Security and personal data
Where the data is stored, how it is encrypted, who can reach it, and what Timply processes about your employees. Written so a procurement question can be answered from this page.
Where the data is stored
The database is with Supabase on AWS in the eu-north-1 region, Stockholm. The rest of the infrastructure runs in Stockholm on Google Cloud Platform. Email is sent through SendGrid within the EU, and web analytics is handled by Vercel Analytics within the EU.
One exception is worth naming because it comes up in procurement. Building and deployment happen at Vercel, which is a global service. That processing covers source code and build logs, not customer data in production.
Transfers outside the EEA are made under standard contractual clauses per Commission decision 2021/914. Swedish law and Swedish courts apply under our data processing agreement.
Encryption
Traffic is encrypted in transit with TLS. Data is encrypted at rest by the database provider. Passwords are never handled by Timply in clear text, because authentication happens through an identity provider.
Access and permissions
Access in Timply follows role. An employee sees their own hours, their own schedule and their own requests. A manager sees their team. An administrator sees the organisation and the billing.
In Pro there are teams with their own permissions, so a manager of one team does not see another team's data.
What Timply processes about employees
The system processes the personal data needed to calculate time and pay: name, email address, employment number, hours worked, absence with a reason, and holiday days. A reason for absence can in some cases be health data, which is a special category of personal data under the GDPR and therefore has to be handled with that in mind.
For organisations keeping an electronic staff register, a personal identity number, coordination number or equivalent is processed as well, because the law requires an identity detail per person. That value is encrypted at the application layer with AES-256-GCM before storage and read out only where the register requires it. It is excluded from ordinary reads of user data, and it is processed only for the premises you have declared as covered.
If you switch on location validation at clock-in, the employee's position is processed at the moment of the clock-in. The position is read then and not in between, and Timply does not track staff through the working day. Switching the feature on requires that you inform your employees and have a clear purpose.
Network and operations
Traffic goes through Cloudflare and Vercel's firewall. Requests are rate limited. Anomalies are monitored, and incidents are handled under a documented procedure.
Data processing agreement
You are the controller for your employees' data. Timply is the processor. The agreement is available in full on the data processing agreement page, together with the complete list of sub-processors.
What we do not claim
Timply is not ISO 27001 certified, and we have not been through a SOC 2 audit. If your procurement requires either, you should know that before going further.
Reporting a security issue
If you have found something, get in touch through the contact page. We answer reports of security issues before anything else in the inbox.
Try Timply with your own staff
You can get going on your own, with your real schedule and your real staff. If you would rather be shown around first, book a demo.
- Trial
- 14 days
- Credit card
- Not required
- Refund
- Within 30 days of purchase