1. Who we are
This policy is issued by the operator of yourwork.place (yourwork.place). For privacy questions, email privacy@yourwork.place or use the book-a-call form on the website.
We have not published a company number or ICO registration number on this page. We will add those details here when they are confirmed.
2. Controller and processor
UK GDPR treats the “controller” as the party that decides why and how personal data is used. We act in two ways:
- Controller — for our own website, accounts, demo requests, sales enquiries, and cookies. That includes your name and email when you create a workplace, book a call, or request a demo.
- Processor — for staff and workplace records the business puts into the product (rotas, clock-ins, Hub posts, e-learning, timesheets, photos and similar). The employer / workplace is the controller for that data. They must have a lawful basis to use it.
If you are a member of staff, your first point of contact for that workplace data is usually your employer. We will help them respond to requests that involve our systems.
3. What we collect
Depending on how you use the service, we may process:
- Identity and contact details — name, email, phone (if you give it), workplace name, user ID.
- Account security — passwords (stored hashed), PINs used for clock-in, join codes.
- Workplace operations — rotas, clock-in and clock-out times, breaks, holiday and sick pay entries, Hub messages, Work Chat, documents you upload, staff directory details, e-learning progress.
- Shift alerts — a device push token if staff allow notifications on the phone app, used only to tell them when a rota is published.
- Photos — if a workplace uses staff photos or a photo on a clock-in terminal.
- Fingerprint confirmation — only where a workplace has that clock-in option enabled. That is biometric data (see below).
- Payroll — hours a workplace sends to Xero, and pay runs or payslips we read back from their Xero account.
- Sales and support — booking form details, notes you send us, and emails.
- Technical — IP address, device/browser data, and cookies as described in the Cookie Policy.
We do not currently run advertising or third-party analytics cookies on the marketing site. We do not buy or sell personal data.
4. Why we use it (lawful bases)
- Contract — to create and run your workplace, sign you in, and provide the features you use.
- Legitimate interests — to keep the service secure, prevent abuse, improve reliability, and reply to enquiries, where those interests are not overridden by your rights.
- Consent — for optional cookies, and for any processing we tell you needs consent (including some biometric clock-in, where used).
- Legal obligation — if we must keep or disclose information for tax, accounting or law enforcement.
When we act as processor, the workplace’s lawful basis (typically employment / contract or legitimate interests as an employer) is a matter for that business.
5. Biometric and photo data
Fingerprint confirmation on a clock-in terminal, where a workplace turns it on, is biometric data. That is special category data under UK GDPR. We do not use it for marketing. The workplace is the controller; they must only enable it where they have a lawful basis (and an Article 9 condition, such as explicit consent or employment law, as their solicitor advises).
We do not offer face recognition as a product feature. Staff photos, if used, are for identification in the workplace tools, not for advertising.
7. How long we keep it
We keep account and workplace data while the workplace is active and for a reasonable period afterwards so we can close the account, resolve disputes, and meet legal duties. Booking enquiries are kept as long as needed to handle the request and any follow-up.
Exact retention for payroll and attendance records may be set by the workplace as controller. If you ask us to delete a workplace, we will delete or anonymise personal data we hold as processor unless we must keep it (for example a legal claim or backup cycle).
8. Your rights
Under UK GDPR you may have the right to access, rectify, erase, restrict or port your data, to object to processing based on legitimate interests, and to withdraw consent where we rely on it. Those rights are not always absolute.
Email privacy@yourwork.place and we will respond. If we are processing the data only as a processor, we will point you to the workplace or handle the request with them.
You can complain to the Information Commissioner’s Office (ICO) at ico.org.uk. We would rather you contact us first so we can try to put it right.
9. Children
yourwork.place is a business product. It is not aimed at children as consumers. A workplace may have young workers on a rota; that employer remains responsible for how those records are used.
10. Changes
We will update this policy as the product and the law change. The date at the top is the current version. Contact privacy@yourwork.place or hello@yourwork.place if you have questions.