Privacy Policy
Version 2026-08-v4. Last updated 25 August 2026. Effective from 25 August 2026.
Privacy Policy
Version 2026-08-v4. In force from 25 August 2026.
This policy explains what OtisIO does with personal information, who is responsible for it, and what you can do about it.
Start with the section that describes you. The rest will still be there if you want it.
- If you use OtisIO because your employer gave you an account
- If your business is our customer
- If you visited our website or contacted us
Who we are
OtisIO is a product of Siege One Limited, a company registered in England and Wales with company number 17110871, registered office 38 Angelica Avenue, Stotfold, Hitchin, England, SG5 4HH.
We are registered with the Information Commissioner's Office under registration number ZC206586.
For anything in this policy, write to privacy@otisio.com.
We are workforce management software. Businesses use us to build rotas, record when people start and finish work, keep employment records, assign tasks and communicate with their teams.
The most important thing in this policy
For most of the information in OtisIO, we are not the ones who decide what happens to it.
If your employer gave you an OtisIO account, your employer decides: whether to use OtisIO at all, what to record about you, who can see it, whether face clock-in or location is switched on, and how long things are kept. In data protection language they are the controller and we are the processor. We hold and process the information on their instructions, and we do not decide what to do with it.
That matters when you want something changed or deleted. Ask your employer first. If you ask us, we will pass your request to them and help them action it, but we cannot overrule them. There are two things you can do yourself without asking anyone, and they are set out at section 1.9.
We are the controller, and fully responsible, for a narrower set of things: our own website, our marketing, the accounts and billing details of the businesses that buy from us, our own security and service records, and the product analytics described at section 1.7.
1. If you use OtisIO because your employer gave you an account
Your employer decides what is in this section. Not all of it will apply to you, because much of it depends on what they have switched on.
1.1 What is held about you
Who you are at work. Your name, work email address, phone number, job title, start date, employee or payroll number, the team and site you belong to, a profile photo if you have one, your date of birth if your employer records it, and an emergency contact if you have given one.
Your rota and your hours. The shifts you are scheduled for, shifts you claim or swap, when you clocked in and out, your breaks, overtime, and the timesheets those add up to. Every correction a manager makes to your recorded hours is logged, including who made it and when.
Your pay. Your hourly or salaried rate and its history, your pay type, and expense claims you submit.
Payroll and bank details, where your employer asks you for them. OtisIO has a payroll profile that a worker fills in themselves, usually as part of joining. It holds your home address, your National Insurance number, and your bank sort code and account number. All four are encrypted individually where they are stored. When a manager opens your record they see your National Insurance number and your bank details masked to the last few digits only; your home address is shown to them in full. Nothing in this profile is ever sent to any of the suppliers listed at section 1.6.
Time off. Leave requests, balances, and absence records. If you give a reason for an absence, that reason is stored. Reasons are free text, so they may include information about your health.
Your work. Tasks you complete, checklists you tick, forms you fill in, photos you attach as evidence, signatures you draw, equipment signed out to you, and patrol checkpoints you scan.
What you say. Messages you send in OtisIO chat, comments, announcements you have read or confirmed, survey answers, and recognition you give or receive.
Please note: OtisIO chat is your employer's system, not a personal messenger. Administrators in your workspace can see messages in it.
Documents about you that your employer uploads: right to work documents, certificates, licences, training records, and in some workplaces DBS or equivalent checks.
Your device. A push notification token if you allow notifications, a device identifier, the IP address the request came from when you sign in, and your session history.
How you sign in. If you sign in with a password we store a hash of it and never the password itself. If you use Sign in with Apple or Sign in with Google we store the account identifier that provider gives us and the email address it releases, which in Apple's case may be a private relay address rather than your real one. If your employer has connected its own single sign-on, we store the identifier its system sends us. We do not receive your password for any of those accounts.
1.2 Where you were when you clocked in
Only if your employer has switched this on.
The app asks your phone for one location reading at the moment you clock in and one at the moment you clock out. That is all.
