GDPR questions
The General Data Protection Regulation, usually called GDPR, gives people more control over their personal data.
In TimeOff.Management, this can include employee information such as:
- name
- email address
- department
- location
- work schedule
- leave requests
- absence records
- allowance and PTO data
- comments linked to leave requests
This article explains the main GDPR-related options available in TimeOff.Management.
It is a practical guide for administrators. It is not legal advice.
Where is TimeOff.Management data stored?
TimeOff.Management data is stored in a UK data centre on the DigitalOcean platform.
TimeOff.Management also uses secure transfer methods to protect data while it moves between your browser and the application.
Read more: Data security
What data does TimeOff.Management collect?
TimeOff.Management stores the information needed to manage employee leave.
This may include:
- employee profile details
- leave requests
- approval records
- leave comments
- departments
- locations
- schedules and rotas
- allowance records
- reports
- company settings
Administrators should only add information that is needed for leave management.
Avoid adding unnecessary personal or sensitive details in comments or custom text fields.
GDPR rights and TimeOff.Management
GDPR gives individuals rights over their personal data.
Common rights include:
| GDPR right | What it means in TimeOff.Management |
|---|---|
| Right of access | A person can ask what personal data is held about them |
| Right to rectification | Incorrect personal data can be corrected |
| Right to erasure | Data can be deleted where this applies |
| Right to portability | Data can be exported |
| Right to object | A person can raise a concern about how their data is used |
Your company should handle employee data requests according to its own GDPR process.
Access employee data
Administrators can review employee information from the Employees section.
This may include:
- employee details
- leave history
- allowance records
- schedules
- rotas
- calendar data
- comments
- request status
Read more: Adding, editing, and deleting users
Correct employee data
If employee information is wrong, an administrator can update it.
For example, you may need to correct:
- name
- email address
- department
- location
- manager or approver
- schedule
- rota
- allowance details
Open the employee profile, enter Edit Mode, make the required change, and save it.
Read more: Customize settings for individual employees
Export company data
Administrators can download a company backup from General Settings.
This gives your company a copy of its data in CSV format.
Use this when you need a broader company record.
Read more: Back up employees’ leave data
Export data for one employee
You can also download leave data for a single employee from the employee details menu.
This is useful when:
- an employee asks for their own leave record
- HR needs an individual absence history
- payroll needs a specific employee record
- an employee is leaving the company
Store downloaded files securely.
Only share them with authorised people.
Read more: Back up employees’ leave data
Delete employee data
If an employee leaves, you may normally deactivate the employee account first.
Deactivation removes access but keeps historical leave data.
This is useful when the company still needs records for HR, payroll, reporting, or legal reasons.
Read more: Deactivate an employee account
If data must be permanently removed, check your company process before deleting anything.
Make sure you have saved any records your company is required to keep.
Delete a company account
Administrators can delete a company account when the whole account is no longer needed.
Before deleting the company account:
- download a company backup
- save required reports
- save invoices
- check with other administrators
- confirm that the company no longer needs access
Once a company account is deleted, the data cannot be reinstated.
Read more: Delete a company account
Data portability
Data portability means being able to export data in a usable format.
TimeOff.Management supports data export through:
- company backup
- reports
- individual employee leave data downloads
Reports can help you export specific leave, allowance, and absence information.
Read more: Reports
Keep employee comments appropriate
Leave request comments can contain personal information.
Employees and managers should keep comments short and relevant.
Avoid adding unnecessary sensitive details.
For example, instead of writing detailed medical information, a short comment such as “Medical appointment” may be enough, depending on your company policy.
Sub-processors and third-party services
TimeOff.Management uses third-party services to provide the application.
These may include hosting, email delivery, payment processing, and anonymised statistical data.
Payment processing is handled by payment providers, so TimeOff.Management does not need to store card details.
Read more: Data security
If an employee makes a GDPR request
If an employee asks about their data, first check your company process.
You may need to:
- Confirm the identity of the requester.
- Check what information is held in TimeOff.Management.
- Export relevant records.
- Correct inaccurate information if needed.
- Decide whether data should be deleted or retained.
- Keep a record of the request according to your company policy.
Administrators should only share data with authorised people.
If you need help
If you have a question about data held in TimeOff.Management, contact TimeOff Support.
For legal questions about GDPR, speak to your company’s data protection adviser or legal adviser.
Related articles
-
Data security Learn where data is stored, how transfer is protected, and how payments and passwords are handled.
-
Back up employees’ leave data Download company data or leave data for one selected employee.
-
Delete a company account Review what to check before permanently removing company data.