Timax Website Privacy Policy
Website & web platform · timax.uk
UK GDPR compliant · Last updated: 25 August 2026
This policy covers use of Timax in a web browser. If you use the Timax mobile app (iOS or Android), read the separate Mobile App Privacy Policy.
- 1. Introduction
- 2. Who Is Responsible for Your Data
- 3. Who the Platform Is For
- 4. Information We Collect on the Website
- 5. Cookies and Similar Technologies
- 6. How We Use Your Information
- 7. Legal Bases for Processing
- 8. How We Share Information
- 9. International Transfers
- 10. Data Retention
- 11. Security
- 12. Your Choices
- 13. Account and Data Deletion
- 14. Your Rights
- 15. Related Policies
- 16. Changes and Contact
This Privacy Policy explains how Timax ("Timax", "we", "us", "our") collects, uses, stores, and protects personal information when you use the Timax website and web platform — including timax.uk, organisation subdomains (for example your-org.timax.uk), and authenticated areas such as the admin dashboard, scheduling tools, compliance modules, and staff-facing web pages (together, the "Platform").
This policy applies to use of Timax in a web browser. It does not apply to the Timax mobile app for iOS and Android. If you use the mobile app, please read our separate Timax Mobile Privacy Policy instead.
We process personal data in accordance with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.
Timax is a business-to-business workforce platform. Depending on your relationship with us:
- If you sign up for a Timax organisation account or manage billing, Timax is typically the data controller for your account, subscription, and platform usage data.
- If you are staff, a supervisor, or a client user invited by an organisation that uses Timax, your employer or contracting organisation is usually the data controller for operational data about you (shifts, welfare records, compliance documents, and similar). Timax processes that data on the organisation's instructions as a data processor.
- Timax remains responsible for securing the Platform and for privacy questions about how the service works.
For questions about employment or operational records held for your organisation, contact your employer or Timax administrator first. For Platform, billing, or account questions, contact us using the details in section 16.
The Platform is intended for security and workforce organisations, their administrators, supervisors, staff, suppliers, and authorised client users. It is a business service, not directed at children, and is not intended for anyone under 16.
Information you provide through the Platform:
- Account and profile data: name, email address, password (stored as a secure hash), organisation membership, role, and preferences
- Organisation and billing data: company details, subscription selections, invoices, and payment-related information when you purchase Timax
- Workforce and operational data entered or generated through the Platform: staff profiles, schedules, shifts, locations, incidents, compliance records, documents, messages, and reporting data — according to your organisation's use of Timax
- Support and communications: information you send when contacting us or responding to in-platform notifications
- Web welfare and attendance submissions: where staff use Timax in a browser, check-call or geofence submissions may include timestamps, notes, evidence answers, and precise location if you submit a location-enabled action
Information collected automatically when you use the Platform:
- Session and authentication data: login sessions, security tokens, and organisation context stored in cookies or similar browser storage
- Technical and usage data: IP address, browser type, device type, pages viewed, actions taken, timestamps, and error or security logs
- Realtime connection metadata: short-lived tokens when the Platform uses live updates for schedules or command-centre views
- Local browser storage: limited preferences or consent flags (for example location-consent acknowledgement on staff web sessions)
Information we do not collect through the website alone:
- Mobile push notification tokens, device biometrics, or other data collected only through the Timax mobile app (see the Mobile Privacy Policy)
- Contacts, SMS, call logs, or advertising identifiers from your device
- Cross-website advertising profiles — we do not sell personal data or use the Platform for third-party ad tracking
The Platform uses cookies and similar browser technologies to:
- Keep you signed in and maintain your session across pages and subdomains
- Remember organisation context and security settings
- Protect against cross-site request forgery and support secure authentication
- Store limited local preferences or consent choices where needed for Platform features
Essential cookies are required for the Platform to function. You can control non-essential cookies through your browser settings, but disabling essential cookies may prevent you from signing in or using core features. We do not use third-party advertising cookies on the Platform.
- Providing, operating, and improving the Timax Platform
- Creating and managing accounts, organisations, and subscriptions
- Processing payments and billing through our payment provider
- Enabling scheduling, welfare, compliance, reporting, and other modules your organisation uses
- Sending service, security, and account-related communications
- Monitoring performance, troubleshooting, and preventing fraud or misuse
- Complying with legal obligations and responding to lawful requests
- Performance of a contract — to provide the Platform and subscription services
- Legitimate interests — to secure, maintain, and improve Timax, and to support organisations using the service
- Legal obligation — where UK law requires record-keeping or disclosure
- Consent — where required for optional communications or specific processing choices
We do not sell your personal information. We may share data with:
- Your organisation's authorised users, according to role permissions configured in Timax
- Service providers that help us host, operate, email, back up, or secure the Platform
- Stripe, when you pay for a Timax subscription (payment card data is handled by Stripe under their privacy policy)
- Mapping or geocoding providers where location features display maps or validate addresses
- Professional advisers or authorities when required by law or to protect rights and safety
Timax is operated from the United Kingdom. Data is primarily processed in the UK or European Economic Area. Some infrastructure or payment providers may process limited data in other countries. Where required, we use appropriate safeguards such as UK-approved contractual protections.
- Account and subscription records are kept while your organisation's account is active and for a period afterwards for billing, tax, and legal requirements
- Operational and workforce records are retained according to your organisation's Timax configuration and applicable law
- Server, security, and audit logs are kept for a limited period, then deleted or anonymised
- Browser session data expires according to authentication settings or when you sign out
We protect personal data using HTTPS/TLS encryption in transit, secure password hashing, role-based access controls, tenant separation between organisations, and industry-standard hosting safeguards. Contact support@timax.uk immediately if you believe your account has been compromised.
- Account settings: update profile and notification preferences within the Platform where available
- Cookies: manage through your browser; essential authentication cookies are required to use signed-in areas
- Marketing: where we send optional product updates, you may opt out using the unsubscribe method in the message
Organisation administrators can manage user access within Timax. To close an organisation account, cancel a subscription, or request deletion of personal data, contact support@timax.uk from your registered email with enough detail for us to verify the request.
Staff or client users invited by an organisation should usually contact their employer or Timax administrator first for deletion of operational records. We aim to complete verified platform deletion requests within 30 days, subject to legal retention requirements.
Under UK GDPR you may have the right to access, rectify, erase, restrict, or object to processing, and to data portability where applicable. Contact your organisation for records they control. Contact support@timax.uk for Platform account matters. You may also complain to the UK Information Commissioner's Office at ico.org.uk.
We may update this policy from time to time. The latest version is published at https://timax.uk/privacy with the "Last updated" date shown at the top of the page.
Questions about this Website Privacy Policy:
- Email: support@timax.uk
- Website: https://timax.uk/contact
Mobile app users: Timax Mobile Privacy Policy · https://timax.uk/privacy