New v2.2Digital Wellbeing screen time insights & native PhonePe UPI billing are now live!See what's new
Legal & Compliance

Privacy Policy & Security Standards

Complete transparency regarding data collection, zero-keylogger architecture, screenshot privacy blurring, and statutory compliance with India DPDP Act 2023 and GDPR.

In plain English
  • Your employer decides what is tracked. iVision processes the data on their behalf.
  • Recorded: work times, apps and website domains used, activity counts per minute, and screenshots if your employer turns them on.
  • Never recorded: which keys you press, anything you type, passwords, card numbers, OTPs, webcam or microphone.
  • Sensitive windows are blurred before a screenshot is uploaded. Each company’s data is kept separate.
  • You can ask for wrong attendance records to be corrected through your manager.
  • Questions or deletion requests: privacy@ivision.work. We reply within 7 business days.

This summary is for convenience. The full text below is what applies.

Where the data goes
  1. STEP 1
    Employee computer
    The iVision app records work time and activity counts.
  2. STEP 2
    Blurred and sent securely
    Sensitive screens are blurred, then data is uploaded over HTTPS.
  3. STEP 3
    Your company’s workspace
    Stored separately from every other company.
  4. STEP 4
    People you choose
    Only admins and managers your company picks can see it.
Effective Date: January 15, 2026Entity: IV Consultancy Services Pvt Ltd

1. Introduction & Scope

IV Consultancy Services Pvt Ltd (operating iVision, "we", "us", or "our") provides workforce analytics, time tracking, and productivity monitoring solutions for commercial organizations. This Privacy Policy outlines how personal and telemetry data is collected, processed, encrypted, and retained when using the iVision web administration portal (https://ivision.work), desktop tracking applications (Windows, Linux, macOS), and associated API services.

In our business relationship, your employer or contracting organization acts as the Data Fiduciary (or Data Controller), determining the policies, capture intervals, and employee scopes. iVision acts strictly as a Data Processor (or Data Fiduciary Agent) processing information under instructions provided by the subscribing organization.

2. Strict Zero-Keylogger Architecture Guarantee

iVision categorically rejects keystroke logging. Our desktop client utilizes the Activity Classification Engine (ACE) to quantify movement velocity (e.g. key-down/up frequency per 60-second window) solely to calculate active focus percentages.

  • We NEVER record which specific keys were pressed.
  • We NEVER capture words, sentences, search terms, or typed messages.
  • We NEVER intercept passwords, credit card numbers, or two-factor codes.
  • We NEVER record webcam video, ambient microphone audio, or physical room activity.

3. Information We Collect

Depending on the feature set enabled by your organization, iVision collects the following categories of data:

A. Account & Profile Information

Employee name, corporate email address, encrypted password hash (bcrypt with salt), assigned department, job role, and company GSTIN for billing.

B. Work Session & Telemetry Data

Session start and stop timestamps, active duration, idle thresholds (after 5 minutes of inactivity), 60-second heartbeat presence indicators (ACTIVE, IDLE, OFFLINE), and device hardware identifiers (used for 1-device license binding).

C. Application & Web Domain Telemetry

Active application window titles (e.g., "VS Code - main.ts") and browser top-level domains (e.g., "github.com", "figma.com") across Chrome, Firefox, Edge, and Brave to determine productivity categorization.

D. Smart Privacy-Blurred Screenshots (Optional)

If enabled by the employer, periodic primary display screenshots (typically every 10 minutes). Where sensitive personal or financial windows are active, automated 30-pixel Gaussian blur is applied to obscure sensitive details before upload.

4. Statutory Compliance Frameworks

India Digital Personal Data Protection (DPDP) Act 2023: iVision operates under explicit commercial contracts with employer organizations. Employers must provide lawful notice and acquire necessary employee consent in according with the DPDP Act 2023 before activating tracking agents on employee or contractor devices.
EU General Data Protection Regulation (GDPR): For European data subjects, processing is conducted on the legal basis of Legitimate Interests (Article 6(1)(f)) and Performance of Contract (Article 6(1)(b)), bounded by proportionality, data minimization, and role-scoped access control.

5. Data Security & Multi-Tenant Isolation

We implement enterprise-grade security controls to protect all stored information:

  • PostgreSQL Row-Level Security (RLS): Hardware-enforced isolation ensuring tenant data is completely siloed and inaccessible across organizations.
  • Encryption Standards: Data in transit is secured via TLS 1.3; screenshots and database volumes are encrypted at rest using AES-256.
  • Offline Datastore Security: Desktop client SQLite files are encrypted on device using OS-level secure storage (Electron safeStorage).
  • Data Retention Schedule: Activity logs and screenshots are retained according to the employer's configured retention schedule (default 90 days), after which they are permanently purged.

6. Data Subject Rights & Grievance Redressal

Employees have the right to inspect their personal tracked hours, view active sessions, and request correction of anomalous records through attendance regularization. Inquiries regarding data privacy or formal deletion requests can be addressed to our Data Protection & Grievance Officer:

Data Protection & Grievance Officer
IV Consultancy Services Pvt Ltd
Official Resolution Window: Within 7 business days