Data security

Time and attendance data security at Computime

A time and attendance system holds some of the most sensitive information your business collects. Working hours, absence records, and in many cases biometric data that counts as special category data under the UK GDPR. This page sets out how Computime protects that data, what we can tell you about our systems, and what you remain responsible for as the employer.

Computime has built and supported workforce management software in the UK since 1989. Our software is developed by our own team in Leeds, and our support is answered by the same people who build it.

The short version


Computime is a UK company based in Leeds, trading since 1989. Our software is written and supported here, not offshore.

We supply two systems. Syncro Connect is cloud based and accessed through a browser or mobile app. Realtime is installed software. The way your data is held differs between them, and both are covered below.

Biometric clocking data is special category data under the UK GDPR. Employers using it need explicit consent and a completed Data Protection Impact Assessment before deployment, in line with ICO biometric recognition guidance.

Because we supply card and fob clocking terminals alongside biometric ones, you can offer employees a genuine alternative to biometrics on the same system, from the same supplier.

You remain the data controller for your workforce data. Our guide to UK GDPR and time and attendance data explains what that means in practice.

Completely free trial · No card required · UK support from our Leeds team

Hosting

Where is your workforce data stored?

All Computime customer data is held in the United Kingdom. Nothing is stored or replicated overseas. Where it sits depends on which of our two systems you use, and for Realtime, on how you choose to run it.

Syncro Connect

Cloud hosted

Hosted in UK data centres by Hyve Managed Hosting, a UK headquartered provider. Your data does not leave the country.

Hyve’s facilities hold ISO 27001, ISO 27017 and ISO 9001 certification, are PCI DSS compliant, and Hyve has been on the UK government’s G-Cloud framework since 2013.

Realtime

Installed, you choose

On your own server. The database sits inside your network, under your control. Computime holds no copy, and your existing policies apply to it.

On our hosted platform. If you would rather not run a server, we host Realtime through ANS, a UK provider, with data held in the UK.

Those certifications belong to our hosting provider rather than to Computime, but they are the standards the infrastructure your data sits on is built and audited to. If a tender needs written confirmation of data location, ask us.

Access

Who can get to your data, and how is that controlled?

Most data protection questions come down to a simple one: who can see this, and is there a record of it. Here is our answer.

01

Two factor on Syncro Connect

Syncro Connect supports two factor authentication, using either an authenticator app or email verification, so a password alone is not enough to reach your data.

02

Restricted internal access

Only our technical support and installation teams can access customer data, and only to install, configure or support your system. Nobody else at Computime can.

03

Access is auditable

That access is logged and auditable, so there is a record of who looked at what and when. Viewing an enrolled facial image is separately restricted and logged.

A note on Realtime

Realtime is installed software and signs in with a username and password rather than two factor. Where it runs on your own server, inside your network, your own network security and access policies sit around it. If two factor authentication is a requirement for you, Syncro Connect is the system to look at.

Biometric data

What does a biometric clocking system actually store?

This is the question we are asked most, and it deserves a direct answer rather than reassurance. Biometric clocking data is special category data under the UK GDPR. What is held differs between fingerprint and face, so here is each.

Fingerprint clocking

No fingerprint image is stored. At enrolment the fingerprint reader converts the characteristics of the fingerprint into a mathematical template, and that template is what is saved. Every clocking is matched against it.

The process does not run in reverse. A fingerprint cannot be reconstructed from the template, by us or by anyone else. If the data were obtained, it could not be turned back into a usable fingerprint.

Facial recognition clocking

Facial recognition works the same way at the point of clocking, matching against a template rather than comparing photographs. One difference is worth stating plainly: the software can display a viewable image of the enrolled face, so an administrator can confirm who is registered and spot enrolment errors.

That image is not held as a file. It cannot be downloaded or exported. It sits in a restricted area of the software, access is limited, and every viewing is logged.

We would rather say this than describe our facial recognition as image free, because it is not, and anyone completing a Data Protection Impact Assessment needs the accurate version.

Where templates are held

In two places: on the clocking terminal, so it keeps working if the network drops, and in the system database. Both matter when you remove a leaver, and we explain deletion across both below.

What the regulator says

In 2024 the ICO ordered Serco Leisure to stop using facial recognition to monitor staff attendance, because employees were not offered a clear alternative and the necessity of the technology had not been demonstrated. The ICO’s biometric recognition guidance sets out what compliant use looks like. It is worth reading before you commit to any biometric system, whoever supplies it.

You do not have to use biometrics at all

Card and fob terminals run on the same software and produce the same timesheets, and our mobile clocking in app clocks staff with no terminal at all. If you would rather not process special category data, or you need an alternative for employees who decline biometric clocking, it is on the same system rather than a second one.

For the legal side, including when explicit consent is required and why a DPIA must be completed before deployment, see our guide to UK GDPR and time and attendance data. Terminal options and prices are on our clocking system pricing page.

Backups

What happens if something goes wrong?

Attendance data feeds payroll, so losing it is not a minor inconvenience. Backups run automatically and are tested rather than assumed.

Frequency

Backed up daily as standard

Location

Held in the UK, like your live data

Testing

Restores are tested, not assumed

Backup frequency can be changed if your business needs something different. Where Realtime runs on your own server, backups are part of your own regime, and our installation team will talk you through what to include.

Retention and deletion

How do you delete data when it is no longer needed?

Keeping personal data longer than you need it is itself a compliance failure. Here is what happens in each situation, including one step that people frequently miss.

