Skip to content

Timesheets hold more personal data than they look

Names, signatures, sick leave. Passed around as spreadsheets and email attachments, they are a data protection risk every month. UniTimesheet keeps them in one place, built for UK and EU GDPR from the data model up.

A hand-drawn figure standing beside a tall green shield with a keyhole, one hand resting on its rim.

How UniTimesheet protects it

Your data stays yours

Every organisation's data carries its own tenant ID, and the database enforces the separation itself with row-level security, on top of the checks in application code.

Encrypted at rest, per organisation

Names, email addresses, timesheet descriptions, leave types and notes are encrypted with AES-256-GCM under a key unique to your organisation.

Personal data in one place

Names and emails live only in the users table. Everything else refers to people by ID, and audit logs never record names, emails or free text.

No passwords stored

Sign-in, passwords and sessions are handled by a dedicated identity provider. UniTimesheet never sees or stores a password.

Special-category data kept back

Sick and parental leave are Article 9 data. Only the person and those who approve their timesheets see the type, PDFs carry no absence list, and you can switch off recording leave types entirely.

Emails carry no content

Notification emails link into the app. They never include descriptions, rejection reasons or leave details.

Retention, erasure and access

  • Anyone can download their own data from the app at any time.
  • Erasing a person anonymises them: names and email become placeholders, their signature and descriptions are deleted, and records keep their integrity.
  • Approved PDFs are kept for your retention period, seven years by default, because funders audit them. Then they are deleted.
  • People who leave are erased automatically after a delay you set, 90 days by default.
  • Every change is recorded in an audit log you can read and export.

Doing due diligence?

We'll answer your security questionnaire and walk your information governance team through how data is stored and processed.