Privacy Policy

Last updated: May 2026 • Version 3.0

1. Introduction

Teamspot App ("Teamspot", "we", "us", or "our") provides a cloud-based workforce management platform for businesses. This Privacy Policy explains how personal data is processed when the Teamspot platform ("Service") is used.

This Privacy Policy applies to:

  • Customers (company administrators, managers, and other representatives), and
  • Authorized Users (such as employees or contractors) who use the Service on behalf of a Customer.

This Privacy Policy also applies to visitors of our website, prospects, demo requesters, business contacts, billing contacts, and support requesters.

2. Roles and Responsibilities under GDPR

Teamspot processes personal data in different roles depending on the context.

For personal data processed through the Service on behalf of a Customer, such as employee, scheduling, time-tracking, absence, messaging, reporting, and payroll-export data, the Customer acts as Controller and Teamspot acts as Processor. This processing is governed by the Teamspot Data Processing Agreement.

For personal data that Teamspot processes for its own business purposes, such as website use, sales communications, account administration, billing, payment administration, customer support, security, fraud prevention, legal compliance, and business-contact management, Teamspot acts as Controller.

Customers are responsible for ensuring that their use of the Service complies with applicable employment, labour, workplace, and data protection laws, including informing Authorized Users and other data subjects where required.

3. Information We Process

3.1 Personal and Account Information

Information provided by Customers or Authorized Users, including:

  • Name, email address, phone number
  • Profile photo and display name
  • User roles and permissions
  • Login and authentication details, including hashed passwords, verification status, session information, and security-related authentication data

3.2 Work-Related Data

Data generated through use of the Service, including:

  • Time entries (clock-in/out times, breaks, working hours)
  • Schedules, shifts, and assignments
  • Absence requests, types, and balances
  • Internal communications (e.g. chat messages, notifications)

3.3 Location Data

If location-related functionality is enabled by the Customer, Teamspot may process limited location data at clock-in or clock-out for validation and workforce management purposes.

This may include GPS coordinates at the time of clock-in or clock-out, whether the location was within a configured work area, and related technical metadata. Teamspot does not perform continuous employee location tracking.

The Customer is responsible for deciding whether to enable location-related functionality, determining the lawful basis, informing affected individuals, and ensuring that use of the feature is necessary and proportionate.

3.4 Technical and Usage Data

Automatically collected technical data, including:

  • Device type, operating system, and browser
  • IP address
  • Log files and usage activity
  • Interaction and feature usage data

We may receive personal data directly from individuals, from the Customer, from Authorized Users, through use of the Service, or from third-party integrations enabled by the Customer or user.

4. Legal Bases for Processing

Where Teamspot processes Customer Personal Data as Processor on behalf of a Customer, the Customer is responsible for determining the applicable legal basis under GDPR.

Where Teamspot acts as Controller, Teamspot may rely on the following legal bases:

  • Contract: to create and manage accounts, provide customer support, administer subscriptions, and communicate about the Service;
  • Legitimate interests: to secure, maintain, troubleshoot, improve, and protect the Service, prevent misuse, manage business relationships, and communicate with business contacts;
  • Legal obligation: to comply with tax, accounting, regulatory, legal, or lawful authority requirements;
  • Consent: where consent is required, such as for certain marketing communications or optional functionality where applicable.

Where location-related functionality is enabled by a Customer, the Customer is responsible for determining the lawful basis and ensuring that affected users are properly informed.

5. How We Use Personal Data

We process personal data to:

  • Provide, operate, and maintain the Service
  • Enable Customers to manage workforce operations
  • Authenticate users and secure accounts
  • Send operational, service-related, and administrative communications
  • Improve, maintain, and develop the Service
  • Ensure security, prevent misuse, and perform audits
  • Comply with legal obligations

We may anonymize and aggregate data so it no longer identifies individuals and use it for analytics, benchmarking, reporting, and product improvement.

6. Access to Data

6.1 Customers and Employers

Customer administrators and managers may access personal data of Authorized Users in accordance with the Customer's internal policies and permissions.

6.2 Teamspot Staff

Teamspot personnel may access personal data only where necessary for customer support, technical maintenance, implementation services, security, compliance, or troubleshooting. Access is restricted to authorized personnel and logged where technically feasible and appropriate.

6.3 Third Parties

A current list of subprocessors used for Customer Personal Data is available in the Teamspot Data Processing Agreement or at the location specified in the DPA.

7. Data Retention

For Customer Personal Data processed by Teamspot as Processor, retention, export, return, deletion, and anonymization are governed by the Teamspot Data Processing Agreement.

In general, Customer Personal Data is retained for the duration of the Customer's agreement with Teamspot, unless deleted earlier by the Customer or unless a different retention period is required by law.

After termination or expiry of the Customer's agreement, the Customer may request return or deletion of Customer Personal Data within 30 days. If no return request is made within that period, Teamspot may delete the Personal Data in accordance with the Data Processing Agreement.

Deleted Personal Data may remain in backups for up to 7 days, after which it is removed through the ordinary backup rotation process.

Teamspot may retain billing, tax, accounting, legal compliance, security, and business-administration records where required or permitted by law. Billing records may be retained for 7 years where required for legal, tax, accounting, or administrative purposes.

Teamspot may retain anonymized data where such data no longer identifies individuals and no longer constitutes Personal Data under GDPR.

8. Data Subject Rights

Authorized Users and Customer representatives may have the right to:

  • Access personal data
  • Request correction of inaccurate data
  • Request deletion or restriction of processing
  • Object to certain processing activities
  • Request data portability

Requests should generally be directed to the Customer (as Data Controller). Where appropriate, requests may also be submitted to us at info@teamspotapp.com.

Individuals also have the right to lodge a complaint with a supervisory authority. In the Netherlands, this is the Autoriteit Persoonsgegevens.

9. Security Measures

We implement appropriate technical and organizational measures to protect personal data, including:

  • Encryption in transit and at rest
  • Role-based access controls
  • Authentication and authorization safeguards
  • Audit logging
  • Security monitoring and incident response procedures

10. Communications and Marketing

We send service-related communications necessary for the operation of the Service, such as security notices, billing messages, and feature updates.

We may send marketing communications to business contacts where permitted by law, based on consent or legitimate interests as applicable. Recipients can opt out at any time using the unsubscribe link or by contacting us.

11. International Data Transfers

Teamspot aims to process Customer Personal Data within the European Economic Area where reasonably possible. Certain providers or integrations may involve processing outside the EEA.

Where Teamspot transfers Personal Data outside the EEA and no adequacy decision applies, Teamspot uses appropriate safeguards in accordance with GDPR, such as Standard Contractual Clauses and supplementary measures where required.

Further information about subprocessors and international transfers for Customer Personal Data is provided in the Data Processing Agreement.

12. Cookies and Similar Technologies

Teamspot may use cookies and similar technologies on its website and within the Service to provide functionality, maintain sessions, improve security, remember preferences, and understand usage.

Where required by law, Teamspot will request consent before using non-essential cookies or similar technologies.

More information may be provided in the separate cookie banner.

13. Changes to This Privacy Policy

We may update this Privacy Policy from time to time. The most recent version will always be available within the Service or on our website. Material changes will be communicated where appropriate.

14. Contact Information

Teamspot App

General contact: info@teamspotapp.com

Support: support@teamspotapp.com