1.Summary
This policy explains what personal data TIMEWOX ([TO BE CONFIRMED], registered entity pending) (“TIMEWOX”, “we”) handles when a school uses our timetable and cover management service, why we handle it, and what rights people have over it.
The most important point: TIMEWOX does not collect or store personal data about individual students. The service schedules staff against classes. It holds no student names, no student contact details, no student identifiers, and no student records of any kind. Where the product refers to class size, it stores only an aggregate headcount, a plain number such as “32”, with no person attached to it and no way to identify anyone from it.
The personal data we do handle is staff data: the names, email addresses and optional phone numbers of the administrators and teachers a school chooses to add.
2.Our role: controller and processor
Data protection law distinguishes the party who decides why data is processed (the controller) from the party who processes it on their behalf (the processor). Both apply here, in different places:
- The school is the controller of the staff and scheduling data it puts into its workspace. The school decides which teachers to add, what to record about them, and how long to keep it. TIMEWOX acts as a processor, handling that data only on the school’s documented instructions and only to provide the service.
- TIMEWOX is the controller of its own business records: the account of the person who signed the school up, billing and invoice records, and support correspondence. We decide the purpose of those, so we are responsible for them directly.
Schools that need a signed data processing agreement can request one at [TO BE CONFIRMED].
3.What personal data we handle
Staff account data. Name, email address, optional phone number, role (administrator or teacher), and the school the person belongs to. Passwords are stored only as salted hashes by our authentication provider; we never see or store a password in readable form.
Scheduling data. Which teacher is assigned to which class, subject and period; a teacher’s subject competencies and maximum teaching load; absence markings and the substitution requests they generate; school calendar entries such as holidays and events. Absence records indicate only that a teacher is unavailable for a given period. We do not collect a reason, and never any health information.
School configuration. School name, subdomain, branding, grades, classes, subjects and the daily period structure. This includes the aggregate class headcount described above.
Mobile device tokens. If a teacher installs the mobile app, a push notification token for their device, used solely to deliver notifications about their own schedule and cover assignments.
Payment data: none. TIMEWOX is currently free and we operate no payment facility. We do not collect card details, bank details or billing addresses anywhere in the product.
Technical logs. Standard server and error logs necessary to operate and secure the service.
4.Why there is no student data
We are explicit about this because it is usually the first question a school’s data protection officer asks, and because it materially changes the risk of adopting the product.
TIMEWOX schedules staff against classes, not students against lessons. A class is a container, “Grade 10 – B”, with a name, a grade and a headcount. No student is enrolled into it, named in it, or identifiable from it. There is no student table, no student import, no parent contact, no attendance register, no grades or assessment data, and no behavioural records.
Consequently, using TIMEWOX does not involve transferring children’s personal data to us. Schools should still, of course, apply their own policies to the staff data they enter.
5.Why we handle it and on what basis
- To provide the service: building timetables, detecting conflicts, assigning cover, and giving each teacher their own schedule. Necessary for performance of our contract with the school.
- To send operational email and notifications: teacher invitations, password resets, and cover assignments. Necessary for performance of the contract.
- To secure the service: authentication, access control, and an audit record of sensitive administrative actions such as a password reset. Our legitimate interest in keeping accounts safe.
We do not sell personal data, we do not share it for advertising, and we do not use it to train machine learning models.
6.Sub-processors
We use a small number of service providers to run the platform. Each is bound by contract to protect the data it handles and to process it only on our instructions.
- Supabase: Database hosting, authentication, and file storage. Data involved: All school configuration and staff account data.
- Resend: Transactional email delivery (teacher invitations, password resets). Data involved: Staff name and email address.
- Expo (push notification service): Delivering push notifications to the teacher mobile app. Data involved: Device push token and notification content.
We will give schools notice of any material change to this list. Schools with an active data processing agreement can ask to be notified in advance.
7.How schools are kept separate
Every school occupies its own isolated workspace on its own subdomain. Separation is enforced in the database itself through row-level security policies keyed to the school, not merely by application code or by the interface hiding things. A query for one school’s data cannot return another school’s rows. Within a school, access is further limited by role: teachers can see their own schedule and the cover requests addressed to them, while administrative functions are restricted to administrators.
8.Security
- All traffic is encrypted in transit using TLS.
- Data is encrypted at rest by our hosting provider.
- Passwords are stored only as salted hashes, never in readable form.
- Access is role-based and enforced at the database layer through row-level security.
- Teachers join only by invitation from their own school administrator. Accounts cannot be self-registered into an existing school.
- Administrative password resets performed by our platform staff are recorded in an audit log identifying who performed the reset, on whom, and when.
No system is perfectly secure. If a breach affects a school’s personal data, we will notify that school without undue delay and provide the detail it needs to meet its own obligations.
9.How long we keep data
Data is kept for as long as the school’s workspace is active. When a school cancels, its data is retained for 90 days so it can be exported or the account reinstated, and is then permanently deleted. A school may request earlier deletion, or an export, at any time.
Invoices and accounting records are kept for as long as tax and company law requires, independently of the workspace.
10.Rights over personal data
Depending on where they live, individuals may have the right to access their personal data, correct it, have it deleted, restrict or object to its processing, receive it in a portable format, and complain to a data protection authority.
Teachers and school staff should contact their own school first. The school is the controller of that data and can usually resolve the request directly in the product. Where a request reaches us instead, we will pass it to the school and assist them in responding.
For data where we are the controller, contact [TO BE CONFIRMED]. We aim to respond within 30 days.
11.International transfers
Our infrastructure and sub-processors may store or process data in countries other than the school’s own. Where data is transferred out of the region it was collected in, we rely on appropriate safeguards such as standard contractual clauses. Schools with a regional data residency requirement should raise it with us before signing, at [TO BE CONFIRMED], it can usually be accommodated, but it needs to be arranged in advance.
13.Changes to this policy
We may update this policy as the service changes. The “last updated” date at the top of this page always reflects the current version, and we will notify schools directly of any change that materially affects how their data is handled.
14.Contact us
For any privacy or data protection question, including data processing agreements and data subject requests:
- Email: [TO BE CONFIRMED]
- Post: Registered address [TO BE CONFIRMED]
General enquiries are handled through our contact page.