Privacy Policy

Last Updated: July 15, 2026

Effective Date: March 14, 2026

Operated by N.S. IT SERVICES PTY LTD (ABN 75 122 740 121 / ACN 122 740 121)

1. Introduction & Identity

TheDeskMonitor ("we," "us," or "our") is a workforce monitoring SaaS platform operated by N.S. IT SERVICES PTY LTD (ABN 75 122 740 121 / ACN 122 740 121). This Privacy Policy governs the collection, use, disclosure, and retention of personal data processed through the TheDeskMonitor web platform, the DeskAgent desktop monitoring application for Windows, any associated mobile companion applications, and our public API. We are committed to processing your data responsibly and in accordance with applicable privacy laws, including the Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs), the UK/EU General Data Protection Regulation (GDPR), the California Consumer Privacy Act (CCPA), and comparable legislation worldwide.

For matters relating to data privacy, you may contact our Privacy Team at . We aim to respond to all enquiries within 30 calendar days. Where we act as a Data Controller (for example, in respect of account registration data), the controller entity is N.S. IT SERVICES PTY LTD (ABN 75 122 740 121 / ACN 122 740 121). Where we process monitoring data on behalf of your employer or organisation (a Tenant), we act as a Data Processor and your employer acts as the Data Controller for that data.

This Policy applies to all individuals who interact with our services, including employees who are monitored via DeskAgent, tenant administrators who configure monitoring settings, and visitors to our public marketing website. By accessing or using any part of the TheDeskMonitor platform, you acknowledge that you have read and understood this Privacy Policy.

2. Australian Privacy Principles

N.S. IT SERVICES PTY LTD (ABN 75 122 740 121 / ACN 122 740 121) complies with the Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs). Our privacy practices are designed to meet the obligations imposed by the APPs, including in relation to the collection, use, storage, disclosure, and security of personal information.

Enquiries and complaints about our privacy practices may be directed to . We will acknowledge your complaint within 5 business days and respond substantively within 30 calendar days. If you are unsatisfied with our response to your complaint, you may contact the Office of the Australian Information Commissioner (OAIC) at www.oaic.gov.au.

3. Information We Collect

A. Account & Identity Data

When you register for a TheDeskMonitor account or are invited to join a Tenant, we collect information necessary to create and manage your identity. This includes your full name, email address, your company or organisation name, and your job title where provided. Passwords are salted and hashed using industry-standard algorithms (bcrypt). We never store plaintext passwords. If you choose to upload a profile photograph, that image is stored as a binary blob within our Catalog database and is never shared with third-party image hosting services. Billing contacts for Tenant accounts may additionally provide company address information for invoicing purposes.

We also capture metadata associated with your account activity, including the IP address, approximate geographic location, and browser information at the time of each login event. This information is stored in the LoginHistory entity and is used for security purposes such as detecting anomalous login attempts and enforcing multi-factor authentication policies. The last five login events are summarised on your account profile to help you identify unauthorised access.

B. Monitoring Data (Collected via DeskAgent and Mobile App)

The DeskAgent desktop application collects workplace activity data on behalf of your employer (the Tenant). The categories of data collected depend on the features enabled by your Tenant administrator and the subscription plan in use. All monitoring data is encrypted in transit and stored securely within your Tenant's isolated database.

  • Screenshots: Periodic screen captures taken at intervals configured by your administrator (default: every 10 minutes). Employees in certain jurisdictions have a mandatory review window before screenshots are uploaded. Smart Blur applies automatic blurring to all background (non-active) windows in captured screenshots. The active window — the one you are currently working in — remains clear so productivity context is preserved. Smart Blur does NOT perform content-aware PII detection within the active window; sensitive data visible in the active window will be captured.
  • Application and URL Tracking: The name of the active application and, where enabled, the top-level domain of websites visited during working hours. This data is used to categorise activity as Productive, Neutral, or Unproductive based on rules set by your Tenant administrator. Full URL paths are not captured.
  • Activity Scores: Aggregate keyboard and mouse activity counts during each monitoring interval, used to calculate active/idle status. DeskAgent does NOT log the content of keystrokes, the text you type, or specific mouse coordinates — only aggregate activity counts.
  • Time Tracking: Clock-in/clock-out times and detected idle periods where no activity was observed for a configurable duration.
  • Location Data: Where enabled by your Tenant (Professional plans and above), approximate geographic location may be recorded during working hours. This feature requires your explicit consent at the device level and is governed by applicable employment law in your jurisdiction. Your IP address is also used at login for security monitoring and to determine applicable compliance rules.
  • Identity Verification (coming in a future release): A future release will add BioMatrix — on-device webcam-based identity verification. When launched, the desktop agent will derive a face-print embedding locally from a live webcam capture and transmit only the match verdict; verification images will never leave the employee's device. The enrolled face-print embedding will be stored on our servers in encrypted form; no viewable image is retained. Only the match verdict and confidence score will appear in the audit trail. Employer-tenants enabling this feature must obtain express written consent from employees as required under APP 3.3 and applicable surveillance legislation. This feature is not active in the current product. When BioMatrix ships, this Privacy Policy will be updated with the specific data-flow description and current customers will be notified.

