At a glance
The short version — details for each row are below.
| Data | Collected when | Shared with third parties |
|---|---|---|
| Operator code & password | You sign in to AIM365 | Never |
| Time spent per tracked site | A tab on your whitelist is active | Never |
| Client / matter code | Pushed from AIM365 at sign-in | Never |
| Browsing on non-whitelisted sites | Not collected | Never |
01 Scope
This policy applies to the AIM365 Time Capture Chrome extension, published by Executive Data Systems, Inc. for use by its own timekeepers and staff. The extension is an internal billing tool, not a consumer product — installing it links your browser to the Time Capture service your organization already runs.
If anything below conflicts with your organization's own employee privacy notice or IT policy, the internal notice governs.
02 What we collect
The extension reads the address of the active browser tab so it can tell whether that site is on your organization's tracked-site whitelist. It only records and transmits data for sites on that list — everything else is looked at in memory and discarded.
The credentials you enter when signing in to AIM365, pushed into the extension so it can authenticate to the Time Capture service on your behalf. Stored locally only after the service confirms they're valid.
Which tracked site was active and when, logged as discrete open/focus events rather than a running total.
Whatever client/matter is currently selected in AIM365, attached to focus events so time can be billed correctly. Blank if none is selected.
Your whitelist, cached server public key, and sync status live in the browser's local extension storage — not synced to a Google account, not readable by other extensions or sites.
03 How we use it
- Authentication — your operator code and password confirm you're a valid timekeeper before anything else syncs.
- Time capture — site and focus events populate timekeeping records in AIM365, so time you'd otherwise forget to log gets captured automatically.
- Whitelist sync — your organization's admin-defined tracked-site list is fetched periodically so new sites appear without a manual update.
None of this data is used for advertising, analytics resale, or any purpose outside your organization's own billing and timekeeping.
04 How we protect it
Every call from the extension to the Time Capture service is encrypted end-to-end, independent of HTTPS:
- The service's RSA-2048 public key is fetched once and cached.
- Each request generates a fresh AES-256 key, encrypts the payload, and signs it with HMAC-SHA256 (encrypt-then-MAC).
- That AES/HMAC key material is wrapped with the service's RSA public key before anything leaves your browser.
Your operator code and password are never sent as plain headers or query parameters — they travel only inside this encrypted envelope.
06 Retention & your choices
- Uninstall anytime from
chrome://extensions— this removes all locally stored data immediately. - Edit your whitelist from the extension's Options page — remove any site you don't want tracked.
- Server-side data is retained under your organization's own records-retention policy; contact your Time Capture administrator to request access or deletion.
07 Children
Time Capture is a workplace billing tool distributed only to adult employees and contractors of the publishing organization. It is not directed at, and does not knowingly collect data from, children.
08 Changes to this policy
If this policy changes materially, the "Effective" date above will be updated and, where required, your organization will notify you before the change takes effect.
09 Contact
Questions about this policy or a request to access or delete your data can be sent to info@perfectlaw.com.