Privacy Notice

Last updated: 5 August 2026

Who we are

Timixo is operated by Timixo. For personal data relating to our own customers and website visitors, Timixo acts as the data controller. Where a customer uses Timixo to monitor their own workforce, that customer is the controller of their employees’ data and we act as their processor. Contact us at support@timixo.com.

Data we collect and why

  • Account data — name, work email, password credentials, company name, role. Used to create and secure your account and provide the Service. Basis: performance of a contract.
  • Workforce data — clock-in/out times, timesheets, breaks, tasks, projects, leave and HR records. Used to deliver time tracking and reporting. Basis: contract / our customer’s legitimate interests as employer.
  • Monitoring data — periodic screenshots, activity levels, location where geofencing or live map is enabled, and face images where face-match punching is enabled (biometric data). Used only to verify attendance for the employer who enabled it. Basis: the employer’s legitimate interests and, where required by law, employee consent.
  • Support data — messages, attachments and correspondence you send us. Used to answer your requests. Basis: legitimate interests.
  • Technical data — IP address, device and browser identifiers, log and usage telemetry, error reports. Used for security, fraud prevention, debugging and improving the product. Basis: legitimate interests and legal obligation.
  • Marketing data — email address where you opt in to updates. Basis: consent, withdrawable at any time.

Who we share data with

  • Hosting and infrastructure providers that store and serve the application and its database and file storage.
  • AI processing providers used to generate assistant responses, anomaly insights and face-match comparisons.
  • Paddle.com, our Merchant of Record, for the sale of subscriptions, subscription management, payments, invoicing and tax compliance.
  • Professional advisers such as legal and accounting providers.
  • Authorities, where we are required to disclose by law.

We do not sell personal data.

International transfers

Our providers may process data outside your country, including outside the UK/EEA. Where that happens we rely on appropriate safeguards such as adequacy decisions or Standard Contractual Clauses.

Retention

Account and workforce records are kept for as long as your account is active. Screenshots are retained for the retention window configured by your company (7 to 365 days depending on plan and settings) and are then permanently deleted from both the database and file storage. After account closure we delete or anonymise remaining personal data once it is no longer needed, subject to legal and accounting obligations.

Security

We apply appropriate technical and organisational measures, including encryption in transit, row-level access controls that isolate each company’s data, role-based permissions, and audit logging of sensitive actions.

Your rights

Depending on where you live, you may have the right to access, correct, delete, restrict or port your data, object to processing, and withdraw consent. Contact support@timixo.com and we will respond within one month. If you are an employee of a Timixo customer, please contact your employer first — they control your workforce records. UK/EEA users also have the right to complain to their local supervisory authority.

Cookies

We use essential cookies and local storage to keep you signed in and remember preferences such as theme. These are required for the app to function. We do not use advertising cookies. Any analytics we run is limited to aggregate usage measurement, and you can control cookies through your browser settings.