Privacy Policy
This Privacy Policy explains how inat360 (“we”, “us”, or “our”) handles information in connection with the inat360 Work Desk applications for Windows desktop, Android, and iOS (together, the “Apps”), and the related employee portal typically available at https://inat360.com (or another URL configured by your employer) (the “Portal”).
By signing in to or using the Apps or Portal, you acknowledge this Privacy Policy. If you do not agree, do not use the Apps. Your employer may also have its own workplace privacy, monitoring, and acceptable-use policies that apply in addition to this document.
Who controls your data. The Apps are provided to employees and authorized contractors by their employer (or the organization that issued their account). That organization is generally the primary controller of work-related personal data processed through the Portal (for example timesheets, tasks, and activity reports). inat360 provides and hosts the software platform on behalf of participating organizations and processes data as a service provider / processor according to that organization’s instructions and configuration, except where we act as an independent controller for our own account administration, security, billing, or product operations.
1. Scope
This Policy applies to:
- The Windows desktop Work Desk agent (Microsoft Store and other distribution channels);
- The Android and iOS mobile Work Desk applications;
- Information the Apps send to or receive from the Portal while you are signed in.
It does not replace your employer’s internal policies, employment contracts, or notices required under local labor or privacy law. Website marketing pages may have additional notices where relevant.
2. Information we collect
Depending on the App you use and features your organization enables, we may collect:
2.1 Account and authentication
- Employee ID / username and password you enter to sign in (passwords are verified by the Portal; we do not store passwords in plain text; session credentials are protected by the operating system and App storage practices).
- Authentication tokens and device registration tokens that link your installation to your Portal account.
2.2 Profile and workplace records
- Name, job title/role, department, branch, avatar or profile photo, and similar directory fields.
- Tasks, support tickets, deployments, notifications, messages, attendance or vacation-related records, and other workplace content your organization makes available to you in the Portal.
2.3 Work session and presence
- When you start or end an “@ Work” / “At work” session.
- Session start and end timestamps, idle/pause events, resumed work, and related presence signals.
- Work-time intervals used for timesheets and operational reporting.
2.4 Location data (mobile Apps only)
- Approximate GPS coordinates and related accuracy/time metadata, collected only while you are in an active @ Work session that you start.
- Background location may be used on mobile so check-ins can continue when the App is not in the foreground, when your organization requires presence verification.
- The Windows desktop App does not collect GPS location.
2.5 Desktop activity signals (Windows App)
- While you are At work, the desktop App may record foreground application/process names and window titles.
- Optional optical character recognition (OCR) samples of on-screen text for organizational productivity reporting, when enabled for your organization.
- Screen images for administrator remote viewing only when authorized under your organization’s policies and while you are signed in.
- These desktop signals are workplace monitoring features configured for your employer; they are not used for third-party advertising.
2.6 Device and technical information
- Device or PC name, operating system version, App version, language/region settings.
- A stable install identifier and App-specific device token.
- Optional system health metrics (for example CPU and memory usage) when Desktop Systems / fleet health features are enabled for your organization.
- Diagnostic logs, error messages, and connectivity status needed to operate and secure the service.
2.7 Offline and local storage
- If connectivity is lost while At work, work-time segments (and on mobile, location check-ins) may be stored locally on the device and uploaded when connectivity returns.
- Cached profile or UI data may be stored temporarily to improve performance.
3. How we use information
We use the information described above to:
- Authenticate users and connect Apps to the correct organization Portal.
- Record work time, presence, idle pauses, and (on mobile) location check-ins for timesheets and operations.
- Deliver tasks, tickets, notifications, chat, and other Portal features assigned to you.
- Support employer-enabled reporting (including desktop activity/OCR summaries where configured).
- Maintain reliability, prevent abuse, debug issues, and protect the security of accounts and systems.
- Comply with law and enforce contractual or organizational terms.
We do not sell your personal information. We do not use the Apps to serve third-party advertising. We do not use desktop OCR or screen data for advertising profiles.