We do not track you in the background. The apps only ever ask for "while using the app" location permission and only ever take a single reading on demand. Neither app has the background location capability that a phone requires before it will report your position with the app closed: the Android app does not request background location, and the iOS app declares no location background mode. There is no live map, and nothing is recorded between clock events or during breaks.
If your employer has drawn a boundary around a site, we work out how far away you were and flag it for a manager to look at. The flag does not stop you clocking in. A poor GPS reading never prevents your hours being recorded.
If you refuse the location permission, or your phone cannot get a fix, the clock still works and the punch is simply marked as having no location.
Your location readings are never sold and never used for advertising.
Photographs. Every photograph you upload is re-encoded before it is stored, which removes the metadata your camera writes inside the image file, including any GPS position it recorded. A stored photo therefore does not carry where it was taken.
1.3 Photographs at clock-in, and face clock-in
These are two different things and it matters which one your workplace uses. People often assume that any camera at a clock-in point is facial recognition. In this product it usually is not.
| A photograph when you clock in | Face clock-in | |
|---|---|---|
| What happens | A picture is taken and saved next to your timesheet entry | Your face is measured, turned into numbers, and compared |
| Is anything measured from your face? | No. Nothing is calculated, no template is made | Yes. A template is worked out from your face |
| Is it compared against anything? | No. Never. Not against you, not against anyone else, not by any system | Yes, that is the whole point of it |
| What kind of information is it? | An ordinary photograph, the same kind of information as a signature or a photo at a site entrance | Biometric data used to identify you, which is special category data under Article 9 of the UK GDPR |
| Which plans have it? | Available on most plans | Only on the top plan, and only where the employer has switched it on |
The rest of this section deals with each in turn. If your workplace only takes a photograph, the paragraphs about templates, recognition, consent and Article 9 do not apply to you at all.
A photograph when you clock in
If your employer has this on, the product takes a picture at the moment you clock in or out and saves it against that timesheet entry. Nothing is measured from it. No face template is created from it. It is never compared against any other face or picture, by us or by any system. It is there so that your employer can see who pressed the button, in the way a signature shows who signed.
Because nothing is measured from it, it is not biometric data and it is not special category data. It is an ordinary photograph of you, which is still personal data, and your employer still has to tell you it is being taken and have a lawful reason for taking it. It is kept for 45 days by default and then deleted automatically, and your employer can choose a shorter period.
A photograph would only become biometric data if it were put through technology that measures a face in order to work out or confirm who somebody is. That is what the next part is about, and it is a separate feature on a separate plan.
Face clock-in
Some workplaces use face clock-in, where you are recognised by your face instead of typing a code. Face templates and the images used for recognition are biometric data used to identify you, which is special category data under Article 9 of the UK GDPR, so the rest of this section sets out exactly what happens.
It is off unless your employer has switched it on, and your employer is the controller for it. They decide whether it is used and what someone who does not take part does instead. Before it can be switched on, the product requires the business to confirm that it has completed a data protection impact assessment. Your employer is also responsible, before using it, for telling its staff, putting an appropriate policy document in place, and settling what it offers people who do not take part.
The legal basis is your employer's to state, and it needs two parts. They must have a basis under Article 6, which for biometric clock-in is normally your explicit consent or their legitimate interests, and a separate condition under Article 9, which for a workplace biometric is normally your explicit consent. Because consent has to be freely given, that is why the alternative below exists and why it cannot be taken away.
There is always another way to clock in. A code entry method is built into the product and no setting can switch it off. Nobody can be required to give a biometric in order to record that they were at work. If you say no to enrolling your face, your employer is told that you clock in by code instead, and your contract with us requires them to keep that route open to you.
What happens if the check does not agree it is you. Your employer chooses between two settings for each workplace. On one, the attempt is recorded against your timesheet entry so a manager can look at it, and you are clocked in regardless. On the other, the clock-in is refused and you use your code instead. Clocking out is never refused, and a face check never decides your pay by itself. If you are not sure which setting your workplace uses, ask your employer: they control it, not us.
