplace, your employer is the right first point of contact. We explain why in Section 2.

1. Who we are

eWorkPulse is a workforce-intelligence platform operated by Neurovia Technologies ("eWorkPulse", "we", "us", "our").

This Privacy Policy explains how we handle personal data in connection with our website (eworkpulse.com), our web application (app.eworkpulse.com), our desktop agent software, our mobile application and our APIs (together, the "Services").

This policy is written primarily against India's Digital Personal Data Protection Act, 2023 ("DPDP Act") and the Information Technology Act, 2000 together with the Reasonable Security Practices Rules, 2011.

2. Our role: processor vs. controller

Our obligations depend on whose data it is. There are two distinct situations, and the difference matters:

2.1 Employee monitoring data — we are a Data Processor

When a customer organisation deploys eWorkPulse to its workforce, that organisation is the Data Fiduciary (controller). It decides:

  • whether to monitor at all, and which employees to monitor;
  • which categories to capture — screenshots, application usage, web activity, idle time — via the policy settings described in Section 6;
  • who inside the organisation may view the data;
  • how long screenshots are retained;
  • what notice and consent it gives its employees.

We act as a Data Processor, processing that data only on the customer's documented instructions in order to provide the Services. We do not determine the purposes of monitoring, and we do not access customer monitoring data except as described in Section 7.

What this means for employees: if you want to know why you are monitored, what is collected about you, or to request access or deletion, your employer must answer that. We will support them in responding, but we cannot act on your data without their instruction. You can still contact our Grievance Officer (Section 15) and we will route your request appropriately.

2.2 Account, billing and website data — we are the Data Fiduciary

For our customers' own account information, billing records, support correspondence and visitors to our marketing website, we are the Data Fiduciary and this policy applies to us directly.

3. What data we collect

We have listed this at the level of detail our software actually operates at, rather than in general terms, so that both customers and monitored employees can see precisely what the product is capable of capturing.

3.1 Activity data captured by the desktop agent

DataDetail
Application usageName of the foreground application and the time spent in it.
Window titlesThe title bar text of the active window — which commonly includes document and file names.
Web addressesThe URL of the active browser tab, where the operating system makes it available to the agent.
ScreenshotsPeriodic captures of the screen, at an interval set by the customer. Can be disabled entirely.
Activity & idle timeWhether the machine is actively used or idle. We detect the presence of keyboard and mouse activity to determine this — we do not log keystrokes, and we do not record what is typed.
Device informationDevice name, operating system, CPU, RAM, storage and connected USB devices.
Network informationLocal and public IP address, MAC address of network interfaces.
Installed softwareA list of applications installed on the device.
OS usernameThe operating-system account name, used to link a device to the correct employee record.

What the agent does not do

The eWorkPulse agent does not record keystrokes, capture passwords, read the contents of files or emails, access the camera or microphone, record audio or video, or track physical location by GPS. It does not operate on personal devices unless the device owner installs it.

3.2 Account and identity data

  • Employee name, work email address, department, team and designation, as entered by the customer or imported from their existing systems;
  • Administrator names, work email addresses and hashed passwords;
  • Working-hours configuration and organisational structure.

3.3 Billing data

Organisation name, billing contact, invoice history and subscription details. Card and bank details are handled by our payment processor and are not stored on our systems.

3.4 Website and support data

If you submit a demo request or contact form, we collect the name, email address, phone number, company name and message you provide. Our web servers keep standard access logs including IP address, browser type and pages requested.

4. Notice to monitored employees

We consider it important enough to state separately: employees should be told they are being monitored.

Under our Terms & Conditions, every customer must give lawful notice to, and obtain any consent required from, the individuals they monitor before deploying the agent. Providing that notice is the customer's legal obligation, not ours — but deploying eWorkPulse covertly against employees who have not been informed is a breach of our Terms and grounds for suspension.

The product is deliberately designed to support transparent use. It captures work-time activity on organisation-controlled devices, and offers privacy controls (Section 6) that let customers limit what is collected.

5. Why we process data

PurposeExplanation
Providing the ServicesProducing the dashboards, reports, analytics and alerts the customer subscribes to.
Security and integrityAuthentication, preventing unauthorised access, and detecting abuse.
SupportDiagnosing and resolving issues a customer reports to us.
BillingInvoicing, payment processing and maintaining statutory financial records.
Service improvementAggregated, de-identified usage statistics that cannot identify an individual or a customer.
Legal complianceMeeting obligations under applicable law and responding to valid legal process.

We do not: sell personal data; share it with data brokers; use it for behavioural advertising; or use customer monitoring data to train machine-learning or artificial-intelligence models.

6. Customer privacy controls

Customers can restrict what the agent collects. These settings take effect on the agent itself, so disabled categories are never transmitted to us:

ControlEffect when disabled
Screenshot captureNo screenshots are taken or stored.
Application trackingApplication names and window titles are not recorded.
Web usage trackingURLs are not recorded and browser activity is reported only as generic browser use.
Idle-time trackingIdle periods are not separately recorded.
Sensitive-content blurringWhen enabled, screenshots are automatically blurred where sensitive content is detected before storage.
Screenshot retentionConfigurable; screenshots are deleted automatically once the retention period elapses. Default is 30 days.

