Compliance

GDPR and works council review

ActivityPulse is designed for review under GDPR Article 88 and by a European works council: sensitive capture is off by default, keystroke content is never recorded, a narrower scope can never widen a broader one, and every configuration change is audited. It is not certified by any body — no such certification exists for this category — so what follows is the design, stated plainly enough to be checked.

What a vendor can and cannot promise

Worth being direct about, because the category is not.

Compliance is a property of a deployment — your lawful basis, your works council agreement, your retention policy, your configuration — not a property of a product. Any vendor claiming to hand you compliance in a box is describing something that does not exist, and a data protection officer will know that within a minute of asking.

What a product can do is make the compliant configuration the default, make the non-compliant one difficult, and make the whole thing inspectable. That is what the rest of this page describes.

Article 88 and the principle of minimisation

Article 88 lets member states set their own rules for processing employee data, and most set them tighter than the GDPR baseline. The common thread across those regimes is proportionality: collect what the purpose requires and no more.

ActivityPulse's purpose is attributing hours to projects. That needs to know which application was in front of a person and for how long. It does not need to know what they typed, what was on their screen, or what their webcam saw — so none of that is collected, and the most invasive capabilities are gated rather than offered as a switch.

The questions a works council asks

With the answers, in the order they usually come.

  • No keystroke content is captured — there is no code path that records what a person types.
  • No screen recording or session replay by default; screenshots are an Enterprise capability, off unless enabled.
  • The monitored person can see what is being captured on their own machine, and can pause capture.
  • No productivity score is calculated for an individual — the product reports hours, not judgements.
  • Capture can be bounded to a working-time window, and a narrower scope can never widen a broader one.
  • Every change to what is captured is written to an audit log with who changed it and when.

What is never captured

  • Keystroke content — what you type is never recorded, on any plan.
  • Webcam or microphone — the agent has no access to either.
  • Continuous screen recording — there is no session replay or video capture.
  • Personal file contents — the agent reads window and process metadata, not documents.
  • Browsing on a paused device — pausing capture stops collection, it does not hide it.

Data subject rights

rtbf
An erasure request deletes the person's captured activity and the raw archive it came from, not just their login.
transparent-agent
The person being monitored can see what is being captured on their own machine and can pause capture.
audited-config
Every change to what an organisation captures is written to an audit log with who changed it and when.

Scope, retention and residency

Retention is bounded per organisation rather than accumulating by default, and capture can be limited to a working-time window. Data residency options are available on the Enterprise plan; the current default region and the full list of sub-processors are published on the sub-processors page.

The processing terms we offer as processor under Article 28 are on the data processing agreement page.

Frequently asked questions

Is ActivityPulse GDPR compliant?

Compliance is a property of a deployment, not of a product, so no vendor can hand it to you. ActivityPulse is designed to make a compliant deployment achievable: data minimisation is the default, sensitive capture is off unless deliberately enabled, every configuration change is audited, and erasure removes the captured activity and the raw archive behind it.

Is ActivityPulse certified under GDPR Article 88?

No, and neither is any comparable product — there is no certification body that issues one for this category. What we can show is the design: what is captured, what is never captured, who can see it, and what is logged when the configuration changes.

Will a German works council approve ActivityPulse?

That decision belongs to the works council, and it depends on your agreement with them. The questions they usually ask have concrete answers here: no keystroke content is captured, there is no screen recording by default, the monitored person can see what is collected and can pause capture, and no productivity score is calculated for an individual.

What is the lawful basis for processing?

In most employment contexts this is legitimate interest or the performance of a contract, narrowed by Article 88 and by national law. ActivityPulse is designed so that the processing you have to justify is as small as possible, which is what makes a legitimate interest assessment straightforward rather than strained.

How does erasure work?

An erasure request removes the person's captured activity and the raw archive it was derived from, not just their account. It is not a soft delete that leaves the underlying records in place.

Can we limit monitoring to working hours?

Yes. A capture schedule bounds when the agent collects at all, and a narrower scope can never widen a broader one — so a team cannot be configured to capture outside the window the organisation set.

See where the hours actually went

Free for up to three people. Windows and macOS. No screenshots, no keystroke logging.