C. Mobile Application Data

The TheDeskMonitor mobile application (Android) collects the following categories of data when you use it as part of your employment account. All data is transmitted over TLS 1.3 and stored within your Tenant's isolated, encrypted database on our servers.

  • Location (GPS — Foreground Only): When your organisation enables geo-gating for clock-in verification (Professional plans and above), the mobile app may request access to your device's precise and approximate GPS location. This permission is requested at your first clock-in attempt and requires your explicit consent via the Android permission dialogue. Location data is collected only while the app is open and in the foreground — the app never requests or uses background location access. If you deny the permission, clock-in still works; geo-gating features are simply unavailable for that session. Location data is stored on TheDeskMonitor servers and is visible only to your organisation's Tenant administrators. It is never shared with third parties.
  • Biometric Authentication (Fingerprint / Face Unlock): The mobile app supports optional biometric login (fingerprint or face recognition) as an alternative to entering your password on each session. Biometric verification is performed entirely on-device by the Android BiometricPrompt API. No biometric data (fingerprint template, face print, or any biometric embedding) is ever transmitted to or stored on TheDeskMonitor servers. The outcome of the biometric check (pass or fail) is used solely to unlock the app locally; the biometric data itself never leaves your device.
  • Push Notification Token (FCM): When you first log into the mobile app, a Firebase Cloud Messaging (FCM) registration token is generated by the Android operating system and sent to our servers. This token is a pseudonymous device identifier used exclusively to deliver push notifications to your device (such as clock-in reminders, task assignments, and administrative alerts). The FCM token is associated with your account and stored securely on our servers. It is never shared with third parties. You may revoke push notifications at any time through your Android device notification settings; revoking notifications causes a new FCM token to be issued or deregistered on your next login.
  • Device Identity (MachineId): A stable pseudonymous device GUID is generated and stored in Android SecureStorage on your device. This MachineId is used to associate your mobile sessions with your account for security and DeskAgent pairing purposes. It is not a hardware identifier and does not contain any personally identifiable information on its own.

D. Usage Data & Cookie-Stored Preferences

We collect anonymised or pseudonymised data about how you interact with the TheDeskMonitor web platform in order to improve our services and identify usability issues. This includes dashboard navigation events, feature usage frequency, browser type and version, device type (desktop, mobile, tablet), and general session duration metrics. This data is not used for advertising profiling and is not shared with advertising networks.

Through a single encrypted preference cookie (.DeskMonitor.Preferences), we store: your cookie consent choice (accepted or rejected) and your selected UI theme (dark or light). All values within this cookie are encrypted using ASP.NET Data Protection and are not readable by third parties. We do not store a visitor UUID or any anonymous tracking identifier in this cookie. See our Cookie Policy for full details.

E. Billing Data

All payment processing for TheDeskMonitor subscriptions is handled by Paddle, our Merchant of Record. We do not store credit card numbers, bank account details, or raw payment instrument data on our systems at any time. We do retain your subscription tier, billing cycle, and the transaction identifiers and event logs received from Paddle's webhook system in order to maintain an accurate record of your subscription history and to resolve billing disputes. For Tenants using the payroll disbursement features (Business and above), transaction identifiers from Wise and PayPal integrations are also retained for financial record-keeping purposes.

4. How We Use Your Information

We use the personal data we collect for the following purposes:

  • Service Delivery: To provide, operate, and maintain the TheDeskMonitor platform, including the generation of timesheets, productivity analytics, shift compliance reports, and payroll calculation services.
  • Monitoring and Reporting: To process activity data submitted by DeskAgent and generate the dashboards, productivity scores, and management reports that are the core purpose of the service. This processing is performed on behalf of the Tenant (your employer).
  • Payroll Processing: For Business and above Tenants using payroll disbursement, to calculate pay entitlements based on logged hours and hourly rates, and to initiate transfers via Wise or PayPal integrations.
  • Communications: To send transactional service notifications, security alerts (such as login from a new device), billing receipts, and platform update announcements. We do not send unsolicited marketing emails without your prior consent.
  • Security and Fraud Detection: To detect, prevent, and respond to unauthorised access attempts, account takeovers, and misuse of the platform in violation of our Acceptable Use Policy.
  • Legal Compliance: To comply with applicable legal obligations, including responding to valid law enforcement requests, satisfying financial record-keeping requirements, and enforcing our Terms of Service.
  • Platform Improvement: To analyse usage patterns, identify bugs, and develop new features. Where possible, this analysis is performed on aggregated or anonymised data sets.

