OPSICLE ← Back to the site

Privacy Policy

Last updated 29 August 2026

OPSICLE is workforce software for shift-based businesses. Most of the personal data that passes through it is not ours — it belongs to the employers who use it, about the people who work for them. This policy explains which data we decide the purposes for, which data we only hold on somebody else’s instructions, and what you can ask us for in either case.

The two roles, and why the difference matters

Data protection law distinguishes the organisation that decides why personal data is processed (the controller) from the one that processes it on the controller’s instructions (the processor). OPSICLE is both, for different data, and the difference decides who you should approach.

Whose dataOur roleWho to ask
Visitors to this website, people who request a demo, and the individuals who administer a customer account Controller Us — info@opsicle.co.uk
Employees, workers and job applicants whose records a customer keeps in OPSICLE Processor Your employer, or the company you applied to. They are the controller and they decide. We will help them answer you, and we cannot answer for them.

If you are an employee and want your data corrected or erased, ask your employer rather than us. They hold the account, they decide what it contains, and the law gives us no authority to change or delete their records on our own initiative. If you contact us we will tell them, and we will not action it ourselves.

Data we hold as a controller

This website

This site sets no cookies, runs no analytics, embeds no trackers and loads nothing from a third party. There is no consent banner because there is nothing to consent to. Our hosting provider processes the ordinary server information any web request produces — IP address, the page asked for, the time, browser type — to serve the page and to defend against attack.

Demo requests and enquiries

When you ask for a demo we collect your name, work email, telephone number if you give one, your company, and whatever you tell us about how you schedule people today. We use it to reply, to prepare for the conversation, and to keep a record of the enquiry. Our lawful basis is legitimate interests — responding to somebody who has approached us about our product. You can ask us to delete an enquiry at any time.

Account administrators

For the people who sign in to administer a customer’s account we hold name, email address, a hashed password, and a record of security-relevant actions taken in the platform. Our lawful basis is performance of a contract with the customer, and legal obligation for the parts we must be able to account for.

Data we process for our customers

Where a customer uses OPSICLE to run their workforce, they decide what goes in. In practice that includes:

Some of this is special category data or close to it — biometric data used to identify someone, and information about health where it explains an absence. We handle it only on the customer’s documented instructions, and the customer is responsible for having a lawful basis and, where required, an appropriate policy document and a DPIA.

Face recognition, specifically

The clock-in terminal can identify staff by face instead of a PIN. Because this is biometric data, it is worth being exact about what happens:

Who else processes it

We use a small number of sub-processors. Each is bound by contract to process personal data only on our instructions and to keep it secure.

ProviderWhat forWhere
RenderApplication hosting and the primary databaseGermany (EEA)
CloudflareContent delivery, security, and object storage for documents, right-to-work evidence, CVs and profile imagesGlobal network; storage in the EU
AnthropicAssessing CVs against a job description, where a customer uses the hiring module’s AI screeningUnited States
PureSMSText messages, such as verification codes and shift notificationsUnited Kingdom
FasthostsOutbound emailUnited Kingdom

Where a transfer leaves the UK we rely on the UK International Data Transfer Addendum to the EU Standard Contractual Clauses, or on adequacy where it applies. AI screening is used only for recruitment material a customer has chosen to put through it; it is not applied to employee records, and no personal data is used to train anybody’s model.

How long we keep it

WhatHow long
Enquiries and demo requestsTwo years from the last contact, unless you ask sooner
CVs and application attachmentsDeleted 90 days after upload by an automatic rule on the storage bucket
Employee and payroll recordsFor as long as the customer’s account is open. They set their own retention, and UK payroll records generally must be kept for six years
Right-to-work evidenceAs the customer requires — statutory retention runs for two years after employment ends
Face templatesUntil consent is withdrawn or the employee record is deleted, whichever is first
Customer data after an account closesAvailable for export for 30 days, then deleted

How it is protected

Your rights

Under UK GDPR you can ask for access to your data, correction of it, erasure, restriction of processing, portability, and you can object to processing based on legitimate interests. Where we rely on consent you may withdraw it at any time without affecting what was done beforehand.

For data we hold as a controller, write to info@opsicle.co.uk and we will respond within one month. For data held in an employer’s account, please ask that employer — see the note at the top of this page.

If you are unhappy with how we have handled your data you can complain to the Information Commissioner’s Office at ico.org.uk, though we would rather you told us first so we can put it right.

Changes

If we change this policy we will change the date at the top. Where a change materially affects how we handle personal data we will tell account administrators directly rather than relying on you to re-read the page.

Contact

OPSICLE — info@opsicle.co.uk