GDPR questions

4 min read By TimeOff Support

The General Data Protection Regulation, usually called GDPR, gives people more control over their personal data.

In TimeOff.Management, this can include employee information such as:

  • name
  • email address
  • department
  • location
  • work schedule
  • leave requests
  • absence records
  • allowance and PTO data
  • comments linked to leave requests

This article explains the main GDPR-related options available in TimeOff.Management.

It is a practical guide for administrators. It is not legal advice.

Where is TimeOff.Management data stored?

TimeOff.Management data is stored in a UK data centre on the DigitalOcean platform.

TimeOff.Management also uses secure transfer methods to protect data while it moves between your browser and the application.

Read more: Data security

What data does TimeOff.Management collect?

TimeOff.Management stores the information needed to manage employee leave.

This may include:

  • employee profile details
  • leave requests
  • approval records
  • leave comments
  • departments
  • locations
  • schedules and rotas
  • allowance records
  • reports
  • company settings

Administrators should only add information that is needed for leave management.

Avoid adding unnecessary personal or sensitive details in comments or custom text fields.

GDPR rights and TimeOff.Management

GDPR gives individuals rights over their personal data.

Common rights include:

GDPR rightWhat it means in TimeOff.Management
Right of accessA person can ask what personal data is held about them
Right to rectificationIncorrect personal data can be corrected
Right to erasureData can be deleted where this applies
Right to portabilityData can be exported
Right to objectA person can raise a concern about how their data is used

Your company should handle employee data requests according to its own GDPR process.

Access employee data

Administrators can review employee information from the Employees section.

This may include:

  • employee details
  • leave history
  • allowance records
  • schedules
  • rotas
  • calendar data
  • comments
  • request status

Read more: Adding, editing, and deleting users

Correct employee data

If employee information is wrong, an administrator can update it.

For example, you may need to correct:

  • name
  • email address
  • department
  • location
  • manager or approver
  • schedule
  • rota
  • allowance details

Open the employee profile, enter Edit Mode, make the required change, and save it.

Read more: Customize settings for individual employees

Export company data

Administrators can download a company backup from General Settings.

This gives your company a copy of its data in CSV format.

Use this when you need a broader company record.

Read more: Back up employees’ leave data

Export data for one employee

You can also download leave data for a single employee from the employee details menu.

This is useful when:

  • an employee asks for their own leave record
  • HR needs an individual absence history
  • payroll needs a specific employee record
  • an employee is leaving the company

Store downloaded files securely.

Only share them with authorised people.

Read more: Back up employees’ leave data

Delete employee data

If an employee leaves, you may normally deactivate the employee account first.

Deactivation removes access but keeps historical leave data.

This is useful when the company still needs records for HR, payroll, reporting, or legal reasons.

Read more: Deactivate an employee account

If data must be permanently removed, check your company process before deleting anything.

Make sure you have saved any records your company is required to keep.

Delete a company account

Administrators can delete a company account when the whole account is no longer needed.

Before deleting the company account:

  • download a company backup
  • save required reports
  • save invoices
  • check with other administrators
  • confirm that the company no longer needs access

Once a company account is deleted, the data cannot be reinstated.

Read more: Delete a company account

Data portability

Data portability means being able to export data in a usable format.

TimeOff.Management supports data export through:

  • company backup
  • reports
  • individual employee leave data downloads

Reports can help you export specific leave, allowance, and absence information.

Read more: Reports

Keep employee comments appropriate

Leave request comments can contain personal information.

Employees and managers should keep comments short and relevant.

Avoid adding unnecessary sensitive details.

For example, instead of writing detailed medical information, a short comment such as “Medical appointment” may be enough, depending on your company policy.

Sub-processors and third-party services

TimeOff.Management uses third-party services to provide the application.

These may include hosting, email delivery, payment processing, and anonymised statistical data.

Payment processing is handled by payment providers, so TimeOff.Management does not need to store card details.

Read more: Data security

If an employee makes a GDPR request

If an employee asks about their data, first check your company process.

You may need to:

  1. Confirm the identity of the requester.
  2. Check what information is held in TimeOff.Management.
  3. Export relevant records.
  4. Correct inaccurate information if needed.
  5. Decide whether data should be deleted or retained.
  6. Keep a record of the request according to your company policy.

Administrators should only share data with authorised people.

If you need help

If you have a question about data held in TimeOff.Management, contact TimeOff Support.

For legal questions about GDPR, speak to your company’s data protection adviser or legal adviser.