Privacy policy
Last updated: July 2026Time-Check processes personal data in accordance with the General Data Protection Regulation (GDPR). This policy describes, in plain terms, what data we process and why.
Data controller
HAY tech (Avenue de l'Exposition 402 / D1, 1090 Jette, company number BCE/KBO 0791.449.328), operating as Time-Check (time-check.be), is the controller for data collected through this site. For time records stored in the application, the employer is the controller and Time-Check acts as processor.
Data processing agreement
A data processing agreement (DPA) is concluded with every employer and forms an integral part of the service contract. Time-Check processes employee data only on the employer’s instruction and for the performance of the service.
Data we process
Account data (name, email address, language), company data (name, VAT number), working-time data (punches, corrections, approvals) and technical data (connection logs).
Signup request form
Data submitted through the signup request form (company, contact person) is processed by Time-Check as controller to review your request and prepare the contract (pre-contractual measures). If no contract is concluded, it is deleted no later than 12 months after the last contact.
No geolocation, no biometrics
Time-Check records no location data, no screenshots and no biometric data. A punch is a simple timestamp.
No profiling, no automated decision-making
Time-Check does not profile users and makes no decisions based solely on automated processing that produce legal effects for employees.
Purposes and legal bases
Providing the working-time registration service (performance of the contract), enabling the employer to meet its legal obligations, and securing and improving the service (legitimate interest).
Retention
Data is kept for the duration of the contract. Time records are kept for the applicable statutory retention period. After the account is closed, data is permanently deleted within 90 days, backups included.
Sub-processors
Data is never sold. It is shared only with our hosting and email providers established in the European Union and, on the employer’s instruction, with its payroll provider. The list of sub-processors is available on request.
International transfers
All data is stored in the European Union. No transfers outside the European Economic Area take place.
Security
Data is encrypted in transit and at rest. Access is role-based and logged, and regular backups are made. To report a vulnerability: security@time-check.be.
Note for employees
Your time records are processed on behalf of your employer. For questions about this data or to exercise your rights, please contact your employer first; we assist them in responding.
Communications
We send only the emails needed for the service (invitations, notifications, billing). Informational emails are sent only with your consent and always contain an unsubscribe link.
Your rights
You have the right to access, rectify, erase, restrict, object to and port your data, and to withdraw your consent at any time. Write to privacy@time-check.be; we respond within one month. You may also lodge a complaint with the Belgian Data Protection Authority (dataprotectionauthority.be).
Data breaches
In the event of a data breach likely to result in a risk, we inform the affected employer without undue delay so it can meet its notification obligations, and we notify the Data Protection Authority where the law requires it.
Changes
This policy may be updated. Any substantial change is notified to employers by email at least 30 days before it takes effect.
Questions? Write to us at privacy@time-check.be