5. Data Retention

TheDeskMonitor applies plan-based retention policies to monitoring data (activity logs and screenshots). The specific periods by subscription plan are:

PlanMonitoring Data Retention
Community60 days
Starter60 days
Professional90 days
Business1 year
EnterpriseUnlimited (no automated purge)

Your administrator can view the applicable retention period in account settings. Once the retention period has elapsed, data is automatically purged from the Tenant database. Enterprise customers may configure custom retention windows to meet their specific compliance obligations.

Account identity data (name, email, profile) is retained for the duration of your active account plus a 30-day grace period following account deletion, during which you may request reinstatement. Payroll and financial records are retained for a minimum of 7 years in compliance with standard financial record-keeping legal requirements across major jurisdictions. Employees who are removed from a Tenant or who voluntarily resign from a Tenant may download their timesheet history within 14 days of departure (paid Tenants) via a secure time-limited download link provided by email. After 30 days, all personal data associated with that user's membership in that Tenant is permanently deleted from our systems.

6. Data Sharing

TheDeskMonitor does not sell your personal data to third parties under any circumstances. We do not share monitoring data, cookie data, or preference data with advertising networks, data brokers, or any external parties for their commercial purposes. Cookie data stored on your device is never transmitted to or shared with any third party. We share data only with the following categories of sub-processors who assist us in operating the platform, each bound by appropriate data processing agreements:

  • Paddle: Our Merchant of Record for subscription billing and payment processing. Paddle receives the billing contact information and payment instrument data necessary to process your subscription. Paddle's own privacy policy governs how they handle this data.
  • Microsoft Corporation (Clarity): When you consent to analytics cookies on our public marketing website, anonymised session data (page URLs, click events, scroll depth, viewport size, truncated IP address, browser user-agent) is transmitted to Microsoft Clarity — a product analytics service operated by Microsoft Corporation. Clarity does not receive any form field content, passwords, payment data, or email addresses; all inputs are masked. Clarity data is retained for up to 30 days (session recordings) and 90 days (aggregated heatmaps). Data transfer mechanism: Standard Contractual Clauses (EU) 2021/914. Clarity is never loaded unless you have opted in via our cookie consent banner. Legal basis: consent (GDPR Art. 6(1)(a)). You may withdraw consent at any time via the Manage Cookies link in the site footer. See our Cookie Policy for full details.
  • Google LLC (Google Analytics 4): When you consent to analytics cookies on our public marketing website, anonymised usage data (page URLs, click events, session identifiers, IP address truncated to city level, browser user-agent, referrer, traffic-source attribution) is transmitted to Google LLC — operating Google Analytics 4 via Google Tag. Google LLC does not receive any form field content, passwords, payment data, or authenticated application data. GA4 data is retained for up to 14 months. Data transfer mechanism: Standard Contractual Clauses (EU) 2021/914 — see policies.google.com/privacy/frameworks. Google Tag is never loaded unless you have opted in via our cookie consent banner. Legal basis: consent (GDPR Art. 6(1)(a)). You may withdraw consent at any time via the Manage Cookies link in the site footer.
  • Cloudflare, Inc.: All traffic to the TheDeskMonitor platform passes through Cloudflare's network, which provides DNS resolution, content delivery (CDN), DDoS protection, WAF (web application firewall), and encrypted tunnel services. Cloudflare processes network-layer data (IP addresses, request metadata, TLS handshakes) as part of routing and protecting traffic. Cloudflare does not receive or process authenticated application data or monitoring content. Data transfer mechanism: Standard Contractual Clauses (EU) 2021/914. Cloudflare's privacy policy is available at cloudflare.com/privacypolicy.
  • Cloud Infrastructure Provider: TheDeskMonitor uses cloud infrastructure providers located in Australia and internationally. The specific provider, region, and configuration are operational matters that may change. We will notify customers of material changes to data storage geography via updated Terms. Customers may withdraw within 30 days of such notification by emailing .
  • Wise and PayPal: For Tenants using payroll disbursement features (Business and above), payroll payment instructions are transmitted to Wise or PayPal as directed by the Tenant administrator. Only the information necessary to execute the payment transfer is shared.

