1. Who we are
Gatula ehf., registration number 450526-1850, Bíldshöfði 16, 110 Reykjavík, Iceland, operates Gatula Time.
For account, commercial, website, security and support data, Gatula may act as a controller. For employee and workforce data entered by a customer, Gatula generally acts as a processor on that customer’s documented instructions.
2. Data we process
- Account data such as name, email, language, timezone, roles and company membership.
- Employee and customer records entered by the customer.
- Projects, assignments, schedules, Time Entries, breaks, Timesheets, approval comments and exports.
- Security and technical data such as session identifiers, device and browser details, IP address, login attempts, request identifiers and audit events.
- Support, invitation, billing and service-configuration data.
- Optional GPS, geofence, photo or similar evidence only when the relevant feature is enabled and lawfully configured.
3. Why we process data
- Provide, secure and support Gatula Time.
- Authenticate users and enforce roles, permissions and company isolation.
- Register, calculate, review and approve working time.
- Generate reports and billing-preparation exports requested by authorized users.
- Detect misuse, investigate incidents, maintain audit history and comply with legal obligations.
- Communicate service, account, security and support information.
4. Legal bases
Depending on the context, processing may be necessary to perform a contract, comply with a legal obligation, pursue legitimate interests in secure service operation, or rely on consent where consent is the appropriate basis.
The customer is responsible for identifying and documenting the lawful basis for workforce processing it controls, including any optional monitoring or location features.
5. Customer instructions and access
Customer administrators determine which users may access company data and which features are enabled. Gatula personnel access customer data only where necessary for service operation, support, security, legal compliance or documented customer instructions, subject to access controls and confidentiality obligations.
6. Sharing and subprocessors
Data may be processed by vetted infrastructure, hosting, storage, email, monitoring, support and security providers required to deliver the service. Gatula does not sell workforce personal data.
Where data is transferred outside the EEA, Gatula will use an available lawful transfer mechanism and appropriate safeguards.
7. Retention
Data is retained for the duration needed to provide the service, meet the customer’s configured retention requirements, maintain security and audit evidence, resolve disputes and comply with law. Backups may retain deleted data for a limited recovery period before rotation.
Customers should define retention periods appropriate to employment, payroll, accounting and legal obligations. Gatula will delete or return processor data according to the applicable agreement, subject to lawful retention requirements.
8. Security
Gatula uses measures designed to protect confidentiality, integrity and availability, including authenticated sessions, role-based access, company isolation, audit logging, protected secrets and controlled storage. No system can guarantee absolute security.
9. Your rights
- Request access to personal data.
- Request correction of inaccurate data.
- Request deletion where the right applies.
- Request restriction or object to processing where applicable.
- Request data portability where applicable.
- Withdraw consent where processing is based on consent.
- Lodge a complaint with Persónuvernd, the Icelandic data-protection authority.
10. Employer-controlled data
Employees should normally direct requests about work records, schedules, approvals and employer policies to their employer, which determines the purpose and use of that data. Gatula will assist the customer with verified data-subject requests where contractually and legally required.
11. Cookies and local storage
Gatula Time uses strictly necessary authentication and security cookies to maintain signed-in sessions and protect access. Non-essential analytics or marketing technologies should not be enabled without appropriate notice and choice where required.
12. Location verification and geofencing
When a customer enables GPS verification, Gatula Time is designed to capture foreground location evidence at Clock In and/or Clock Out according to the configured company policy. The Core does not continuously track employees in the background.
Geofence checks compare the captured position with customer-configured work locations. Location evidence is stored separately from the core Time Entry, access is permission-restricted, and the customer must configure an appropriate retention period and employee notice.
- GPS may be off, optional, required at Clock In, required at Clock Out, or required at both events.
- The customer is responsible for a lawful basis, transparency to employees and any required impact assessment before enabling monitoring features.
- Location accuracy and geofence results may be recorded as operational evidence.
13. Changes and contact
This policy may be updated when the service, legal requirements or processing practices change. The current version and update date will be published on the website.
Privacy questions and verified rights requests may be submitted through the contact details published on the Gatula Time website.