User Declaration
Last updated: 27 July 2026
This user declaration describes what you undertake when you use OurTimetable, and which use is and is not permitted. It supplements the terms and conditions and the privacy statement; in the event of a conflict, those documents prevail.
1. Authority
You declare that you are authorised to act on behalf of the organisation that gave you access to OurTimetable. If you act on behalf of an organisation, you bind that organisation to the use of the service and to the applicable terms. If you are not so authorised, do not use the service under this account.
2. Lawful use
You use the service solely for lawful purposes and in accordance with the law, including the Dutch Working Hours Act, the applicable collective labour agreement and the GDPR. You do not use the service for unlawful, misleading or harmful acts, nor in a way that harms the service, other users or third parties.
The following is expressly not permitted:
- attempting to access data of another organisation or of colleagues beyond your own permissions;
- circumventing or testing the security without our written permission, including automated scanning of the service and load testing;
- reverse engineering, copying, reselling or offering the software as your own service;
- loading the service to the detriment of other customers, for example with artificial traffic or large volumes of fake data;
- sharing or transferring accounts, or using an account that was not issued to you;
- entering unlawful, abusive or discriminatory content in the free-text fields, such as the note on a shift or a leave request;
- using the service to monitor employees beyond what is necessary for planning and time accounting.
3. Accuracy and data of others
You are responsible for the accuracy, completeness and lawfulness of the data you enter or import. This applies equally, and especially, to the personal data of others: your colleagues, agency workers, self-employed contractors and flexible pool staff.
You declare that you have a valid legal basis for processing that data, that you have informed the data subjects where required, and that you record no more data than is necessary for planning, time accounting and payroll processing.
4. Absence: do not record what you may not record
This point deserves its own heading, because in practice it goes wrong most often. An employer may record that an employee is ill and over which period. An employer may not record what the complaints are, what the diagnosis is, which treatment is under way or which part of the body is involved. This applies even where the employee volunteered the information and has no objection.
On a sickness report there is no longer a field for it: the free-text note has been withdrawn. The service now only asks about the practical side of the absence, with fixed options: the expected duration, whether the employee can be reached, whether (adjusted) work is possible, and which contact moment you have agreed. We encrypt those details and keep them for two years. Anything medical belongs with the company doctor or the occupational health service and should not be recorded anywhere in this service, so not in the note on a shift, on a swap request or on a leave request either.
5. Account and confidentiality
You keep your login details confidential and do not share your account with others. Actions taking place under your account are attributed to you, unless you make it plausible that this happened without your involvement. If you suspect that someone else has access to your account, change your password immediately and alert your administrator.
If you work with a shared kiosk or time clock, the PIN is personal. Never clock in or out on behalf of someone else, and do not let anyone do it for you: the clock entry is the basis for time accounting and payroll processing.
6. Roles and permissions
Administrators assign roles and locations. Do not grant more permissions than someone needs: the right to view the personal data of employees is deliberately a separate permission and does not belong to the manager role by default. Assign a manager only the locations they actually manage. If someone leaves or a role changes, adjust it straight away.
7. Reporting misuse and security issues
If you notice misuse, a security issue or a possible data breach, report it without undue delay to your administrator and to us at info@ourtimetable.com. Do not publish a discovered vulnerability before we have had a reasonable opportunity to fix it. We take reports seriously and will keep you informed.
8. Your own responsibility
The service is an aid and does not replace legal, tax or employment law advice. The signals about rest periods, contract hours and premiums come from the rules you configured yourself; check a roster and a payroll export before you finalise or send it. In addition, periodically export the data you wish to keep.
9. Consequences of a breach
Where misuse is suspected, we may investigate. In the event of a serious or repeated breach we may suspend an account or an environment and, ultimately, terminate the agreement. We always choose the lightest measure that suffices and, where possible, we contact you first. Where there is an acute risk to the security of data we may intervene immediately and explain afterwards.
10. Changes to this declaration
We may amend this user declaration. The current version is always on this page, with the date of last amendment at the top. If you continue to use the service after an amended declaration, the most recent version applies.