Data security
TimeOff.Management stores employee leave and absence data for your company.
This may include:
- employee names
- email addresses
- departments
- locations
- leave requests
- approval records
- allowance and PTO information
- schedules and rotas
- comments added to leave requests
This article explains how TimeOff.Management helps protect that data and what administrators can do to keep company information safe.
Where data is hosted
TimeOff.Management is hosted on the DigitalOcean platform.
Company data is stored in a UK data centre.
DigitalOcean conducted an extensive analysis of their operations to ensure compliance with GDPR before it went into effect. See their GDPR FAQs here: https://www.digitalocean.com/legal/gdpr-faq/
Secure data transfer
Data is transferred using HTTPS.
This helps protect information while it moves between your browser and TimeOff.Management.
Always check that you are using the official TimeOff.Management application and a secure browser connection when signing in.
Password protection
Passwords are protected using one-way salted encryption.
This means passwords are not stored as plain text.
Employees and administrators should still use strong passwords.
A good password should be:
- difficult to guess
- different from passwords used on other websites
- kept private
- changed if there is any concern that it has been shared
If an employee forgets their password, they should use the password reset process.
Read more: Reset a forgotten password
Single Sign-On
Some companies use Google or Microsoft Single Sign-On instead of email and password login.
Administrators can choose the login type for each employee.
Only one login method can be active at a time.
Read more: Choose an employee login type and enable SSO
Payment processing
Standard TimeOff.Management subscription payments are handled by Stripe or PayPal.
Payment details are not stored or managed inside TimeOff.Management.
If a customer needs a different payment method, they can contact TimeOff Support to discuss whether an annual subscription payment can be arranged.
Read more: Paying your invoice
Paypal privacy policy.
Stripe privacy policy.
Access control
Administrators control who can access company leave data.
Access can depend on:
- user role
- department
- location
- supervisor permissions
- Team View privacy settings
- employee policies
- report access settings
Only give users the access they need to do their job.
Review access regularly, especially when employees change role, move department, or leave the company.
Read more: Team View leave data privacy options
Employee data visibility
TimeOff.Management includes privacy options for Team View.
Administrators can choose who can see leave information.
For example, Team View can be limited to:
- administrators only
- administrators and supervisors
- department members
- everyone in the company
Administrators can also hide leave type names so employees can see that someone is unavailable without seeing the reason.
Read more: Team View leave data privacy options
Data exports
Administrators can export company data.
This can help with:
- internal records
- payroll checks
- HR records
- GDPR requests
- account closure preparation
- moving data to another system
TimeOff.Management supports company backup and employee-level leave data downloads.
Read more: Back up employees’ leave data
Reports and data handling
Reports can contain employee leave, allowance, comments, approvers, and absence history.
Only give report access to people who need it.
When downloading reports:
- store files securely
- avoid personal devices where possible
- do not share files with unauthorised people
- delete old copies according to your company policy
- avoid adding unnecessary sensitive information to comments
Read more: Reports
Account deletion
Administrators can delete a company account when the company no longer needs TimeOff.Management.
Before deleting an account:
- download a company backup
- save required reports
- save invoices
- check with other administrators
- confirm that the account should be permanently removed
Once a company account is deleted, its data cannot be reinstated.
Read more: Delete a company account
GDPR-related rights
GDPR gives individuals rights over their personal data.
These may include:
- right of access
- right to rectification
- right to erasure
- right to portability
- right to object
TimeOff.Management provides tools that can help administrators respond to GDPR-related employee data requests, including data export, correction, and account deletion options.
Read more: GDPR questions
Sub-processors
Under GDPR, a sub-processor is a third-party service that may process data as part of delivering the TimeOff.Management service.
Sub-processors may support areas such as:
- hosting
- email delivery
- payment processing
- application operations
Administrators should review their own company requirements if they need a formal record of sub-processors.
Report a security issue
If you need to report a security issue, contact TimeOff Support.
Use the contact form and include enough detail for the team to understand the issue.
Do not include passwords, payment details, or unnecessary personal information in your message.
What administrators should do
Administrators help keep data secure by:
- using strong passwords
- enabling SSO where appropriate
- reviewing administrator access
- deactivating employees who leave
- checking Team View privacy settings
- limiting report access
- downloading backups securely
- keeping employee data accurate
- avoiding sensitive details in comments
Read more: Deactivate an employee account
Related articles
-
GDPR questions Learn how TimeOff.Management supports access, correction, export, deletion, and portability requests.
-
Back up employees’ leave data Download company data or leave data for one selected employee.
-
Team View leave data privacy options Control who can see Team View and whether leave type names are visible.
Best practice
Give users the lowest level of access they need.
Review administrators, supervisors, report access, and Team View privacy settings regularly.