Stage 01
Collect
Category, subject, source, necessity, validation.
Is this necessary for the stated purpose?
What categories are collected and from which sources, for what purpose, who can access or receive them, how long they are kept, where they are processed — and how the person a record describes can see it, understand it, and ask for it to be corrected.

Truth boundary
A privacy statement is valid only within its stated role, data category, purpose, customer configuration, product scope, region, date, and limitation. Technical capability never creates permission by itself.
Time evidence without hidden surveillance
No screenshots, keystroke content, URL history, application-name monitoring, or clipboard collection under any tier or configuration.
Time entries, schedules, approvals, presence context, and evidence records describe work against configured policy. Invasive productivity monitoring describes a person using a device. These are different categories of data, and ZoikoTime collects only the first.
Commitment owner: Trust & Governance · Status: Current · Last reviewed 12 Jul 2026 · Next review 12 Jan 2027
Workforce-Data Lifecycle
This diagram is not a claim that every category follows the same schedule or basis — different categories diverge at almost every stage.
Stage 01
Category, subject, source, necessity, validation.
Is this necessary for the stated purpose?
Stage 02
Purpose, policy, context, rule version.
Is any secondary use prohibited here?
Stage 03
Recipient, role, authority, scope, transfer, contract.
Who receives it, and under what authority?
Stage 04
Environment, location class, tenant separation, protection.
Where does it live, and how is it bounded?
Stage 05
Schedule, trigger, owner, legal hold, review.
What ends this, and who owns that decision?
Stage 06
Deletion, anonymization, archive, export, hold, evidence.
What actually happened, and what proves it?
Deletion is not instantaneous or universal
Deletion, anonymization, archive expiry, backup expiry, and legal hold are distinct outcomes with distinct timelines. Legal holds and security records are not silently removed by an ordinary user deletion, and no page on this site claims data is "deleted everywhere immediately."
Data Categories & Sources
The third column matters as much as the second. Most privacy harm comes from a category being read as more than it is.
| Category | Illustrative contents | Approved purposes | Never implies |
|---|---|---|---|
| Account & identity | Name, work email, account ID, authentication and role context. | Account access, identity, permissions, support, security. | That identity data determines employment status or legal authority. |
| Organization & configuration | Entities, teams, groups, roles, policies, schedules, integrations. | Administration, scope, workflow and reporting context. | That customer configuration creates legal permission. |
| Time & workforce records | Time entries, attendance and presence context, timesheets, breaks, approvals, exceptions, corrections where enabled. | Create, review, approve, preserve and report governed records. | Screenshots, keystroke content, URL history, application names, or clipboard content — none of which is ever collected. |
| Device & service metadata | Device and app version, timestamps, sync, security and diagnostic metadata where approved. | Service operation, security, troubleshooting, reliability. | Covert productivity monitoring or unrestricted location tracking. |
| Integration & provider records | External IDs, events, sync status, imported and exported records, connector health. | Authorized data exchange, reconciliation, recovery. | That every connector receives all data, or acts in the same privacy role. |
| Support, audit & incident | Support requests, change history, access and audit events, incident context. | Support, accountability, security, dispute resolution, legal and contractual needs. | That all message content or sensitive attachments are required. |
Purposes, Roles & Authority
Two things this model does not do
It does not make your employment or legal decisions compliant — ZoikoTime cannot do that for you. And it does not transfer your responsibilities onto workers through obscure consent language. Controller and processor terminology appears only where the applicable contract and jurisdiction support it, not as decoration.
Worker Visibility, Explanation & Correction
A right you cannot exercise from inside the product is not a right. Workers can see the record, understand why it says what it says, and ask a person to look again.
Step 01
Permitted record, source, timestamp, status, and relevant history.
Step 02
Policy and rule context, the deterministic classification applied, and any pending-review state.
Step 03
Request a correction or an explanation, with a reason and supporting context.
Step 04
Routed to an authorized reviewer with status, due context, and an escalation path.
Step 05
Decision, change, source, and history recorded — without hiding the original record.
An account or privacy request route exists for cases the in-product view cannot resolve. It does not require marketing consent, and it never has.
Privacy request routesWhat a flagged record is not
There is no automatic guilt or misconduct conclusion anywhere in this product. A record in review describes a record condition, not a person.
Honest limitation: correction rights and response obligations vary by role and jurisdiction. We describe the route clearly — we do not guarantee that every requested outcome will be granted.
