Privacy Policy
Last updated: 08 August 2026
This Privacy Policy explains how TimeProf (“TimeProf”, “we”, “us”, “our”) handles personal information when you use the TimeProf website, customer administration portal, staff portal, mobile application, APIs, notifications, communication features, workforce management tools and related services (collectively, the “Service”).
This policy is intended to explain both our web and mobile privacy practices, including the information disclosed in our Apple App Store and Google Play privacy declarations.
1. Who We Are and Our Data Protection Role
TimeProf is a workforce management, rota scheduling, attendance, leave, task, communication and workforce intelligence platform.
Our data protection role depends on the circumstances:
- Customer organisation as Data Controller: where an employer or other customer organisation creates and manages staff accounts, rotas, leave, attendance, tasks, forms, messages or other workforce information, that organisation will normally determine the purposes and means of processing and will normally act as the Data Controller.
- TimeProf as Data Processor: where we process workforce personal data on behalf of a customer organisation, we normally act as its Data Processor and process that information on its documented instructions and under our contractual and data-processing obligations.
- TimeProf as Data Controller: we may act as a Data Controller for information we process for our own purposes, including website enquiries, account administration, service security, fraud prevention, billing administration, service analytics, legal compliance and our direct communications with customers.
Contact Details:
TimeProf
Email: info@timeprof.co.uk
Privacy: privacy@timeprof.co.uk
Website: www.timeprof.co.uk
2. What Personal Data We Collect
The information we process depends on the features enabled by your employer or organisation and how you use the Service.
2.1 Identity, Account and Contact Data
- Full name, username, account ID, user ID and staff ID.
- Email address and phone number.
- Postal address and postcode where supplied or managed in a staff profile.
- Profile photograph or other profile image uploaded by the user or organisation.
- Assigned organisation, site, role and permissions.
2.2 Authentication and Security Data
- Password credentials stored using secure one-way hashing.
- Two-factor authentication settings and related security information.
- Security and recovery information where applicable.
- Login, session, device, security and audit records.
- Biometric authentication such as Face ID or fingerprint may be used through the device operating system. TimeProf does not receive or store your biometric template.
2.3 Employment and Workforce Data
- Employment status, start/end dates and assigned work sites.
- Skills, qualifications, training and role information.
- Rotas, shifts, availability, open-shift claims and shift responses.
- Clock-in, clock-out, attendance, lateness and timekeeping information.
- Tasks, task completion records, forms, form submissions and workflow records.
- Leave and absence requests, approvals, rejections and associated notes.
2.4 Health and Sickness-Related Information
Where sickness or health-related absence features are used, TimeProf may process information indicating that a staff member is sick or absent for health reasons, together with dates, status, notes or other information supplied by the user or organisation.
Health information can constitute special category personal data under UK data protection law. Access to this information should be limited to authorised persons and it is processed only where there is an appropriate legal basis and, where required, an applicable special-category condition.
2.5 Location and Geofencing Data
If your organisation enables location-based clock-in or geofencing, the mobile app may collect and transmit precise location data, including latitude, longitude and location accuracy, when you attempt to clock in or when the Service checks whether you are within an authorised work-site boundary.
Approximate or coarse location may also be inferred from IP address, network information or analytics/security services. TimeProf does not use location information for third-party advertising or cross-app tracking.
2.6 Communications and User-Generated Content
- Private and site/group in-app chat messages.
- Message sender, recipient, timestamps, read status and reactions.
- Announcements, comments and reactions where enabled.
- Leave notes, task notes, form responses and other information entered into free-text fields.
- Notification preferences and notification interaction information.
2.7 Device, Push Notification and Identifier Data
- Device or app-installation identifiers.
- Push-notification registration tokens, including APNs/FCM registration information.
- Device platform, operating-system version, app version and language/locale information.
- Browser type, IP address and technical request/log information.
2.8 Usage, Analytics and Diagnostic Data
- App launches, sessions, screens viewed and product/feature interactions.
- General app usage and technical telemetry.
- Crash reports, stack traces and application state at the time of a crash.
- Device, operating-system, app-version and other diagnostic information.
- Performance and reliability information needed to operate and improve the Service.
2.9 Customer Billing Information
For customer organisations, we may process business billing information, invoice information, payment status and related account details. Payment-card or bank information handled directly by a payment provider is subject to that provider's privacy and security practices and is not normally stored directly by TimeProf.
