1. Who is responsible
For workforce information entered into a company workspace, the subscribing organisation normally decides why and how that information is used and acts as the data controller. EPTS normally acts as its processor. EPTS acts as controller for its own account administration, contracting, security, support and service records.
2. Information processed
- Name, work email, role, department and account-security information.
- Duties, rotas, availability, interests, allocations and route knowledge.
- Holiday, lieu and sickness or absence records entered by authorised administrators.
- Rates, hours, payroll approval information and generated pay summaries.
- Uploaded duty paperwork, support access approvals, emails and audit logs.
- Technical security information such as session, sign-in and activity records.
3. Why information is used
Information is used to provide the contracted workforce service, administer accounts, plan and allocate work, communicate duty information, prepare payroll records, manage absence, maintain auditability, prevent misuse, provide support and meet legal obligations. The subscribing organisation must identify and document its lawful bases.
4. Sickness and health information
A simple absence record may become health information where it reveals a person’s condition. Organisations must limit access and notes to what is necessary, identify an Article 6 lawful basis and, where applicable, an Article 9 special-category condition before recording it. EPTS does not require medical detail in free-text notes.
5. Sharing and international processing
Information is available to authorised users of the relevant company and to time-limited EPTS Support sessions approved by the company owner. EPTS uses infrastructure and communication providers, including Cloudflare, to host, protect, back up and deliver the service. Providers act under contractual and security obligations. Information is not sold for advertising.
6. Retention and deletion
Each company can configure retention for finalised operational records, absence records, uploaded paperwork and delivered email records. Default periods are 24 months for operational and paperwork records, 24 months for absence records and 90 days for delivered email records. Daily recovery backups are retained for up to 35 days. Open or assigned duties, active accounts and queued emails are not automatically deleted.
7. Security
Controls include encrypted transport, tenant separation, role permissions, secure session cookies, rate-limited sign-in, optional two-factor authentication, audited support access, restricted file downloads and daily backups. No service can eliminate every risk; suspected incidents should be reported promptly.
8. Your rights
Depending on the circumstances, individuals may have rights to access, correct, restrict, object to, erase or obtain a copy of their personal information. Staff should normally contact their employer or workspace administrator first. EPTS privacy enquiries can be sent to accounts@epts.uk. You may also complain to the UK Information Commissioner’s Office.
9. Further information
This notice is specific to EPTS Duties and should be read with the EPTS master privacy policy. Organisations should provide their own employee privacy information explaining their particular purposes, lawful bases and retention decisions.