Situation What happens
You delete an employee record The record is removed from the database, and any biometric template and enrolled facial image go with it.
The clocking terminal This is the step people miss. Terminals hold their own copy of the template so they keep working offline, so deleting from the software does not clear the device. The employee must also be removed at the terminal. Our help centre and support team will show you how, and it is worth building into your leaver process.
You leave Computime Your data is deleted when the contract ends. Before that, we offer you an export so you keep your records for the statutory periods you are required to.
Realtime on your own server The database is yours, so deletion is under your control. The terminal step above still applies.

Statutory retention periods for attendance, holiday and payroll records, including the six year requirement under the Employment Rights Act 2025, are set out in our UK GDPR guide.

Your compliance

How does Computime support your GDPR compliance?

When you use a Computime system, you are the data controller for your workforce data. The decisions about what you collect, why, and how long you keep it are yours to make and to document. We cannot make them for you, but we can make them considerably easier.

A plain English guide to the rules

We maintain a detailed guide to UK GDPR and time and attendance data, covering lawful basis, when biometric clocking becomes special category data, what you must tell your workers, statutory retention periods, and the ICO’s enforcement action against Serco Leisure. It is free, it is kept current, and you do not need to be a customer to read it.

Help with your Data Protection Impact Assessment

A DPIA is mandatory before you deploy any biometric clocking system, and it has to be completed before processing begins rather than after installation. Most businesses have never written one. The ICO publishes guidance on biometric recognition that is the right starting point.

If you are buying a biometric system from us, ask and we will talk you through it. We have installed these systems for over 30 years and we can tell you what the assessment usually needs to cover, what questions tend to come up, and where businesses commonly get stuck. Nobody has to start from a blank page.

A genuine alternative to biometrics, on the same system

The ICO’s position is that employees must be able to refuse biometric clocking without penalty, which means offering a real alternative rather than a token one. That requirement has caught out employers who bought a biometric-only system and then had to find a second solution for anyone who said no.

We supply card and fob terminals alongside our biometric ones, running on the same software, reporting into the same timesheets. You can mix them across a site, or across your workforce, without buying anything twice.

What this support is, and what it is not

Our guidance is offered informally and in good faith, based on our experience of installing time and attendance systems in UK workplaces. It is not legal advice and it is not a substitute for it. Responsibility for your compliance stays with you as the data controller, and for anything of consequence you should take qualified data protection or employment law advice for your own circumstances.

Questions about how any of this applies to your business? Speak to our Leeds team and you will get a straight answer from someone who knows the system.

Questions

Data security FAQs

Where is my time and attendance data stored?

All Computime customer data is held in the United Kingdom. Syncro Connect is hosted in UK data centres by Hyve Managed Hosting. Realtime is installed software, so you can either hold the database on your own server inside your own network, or use our hosted platform, which runs through the UK provider ANS. Nothing is stored or replicated outside the UK.

Does Computime store employee fingerprints?

No. No fingerprint image is stored at any point. When an employee enrols, the reader converts the characteristics of their fingerprint into a mathematical template, and it is that template which is saved and matched against at each clocking. The process does not run in reverse, so a fingerprint cannot be reconstructed from the stored template by us or by anyone else.

Does facial recognition clocking store photographs of employees?

Clocking is matched against a template rather than by comparing photographs, but the software can display a viewable image of the enrolled face so that an administrator can confirm who is registered. That image is not held as a file and cannot be downloaded or exported. It sits within a restricted area of the software, access to it is limited, and every viewing is logged.

Who at Computime can access my data?

Only our technical support and installation teams, and only in order to install, configure or support your system. That access is logged and auditable, so there is a record of who accessed what and when. Viewing an enrolled facial image is separately restricted and separately logged.

Does Computime support two-factor authentication?

Syncro Connect supports two-factor authentication using either an authenticator app or email verification, so a password on its own is not enough to reach your data. Realtime is installed software and signs in with a username and password, sitting behind your own network security. If two-factor authentication is a requirement for your business, Syncro Connect is the system to look at.

What happens to biometric data when an employee leaves?

Deleting the employee record removes it from the database, and any biometric template and enrolled facial image go with it. There is a second step that is easy to miss. Clocking terminals hold their own copy of the template so that they keep working if the network drops, so the employee must also be removed at the terminal itself. Our support team will show you how, and it is worth building into your leaver process.

How often is my data backed up?

Daily as standard, held in the UK alongside your live data, and restores are tested rather than assumed. Backup frequency can be changed if your business needs something different. Where Realtime runs on your own server, backups form part of your own regime, and our installation team will talk you through what to include.

What happens to my data if I stop using Computime?

Your data is deleted when the contract ends. Before that happens we offer you an export, so that you keep the records you are required to retain for statutory periods. Where Realtime runs on your own server, the database is yours and deletion is under your control.

Do I need employee consent to use biometric clocking?

Biometric clocking data is special category data under the UK GDPR, and the ICO’s published position is that explicit consent is likely to be the only viable condition in most workplace scenarios. Consent must be freely given, which means offering a genuine alternative that carries no penalty for choosing it. A Data Protection Impact Assessment is also mandatory before deployment. Our guide to UK GDPR and time and attendance data covers this in detail.

Can I use a Computime system without biometrics?

Yes. Card and fob clocking terminals run on the same software and produce the same timesheets, and our mobile app clocks staff with no terminal at all. If you would rather not process special category data, or you need an alternative for employees who decline biometric clocking, it is available on the same system rather than as a second one.

Left Menu Icon