We may also disclose data to comply with a valid legal obligation, court order, or governmental request, or to protect the rights, property, or safety of TheDeskMonitor, our customers, or the public. In such cases, we will notify the affected Tenant to the extent permitted by law.

7. Employee Rights & Transparency

TheDeskMonitor is designed with employee transparency as a core principle. Every employee monitored via DeskAgent has access to a personal dashboard where they can review their own activity logs, screenshots, productivity scores, and timesheet data. Employees are never subject to covert monitoring; DeskAgent is visible in the Windows system tray at all times and displays clear status indicators showing when monitoring is active.

Employees may activate Privacy Mode at any time through the DeskAgent system tray menu. When Privacy Mode is active, all monitoring is paused — no screenshots, activity logs, or location data are collected. Privacy Mode is time-limited to a maximum of two consecutive hours per session, after which DeskAgent automatically logs the employee offline. Tenant administrators are not permitted to disable the Privacy Mode control on a per-employee basis.

All employees receive a disclosure notice when DeskAgent is first installed on their device. This notice explains what data is collected, how it is used, who has access to it, and how to exercise Privacy Mode. Employees may request a full export of their personal data by emailing . Employees who leave a Tenant may download their timesheet history for 14 days following departure (on paid plans) and may request erasure of their data subject to the applicable legal retention requirements described in Section 5.

Employer-tenants are the data controllers responsible for compliance with applicable privacy and workplace surveillance laws in their jurisdiction. TheDeskMonitor is a technology provider and data processor only. Employees should contact their employer in the first instance regarding their monitoring data.

8. Data Security

TheDeskMonitor implements comprehensive technical and organisational measures to protect personal data against unauthorised access, loss, or disclosure. All data in transit between DeskAgent, the browser, and our servers is protected using TLS 1.3 encryption. Screenshot image data is stored as encrypted binary blobs within Tenant databases and is not accessible via unauthenticated public URLs.

TheDeskMonitor strongly recommends two-factor authentication (2FA) for all accounts; 2FA is mandatory for Administrator and OwnerAdmin roles. Role-based access controls ensure that Tenant employees can only access their own data, Team Managers can access their team's data, and Administrators can access data within their own Tenant only. Authorised TheDeskMonitor staff may access your data as necessary to operate, support, maintain, develop and improve the Service. We conduct annual penetration testing against the platform and remediate critical findings within 30 days of discovery.

Notifiable Data Breaches: In the event of an eligible data breach as defined under Part IIIC of the Privacy Act 1988 (Cth), TheDeskMonitor will notify the Office of the Australian Information Commissioner (OAIC) and affected individuals as soon as practicable after determining an eligible breach has occurred, in accordance with the Notifiable Data Breaches (NDB) scheme. We will also notify affected Tenants as Data Controllers within 72 hours of becoming aware of a breach, consistent with our obligations under GDPR Article 33 where applicable.

9. International Data Transfers

TheDeskMonitor uses cloud infrastructure providers located in Australia and internationally. The specific provider, region, and configuration are operational matters that may change. We will notify customers of material changes to data storage geography via updated Terms. Customers may withdraw within 30 days of such notification by emailing .

TheDeskMonitor's Zone-Based Compliance feature automatically detects the geographic zone of each employee based on IP geolocation and enforces the applicable regulatory requirements for that zone. Zone A (covering EU/EEA, UK, Australia (all states and territories), and Canada) enforces the strictest controls, including mandatory screenshot review periods and enhanced notification requirements for on-demand sync activities. Note: The Privacy Act 1988 (Cth) applies federally across all Australian states and territories. This feature operates automatically and does not require manual configuration by Tenant administrators for standard compliance scenarios.

For Tenants in the European Economic Area or the United Kingdom whose data is transferred internationally, we rely on Standard Contractual Clauses (SCCs) as the appropriate transfer mechanism under GDPR Article 46.

Microsoft Clarity (Microsoft Corporation) — EU to US Transfer (Schrems II)

When you consent to analytics cookies on our public marketing website, anonymised session data is transferred to Microsoft Corporation in the United States via Microsoft Clarity. This transfer is governed by the Standard Contractual Clauses (SCCs) approved by the European Commission under Implementing Decision (EU) 2021/914, incorporated into Microsoft's Data Processing Agreement. Microsoft's SCC-based data transfer documentation is available at microsoft.com/licensing. Microsoft's government access transparency report is published at microsoft.com/transparency-report.

