Legal

Privacy policy

This policy explains how FieldForce handles personal information when people visit, contact or use FieldForce.

Effective and last updated: 2 August 2026

This policy is an operational draft for a UK SaaS service. Before public launch, confirm the legal entity details, actual suppliers, retention periods, cookie behaviour and any customer data-processing agreement.

1. Who we are

FieldForce operates FieldForce, a software service for managing workforce records such as timesheets, working hours, mileage, expenses, receipts, employee access, approvals and reports.

Contact address: United Kingdom.

Privacy contact: support@fieldforceapp.co.uk.

2. Our data-protection role

For website enquiries, account administration, billing, service security and our own support records, we normally act as the controller because we determine why and how that information is used.

For workforce information entered into a company workspace, the customer organisation normally decides why the information is collected and how it is used. In that context, the customer is generally the controller and FieldForce acts as its processor. Employees should first contact their employer or contracting organisation about workplace-data requests.

3. Personal information we collect

Account and identity data

Names, email addresses, telephone numbers, profile images, job titles, company membership, account roles, authentication identifiers and invitation records.

Workforce and operational data

Timesheet dates, start and finish times, break durations, normal and overtime hours, overtime types or rates, site names, mileage, notes, approvals and audit history.

Expense information

Expense dates, descriptions, categories, amounts, VAT values, mileage claims, receipt images and associated work records.

Billing and subscription data

Plan, seat capacity, subscription status, billing identifiers, transaction references and limited payment information made available by our payment provider. We do not need to store complete payment-card numbers in FieldForce.

Technical and communications data

IP address or a protected hash of it, browser and device information, security events, diagnostic logs, support or sales messages, message references and email-delivery status.

4. How and why we use personal information

PurposeInformationTypical lawful basis
Provide accounts and the serviceAccount, company, workforce, timesheet and expense dataPerformance of a contract; legitimate interests
Authenticate users and secure the platformAuthentication, device, network and security-event dataPerformance of a contract; legitimate interests; legal obligations where applicable
Process subscriptions and paymentsPlan, billing identifiers and transaction recordsPerformance of a contract; legal obligation
Provide support and answer sales enquiriesContact details, communications and diagnostic informationPerformance of a contract or steps requested before a contract; legitimate interests
Send operational emailsEmail, company, invitation and account-event dataPerformance of a contract; legitimate interests
Improve reliability and prevent misuseUsage, error, audit and security dataLegitimate interests
Comply with law and protect rightsRelevant account, transaction, communication and audit dataLegal obligation; legitimate interests

Where we rely on legitimate interests, those interests include operating a secure and reliable business service, preventing abuse, improving product performance, supporting customers and protecting legal rights. We consider whether those interests are overridden by the rights and freedoms of the person whose data is involved.

5. Who we share information with

We may share information with:

  • The customer organisation that controls a company workspace and its authorised owners, administrators or managers.
  • Cloud hosting, database, authentication, payment, email-delivery, monitoring and support providers acting under contract.
  • Professional advisers, insurers, auditors and prospective purchasers where reasonably necessary.
  • Regulators, courts, law-enforcement bodies or other authorities where disclosure is required or legally permitted.

We do not sell personal information to advertisers. We do not permit third parties to use customer workforce records for their own advertising purposes.

6. International transfers

Some service providers may process information outside the United Kingdom. Where required, we use an appropriate legal transfer mechanism and assess the safeguards used by the recipient. Customers should review any separate data processing agreement and provider list made available for their subscription.

7. How long we keep information

We keep information only for as long as reasonably necessary for the purposes described in this policy, to provide the service, meet contractual commitments, resolve disputes, maintain security and comply with legal or accounting duties.

  • Customer workspace data is normally retained while the account is active and for a limited deletion or recovery period after termination, unless the customer exports or deletes it earlier.
  • Uncompleted signup and expired invitation records may be deleted or anonymised after they are no longer operationally required.
  • Support and sales messages are normally retained for up to 24 months, unless a longer period is needed for an active dispute, security matter or legal duty.
  • Billing and transaction records may be kept for the period required for tax, accounting, fraud-prevention and legal purposes.
  • Security logs are retained for a proportionate period based on risk and investigation needs.

A customer may need to retain workforce records for its own employment, tax, health and safety or contractual obligations. Those retention decisions are the customer’s responsibility where it acts as controller.

8. Security

We use administrative, technical and organisational measures designed to protect information, including access controls, role separation, authentication, encrypted connections, service-provider controls, logging and backups where appropriate. No internet service can guarantee absolute security, so customers must also protect account credentials, devices and administrator access.

9. Cookies and similar technologies

FieldForce may use strictly necessary browser storage or cookies for authentication, security, session continuity and preferences. These are needed to provide the service requested by the user.

We will not intentionally activate non-essential analytics, advertising or personalisation technologies before obtaining any consent required by law. If we introduce those tools, we will update this policy and provide appropriate controls.

10. Your data-protection rights

Depending on the circumstances, you may have rights to be informed, access your information, correct inaccurate data, request deletion, restrict processing, receive portable data, object to processing and withdraw consent where consent is the lawful basis. These rights are not absolute and legal exceptions may apply.

For workforce data in a company workspace, contact the employer or organisation that controls the workspace first. We will support verified customer instructions where required.

11. Contact, complaints and changes

Email privacy enquiries to support@fieldforceapp.co.uk. We may need to verify identity before responding to a rights request.

You may also complain to the UK Information Commissioner’s Office. We encourage you to contact us first so we can try to resolve the concern.

We may update this policy when the product, suppliers or legal requirements change. We will publish the revised date and, where appropriate, provide additional notice.

Need help with your data?

Send a support request and choose the most relevant category.

Contact support