Privacy policy
Last updated: July 2026
Who is the controller
AccessTime is the time-tracking and HR platform available at this domain. For any question about this policy or your data, you can write to the team through the support chat or the contact form.
For the purposes of Regulation (EU) 2016/679 (GDPR), two roles should be distinguished:
- For account data and data about visitors to this website, AccessTime acts as the data controller.
- For the employee data each company records on the platform (time entries, absences, schedules), the client company is the controller and AccessTime acts as the data processor on its behalf.
What data we process
- Account data: name, email, password (stored with a secure hash), language and the company you belong to.
- Working-time record data: time entries with date and time, method used (web, app, kiosk), and — only if your company enables it and your browser allows it — the entry's geolocation.
- Absences and requests: holidays, leave, attached supporting documents, schedule changes and remote work, along with their approval status.
- Billing data: handled by Stripe; AccessTime does not store card numbers.
- Support: name, email and the content of the messages you send through the chat or the contact form.
- Technical data: IP address, user agent and a log of active sessions, for security purposes.
Why and on what legal basis
- Providing the service (performance of a contract): accounts, time entries, absences, reports.
- Complying with legal obligations: the working-time record is kept for 4 years in accordance with art. 34.9 of the Estatuto de los Trabajadores (Spain's Workers' Statute, as amended by RD-ley 8/2019).
- Platform security (legitimate interest): session control, login attempt limits, change auditing and anti-bot protection.
- Responding when you write to us (consent): chat and contact form.
Recipients and transfers
- Stripe Payments Europe processes subscription payments.
- Google reCAPTCHA is used on public forms to prevent abuse; Google may process technical data from your browser.
- The service is hosted on servers within the European Union. We do not sell data or share it with third parties for advertising purposes.
Retention
- Time entries and working-time records: 4 years, by legal obligation.
- Account data: for as long as the account is active and, after cancellation, for the time strictly necessary to address legal responsibilities.
- Support conversations: up to 2 years from the last message.
Your rights
You can exercise your rights of access, rectification, erasure, objection, restriction and portability by writing to us through the chat or the contact form. If you're an employee of a client company, contact your company first (the data controller); we'll still help you channel the request. You can also lodge a complaint with the Agencia Española de Protección de Datos, Spain's data protection authority (aepd.es).
Security
We apply TLS encryption in transit, password hashing, optional two-step verification, strict data isolation between companies, active session control and an audit log of sensitive changes.