GDPR, Privacy & Security
This guide covers TimeKeeper’s approach to GDPR, privacy, and security, and is designed to help you respond to any related queries.
1. How is biometric data (employee photos) and personal data processed?
Photos used for facial recognition are stored in a private, encrypted‑at‑rest Amazon Web Services (AWS) S3 bucket. These images are not publicly accessible. They only become temporarily accessible (via a time‑limited secure link) when viewed by authorised administrators, managers, or employees.
TimeKeeper processes personal data solely to deliver specific features. All such data is opt‑in – if you don’t use a particular feature, we don’t process the related data. For a full list of data types and purposes, please see our Privacy Policy:
https://www.timekeeper.co.uk/privacy/
2. Where is the data stored?
TimeKeeper uses Amazon Web Services as its infrastructure provider. Our compute and storage run in the eu‑west‑1 (Dublin) data centre. For disaster recovery, we maintain replicated failover storage in eu‑central‑1 (Frankfurt).
AWS is an ISO 27001‑certified provider (https://aws.amazon.com/compliance/iso-27001-faqs/) and underpins many leading global web services.
3. Who has access to this data besides you (the customer)?
Access is strictly limited. Our ICO Data Protection Officer, Richard Grey, is the only person within TimeKeeper who has direct access to this data.
4. How secure is TimeKeeper?
TimeKeeper uses multiple security measures to protect data, including:
All data communication is encrypted using modern TLS.
Compute resources run in a private network; SSH access is restricted to our ICO Data Protection Officer.
We operate on a serverless infrastructure with automatic security updates managed by AWS.
SSH access is only available via our internal VPN, which is password‑protected and secured with an additional TOTP (two‑factor) verification.
Nightly backups are taken and retained for 3 months, with the ability to restore to a specific point in time within 24 hours.
Additionally, TimeKeeper undergoes annual penetration testing by an independent professional security firm to identify, test, and remediate potential vulnerabilities.
5. Where can I read more?
Further information is available here:
You can find links to additional resources below:
If you have any further questions, please reach out via live chat or email: [email protected].