Draft — pending counselv0.1Effective Pending
DRAFT — for counsel review. Not legal advice, and not yet in effect.
Observation & Screen-Recording Disclosure
Version 0.1 (draft) · Effective [Effective Date] · [Neivan Legal Entity, Inc.]
This Disclosure explains how the Synapse platform ("Synapse") provided by [Neivan Legal Entity, Inc.] ("Neivan", "we", "us") observes work activity, exactly what is and is not collected, and how that activity is used. It is written for two audiences: the Customer (the organization that licenses Synapse and decides whether to turn observation on) and the Authorized Users (the Customer's admins and employees) who may be observed.
Read together with the Privacy Policy, the Data Processing Addendum (DPA), and the Employee Monitoring Notice (template) that the Customer is expected to deliver to its own staff.
1. Roles: who controls the monitoring
Observation in Synapse is operated by the Customer, using tooling provided by Neivan.
- The Customer is the controller of its employees' personal data. The Customer decides whether to enable observation, for which sources, for which people, and for what business purpose. The Customer is responsible for the lawfulness of monitoring its own staff, including providing any notices and obtaining any consents required by law.
- Neivan is the processor. We provide the software, process observed data on the Customer's documented instructions, and do not decide to monitor any individual on our own initiative.
Neivan does not operate a workforce-surveillance service. Synapse exists to discover repetitive work that can be automated — not to score, rank, or covertly watch individuals.
2. The two kinds of observation
Synapse supports two distinct, separately controlled kinds of observation. A Customer may enable either, both, or neither, and consent is captured per employee, per source.
2.1 Cloud activity observation (metadata only)
This reads activity metadata from tools the Customer has connected (for example, a document workspace, a calendar, or a messaging tool). It records facts such as "a file was edited at a time" or "a message was sent in a channel at a time" — the shape and timing of activity.
It does not read the contents of files, the bodies of messages, or the text of documents. It is metadata only.
Cloud activity observation is opt-in and consent-gated per employee per connected source.
2.2 Desktop screen observation — the "Synapse Recorder"
The Synapse Recorder is a native agent the Customer installs on a specific employee's machine. It is used to understand repetitive work that happens in desktop or legacy applications that have no usable API. It is consent-gated: the employee must grant consent, and that consent is mirrored by an in-app gate (referred to internally as can_capture / canObserve). If consent is not granted, the Recorder does not capture.
3. Exactly what the Synapse Recorder captures — and does not
3.1 What it captures
| Captured | Description |
|---|
| Active window / application title | The title of the app or window currently in focus (e.g. the name of the application and document tab). |
| Accessibility (a11y) control metadata | Metadata about the on-screen control a user interacted with (e.g. that a particular button or field was used), drawn from the operating system's accessibility layer. |
| Redacted screen frames — only at the optional "frames" fidelity | Redacted screenshots / screen frames, captured only when the higher "frames" fidelity is explicitly enabled. Sensitive on-screen labels can be redacted before storage. |
3.2 What it does NOT capture
- No covert capture. The employee is informed and must consent; the in-app gate reflects that consent.
- No content keystroke logging. The Recorder does not log the content a person types. It records that a control was used — not the characters entered into it.
- No reading of message bodies or file contents as a function of the Recorder's design; screen frames are captured only at the optional "frames" fidelity and are subject to redaction.
- No individual productivity scoring. Captured data is used to find automatable steps, not to rate, rank, or discipline a person (see Section 4).
3.3 Redaction
The Recorder supports redaction of sensitive on-screen labels, so that designated sensitive fields can be masked before a frame is stored. Customers should configure redaction before enabling "frames" fidelity in areas where sensitive data may appear on screen.
4. Purpose limitation
Observed and captured data is collected for one purpose: to discover repetitive, automatable work so that it can be turned into agents and workflows.
It is not used to:
- score, rank, or measure the individual productivity of an employee;
- conduct covert surveillance;
- log the content of an individual's keystrokes; or
- make solely automated decisions that produce legal or similarly significant effects about a person.
