Privacy Policy

Last updated: 30 July 2026 · Version 1.0

This policy explains what personal data ClockIn handles, why, and what rights you have over it. It covers two very different situations — people who visit this website or contact us, and employee data that we process on behalf of a customer — because the law treats them differently.

Who we are. ClockIn is workforce management software operated by [LEGAL ENTITY NAME], registered in [COUNTRY] under company number [REGISTRATION NUMBER], with a registered address at [REGISTERED ADDRESS]. For any question about this policy or your data, email [email protected].

1. Our two roles: controller and processor

Under the GDPR, the obligations that apply depend on whether an organisation decides why data is processed (a controller) or merely processes it on someone else's instructions (a processor). ClockIn is both, in different contexts:

ContextOur roleWhat that means
You visit clockin.uk, request a demo, or email us Controller We decide what to collect and why. This policy governs it directly.
Your employer uses ClockIn and your hours, leave or review data are stored in it Processor Your employer is the controller. They decide what is collected and for how long; we act on their instructions.
Your employer self-hosts ClockIn on their own servers Neither We have no access to that data at all. Direct all requests to your employer.

If you are an employee wanting to access or correct your own attendance, leave or performance records, contact your employer's HR or system administrator — not us. We are not permitted to act on your data without their instruction.

2. Data we collect through this website

We keep this deliberately minimal. On clockin.uk we collect:

We do not run analytics, advertising pixels, session recording, or any third-party tracking on this website. There is no marketing automation behind the contact forms — an email arrives in a human's inbox.

3. Workforce data inside the product

When an organisation uses ClockIn, the product stores the data that organisation chooses to put into it. Depending on which modules they enable, that can include:

The customer decides which of these apply. We do not use workforce data to train models, to market to your employees, or for any purpose of our own.

4. Self-hosting vs. managed hosting

This distinction determines whether we ever touch your data at all.

Self-hosted

ClockIn runs entirely on the customer's own infrastructure. Workforce data never reaches us, and we have no ability to access it. The customer is solely responsible for the security, backup and lawful processing of that deployment.

Managed hosting (we host it for you)

We operate the deployment on the customer's behalf, on infrastructure located in [HOSTING PROVIDER AND REGION]. In this arrangement we are a processor: we access data only as needed to run, support and back up the service, and we act on the customer's documented instructions. Customers on managed hosting should have a Data Processing Agreement with us — email [email protected] if you need one.

5. Lawful bases

WhatLawful basis (GDPR Art. 6)
Replying to your demo request or sales enquiryLegitimate interests — responding to someone who contacted us; and steps prior to entering a contract.
Providing the service to a paying customerPerformance of a contract.
Server logs, audit records, abuse preventionLegitimate interests — securing the service; and legal obligation where retention is required.
Cold outreach to business contactsLegitimate interests — B2B marketing relevant to the recipient's role. You can opt out at any time by replying or emailing [email protected], and we will not contact you again.
Workforce data inside the productDetermined by the customer as controller — typically contract and legal obligation (employment and payroll record-keeping).

6. Who we share data with

We do not sell personal data, and we do not share it for advertising. We use a small number of service providers:

ProviderPurposeData involved
CloudflareWebsite delivery, network protection, and inbound email routing for our @clockin.uk addressesIP address, request metadata, email content in transit
Resend (using Amazon SES)Sending transactional and notification emailRecipient email address, message content
Google FontsServing the typeface used on this websiteYour IP address is visible to Google when the font file is fetched
[HOSTING PROVIDER]Running managed deploymentsAll product data, for managed-hosting customers only

We may also disclose data where we are legally required to, or to establish or defend legal claims. If we are ever compelled to hand over customer data, we will tell the affected customer unless the law forbids it.

7. How long we keep data

8. How we protect data

No system is perfectly secure. If we become aware of a personal data breach affecting your data, we will notify the relevant supervisory authority within 72 hours where required, and affected individuals or customers without undue delay.

9. International transfers

Some of our providers operate outside the European Economic Area. Where personal data is transferred outside the EEA or the UK, we rely on the European Commission's Standard Contractual Clauses or an adequacy decision. Customers who need all data to remain in a specific jurisdiction should either self-host or ask us about regional hosting before signing.

10. Your rights

If we are the controller of your data — that is, you contacted us or visited this site — you have the right to:

Email [email protected] and we will respond within one month. We do not charge for this.

If your data is in ClockIn because your employer uses it, these requests must go to your employer, who is the controller. If they ask us to help, we will.

11. Cookies and tracking

This marketing website sets no cookies — no analytics, no advertising, no consent banner needed, because there is nothing to consent to.

The application (after you sign in) stores your authentication token in your browser's sessionStorage. It is strictly necessary to keep you signed in, it is cleared when you close the tab or sign out, and it is not used for tracking.

One caveat we would rather state plainly than bury: this site loads its typeface from Google Fonts, which means Google receives your IP address when the font is fetched. We intend to self-host the font to remove that dependency.

12. Children

ClockIn is workplace software sold to businesses and is not directed at children. We do not knowingly collect data from anyone under 16 through this website.

13. Changes to this policy

If we change this policy we will update the date at the top. Where a change materially affects your rights, we will notify customers directly rather than relying on you to re-read the page.

14. Contact and complaints

Privacy questions and data requests: [email protected]
General enquiries: [email protected]

You also have the right to complain to a data protection supervisory authority. If you are in Romania, that is the ANSPDCP (Autoritatea Naţională de Supraveghere a Prelucrării Datelor cu Caracter Personal, dataprotection.ro). In the UK it is the ICO (ico.org.uk). Elsewhere in the EU, your national authority. We would rather you raised it with us first, but you are not obliged to.