The GDPR-aware local time tracker
by minimising data flows

For EU buyers who want time-entry data to remain on their own machines. We do not receive your time-entry data, but your DPO still needs to assess the chosen sync provider, plain local storage, employee-monitoring rules, endpoint controls, and payment data.

No vendor time-entry database Local data path Sync provider matters DPO review ready

What GDPR requires of us, and what it doesn't:

The Workforce application does not send time-entry data, customer names, or timesheet content to our servers. However: the files are plain, unencrypted JSON, and if you place them in Dropbox, OneDrive, iCloud, or another commercial sync service, that provider becomes part of your data-protection assessment. Auto-tracking can also read active window titles when enabled, which may create employee-monitoring and sensitive-context obligations. As the licence buyer, you exchange standard commercial contact data with us under our privacy policy. This page is general information, not legal advice; your DPO should make the final decision.

Why this product makes GDPR easier than the alternative

No data flows to us

The time-entry JSON files are written to disk on your laptop. We have no server that receives them. No backup of your data exists outside your control.

No vendor account

Your end users do not register with us. There is no "Workforce Time Tracker user" in any database we own. There is nothing to delete on subject access / right-to-erasure requests on the user side.

No telemetry

The app does not phone home with usage analytics, crash reports, or click-tracking. The only optional outbound call is a version check (disable-able in Settings).

Your sync provider is your choice

If you use multi-device sync we put plain JSON files in a folder you control. For strict EU-only handling, prefer SyncThing, an internal share, or a NAS. Dropbox, OneDrive, and iCloud are optional providers whose processing, location, contractual terms, and transfer mechanisms must be assessed by you.

Plain JSON files

Your data is in a text format you can read, audit, copy and delete with standard OS tools. There is no proprietary database to dump, decrypt or migrate from. Right-to-erasure is "delete the file."

Cryptographic licence with no server

The licence is RSA-PSS-signed and verified locally. Even the licence-validation step never contacts us. If we vanish tomorrow, your installation continues to work indefinitely.

Employee monitoring is your responsibility

When auto-tracking is enabled, the app reads the active window title locally and may derive a customer, case, or project name. Do not treat this as invisible monitoring. Give employees appropriate notice, define a lawful purpose and retention period, configure ignored screens, and consult your DPO, works council, Betriebsrat, or other employee representative where required. Manual tracking remains available without window-title capture.

What changes with us vs a typical SaaS time tracker

GDPR consideration Workforce Time Tracker Typical SaaS time tracker
Workforce receives time-entry dataNoUsually yes
Chosen sync/payment providers to reviewYour responsibilityVendor-managed plus your review
Records of Processing Activity (Article 30) updateInternal onlyPlus a vendor entry
Standard Contractual Clauses (SCCs)Depends on chosen providersDepends on vendor stack
Transfer Impact AssessmentDepends on chosen providersDepends on vendor stack
72-hour breach notification dependency on vendorNoYes
Subject access / right to erasure on user dataLocal file deleteVendor process, vendor SLA
Vendor risk assessment / procurement reviewStill required for your deploymentFull SaaS vendor onboarding

This table compares the GDPR overhead of two procurement paths, not the products' features. It is general guidance, not legal advice. Your DPO is the decision-maker.

Common GDPR / EU procurement questions

Does Workforce receive our time-entry data?

No. The desktop application does not send time-entry data, customer names, or timesheet content to our servers. However, your chosen sync provider, payment provider, endpoints, and employee-monitoring configuration remain your responsibility. Review our privacy policy for the commercial contact data exchanged when licensing.

Are you a data controller for our employees' time entries?

You are responsible for the working-hours data processed on your machines. We do not receive it. If auto-tracking is enabled, assess notice, lawful basis, retention, DPIA, and employee-representation requirements before deployment.

Can we use this for strict EU-only handling?

Yes, if you keep the plain JSON files on internally controlled machines, an internal share, NAS, or a suitable peer-to-peer setup such as SyncThing. Dropbox, OneDrive, iCloud, and other commercial sync services may introduce their own processor, location, and transfer considerations; your DPO must assess that choice.

Where is the data hosted?

On your own machines as plain, unencrypted JSON. For strict EU-only handling, use an internally controlled share, NAS, or SyncThing. Commercial sync providers are optional and require your own assessment.

Do we need to inform our DPO before deploying this?

Yes. Your DPO should review the plain local storage, chosen sync provider, endpoint controls, auto-tracking behavior, retention, and employee-representation requirements. We can provide the technical facts: no vendor time-entry database, no telemetry, local licence validation, and JSON files on disk.

What happens to the data if you go out of business?

Nothing - your installations and data are unaffected. The licence is RSA-PSS-signed and validated locally, with no server contact required. The signed licence file you have on disk continues to validate forever. Your existing copy of the app keeps working indefinitely. Your data remains in human-readable JSON you can read, export, or import into another tool.

Is there a German / Dutch / French version?

The current UI is English only. Currency, date format and timezone are configurable per user, so the app handles EUR, GBP and other currencies; weekly start day (Monday is default in Europe) is configurable; date format follows your OS regional settings. UI translation to other EU languages is on the roadmap.

What if the subscription lapses while we are mid-engagement with a client?

You get a 14-day grace period after the expiry date during which the app keeps working normally. After that, the app shows renewal reminders but does not lock, encrypt, or hide your data. Time entries, customer list, exports, settings and backups stay in plain JSON files you can read with any text editor, archive, or migrate to any other tool. This is written into the EULA at section 8.5 - it is a contractual commitment, not a marketing line.

Try it for 14 days, no account, no credit card

Same product on Windows and macOS. One licence covers both.

Download the trial
Also relevant: Offline time tracker Salesforce time tracker Dynamics 365 time tracker Jira time tracker