Privacy policy
What we collect, why we collect it, and what you can do about it. Written to be read, not to be survived.
Last updated: 4 August 2026 · Applies to: taskbithr.com and the TaskBit application
1. Who is responsible for your data
TaskBit is used by employers to manage their workforce. That creates two distinct relationships, and which one applies to you changes who you should contact.
| If you are… | Then your employer is… | And TaskBit Ltd is… |
|---|---|---|
| An employee or worker whose employer uses TaskBit | The controller — they decide what is collected and why | A processor, acting on their instructions |
| A visitor to taskbithr.com, or someone who contacts us | — | The controller for that data |
| An administrator of a customer organisation | — | The controller for your account and billing data |
If you are an employee and want your record corrected or deleted, start with your employer. We will help them action it, and we will act on a request sent directly to us where we are permitted to.
2. What we collect
Data your employer puts into TaskBit about you
- Identity and contact — name, work email, phone number, photograph where uploaded, emergency contact.
- Employment — job title, location, department, reporting line, start date, contracted hours, pay rate.
- Scheduling and attendance — shifts, clock-in and clock-out times, breaks, worked hours, absence and lateness.
- Leave — requests, approvals, balances, accrual and sickness records.
- Pay — payslips, gross and net pay, tax code, National Insurance number and category, student loan plan, pension contributions, and bank details where payroll is run in TaskBit.
- Documents and compliance — contracts, policies, signatures, right-to-work evidence, DBS and background-check status, visas, licences, professional registrations and training certificates, each with its expiry date.
- Communication — messages, announcements and read receipts within the platform.
Data we generate
- Account and security — hashed password, two-factor settings, sessions and devices, login attempts.
- Audit — a record of sensitive actions such as pay runs, permission changes, publishes and exports, including who performed them and when.
- Technical — IP address, device and browser type, and error diagnostics.
Data you give us directly
- Anything you send through a form or email on taskbithr.com — name, work email, company, team size and your message.
- Billing contact and payment details, which are processed by Stripe and not stored on our systems.
We do not sell personal data, and we do not use it to train machine-learning models.
3. Location data — read this one
TaskBit captures location because geofenced clock-in is one of its core functions. It is the most sensitive thing we handle, so we are explicit about the boundaries:
- Location is read at the moment of a clock-in or clock-out, and at no other time.
- What is stored is the coordinates of that punch and the distance from the geofence centre of the location you are clocking into.
- There is no background tracking. The app does not follow you between punches, on a break, or off shift.
- Your employer sees whether a punch was inside their geofence and how far from the centre it was. They do not get a movement history, because none exists.
- If you decline location permission, your employer may require you to use a kiosk or QR clock-in instead. That is their operational decision, not ours.
Whether to enable geofencing at all is your employer's choice as controller. If you object to it, raise it with them first.
4. Why we process it
| Purpose | Lawful basis (where we are controller) |
|---|---|
| Providing the platform to a customer organisation | Performance of a contract with that organisation; for their employees we act on the controller's basis, usually contract or legitimate interests |
| Payroll calculation and payslip production | Legal obligation and contract, as instructed by the employer |
| Right-to-work and compliance record keeping | Legal obligation of the employer |
| Security, fraud prevention and audit logging | Legitimate interests in keeping the service and its data safe |
| Service email — invitations, resets, notifications | Performance of a contract |
| Responding to your sales or support enquiry | Legitimate interests, or steps prior to a contract |
| Marketing email to a business contact | Consent, or legitimate interests where you are an existing customer — with an unsubscribe link in every message |
5. Who we share it with
Only the sub-processors needed to run the service, each under a written contract, each named publicly on our sub-processors page. In summary: hosting and database, transactional email, payment processing, error monitoring, push notification delivery and — if your employer enables it — receipt OCR.
We also disclose data where we are legally required to, and to a successor entity in a merger or acquisition, in which case we will notify affected customers.
6. How long we keep it
| Data | Retention |
|---|---|
| Employee records in a live customer organisation | For as long as the organisation keeps them, under their own retention policy |
| Payroll and payslip records | Retained to meet statutory record-keeping periods, typically six years |
| Attendance and clock-in records, including location | Retained by the employer; deleted with the organisation |
| An entire organisation after cancellation | Held for 30 days so an accidental cancellation can be reversed, then deleted |
| Audit logs | 12 months |
| Website enquiries | 24 months from the last contact |
| Backups | Rolled off on the backup cycle, no more than 35 days behind live |
7. Your rights
Under UK and EU data protection law you can ask for access to your data, correction of it, deletion, restriction of processing, portability, and you can object to processing based on legitimate interests. You can also withdraw consent where consent is the basis.
TaskBit has data-subject export and delete built into the product, so an employer can action a request without it becoming a project. To exercise a right:
- If you are an employee — contact your employer first. They are the controller. We will support them, and act directly where appropriate.
- Otherwise — write to privacy@taskbithr.com. We respond within one month.
If you are not satisfied you can complain to the Information Commissioner's Office (ico.org.uk) or your local supervisory authority.
8. Security
Encryption in transit and at rest, application-layer encryption for particularly sensitive fields such as bank details, per-organisation isolation enforced on every request, two-factor authentication, rate limiting and lockout, session revocation, audit logging, and tested backups. The detail is on our security page.
9. International transfers
Data is hosted in the UK/EU by default. Where a sub-processor processes data outside the UK or EEA, the transfer is covered by an adequacy decision or by standard contractual clauses with supplementary measures. The location of each sub-processor is listed on the sub-processors page.
10. Changes and contact
We will update this page when our processing changes, and material changes are notified to customer administrators by email before they take effect.
Data protection enquiries: privacy@taskbithr.com
General enquiries: hello@taskbithr.com
TaskBit Ltd, registered in England & Wales. Our company number and registered address are provided on request and on every invoice.