Your employer cannot agree to this for you. Most of what an employer decides about the product it decides on your behalf, which is normal and is how workplace software works. Facial recognition is one of the few things that is different. Because it measures your face, the law requires your own explicit consent, and an employer cannot give it for you. So the product asks you directly: it shows you the wording, you tick to accept it, and we record which version of the wording you were shown and when you accepted it. If you do not tick it, you are not enrolled and nothing about your face is measured or stored. Your employer has agreed with us, in their contract, that you can say no and use a code instead, and that saying no must not be held against you.
What a face template is. A fixed list of 128 numbers worked out from images of your face. It is not a photograph, it cannot be looked at, and it cannot be turned back into a picture of you. It is stored encrypted against your record, together with the date you consented and the exact wording you were shown.
Where the recognition happens, which depends on where you clock in. There are two ways this works and we describe both rather than only the flattering one.
At a shared clock-in device at your workplace. The templates for everyone enrolled at that workplace are sent down to the device and held in its encrypted secure storage, where they expire if the device goes 24 hours without a successful connection to us. The camera image is compared against those templates on the device itself, because the device has to work out which of you is standing in front of it. When someone is recognised, the device sends us only who it was and a rough confidence band. On a successful clock in or out at a shared device, neither the image nor the numbers are sent to us.
On your own phone or in a browser. Here the product already knows who is signed in, so it is only checking that the face is yours. In this case the photograph is sent to us, and we work out the numbers and do the comparison on our own servers. The numbers exist only for the moment of the comparison and are never saved, written to a log, or passed on to anyone. The photograph is kept in the same way as any other clock-in photograph, on the timescales below.
Face detection on the device uses a component supplied by Google that runs entirely on the device. No image is sent to Google. No face image and no face template is ever sent to any external face recognition service, and never to an artificial intelligence provider. There is no third party facial recognition supplier anywhere in this product.
When face images are kept. This depends on how you enrolled and how your employer has set things up.
- If you enrol at a shared clock-in device at your workplace, the pictures are measured on the device itself and no image ever leaves it. Only the resulting numbers are sent to us. There is no photograph of your enrolment for anyone to store, look at or ask us for, because we never receive one.
- If you enrol from the OtisIO staff app, the selfie you take is sent to us, converted into a template, and not stored.
- If you enrol from a web link your employer sends you, the images taken during enrolment are stored alongside your template, so your employer can confirm the enrolment is really you and so your template can be rebuilt if we improve the underlying software. They are kept while you stay enrolled and deleted with your template.
- If a clock-in attempt matches nobody, that single frame is kept for a manager to review, because a non-match is how an unauthorised clock-in is caught.
- If your employer requires a photo at clock-in, that photo is stored against the timesheet entry.
How long clock-in images are kept. One daily job sweeps both kinds of image, on two separate clocks. The first is the ordinary photograph described at the top of this section, which is not biometric data. The second is a frame kept from a facial recognition attempt that matched nobody.
- Photographs taken at clock-in: 45 days unless your employer has chosen a shorter figure.
- Frames from an attempt that matched nobody: 30 days unless your employer has chosen a shorter figure.
An employer can shorten either, and if they shorten the non-match window the clock-in photograph window follows it down. Neither can go beyond 90 days, which is enforced in the product and no setting overrides it. That outer limit is a single ceiling the product applies to every image taken at a clock-in point, whether or not any face was measured from it; it is not a statement that an ordinary clock-in photograph is biometric data.
The window runs from the day the image was captured, or, once a manager has made a decision about it, from the day of that decision, so an image is not deleted the moment somebody looks at it. Where the system clears an attempt itself, because the same person was recognised correctly moments later, the image is deleted straight away.
Deleting the image does not delete the record that the attempt happened. We keep an entry recording the time, whether the check found a live person, a rough confidence band, and who a manager confirmed it was. That entry holds no image and no template, it is not swept by any deletion job, and it is kept for as long as your employer keeps their other timekeeping records, because it is the audit trail of who clocked in.
Who can see face images. They are held on private storage that cannot be reached from the public web, kept separately for each workplace. Only administrators your employer has specifically granted the face review permission can open one, and every single time somebody looks at a face image it is written to an access log and to your employer's audit trail, recording who looked and when.
