Privacy Policy
This Privacy Policy explains what personal data WorkingClock collects, why, and what rights you have over it. WorkingClock is operated by Almaware S.r.l., an Italian company, and its infrastructure is hosted in the EU.
Last updated: 17 July 2026
1. Who we are
WorkingClock is a product of Almaware S.r.l., a company registered in Italy at Via Camozzi 111, 24121 Bergamo (BG) — VAT number IT03779610165, REA BG-407632.
For account, billing, and marketing data, Almaware S.r.l. is the data controller. For the time-tracking data an organization records about its own team, clients, and projects, Almaware S.r.l. acts as a processor on that organization's instructions — see our Data Processing Agreement.
2. Data we collect
We collect only what is needed to run the service:
- Account data — email address, name, password hash (or third-party sign-in identifier), and organization membership
- Time-tracking data — projects, tasks, tags, clients, and time entries you or your organization record
- Billing profile — name, VAT ID, country, and Stripe customer/subscription IDs; card numbers are never seen or stored by us, only by Stripe
- Device and log data — authentication sessions, security and diagnostic logs, and minimal product usage telemetry
- Communications — messages you send us through the contact form or support email, including the content you provide
3. How we use your data
To provide the time-tracking, reporting, and billing service you sign up for; to secure accounts and prevent fraud or abuse; to respond to support requests; and, only where you have opted in, to send product update emails.
4. Legal bases for processing
Under Article 6 GDPR, we rely on the following bases, depending on purpose:
- Contract (Art. 6(1)(b)) — providing the tracking service and billing for core account and subscription data
- Legal obligation (Art. 6(1)(c)) — retaining invoices for tax and accounting law (Italian and, where applicable, German record-keeping rules)
- Legitimate interest (Art. 6(1)(f)) — security, fraud prevention, and minimal product telemetry
- Consent (Art. 6(1)(a)) — marketing emails and non-essential cookies or analytics, both opt-in and revocable at any time
5. Who we share data with
We do not sell personal data. We share it only with the sub-processors needed to run the service — hosting, payments, transactional email, push notifications, sign-in, and error tracking. The full list, with each provider's purpose and location, is on our Sub-processors page.
6. International data transfers
Our infrastructure is hosted in the EU (Germany): application data in Frankfurt, transactional email delivery routed through the EU (Ireland). Where a sub-processor is located outside the EU/EEA — Stripe for payments, or Google, Apple, Microsoft, and Facebook for third-party sign-in — the transfer relies on the EU Standard Contractual Clauses and/or the EU-US Data Privacy Framework.
7. Data retention
- Account data — for the life of the account, plus a 30-day grace period after deletion
- Time entries and projects — for the life of the organization; deleted with the account/organization after the grace period
- Invoices and billing records — retained for the statutory period required by Italian tax law, even after account deletion, minimized to what the law requires
- Authentication sessions — until expiry (30 days) or until you sign out or revoke the session
- Server and audit logs — a bounded window of 90–180 days
8. Your rights
Under Articles 12–22 GDPR you have the right to access your data (self-serve export from account settings), rectify it (edit your profile or entries directly in the app), request erasure (self-serve account deletion, minus legally-retained invoices), restrict or object to processing, and receive your data in a portable, machine-readable format.
To exercise any of these rights, or if a request cannot be completed self-serve, contact support@workingclock.app. We respond within one month, as required by the GDPR.
If you believe your data has been processed unlawfully, you may lodge a complaint with the Italian supervisory authority, Garante per la protezione dei dati personali (Piazza Venezia 11, 00187 Rome, Italy — www.garanteprivacy.it), or with the supervisory authority of your own EU country of residence.
9. Cookies and tracking
See our Cookie Policy for the full detail on cookies, local storage, and the consent choices available to you.
10. Children
WorkingClock is not directed to, and is not knowingly used by, children under 16. If we learn that we have collected data from a child under this age, we will delete it.
11. Security
We use encryption in transit (TLS) and at rest, role-based access control, and tenant isolation between organizations. No system is perfectly secure, but we design and operate WorkingClock to minimize risk and detect problems quickly.
12. Changes to this policy
If we make a material change to this policy, we will notify account holders by email and update the "Last updated" date above before the change takes effect.
13. Contact
Questions about this policy or your data: support@workingclock.app.
Formal legal notices to Almaware S.r.l. may be sent via certified email (PEC) to almaware@legalmail.it.