Minimum security requirements

Last updated: 6 August 2026

These Minimum Security Requirements ("MSR") describe the minimum security measures that TimeOff.Management uses to protect Customer Data when providing its leave and absence management service.

This MSR forms part of the TimeOff.Management Terms of Service, Data Processing Addendum, order form or other agreement between TimeOff.Management and the Customer.

In this MSR, "Customer Data" means information that the Customer or its users enter into, or that is generated within, the Customer's TimeOff.Management account, including employee records, leave and absence records, account settings and related content. Customer Data includes the Customer Personal Data processed under the Data Processing Addendum.

1. Parties

This MSR applies between:

  • The Customer, being the organisation that creates or operates a TimeOff.Management account; and
  • TimeOff.Management, the provider of the service.

Together, they are referred to as the "Parties".

2. Purpose

The purpose of this MSR is to:

  • explain the minimum security measures used by TimeOff.Management;
  • protect Customer Data against unauthorised access, loss, alteration or disclosure;
  • define the security responsibilities of each Party; and
  • support compliance with applicable data protection laws.

Security measures will be proportionate to:

  • the type of data being processed;
  • the way the service is used;
  • the risks to individuals;
  • the available technology; and
  • the size and nature of the service.

No security system can remove every possible risk. TimeOff.Management will maintain reasonable safeguards designed to reduce security risks and respond to security incidents.

3. Scope

This MSR applies to:

  • the TimeOff.Management web application;
  • the primary application servers;
  • the primary customer database;
  • service backups;
  • administrative systems used to operate the service;
  • authorised TimeOff.Management personnel; and
  • sub-processors used to host or support the service.

This MSR applies only to systems and data controlled by TimeOff.Management.

It does not apply to:

  • Customer devices;
  • Customer email accounts;
  • Customer networks;
  • third-party services selected by the Customer;
  • files exported from TimeOff.Management;
  • calendar applications connected by the Customer; or
  • user credentials after they have been shared or disclosed by the Customer or its users.

4. Security governance

TimeOff.Management will maintain security practices appropriate to the nature and size of the service.

These practices will include:

  • assigning responsibility for the security of the service;
  • reviewing security risks when material changes are made;
  • maintaining procedures for managing security incidents;
  • limiting access to systems and Customer Data;
  • keeping the application and supporting systems maintained;
  • reviewing reported security concerns; and
  • updating security measures where reasonably necessary.

Security responsibilities may be carried out by TimeOff.Management team members or by approved service providers.

5. Data minimisation

TimeOff.Management will process Customer Data only where it is reasonably required to:

  • provide the service;
  • maintain the service;
  • support the Customer;
  • protect the security of the service;
  • meet legal obligations; or
  • exercise or defend legal rights.

TimeOff.Management will not sell Customer Data or use it for third-party advertising.

The Customer controls which employee records, leave types, notes, comments and other information are entered into the service.

The Customer should not enter information that is not required for leave or absence management.

6. Access control

Access to TimeOff.Management systems and Customer Data will be restricted to authorised people.

TimeOff.Management will:

  • use authenticated accounts for access to administrative systems;
  • restrict administrative access to people who need it;
  • apply access permissions based on job responsibilities;
  • remove or change access when it is no longer required;
  • avoid using shared administrative accounts where individual accounts are reasonably available;
  • review access following significant role changes; and
  • take reasonable steps to prevent unauthorised access.

Administrative access will be used only where required to:

  • operate or maintain the service;
  • investigate technical problems;
  • respond to support requests;
  • address security concerns; or
  • comply with legal obligations.

7. Customer account permissions

TimeOff.Management provides permission controls that allow the Customer to manage access within its account.

Depending on the service configuration, these may include:

  • employee access;
  • manager access;
  • supervisor access;
  • administrator access;
  • department-based access;
  • access to selected leave types;
  • access to reports; and
  • access to sensitive absence information.

The Customer is responsible for:

  • selecting the correct permissions;
  • deciding who should be an administrator or manager;
  • checking access when staff responsibilities change;
  • removing users who no longer require access; and
  • reviewing access to private or sensitive leave records.

8. User authentication

Users must sign in before accessing protected areas of TimeOff.Management.

TimeOff.Management will maintain authentication controls designed to reduce unauthorised access.

Where available under the Customer's plan or configuration, the service may support additional authentication options such as single sign-on.

The Customer and its users are responsible for:

  • using strong and unique passwords;
  • keeping login information private;
  • not sharing user accounts;
  • protecting access to connected email accounts;
  • signing out of shared devices; and
  • reporting suspected account access promptly.

TimeOff.Management may temporarily block or restrict access where it reasonably believes an account presents a security risk.

9. Customer separation

TimeOff.Management is a service used by multiple customers.

The application will use access controls designed to prevent one Customer from accessing another Customer's account or Customer Data.

Customer access is linked to:

  • the Customer account;
  • the authenticated user;
  • the user's assigned role; and
  • the permissions configured within the service.

TimeOff.Management personnel must not access one Customer's data while responding to a different Customer's request.

10. Protection of data in transit

Connections to the TimeOff.Management application will use HTTPS and TLS where supported by the user's browser, device and connected service.

These controls are designed to protect information while it is being transmitted between:

  • the user's browser and TimeOff.Management;
  • TimeOff.Management application components; and
  • approved service providers.

The Customer is responsible for protecting any information after it has been:

  • exported;
  • downloaded;
  • copied;
  • emailed;
  • added to a calendar application; or
  • transferred to another system controlled by the Customer.

11. Hosting and infrastructure

The TimeOff.Management application and primary customer database are hosted using DigitalOcean infrastructure.

The primary hosting location is DigitalOcean's London data centre, including the LON1 region, in the United Kingdom.

TimeOff.Management will take reasonable steps to:

  • restrict access to hosting accounts;
  • securely configure the infrastructure used by the service;
  • apply relevant security updates;
  • monitor significant infrastructure problems;
  • remove services that are no longer required; and
  • protect administrative credentials.

Physical data centre security is managed by the hosting provider.

12. Software maintenance

TimeOff.Management will maintain the software used to provide the service.

This will include, where reasonably appropriate:

  • reviewing security updates;
  • applying relevant operating system and application updates;
  • replacing unsupported software;
  • reviewing important dependency updates;
  • correcting confirmed security defects;
  • removing unnecessary software or services; and
  • prioritising changes according to the risk they present.

The timing of an update may depend on:

  • the seriousness of the issue;
  • whether the service is affected;
  • the availability of a reliable fix;
  • the risk of disruption caused by the update; and
  • any testing needed before release.

13. Application development and changes

TimeOff.Management will take reasonable security precautions when developing or changing the service.

These precautions may include:

  • limiting access to source code;
  • reviewing important changes;
  • testing changes before release;
  • separating development work from the live service where reasonably possible;
  • avoiding the use of live Customer Data for routine development;
  • keeping access credentials outside publicly available source code;
  • reviewing third-party software dependencies; and
  • correcting confirmed security defects.

Changes may be released in stages where this helps reduce risk or disruption.

14. Security reporting

Customers and users may report suspected security issues to TimeOff.Management using the contact details at the end of this MSR.

TimeOff.Management will:

  • review credible reports;
  • assess whether the service or Customer Data is affected;
  • take reasonable steps to contain confirmed issues;
  • correct confirmed security defects where appropriate; and
  • communicate with affected Customers where required.

A report should include enough information to help TimeOff.Management understand and reproduce the issue.

The person making the report must not:

  • access data belonging to another Customer;
  • alter or delete data;
  • interrupt the service;
  • use automated activity that places an unreasonable load on the service;
  • publish confidential information; or
  • use the issue for extortion or unlawful purposes.

15. Logging and monitoring

TimeOff.Management may maintain logs required to:

  • operate the service;
  • investigate errors;
  • investigate suspected misuse;
  • identify security incidents;
  • manage user access;
  • support Customers; and
  • meet legal obligations.

Access to logs will be restricted where they contain Customer Data or security information.

Logs will be kept only for as long as reasonably required for their purpose, subject to operational and legal requirements.

TimeOff.Management does not guarantee that every user action or system event will be recorded.

16. Backups

TimeOff.Management will maintain regular backups to support service recovery.

Backups are normally retained for up to five days.

Older backups are automatically overwritten or deleted as part of the normal backup rotation.

Access to backups will be restricted to authorised people and service providers.

Backups will be used only where reasonably necessary for:

  • disaster recovery;
  • service recovery;
  • investigation of a serious technical problem; or
  • investigation of a security incident.

It may not be possible to remove a single record from an existing backup immediately.

Where data has been removed from the active service, it will normally leave the backup environment when the relevant backup is overwritten.

Backups are intended to support recovery of the service. They are not a substitute for Customer exports or the Customer's own record-retention process.

17. Service recovery and continuity

TimeOff.Management will maintain reasonable arrangements designed to restore the service following a serious technical failure.

These arrangements may include:

  • system backups;
  • database backups;
  • infrastructure recovery procedures;
  • access to hosting support;
  • procedures for investigating failures; and
  • communication with affected Customers.

TimeOff.Management does not guarantee uninterrupted availability unless a separate written service-level agreement states otherwise.

Recovery times may depend on:

  • the nature of the failure;
  • the availability of the hosting provider;
  • the integrity of available backups;
  • third-party services;
  • internet availability; and
  • events outside TimeOff.Management's reasonable control.

18. Security incidents

TimeOff.Management will maintain a process for responding to confirmed security incidents.

The response may include:

  • recording the incident;
  • investigating what happened;
  • restricting affected access;
  • containing the issue;
  • restoring affected services;
  • assessing whether Customer Data was affected;
  • keeping relevant evidence;
  • correcting identified problems; and
  • communicating with affected Customers.

Where a Personal Data Breach affects Customer Personal Data, TimeOff.Management will notify the Customer without undue delay after becoming aware of it.

TimeOff.Management will aim to provide an initial notification within 48 hours of becoming aware of the breach.

Information may be provided in stages as the investigation develops.

The notification may include:

  • the nature of the incident;
  • the information affected;
  • the approximate number of people or records affected;
  • the likely consequences;
  • actions already taken;
  • recommended Customer actions; and
  • contact details for further information.

Notification of an incident does not constitute an admission of fault or liability.

19. Personnel and confidentiality

People authorised to access Customer Data must:

  • access it only where required for their work;
  • keep it confidential;
  • follow TimeOff.Management security procedures;
  • protect passwords and access credentials;
  • report suspected security issues; and
  • stop accessing the data when authorisation ends.

TimeOff.Management will take reasonable steps to ensure that team members understand their security and confidentiality responsibilities.

Access will be removed or changed when a team member leaves or no longer requires the same level of access.

20. Sub-processors and service providers

TimeOff.Management may use service providers where reasonably required to host, maintain or support the service.

The current main sub-processors are:

Service provider Purpose Main processing location
DigitalOcean Cloud infrastructure, servers, database hosting, storage and backups London, United Kingdom
Mailgun Transactional email and service notifications European Union

TimeOff.Management will take reasonable steps to select service providers that can support the security needs of the service.

Service providers that process Customer Personal Data must be bound by data protection and confidentiality obligations substantially the same as those in the Data Processing Addendum.

TimeOff.Management remains responsible for its obligations under the Data Processing Addendum.

21. Data location

The main TimeOff.Management application, database and backups are hosted in the United Kingdom.

TimeOff.Management does not routinely move or store the main Customer Data outside the United Kingdom.

Where a service provider or support function involves processing outside the United Kingdom, TimeOff.Management will use an appropriate legal transfer mechanism where required by applicable data protection law.

22. Data retention and deletion

Customer Data will be retained while the Customer has an active account, subscription or trial, unless a different period is required by law or agreed in writing.

During the service, the Customer may use available controls to:

  • edit records;
  • delete records;
  • remove users; and
  • export reports.

Following account closure or a valid deletion request, TimeOff.Management will delete Customer Data from the active service within a reasonable period, unless retention is required for:

  • legal compliance;
  • tax or accounting records;
  • fraud prevention;
  • service security;
  • dispute resolution; or
  • establishing, exercising or defending legal claims.

Deleted information may remain temporarily within the normal backup rotation and will normally be overwritten within five days.

23. Customer exports

The Customer may export available information using the service's reporting and export features.

Once information has been exported, the Customer is responsible for:

  • storing it securely;
  • controlling access;
  • sending it securely;
  • keeping it only for as long as required;
  • deleting copies that are no longer required; and
  • meeting any legal obligations that apply to the exported information.

TimeOff.Management is not responsible for the security of Customer Data after it has been exported to a system or device outside TimeOff.Management's control.

24. Customer security responsibilities

The Customer must take reasonable steps to protect its TimeOff.Management account.

The Customer is responsible for:

  • providing accurate user information;
  • assigning suitable roles and permissions;
  • limiting administrator access;
  • removing access promptly when a person leaves;
  • reviewing permissions when responsibilities change;
  • protecting passwords and connected email accounts;
  • keeping its own devices and networks secure;
  • controlling exported information;
  • ensuring that users do not share accounts;
  • notifying TimeOff.Management promptly about suspected misuse;
  • maintaining a lawful basis for the information entered into the service; and
  • avoiding unnecessary sensitive information in free-text fields.

The Customer must not:

  • attempt to bypass access controls;
  • access another Customer's data;
  • upload malicious software;
  • interfere with the operation of the service;
  • use automated tools in a way that harms the service;
  • share administrative credentials with unauthorised people; or
  • use the service for unlawful purposes.

25. Customer administrators

A Customer administrator may be able to:

  • add or remove users;
  • assign roles;
  • view employee information;
  • manage leave types;
  • manage absence records;
  • access reports;
  • edit account settings; and
  • make decisions about the Customer's data.

The Customer must select administrators carefully.

TimeOff.Management may treat instructions received through an authorised administrator account as instructions from the Customer.

The Customer should contact TimeOff.Management promptly if an administrator account is compromised or used without permission.

26. Security information and assurance

On reasonable request, TimeOff.Management may provide information needed to help the Customer understand the security of the service.

This may include:

  • this MSR;
  • the Data Processing Addendum;
  • hosting information;
  • backup information;
  • data-location information;
  • sub-processor information;
  • answers to a reasonable security questionnaire; and
  • information about a confirmed incident affecting that Customer.

TimeOff.Management is not required to disclose:

  • another Customer's information;
  • source code;
  • passwords or access credentials;
  • information that could weaken the security of the service;
  • confidential information belonging to a service provider;
  • personal data unrelated to the request; or
  • trade secrets.

TimeOff.Management may charge reasonable costs where a request requires substantial work beyond the normal provision of the service.

27. Legal and regulatory requests

TimeOff.Management may disclose Customer Data where required by law, court order or a valid request from a competent public authority.

Where legally permitted, TimeOff.Management will:

  • check that the request appears valid;
  • limit the disclosure to the information reasonably required; and
  • inform the Customer before disclosure.

TimeOff.Management may preserve information where reasonably required to comply with a legal obligation or protect legal rights.

28. Changes to these requirements

TimeOff.Management may update this MSR to reflect:

  • changes to the service;
  • changes to hosting arrangements;
  • changes to security risks;
  • changes to legal requirements;
  • changes to service providers; or
  • improvements to security practices.

Material changes will be communicated through the website, service, account notification or email.

An update will not materially reduce the overall protection of Customer Data during an active paid subscription unless:

  • the change is required by law;
  • the change is needed to address a security risk;
  • the Customer agrees to the change; or
  • the existing service can no longer reasonably be provided.

29. Relationship with other agreements

This MSR should be read together with:

If there is a conflict:

  • a specifically negotiated written agreement will take priority;
  • the Data Processing Addendum will take priority for personal data processing matters;
  • this MSR will take priority for security requirements; and
  • the Terms of Service will apply to all other matters.

30. Liability

Each Party's liability under this MSR is subject to the exclusions and limitations of liability in the main agreement between the Parties.

Nothing in this MSR limits liability where that limitation is prohibited by law.

31. Duration

This MSR applies from the date the Customer creates an account, starts a trial, accepts an order or otherwise begins using TimeOff.Management.

It continues while TimeOff.Management processes Customer Data on behalf of the Customer.

Requirements relating to confidentiality, incident investigation, legal retention and deletion will continue for as long as they remain relevant.

32. Governing law

This MSR is governed by the same law and jurisdiction as the TimeOff.Management Terms of Service.

Unless another written agreement states otherwise, this MSR is governed by the laws of England and Wales.

The courts of England and Wales will have jurisdiction.

33. Contact details

Questions or security concerns relating to this MSR should be sent to:

TimeOff.Management
Email: info@timeoff.management

For urgent security concerns, the subject line should clearly state:

Urgent security concern – TimeOff.Management

34. Acceptance

This MSR is designed to be accepted electronically as part of the TimeOff.Management Terms of Service, Data Processing Addendum or Customer subscription.