Visitors. Where a business uses face recognition for visitor sign-in, the visitor's face data is held for a fixed 7 days, which an employer cannot extend, and is then deleted automatically whether or not the visit was completed.
We never sell or share face data. It is never used for advertising, marketing or profiling, and never shared with anyone for their own purposes. It is used for one thing: establishing who is clocking in or out. It is not used to follow where you are or what you do.
How to get your face data deleted. You can delete your own face template in the OtisIO app, under Settings, without asking anyone. That removes your template and any enrolment images stored with it, and clock-in devices at your workplace drop you at their next sync. You can also ask any administrator in your workspace to do it, or email us at privacy@otisio.com and we will action it.
Deleting your template does not remove non-match frames or clock-in photos already recorded against your timesheet. Those are removed by the retention windows above, and you can ask your employer or us to remove them sooner.
1.4 What the phone app does and does not do
Photos you take or choose are uploaded when you attach one to a task, a form or a message, or where your employer requires a photo at clock-in. Messages you send are stored on our servers so they can be delivered and read later.
The app registers a device identifier and a push notification token so notifications reach the right phone. Both are deleted when you sign out or delete your account.
When the app crashes or cannot reach us, it sends a fault report to our own error inbox so we can fix it. That report carries the error, the app version, your device's operating system version, and, if you are signed in, the account it happened to. It never contains your workspace's content. We use no third party crash or error reporting service.
If you unlock the app with Face ID, Touch ID or a fingerprint, that check happens entirely on your phone, by your phone's own operating system. Your fingerprint or face is never sent to us and we never see it. All the app receives back is a yes or a no.
The app does not record audio, does not read your files or documents, contains no advertising, and contains no third party analytics or session recording software. The session recording described at section 1.7 runs on the web app only and is not in the phone app.
1.5 Why this is allowed
Your employer decides the lawful basis for everything in your workspace and is responsible for telling you what it is. Typically it will be their legitimate interests in running their business, their contract with you, or a legal obligation such as keeping working time and pay records or checking your right to work.
For special category information, such as health implied by an absence record, or face data, your employer must have an additional condition under Article 9 and, where relevant, an appropriate policy document. Their contract with us requires it.
We do not decide your employer's lawful basis and we do not tell them their processing is lawful. If you want to know what they rely on, ask them; they are required to tell you.
The one thing in this section we decide ourselves, as controller, is the product analytics at section 1.7.
1.6 Who else sees your information
We use a small number of suppliers to run the service. Each acts only on our instructions, under a written contract, and none may use your information for their own purposes.
| Supplier | What they do | What they see |
|---|---|---|
| Hetzner | Runs the servers your data lives on, and holds the off-site backups | Everything, at rest. The off-site copy is encrypted by us before it leaves our server, so Hetzner cannot read it |
| Cloudflare | Runs the DNS for our domain, and the bot check on our sign-in, sign-up and contact forms | Your IP address when the bot check runs. Cloudflare does not carry our traffic: the service is served directly from our own servers, and Cloudflare does not terminate our encryption or see the contents of a request |
| Microsoft | Session recording on the signed-in web app and on our public pages. See section 1.7 | A masked recording of the screen layout and where you clicked, plus your IP address, browser and rough location |
| Brevo | Sends our emails | Your email address and the contents of the email |
| Twilio | Sends text messages, where your employer uses SMS | Your mobile number and the message |
| Expo | Delivers push notifications to your phone, where your employer has the app and notifications switched on | Your push token and the notification text, which can include your name and shift details. Expo is the only notification supplier that can read the whole message |
| Apple and Google | Distribute the mobile apps, and carry a notification the last step to your device | That you downloaded the app, under your own Apple or Google account, and the delivery details of a notification |
| OpenStreetMap Foundation | Draws the map when a manager sets a site boundary or looks at a location, and turns a typed address into a point on that map | The map squares being looked at and the site address text that was typed, together with the manager's browser IP address. These requests are made from the manager's own browser. No worker record is ever sent |
| Anthropic | Reads a photographed receipt to fill in an expense claim, and interprets a typed instruction in the scheduling assistant, where your employer uses those features | The receipt image, or the sentence typed into the assistant. See below |
| Xero, QuickBooks Online, Sage Business Cloud, FreeAgent, BrightPay Connect or Staffology by IRIS | Receives approved hours, if your employer connects one | Your name, payroll identifier and approved hours. No home address, National Insurance number or bank details are sent |
Apple's live clock timer, and what Apple can read. If you use the iPhone app, the running clock that appears on your lock screen is delivered by Apple. To start it we send Apple, unencrypted to them, the words "Clocked in", a line reading "Shift started at" followed by the name of the site you clocked in at, and that site name again as a value the timer displays. Later updates and the message that stops the timer carry no text and no site name. Your own name is never in it, and neither are your coordinates.
