Privacy Policy

Last updated: September 2, 2026

This Privacy Policy explains how KpiClock ("we," "us," or "our") collects, uses, discloses, and protects personal data through our website and workforce management platform (the "Service").

This Policy distinguishes between two categories of individuals:

  • Customer — the business or individual that registers for and administers a KpiClock account.

  • End User — an employee, contractor, or team member added to a Customer's workspace, whose time, attendance, or activity may be tracked through the Service.

Where KpiClock processes End User personal data on behalf of a Customer, the Customer acts as the data controller and KpiClock acts as the data processor. Our Data Processing Agreement governs that relationship. This Policy also describes our own practices as a controller with respect to Customer account and billing data.

1. Information We Collect

Account and billing information: name, email address, company name, billing address, and payment details (processed by our third-party payment processor; we do not store full card numbers).

Time tracking and work data: clock-in/clock-out times, timesheets, project and task names, and time entries created by End Users.

Productivity and activity data (where enabled by the Customer): activity levels, keyboard/mouse activity indicators, application and website/URL usage while a timer is running, and idle time.
Screenshots (optional, Customer-configurable): periodic screen captures taken while a timer is active. Customers may configure blur mode or disable this feature entirely.

Attendance and leave data: shift schedules, late/absence records, leave requests, balances, and approvals.

Document signing data: documents uploaded for signature, signer names, email addresses, IP addresses, timestamps, and audit trail information created during the e-signature process.

Device and technical data: IP address, browser type, operating system, device identifiers, and log data collected automatically when you use our website or desktop applications.

Cookies and similar technologies: as described in our Cookie Policy.

2. How We Use Information

Where the GDPR or UK GDPR applies, we rely on the following legal bases: performance of a contract (providing the Service to Customers), legitimate interests (such as security, fraud prevention, and product improvement), compliance with legal obligations, and, where required, consent. Where we process End User data as a processor, the applicable legal basis for that processing is determined by the Customer as the data controller.

3. Legal Bases for Processing (EEA/UK Users)

Where the GDPR or UK GDPR applies, we rely on the following legal bases: performance of a contract (providing the Service to Customers), legitimate interests (such as security, fraud prevention, and product improvement), compliance with legal obligations, and, where required, consent. Where we process End User data as a processor, the applicable legal basis for that processing is determined by the Customer as the data controller.

4. Productivity Monitoring and Screenshot Disclosure

Activity monitoring and screenshot features are controlled and configured by the Customer, not by KpiClock. If you are an End User whose activity is being monitored, the Customer that added you to the workspace is responsible for informing you about what is tracked and why, and for ensuring it has a lawful basis to do so. KpiClock stores this data as instructed by the Customer and does not use it for any purpose other than providing the Service, unless required by law.

5. How We Share Information

We do not sell personal data. We may share personal data with:

  • Sub-processors and service providers who help us operate the Service, such as cloud hosting, payment processing, email delivery, and customer support tools, under contracts requiring appropriate data protection safeguards;

  • Third-party integrations you choose to connect (e.g., ClickUp, Linear, Trello, Asana, Jira, Monday.com), to the extent necessary to provide the integration, governed also by that provider's own terms;

  • Within a Customer's workspace, where account administrators can access time, attendance, activity, and document data of their own End Users as part of the Service's core functionality;

  • Legal and safety purposes, where required to comply with law, respond to lawful requests, or protect the rights, property, or safety of KpiClock, our users, or others; and

  • Corporate transactions, such as a merger, acquisition, or asset sale, subject to standard confidentiality protections.

6. International Data Transfers

We may transfer personal data to countries other than the one in which it was originally collected, including the United States. Where required, we use appropriate safeguards for such transfers, such as Standard Contractual Clauses approved by the European Commission or equivalent mechanisms.

7. Data Retention

We retain personal data for as long as needed to provide the Service and for legitimate business or legal purposes. Time tracking, activity, and screenshot data collected under our Time Tracking plan is retained for approximately 3 months unless a longer period is selected, required by a Customer's plan, or required by law. Account and billing records may be retained longer to meet accounting, tax, and legal obligations. Upon account termination, Customer Data is deleted or anonymized within a reasonable period, except where retention is required by law.

8. Security

We implement technical and organizational measures designed to protect personal data, including encryption in transit, access controls, two-factor authentication (2FA), and regular security assessments. See our Security page for more detail. No method of transmission or storage is completely secure, and we cannot guarantee absolute security.

9. Your Rights

Depending on your location, you may have rights to access, correct, delete, restrict, or port your personal data, or to object to certain processing. If you are an End User, we recommend directing requests to the Customer that manages your workspace, as they control that data; we will assist Customers in responding to such requests. You may also contact us directly at info@kpiclock.com, and we will route or respond to your request as appropriate under applicable law.

California residents may have additional rights under the CCPA/CPRA, including the right to know, delete, and opt out of the sale or sharing of personal information (KpiClock does not sell personal information).

10. Children's Privacy

The Service is not directed to individuals under the age of 18, and we do not knowingly collect personal data from children. If we learn that we have collected personal data from a child without appropriate consent, we will take steps to delete it.

11. Cookies

Our use of cookies and similar tracking technologies is described in our Cookie Policy.

12. Changes to This Policy

We may update this Privacy Policy from time to time. Material changes will be communicated via email or through the Service prior to taking effect. The "Last updated" date at the top of this page indicates when it was last revised.

13. Contact Us

For questions about this Privacy Policy or our data practices, contact us at:

info@kpiclock.com KpiClock 1178 Broadway, 3rd Floor, Ste 302, New York, NY 10001, USA