Insightful is a SOC 2 certified, HIPPA and GDPR compliant organization fully dedicated to protecting data privacy and security.
Data we collect is encrypted during transit and while stored in a secure data center hosted by Google Cloud Platform (GCP).
To learn more about our data privacy and security policies and practices please review this article.
Insightful collects the following data:
Device/User info
Information not related to user activities.
Device name | The name of the device directly from the machine itself |
Device Time zone | The time zone setting of the local device |
Domain info | If a user is Active Directory domain attached, Insightful will collect information like email department and job title. We will also collect the the main AD domain name of the machine that is part of the unique computer name |
IP addresses | The internet protocol address: 1. Within the local network; 2. Used to access the internet; |
Session | The session ID is used by Windows to tell the difference between user sessions |
User name | User name pulled from the device or the operating system |
Hardware ID | The unique hardware ID of a device |
User Activity Info
Individual user activity info (e.g. mouse and keyboard activities).
Date and Time | The exact date and time the user first accessed a specific activity |
Description | A short description of each user activity |
Duration | The amount of time a user spent in an activity |
Apps/Websites | Name of the app / website related to each user activity |
Screenshots | All screenshots are taken for activities as set up by company admins |
Title | Content of the title bar of the window containing each user activity |
URL | The full URL the user accessed for an activity in a browser |
Data Insightful Does Not Collect
We want to ensure that we are clear about data that Insightful does NOT capture:
Keystroke Logging;
Video Camera Monitoring;
Any data that is kept solely on a mobile phone;
Configuration for Additional Privacy
Insightful can be configured to only collect work related activities, to additionally respect employees privacy. This would allow you at the organization level to:
Disable collection of non-work related applications and websites;
Track data data only when employees are on VPN or in the office;
Track data only during work hours or scheduled hours;