Notifications shown in your web browser are sent in a sealed form. The notification service your browser uses (Google for Chrome and Edge, Mozilla for Firefox, or Apple for Safari) can see only that a message was delivered, when, and roughly how big it was. It cannot read the message.
Artificial intelligence. Two optional features send content to Anthropic PBC: photographing a receipt so an expense claim fills itself in, and typing an instruction into the scheduling assistant. Each one sends data only when somebody uses it, and nothing else in your workspace is sent to any artificial intelligence provider. No face image, no face template, no message, no timesheet and no payroll detail is ever sent to one.
Your employer may also send your information somewhere else themselves. OtisIO lets a business connect its own integrations and send data to systems it chooses. When it does, that is its decision and its responsibility, and this policy stops at our boundary.
We will also disclose information if the law requires it, and to our professional advisers where necessary.
1.7 Session recording inside the app, which is our decision and not your employer's
We record masked sessions of the signed-in web app, using Microsoft Clarity, so we can see where people get stuck and fix it. This one is ours: we are the controller for it, your employer did not choose it, and it is the reason this section exists rather than being buried in the list above.
What is recorded. The shape of the page, where you click, how far you scroll, your IP address, your browser and device type and a rough location derived from your IP address.
What is masked. Strict content masking is switched on from our own code, not from a setting in Microsoft's dashboard, by an attribute applied to the whole page body. That masks every piece of text and every value typed into a field, so a recording shows the layout and where somebody clicked and never the names, pay, timesheets or personal details on the screen. An automated test asserts that the masking attribute is present on every recorded screen, and it has to pass before a release reaches production.
Where it does not run at all. It is skipped entirely, not merely masked, on every face and kiosk screen. It does not run on the sign-in page, on the sign-up flow, or anywhere outside our live production service. It is not in the phone app, the kiosk app or the desktop app.
No cookies, and nothing is stored on your device. Inside the signed-in app we send Microsoft no consent signal, and without one their tool runs in its cookieless mode for everyone in the UK, the EEA and Switzerland: it sets no cookie, writes nothing into your browser's storage, and gives each page view a fresh identifier rather than following you between them. That is why there is no cookie banner inside the app, and it is a different position from our public marketing pages at section 3.2, where the same tool does set cookies and only runs if you accept them.
Why we say we are allowed to. We rely on our legitimate interests in understanding and improving a product people have to use at work, on the basis that the recording is masked so that it does not reveal the content of anybody's record, that nothing is stored on your device, and that you may object and be excluded.
How to stop it. You can object at any time, and you do not have to give a
reason. Email us at privacy@otisio.com saying which workspace you work in,
or tell your employer's administrator and ask them to raise it with us, and we
will exclude you personally so that nothing further of yours is recorded. It takes
effect on your next page. It is only you who is excluded, so objecting has no
effect on anybody else you work with, and nothing else about the app changes for
you. Your employer can separately ask us to switch recording off for their whole
workspace. You can also block it in your browser: it is loaded from clarity.ms,
and any tracker blocker that blocks that address stops it without affecting
anything else in OtisIO.
Separately, on our public marketing pages, the same tool and Google Analytics run only if you accept analytics cookies. That is covered at section 3.2.
