We value your privacy. TimeProf uses cookies and personal data to operate this platform. Please review our Privacy Policy , Cookie Policy and Terms of Service .

Privacy Policy

Last updated: 08 August 2026

This Privacy Policy explains how TimeProf (“TimeProf”, “we”, “us”, “our”) handles personal information when you use the TimeProf website, customer administration portal, staff portal, mobile application, APIs, notifications, communication features, workforce management tools and related services (collectively, the “Service”).

This policy is intended to explain both our web and mobile privacy practices, including the information disclosed in our Apple App Store and Google Play privacy declarations.


1. Who We Are and Our Data Protection Role

TimeProf is a workforce management, rota scheduling, attendance, leave, task, communication and workforce intelligence platform.

Our data protection role depends on the circumstances:

Contact Details:
TimeProf
Email: info@timeprof.co.uk
Privacy: privacy@timeprof.co.uk
Website: www.timeprof.co.uk

2. What Personal Data We Collect

The information we process depends on the features enabled by your employer or organisation and how you use the Service.

2.1 Identity, Account and Contact Data
2.2 Authentication and Security Data
2.3 Employment and Workforce Data
2.4 Health and Sickness-Related Information

Where sickness or health-related absence features are used, TimeProf may process information indicating that a staff member is sick or absent for health reasons, together with dates, status, notes or other information supplied by the user or organisation.

Health information can constitute special category personal data under UK data protection law. Access to this information should be limited to authorised persons and it is processed only where there is an appropriate legal basis and, where required, an applicable special-category condition.

2.5 Location and Geofencing Data

If your organisation enables location-based clock-in or geofencing, the mobile app may collect and transmit precise location data, including latitude, longitude and location accuracy, when you attempt to clock in or when the Service checks whether you are within an authorised work-site boundary.

Approximate or coarse location may also be inferred from IP address, network information or analytics/security services. TimeProf does not use location information for third-party advertising or cross-app tracking.

2.6 Communications and User-Generated Content
2.7 Device, Push Notification and Identifier Data
2.8 Usage, Analytics and Diagnostic Data
2.9 Customer Billing Information

For customer organisations, we may process business billing information, invoice information, payment status and related account details. Payment-card or bank information handled directly by a payment provider is subject to that provider's privacy and security practices and is not normally stored directly by TimeProf.

3. How We Collect Personal Data

4. How We Use Personal Data

5. Legal Bases for Processing

The lawful basis depends on the processing activity and on whether TimeProf is acting as Controller or Processor.

Where TimeProf acts as a Data Processor, the customer organisation is normally responsible for identifying its lawful basis and any required special-category condition. TimeProf processes that data on the customer's documented instructions and in accordance with the applicable data-processing agreement.

Where TimeProf acts as a Data Controller, our lawful bases may include:

Where health or other special-category information is processed, the relevant Controller must also identify an appropriate condition under Article 9 UK GDPR and, where applicable, the Data Protection Act 2018.

6. Mobile App Permissions

Depending on the features you use, the TimeProf mobile app may request access to:

You can change device permissions through your iOS or Android device settings. Some features may not work if a required permission is disabled.

7. Analytics, Crash Reporting and Push Notifications

The TimeProf mobile app uses third-party technologies to help operate, secure and improve the Service. These may include:

These providers may process technical information such as device identifiers, app-installation identifiers, push tokens, app version, operating-system version, language, approximate location, session/activity information and diagnostic data as necessary to provide their services.

8. Advertising and Tracking

TimeProf does not use personal data collected through the mobile app for third-party advertising, and we do not use mobile-app personal data to track users across apps or websites owned by other companies for advertising purposes.

Where analytics are used, they are used for service operation, reliability, security and product improvement rather than third-party advertising.

9. Sharing Personal Data

We may share or make personal data available only where reasonably necessary for the Service, including with:

We require service providers that process personal data on our behalf to apply appropriate confidentiality, security and data-protection safeguards.

10. International Transfers

Some service providers may process information outside the United Kingdom. Where personal data is transferred internationally, we use appropriate safeguards required by applicable data-protection law, which may include UK International Data Transfer Agreements, the UK Addendum to Standard Contractual Clauses, adequacy regulations or other lawful transfer mechanisms.

11. How Long We Keep Personal Data

We retain personal data only for as long as reasonably necessary for the purpose for which it was collected, to provide the Service, to meet customer instructions, or to satisfy legal, security, audit and regulatory requirements.

Customer organisations may have their own retention policies that apply to workforce records for which they are the Data Controller.

12. Data Security

We use appropriate technical and organisational safeguards designed to protect personal data, including encryption in transit, access controls, authentication and multi-factor authentication, tenant isolation, security logging, audit trails, secure backups, monitoring and other security controls.

No online service can guarantee absolute security, but we review and improve our controls as the Service evolves.

13. Your Rights Under UK Data Protection Law

Depending on the circumstances, you may have rights to:

Where your employer or organisation is the Data Controller, you should normally direct a data-rights request to that organisation first. TimeProf will assist our customer organisations with valid data-subject requests where required by law and contract.

For privacy enquiries relating directly to TimeProf, contact: privacy@timeprof.co.uk.

You also have the right to complain to the UK Information Commissioner's Office: ico.org.uk.

14. Account and Data Deletion

Staff accounts are normally created and managed by the employing or customer organisation. If you wish to request deletion of your staff account or workforce personal data, contact your employer or organisation administrator in the first instance.

You may also contact privacy@timeprof.co.uk for assistance. We may need to refer the request to the relevant customer organisation where that organisation is the Data Controller.

Some information cannot be deleted immediately where retention is necessary for legal obligations, employment records, fraud/security prevention, disputes, audit evidence or other lawful purposes.

15. Cookies and Web Technologies

The TimeProf website and web portals may use cookies or similar technologies for:

Where consent is legally required for non-essential cookies or similar technologies, we will seek that consent through the applicable website controls.

16. Automated Decision-Making and Workforce Intelligence

Depending on the customer configuration, TimeProf may provide workforce intelligence or decision-support features such as fatigue indicators, rota diagnostics, skills matching, suitability checks or other operational recommendations.

These tools are intended to support human decision-making. TimeProf does not intend such features to make solely automated decisions that produce legal or similarly significant effects on staff without appropriate human involvement.

17. Children's Privacy

TimeProf is a workforce-management service and is not designed for children. The Service is not intended for individuals under 16 and we do not knowingly target or collect personal data from children for consumer use.

18. Third-Party Links

The Service may contain links to websites or services operated by third parties. Their privacy practices are governed by their own privacy notices, and we are not responsible for the content or privacy practices of third-party websites that we do not control.

19. Changes to This Privacy Policy

We may update this Privacy Policy from time to time to reflect changes to the Service, mobile applications, third-party providers, legal requirements or our privacy practices. When we make changes, we will update the “Last updated” date shown at the top of this page.

20. Contact Us

If you have questions, concerns or requests about privacy or personal data, contact:

TimeProf Privacy
Email: privacy@timeprof.co.uk
Website: www.timeprof.co.uk