Clocknet
Features How it works Pricing Use cases
Log in Get started free
Clocknet
grid_viewFeatures timelineHow it works sellPricing apartmentUse cases
EN FR AR
Log in Get started free

Legal

GDPR & Data Processing

How Clocknet supports GDPR compliance, including the data processing agreement. Draft pending legal review.

Last updated: 5 October 2026

tocOn this pageexpand_more
  1. Controller and processor roles
  2. Data processing agreement
  3. Subprocessors
  4. International transfers
  5. Special category data
  6. Data subject requests
  7. Personal data breaches
  8. End of the contract
  9. Contact

Legal

  • Privacy Notice
  • Terms of Service
  • GDPR & Data Processing
  • Security
draft

Draft: pending legal review

This is a first draft. A lawyer has not reviewed it yet and it is not a binding agreement. Text marked TO CONFIRM is still being checked.

Controller and processor roles

link

Under the GDPR, the customer (the employer that runs a Clocknet workspace) is the controller for the personal data in its workspace. [TO CONFIRM: legal entity name and registered address], the company that runs Clocknet, is its processor and handles that data only on the customer's documented instructions.

  • Workspace data: members' profiles, time entries, timesheets, locations, face checks, time off, pay and approvals. The customer decides why and how this data is used, and we process it for the customer.
  • Our own data: the sign-up and billing details of the person who creates a workspace, messages sent through this website, and support requests. We are the controller for this data, as the Privacy Notice explains.

If you use Clocknet through your employer, send privacy requests to your employer. If a request reaches us, we pass it on to your employer and help them answer it.

Data processing agreement

link

Our data processing agreement (DPA) sets out the terms required by Article 28 of the GDPR. In summary, the company that runs Clocknet:

  • processes workspace data only on the customer's documented instructions, including for transfers outside the EEA, unless the law requires otherwise
  • makes sure that everyone who can access the data is bound to keep it confidential
  • protects the data with the technical and organisational measures described in the DPA and on our Security page
  • uses sub-processors only as described below, under a contract that gives the same level of protection, and stays responsible for them
  • helps the customer answer requests from the people whose data it holds, and with data protection impact assessments and consultations with a supervisory authority
  • tells the customer about a personal data breach without undue delay, as described below
  • gives the customer the information it needs to show compliance, and allows audits [TO CONFIRM: how audits work, for example a written questionnaire first, an on-site audit at the customer's cost, and how much notice is needed]
  • deletes or returns the data at the end of the contract, as described below

[TO CONFIRM: how customers get and accept the DPA: a signed PDF, a click-through agreement, or acceptance recorded in the app. Until this is settled, a customer can ask us for the DPA.]

Subprocessors

link

These are the service providers that may process workspace data for us. Each one works under a contract that requires it to protect the data. [TO CONFIRM: that a data processing agreement is in place with each provider.]

Provider What it does Personal data Location Transfer safeguard
Server host [TO CONFIRM: provider, for example Hetzner, DigitalOcean or Vultr] Runs the Clocknet web app, API and database All workspace data [TO CONFIRM: country of the production server] [TO CONFIRM: depends on the country]
Cloudflare Domain names, network protection and HTTPS for this website and the app, and file storage (R2) IP addresses and requests that pass through its network; stored files, including face photos while they are kept. [TO CONFIRM: encrypted database backups are planned in R2 but not set up yet.] [TO CONFIRM: R2 storage region; the network runs worldwide] [TO CONFIRM: standard contractual clauses in Cloudflare's DPA]
Amazon Web Services (Rekognition) Face matching for face verification Face photos and face templates of members who agreed to face verification eu-west-1 (Ireland, European Union) [TO CONFIRM: standard contractual clauses if a region outside the EEA is used]
Sentry Error and crash reports from the website, the web app and the mobile app Technical details of errors, set up so that names, email addresses and IP addresses are not attached [TO CONFIRM: region of the Sentry account, United States or EU] [TO CONFIRM: standard contractual clauses or the EU-US Data Privacy Framework]
Expo Sends push notifications to the mobile app Push tokens and the text of notifications [TO CONFIRM: United States] [TO CONFIRM: standard contractual clauses or the EU-US Data Privacy Framework]
Google (Firebase Cloud Messaging) Delivers push notifications to Android phones, through Expo Push tokens and the text of notifications [TO CONFIRM: United States, and whether Google is listed here or as a sub-processor of Expo] [TO CONFIRM: standard contractual clauses or the EU-US Data Privacy Framework]
Apple (Push Notification service) Delivers push notifications to iPhones, through Expo Push tokens and the text of notifications [TO CONFIRM: United States, and whether Apple is listed here or as a sub-processor of Expo] [TO CONFIRM: standard contractual clauses or the EU-US Data Privacy Framework]
Email provider [TO CONFIRM: not chosen yet, for example Amazon SES, Mailgun, Postmark or Resend] Sends emails from Clocknet, such as invitations, password resets and notifications Name, email address and the content of each email [TO CONFIRM: depends on the provider] [TO CONFIRM: depends on the provider]
Google Maps Platform Map and address search when a new customer sets up its first site during sign-up The addresses typed in and the visitor's IP address [TO CONFIRM: United States] [TO CONFIRM: standard contractual clauses or the EU-US Data Privacy Framework]
OpenStreetMap Foundation (maps and Nominatim address search) Maps and address search in the geofence editor and the live map IP address of the person viewing the map, the map area shown, and the addresses searched [TO CONFIRM: United Kingdom and the countries of its map servers] [TO CONFIRM: UK adequacy decision, and whether these map services count as sub-processors]
CARTO and Esri (map backgrounds) Dark and satellite map backgrounds on the live map IP address of the person viewing the map and the map area shown [TO CONFIRM: countries of their map servers] [TO CONFIRM: whether these map services count as sub-processors]
Anthropic Writes the optional AI summary on the dashboard Workspace totals only, such as hours and counts, without names, email addresses, locations or face data [TO CONFIRM: United States, and whether the feature is switched on in production] [TO CONFIRM: standard contractual clauses or the EU-US Data Privacy Framework]

Stripe handles payments for workspace owners. We are the controller for billing data, so Stripe is our own service provider and is not a sub-processor of workspace data.

