GDPR statement.
1Your data stays yours
We will return or delete all personal data at the end of your contract: a full structured export of every module as standard, with a copy of your dedicated database available by written agreement.
2We act only on your instructions
We process personal data only on your documented instructions, unless legally required to act without them, and we will tell you if we believe an instruction infringes data protection law.
3We keep it in the UK
timeware® HRMS is hosted exclusively in UK Microsoft Azure regions. We will not transfer personal data outside the UK except to the EEA under UK adequacy regulations or under an Article 46 UK GDPR transfer mechanism.
4We keep it secure
One dedicated database per customer, encryption at rest and in transit, immutable audit logging, geo-redundant UK backups, SSO and MFA, and certified ISO 27001, ISO 9001 and ISO 14001 management systems with Cyber Essentials Plus.
5Our people are bound to confidentiality
Everyone engaged in processing personal data is under a strict duty of confidentiality, and support staff access a customer tenant only for the work requested.
6Sub-processors need your authorisation
We engage sub-processors only with prior notice and a right to object, under written terms that meet the requirements of your contract. The current list is published in our Data Processing Addendum.
7We help you meet your obligations
We assist with data subject requests, security of processing, personal data breach notification and data protection impact assessments, supported by the platform’s configurable retention and GDPR controls.
8We notify without undue delay
If a personal data breach affects your data, we will notify you without undue delay with the information you need for your own notification obligations.
9We are open to audit
We will provide the information necessary to demonstrate compliance and will allow for and contribute to audits and inspections under Article 28 UK GDPR.
10Nothing is deleted silently
The platform never deletes personal data automatically. Retention rules are set by you, deletions are made by your data controller, and every deletion is audited.