Objective: ensure only the right people and services can see or receive a record, for a stated purpose.
Limitations: internal privileged architecture and restricted recipient detail are not published. Not every integration receives the same data, and connectors do not share a single privacy role — each is scoped separately.
Objective: govern lifecycle endpoints so records neither persist without reason nor disappear without record.
Limitations: there is no universal deletion deadline and no "deleted everywhere immediately" claim. Customer-configured retention cannot exceed product, contract, or legal constraints without review. Legal holds and security records survive ordinary user deletion by design.
Objective: explain movement and location concepts without making promises this page cannot support.
Limitations: no blanket "data stays in country" or "no international transfer" claim. Legal adequacy and transfer validity are never inferred from infrastructure region alone. Specific residency commitments belong to contracts and to the evidence-gated Data Location & Residency destination — which is not yet released and is therefore not linked here.
Automation, AI & Analytics Boundary
Policy-bound inputs and reviewable rules. It is not AI, and it is not described as AI anywhere in this product.
May flag anomalies or signal-quality concerns for human review. It does not decide anything.
Retrieves, summarizes, and explains governed data within authorized scope. Decides nothing.
Privacy-minimized. Excludes worker-level content, search text, and sensitive intent.
Four claims absent by design
No automated employment, payroll, disciplinary, or legal decision. No hidden workforce scoring or behavioral profiling. No model-training claim — if training use ever exists, it will be described only with approved evidence. And no claim that AI is unbiased, compliant, or infallible.
Processors, Subprocessors & Integrations
Subprocessor summaries link to current authoritative sources where approved. Restricted recipient detail and provider terms are not exposed publicly. We do not present provider controls as ZoikoTime controls.
Privacy-Practices Directory
What is never collected, in every tier and configuration.
Limitation: describes non-collection. Not a compliance conclusion.
Categories, illustrative contents, approved purposes, and what each must never imply.
Limitation: contents are illustrative, not an exhaustive field list.
What a worker can see, ask, and escalate — and the limits of each.
Limitation: available routes depend on your configuration and jurisdiction.
Schedules by record type, trigger, and owner for your configuration.
No public universal claim exists. Request through Privacy Review.
Current contractual processing terms and their scope.
Terms depend on your agreement. Routed through controlled review.
Processing and backup location classes assessed region by region.
The Data Location & Residency destination is not released, so it is not linked.
Withdrawn and superseded practices are excluded from default results and link to their current replacement. The search index excludes restricted and customer-specific content, and search terms are never captured in analytics.
Privacy Requests & Rights Routing
For most workforce-record questions your employer is the primary route, because they define the purpose and hold the context. We say so plainly rather than routing you in a circle.
A question about a specific time, attendance, or approval record.
Primary route
Your authenticated personal record view, or the approved worker route with your employer.
Your name, work email, or account details.
Primary route
Account settings, or the Help and Privacy route.
Organization-level export, deletion, or scope change.
Primary route
An authorized administrator, or Enterprise Support.
Access, correction, deletion, restriction, objection, or portability questions.
Primary route
Privacy request route, with jurisdiction and relationship triage — and appropriate involvement of your employer.
Contractual and procurement evidence needs.
Primary route
Controlled Privacy Review, with secure evidence delivery.
When a response was inadequate or a route did not work.
Primary route
Privacy or support escalation, with a named owner and a status path.
When submitting, do not include credentials, health information, union or representative details, legal strategy, or unnecessary worker data.
New or materially changed data use is reviewed before release: purpose, necessity, categories, roles, retention, worker impact, notice requirements, and evidence. A material change can require notice, reconsultation, or a blocked release under your governance rule.
Unsafe, stale, or factually unsupported privacy wording may be corrected or removed immediately, followed by a retrospective change record. We do not silently rewrite prior statements.
Privacy incidents follow a governed response with assessment, containment, notification criteria, and correction. Current service state — including operational incidents — is published on System Status, which is the authoritative source.
Not promised
Breach-notification obligations and timing depend on jurisdiction, contract, and assessed impact. No universal notification commitment is published here.
Direct Answers
It collects account and identity data, organization configuration, time and workforce records, device and service metadata, integration records, and support, audit and incident records — each for stated purposes. It never collects screenshots, keystroke content, URL history, application-name monitoring, or clipboard content, under any tier or configuration.