1.8 Where your information is held, and for how long
Our servers are in Helsinki, Finland. Off-site backups are held in Falkenstein, Germany, and a scheduled job pulls a copy down every day to a machine in the United Kingdom under the sole control of a director of the company. That third copy is a mirror of the encrypted backup repository, on a machine with full-disk encryption, and because it is a mirror it deletes whatever the off-site retention has already deleted, so it does not build up a longer history than the copies it came from. All three locations are within the United Kingdom and the European Economic Area, so there is no international transfer of the service's own data to solve.
Some of our suppliers process information in the United States. Where that happens, the transfer is protected either by the UK's adequacy regulations or by the International Data Transfer Agreement or the Standard Contractual Clauses together with the UK Addendum.
How long it is kept is your employer's decision, not ours, except where the product enforces a limit:
| Information | How long |
|---|---|
| Clock-in photographs, which are not biometric data | 45 days by default, employer may shorten, 90 days maximum, enforced |
| Face frames that matched nobody, where face clock-in is in use | 30 days by default, employer may shorten, 90 days maximum, enforced |
| Visitor face data | 7 days, fixed |
| Visitor sign-in records: name, company, who they came to see, when they arrived and left, and the answers they gave to any form asked at sign-in | 2 years by default, employer may shorten |
| Face templates | While you stay enrolled |
| Right to work and onboarding documents | Six years after the worker's record is archived |
| Your sign-in session history | 13 months |
| Notifications you were sent | 90 days |
| Everything else in the workspace | For as long as your employer keeps it |
| Audit trails of who did what | Kept, not swept by any deletion job |
| After a workspace closes | 30 days in which it can be restored or exported, after which we delete it. The deletion is carried out by us, not by an automatic job |
Why visitor records are kept for two years. A site sign-in register is the record an accident investigation, an HSE enquiry or an insurer asks for, and it is worth nothing if it has already been purged. Two years is the default for that reason and an employer can shorten it. Note the row above it: the face used for visitor sign-in is not kept for two years. That is biometric data, it is held for seven days, and no employer can extend it.
Backups. Our backups are not on the same clock as the live data, so a copy of something deleted from the service survives in a backup until that backup itself is aged out. We keep the last three off-site snapshots, then one a day for 14 days, one a week for 8 weeks, one a month for 12 months and one a year for 2 years, so the longest-lived copy of a deleted record can persist for up to two years. We also keep 14 days of local database dumps on the server itself. Restoring a backup to retrieve one person's record is not something we can sensibly do, so this is a limit on how long a copy can exist rather than a place anyone routinely looks.
Your employer is legally required to keep some records for years after you stop working for them, particularly pay and working time records. Deleting your account does not, and cannot, delete those.
1.9 Your rights, and the two things you can do without asking anyone
Under UK GDPR you can ask for access to your information, correction of it, deletion, restriction, a portable copy, and you can object to how it is used.
For most of these, ask your employer. They are the controller and the decision is theirs. Your manager or HR contact is the right person. If you ask us instead, we will forward your request to them and help them action it, but we cannot overrule them.
Two things you can do yourself, right now, without asking anyone:
- Delete your own face template, in the OtisIO app under Settings. See section 1.3.
- Delete your own account, from inside the app or from our website. There are guards preventing the last administrator of a workspace from locking everyone out, but otherwise the decision is yours. The steps, what is removed, and what survives, are set out at otisio.com/data-deletion.
You can also ask us for a copy of your information at any time, free, and we will either provide it or pass the request to your employer where the decision is theirs.
For the one thing in this section we decide ourselves, the session recording at section 1.7, you can object to us directly and we will action it without asking anybody.
Complaints. If you are unhappy with how your information has been handled, you can complain to the Information Commissioner's Office at ico.org.uk or on 0303 123 1113. We would appreciate the chance to put it right first, at privacy@otisio.com.
1.10 Decisions about you
No decision that has a legal or similarly significant effect on you is made about you by machine alone.
A geofence flag is a prompt for a human manager to look at something. A failed face match does not decide whether you are paid; it prompts a person to check. Every correction to your recorded hours is made by a person and logged.
2. If your business is our customer
For this section, we are the controller and we are fully responsible.
