EnglishNederlands

Privacy Statement

Last updated: 1 September 2026

Qfile B.V. processes personal data through OurTimetable. This statement explains which data we process, why, on what legal basis, for how long and what rights you have. It applies both to visitors of this website and to the employees whose data is held in the service.

Who is responsible?

For the data of the employees of a customer, the organisation of that customer is the controller; we are then the processor. What we do and do not do in that role is set out in the data processing agreement. If you are an employee and have a question about your data, please address it to your own employer.

For the data of our own account holders and of visitors to this website, we are the controller. Our details: Qfile B.V., Europalaan 40, 3526 KS Utrecht, the Netherlands, Chamber of Commerce (KvK) 97758388, info@ourtimetable.com.

Which data do we process?

  • Sign-up and account data: name, email address, organisation name, role and a password stored as a hash. In addition, if you use them, the two-factor authentication secret and recovery codes (both encrypted) and registered passkeys.
  • Employee data in the service: name, email address, telephone number, address, date of birth, payroll number, employment details, rosters and shifts, worked hours, leave, absence, availability, competencies, kilometres and the payroll export. Optionally also the IBAN and an emergency contact.
  • Absence data is data concerning health and therefore a special category of personal data (Article 9 GDPR). See the separate heading below.
  • Usage and security data: sign-in moments, active sessions including IP address and browser characteristics, security events including the source IP address, and an audit log recording who changed which data and when.
  • Billing data for the subscription: payments, invoices and their status.

Two things we deliberately do not process: the Dutch citizen service number (BSN) and the salary or hourly wage per employee. There is no field for them, and the integration with a personnel system rejects those categories outright. OurTimetable is a planning tool, not a payroll administration.

Absence and health

For a sickness report the service records the start and end date, who reported it, and a small number of support details drawn from fixed lists: the expected duration, whether the employee can be reached, whether (adjusted) work is possible, and which contact moment has been agreed. The fact that someone is ill is data concerning health. An employer may record that someone is ill and when, but not the complaints, the diagnosis or the treatment. That is why the service no longer has a free-text field on a sickness report: a reason for illness no longer fits anywhere, not even by accident.

We encrypt these support details separately, apply a retention period of two years to them, restrict absence data by role and by location, and record every change in the audit log. Notes dating from before this change are no longer returned by the service; HR or the administrator can count them and erase them in a single action. The full safeguards are set out in Article 5 of the data processing agreement.

For what purpose and on what basis?

  • Providing the service (rostering, hours, leave, absence, payroll export): performance of the contract with the customer. For the employees of the customer, processing rests on the legal bases the employer holds, as a rule performance of the employment contract and a legal obligation.
  • Absence registration: Article 9(2)(b) GDPR in conjunction with Article 30(1)(a) of the Dutch GDPR Implementation Act, for the support and reintegration of employees who are ill.
  • Security and fraud prevention (sign-in attempts, IP addresses in security events, audit log): our legitimate interest in a secure and reliable service, and a legal obligation where the law requires it. We have weighed the interests involved and consider this processing proportionate.
  • Billing and administration: performance of the contract and the statutory tax retention obligation.

We take no decisions with legal or similarly significant effects based solely on automated processing, and we do not carry out profiling. The roster and planning suggestions in the service are deterministic and are aids: a person decides.

Cookies and measurement

This website places no analytical or advertising cookies. There is no Google Analytics, no tag manager and no other measurement service running, and therefore no cookie banner is needed. We place only the strictly necessary cookies that make signing in work. What exactly is stored, with names and retention, is set out in our cookie policy.

How do we secure it?

The main measures: strict separation of data per organisation, encryption at rest of the sensitive fields (date of birth, IBAN, telephone number, address, postcode, emergency contact and the support details on a sickness report) with AES-256-GCM, encrypted connections through HTTPS with HSTS, passwords stored as hashes, two-factor authentication and passkeys, sessions that can be revoked immediately server-side, role-based access with a separate restriction per location, rate limiting and account lockout against brute force, an audit log with a hash chain that makes tampering visible, and encrypted backups whose restore is tested periodically. The full description is in Article 8 of the data processing agreement.

Retention periods

We do not retain data longer than necessary for the stated purposes or than legally required.

  • Account data is retained for as long as you have an account and up to 60 days after closure of the environment; after that we delete or anonymise it. Where a paid plan is merely cancelled, your account simply continues to exist.
  • Invoices and administration are retained for 7 years because of the statutory tax retention obligation.
  • Data we hold as a processor on behalf of a customer is retained in accordance with the instructions of that customer. The periods per category, including two years for the support details on a sickness report and seven years for clock entries, are set out in Article 13 of the data processing agreement.
  • Security events are retained for 180 days by default.

Where does the data come from?

Sign-up and account data we receive directly from you. Employee data we receive from the employer using the service, or from the employee themselves when they submit availability or clock in, for example. If the employer uses an integration with a personnel system, the master data comes from there; that integration never supplies a citizen service number or pay data.

Who receives the data?

  • Hosting and email: TransIP B.V., the Netherlands.
  • Payments: Mollie B.V., the Netherlands. The payment provider receives the amount and a reference to the organisation, no names or employee data.
  • Push messages: where push notifications are enabled, delivery runs through the push service of the browser or operating system of the employee. The content is encrypted and readable only by the device.
  • Voice input (optional): anyone using voice input has their browser download the recognition model once from Hugging Face and a public software archive. The speech and the recognised text stay on the device.

We do not sell data and do not use it for advertising. The current list of sub-processors is in Article 10 of the data processing agreement. No language model or AI service is engaged: the assistant in the service runs deterministically on our own server.

Transfers outside the EEA

No personal data is stored or processed outside the European Economic Area. Should this change in future, it will only happen with a valid transfer mechanism, such as an adequacy decision or standard contractual clauses.

Your rights

You have the right to access, rectification, erasure, restriction, objection and portability of your data. Where we process data on the basis of your consent, you may withdraw that consent at any time; pursuant to Article 7(3) GDPR this does not affect the lawfulness of processing carried out before the withdrawal.

To exercise a right regarding data for which we are the controller, send a request to info@ourtimetable.com. To prevent misuse we may ask you to identify yourself. We respond within one month at the latest; for complex or numerous requests we may extend that period by two months and will tell you so within the first month.

If the request concerns data held in the environment of your employer, it runs through your employer. The service contains a built-in access export for this: HR can compile everything the service holds about one person into a file in a single action.

You can always lodge a complaint with the Dutch Data Protection Authority (Autoriteit Persoonsgegevens).

Changes

We may amend this statement. The current version is always on this page, with the date of last amendment at the top. For significant changes we inform you actively, for example through a notification in the app or by email.