Privacy Policy
How we collect, use and protect personal data, in the app and on this website.
Last updated: October 2026
1. Introduction
UniTimesheet ("we", "our" or "us") is committed to protecting your privacy. This policy explains how we collect, use, share and protect information when you use the UniTimesheet timesheet platform and this website.
UniTimesheet is operated by UniTimesheet Ltd, based in the United Kingdom. Our role depends on whose data is involved. For our own records, such as the contact details of people who get in touch and of the people we deal with at customer organisations, we are the data controller. For the data an organisation keeps in UniTimesheet, including its staff, timesheets, absences and signatures, that organisation is the controller and we act as its data processor, on its instructions. Our Data Processing Agreement sets those terms out in full.
We comply with the UK General Data Protection Regulation (UK GDPR) and, where it applies, the EU General Data Protection Regulation (EU GDPR).
2. Information We Collect
Account information
Staff are invited by their organisation. Each account holds a name, an email address, a role, contracted weekly hours and, where the person signs timesheets, an image of their signature. Sign-in is handled by Clerk.
Timesheets and allocations
The projects a person is allocated to, with their percentages and dates; the hours on each timesheet, week by week; the description written for each project; who submitted, approved or rejected each timesheet and when; and any rejection reason.
Absences
The dates of days off, whether a day was a half day, the type of leave and an optional note. Some leave types, such as sick leave and maternity or paternity leave, are special category data under Article 9 of the UK GDPR. Only the person and those who approve their timesheets see the type, signed PDFs carry no absence list, and an organisation can switch off recording leave types altogether.
Project and organisation data
Project acronyms, funders, cost codes and grant numbers, the organisation's logo, and its settings such as the submission deadline and retention periods.
This website
This website collects no personal data. It has no forms, analytics, tracking pixels or cookies, and it loads nothing from other providers. If you email us, we use your message only to reply.
3. How We Use Your Information
- Provide and maintain the service, including working out hours and producing signed timesheet PDFs
- Send the notifications the service relies on, such as reminders, approver summaries, escalations and approval or rejection notices
- Respond to enquiries and support requests
- Keep the service secure and investigate misuse
- Improve the service
We do not use your information for advertising, we do not sell it, and we do not use it to train any machine learning model.
4. Legal Basis for Processing
- Contract: processing needed to provide the service to your organisation
- Legitimate interests: keeping the service secure and improving it
- Legal obligation: complying with the law, including record-keeping duties
For the data an organisation keeps in UniTimesheet, including any special category leave types, the organisation decides the purpose and the legal basis as controller, and we process it only on its instructions.
5. Data Sharing and Sub-processors
We share data only with the providers that run the service, under contract, and only for that purpose. We do not sell personal data. For organisations that need signed terms, our Data Processing Agreement is at /dpa.
| Provider | Purpose | Data processed | Location |
|---|---|---|---|
| Clerk | Sign-in and session management | Name, email address | United States |
| Neon | Database hosting | All application data | London, UK |
| Fly.io | Application server hosting | All application data | London, UK |
| Cloudflare | File storage (R2) for signed timesheet PDFs, signature images and organisation logos; scheduling of nightly jobs; hosting of this website | Signed PDFs, signature images and logos; IP address and request metadata | European Union (file storage); global edge network (website) |
| Resend | Notification emails | Recipient name and email address, and the names of staff listed in approver summaries and escalations. Emails carry no timesheet descriptions, rejection reasons or leave details | United States |
| Vercel | Hosting of the application's web interface | IP address and request metadata | Global edge network |
6. Data Retention
Account data is kept while the account is active. When an organisation deletes a person, their account is closed at once and their personal data is erased after a delay the organisation sets, 90 days by default and never less than 30: their name and email address become placeholders, their signature image is deleted, their timesheet descriptions, rejection reasons and leave notes are cleared, and special category leave types become a generic type. The anonymised rows are kept so the organisation's records stay consistent.
Signed timesheet PDFs and audit logs are kept for the organisation's record retention period, 7 years by default, because funders audit them, and are deleted after that. This applies to an erased person's signed PDFs too, which UK GDPR permits where records must be kept for legal claims or audit (Article 17(3)).
When an organisation leaves, it exports its data first, and everything it held, including stored files and its encryption keys, is permanently deleted 30 days after the organisation is removed. Database backups are kept for at most 7 days for disaster recovery.
7. Data Security
Names, email addresses, timesheet descriptions, rejection reasons, leave types and notes are encrypted at rest with AES-256-GCM, under a key unique to each organisation that is itself wrapped by a master key held in a dedicated secrets manager. Email addresses are looked up through a keyed hash, so they never need decrypting to find an account.
Every organisation's data is separated by Postgres row-level security as well as by the application. Personal data is kept to one table and referred to everywhere else by ID; it is never written to logs, and audit logs record IDs only. Data travels over TLS. For more, see our Security page at /security.
8. Your Rights
Under UK and EU GDPR you have the right to:
- Access: request a copy of your personal data
- Rectification: have inaccurate personal data corrected
- Erasure: have your personal data deleted
- Restriction: restrict how your personal data is processed
- Portability: receive your data in a portable format
- Objection: object to processing based on legitimate interests
Anyone with an account can download their own data at any time from the app (user menu, Download my data). Names are corrected in UniTimesheet and email addresses through sign-in.
For the records your organisation keeps in UniTimesheet, your organisation is the controller, so exercise these rights with it, normally through your grant administrator. If you contact us instead, we will pass your request on, because we may not act on an organisation's data ourselves. For data we hold as controller, contact us at [email protected].
10. International Data Transfers
The database and the application servers are in London and stored files are in the European Union, so the core application data stays in the UK and EU. Some providers are based in the United States: Clerk (sign-in), Resend (email), Vercel (web interface hosting) and Cloudflare (edge network). Where personal data leaves the UK or EEA, we rely on appropriate safeguards, including the UK International Data Transfer Agreement and the EU Standard Contractual Clauses as applicable.
11. Children's Privacy
The service is not intended for anyone under 18, and we do not knowingly collect personal data from children.
12. Changes to This Policy
We may update this policy from time to time. We will post significant changes on this page and update the "Last updated" date.
13. Contact Us
Questions about this policy or our data practices: [email protected].
You also have the right to complain to the Information Commissioner's Office (ICO) at ico.org.uk, or to your local supervisory authority.