3. How We Collect Personal Data
- When a customer organisation or administrator creates or manages an account.
- When a staff member enters or updates information in the website or mobile app.
- When users create rotas, shifts, leave requests, tasks, forms, messages or other records.
- When the mobile app uses a device permission such as location, photos or notifications.
- Automatically through authentication, security, logging, analytics and diagnostic technologies.
- From service providers that help us host, secure, operate and support the Service.
4. How We Use Personal Data
- To create, authenticate, secure and manage staff and customer accounts.
- To generate and display rotas and allocate or manage shifts.
- To process open-shift claims, responses and other workforce workflows.
- To manage leave, holiday, sickness, training and availability.
- To record timekeeping, attendance and geofence validation where enabled.
- To deliver tasks, forms, notes, announcements, chat and other communication features.
- To send service, security and workforce-related push notifications and emails.
- To detect abuse, prevent fraud, investigate security events and maintain audit records.
- To diagnose crashes, improve reliability, understand feature usage and improve the Service.
- To administer subscriptions, billing, invoices and customer accounts.
- To comply with contractual, regulatory and legal obligations.
5. Legal Bases for Processing
The lawful basis depends on the processing activity and on whether TimeProf is acting as Controller or Processor.
Where TimeProf acts as a Data Processor, the customer organisation is normally responsible for identifying its lawful basis and any required special-category condition. TimeProf processes that data on the customer's documented instructions and in accordance with the applicable data-processing agreement.
Where TimeProf acts as a Data Controller, our lawful bases may include:
- Contract: where processing is necessary to provide or administer the Service.
- Legitimate Interests: service security, fraud prevention, reliability, analytics, support and product improvement where those interests are not overridden by individual rights.
- Legal Obligation: where processing is necessary to comply with law or regulatory obligations.
- Consent: where consent is appropriate, for example for certain optional communications or device permissions.
Where health or other special-category information is processed, the relevant Controller must also identify an appropriate condition under Article 9 UK GDPR and, where applicable, the Data Protection Act 2018.
6. Mobile App Permissions
Depending on the features you use, the TimeProf mobile app may request access to:
- Location: for clock-in and geofence validation where enabled.
- Photos/Photo Library: when you choose to upload a profile picture or other supported image.
- Notifications: to deliver rota, shift, leave, task, form, chat, announcement, security or other service notifications.
- Face ID/Fingerprint: to allow device-based biometric authentication where enabled. Biometric templates remain controlled by the operating system.
You can change device permissions through your iOS or Android device settings. Some features may not work if a required permission is disabled.
7. Analytics, Crash Reporting and Push Notifications
The TimeProf mobile app uses third-party technologies to help operate, secure and improve the Service. These may include:
- Google Firebase Analytics: to understand app usage, sessions and product interactions.
- Google Firebase Crashlytics: to receive crash reports, stack traces and technical diagnostic information so we can identify and fix faults.
- Firebase Cloud Messaging (FCM): to manage mobile push-notification delivery and app/device registration tokens.
- Apple Push Notification service (APNs): to deliver notifications to Apple devices.
These providers may process technical information such as device identifiers, app-installation identifiers, push tokens, app version, operating-system version, language, approximate location, session/activity information and diagnostic data as necessary to provide their services.
8. Advertising and Tracking
TimeProf does not use personal data collected through the mobile app for third-party advertising, and we do not use mobile-app personal data to track users across apps or websites owned by other companies for advertising purposes.
Where analytics are used, they are used for service operation, reliability, security and product improvement rather than third-party advertising.
9. Sharing Personal Data
We may share or make personal data available only where reasonably necessary for the Service, including with:
- Customer organisations, employers, authorised managers and administrators.
- Cloud hosting, infrastructure, storage and secure-backup providers.
- Email and notification delivery providers.
- Google Firebase services used for analytics, diagnostics and messaging.
- Apple for APNs push-notification delivery to Apple devices.
- Payment providers where customer billing or payment processing is used.
- Professional advisers, auditors, insurers or legal representatives where necessary.
- Police, regulators, courts or other authorities where disclosure is required or permitted by law.
We require service providers that process personal data on our behalf to apply appropriate confidentiality, security and data-protection safeguards.
