Privacy Policy
In plain English
eWorkPulse is workforce-analytics software that organisations install on computers they own or control, to understand how work time is spent. It can capture application usage, window titles, browser activity, periodic screenshots, idle time and device information.
When your employer uses eWorkPulse, your employer decides what is collected, who sees it and how long it is kept. We hold and process that data on their behalf — we do not sell it, we do not use it to train AI models, and we do not use it for advertising.
If you are an employee with a question about monitoring at your workplace, your employer is the right first point of contact. We explain why in Section 2.
1. Who we are
eWorkPulse is a workforce-intelligence platform operated by Neurovia Technologies ("eWorkPulse", "we", "us", "our").
This Privacy Policy explains how we handle personal data in connection with our website (eworkpulse.com), our web application (app.eworkpulse.com), our desktop agent software, our mobile application and our APIs (together, the "Services").
This policy is written primarily against India's Digital Personal Data Protection Act, 2023 ("DPDP Act") and the Information Technology Act, 2000 together with the Reasonable Security Practices Rules, 2011.
2. Our role: processor vs. controller
Our obligations depend on whose data it is. There are two distinct situations, and the difference matters:
2.1 Employee monitoring data — we are a Data Processor
When a customer organisation deploys eWorkPulse to its workforce, that organisation is the Data Fiduciary (controller). It decides:
- whether to monitor at all, and which employees to monitor;
- which categories to capture — screenshots, application usage, web activity, idle time — via the policy settings described in Section 6;
- who inside the organisation may view the data;
- how long screenshots are retained;
- what notice and consent it gives its employees.
We act as a Data Processor, processing that data only on the customer's documented instructions in order to provide the Services. We do not determine the purposes of monitoring, and we do not access customer monitoring data except as described in Section 7.
What this means for employees: if you want to know why you are monitored, what is collected about you, or to request access or deletion, your employer must answer that. We will support them in responding, but we cannot act on your data without their instruction. You can still contact our Grievance Officer (Section 15) and we will route your request appropriately.
2.2 Account, billing and website data — we are the Data Fiduciary
For our customers' own account information, billing records, support correspondence and visitors to our marketing website, we are the Data Fiduciary and this policy applies to us directly.
3. What data we collect
We have listed this at the level of detail our software actually operates at, rather than in general terms, so that both customers and monitored employees can see precisely what the product is capable of capturing.
3.1 Activity data captured by the desktop agent
| Data | Detail |
|---|---|
| Application usage | Name of the foreground application and the time spent in it. |
| Window titles | The title bar text of the active window — which commonly includes document and file names. |
| Web addresses | The URL of the active browser tab, where the operating system makes it available to the agent. |
| Screenshots | Periodic captures of the screen, at an interval set by the customer. Can be disabled entirely. |
| Activity & idle time | Whether the machine is actively used or idle. We detect the presence of keyboard and mouse activity to determine this — we do not log keystrokes, and we do not record what is typed. |
| Device information | Device name, operating system, CPU, RAM, storage and connected USB devices. |
| Network information | Local and public IP address, MAC address of network interfaces. |
| Installed software | A list of applications installed on the device. |
| OS username | The operating-system account name, used to link a device to the correct employee record. |
What the agent does not do
The eWorkPulse agent does not record keystrokes, capture passwords, read the contents of files or emails, access the camera or microphone, record audio or video, or track physical location by GPS. It does not operate on personal devices unless the device owner installs it.
3.2 Account and identity data
- Employee name, work email address, department, team and designation, as entered by the customer or imported from their existing systems;
- Administrator names, work email addresses and hashed passwords;
- Working-hours configuration and organisational structure.
3.3 Billing data
Organisation name, billing contact, invoice history and subscription details. Card and bank details are handled by our payment processor and are not stored on our systems.
3.4 Website and support data
If you submit a demo request or contact form, we collect the name, email address, phone number, company name and message you provide. Our web servers keep standard access logs including IP address, browser type and pages requested.
4. Notice to monitored employees
We consider it important enough to state separately: employees should be told they are being monitored.
Under our Terms & Conditions, every customer must give lawful notice to, and obtain any consent required from, the individuals they monitor before deploying the agent. Providing that notice is the customer's legal obligation, not ours — but deploying eWorkPulse covertly against employees who have not been informed is a breach of our Terms and grounds for suspension.
The product is deliberately designed to support transparent use. It captures work-time activity on organisation-controlled devices, and offers privacy controls (Section 6) that let customers limit what is collected.
5. Why we process data
| Purpose | Explanation |
|---|---|
| Providing the Services | Producing the dashboards, reports, analytics and alerts the customer subscribes to. |
| Security and integrity | Authentication, preventing unauthorised access, and detecting abuse. |
| Support | Diagnosing and resolving issues a customer reports to us. |
| Billing | Invoicing, payment processing and maintaining statutory financial records. |
| Service improvement | Aggregated, de-identified usage statistics that cannot identify an individual or a customer. |
| Legal compliance | Meeting obligations under applicable law and responding to valid legal process. |
We do not: sell personal data; share it with data brokers; use it for behavioural advertising; or use customer monitoring data to train machine-learning or artificial-intelligence models.
