Last updated: 5 August 2026.
Who is responsible for your data
Where you use Klockity as a member of a company, that company is the data controller and Klockity Ltd acts as processor on its instructions. For your own account details and our own billing records, Klockity Ltd is the controller.
What we collect
- Account details: name, email address, and the companies you are a member of.
- Attendance records: check-in and checkout timestamps, the site scanned, whether the scan was location-verified, and whether a checkout was applied manually by an administrator.
- Location: latitude and longitude captured at the moment of a check-in or checkout, used to test the site geofence. We do not track location at any other time.
- Company data: sites, coordinates and radii, shifts, announcements and messages.
- Billing data: subscription tier and status. Card details are handled by Stripe and never reach Klockity servers.
Why we process it
To operate attendance verification, scheduling and reporting for your employer; to secure the service against fraudulent check-ins; to bill companies for their subscription; and to meet legal obligations. The lawful bases are contract, legitimate interests and legal obligation as applicable.
Sharing
Your attendance and membership data is visible only to administrators of the company that record belongs to. We use Supabase for hosted database, authentication and storage, and Stripe for payments. We do not sell personal data or use it for advertising.
Retention
Attendance records are retained for as long as the company keeps its Klockity account, so the company can meet payroll and employment record obligations. Deleting your account removes your profile and login; records that a company must retain remain under that company's control.
Your rights
Under UK GDPR you may request access, correction, erasure, restriction, portability, or object to processing. Contact your company administrator first for records held on their behalf, or email us and we will route the request.
Security
Data is isolated per company through row-level security, transmitted over TLS, and access is scoped by role. Site QR secrets are never exposed to non-administrators.
Contact
Privacy questions: privacy@klockity.com. You also have the right to complain to the UK Information Commissioner's Office.