4. Legal bases (where applicable)
Where privacy laws require a legal basis (for example GDPR), processing typically relies on:
- Performance of a contract / employment relationship — providing the workplace tools your employer offers;
- Legitimate interests — security, service integrity, and product improvement that do not override your rights;
- Legal obligation — where retention or disclosure is required by law;
- Consent — where required for optional device permissions (for example mobile location or notifications), which you can withdraw in system settings (features may then be limited).
Your employer determines many workplace monitoring purposes; ask them for the notice that applies to your role.
5. Location data (mobile — important)
Mobile Apps may request location permission because your organization may require location check-ins while @ Work. Location is used for periodic GPS check-ins, map features (such as setting a project pin), geofenced attendance rules where configured, and presence reporting on the Portal.
- Location is collected only during an active @ Work session you start.
- Background location may be used so check-ins continue if the App is backgrounded.
- You can stop collection by ending @ Work and/or revoking location permission in device settings.
6. Desktop activity and monitoring (Windows)
The Windows Work Desk App is a workplace presence and productivity agent. Collection of window metadata, OCR samples, or remote screen frames (if enabled) occurs in the context of your employment and your organization’s policies. Ending At work or signing out stops further collection for that session. Administrators who can view related reports or remote sessions are determined by Portal permissions.
7. Where data is stored and international transfers
Data is transmitted to your organization’s Portal and stored on servers used to operate that Portal (commonly associated with https://inat360.com or an employer-configured host). Hosting may involve cloud infrastructure providers. If you or your organization are located in a different country from the hosting region, information may be transferred across borders. Where required, appropriate safeguards are applied (for example contractual protections with processors). Local device storage may hold tokens, queued intervals, and caches until sync or sign-out.
8. Sharing
Information may be shared with:
- Your employer / organization — administrators, managers, and colleagues according to Portal roles and policies.
- Service providers — hosting, email, push notification, storage, or similar infrastructure vendors, only as needed to run the service and under appropriate obligations.
- Professional advisors and corporate events — for example auditors or in connection with a merger, acquisition, or reorganization, subject to confidentiality where appropriate.
- Legal and safety — when required by law, legal process, or to protect rights, security, and safety.
9. Retention
Retention periods are primarily set by your organization’s policies and Portal configuration. Work-time records, location history, desktop activity/OCR records, tickets, and related logs may be kept for operational, HR, audit, or compliance purposes. Local App caches are typically removed or become inaccessible after sign-out, subject to operating-system backup behavior. Contact your administrator for organization-specific retention schedules.
10. Security
We use industry-standard measures such as encrypted transport (HTTPS/TLS), authenticated API access, hashed or tokenized device credentials where applicable, and access controls on the Portal. No method of transmission or storage is completely secure. Protect your device with a passcode, Windows Hello / sign-in, and keep the Apps and OS updated. Report suspected unauthorized access to your administrator and to us when appropriate.
11. Your choices and rights
- End At work / @ Work when you finish to stop presence and related session collection.
- Sign out to clear local session data on the device.
- Manage location, notification, microphone/camera/screen-capture, and similar permissions in OS settings.
- Request access, correction, deletion, restriction, or portability of Portal-held personal data through your organization’s administrator (they control most workplace records).
- Where applicable law grants additional rights (for example GDPR/UK GDPR/CCPA), you may also contact us at the email below; we may need to route requests to your employer as controller.
12. Children’s privacy
The Apps are intended for authorized adult employees and contractors. They are not directed to children under 13 (or the higher age required in your jurisdiction). We do not knowingly collect personal data from children. If you believe a child has provided data, contact us and we will take appropriate steps.
13. Third-party services and links
The Portal or Apps may link to third-party sites or rely on infrastructure providers. Their privacy practices are governed by their own policies. This Policy applies to inat360 Apps and Portal processing described here.
14. Changes to this Policy
We may update this Privacy Policy from time to time. The “Last updated” date at the top will change when we do. Material changes may also be communicated through the Portal or Apps. Continued use after the effective date means you accept the updated Policy, except where additional consent is required by law.
15. Contact
For privacy questions about data held by your employer (access, correction, deletion, workplace monitoring notices), contact your organization’s HR or IT administrator first.
For questions about the inat360 platform or this Policy, contact: privacy@inat360.com
Public policy URL: https://inat360.com/privacy-policy