Draft for legal review. This policy is for Business Viremail and does not apply until it has been approved and published.
Workplace Monitoring Policy
Last updated 2 October 2026Effective 26 September 2026
Where this stands
Business analytics, presence and location are not available yet. This policy explains how they will work, so businesses and their staff can know before any of it is switched on. The product page is at Workplace monitoring, openly.
Rota, for staff rotas, clocking in and timesheets, is being opened to businesses step by step. How it handles working time records, and the optional checks at clock-in, is in the Rota and clocking in section below.
What the service records
Only for business mailboxes, only in the categories the business turns on, and only after the steps below:
- Presence: online, idle and offline, active time per day, first and last seen. Only while Viremail is open.
- Activity counts: for example messages sent and replied to, calls and their length, files edited and shared, tasks finished, leads by stage. These are counts and times, with items referred to by an opaque reference.
- Who talks to whom inside the business: off unless the business turns it on. People outside the business are kept as their domain only.
- Vault for teams: who revealed which shared password, by the label an admin gave it. Never anything from a personal vault.
- Location: an optional policy, off by default. See below.
What it never records
The text or subject of any email, chat or note; attachment and file contents; call sound or video; passwords and other Vault secrets; keystrokes, screenshots, the webcam or the clipboard; browsing or anything outside Viremail; photos, fingerprints or other biometrics; and precise location, unless the location policy or a clock-in location check is on. The account of the person who created the business is never monitored.
Before anything is collected
- The business owner completes the monitoring setup: the categories, the countries and states where staff work, a legitimate interests assessment, and, for the UK, EU and EEA, a data protection impact assessment.
- The business publishes its monitoring policy, made from its choices.
- Each person sees a full-screen notice listing what is recorded, what never is, who can see it, how long it is kept and their rights, and acknowledges it. It shows again whenever the policy changes.
Collection for a person starts when they acknowledge the notice. Where they work in New South Wales or the Australian Capital Territory, it starts 14 days after notice, as those territories’ workplace surveillance laws require.
Who can see it
| Role | What they see |
|---|---|
| Owner and admins | Everyone, every category turned on, and exports |
| Managers | Only people in the teams they lead; no Vault details and no exports unless allowed |
| Everyone else | Their own figures, unless the business turns that off |
How long it is kept
| Data | Kept by default | The business can choose |
|---|---|---|
| Logged events | 12 months | 1 to 84 months |
| Presence | 6 months | 1 to 24 months |
| Daily and monthly totals | 25 months | 13 to 84 months |
| Location history | 30 days | 7 to 180 days |
| Clock-in location points (Rota) | 90 days, then removed from the clock event | No |
| Working time records (Rota) | UK 6 years, US 3 years, Australia 7 years, EU 5 years | Longer, never shorter than the legal minimum |
Location
- A business can set location to off (the default), optional or required, only after the monitoring setup and with a stated purpose.
- Browsers share location only while a Viremail tab is open and the person has allowed it. The desktop app shares it while it runs. Nothing is collected once it has closed.
- Points are taken during working hours unless the business chooses otherwise, which shows a warning about the law.
- The business chooses precise points or points rounded to about 1 km. No address lookups are sent to third parties.
- Each person can see their own history and a sign while location is collected. Every admin view is recorded in the audit log.
Rota and clocking in
Rota keeps a business’s staff rota, clock events, time off and timesheets. These are working time records that employers must keep by law, so they are kept without the monitoring setup. What makes clocking in monitoring is the optional checks below, and they follow the same rules as everything else on this page.
- Clock events: each clock in, break and clock out, with its time, how it was made (browser, desktop app, phone or kiosk) and the shift it matched. Events are never edited; a manager’s correction is a new entry with a reason, recorded in the business’s audit log.
- Location check (optional): the business can check that people clock in at a workplace. Only after its monitoring notice is published, and in New South Wales and the Australian Capital Territory only 14 days after notice. The browser or app shares one location point at the moment of each clock action, never a trail. The point is encrypted, kept with that clock event only, and removed after 90 days. Whether the person was inside the workplace is kept with the event.
- Network check (optional): the business can check that people clock in from the workplace’s own network. Only after its monitoring notice. The raw address is never stored: only whether it matched, and a keyed hash of it.
- Kiosk: a shared tablet at a workplace, where staff tap their name and type a 4 to 6 digit PIN. PINs are stored only as a salted hash. There are no photos, no fingerprints and no other biometrics, and the kiosk never shows anyone’s hours or details.
- Clocked time is not online time: timesheets come only from clock events and the rota, never from presence or activity in Viremail. Online time is never used to make or change a timesheet.
- How long: working time records are kept for the business’s retention period, which defaults to 6 years for the UK (the Working Time Regulations need 2, minimum wage records 6), 3 years for the US (the Fair Labor Standards Act), 7 years for Australia (the Fair Work Regulations) and 5 years in the EU, and cannot be set below the legal minimum. Each person can see their own records.
Rights of the people monitored
The business is the controller of this data, and we process it for the business under our Data Processing Addendum. People can ask their employer for a copy of their data, or for it to be corrected or deleted, as the law where they work allows. Staff can see their own figures and the notice at any time. If you work for a business on Viremail and have a question, ask your employer first; you can also contact us at [email protected].
What the business must do
- Make sure the monitoring is lawful, necessary and proportionate where its staff work, and use only the categories it needs.
- Carry out the assessments the law requires, and consult works councils or staff representatives where the law requires it, for example in Germany, France, Austria and the Netherlands.
- Give the notices the law requires, such as the written and posted notices in New York and the written notices in Connecticut and Delaware.
- Answer its staff’s requests about their data.
Templates
The service will offer editable templates: a monitoring policy, a legitimate interests assessment, a data protection impact assessment, the employee notice, a New York posting notice and a works council brief. Each starts with the words "This template is not legal advice."