6. Customer privacy controls
Customers can restrict what the agent collects. These settings take effect on the agent itself, so disabled categories are never transmitted to us:
| Control | Effect when disabled |
|---|---|
| Screenshot capture | No screenshots are taken or stored. |
| Application tracking | Application names and window titles are not recorded. |
| Web usage tracking | URLs are not recorded and browser activity is reported only as generic browser use. |
| Idle-time tracking | Idle periods are not separately recorded. |
| Sensitive-content blurring | When enabled, screenshots are automatically blurred where sensitive content is detected before storage. |
| Screenshot retention | Configurable; screenshots are deleted automatically once the retention period elapses. Default is 30 days. |
We recommend customers enable only what they can justify for a clearly stated business purpose, and document that decision.
7. Who we share data with
We share personal data only in the following circumstances:
- Sub-processors — vetted service providers who help us run the platform (cloud hosting, email delivery, payment processing). They act on our instructions, are bound by confidentiality, and may not use the data for their own purposes. A current list is available on request.
- At the customer's direction — for example, where a customer enables an integration with a practice-management or timesheet system, or connects their own cloud storage (Amazon S3, Google Drive or Microsoft OneDrive) as the destination for their screenshots. Where a customer directs data to storage they control, it is held under their arrangements, not ours.
- Legal process — where required by applicable law, court order or a lawful request from a government authority. Where we are legally permitted to do so, we will notify the affected customer before disclosing.
- Business transfer — in a merger, acquisition or sale of assets, subject to the acquirer honouring this policy. Customers will be notified.
We do not disclose one customer's data to another customer. Every organisation's data is logically segregated and access-scoped to that organisation.
8. Storage & location
Our production infrastructure is hosted on Amazon Web Services in the Asia Pacific (Mumbai) region, India. Personal data processed through the Services is stored in India by default.
Two exceptions are worth stating plainly:
- If a customer configures their own Google Drive or Microsoft OneDrive account as screenshot storage, the location of that data is determined by that provider and the customer's own account settings, which may be outside India.
- A small number of our sub-processors, such as email delivery services, may process limited data outside India.
Where data is transferred outside India, we do so in accordance with applicable law and under appropriate contractual safeguards.
9. How long we keep data
| Data | Retention |
|---|---|
| Screenshots | Per the customer's configured retention period. Default 30 days, after which they are deleted automatically. |
| Activity logs & analytics | For the duration of the subscription, unless the customer deletes them sooner. |
| Account data | For the duration of the subscription. |
| Billing records | As required by Indian tax and company law, typically eight years. |
| Website enquiries | Up to 24 months from last contact. |
On termination, customers may export their data. We then delete or irreversibly anonymise customer data within 90 days, except where retention is required by law. Backups are purged on their own rotation, within 35 days.
10. Security
We maintain administrative, technical and physical safeguards including encryption in transit, encryption at rest, role-based access control, tenant isolation and audit logging. Our Data Security Policy sets out these measures in detail.
No system is perfectly secure. If a personal-data breach occurs, we will notify affected customers and the Data Protection Board of India as required by the DPDP Act, without undue delay.
11. Your rights
Subject to applicable law, you have the right to:
- obtain confirmation of, and access to, the personal data we hold about you;
- have inaccurate or incomplete data corrected, and to request erasure;
- nominate another individual to exercise your rights in the event of death or incapacity;
- withdraw consent, where processing is based on consent;
- have your grievance addressed by our Grievance Officer.
How to exercise them. If you are an employee of a customer organisation, please contact your employer — they control that data and must respond. If you are a customer administrator, a website visitor or an enquirer, contact us directly using the details in Section 15.
We respond to verified requests within 30 days. We may need to verify your identity before acting.
12. Children's data
The Services are workplace software intended for use by adults in employment. They are not directed at children, and we do not knowingly collect personal data of any individual under 18 years of age. Customers must not deploy the agent to monitor a child.
13. Cookies
Our marketing website uses only what is necessary to make the site work and to understand aggregate traffic. Our web application uses strictly necessary cookies to keep you signed in and to maintain session security; these cannot be disabled without preventing the application from functioning. We do not use advertising or cross-site tracking cookies.
14. Changes to this policy
We may update this policy as the Services or the law change. The "Last updated" date at the top will always reflect the current version. For material changes affecting how we handle personal data, we will give customers at least 30 days' notice by email or in-application notice before the change takes effect.
15. Grievance Officer
In accordance with the DPDP Act, 2023 and the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011, you may contact our Grievance Officer with any question, concern or complaint about how we handle personal data:
| Grievance Officer | Sujeet Karn, Founder |
|---|---|
| Entity | Neurovia Technologies |
| privacy@eworkpulse.com | |
| Support | support@eworkpulse.com |
| Registered office | 319, Globe Estate NEXT, MIDC, Vikas Naka, Dombivli (East), Thane – 421203, Maharashtra, India |
We acknowledge grievances within 72 hours and aim to resolve them within 30 days. If you are not satisfied with our response, you may escalate to the Data Protection Board of India.