Legal

Privacy Policy

We collect only what we need to run the service, never sell your data, and protect it carefully. This page explains the details.

Effective

Overview

Weekola ("we", "us", or "our") operates the Weekola service and is the data controller for account, security, support, marketing-site and billing administration data. This notice explains what we collect, why, where it comes from, who receives it, and how long we keep it when you use weekola.com.

For employee and workforce records entered by a customer organisation, that organisation is normally the controller and Weekola acts as its processor. Staff should first raise employment-record questions with their organisation; we will assist the organisation with rights requests.

Data comes from you, your organisation's owners or managers, other team members using shared workflows, Stripe billing events, and the device/browser used to access the service. A privacy notice describes processing; it is not a request for blanket consent.

Data we collect

We collect the following categories of data:

  • Account data

    Name, email address, and hashed password when you create an account or are invited by an organisation owner.

  • Organisation data

    Organisation name, billing contact details, and module subscription choices.

  • Workforce & operational data

    Rota shifts, availability, attendance and timesheet entries, clock-in evidence, roles, branch access, swap and open-shift requests, leave requests and notes created by you, managers or colleagues. Sick-leave information can reveal health data and is treated as special-category data.

  • Location data

    When clock-in geofencing is enabled by your organisation admin, we collect your device's GPS coordinates at the moment of clock-in. This data is only used to verify proximity to the configured workplace address and is not tracked continuously.

  • Usage data

    Pages and features used, browser and device type, IP address, security events, and aggregate performance information from server logs, Vercel Analytics and Vercel Speed Insights.

  • Uploads and imports

    Company logos are uploaded to private object storage and displayed only to authenticated members of that organisation. Team and rota CSV/TSV files are read in your browser; the original file is not uploaded or retained, but records you choose to import are saved in the service. Do not upload unnecessary personal data.

  • Messages and notification data

    Support messages, founding-programme applications, transactional email delivery details, notification preferences, and browser push subscription endpoints and encryption keys.

  • Billing data

    Payments are handled by our payment processor, Stripe. We never receive or store your card number. We store only what is needed to run your subscription and show you an accurate account: which modules you subscribe to, your subscription and trial status, renewal dates, the identifiers Stripe gives us (customer, subscription and invoice references), and a record of any refund we issue to you (its amount, reason and date). Card details shown to you in the app — such as the brand and last four digits — are fetched from Stripe when the page loads and are not kept in our database.

How we use your data

We use your data to:

  • Provide and maintain the Weekola service.
  • Authenticate users and protect accounts.
  • Process billing and send transactional emails (e.g. receipts, password resets).
  • Enforce geofencing rules configured by your organisation admin.
  • Analyse usage patterns to improve the product.
  • Respond to support requests.
  • Comply with legal obligations.

Our lawful bases depend on the purpose: contract for account and paid service delivery; legitimate interests for service security, fraud prevention, support and proportionate product analytics; and legal obligation for tax, accounting, rights requests and regulatory duties. Where we process workforce data for an organisation, the organisation determines its Article 6 basis and any Article 9 condition. Health-related leave data must only be entered where the organisation has both a lawful basis and a valid special-category condition. We do not rely on employee consent where the employment relationship makes consent unlikely to be freely given.

Sharing your data

We do not sell your personal data. We share it only in the following limited circumstances:

  • Your organisation and authorised colleagues — access depends on role and branch permissions.
  • Stripe — checkout, payment methods, invoices, subscriptions, refunds and fraud controls.
  • Vercel — application hosting, delivery, aggregate analytics and performance monitoring.
  • Our PostgreSQL hosting provider — encrypted application database hosting.
  • Resend — transactional email delivery.
  • Upstash — rate limiting, abuse prevention and background-job wake coordination.
  • Amazon S3 or the configured S3-compatible provider — private organisation-logo storage.
  • Browser push services selected by your browser or operating system — only when you opt in to push notifications.
  • OpenHolidays API and Nager.Date — public-holiday lookups using country/region and year, not employee records.
  • Professional advisers, authorities or courts where necessary for legal claims, compliance or safety.

Processors are contractually restricted to authorised processing and appropriate security. Some providers may process data outside the UK or EEA. Where a restricted transfer occurs, we use an applicable adequacy regulation or contractual safeguards such as the UK International Data Transfer Agreement or UK Addendum, together with a transfer risk assessment. Contact us for current safeguard details.

AI and automated decisions

Weekola does not currently send account, workforce, uploaded or support data to OpenAI, Anthropic, Google Gemini, or another generative-AI model. It does not provide an AI chatbot and does not make solely automated decisions with legal or similarly significant effects about workers. Scheduling suggestions and rule-based warnings remain subject to a manager's review.

If we introduce AI processing, we will complete data-protection and safety assessments, add appropriate human oversight and crisis/self-harm handling for any conversational feature, update this notice, identify the provider and purpose, and inform affected users before their data is used.

Data retention

Active organisations retain their records until the organisation deletes them or closes the account. Pausing a subscription does not delete data. After organisation closure, operational personal data is deleted or irreversibly anonymised within 90 days, including backup expiry, unless a legal hold or a documented statutory retention duty applies.

Billing invoices, refunds and transaction evidence may be kept for up to 6 years for tax, accounting and legal claims. Security and audit records are kept only for the period reasonably needed to investigate abuse and support claims. The customer organisation decides its live workforce-record retention and must not keep health or location data longer than necessary.

Where workplace location verification is enabled, precise device coordinates, GPS accuracy and exact distance are minimised after 90 days. We retain the punch time and verification outcome with the attendance record for audit and payroll purposes.

CSV/TSV source files used for team or rota import are not retained by us. Expired authentication artefacts are removed on operational retention schedules. Current organisation logos remain until they are replaced or the organisation closes its account; superseded private objects are removed after replacement, and account deletion stops if current assets cannot be removed. A paused subscription follows the same security and retention controls as an active account.

Your rights

Under UK and EU GDPR, you have the following rights with respect to your personal data:

  • AccessRequest a copy of the data we hold about you.
  • RectificationAsk us to correct inaccurate or incomplete data.
  • ErasureRequest deletion of your data (subject to legal retention requirements).
  • PortabilityReceive your data in a structured, machine-readable format.
  • RestrictionAsk us to restrict processing in certain circumstances.
  • ObjectionObject to processing based on legitimate interest.

To exercise any of these rights, email us at team@weekola.com. We normally respond within one month and may need to verify your identity.

You also have the right to lodge a complaint with the Information Commissioner's Office (ICO) at ico.org.uk.

Cookies

We use cookies and browser storage that are necessary to operate the service:

  • Session cookies to keep you logged in.
  • CSRF tokens to protect form submissions.
  • Local or session storage to remember interface preferences, installation prompts and an unfinished signup draft (passwords are excluded).

We do not use advertising cookies. Vercel Analytics and Speed Insights are configured for aggregate product and performance measurement and do not give us cross-site advertising profiles. If we introduce any non-essential cookie or similar storage requiring consent, it will remain off until the visitor makes a choice and can later withdraw it as easily.

Security

We implement appropriate technical and organisational measures to protect your data, including TLS in transit, hashed passwords, private object storage, rate limiting, signed webhook verification, branch/role access controls and audit trails. No system is perfectly secure; if you believe your account has been compromised, contact us immediately.

Policy changes

We may update this policy from time to time. If we make material changes, we will notify account holders by email or via an in-app notice before the change takes effect. The effective date at the top of this page reflects the most recent update.

Contact us

For any privacy-related questions or to exercise your rights, please contact us at: