GDPR Privacy Notice
Last updated: June 15, 2026General Data Protection Regulation
This GDPR Notice supplements our Privacy Policy and applies to individuals in the European Economic Area (EEA), the United Kingdom, and Switzerland. It describes how Splocket processes your personal data, the lawful bases we rely on, and your rights under GDPR.
Data Controller vs. Processor: Splocket acts as a data processor on behalf of your employer (the data controller) for workforce data processed through the platform. For data we collect directly (account registration, usage analytics, contact inquiries), Splocket acts as the data controller.
1. Data Controller
For personal data where Splocket acts as the data controller, the controller is:
Splocket
Contact: support@splocket.com
If you are an employee or worker whose data is processed on behalf of your employer, your employer is the data controller. Please contact your employer's HR or IT department for queries about how they use Splocket to manage your data.
2. Personal Data We Process
We process the following categories of personal data:
- Identity data — name, email address, platform user ID
- Employment data — job role, department, shift schedules, clock-in/out records, availability, reliability scores
- Technical data — IP address, browser type, device identifiers, push notification tokens
- Usage data — features accessed, actions taken, session duration
- Location data — approximate geolocation for geofence verification, only where enabled by your employer
We do not process special categories of personal data (health data, biometric data, etc.) unless explicitly configured by your employer and consented to by you.
3. Lawful Bases for Processing
We rely on the following lawful bases under Article 6 GDPR:
| Processing Activity | Lawful Basis |
|---|---|
| Providing the platform (scheduling, attendance, adherence) | Contract performance (Art. 6(1)(b)) |
| Account registration and authentication | Contract performance (Art. 6(1)(b)) |
| AI-powered recommendations and reports | Legitimate interests (Art. 6(1)(f)) — improving workforce operations |
| Security monitoring and fraud prevention | Legitimate interests (Art. 6(1)(f)) |
| Geofence-based location verification | Legitimate interests or consent, depending on employer configuration |
| Compliance with legal obligations | Legal obligation (Art. 6(1)(c)) |
4. International Data Transfers
Splocket Pulse is hosted on infrastructure operated in the United States (Supabase, Vercel). If you are located in the EEA or UK, your personal data may be transferred to and processed in the US.
We rely on the following transfer mechanisms to ensure adequate protection:
- Standard Contractual Clauses (SCCs) with our US-based sub-processors
- The EU-US Data Privacy Framework where applicable
A list of our sub-processors is available on request at support@splocket.com.
5. Data Retention
We retain personal data only as long as necessary for the purposes described in this notice:
- Account and employment data — retained for the duration of the subscription and deleted within 30 days of account termination upon request
- Operational logs and telemetry — up to 24 months for reporting and forecasting
- Security and audit logs — up to 12 months
- Contact form submissions — up to 3 years for support history
6. Your Rights Under GDPR
As a data subject under GDPR, you have the following rights:
- Right of access (Art. 15) — request a copy of the personal data we hold about you
- Right to rectification (Art. 16) — request correction of inaccurate or incomplete data
- Right to erasure (Art. 17) — request deletion of your data where there is no lawful basis for continued processing
- Right to restriction (Art. 18) — request that we limit processing of your data in certain circumstances
- Right to data portability (Art. 20) — receive your data in a structured, machine-readable format
- Right to object (Art. 21) — object to processing based on legitimate interests
- Rights related to automated decision-making (Art. 22) — AI-generated scores (e.g. reliability scores) are used as recommendations only; human managers make all final decisions
Note: If your data is processed by Splocket as a data processor on behalf of your employer, please direct your rights requests to your employer first. We will assist employers in responding to data subject requests.
7. How to Exercise Your Rights
Submit a data subject request by emailing support@splocket.com with the subject line "GDPR Request." We will respond within 30 days. We may request identity verification before processing your request.
8. Right to Lodge a Complaint
If you believe we have not handled your personal data in accordance with GDPR, you have the right to lodge a complaint with your local supervisory authority. In the UK, this is the Information Commissioner's Office (ICO) at ico.org.uk. In the EEA, contact your national data protection authority.
9. Contact & DPO
For GDPR-related inquiries, contact us at support@splocket.com. We do not currently have a designated Data Protection Officer, but our privacy team will respond to all inquiries within 30 days.