Overview
Weekola ("we", "us", or "our") operates the Weekola service and is the data controller for account, security, support, marketing-site and billing administration data. This notice explains what we collect, why, where it comes from, who receives it, and how long we keep it when you use weekola.com.
For employee and workforce records entered by a customer organisation, that organisation is normally the controller and Weekola acts as its processor. Staff should first raise employment-record questions with their organisation; we will assist the organisation with rights requests.
Data comes from you, your organisation's owners or managers, other team members using shared workflows, Stripe billing events, and the device/browser used to access the service. A privacy notice describes processing; it is not a request for blanket consent.
Data we collect
We collect the following categories of data:
Account data
Name, email address, and hashed password when you create an account or are invited by an organisation owner.
Organisation data
Organisation name, billing contact details, and module subscription choices.
Workforce & operational data
Rota shifts, availability, attendance and timesheet entries, clock-in evidence, roles, branch access, swap and open-shift requests, leave requests and notes created by you, managers or colleagues. Sick-leave information can reveal health data and is treated as special-category data.
Location data
When clock-in geofencing is enabled by your organisation admin, we collect your device's GPS coordinates at the moment of clock-in. This data is only used to verify proximity to the configured workplace address and is not tracked continuously.
Usage data
Pages and features used, browser and device type, IP address, security events, and aggregate performance information from server logs, Vercel Analytics and Vercel Speed Insights.
Uploads and imports
Company logos are uploaded to private object storage and displayed only to authenticated members of that organisation. Team and rota CSV/TSV files are read in your browser; the original file is not uploaded or retained, but records you choose to import are saved in the service. Do not upload unnecessary personal data.
Messages and notification data
Support messages, founding-programme applications, transactional email delivery details, notification preferences, and browser push subscription endpoints and encryption keys.
Billing data
Payments are handled by our payment processor, Stripe. We never receive or store your card number. We store only what is needed to run your subscription and show you an accurate account: which modules you subscribe to, your subscription and trial status, renewal dates, the identifiers Stripe gives us (customer, subscription and invoice references), and a record of any refund we issue to you (its amount, reason and date). Card details shown to you in the app — such as the brand and last four digits — are fetched from Stripe when the page loads and are not kept in our database.
How we use your data
We use your data to:
- Provide and maintain the Weekola service.
- Authenticate users and protect accounts.
- Process billing and send transactional emails (e.g. receipts, password resets).
- Enforce geofencing rules configured by your organisation admin.
- Analyse usage patterns to improve the product.
- Respond to support requests.
- Comply with legal obligations.
Our lawful bases depend on the purpose: contract for account and paid service delivery; legitimate interests for service security, fraud prevention, support and proportionate product analytics; and legal obligation for tax, accounting, rights requests and regulatory duties. Where we process workforce data for an organisation, the organisation determines its Article 6 basis and any Article 9 condition. Health-related leave data must only be entered where the organisation has both a lawful basis and a valid special-category condition. We do not rely on employee consent where the employment relationship makes consent unlikely to be freely given.
AI and automated decisions
Weekola does not currently send account, workforce, uploaded or support data to OpenAI, Anthropic, Google Gemini, or another generative-AI model. It does not provide an AI chatbot and does not make solely automated decisions with legal or similarly significant effects about workers. Scheduling suggestions and rule-based warnings remain subject to a manager's review.
If we introduce AI processing, we will complete data-protection and safety assessments, add appropriate human oversight and crisis/self-harm handling for any conversational feature, update this notice, identify the provider and purpose, and inform affected users before their data is used.
Data retention
Active organisations retain their records until the organisation deletes them or closes the account. Pausing a subscription does not delete data. After organisation closure, operational personal data is deleted or irreversibly anonymised within 90 days, including backup expiry, unless a legal hold or a documented statutory retention duty applies.
Billing invoices, refunds and transaction evidence may be kept for up to 6 years for tax, accounting and legal claims. Security and audit records are kept only for the period reasonably needed to investigate abuse and support claims. The customer organisation decides its live workforce-record retention and must not keep health or location data longer than necessary.
Where workplace location verification is enabled, precise device coordinates, GPS accuracy and exact distance are minimised after 90 days. We retain the punch time and verification outcome with the attendance record for audit and payroll purposes.
CSV/TSV source files used for team or rota import are not retained by us. Expired authentication artefacts are removed on operational retention schedules. Current organisation logos remain until they are replaced or the organisation closes its account; superseded private objects are removed after replacement, and account deletion stops if current assets cannot be removed. A paused subscription follows the same security and retention controls as an active account.
Your rights
Under UK and EU GDPR, you have the following rights with respect to your personal data:
- AccessRequest a copy of the data we hold about you.
- RectificationAsk us to correct inaccurate or incomplete data.
- ErasureRequest deletion of your data (subject to legal retention requirements).
- PortabilityReceive your data in a structured, machine-readable format.
- RestrictionAsk us to restrict processing in certain circumstances.
- ObjectionObject to processing based on legitimate interest.
To exercise any of these rights, email us at team@weekola.com. We normally respond within one month and may need to verify your identity.
You also have the right to lodge a complaint with the Information Commissioner's Office (ICO) at ico.org.uk.
Security
We implement appropriate technical and organisational measures to protect your data, including TLS in transit, hashed passwords, private object storage, rate limiting, signed webhook verification, branch/role access controls and audit trails. No system is perfectly secure; if you believe your account has been compromised, contact us immediately.
Policy changes
We may update this policy from time to time. If we make material changes, we will notify account holders by email or via an in-app notice before the change takes effect. The effective date at the top of this page reflects the most recent update.
Contact us
For any privacy-related questions or to exercise your rights, please contact us at:
Weekola
team@weekola.comAlso see