Privacy Policy
This policy explains what personal data ClockIn handles, why, and what rights you have over it. It covers two very different situations — people who visit this website or contact us, and employee data that we process on behalf of a customer — because the law treats them differently.
Who we are. ClockIn is workforce management software operated by [LEGAL ENTITY NAME], registered in [COUNTRY] under company number [REGISTRATION NUMBER], with a registered address at [REGISTERED ADDRESS]. For any question about this policy or your data, email [email protected].
On this page
- Our two roles: controller and processor
- Data we collect through this website
- Workforce data inside the product
- Self-hosting vs. managed hosting
- Lawful bases
- Who we share data with
- How long we keep data
- How we protect data
- International transfers
- Your rights
- Cookies and tracking
- Children
- Changes to this policy
- Contact and complaints
1. Our two roles: controller and processor
Under the GDPR, the obligations that apply depend on whether an organisation decides why data is processed (a controller) or merely processes it on someone else's instructions (a processor). ClockIn is both, in different contexts:
| Context | Our role | What that means |
|---|---|---|
| You visit clockin.uk, request a demo, or email us | Controller | We decide what to collect and why. This policy governs it directly. |
| Your employer uses ClockIn and your hours, leave or review data are stored in it | Processor | Your employer is the controller. They decide what is collected and for how long; we act on their instructions. |
| Your employer self-hosts ClockIn on their own servers | Neither | We have no access to that data at all. Direct all requests to your employer. |
If you are an employee wanting to access or correct your own attendance, leave or performance records, contact your employer's HR or system administrator — not us. We are not permitted to act on your data without their instruction.
2. Data we collect through this website
We keep this deliberately minimal. On clockin.uk we collect:
- What you send us. If you request a demo or email [email protected] or [email protected], we receive your name, email address, and whatever you choose to write — typically your company and what you're trying to solve.
- Server logs. Our web server and network provider record the IP address, timestamp, requested URL, and browser user-agent of requests, as any web server does. These are used for security and troubleshooting, not to build a profile of you.
We do not run analytics, advertising pixels, session recording, or any third-party tracking on this website. There is no marketing automation behind the contact forms — an email arrives in a human's inbox.
3. Workforce data inside the product
When an organisation uses ClockIn, the product stores the data that organisation chooses to put into it. Depending on which modules they enable, that can include:
- Identity and employment: name, work email, team, role, job position, cost center, employment start date, and — where a customer enables payroll export — payroll identifiers.
- Time and attendance: clock-in and clock-out events, hours per day, time types, and edits to those records.
- Leave and absence: leave requests, balances, approvals, and applicable public holidays.
- Performance: review cycles, feedback, goals and check-ins, where the performance module is enabled.
- Recruitment: candidate names, contact details, applications and interview notes, where the recruitment module is enabled.
- Audit records: who changed what, when, and from which address — a security and compliance requirement, described in section 8.
- Location: only if the customer explicitly enables the optional geofencing module, in which case clock events may record a location. This module is off by default.
The customer decides which of these apply. We do not use workforce data to train models, to market to your employees, or for any purpose of our own.
4. Self-hosting vs. managed hosting
This distinction determines whether we ever touch your data at all.
Self-hosted
ClockIn runs entirely on the customer's own infrastructure. Workforce data never reaches us, and we have no ability to access it. The customer is solely responsible for the security, backup and lawful processing of that deployment.
Managed hosting (we host it for you)
We operate the deployment on the customer's behalf, on infrastructure located in [HOSTING PROVIDER AND REGION]. In this arrangement we are a processor: we access data only as needed to run, support and back up the service, and we act on the customer's documented instructions. Customers on managed hosting should have a Data Processing Agreement with us — email [email protected] if you need one.
