Employee Monitoring Law Planner

Privacy

What you paste is read in your browser and is not sent to us unless you choose to save a plan. The paste needs monitoring practices, what they watch, staff groups, sites and countries, never employee names or anyone's personal data; staff groups are enough. Cells over 300 characters are not read: each is replaced with "content removed", and the saved text is the list as it was read. That is data minimisation, not de-identification: whatever else you put in a short cell is kept as you pasted it, so leave it out. When you save, the lines and the reading are stored so the product can show them back to you. You can delete a saved plan or your account at any time by writing to us, and we delete them; closing your account deletes everything saved under it. Your email address is stored for sign-in. We do not sell data, run advertising, or share your plans with anyone. Transactional email (sign-in links, receipts) is the only email a saved account receives. Payment details are handled by our payment processor and never touch our systems.

Where it is kept and who can see it. Pages are served by Cloudflare. Saved work and your account are stored in a Supabase database in Sydney, Australia (AWS ap-southeast-2), encrypted at rest and reached only over encrypted connections. Payments are processed by Stripe, and sign-in links and receipts are sent through SendGrid; those four are the only services that handle your data for us. Saved work is kept until you delete it or close your account. Our support staff open a saved record only to answer a request from you.

Sign-in security, the audit log and deleting your data. Two-step sign-in is optional unless the owner of a Team account requires it for everyone on it; the authenticator key is stored encrypted and recovery codes only as one-way hashes. The account keeps an audit log of sign-ins and sign-outs, two-step sign-in changes and refused codes, opening, saving, deleting and exporting saved work, teammate invitations and role changes, security settings and plan changes. Each entry holds who, when, the kind of action and which saved record, with a one-way hash of the network address and the browser family; it never holds what you pasted or saved. On Team the owner and editors of the account can read and export it; on Solo you can read your own. Entries are deleted automatically after two years. You can delete a saved record, or your whole account and everything saved under it, yourself from the account page; deleting an account cancels an active subscription, and Stripe keeps its own record of past payments.

Emailing a result to yourself. Where a result offers to be emailed to you, your browser sends only the summary shown on the page: the counts, the titles of the findings raised with their counts, and any coverage notice. The list you pasted, and any name or value in it, is never sent. We store your email address, that summary, when you asked, and whether you ticked the box for a note when the tool adds something new (no more than once a month), with the words of that box. Without the tick you get the one email and nothing else, and your address goes on no mailing list. Every email carries a link that stops them at once; an address that uses it is kept on a do-not-send list so we never write to it again. A request without the tick is deleted after 30 days; with it, it is kept until you unsubscribe and deleted 30 days after that. The email is sent through SendGrid from support@theartofservice.com.

Questions or deletion requests: support@theartofservice.com.

Employee Monitoring Law Planner is operated by The Art of Service Pty Ltd, GPO Box 2673, Brisbane QLD 4001, Australia.