Settings & Admin

Data Retention and Worker Privacy

Set how long each kind of personal data is kept, run the nightly sweep in report-only mode first, and use the Worker privacy page for consent, subject access exports and erasure.

Talk to us Browse all guides

Overview

You are the controller; these are your settings.

TempClock keeps each kind of personal data for the period you set, and a nightly job removes what has passed its period. Face data does not wait for that job: it is removed when a worker leaves or withdraws consent.

Retention Schedule

Setup > Data retention.

Data Default What happens after the period
Time and pay records 6 years Clock entries, their photos, adjustments and queries, and rota shifts are deleted.
Leaver personal data 24 months after the last shift The worker is anonymised: name, contact details, PIN, face data, documents and photos removed; hours, pay and badge number kept for payroll.
PIN clock photos 90 days Photo files deleted.
Visitor photos 30 days Photo deleted; the visit record is kept.
Kiosk camera frames 24 hours Frames deleted after the kiosk session ends.
Face match log 90 days Match score rows deleted.
Liveness sessions 30 days Enrolment liveness records deleted.
Enrolment links 30 days after expiry Deleted.
Dashboard notifications 180 days Deleted.
SMS log 365 days Records of texts sent deleted.
API request logs 90 days Deleted.
Audit log 6 years Older rows deleted.

Change a period and click Save schedule. Values outside the allowed range are set to the nearest limit.

The Nightly Sweep

Report-only until you are happy.

Sweep mode starts as Dry run (report only): it counts what it would remove and stores the report, deleting nothing.
Click Dry run (report only) under Run the sweep now to see the report straight away. Recent sweeps lists every run.
When the report looks right, set the mode to Live (delete). To run a live sweep by hand, type RUN and click Run live sweep.
Privacy jobs: last run shows when the sweep and the face clean-up last ran.

Face Data

Not left to the sweep.

A worker made inactive (a leaver): face template, stored face data and enrolment photo removed within 4 hours.
Consent withdrawn, or the worker anonymised or deleted: removed at once.
A dormant (off-season) worker keeps their face data until you make them inactive.

Worker Privacy Page

The consent register.

Open Workforce > Privacy (GDPR), or Privacy on a worker. The register lists workers with their consent status, method and notice version, and whether face data is held, and warns about anyone with face data but no consent on record. On a worker you can:

Record paper consent when the worker signed the paper form.
Withdraw consent: deletes their face template, face data and enrolment photo, and moves them to PIN.
Delete face data without changing their consent record.
See the biometric and image data held: face template, enrolment photo, PIN clock photos and documents.

Subject Access Exports

A worker's data in one ZIP.

Under Subject access export, click Export this worker's data. The ZIP holds the worker record, clock events, documents, photos and PIN clock photos, consent history and audit entries. The download link expires after 7 days, and every export is logged.

Anonymise or Delete

Erasure requests.

Anonymise worker keeps hours, pay and shifts for payroll records and removes the name, email, phone, PIN, face data, photos, documents and export files. It needs an account admin.
Delete permanently removes the worker completely and needs a super admin.
Note

A compliance pack with a data processing agreement, a DPIA template, the retention schedule and worker notices in four languages is available on request.

Know who turned up, and pay every hour right.

Face-verified clock-ins, live geofencing and payroll-ready timesheets in one system. Tell us how your shifts run and we will show you how it fits.

App hosted in the UK · Onboarding led by a pilot site · No app needed to clock in