Google Analytics 4 (Google LLC) — EU to US Transfer (Schrems II)

When you consent to analytics cookies on our public marketing website, anonymised usage data (page URLs, click events, session identifiers, truncated IP address, browser user-agent, referrer, and traffic-source attribution) is transferred to Google LLC in the United States via Google Tag / Google Analytics 4. This transfer is governed by the Standard Contractual Clauses (SCCs) approved by the European Commission under Implementing Decision (EU) 2021/914, incorporated into Google's Data Processing Terms. Google's SCC-based data transfer documentation is available at policies.google.com/privacy/frameworks. Google's privacy policy is available at policies.google.com/privacy. Google's government access transparency report is published at transparencyreport.google.com.

Data shared with Google Analytics 4: page URLs visited on our public marketing site, click events, session identifiers (pseudonymous), IP address truncated to city level (last octet zeroed by GA4), browser user-agent string, referrer URL, and traffic-source attribution (utm_source, utm_medium, utm_campaign parameters). No authenticated application data, form inputs, passwords, payment details, or monitoring data are shared. Legal basis: consent (GDPR Art. 6(1)(a)). Default retention: 14 months.

EU/EEA residents may request a copy of the applicable SCCs by contacting our Privacy Team at . Both analytics tools are only loaded when you have opted in to analytics cookies — you may revoke consent at any time via the Manage Cookies link in the site footer.

10. Children's Privacy

The TheDeskMonitor platform is a business-to-business service intended exclusively for use by adults in a professional employment context. We do not knowingly collect or process personal data from individuals under the age of 16. Users confirm they are 18 or older by checking a declaration on the registration form. TheDeskMonitor does not independently verify age. If you believe that a minor's data has been inadvertently collected through our platform, please contact us immediately at and we will take prompt steps to delete that data. Tenant administrators are prohibited from deploying DeskAgent to monitor any individual who is under the age of 18, per our Acceptable Use Policy.

11. Your Rights (GDPR, CCPA, Australian Privacy Principles)

Depending on your location, you may have the following rights with respect to your personal data. These rights apply to the extent that TheDeskMonitor acts as a Data Controller for the relevant data (primarily account and identity data). For monitoring data where your employer is the Data Controller, you should direct requests to your employer, who may then coordinate with us as the Data Processor.

  • Right to Access (APP 12 / GDPR Art. 15): You have the right to request a copy of the personal data we hold about you, along with information about how it is processed.
  • Right to Rectification / Correction (APP 13 / GDPR Art. 16): You have the right to request correction of inaccurate or incomplete personal data we hold about you. Most profile data can be updated directly through your account settings. Under APP 13, we will correct or associate a statement of correction with your personal information if you establish that it is inaccurate, out of date, incomplete, irrelevant or misleading.
  • Right to Erasure ("Right to be Forgotten"): You have the right to request deletion of your personal data, subject to our legal obligations to retain certain records (for example, payroll records retained for 7 years).
  • Right to Restrict Processing: You have the right to request that we restrict the processing of your personal data in certain circumstances, for example while the accuracy of data is being contested.
  • Right to Data Portability: You have the right to receive your personal data in a structured, commonly used, and machine-readable format, and to transmit that data to another controller where technically feasible.
  • Right to Object: You have the right to object to processing of your personal data where we rely on legitimate interests as the legal basis for processing.
  • CCPA Rights: California residents have the right to know what personal information is collected, the right to delete personal information, and the right to non-discrimination for exercising privacy rights. We do not sell personal information as defined under CCPA.
  • Australian Complaints Pathway: If you are unsatisfied with our response to any privacy complaint, you may lodge a complaint with the Office of the Australian Information Commissioner (OAIC) at www.oaic.gov.au.

To exercise any of these rights, please submit a request to . Access, rectification, portability, and objection requests are acknowledged within 5 business days and completed within 30 calendar days, or we will inform you if a legally permissible extension is required. Deletion requests (individual account or workspace) are also acknowledged within 5 business days and completed within 30 calendar days of receipt; acknowledgement and completion notifications are sent to your registered email address.

How to Request Deletion of Your Data

Individual Account Deletion

If you are an individual user and wish to delete your account and associated personal data, you may do so directly through the TheDeskMonitor web platform:

  1. Log in at thedeskmonitor.com
  2. Click your profile avatar in the top-right corner
  3. Navigate to SettingsAccountDelete Account
  4. Confirm by clicking the link sent to your registered email address

After confirmation, your account is logically suspended immediately. All personal data we hold about you as the account holder is permanently erased within 30 calendar days, subject to the legal retention exemptions described in Section 5 (for example, payroll records are retained for 7 years as required by law).

Alternative contact. If you cannot access the web flow, you may email with the subject line "Account Deletion Request" and we will process the request on your behalf within the same 30-day timeline.

