Privacy notice

Last updated: September 2026

This notice explains how [Your legal business name] ("TimeNeatly", "we") handles personal data under the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.

Our role

For your account details (name, email, company name, billing) we are the data controller. For the timesheet data you upload about your staff, your company is the controller and we act as your data processor, handling it only on your instructions to calculate and export hours.

What we collect

Why we use it (lawful basis)

AI processing

Some files and assistant questions are processed by an AI model to read timesheets, flag unusual hours and answer questions. Data is sent only for that task and is not used to train models. No automated decisions with legal effects are made — a person always approves pay periods.

Who we share it with

Only service providers needed to run TimeNeatly: secure cloud hosting, our AI provider and Paddle for payments. We never sell data. Where data leaves the UK, we rely on appropriate safeguards such as UK adequacy regulations or the International Data Transfer Agreement.

Security

Data is encrypted in transit and at rest, and each company can only ever see its own records.

How long we keep it

We keep your data while your account is active. You can delete uploads at any time. When you close your account we delete your timesheet data within 30 days, except billing records we must keep for up to 6 years by law.

Your rights

You have the right to access, correct, delete, restrict or object to processing of your data, and to receive it in a portable format. Employees whose hours appear in timesheets should contact their employer first. To exercise a right, email [privacy contact email]. We respond within one month.

You can also complain to the Information Commissioner's Office (ico.org.uk, 0303 123 1113).

Contact

[Your legal business name] — [privacy contact email]