Before we add or replace a sub-processor, we will tell customers [TO CONFIRM: how far in advance, for example 30 days, and how, for example by email to workspace owners]. A customer can object to the change [TO CONFIRM: within how many days, and what happens if we cannot resolve the objection, for example the customer may end the contract].

International transfers

link

[TO CONFIRM: the country where Clocknet's servers and file storage are hosted.] AWS Rekognition runs in the eu-west-1 region (Ireland). Some of the sub-processors above are in the United States.

When personal data from the European Economic Area goes to a country without an adequacy decision, we use the European Commission's standard contractual clauses (Decision 2021/914) or another safeguard the GDPR allows, and we assess the risks of each transfer. [TO CONFIRM: the safeguard in place with each sub-processor, and the transfer impact assessment.]

[TO CONFIRM: Morocco. Under Law 09-08, transfers abroad are allowed to countries on the CNDP's list of adequate countries (deliberation 236-2015 names the EU and EEA countries, the United Kingdom, Switzerland and Canada) and otherwise need CNDP authorisation. The United States was on the list through Safe Harbor, which no longer exists, so transfers to US sub-processors need review.]

Special category data

link

Face templates are biometric data, a special category under Article 9 of the GDPR. Face verification is optional and the customer decides whether to turn it on.

  • Before a member sets it up, the app asks for their explicit consent and records which version of the consent text they agreed to, when, and from which IP address.
  • The photo used to set it up is deleted once the face template is made, unless the customer sets a period for keeping photos.
  • By default, a failed face check refuses the clock-in so the member can try again. The customer can choose to accept it and mark it for review instead. A failed or missing check never deletes hours already recorded, and a person reviews it. Clocknet makes no decision about pay on its own.
  • A member who declines or withdraws consent can still clock in. Their entries are marked as not verified by face.
  • When a member withdraws consent, their face template is deleted and their most recent face checks are deleted within 24 hours.

[TO CONFIRM: Morocco. CNDP deliberation 478-2013 requires prior authorisation for biometric processing and lists tracking employees' working time and attendance among the purposes for which biometrics are not allowed. Legal must decide how face verification is offered to workspaces in Morocco, and whether the company that runs Clocknet needs CNDP declarations or authorisations under Law 09-08.]

Location data is not a special category under the GDPR. Location sharing during a shift is off until the member turns it on, and recording stops when they clock out. While the app is open, it records the location at regular intervals. In the background, it records a location only when the member enters or leaves one of the workspace's sites, and does not follow them continuously.

Data subject requests

link

People can ask to see, correct, delete or move their data, or object to how it is used. The customer, as controller, answers these requests, and we help.

Members can do some of this themselves:

  • Download my data, in the app or on their profile page on the web, gives them a copy of their profile, devices, time entries and breaks, face consent and check records, notifications, and the changes they made.
  • Delete account, in the app, erases their account straight away. Without the app, they can follow the steps at /account/delete on this website. Their name, contact details, photo and face data are erased. The customer keeps their work records, linked to their employee code instead of their name.
  • Administrators can export reports and timesheets as CSV, Excel or PDF files.

For other requests, such as erasing a member's work records, the customer can contact us and we will help. [TO CONFIRM: how we handle these requests until an erasure tool for administrators is available.]

The GDPR gives one month to answer a request. We forward requests that reach us to the customer without delay, so it can meet that deadline. [TO CONFIRM: the number of days within which we forward a request and help with it.]

Personal data breaches

link

If we become aware of a personal data breach affecting workspace data, we will tell the customer without undue delay [TO CONFIRM: a fixed deadline, for example within 48 hours of becoming aware of it], so that it can notify its supervisory authority within the 72 hours the GDPR requires.

Our notice will describe what happened, the data and people affected, the likely consequences, and what we are doing about it. We will add information as we learn it.

[TO CONFIRM: the incident response plan behind this commitment, which has not been written yet.]

End of the contract

link

When the contract ends:

  • The customer can export its data for 30 days after an owner closes the workspace. The workspace is read-only during that time.
  • We then delete the workspace data, unless the law requires us to keep it, and email the workspace owners to confirm the deletion.
  • Copies in backups are deleted when those backups expire. [TO CONFIRM: how long backups are kept in production.]
  • Face templates are deleted from AWS Rekognition together with the rest of the workspace data, 30 days after the workspace is closed.

Contact

link

Questions about data processing or the DPA: [TO CONFIRM: privacy contact email, and whether a data protection officer is appointed].

Postal address: [TO CONFIRM: registered address of the company that runs Clocknet].

EU representative: [TO CONFIRM: whether an EU representative is needed under GDPR Article 27, and their contact details].

Clocknet

A simple way for teams to track work time: verified, ready for offline use, and fair to everyone who clocks in.

Coming soon toApp Store Coming soon toGoogle Play

Product

  • Features
  • How it works
  • Pricing
  • Use cases
  • Get started

Company

  • About
  • Trust & security
  • Book a demo
  • Contact

Resources

  • Help center
  • Log in

Legal

  • Privacy
  • Terms
  • GDPR
  • Security
  • Delete your account
© 2026 Clocknet Privacy Terms GDPR
EN FR AR
cookie
Cookies on this site

This site only uses essential cookies. They keep you signed in, protect forms and remember your language. We don't use analytics or advertising cookies.

Cookie details