Workspace Deletion (Owner Admins Only)

Owner Admins of an organisation (tenant) may delete the entire workspace, which removes all employees' personal data held within that tenant. To request workspace deletion:

  1. Log in at thedeskmonitor.com as an Owner Admin
  2. Navigate to Workspace SettingsDelete Workspace
  3. Confirm by typing the workspace name and clicking the confirmation link sent to your registered email address

Workspace deletion requests are acknowledged within 5 business days and completed within 30 calendar days. All personal data of employees in that tenant is permanently purged, except data we are legally required to retain under applicable law (for example, payroll and financial records retained for 7 years — see Section 5).

Alternative contact. You may also email with the subject line "Workspace Deletion Request", including your organisation name and registered Owner Admin email address.

12. Cookies & Tracking

TheDeskMonitor uses a minimal set of cookies on our web platform. Our cookies fall into two categories:

  • Essential cookies (.DeskMonitor.Session, .DeskMonitor.External, .AspNetCore.Antiforgery.*, .DeskMonitor.Preferences, dm_consent) required for authentication, security, and storing your consent choices. Always active — cannot be disabled.
  • Analytics cookies — with your consent, we load Microsoft Clarity (Microsoft Corporation, US-hosted) and Google Analytics 4 (Google LLC, US-hosted) to understand how visitors use our marketing site. Clarity records anonymised page visits, click patterns, scroll depth, and session replays with all form input values masked. Google Analytics 4 records page views, session metadata, and traffic-source attribution. Legal basis: consent (GDPR Art. 6(1)(a)). Default: off. Opt-in required via the cookie banner. Both tools stop loading when consent is revoked.

We do not use advertising cookies or retargeting pixels at this time. If marketing cookies are introduced in future, you will be re-prompted for consent before they are activated. You may update your preferences at any time via the Manage Cookies link in the site footer.

For the complete list of cookies, their purposes, durations, security attributes, and Schrems II transfer mechanism, please see our Cookie Policy.

13. Changes to This Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, the features we offer, or applicable legal requirements. When we make material changes, we will notify affected users via email and via an in-app notification banner within the TheDeskMonitor platform. The "Last Updated" date at the top of this document will always reflect the date of the most recent revision. We encourage you to review this Policy periodically. Continued use of the TheDeskMonitor platform after the effective date of any update constitutes your acceptance of the revised Policy.

If you have any questions about this Privacy Policy or our data practices, please contact us at .

14. Google & Microsoft Sign-In (OAuth)

TheDeskMonitor offers Google Sign-In and Microsoft Sign-In as optional login mechanisms, allowing you to authenticate using your existing Google or Microsoft account instead of a separate TheDeskMonitor password. Both features are implemented using the OAuth 2.0 authorisation protocol.

Google Sign-In

Scopes Requested

When you choose to sign in with Google, TheDeskMonitor requests the following OAuth scopes from Google's authorisation server:

  • openid — confirms your identity with Google and returns a unique identifier (sub) so we can locate or create your TheDeskMonitor account.
  • email — your Google account email address, used to match you to an existing TheDeskMonitor account or pre-fill registration.
  • profile — your display name and profile photo URL as provided by your Google account, used to pre-populate your TheDeskMonitor profile.

These scopes are classified by Google as non-sensitive identity scopes. We do not request access to Gmail, Google Drive, Google Calendar, Google Contacts, or any other Google service beyond the three identity scopes listed above.

Data Received and How It Is Used

Upon successful Google Sign-In, we receive from Google: your Google account identifier (sub), your email address, your display name, and the URL of your Google profile picture. We use this data solely to authenticate your session and, where applicable, to create your TheDeskMonitor account profile. We do not access your Google contacts, Google Drive files, Google Calendar events, Gmail messages, or any other Google account data.

Token Handling

OAuth access tokens and ID tokens issued by Google during the sign-in flow are used transiently to complete authentication and are not persisted on our servers (SaveTokens = false). We do not store your Google OAuth tokens after the authentication handshake is complete. Your TheDeskMonitor session is governed by our own session cookie (.DeskMonitor.Session) once sign-in is complete; no Google token is retained beyond that point.

Google LLC as Sub-Processor (Authentication Context)

In the context of Google Sign-In, Google LLC acts as a sub-processor of your basic identity data (account identifier, email address, and display name) in order to perform the OAuth authentication exchange. This is a distinct and separate sub-processor role from Google LLC's role as an analytics provider (Google Analytics 4, described in Section 6) and from Google LLC's role as an AI provider (Aria / Gemini, described in Section 15). Google Sign-In data exchange is governed by Google's OAuth policies and Google's Privacy Policy at policies.google.com/privacy. For GDPR purposes, the data transfer mechanism for the OAuth authentication exchange is Standard Contractual Clauses (EU) 2021/914.

