Introduction: The General Data Protection Regulation (GDPR) is a significant legislative change in European data protection laws, becoming enforceable on May 25, 2018. It aims to strengthen the security and protection of personal data in the EU, and acts as a single piece of legislation for all EU countries.
Data Location: The application, customer database and backups are hosted in the UK, on DigitalOcean's London data centre. Transactional emails, such as leave request notifications, are delivered by Mailgun and processed in the European Union. Please refer to the DigitalOcean GDPR FAQs for further information.
Data Usage: We will never sell your data.
Data Protection: We utilize advanced encryption technologies to encrypt all data passing through our TimeOff.Management services during transmission. We use HTTPS to encrypt all data transmitted between you and our services. We also enforce HSTS to ensure that your initial request to our site is also secure. Data can be deleted within the application or the entire account can be deleted.
Data Export: At TimeOff.Management, we believe in putting our users in control of their data. That's why we've built in backup and reporting tools that allow you to export your data in CSV format, and if you need to, permanently erase it.
Responsible Data Handling and Storage: We minimize the amount of data we collect and store, ensuring that every piece of data is backed by a justifiable reason. We have implemented strict policies for data retention, and personal data is deleted as soon as it is no longer necessary.
Automated Infrastructure Monitoring: Our infrastructure is continuously monitored through automated tests, so problems are detected and addressed quickly. This allows us to regularly evaluate and assess the effectiveness of our measures in maintaining our system's resilience and reliability.
Secure User Identification and Authorization: To ensure maximum security, passwords for signing in are hashed and salted using a PBKDF2-based function in accordance with the recommendations of the UK's National Cyber Security Centre. This means that passwords are securely stored and protected from potential breaches.
Payment Handling: All payments are handled by our payment providers — Stripe as standard, with PayPal still supported for longstanding accounts. TimeOff.Management does not store any payment information.
Support: If you have any questions or concerns about security, please do not hesitate to contact our support team. We are always here to help clarify any uncertainties and provide you with peace of mind.
TimeOff.Management application is hosted on DigitalOcean platform
Data is stored in data centre in UK. DigitalOcean conducted an extensive analysis of their operations to ensure compliance with the requirements of the GDPR before it went into effect. Please check their FAQs regarding GDPR here .
Payments are processed by Stripe or PayPal.
Stripe is our standard payment processor. Some longstanding accounts still pay through PayPal, which we continue to support on request. Please check the Stripe privacy policy and the PayPal privacy policy .
Data is transferred using HTTPS.
When data is transferred it is encrypted using HTTPS.
Passwords are encrypted.
Passwords are encrypted (hashed and salted). But please make sure that you create a strong password. It is a good idea to check your password using a password checker tools.
Report security issue.
Please use our contact us form to raise any issue. We will do our best to reply ASAP.
GDPR gives you new protection rights and assures better access to your personal data.
Right to rectification: Rectify your personal information at any time from your account settings. You can also contact us directly to do so.
Right to be forgotten: Cancel your TimeOff.Management subscription and close your account at any time. Once you delete your account, your data is erased from the active service and cannot be reinstated. Deleted data leaves the backup rotation as backups are overwritten, normally within five days, and we may retain basic account, billing and transaction records where tax, accounting, fraud-prevention or legal obligations require it, as described in our Data Processing Addendum .
Right to portability: Data can be exported from application at any time.
Right to object: If you would like to object how your data has been used please get in touch using our contact us forms.
Right of access: You can contact us at any time to access and modify any of your personal data.
Sub-contractors.
Under the GDPR, a sub-processor is any business which may process your data as a side effect of using the TimeOff.Management service.
| Sub-contractor | Purpose |
|---|---|
| DigitalOcean | Cloud hosting |
| Mailgun | Email distribution |
| Anonymised statistical data | |
Formal agreements.
The formal detail behind this page lives in two documents that form part of our Terms and conditions : the Data Processing Addendum , which governs how we process personal data on your behalf, and the Minimum Security Requirements , which describe the security measures we maintain and the responsibilities of each party.