Legal

Privacy policy

How TeamOS collects, uses and protects personal data, both yours and your employees'.

Draft, not yet in force. Last revised 13 September 2026.

1. Who we are

TeamOS is staff management software. Businesses (“customers”) use it to hold employee records and to run attendance, leave and approvals for their own staff.

2. Two different roles

This distinction determines nearly everything else in this policy, so it comes first:

When your company is set up on TeamOS and you use it
We are the data controller for your account details, your name, email address, sign-in records and billing information. We decide how that data is used.
When you store your employees' data in TeamOS
You are the controller and we are the data processor. We hold and process employee records on your instruction. We do not decide what goes in, we do not use it for our own purposes, and we do not sell it.

3. What we collect

Account data (we are the controller)

  • Name and work email address
  • Company name and the workspace address you choose
  • Password, stored only as a cryptographic hash, never in readable form
  • Sign-in timestamps and IP address, for security and abuse prevention
  • Billing status and payment references

Employee data (your customers' data, we are the processor)

What is held depends on what you enter, but typically includes:

  • Employee name, contact details, role, department, assigned office, manager and start date
  • Attendance records
  • Leave requests, leave types, balances and approval decisions
  • A permanent record of changes to someone's role, department, office, manager or status, including the reason recorded when someone leaves
  • An audit trail of who changed what, and when

What we deliberately do not collect

  • No location data. This release has no mobile app and records no coordinates.
  • No biometric data, ever. No fingerprints and no face recognition. This is a permanent decision, not a gap.
  • No salary, bank or payment details. Payroll is not part of this release.
  • We do not use advertising cookies or third-party trackers.
  • Our error monitoring is configured to strip personal data before it is sent. Employee names, emails, leave reasons and attendance records are never transmitted to it.
  • We do not sell personal data to anyone, in any circumstances.

4. Why we use it

  • To provide the service to your company (performance of a contract).
  • To keep accounts secure, rate limiting, sign-in monitoring and abuse prevention (legitimate interests).
  • To send transactional email: invitations, password resets and address verification (performance of a contract).
  • To meet legal, tax and accounting obligations (legal obligation).

5. Where data is stored

TeamOS data is hosted in Europe (London and Western Europe). There is no data-centre region in Africa offered by our infrastructure providers, and London is the nearest point to Nigeria with reliable connectivity. Data is transferred and stored under appropriate safeguards for international transfer.

6. Who else processes data

We use the following subprocessors. Each is contractually bound to protect the data and to process it only on our instruction:

ProviderPurposeRegion
NeonDatabase hosting, the primary data storeLondon
NetlifyApplication hosting and deliveryGlobal edge
CloudflareDNS; object storage for logos and exports when enabledWestern Europe
ResendTransactional email delivery
UpstashRate limiting and short-lived cachingEU West
SentryError monitoring, with personal data strippedEU

7. How long we keep it

Employee data is kept for as long as the customer's account is active, because it is the customer's record to control. When an account is closed, data is deleted after a short grace period during which it can still be recovered or exported.

8. Your rights

Depending on where you are, you have rights to access, correct, delete, export and restrict the processing of your personal data, and to object to it.

If you are an employee of a company using TeamOS, your employer controls your records, please contact them first. We will support them in responding to you, but we cannot change their data on your behalf.

Customers can export their full account data at any time, including while an account is suspended or a payment is overdue. Your data is yours, and we will not hold it hostage.

9. Security

  • All traffic is encrypted in transit.
  • Passwords are hashed; nobody at TeamOS can read them.
  • Each customer's data is isolated, and every query is scoped to a single company.
  • Access is role-based, and every change is written to an audit log.

No system is perfectly secure. If a breach affects your data, we will notify you and the relevant authority as required by law.

10. Cookies

We use one cookie, to keep you signed in. It is essential to the service and is not used for tracking or advertising. There are no analytics or advertising cookies on this site.

11. Changes to this policy

We will post any changes on this page. Material changes affecting how personal data is used will be communicated by email before they take effect.

12. Contact

Questions about this policy can be sent to privacy@teamos.work, or through our contact page.