Privacy policy

Timr is a shift management system for Icelandic workplaces. It handles sensitive information about employees, including Icelandic ID numbers (kennitala), working hours and the location captured when they clock in. This page explains what we collect, why, how long we keep it and what rights you have.

1. About this policy

This policy applies to all use of Timr, whether through timr.is, app.timr.is or the employee mobile app. It covers subscribing companies, their managers and the employees registered in the system.

2. Controller and processor

Timr acts in two capacities depending on the data. Timr is the controller of the data created when a subscription is set up and run, such as the company's contact and billing details. When a company registers its employees in the system, that company is the controller of their data and Timr processes it solely as a processor, on the company's instructions.

Employees who wish to exercise their rights over working-time and location data should therefore contact their employer first; Timr assists the employer in responding.

3. What we collect

We collect only the data needed to run the service:

  • Account details: name, email address, phone number and a hashed password.
  • Company details: name, ID number (kennitala), address and worksites.
  • Employee details entered by the employer: name, ID number, email address, phone number, contracted hours and pay parameters.
  • Working-time data: shifts, clock-ins, clock-outs, time off and holiday.
  • Location at the moment of clocking, where the employer has enabled location verification.
  • Billing details for the subscription. Card numbers are handled by our payment provider and are never stored in Timr's systems.
  • Technical data: IP address, device and browser type, and logs of how the system is used.

4. Why we use it

Personal data is used only for the following purposes:

  • Delivering the service: shift planning, time tracking, pay calculations and reports.
  • Confirming that a clock-in happens at the right worksite, where the employer has enabled that feature.
  • Providing customer support and answering enquiries.
  • Collecting subscription fees and maintaining invoices.
  • Improving the system, diagnosing faults and keeping it operationally secure.
  • Meeting legal obligations, including accounting and record-retention duties.

5. Legal basis

Processing is carried out under Icelandic Act no. 90/2018 on Data Protection and the Processing of Personal Data and the General Data Protection Regulation (EU) 2016/679. The bases are:

  • Performance of a contract, where processing is necessary to provide the subscriber with the service.
  • Legal obligation, including accounting and tax reporting.
  • Legitimate interests, such as protecting the system against misuse and keeping it operationally secure.
  • Consent, where applicable — for example the mobile app's access to the device's location. Consent can be withdrawn at any time in the device settings.

6. Location data

Timr does not track employees' movements. Location is read only at the moment an employee clocks in or out, and only a single coordinate is stored alongside a timestamp. The system requests no location while the app is closed or in the background, and no movement history is created.

The employer decides whether location verification is enabled and how large an area counts as valid. An employee can deny location access in the device settings; clocking in then has to be arranged another way with the employer.

7. Sharing with third parties

Timr never sells personal data and does not share it with third parties for marketing. Data is shared only with service providers necessary to run the system, each acting as a processor under a data processing agreement:

  • Hosting and infrastructure providers that run the website and the database.
  • The payment provider that handles card payments and subscriptions.
  • The service that sends notifications and system email.
  • The web analytics service that collects aggregated information about site usage.
  • Public authorities, where required by law.

8. Transfers outside the EEA

Data is stored within the European Economic Area as a rule. Where a provider processes data outside the EEA, that processing is safeguarded by the European Commission's standard contractual clauses or another recognised transfer mechanism.

9. How long we keep it

Data is not kept longer than necessary. Shifts, time records and other company data are retained while the subscription is active. Accounting records are retained for seven years under Icelandic Act no. 145/1994 on Accounting.

When a subscription ends, the company is given the opportunity to export its data before it is deleted. An employer may at any time request deletion of the data it controls, to the extent no legal obligation requires it to be kept.

10. Security

All communication with Timr runs over an encrypted connection (TLS). Passwords are stored hashed and are never visible to Timr staff. Access to data is limited to those who need it, and each company's data is isolated from every other company in the system.

In the event of a breach likely to result in a risk to individuals' rights, the Icelandic Data Protection Authority is notified within 72 hours and the affected controllers are informed without undue delay.

11. Your rights

You have the following rights over personal data concerning you:

  • The right of access to the data being processed about you.
  • The right to have inaccurate or incomplete data corrected.
  • The right to erasure, to the extent no legal obligation prevents it.
  • The right to restrict processing or to object to it.
  • The right to receive your data in a machine-readable format.
  • The right to withdraw consent that processing relies on, without affecting the lawfulness of processing before withdrawal.

If you are an employee of a company that uses Timr, address your request to your employer, who is the controller of that data.

12. Cookies

Timr uses cookies that are necessary for the system to work, such as keeping you signed in and remembering your language. We also use web analytics to understand how the site is used. You can delete and refuse cookies in your browser settings, but some functionality may stop working.

13. Changes to this policy

This policy may change, for example as features or legal requirements change. The current version is always on this page and the date of the last update is shown at the top. Where changes are material, subscribers are notified by email before they take effect.

14. Contact us

Questions about this policy and requests to exercise your rights can be sent to hjalp@timr.is.

If you believe personal data is not being processed lawfully, you may lodge a complaint with the Icelandic Data Protection Authority (Persónuvernd), Rauðarárstígur 10, 105 Reykjavík (personuvernd.is).