You may disconnect Google Sign-In at any time via your TheDeskMonitor account Settings page. Disconnecting does not delete your TheDeskMonitor account; it reverts your login method to email-and-password. You may also revoke TheDeskMonitor's access to your Google account at any time via myaccount.google.com/permissions.

Microsoft Sign-In (Microsoft Account / Entra)

Scopes Requested

When you choose to sign in with Microsoft, TheDeskMonitor requests the following OAuth scopes from Microsoft's identity platform (Entra / Microsoft Account):

  • openid — confirms your identity with Microsoft and returns a unique identifier so we can locate or create your TheDeskMonitor account.
  • email — your Microsoft account email address, used to match you to an existing TheDeskMonitor account or pre-fill registration.
  • profile — your display name as provided by your Microsoft account, used to pre-populate your TheDeskMonitor profile.
  • offline_access — included by the Microsoft identity platform as a default scope for the authorisation code flow; it is not used by TheDeskMonitor to obtain refresh tokens (tokens are not persisted — see Token Handling below).

We do not request access to Outlook, OneDrive, Teams, Contacts, Calendar, or any other Microsoft 365 service beyond the basic identity scopes above.

Token Handling

OAuth access tokens and ID tokens issued by Microsoft during the sign-in flow are used transiently to complete authentication and are not persisted on our servers (SaveTokens = false). No Microsoft OAuth tokens are retained after the authentication handshake is complete.

Microsoft Corporation as Sub-Processor (Authentication Context)

In the context of Microsoft Sign-In, Microsoft Corporation acts as a sub-processor of your basic identity data (account identifier, email address, and display name) in order to perform the OAuth authentication exchange. This is a distinct and separate sub-processor role from Microsoft Corporation's role as an analytics provider (Microsoft Clarity, described in Section 6). Microsoft Sign-In data exchange is governed by Microsoft's OAuth policies and Microsoft's Privacy Statement at privacy.microsoft.com/privacystatement. For GDPR purposes, the data transfer mechanism for the OAuth authentication exchange is Standard Contractual Clauses (EU) 2021/914.

You may disconnect Microsoft Sign-In at any time via your TheDeskMonitor account Settings page. You may also revoke TheDeskMonitor's access to your Microsoft account at any time via myapps.microsoft.com (under App permissions).

15. AI Features & MCP Data Processing

TheDeskMonitor includes AI-powered features designed to help you and your organisation understand and act on your workplace productivity data. This section describes how data is processed in connection with those features, which third-party AI providers are involved, and the controls available to you.

A. Aria — In-App AI Assistant

Aria is TheDeskMonitor's built-in AI assistant. Aria answers questions about your productivity data, timesheets, team reports, schedule, and attendance records in natural language. Aria is accessible to authenticated users on paid plans via the in-app chat interface.

How Aria works: When you send a message to Aria, TheDeskMonitor compiles a structured context from your authenticated session — including your role-scoped workspace data such as your productivity scores, timesheet records, team summaries (for managers), and attendance data — and submits that context along with your message to a third-party AI model for response generation. The AI model processes your query and returns a response, which Aria presents to you. TheDeskMonitor is the data controller for this processing; the AI provider operates as a sub-processor under a data processing agreement.

AI provider — Google (Gemini): Aria's responses are currently generated by Google LLC's Gemini language model (specifically gemini-2.5-flash-lite), accessed via Google's Generative Language API. Your query and the associated workspace context compiled for your session are transmitted to Google's API endpoint and processed to generate a response. Google LLC acts as an AI sub-processor in this context. This is a distinct and separate sub-processor role from Google LLC's roles as an analytics provider (Google Analytics 4) or an authentication provider (Google Sign-In), each described in their respective sections of this Policy. Google's data processing terms for the Generative Language API are available at ai.google.dev/gemini-api/terms. For GDPR purposes, the data transfer mechanism is Standard Contractual Clauses (EU) 2021/914.

AI provider — Anthropic (Claude) — future / conditional: TheDeskMonitor's architecture supports an optional routing path through Anthropic's Claude models, operated via a locally-managed session bridge rather than a direct Anthropic API connection. This path is not active in the current production configuration. If and when this routing path is enabled in a future release, we will update this Policy and notify affected users before activation. Where this path is active, Anthropic, Inc. acts as an AI sub-processor. Anthropic's privacy policy is available at anthropic.com/privacy.

B. MCP (Model Context Protocol) Integration

TheDeskMonitor exposes a Model Context Protocol (MCP) server at https://api.thedeskmonitor.com/api/mcp/v1/. MCP is an open protocol that enables external AI clients — such as Claude Desktop, Gemini CLI, or other MCP-compatible AI assistants — to connect to TheDeskMonitor and access your workspace data on your behalf, using natural language commands.

