Who sees what

Privacy

Schedura holds records about how people work — when they clocked in, what they logged, what they asked for. That is sensitive, and this page says plainly what we collect, why, who can see it, and how long we keep it.

Last updated Sep 21, 2026.

Two different relationships

Schedura is sold to employers. That means there are two distinct roles, and which one applies changes who you should talk to about your data.

  • Your employer is the controller of everything in their workspace — attendance, leave, timesheets, expenses, assets, requests. They decide what is collected, who is allowed to see it, and how long it is kept. We process it on their instructions, under our agreement with them.
  • We are the controller of a much smaller set: the account we hold for the person who signs up, billing records, support correspondence, and the operational logs we need to keep the service running and secure.

If you are an employee and want to see, correct or delete your records, start with your employer. We will help them, but we will not change or hand over their workspace data on an individual employee's request alone.

What we collect

  • Account and profile — name, work email, password (stored only as a bcrypt hash, never in readable form), role and permissions, department and job title, optional photo, phone number, date of birth and joining date where your employer records them.
  • Attendance — clock-in and clock-out times, breaks taken and their duration, and whether a day was worked remotely.
  • Location, only when your employer switches it on — if location tracking or office geofencing is enabled, we record the coordinates of the device at the moment of a punch, and the street address those coordinates resolve to. It is captured at the punch and at nothing else: Schedura does not track anyone continuously, in the background, or between punches. Your browser will ask your permission first. If the feature is off, no location is requested or stored.
  • Work records — timesheet entries and the projects or categories they are booked to, leave requests and balances, comp-off credits, expense claims and uploaded receipts, assigned assets and transfers, and requests or complaints raised through the staff desk (including ones marked confidential or submitted anonymously).
  • Availability check-ins — if your employer uses them, the random prompts sent, whether you responded, and the score and streak derived from that.
  • Assistant conversations — messages exchanged with the in-product assistant, on the web or over a connected chat app, are stored so the conversation persists between sessions.
  • Technical and security data — IP address, browser user agent, and a record of sign-ins, failed sign-in attempts and significant administrative actions.

Why we hold it

To operate the service your employer has asked us to provide: recording attendance, calculating balances, routing approvals, producing reports, and notifying the right people when something needs a decision. Separately, we hold a limited amount of data to keep accounts secure, to detect and investigate abuse, to bill our customers, and to meet our own legal obligations. We do not sell personal data, and we do not use your employer's workspace data to train machine-learning models.

Who can see it inside your workspace

Access follows permissions, not seniority. An employee with no permission flags sees only their own records plus what is company-wide by design: the team directory, the holiday calendar, celebrations and the engagement leaderboard. Each approval area is a separate permission, so a leave approver does not thereby get to see timesheets or expenses. An administrator can see everything in their own company and nothing in any other.

Requests marked confidential are visible only to their assigned handlers, and the notifications they trigger deliberately carry none of the content — just a pointer to open the case in the product. A request submitted anonymously does not carry the submitter's identity to the handler.

Who we share it with

We use a small number of processors to run the service. Each one only receives what its job requires, and none of them may use it for their own purposes.

  • Hosting and database — the application and its PostgreSQL database.
  • File storage — receipts, request attachments, profile photos and celebration images.
  • Email delivery — password resets, invitations and notification emails.
  • Slack, Telegram and WhatsApp — only where your employer has connected them and only for the categories they have chosen to route there. Message content reaches the relevant provider. An employee can pause their own notifications.
  • An AI provider — powers the assistant. The text of your conversation and a snapshot of the data needed to answer it are sent to be processed. Administrators can generate a short work-relevant summary of an employee's activity; that summary is generated on demand and never stored, and raw conversation transcripts are not exposed to administrators.
  • A job queue — schedules background work such as celebration posts.

We will also disclose data where we are legally required to, and we will tell the affected customer unless we are prohibited from doing so.

How long we keep it

Workspace data is kept for as long as your employer's account is active, because attendance and leave records are exactly the kind of thing employers are obliged to retain — often for several years. Your employer controls deletion within the product. When an account is closed, we delete or irreversibly anonymise its data within 90 days, except where we must keep something longer to meet a legal obligation such as tax records. Security and audit logs are kept on their own shorter schedule.

How it is protected

Traffic is encrypted in transit. Passwords are hashed with bcrypt and never stored or logged in readable form. Every query is scoped to a single company, so one customer cannot reach another's data. Administrative access to the platform console requires two-factor authentication, and every action taken there is written to an audit log. Support access to a customer workspace is read-only by default, time-limited, and recorded. Signed webhooks are verified before they are acted on.

No system is perfect. If a breach affects your data we will notify the affected customers without undue delay, along with any regulator we are required to inform.

Your rights

Depending on where you live, you may have the right to access your data, correct it, delete it, restrict or object to its processing, or receive a copy in a portable format. Employees should raise these with their employer, who controls the workspace. For the data we hold as controller — your account, billing and support history — write to us directly. You may also complain to your local data protection authority.

Cookies

Schedura sets only the cookies it needs to work: a session cookie that keeps you signed in, and a preference cookie remembering whether you last used the personal or the management view so the right layout renders on first paint. There is no advertising tracking and no third-party analytics cookie.

Changes and contact

We will update this page when the product changes in a way that affects it, and material changes are communicated to customer administrators rather than made quietly. Questions, requests or complaints: privacy@schedura.work, or write to [Registered company name], [Registered address].