Privacy Policy
Date of last revision: April 29, 2026
This Privacy Policy describes how Clockio HR, SL collects, uses, and protects the personal information of its users, strictly complying with the General Data Protection Regulation (EU) 2016/679 (GDPR) and Organic Law 3/2018 (LOPDGDD).
1) IDENTIFICATION OF THE DATA CONTROLLER
- Owner: Clockio HR, SL (hereinafter, "Clockio")
- NIF (Tax ID): B55368062
- Registered office: c/ Sant Maurici 24, 17740 - Vilafant, Girona (Spain)
- Contact email: info@clockio.net
2) SCOPE AND CLARIFICATION OF ROLES
To guarantee maximum transparency, we distinguish Clockio's role according to the nature of the service:
- Clockio as CONTROLLER: We process the data of our Clients (those who contract the software), their billing data, commercial contact, web browsing logs, and cookies.
- Clockio as DATA PROCESSOR: Regarding the data of the Employees/Users that the Client enters into the platform (time tracking logs, vacations, payroll, etc.), Clockio acts solely as a technological provider following the Client's instructions. The Client is the sole Data Controller for that data and is responsible for ensuring the legal basis for monitoring their workers.
3) DATA WE PROCESS
Depending on your interaction, we process the following categories:
- Client and Lead Data: Name, professional email, telephone number, and billing data.
- Data in the SaaS platform (on behalf of the client):
- Time tracking and attendance logs: Clock-ins, clock-outs, and total hours calculated.
- Geolocation (only if the Client activates this feature): It is strictly limited to the moment of clocking in/out to verify the location at the start/end of the workday, respecting the principles of proportionality and privacy outside of working hours.
- Document management: Payroll, contracts, and expense receipts.
- Technical evidence: Electronic signature metadata (digital fingerprint that guarantees the integrity of the clock-in/out) and audit logs.
4) PURPOSES, LEGAL BASES, AND RETENTION
| Purpose | Legal Basis | Retention Period |
| SaaS Service Provision: Account management and maintenance. | Performance of a contract (Art. 6.1.b GDPR). | For the duration of the contractual relationship. |
| Technical Support: Incident resolution and inquiries. | Legitimate interest (Art. 6.1.f GDPR). | 2 years after the last interaction. |
| Administrative Management: Billing and accounting. | Legal obligation (Art. 6.1.c GDPR). | 6 years (commercial regulations). |
| Communications: Updates and training on the tool. | Consent or legitimate interest. | Until cancellation or revocation is requested. |
| Time Tracking Logs: Compliance with Art. 34.9 ET. | Legal obligation of the Client. | 4 years available to the Client. |
5) SUB-PROCESSORS AND INTERNATIONAL TRANSFERS
Clockio selects providers that guarantee the highest security standards:
- Google Cloud: Storage on servers within the European Union.
- SendGrid / Firebase (Google): Sending notifications and emails. Although these entities may process metadata in the US, the transfer is covered by Standard Contractual Clauses (SCC) approved by the European Commission.
- Cloudflare: Security optimization. Data is processed in an encrypted format to prevent cyberattacks.
6) INFORMATION SECURITY
We have implemented measures to guarantee the security triad (Confidentiality, Integrity, and Availability):
- Data Isolation (Tenant Isolation): Each company's data is logically separated; it is impossible for one company to access another's logs.
- High-level encryption: Use of TLS 1.3 protocols in transit and AES-256 encryption at rest.
- Two-Factor Authentication (2FA): Available to prevent unauthorized access to administrator accounts.
7) RESPONSIBLE ARTIFICIAL INTELLIGENCE (AI)
- Privacy by design: Clockio does not use its clients' data or employee logs to train third-party AI models.
- Human Oversight: AI-assisted features (such as productivity summaries) are supporting tools. Clockio does not make "automated decisions" that have legal effects without human intervention.
8) YOUR RIGHTS
You can exercise your rights of access, rectification, erasure, objection, restriction, and portability by sending an email to info@clockio.net.
To protect your privacy, we will request that you prove your identity (using an ID card or similar document). If you are an employee, please note that to access or rectify your time tracking data, you must first contact your employer (the Data Controller).
Likewise, you have the right to lodge a complaint with the Spanish Data Protection Agency (www.aepd.es).
9) UPDATES
Any substantial change to this policy will be notified through the platform or by email 15 days in advance of its entry into force.