Legal

Privacy policy

What we collect, why we collect it, and what you can do about it. Written to be read, not to be survived.

Last updated: 4 August 2026 · Applies to: taskbithr.com and the TaskBit application

1. Who is responsible for your data

TaskBit is used by employers to manage their workforce. That creates two distinct relationships, and which one applies to you changes who you should contact.

If you are…Then your employer is…And TaskBit Ltd is…
An employee or worker whose employer uses TaskBitThe controller — they decide what is collected and whyA processor, acting on their instructions
A visitor to taskbithr.com, or someone who contacts usThe controller for that data
An administrator of a customer organisationThe controller for your account and billing data

If you are an employee and want your record corrected or deleted, start with your employer. We will help them action it, and we will act on a request sent directly to us where we are permitted to.

2. What we collect

Data your employer puts into TaskBit about you

  • Identity and contact — name, work email, phone number, photograph where uploaded, emergency contact.
  • Employment — job title, location, department, reporting line, start date, contracted hours, pay rate.
  • Scheduling and attendance — shifts, clock-in and clock-out times, breaks, worked hours, absence and lateness.
  • Leave — requests, approvals, balances, accrual and sickness records.
  • Pay — payslips, gross and net pay, tax code, National Insurance number and category, student loan plan, pension contributions, and bank details where payroll is run in TaskBit.
  • Documents and compliance — contracts, policies, signatures, right-to-work evidence, DBS and background-check status, visas, licences, professional registrations and training certificates, each with its expiry date.
  • Communication — messages, announcements and read receipts within the platform.

Data we generate

  • Account and security — hashed password, two-factor settings, sessions and devices, login attempts.
  • Audit — a record of sensitive actions such as pay runs, permission changes, publishes and exports, including who performed them and when.
  • Technical — IP address, device and browser type, and error diagnostics.

Data you give us directly

  • Anything you send through a form or email on taskbithr.com — name, work email, company, team size and your message.
  • Billing contact and payment details, which are processed by Stripe and not stored on our systems.

We do not sell personal data, and we do not use it to train machine-learning models.

3. Location data — read this one

TaskBit captures location because geofenced clock-in is one of its core functions. It is the most sensitive thing we handle, so we are explicit about the boundaries:

  • Location is read at the moment of a clock-in or clock-out, and at no other time.
  • What is stored is the coordinates of that punch and the distance from the geofence centre of the location you are clocking into.
  • There is no background tracking. The app does not follow you between punches, on a break, or off shift.
  • Your employer sees whether a punch was inside their geofence and how far from the centre it was. They do not get a movement history, because none exists.
  • If you decline location permission, your employer may require you to use a kiosk or QR clock-in instead. That is their operational decision, not ours.

Whether to enable geofencing at all is your employer's choice as controller. If you object to it, raise it with them first.

4. Why we process it

PurposeLawful basis (where we are controller)
Providing the platform to a customer organisationPerformance of a contract with that organisation; for their employees we act on the controller's basis, usually contract or legitimate interests
Payroll calculation and payslip productionLegal obligation and contract, as instructed by the employer
Right-to-work and compliance record keepingLegal obligation of the employer
Security, fraud prevention and audit loggingLegitimate interests in keeping the service and its data safe
Service email — invitations, resets, notificationsPerformance of a contract
Responding to your sales or support enquiryLegitimate interests, or steps prior to a contract
Marketing email to a business contactConsent, or legitimate interests where you are an existing customer — with an unsubscribe link in every message

5. Who we share it with

Only the sub-processors needed to run the service, each under a written contract, each named publicly on our sub-processors page. In summary: hosting and database, transactional email, payment processing, error monitoring, push notification delivery and — if your employer enables it — receipt OCR.

We also disclose data where we are legally required to, and to a successor entity in a merger or acquisition, in which case we will notify affected customers.

6. How long we keep it

DataRetention
Employee records in a live customer organisationFor as long as the organisation keeps them, under their own retention policy
Payroll and payslip recordsRetained to meet statutory record-keeping periods, typically six years
Attendance and clock-in records, including locationRetained by the employer; deleted with the organisation
An entire organisation after cancellationHeld for 30 days so an accidental cancellation can be reversed, then deleted
Audit logs12 months
Website enquiries24 months from the last contact
BackupsRolled off on the backup cycle, no more than 35 days behind live

7. Your rights

Under UK and EU data protection law you can ask for access to your data, correction of it, deletion, restriction of processing, portability, and you can object to processing based on legitimate interests. You can also withdraw consent where consent is the basis.

TaskBit has data-subject export and delete built into the product, so an employer can action a request without it becoming a project. To exercise a right:

  • If you are an employee — contact your employer first. They are the controller. We will support them, and act directly where appropriate.
  • Otherwise — write to privacy@taskbithr.com. We respond within one month.

If you are not satisfied you can complain to the Information Commissioner's Office (ico.org.uk) or your local supervisory authority.

8. Security

Encryption in transit and at rest, application-layer encryption for particularly sensitive fields such as bank details, per-organisation isolation enforced on every request, two-factor authentication, rate limiting and lockout, session revocation, audit logging, and tested backups. The detail is on our security page.

9. International transfers

Data is hosted in the UK/EU by default. Where a sub-processor processes data outside the UK or EEA, the transfer is covered by an adequacy decision or by standard contractual clauses with supplementary measures. The location of each sub-processor is listed on the sub-processors page.

10. Changes and contact

We will update this page when our processing changes, and material changes are notified to customer administrators by email before they take effect.

Data protection enquiries: privacy@taskbithr.com
General enquiries: hello@taskbithr.com
TaskBit Ltd, registered in England & Wales. Our company number and registered address are provided on request and on every invoice.