Neivan will not repurpose observed data beyond what is needed to provide and improve the automation-discovery function described here and in the DPA.
5. Consent model
- Opt-in. Observation is off until enabled. The Recorder captures nothing until the employee grants consent.
- Per-employee, per-source. Consent is captured for each employee and each source separately. Enabling observation for one person or one tool does not enable it for others.
- Revocable. An employee may withdraw consent at any time (see Section 10). Withdrawal stops future capture for that person and source.
- In-app gate. Consent is enforced by an in-app gate (can_capture / canObserve). When the gate is closed, capture does not occur.
The Customer remains responsible for ensuring that, in its jurisdiction and workforce context, consent is a valid and freely given basis — or for relying on another lawful basis where consent is not appropriate (see Section 8).
6. Transparency
Synapse is designed so that an observed employee can see what is being captured about them, including the kind of observation enabled for them and the data it produces. Transparency is a core design property of the Recorder, not an add-on. The Customer should not configure Synapse to defeat this transparency.
7. Retention, deletion, and access
- Configurable retention. The Recorder and the platform support configurable retention of observed data and frames. The Customer sets retention consistent with its purpose and its legal obligations; data is deleted or de-identified at the end of the retention window.
- Deletion. On termination, on a valid deletion request routed through the Customer, or on withdrawal of consent, the corresponding observed data is deleted or de-identified in line with the DPA and the configured retention.
- Who can access. Access to observed data within a Customer tenant is limited to the Customer's authorized admins and to Neivan personnel acting as processor strictly to provide, secure, and support the service. Access is logged.
8. The Customer's responsibilities
Because the Customer controls the monitoring, the Customer must:
- Provide required notices and obtain required consents from its employees before enabling observation, including by delivering the Employee Monitoring Notice (template) or an equivalent.
- Comply with local monitoring and recording law, which varies by jurisdiction. In particular, the Customer should account for:
- EU / UK and other GDPR-grade regimes: identify a valid lawful basis, satisfy necessity and proportionality, and conduct a Data Protection Impact Assessment (DPIA) for systematic monitoring of employees.
- US state employee-monitoring notice laws that require advance written notice of electronic monitoring (for example, New York, Connecticut, and Delaware).
- Two-party (all-party) consent recording states, where capturing certain recordings without the consent of all parties may be unlawful.
- Configure redaction and retention appropriately before enabling higher-fidelity capture.
- Honor employee withdrawals of consent and route data-subject requests appropriately.
Neivan provides the controls to meet these obligations but cannot determine, for the Customer, what its local law requires.
9. AI analysis of observed data
To identify automatable steps, observed and captured data — including, at "frames" fidelity, redacted frames — may be analyzed by a third-party large language model (LLM) via API. Sub-processors may include Anthropic, OpenAI, Google, Perplexity, Mistral, DeepSeek, and xAI, as identified in the DPA's sub-processor list.
This analysis is performed to detect repetitive, automatable patterns. Observed data is not used to train the providers' models. The Customer's selection of provider and the applicable data-handling terms are governed by the DPA.
10. Data-subject rights, withdrawing consent, and raising concerns
- Data-subject rights. Employees may have rights to access, correct, delete, or restrict the processing of their personal data, and to object to monitoring, depending on jurisdiction. Because the Customer is the controller, these requests are directed to the Customer, which may use Synapse's tooling to fulfill them. Neivan assists the Customer as processor.
- Withdrawing consent. An employee may withdraw consent through the in-app gate or by contacting their employer; withdrawal stops future capture for that person and source.
- Raising concerns. Employees should raise concerns about monitoring with their employer ([Customer Name]) in the first instance. Privacy questions directed to Neivan as processor may be sent to [[email protected]], and we will route them appropriately.
This is a draft prepared for review by qualified counsel and the Customer's data-protection function. It is not legal advice and is not yet in effect. Privacy questions to [[email protected]].