Authentication and access control: MCP access requires authentication via TheDeskMonitor's OAuth 2.1 + PKCE authorisation flow or a Tenant API key. MCP tokens are issued by TheDeskMonitor's own authorisation server and are scoped to the authenticated tenant and the authenticated user's role. Tenant identity is always resolved from the authentication credential — it is never accepted from tool arguments or request headers. This means an MCP session can only access data within the tenant of the authenticated user, at the permission level of that user's role (Employee, Manager, Admin, or OwnerAdmin). Cross-tenant data access is architecturally prevented.

What data MCP can access: Through the MCP integration, an authorised AI client may access the following categories of workspace data, subject to the authenticated user's role permissions: dashboard productivity summaries, employee lists and profiles (scoped to the tenant), timesheet records, team hour summaries, schedule and attendance data, workload alerts, productivity overviews, and pending approval records. The MCP server exposes read-oriented access to this data via structured tool calls; it does not enable arbitrary database queries.

Which AI providers process MCP-sourced data: The MCP server provides structured data responses to the AI client application that initiated the request. The AI client — not TheDeskMonitor — determines which AI model processes those responses. If you use Claude Desktop as your MCP client, your queries and the data returned by TheDeskMonitor's MCP tools are processed by Anthropic, Inc. (Claude) subject to Anthropic's privacy policy. If you use a Gemini CLI or other client, the applicable AI provider's policy governs. TheDeskMonitor does not control the AI model used by the MCP client application you choose; we are responsible only for the data we supply to the MCP tool response, not for how the AI client processes it.

MCP audit logging: Every MCP tool call is recorded in an audit log that captures: the tenant, user, tool name, arguments, response status, call duration, outcome, and client identifier. Arguments are stored in structured form; they do not include free-text user queries (those remain in the AI client application). MCP audit logs are retained for up to 2 years, after which they are automatically purged.

C. AI Query Session Context

AI chat sessions with Aria are held in transient server-side session state (Redis), keyed to your authenticated identity. Guest (unauthenticated) Aria sessions have a 30-minute sliding inactivity timeout and do not include any personal workspace data. Authenticated Aria sessions have a 60-minute sliding inactivity timeout. Session context held in Redis is not persisted to the database; it expires automatically at the end of the inactivity window. Conversation history is not retained beyond the active session window without explicit export.

AI action logs — which record AI-proposed actions that you explicitly confirm or decline — are retained for up to 2 years per your tenant's audit record, then automatically purged.

D. Data Minimisation and Scope

TheDeskMonitor applies role-based scoping to all AI feature access. The workspace data compiled and submitted to AI providers reflects only the data your role is permitted to access within the TheDeskMonitor platform — an Employee's Aria context contains only that employee's own data; a Manager's context is scoped to their team; an Admin's context is scoped to their tenant. No cross-tenant data is included in any AI context or MCP response.

We do not use your personal workspace data to train AI models. Data submitted to Google Gemini for Aria response generation is used solely to generate responses to your queries within the TheDeskMonitor platform. We rely on Google's Generative Language API terms, under which API usage data is not used to train Google's foundational models.

E. User Controls and Opt-Out

AI features (Aria and MCP access) require your active use — they are not background data-processing services that operate without your initiation. You control access as follows:

  • Aria (in-app assistant): Aria is accessible via the in-app chat interface on eligible plans. You may simply not use the feature. If you are a Tenant administrator and wish to restrict Aria access for your workspace, please contact and we will assist with the appropriate configuration.
  • MCP integration: MCP access is opt-in — it requires you or your Tenant administrator to actively configure an MCP client application and complete the OAuth authorisation flow. No MCP access occurs without an explicit authorisation grant. You may revoke an MCP authorisation by contacting . MCP access tokens expire after 1 hour; client registrations expire after 30 days of inactivity.
  • Employees: Employees' data may be included in AI responses generated for Managers, Admins, or OwnerAdmins who query Aria about team performance, in the same way that employee data is already visible to those roles in the standard platform dashboards. If you have concerns about AI-assisted access to your data, please contact your Tenant administrator or email .

F. International Transfers (AI Processing)

Queries submitted to Google Gemini may be processed on infrastructure located in the United States or other jurisdictions. For transfers from the EU/EEA or UK, we rely on Standard Contractual Clauses (EU) 2021/914 with each AI sub-processor. You may request a copy of the applicable SCCs by contacting .

N.S. IT SERVICES PTY LTD (ABN 75 122 740 121 / ACN 122 740 121) |

Was this page helpful?

For privacy enquiries: