Legal

Data processing agreement

Last updated August 2026

What this page covers

  • You are the controller of your workers' data. We are your processor.
  • What we process, why, and the instructions we act on.
  • Security, sub-processors, and what happens if something goes wrong.
  • How long we keep things, and the specific case of IP addresses.

About 8 minutes to read.

Who is who

Under the GDPR you are the data controller for the personal data you put into Formclock: your workers' names, contact details, schedules, hours, pay rates and time records. You decide why it is collected and what happens to it. Formclock is your data processor: we hold and process that data to provide the service, and only on your instructions.

This matters more than it sounds. Your staff's rights (to see their data, to correct it, to have it erased) are exercised against you, not against us. Our job is to make sure you can honour them, and to never do anything with the data that you did not ask for.

This agreement forms part of the Terms of Service. If you need it signed as a standalone document, or need standard contractual clauses for a transfer outside your region, contact us and we will provide one.

What we process, and why

Categories of data subject: your employees, contractors, and anyone you invite into your workspace. Categories of personal data: identity and contact details, employment details (role, location, skills, pay rate), scheduling and attendance records, leave, messages sent inside the product, and, only where you switch them on, clock-in photographs and clock-in coordinates.

Purpose of processing: providing workforce scheduling, time and attendance, and coverage automation. Nothing else. We do not sell customer data, we do not use it to advertise, and we do not train models on it.

Duration: for as long as your workspace is open, plus the retention windows set out below.

Acting on your instructions

We process personal data only on your documented instructions. In practice your instructions are the product itself: the settings you choose, the features you turn on, and the actions you and your team take. Where we would otherwise be required by law to process data differently, we will tell you before doing so unless the law forbids it.

Automated actions taken by the coverage agent are your instructions too. You configure how much autonomy it has, every action it takes is recorded in your audit trail with the reasoning behind it, and every one is reversible.

IP addresses, specifically

An IP address is personal data when it can be linked to an individual, and in an activity record it sits directly beside a named person. So it is one of the few things we ask you to decide about explicitly, in Settings → General.

By default we record no IP address at all on activity records. You can choose instead to record only the network portion (203.0.113.0, enough to tell one office from another but not enough to identify a household), or the full address if your own compliance regime requires it. That choice governs what is written to the database, not merely what is shown on screen: if you have not asked us to store an address, we do not store one.

The exception is sign-in activity: successful sign-ins, sign-outs, and above all refused sign-in attempts. Those keep the full address regardless of the setting, because "someone tried to get into your workspace" is only useful if it says from where. That exception is bounded: every IP address in the activity log, of either kind, is permanently erased after 90 days. The record of the event remains; the location does not.

How long we keep things

Clock-in photographs are deleted after 90 days. The punch record survives; the picture does not.

Exact clock-in coordinates are erased after 90 days. We keep only whether the punch was inside the geofence you configured. The yes or no, not the place.

IP addresses on activity records are erased after 90 days, as above.

If you close your workspace it enters a 60-day recovery window during which one click restores it. After that window we permanently delete the organisation and its personal data. Cancelling a subscription does not start this clock; it only moves you to the free plan.

Scheduling, attendance and pay records are kept while your workspace is open, because they are your employment records and you may have your own statutory obligation to retain them. Deleting them is your decision to make, not ours to make for you.

Security

Data is encrypted in transit and at rest. Access is scoped to your workspace at two independent layers. Every query is filtered by your organisation, and the database itself enforces row-level isolation, so a mistake in one layer does not become a data leak.

Access is role-based: what someone can see is determined by the role you assign them, and privileged actions are recorded in your audit trail. Sign-in is passwordless, so there is no password of yours for us to lose.

Staff access to production data is limited to what is needed to operate and support the service.

Sub-processors

We use a small number of sub-processors to run the service: hosting, email delivery, payments and error monitoring. The current list, with what each one does and where it operates, is published at /legal/subprocessors.

We remain responsible to you for their performance. We will give you notice before adding a new sub-processor, so you have a reasonable opportunity to object.

Helping you meet your obligations

If one of your workers asks to see, correct, export or delete their data, we will help you answer. Most of it you can do yourself from inside the product; where you cannot, contact us.

If we become aware of a personal data breach affecting your workspace, we will notify you without undue delay and give you what you need to make your own notification: what happened, what data was involved, and what we did about it.

We will make available the information you reasonably need to demonstrate compliance with Article 28, and will cooperate with audits within reason.

Return and deletion

You can export your data from the product at any time while your workspace is open. Do this before you close it.

On closure we delete your data at the end of the 60-day recovery window, other than anything we are legally required to retain (for example, billing records kept for tax purposes).

Contact

Questions about this agreement, a data subject request you need help with, or a signed copy: privacy@formclock.com.

Formclock is operated by Azeez Ade as an independent software provider, based in Ilfov, Romania.

© 2026 Formclock. All rights reserved.