Privacy Policy
Last updated: 30 September 2026
1. Who we are
TempClock is a time, attendance and workforce platform for temporary labour agencies and multi-site employers. It is operated by TempClock. In this policy "TempClock", "we", "us" and "our" mean that operator. You can contact us about privacy at support@tempclock.com.
2. Our two roles
- •Processor for our customers. When an agency or employer (our customer) uses TempClock, the customer decides what worker data is collected and why. The customer is the controller and we are its processor, under a data processing agreement (DPA). If you are a worker, your agency's privacy notice explains how your data is used, and requests about your data should go to your agency. If you send them to us, we pass them on.
- •Controller for our own business. We are the controller for the details of people who use this website, contact us, subscribe to our newsletter, or are named as contacts on a customer account.
3. Data we collect as a controller
- •Enquiries: the name, email address, company, workforce size and message you send through the contact form or by email.
- •Newsletter: your email address, name and company if given, and a record of your consent. Our newsletter emails record whether they were opened and which links were clicked. You can unsubscribe from any email.
- •Customer account and billing contacts: names, work email addresses and phone numbers of the people who run a customer's account, invoices and subscription records.
- •Support tickets: what you tell us when you raise a support ticket, and who raised it.
- •Technical data: web server logs (IP address, browser, pages requested) kept for security and fault finding.
We use this data to answer you, provide and bill the service, send the newsletter you asked for, and keep the service secure. Our lawful bases are contract (to provide the service), legitimate interests (to answer enquiries, support customers and keep systems secure) and consent (for the newsletter). We do not sell personal data and we do not use advertising cookies.
4. Data we process for customers
Depending on the features a customer uses, its TempClock instance holds:
- •Worker details: name, badge number, contact details, preferred language, job role, home site, pay and charge rates, documents the customer uploads, availability, time off, booked shifts and confirmations.
- •Clock records: times, site, kiosk, clock method, device location where geofencing is on, IP address, breaks, corrections with the reason, client approvals and queries.
- •Face clock-in data (special category data, only for workers who agree): see section 5.
- •Users: names, emails, roles and sign-in records of the customer's staff and its clients' portal users, and the audit log of what they change.
- •Visitors and contractors who sign in at a kiosk, where the customer uses that feature.
- •Messages sent: a log of shift emails and, with the SMS add-on, text messages.
5. Face clock-in
- •It is optional. A worker sees a versioned notice before any camera use. Their consent, decline or withdrawal is recorded. A worker who says no clocks in with their badge and a PIN, or a supervisor clocks them in.
- •Matching: face matching uses Amazon Web Services Rekognition in Ireland (eu-west-1). The worker's face template is held there, in a face collection for the customer's client. At clock-in the kiosk photo is sent for matching and then discarded; we keep the match score and outcome.
- •Liveness: at enrolment, AWS Face Liveness checks that a real person is present. At clock-in the customer can switch on an optional anti-photo check for each site.
- •Photos we store: the enrolment reference photo, and a photo taken when someone clocks in by PIN or, where the customer allows it, from their own phone. They are stored in the customer's instance in the UK, shown only to users with access to that worker or site, and deleted on the retention schedule. A live kiosk camera feed is off by default; if a customer switches it on for a site, frames are kept for 24 hours by default.
- •Deletion: the face template and reference photo are deleted within 4 hours of a worker being made inactive, and at once if the worker withdraws consent or is anonymised.
6. Where data is held
The TempClock application, its database and uploaded files are hosted in a UK data centre. Face matching and enrolment liveness run at Amazon Web Services in Ireland, which the UK treats as adequate. Some optional services are based in the United States (see the table below). Transfers to them are covered by the UK International Data Transfer Agreement, the UK Addendum to the EU Standard Contractual Clauses, or the UK Extension to the EU-US Data Privacy Framework, as set out in each provider's data processing terms.
7. Sub-processors
These are the third parties that may process customer personal data. Customers get at least 30 days' notice before we add or replace one.
| Provider | What for | Location | When used |
|---|---|---|---|
| GoDaddy | Hosting of the application, database, uploaded files and server backups | United Kingdom data centre | Always |
| Amazon Web Services (Rekognition, Face Liveness, Cognito) | Face template creation, face matching at clock-in and the liveness check at enrolment | Ireland (eu-west-1) | When face clock-in is used |
| Twilio | Sending text messages (worker mobile number and message text) | United States | Only when the customer takes the SMS add-on |
| Email delivery provider (the hosting server's mail service, or the email service set for the customer's instance, such as Microsoft 365) | Sending system emails such as enrolment links, notifications and reports | Depends on the provider set for the instance; confirmed in the customer's DPA | Always (email notifications are included) |
| Anthropic | Optional AI features (dashboard brief, report summaries, assistant chat, rota suggestions). No face data, photos or PINs are sent. | United States | Only if the customer switches AI features on (off by default) |
| Stripe | TempClock's own subscription billing. No worker data. | Stripe's processing locations | TempClock billing only |
The service also loads some page resources from content delivery networks (for example a chart library), which see the browser's IP address. No customer personal data is sent to them. The full list, with transfer safeguards, is in our DPA, available on request.
8. How long we keep data
- •Customer data: the customer sets retention periods in its instance. The defaults include 6 years for time and pay records, 24 months before a leaver's personal details are anonymised, 90 days for PIN clock photos and 90 days for face match scores. The retention sweep starts in a report-only mode until the customer switches it on.
- •After a contract ends: we delete the customer's data, including face templates and backups, within 30 days, unless the customer asks for an export first or the law requires us to keep something.
- •Enquiries and newsletter: enquiries for as long as we need to deal with them and any follow-up; newsletter details until you unsubscribe.
- •Backups: nightly encrypted backups roll off after about 2 months (14 daily and 8 weekly copies).
9. Your rights
Under UK GDPR you can ask for access to your data, correction, deletion, restriction, portability, and object to processing. You can withdraw consent for face clock-in at any time and clock in by PIN instead. Workers should contact their agency, which controls their data; TempClock gives agencies the tools to answer these requests. For data we control, email support@tempclock.com.
You can also complain to the Information Commissioner's Office (ico.org.uk).
10. Security
Each customer has its own instance. Traffic is encrypted with HTTPS. Every console offers two-factor sign-in. Access is checked on the server by role and site. Changes are written to an audit log. Backups are encrypted. Two-factor secrets and cloud keys are encrypted by the application; the live database is protected by the hosting provider's controls rather than by application-level encryption. See our Security page for more detail.
11. Cookies
We use strictly necessary cookies to keep you signed in and to protect forms. This website does not use advertising or analytics cookies.
12. Contact
TempClock. Privacy enquiries: support@tempclock.com. You can also use our contact page.