We recommend customers enable only what they can justify for a clearly stated business purpose, and document that decision.

7. Who we share data with

We share personal data only in the following circumstances:

  • Sub-processors — vetted service providers who help us run the platform (cloud hosting, email delivery, payment processing). They act on our instructions, are bound by confidentiality, and may not use the data for their own purposes. A current list is available on request.
  • At the customer's direction — for example, where a customer enables an integration with a practice-management or timesheet system, or connects their own cloud storage (Amazon S3, Google Drive or Microsoft OneDrive) as the destination for their screenshots. Where a customer directs data to storage they control, it is held under their arrangements, not ours.
  • Legal process — where required by applicable law, court order or a lawful request from a government authority. Where we are legally permitted to do so, we will notify the affected customer before disclosing.
  • Business transfer — in a merger, acquisition or sale of assets, subject to the acquirer honouring this policy. Customers will be notified.

We do not disclose one customer's data to another customer. Every organisation's data is logically segregated and access-scoped to that organisation.

8. Storage & location

Our production infrastructure is hosted on Amazon Web Services in the Asia Pacific (Mumbai) region, India. Personal data processed through the Services is stored in India by default.

Two exceptions are worth stating plainly:

  • If a customer configures their own Google Drive or Microsoft OneDrive account as screenshot storage, the location of that data is determined by that provider and the customer's own account settings, which may be outside India.
  • A small number of our sub-processors, such as email delivery services, may process limited data outside India.

Where data is transferred outside India, we do so in accordance with applicable law and under appropriate contractual safeguards.

9. How long we keep data

DataRetention
ScreenshotsPer the customer's configured retention period. Default 30 days, after which they are deleted automatically.
Activity logs & analyticsFor the duration of the subscription, unless the customer deletes them sooner.
Account dataFor the duration of the subscription.
Billing recordsAs required by Indian tax and company law, typically eight years.
Website enquiriesUp to 24 months from last contact.

On termination, customers may export their data. We then delete or irreversibly anonymise customer data within 90 days, except where retention is required by law. Backups are purged on their own rotation, within 35 days.

10. Security

We maintain administrative, technical and physical safeguards including encryption in transit, encryption at rest, role-based access control, tenant isolation and audit logging. Our Data Security Policy sets out these measures in detail.

No system is perfectly secure. If a personal-data breach occurs, we will notify affected customers and the Data Protection Board of India as required by the DPDP Act, without undue delay.

11. Your rights

Subject to applicable law, you have the right to:

  • obtain confirmation of, and access to, the personal data we hold about you;
  • have inaccurate or incomplete data corrected, and to request erasure;
  • nominate another individual to exercise your rights in the event of death or incapacity;
  • withdraw consent, where processing is based on consent;
  • have your grievance addressed by our Grievance Officer.

How to exercise them. If you are an employee of a customer organisation, please contact your employer — they control that data and must respond. If you are a customer administrator, a website visitor or an enquirer, contact us directly using the details in Section 15.

We respond to verified requests within 30 days. We may need to verify your identity before acting.

12. Children's data

The Services are workplace software intended for use by adults in employment. They are not directed at children, and we do not knowingly collect personal data of any individual under 18 years of age. Customers must not deploy the agent to monitor a child.

13. Cookies

Our marketing website uses only what is necessary to make the site work and to understand aggregate traffic. Our web application uses strictly necessary cookies to keep you signed in and to maintain session security; these cannot be disabled without preventing the application from functioning. We do not use advertising or cross-site tracking cookies.

14. Changes to this policy

We may update this policy as the Services or the law change. The "Last updated" date at the top will always reflect the current version. For material changes affecting how we handle personal data, we will give customers at least 30 days' notice by email or in-application notice before the change takes effect.

15. Grievance Officer

In accordance with the DPDP Act, 2023 and the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011, you may contact our Grievance Officer with any question, concern or complaint about how we handle personal data:

Grievance OfficerSujeet Karn, Founder
EntityNeurovia Technologies
Emailprivacy@eworkpulse.com
Supportsupport@eworkpulse.com
Registered office319, Globe Estate NEXT, MIDC, Vikas Naka,
Dombivli (East), Thane – 421203,
Maharashtra, India

We acknowledge grievances within 72 hours and aim to resolve them within 30 days. If you are not satisfied with our response, you may escalate to the Data Protection Board of India.

Related documents
Terms & Conditions Data Security Policy Data Processing Agreement Contact us
logo

Next-generation workforce intelligence platform for remote & hybrid teams. Real data. Real insights. No micromanagement.

Product
  • All Features
  • How It Works
  • Pricing
  • Request Demo
Legal
  • Privacy Policy
  • Terms & Conditions
  • Data Security Policy
  • Data Processing Agreement
Company
  • Contact Sales
  • Support
  • Privacy Enquiries
Privacy Policy·Terms & Conditions·Data Security·DPA © 2026 Neurovia Technologies. All rights reserved.