Last Updated: 23 September, 2026
General Data Protection Regulation (GDPR)
Supporting Our Customers' Privacy and Compliance
Softhealer Technologies Pvt. Ltd. ("Softhealer", "we", "our", or "us") is the developer and provider of Monitor360, an enterprise workforce monitoring and productivity platform.
We are committed to protecting personal data and supporting organisations that operate under the General Data Protection Regulation (GDPR).
Monitor360 is designed with privacy-focused principles, configurable monitoring controls and enterprise security practices to help customers meet their own GDPR obligations.
This page explains how Monitor360 supports GDPR. For detailed information about the personal data processed through Monitor360, please refer to our Privacy Policy.
1. Our Approach to GDPR
Privacy and data protection are fundamental to the design and operation of Monitor360.
We believe workforce monitoring should provide organisations with meaningful operational insights while respecting employee privacy and protecting personal data.
Rather than collecting all available information from monitored devices, Monitor360 is designed to collect only the information necessary to deliver productivity, operational visibility and security insights.
Our monitoring capabilities are configurable, allowing customers to enable or disable features according to their organisational policies and applicable legal requirements.
2. Privacy by Design
Monitor360 follows the principles of Privacy by Design by integrating privacy considerations throughout the product lifecycle.
Our approach includes:
- Collecting only information necessary to provide the service.
- Providing configurable monitoring features.
- Reducing unnecessary processing of personal information.
- Applying appropriate technical and organisational security measures.
- Continuously improving privacy and security as the platform evolves.
For information about the categories of personal data processed by Monitor360, please refer to our Privacy Policy.
3. Data Controller and Data Processor
Under the GDPR, responsibilities are shared between Softhealer Technologies Pvt. Ltd. and our customers.
Softhealer Technologies Pvt. Ltd.
When providing Monitor360 services, Softhealer generally acts as a Data Processor, processing personal data on behalf of customers in accordance with their documented instructions.
We are responsible for implementing appropriate technical and organisational measures designed to protect personal data processed through Monitor360.
Customer
Customers generally act as the Data Controller and are responsible for:
- Determining the purpose of processing personal data.
- Establishing an appropriate lawful basis for processing.
- Configuring monitoring according to organisational policies.
- Informing employees about workplace monitoring where required.
- Responding to applicable data subject requests.
- Complying with applicable privacy and employment legislation.
4. Supporting GDPR Principles
Monitor360 is designed to support customers in implementing key GDPR principles.
Lawfulness, Fairness and Transparency
Customers determine the lawful basis for processing personal data and remain responsible for informing employees where required by applicable law.
Purpose Limitation
Information processed through Monitor360 is intended to support workforce productivity, operational management and organisational security.
Data Minimisation
Monitor360 is designed to minimise unnecessary data collection through configurable monitoring features and a privacy-focused approach.
Accuracy
Customers may update and maintain user information stored within the platform.
Storage Limitation
Monitor360 supports data retention and deletion processes to help customers manage how long personal data is retained.
Integrity and Confidentiality
Personal data is protected through appropriate technical and organisational security measures designed to safeguard confidentiality, integrity and availability.
5. Data Subject Rights
The GDPR provides individuals with important rights regarding their personal data.
Depending on the circumstances and applicable law, these rights may include:
- Right of access
- Right to rectification
- Right to erasure
- Right to restrict processing
- Right to data portability
- Right to object to processing
As customers generally act as the Data Controller, requests relating to employee personal data should normally be directed to the relevant employer.
Where Softhealer Technologies Pvt. Ltd. processes personal data on behalf of customers, we assist customers in fulfilling applicable GDPR obligations in accordance with our contractual commitments.
6. Security Measures
Protecting personal data is an important part of GDPR
Our security programme is independently validated through four audited certifications: ISO/IEC 27001:2022 (Cert. 26MEQXN18), ISO 9001:2015 (Cert. 26MEQXG22), SOC 2 Type II (Cert. EU/SOC/00878) and SOC 1 Type II (Cert. EU/SOC/00879).
- Encryption of data in transit (TLS 1.2)
- Encryption of data at rest (AES-256)
- Multi-factor authentication (MFA)
- Audit logging of system access and user activity
- Automatic session timeout
- Role-based access controls
- Configurable monitoring controls
- Secure cloud infrastructure (AWS Asia Pacific — Mumbai)
- Backup and disaster recovery procedures
For additional information regarding our security practices, please refer to our Security page.
7. International Data Transfers
Customer data processed through Monitor360 is hosted in the AWS Asia Pacific (Mumbai) Region (ap-south-1).
Where personal data is transferred across international borders, Softhealer Technologies Pvt. Ltd. implements appropriate safeguards in accordance with applicable data protection laws.
Additional information regarding international data processing is available in our Privacy Policy and Data Processing Agreement.
8. Data Processing Agreement (DPA)
Softhealer Technologies Pvt. Ltd. provides a Data Processing Agreement (DPA) in accordance with GDPR Article 28 for customers who act as controllers of personal data processed through Monitor360.
The DPA outlines our commitments regarding the processing, protection and security of personal data, including data subject rights, international transfers, security incident notification and subprocessor obligations.
For full details, please refer to our Data Processing Agreement (DPA) page. To request a copy, Contact Us.
9. Customer Responsibilities
While Monitor360 provides privacy-focused technology and configurable monitoring controls, customers remain responsible for ensuring that their use of the platform complies with applicable laws.
Customers should:
- Determine an appropriate lawful basis for processing.
- Inform employees about workplace monitoring where required.
- Configure monitoring appropriately.
- Establish appropriate retention periods.
- Respond to data subject requests.
- Comply with applicable employment and privacy legislation.
10. Contact Us
If you have questions regarding GDPR, privacy or data protection, please Contact Us using the contact information available on our website.