5. Lawful bases
| What | Lawful basis (GDPR Art. 6) |
|---|---|
| Replying to your demo request or sales enquiry | Legitimate interests — responding to someone who contacted us; and steps prior to entering a contract. |
| Providing the service to a paying customer | Performance of a contract. |
| Server logs, audit records, abuse prevention | Legitimate interests — securing the service; and legal obligation where retention is required. |
| Cold outreach to business contacts | Legitimate interests — B2B marketing relevant to the recipient's role. You can opt out at any time by replying or emailing [email protected], and we will not contact you again. |
| Workforce data inside the product | Determined by the customer as controller — typically contract and legal obligation (employment and payroll record-keeping). |
6. Who we share data with
We do not sell personal data, and we do not share it for advertising. We use a small number of service providers:
| Provider | Purpose | Data involved |
|---|---|---|
| Cloudflare | Website delivery, network protection, and inbound email routing for our @clockin.uk addresses | IP address, request metadata, email content in transit |
| Resend (using Amazon SES) | Sending transactional and notification email | Recipient email address, message content |
| Google Fonts | Serving the typeface used on this website | Your IP address is visible to Google when the font file is fetched |
| [HOSTING PROVIDER] | Running managed deployments | All product data, for managed-hosting customers only |
We may also disclose data where we are legally required to, or to establish or defend legal claims. If we are ever compelled to hand over customer data, we will tell the affected customer unless the law forbids it.
7. How long we keep data
- Sales and demo enquiries: up to 24 months from our last contact, then deleted.
- Server logs: retained on a short rolling window for security and troubleshooting.
- In-product audit records: retained according to the customer's configured retention period. Audit records are append-only by design and are removed only by that retention job.
- Workforce data on managed hosting: for the life of the customer's account. On termination we delete or return it in line with the Data Processing Agreement.
- Candidate data: the recruitment module includes an anonymisation function so customers can meet their own retention limits.
8. How we protect data
- All traffic to the service is encrypted in transit with TLS.
- Passwords are hashed with bcrypt. They are never stored or logged in readable form.
- Access is controlled by role and power level, so users see only what their role permits.
- Every create, update and delete is written to an audit log recording who did it, when, and from which address. Fields matching known secret patterns, and fields marked as sensitive, are masked before they are written.
- Managed deployments are backed up daily.
- Dependencies are reviewed and security-patched on a regular automated cadence.
No system is perfectly secure. If we become aware of a personal data breach affecting your data, we will notify the relevant supervisory authority within 72 hours where required, and affected individuals or customers without undue delay.
9. International transfers
Some of our providers operate outside the European Economic Area. Where personal data is transferred outside the EEA or the UK, we rely on the European Commission's Standard Contractual Clauses or an adequacy decision. Customers who need all data to remain in a specific jurisdiction should either self-host or ask us about regional hosting before signing.
10. Your rights
If we are the controller of your data — that is, you contacted us or visited this site — you have the right to:
- ask what data we hold about you and get a copy of it;
- have inaccurate data corrected;
- have your data erased;
- restrict or object to how we use it, including objecting to marketing at any time;
- receive your data in a portable, machine-readable format;
- withdraw consent, where we relied on consent, without affecting prior processing.
Email [email protected] and we will respond within one month. We do not charge for this.
If your data is in ClockIn because your employer uses it, these requests must go to your employer, who is the controller. If they ask us to help, we will.
11. Cookies and tracking
This marketing website sets no cookies — no analytics, no advertising, no consent banner needed, because there is nothing to consent to.
The application (after you sign in) stores your authentication token in your
browser's sessionStorage. It is strictly necessary to keep you signed in, it is
cleared when you close the tab or sign out, and it is not used for tracking.
One caveat we would rather state plainly than bury: this site loads its typeface from Google Fonts, which means Google receives your IP address when the font is fetched. We intend to self-host the font to remove that dependency.
12. Children
ClockIn is workplace software sold to businesses and is not directed at children. We do not knowingly collect data from anyone under 16 through this website.
13. Changes to this policy
If we change this policy we will update the date at the top. Where a change materially affects your rights, we will notify customers directly rather than relying on you to re-read the page.
14. Contact and complaints
Privacy questions and data requests: [email protected]
General enquiries: [email protected]
You also have the right to complain to a data protection supervisory authority. If you are in Romania, that is the ANSPDCP (Autoritatea Naţională de Supraveghere a Prelucrării Datelor cu Caracter Personal, dataprotection.ro). In the UK it is the ICO (ico.org.uk). Elsewhere in the EU, your national authority. We would rather you raised it with us first, but you are not obliged to.