Data Policy

The TimoDesk Data Policy explains how we store, keep and delete your organization's time tracking data, and which parts are our job and which parts are yours.

The short version

Who is responsible for what

This is a summary, not the legal terms. In short, you decide what is collected, and we process it for you. That means most of the legal duties are yours, and we want you to know this from the start.

Our role
Processor
We handle your team's data for you, on your instructions, only to run TimoDesk.
Your role
Controller
You decide what is collected and why, so the legal duties that come with monitoring are yours.
Advertising
Never
We never use your team's data for ads, profiling, or resale.
Retention
While active
Kept while your account is active and while the law requires it, then removed.
00

About this policy

This Data Policy explains how TimoDesk ("we," "us," "our") handles, stores, and protects personal data for our customers ("you," "your"). Personal data is any information about a person who can be identified, such as a name, an email address, or a screenshot of their screen.

By using TimoDesk, you agree to this policy. It explains who is responsible for what when your team's data passes through our time tracking and monitoring tools. It works alongside our Terms of Service and Privacy Policy.

01

Roles and responsibilities

Data protection law gives two different roles to the two sides of this arrangement. In plain words: the controller decides what is collected and why, and the processor handles the data for the controller and follows its instructions.

A. You are the controller

Your organization decides who is tracked, which projects they track time on, how often screenshots are taken, and who can see the results. Because you make those choices, you must make sure your use of TimoDesk follows the laws that apply to you, including labor, privacy, and monitoring laws.

B. We are the processor

We handle personal data only to run the Service for you: recording time, activity, screenshots, app and website use, and the reports built on them.

We do not use your team's data for advertising, profiling, or resale.

Why this matters These roles decide who answers when an employee asks about their data, who must get consent where the law requires it, and who is accountable if monitoring is set up in a way the law where they work does not allow. In almost every case, that is you, not us.
02

What we process

Depending on the settings your organization chooses, we may process:

A. Account data
  • Name
  • Email
  • Workspace or company information
  • Role and permissions
  • Phone number
B. Work and activity data

The desktop app records this only while a member's timer is running:

  • Time entries: when work started and ended, and the project and task it was for
  • Activity level: how much of the tracked time had keyboard or mouse input. We count input; we never record which keys were pressed
  • Idle time: stretches with no input, which are not counted as work time
  • Apps used, and how long each one was used
  • Websites visited: the site, page address (URL), page title, and browser, never the page content
  • Screenshots, taken at the interval your organization sets, from every 3 to every 60 minutes

If your organization allows manual time, we also keep each request: the time asked for, the project and task, the reason given, and the reviewer's decision and note.

When the desktop app reports a stretch of time as idle, screenshots from that stretch are thrown away, not saved.

What we never record TimoDesk does not record what you type (keystroke content), passwords, the content of the pages you open, audio, video, or your GPS location.
C. Device and technical data
  • IP address
  • Approximate city and country, worked out from the IP address at sign-in
  • Browser type
  • Device identifiers
  • Operating system
  • App version
  • Login timestamps
03

Why we process it

We use personal data only to:

  • Run TimoDesk for you
  • Build time, activity, and productivity reports
  • Keep accounts secure
  • Give support
  • Improve features and speed
  • Handle billing and account checks
  • Meet our legal and security duties

We do not use this data for marketing unless you agree to it.

04

Storage and security

We use common industry practices to keep data safe:

  • Data is sent over encrypted HTTPS connections
  • Secure cloud hosting
  • Role-based access, so each person sees only what their role allows
  • The desktop app signs each request with a key that belongs to that device
  • A record of each sign-in, with its IP address, browser, and time
  • Strict internal access rules
Where screenshots are stored

By default, we store screenshots in TimoDesk storage. Your organization can instead connect its own Amazon S3 bucket or FTP server in the dashboard settings. New screenshots then go to that storage, and you control it, including how it is secured and how long files stay there.

Your screenshot settings

Your organization controls the screenshot settings for each member. It can turn screenshots on or off, or change how often they are taken, for one member or many at once, at any time in the dashboard.

Only our staff who need it can reach customer data, and only when it is necessary to support or improve the Service.

No system is completely secure. We take reasonable steps to protect data, but we do not guarantee its security and we are not responsible for keeping it safe. As far as the law allows, we are not liable for data leaks, unauthorized access, loss, or any damage that results from a cyberattack or data breach.

