E EPTS DUTIES

PUBLIC LEGAL INFORMATION

Privacy notice

How EPTS Duties and your organisation use and protect account, rota, payroll, absence and operational information.

Effective 30 August 2026 · Version 1.0

1. Who is responsible

For workforce information entered into a company workspace, the subscribing organisation normally decides why and how that information is used and acts as the data controller. EPTS normally acts as its processor. EPTS acts as controller for its own account administration, contracting, security, support and service records.

2. Information processed

  • Name, work email, role, department and account-security information.
  • Duties, rotas, availability, interests, allocations and route knowledge.
  • Holiday, lieu and sickness or absence records entered by authorised administrators.
  • Rates, hours, payroll approval information and generated pay summaries.
  • Uploaded duty paperwork, support access approvals, emails and audit logs.
  • Technical security information such as session, sign-in and activity records.

3. Why information is used

Information is used to provide the contracted workforce service, administer accounts, plan and allocate work, communicate duty information, prepare payroll records, manage absence, maintain auditability, prevent misuse, provide support and meet legal obligations. The subscribing organisation must identify and document its lawful bases.

4. Sickness and health information

A simple absence record may become health information where it reveals a person’s condition. Organisations must limit access and notes to what is necessary, identify an Article 6 lawful basis and, where applicable, an Article 9 special-category condition before recording it. EPTS does not require medical detail in free-text notes.

5. Sharing and international processing

Information is available to authorised users of the relevant company and to time-limited EPTS Support sessions approved by the company owner. EPTS uses infrastructure and communication providers, including Cloudflare, to host, protect, back up and deliver the service. Providers act under contractual and security obligations. Information is not sold for advertising.

6. Retention and deletion

Each company can configure retention for finalised operational records, absence records, uploaded paperwork and delivered email records. Default periods are 24 months for operational and paperwork records, 24 months for absence records and 90 days for delivered email records. Daily recovery backups are retained for up to 35 days. Open or assigned duties, active accounts and queued emails are not automatically deleted.

7. Security

Controls include encrypted transport, tenant separation, role permissions, secure session cookies, rate-limited sign-in, optional two-factor authentication, audited support access, restricted file downloads and daily backups. No service can eliminate every risk; suspected incidents should be reported promptly.

8. Your rights

Depending on the circumstances, individuals may have rights to access, correct, restrict, object to, erase or obtain a copy of their personal information. Staff should normally contact their employer or workspace administrator first. EPTS privacy enquiries can be sent to accounts@epts.uk. You may also complain to the UK Information Commissioner’s Office.

9. Further information

This notice is specific to EPTS Duties and should be read with the EPTS master privacy policy. Organisations should provide their own employee privacy information explaining their particular purposes, lawful bases and retention decisions.

© 2026 EPTSTerms · Privacy · accounts@epts.uk
Product demoCreate a companyTerms of usePrivacy noticeEPTS termsEPTS privacyContact EPTS
Privacy notice — EPTS Duties