EMPLOYEE MONITORING NOTICE
A template for a Beyond Pulse customer to issue to their own staff
Draft prepared for attorney review. Drafted 09/09/2026 against POPIA section 18. Risk rating R2. This is the one document here that is not Beyond's to issue. If you use Beyond Pulse's activity signal, you are the Responsible Party for your own employees, and this notice is yours to give them — under your name, before the agent goes on anybody's machine. Beyond supplies it because a customer should not have to write it from nothing, and because clause 2.5 of the Operator Agreement makes issuing it your obligation. Fill in the four bracketed fields, put it on your letterhead, and give it to people. Then record that you did.
Version 1.0 · Effective 9 September 2026
HOW TO USE THIS
- Replace the four bracketed fields:
[COMPANY],[INFORMATION OFFICER NAME],[INFORMATION OFFICER EMAIL],[RETENTION PERIOD]. - Check that
[RETENTION PERIOD]matches what you have actually set in Beyond Pulse. If the notice says 24 months and the setting says 60, the notice is wrong and the setting wins. - Give it to every person before the agent is installed on their machine. Not afterwards, and not buried in a handbook nobody opens.
- Let them ask questions, and record that it was given — a signed acknowledgement, or a dated register.
- Delete this "How to use this" section before you issue it.
Employee monitoring notice — [COMPANY]
This notice must be given to every person before the activity agent is installed on their machine. It is a POPIA requirement, and separately it is the only version of this that works: monitoring people without telling them what is collected produces resentment and bad data in equal measure.
Read it, ask anything you want to, and keep a copy.
What is collected about you
[COMPANY] uses Beyond Pulse to understand how much time goes into which projects, what that work costs, and whether projects are profitable. Part of that involves a small program — the pulse-agent — running on your work machine.
What the agent sends, every 15 minutes
| The date and your machine's name | e.g. 2026-09-09, DEV-LAPTOP |
| Minutes your machine was in use | e.g. 312 |
| Minutes it was running but idle | e.g. 48 |
| Coarse category totals | e.g. editor 210, browser 62, communication 40 |
That is the complete list. Nothing else leaves your machine.
What the agent never collects
- Window titles, document names and URLs. The agent does not read them. The field exists in the underlying data and is discarded at the boundary — there is no setting that turns it on.
- Screenshots. None, ever. This was ruled out as a product decision, not left as an option.
- Keystrokes. Not recorded in any form.
- Individual application names. Your machine works out that a given program is an "editor" and sends only the category. Beyond Pulse never learns which specific programs you use.
- Anything at all outside working hours beyond the same active and idle minute counts, which is the same data whenever it is generated.
These limits are enforced by automated checks in Beyond Pulse's own build, not by policy alone. The server is built so that it cannot accept a window title, a URL or an application name even if something tried to send one.
Coding time — optional, and yours to switch on
If you choose to, you can connect your own coding-time account, which records how long you spend in an editor, by project and language. This is opt-in. It does nothing until you connect it from your own profile, and you can disconnect it at any time. Nobody else can connect it for you — there is no administrative way to do so.
Where it goes
To [COMPANY]'s own Beyond Pulse workspace. It is not sold, and it is not sent to any third party beyond the operators listed in [COMPANY]'s privacy policy.
How it is used
Beyond Pulse compares three separate things:
- Hours you logged against a task.
- Time you spent in an editor, if you connected coding time.
- Time your machine was in use.
They will never agree, and are not expected to. The comparison exists to catch one specific situation: a full day logged against a client where nothing at all happened on the machine. That is a conversation, and it is always a conversation with you before it is anything else.
What this data is explicitly not used for
- It is not a performance score. There is no ranking, no league table and no percentage that feeds a rating. Reading documentation, testing, thinking about an architecture, sitting in a workshop and talking to a client are all real work, and all of them look like inactivity to a machine.
- It is not used to police hours or breaks. Nobody is asked why they were idle at 11am.
- Low activity on its own is never treated as a problem. The system refuses to assess a day shorter than two hours, and a day with no agent data is recorded as no data — never as a zero and never as a bad mark.
If your agent is broken, uninstalled, or was never set up, that shows as an instrumentation gap on the company's side, not as a mark against you.
Your rights
Under POPIA you may:
- See everything held about you. Sign in and open My day — that is the same data your manager sees, not a filtered version. You can also open the agent's status file on your own machine (
beyond-pulse-agent-status.json) to see exactly what was last sent. - Ask for a correction if something is wrong.
- Ask why a particular figure is being used in a decision that affects you.
- Object to the processing. Speak to the Information Officer named below.
- Complain to the Information Regulator of South Africa if you believe your rights have been infringed — JD House, 27 Stiemens Street, Braamfontein, Johannesburg, 2001; complaints.IR@justice.gov.za; www.inforegulator.org.za.
You can also stop the agent yourself at any time — it is an ordinary service on your own machine. If you do, please say so, so that it is not mistaken for a fault.
The practical details
| Responsible party | [COMPANY] |
| Information Officer | [INFORMATION OFFICER NAME] ([INFORMATION OFFICER EMAIL]) |
| Lawful basis | Legitimate interest — measuring project cost and profitability, and confirming that work billed to clients was performed. Balanced against your privacy by collecting the least data that answers the question. |
| Retention | Activity data is kept for [RETENTION PERIOD] and then deleted automatically. Aggregated project totals are kept for as long as the financial records they support. |
| Sharing | Not sold. Not shared outside [COMPANY] except with the operators named in its privacy policy. |
| Who can see your activity | You, and directors. Project managers see project hours, not individual activity. |
Before you roll this out — a checklist for [COMPANY]
- [ ] The four bracketed fields above are filled in, and
[RETENTION PERIOD]matches the setting in Beyond Pulse. - [ ] The Information Officer is named — and registered with the Information Regulator, as section 55 of POPIA requires before they perform their duties.
- [ ] This notice given to each person, with a chance to ask questions, and the fact recorded.
- [ ] Added to the employment contract addendum or the staff handbook.
- [ ] Your own privacy policy mentions the activity signal and names your operators.
For the attorney reviewing this
- Lawful basis. Drafted on legitimate interest under POPIA section 11(1)(f) rather than employee consent — consent given by an employee to an employer is rarely freely given, and relying on it here would be weaker, not stronger. Please confirm, and confirm the balancing is adequately expressed.
- This is a template for a customer to issue. The four bracketed fields are deliberate; every other Beyond document here has no blanks. Please confirm the instruction block is clear enough that nobody issues it with the brackets still in.
- Section 18 timing. The notice must be given before collection begins. Please confirm the wording obliges that clearly enough to be evidence that it happened.
monitoring-notice · v1.0 · sha256 efe66f041100b215736dce9836948bf4ba74985ffcd7557392dccf2257396b18