05

Access and sharing

A. Your organization

People in your organization see the data their role allows:

  • Organizers and managers see everyone in the organization
  • Team managers see the members of the teams they manage
  • Staff see their own time, activity, and screenshots. A staff member who leads a project also sees the work of everyone on that project

You must tell your employees that monitoring is happening, and get their consent where the law requires it.

B. Your clients

If you invite a client to the client portal at client.timodesk.com, they see only the projects you assign to them, and only the screens you turn on for them. Screenshots, app usage, and website usage stay hidden from a new client until you turn them on. You can also hide member names, so the client sees the tracked time but not who tracked it.

C. Approved service providers

We share data with trusted third parties that help us run TimoDesk:

  • Cloud hosting and file storage
  • Payment processors
  • Email delivery
  • An IP lookup service that turns a sign-in IP address into an approximate location

They use it only on our instructions. Analytics on our public website is covered in our Cookie Policy and does not receive your team's tracking data.

D. Legal requirements

We may share data when the law, a court order, fraud prevention, or someone's safety requires it. We never sell or rent personal information.

06

International transfers

Your data may be stored or processed in other countries, depending on where our servers are hosted. When data moves between countries, we protect it in line with common industry standards. If your organization uses its own Amazon S3 or FTP storage, your screenshots are stored wherever that storage is located.

We cannot guarantee the security of data while it moves between countries or is stored in another country, and we are not responsible for keeping it safe there. Your organization can change each member's screenshot settings, including turning screenshots off, at any time.

07

Retention

We keep personal data only as long as:

  • You have an active TimoDesk account
  • We need it to run the Service
  • We need it for legal, tax, or security reasons

An organization's owner or a manager can remove a member in the dashboard at any time, which ends that member's access and stops their tracking. The owner can also ask us to delete the whole organization. We then delete it, along with every member account in it, and its data is removed under our retention schedule unless a specific law requires us to keep it.

08

Your rights

Depending on where you live, you may have the right to:

  • See the data we hold about you
  • Fix information that is wrong
  • Ask for deletion
  • Get a copy of your personal data
  • Limit or object to some uses of your data
  • Withdraw consent, where consent is what we relied on

We answer data requests within a reasonable time. The organization that collects tracking data controls it, so requests about it are the organization's to answer. If a member writes to us directly about their tracking data, we will refer them to their organization.

If you use TimoDesk through your employer, contact them first. The account is theirs, and they decide what is collected. The organization's owner or a manager can remove you. We act on deletion requests from the owner, who can ask us to delete the organization through our contact page.

09

Sub-processors

A sub-processor is an outside company that handles personal data for us so we can run the Service. We keep a list of approved sub-processors for cloud hosting and file storage, payments, email delivery, and IP lookup. We require each of them to meet strict security and data protection standards. Where the law requires it, we will tell customers about important changes to that list.

Sub-processors run their own systems. We are not responsible if a sub-processor has an outage, or loses or exposes data.

Storage your organization connects itself, such as your own Amazon S3 bucket or FTP server, is not our sub-processor. You choose it and you are responsible for it.

10

Breach notification

If we become aware that someone has reached personal data without permission, we will try to:

  • Tell affected customers within a reasonable time
  • Share the relevant details where we can
  • Take steps to contain and fix it

We cannot guarantee that we will find out about every breach, or that we will be able to tell you about it. Where the law requires it, we will notify affected customers and the relevant authorities.

11

Your responsibilities

You agree to:

  • Use TimoDesk lawfully
  • Tell your employees what is being collected
  • Set up monitoring settings responsibly
  • Get and manage consent where the law requires it
  • Keep access to your TimoDesk account secure
  • Never share your sign-in details or account access with anyone
  • Secure any storage you connect yourself, such as your own Amazon S3 bucket or FTP server
  • Tell us if you find a technical bug or a way around a control
12

Changes to this policy

We may update this Data Policy when needed. If a change is significant, we will tell you by email or in the TimoDesk dashboard. We keep the right to edit, update, add to, or delete any part of this policy at any time.

13

Contact

Please send questions about how we handle data to [email protected].

Doing a vendor review?

Your legal team will want clause 01, and your security team will ask about clauses 04 and 09.

Contact the team
Need help? Book a meeting with the TimoDesk team Book a meeting