10. International Transfers
Some service providers may process information outside the United Kingdom. Where personal data is transferred internationally, we use appropriate safeguards required by applicable data-protection law, which may include UK International Data Transfer Agreements, the UK Addendum to Standard Contractual Clauses, adequacy regulations or other lawful transfer mechanisms.
11. How Long We Keep Personal Data
We retain personal data only for as long as reasonably necessary for the purpose for which it was collected, to provide the Service, to meet customer instructions, or to satisfy legal, security, audit and regulatory requirements.
- Account data: normally retained while the relevant account/customer relationship is active and for an appropriate period afterwards.
- Rota, shift, attendance and scheduling records: may be retained for up to 6 years where required for contractual, audit or legal purposes.
- Chat and communication records: normally retained for up to 24 months unless a customer configures or requires a different lawful retention period or the information is required for investigation/audit.
- Audit and security logs: may be retained for up to 6 years where required for compliance, security or evidential purposes.
- Analytics and diagnostic information: retained according to our configuration and the applicable service provider's retention settings.
- Health/sickness information: retained only for the period determined by the relevant Controller's lawful employment, regulatory and record-management requirements.
Customer organisations may have their own retention policies that apply to workforce records for which they are the Data Controller.
12. Data Security
We use appropriate technical and organisational safeguards designed to protect personal data, including encryption in transit, access controls, authentication and multi-factor authentication, tenant isolation, security logging, audit trails, secure backups, monitoring and other security controls.
No online service can guarantee absolute security, but we review and improve our controls as the Service evolves.
13. Your Rights Under UK Data Protection Law
Depending on the circumstances, you may have rights to:
- Request access to your personal data.
- Request correction of inaccurate or incomplete data.
- Request deletion of personal data in certain circumstances.
- Request restriction of processing.
- Object to certain processing.
- Request data portability where applicable.
- Withdraw consent where processing is based on consent.
- Raise a complaint with the Information Commissioner's Office (ICO).
Where your employer or organisation is the Data Controller, you should normally direct a data-rights request to that organisation first. TimeProf will assist our customer organisations with valid data-subject requests where required by law and contract.
For privacy enquiries relating directly to TimeProf, contact: privacy@timeprof.co.uk.
You also have the right to complain to the UK Information Commissioner's Office: ico.org.uk.
14. Account and Data Deletion
Staff accounts are normally created and managed by the employing or customer organisation. If you wish to request deletion of your staff account or workforce personal data, contact your employer or organisation administrator in the first instance.
You may also contact privacy@timeprof.co.uk for assistance. We may need to refer the request to the relevant customer organisation where that organisation is the Data Controller.
Some information cannot be deleted immediately where retention is necessary for legal obligations, employment records, fraud/security prevention, disputes, audit evidence or other lawful purposes.
15. Cookies and Web Technologies
The TimeProf website and web portals may use cookies or similar technologies for:
- Authentication and session management.
- Security and fraud prevention.
- Load balancing, reliability and performance.
- Analytics and traffic insights where enabled.
- Remembering user preferences where appropriate.
Where consent is legally required for non-essential cookies or similar technologies, we will seek that consent through the applicable website controls.
16. Automated Decision-Making and Workforce Intelligence
Depending on the customer configuration, TimeProf may provide workforce intelligence or decision-support features such as fatigue indicators, rota diagnostics, skills matching, suitability checks or other operational recommendations.
These tools are intended to support human decision-making. TimeProf does not intend such features to make solely automated decisions that produce legal or similarly significant effects on staff without appropriate human involvement.
17. Children's Privacy
TimeProf is a workforce-management service and is not designed for children. The Service is not intended for individuals under 16 and we do not knowingly target or collect personal data from children for consumer use.
18. Third-Party Links
The Service may contain links to websites or services operated by third parties. Their privacy practices are governed by their own privacy notices, and we are not responsible for the content or privacy practices of third-party websites that we do not control.
19. Changes to This Privacy Policy
We may update this Privacy Policy from time to time to reflect changes to the Service, mobile applications, third-party providers, legal requirements or our privacy practices. When we make changes, we will update the “Last updated” date shown at the top of this page.
20. Contact Us
If you have questions, concerns or requests about privacy or personal data, contact:
TimeProf Privacy
Email: privacy@timeprof.co.uk
Website: www.timeprof.co.uk