2.1 What we hold
Your name, work email address, phone number, your business name and type, your company number and registered office, your workspace, the plan you are on and its history, invoices and subscription status, quotes and the terms you accepted, support conversations, your marketing preferences, and a record of which version of our legal documents you accepted and when.
We never see or store your card number. Card payments are handled entirely by Stripe.
When you enter a company number at sign-up we look it up at Companies House, which is public register information.
2.2 Why we are allowed to
| What we do | Our lawful basis |
|---|---|
| Provide the service under our terms | Contract |
| Take payment, prevent fraud, keep tax records | Contract, and legal obligation |
| Keep the service secure, investigate abuse, keep audit records | Legitimate interests in running a secure service, weighed against your interests and limited to what security requires |
| Understand how the product is used, through the masked session recording at section 1.7 | Legitimate interests in improving the product, with the content masked and an objection route |
| Send you service messages, such as a failed payment or a change to our terms | Contract. These are not marketing and you cannot switch them off while you have an account |
| Send you product news and offers about OtisIO | Consent, or our legitimate interests where you are an existing customer and we told you at sign-up. Either way you can stop it at any time |
| Pass your details to other businesses for their marketing | We do not do this. See 2.3 |
2.3 Marketing
There are two separate things here and we ask about them separately.
Email about OtisIO itself: tips, product news, and offers on our own plans and add-ons. We tell you at sign-up that we will send it and give you the chance to refuse there and then, and every one of those emails carries a one-click unsubscribe that works without signing in.
Offers from other businesses we work with, which is optional and off unless you tick it. Your details are never passed to those businesses. We send the email ourselves and they never receive your address.
Where the person signing up is a sole trader or an ordinary partnership, UK marketing law treats them as an individual rather than a business, which is why sign-up asks what kind of business you are.
You can change either decision at any time under Settings, notifications, and we keep a record of exactly what wording you were shown and what you chose.
2.4 Who else sees it
Stripe processes payments and holds your billing details and payment method. No information about your workforce is ever sent to Stripe.
HubSpot holds the business contact details of people who deal with us commercially, so we can manage sales conversations and support. It holds no workforce data.
Brevo sends our emails. Cloudflare runs our DNS and the bot check on our forms. Companies House is a public register we read from and never write to.
2.5 How long we keep it
Account and billing records for as long as you are a customer and then for six years, because tax law requires it. Records of which legal documents you accepted for as long as they might be needed to evidence the agreement. Marketing preferences until you change them. Support conversations for three years.
3. If you visited our website or contacted us
For this section, we are the controller.
3.1 What we collect
If you fill in a contact form, request a demo or join a waiting list: your name, email address, business name, whatever you tell us, and whether you agreed to marketing.
If you simply visit: your IP address and standard technical information, which we need to serve the pages and to keep the site secure.
3.2 Cookies and similar technology
This is the full list. There is no separate cookie page.
Strictly necessary. These do not need your consent and cannot be switched off.
| Cookie | What it is for | How long it lasts |
|---|---|---|
otisio-session |
Keeps you signed in and holds your session | 2 hours |
XSRF-TOKEN |
Stops another site submitting a form as you | 2 hours |
analytics_consent |
Remembers whether you accepted or declined analytics, so we do not ask again | 182 days |
| Cloudflare Turnstile | Tells a person from a bot on our sign-in, sign-up and contact forms. It sees your IP address. It is a security measure | Set and cleared by Cloudflare during the check |
Analytics, on our public marketing pages only. Two tools, and neither loads unless you agree to analytics cookies. Nothing is requested from Google or Microsoft until you accept. If you decline, or if your browser sends a Do Not Track signal, the scripts are never added to the page and no cookie of theirs is set. How the banner works, so you can judge it for yourself: the banner has an Accept button, which is one click, and a Choose what's on link, which opens a panel where you can switch each category off and save. Turning analytics off is therefore two steps where accepting is one.
- Google Analytics, to see which pages people read and where they arrive from. It sets its own cookies. IP addresses are anonymised and the data is kept for two years.
- Microsoft Clarity, to see where people click and how far they scroll, so we can find what is confusing. It sets its own cookies. On these public pages the masking is whatever is configured in our Clarity account rather than forced from our code, which is the opposite of the position inside the signed-in app described at section 1.7.
