timeware® HRMS · Legal

GDPR statement.

How timeware UK Ltd protects personal data in the timeware® HRMS cloud service. These are our standing commitments as a processor under UK GDPR and the Data Protection Act 2018; the contractual detail sits in our Data Processing Addendum.
Revised 28th August 2026 · UK GDPR · Data Protection Act 2018

1Your data stays yours

We will return or delete all personal data at the end of your contract: a full structured export of every module as standard, with a copy of your dedicated database available by written agreement.

2We act only on your instructions

We process personal data only on your documented instructions, unless legally required to act without them, and we will tell you if we believe an instruction infringes data protection law.

3We keep it in the UK

timeware® HRMS is hosted exclusively in UK Microsoft Azure regions. We will not transfer personal data outside the UK except to the EEA under UK adequacy regulations or under an Article 46 UK GDPR transfer mechanism.

4We keep it secure

One dedicated database per customer, encryption at rest and in transit, immutable audit logging, geo-redundant UK backups, SSO and MFA, and certified ISO 27001, ISO 9001 and ISO 14001 management systems with Cyber Essentials Plus.

5Our people are bound to confidentiality

Everyone engaged in processing personal data is under a strict duty of confidentiality, and support staff access a customer tenant only for the work requested.

6Sub-processors need your authorisation

We engage sub-processors only with prior notice and a right to object, under written terms that meet the requirements of your contract. The current list is published in our Data Processing Addendum.

7We help you meet your obligations

We assist with data subject requests, security of processing, personal data breach notification and data protection impact assessments, supported by the platform’s configurable retention and GDPR controls.

8We notify without undue delay

If a personal data breach affects your data, we will notify you without undue delay with the information you need for your own notification obligations.

9We are open to audit

We will provide the information necessary to demonstrate compliance and will allow for and contribute to audits and inspections under Article 28 UK GDPR.

10Nothing is deleted silently

The platform never deletes personal data automatically. Retention rules are set by you, deletions are made by your data controller, and every deletion is audited.

Simon Birchall
Managing Director, timeware UK Ltd
This statement covers the timeware® HRMS cloud service. Customers running timeware® Professional on their own infrastructure act as host of their own data, and the on-premise statement continues to apply.