Session recording inside the signed-in app is a separate thing, it does not depend on this banner, and it is described in full at section 1.7. If you have an OtisIO account, read that section rather than this one.
Both Google and Microsoft process this data in the United States, under the Standard Contractual Clauses with the UK Addendum.
Changing your mind. There is a Cookie choices link in the Legal column of the footer on every public page. It reopens the same panel, and a change there takes effect immediately.
What your choice is and is not. Your answer is stored in the
analytics_consent cookie on your own device for 182 days, with a version stamp,
so that if we ever add a new category of cookie the question is asked again rather
than assumed. We keep no record of it on our servers, which means we cannot
look up what any individual visitor chose; clearing your cookies clears your
answer and you will be asked again.
3.3 Why we are allowed to
Answering your enquiry is our legitimate interest, and yours, in responding to you. Keeping the site secure is our legitimate interest. Analytics on the public pages is consent. Marketing email is consent. Session recording inside the signed-in app is our legitimate interest, as set out at section 1.7.
3.4 How long we keep it
Enquiries that do not become customers, two years. Server and security logs, 13 months.
4. Things that apply to everyone
4.1 How we protect information
Everything is encrypted in transit with TLS, and requests to the insecure address are redirected to the secure one.
Each customer's workspace lives in its own separate database, so one business's information is not in the same place as another's. That separation is enforced by the application, and an automated security test suite covering workspace isolation, permissions and feature access, including tests that deliberately try to reach across workspaces, has to pass before a release reaches production.
Encryption at rest is done at the application layer, in the database, rather than by encrypting the disk. Special category and financial fields are stored with authenticated encryption keyed to an application key held outside the database: facial recognition templates and visitor face data, National Insurance numbers, bank details and home addresses, the credentials for any payroll or accounting system a customer connects, single sign-on secrets, webhook signing secrets and kiosk administrator codes. Passwords and clock-in PINs are hashed rather than encrypted, which means we cannot read them at all. Two-factor secrets and recovery codes are encrypted and are never returned by the application. Off-site backups are encrypted on our server before they are transmitted or stored, so the company holding them cannot read them.
Files uploaded into a workspace, which include right to work documents, clock-in photographs, signatures and receipts, are encrypted on the same key.
Not everything is encrypted at rest, and we would rather name what is not than let you assume otherwise. Two things are outside that protection: the host disk itself, which does not use full-disk encryption, and the 14 days of local database dumps kept on the server. Those are protected by the physical security of the data centre and by the access controls on the machine, not by encryption.
Access inside a workspace is controlled by roles and permissions the employer sets. Two-factor authentication is available and we recommend it. Every administrative action is written to an audit log the customer can read, and when we sign in to support a customer, their audit log records that it was us, by name.
Code style checks and static analysis run automatically on every change we make. We test that we can actually restore from a backup, automatically, every week.
No system is perfectly secure and we will not pretend otherwise. If a breach puts your rights at risk, we will tell the affected business without undue delay and in any event within 72 hours. Their own 72 hours for telling the Information Commissioner starts when we tell them, not when the breach happened, so our notice does not use up their time. They will also tell you directly where the law requires it.
4.2 Children
OtisIO is workplace software and is not for children. We do not knowingly collect information from anyone under 16. Where a business schedules workers aged 16 or 17, that business is the controller and is responsible for the basis on which it does so. Face clock-in must not be enabled for anyone under 18.
4.3 Changes to this policy
If we change this policy in a way that matters, we will say so on this page and, where the change affects our customers, tell them by email before it takes effect. Every version is kept and the date at the top is always the date of the current one.
4.4 Contact
Siege One Limited, 38 Angelica Avenue, Stotfold, Hitchin, England, SG5 4HH. Company number 17110871.
You can complain to the Information Commissioner's Office at ico.org.uk or on 0303 123 1113.
Version 2026-08-v4, in force from 25 August 2026.
Privacy Policy version 2026-08-v4, effective 25 August 2026. Generated on 13 September 2026. Source text SHA-256 5f551562c39f7f6e.