ClockFence Privacy Notice
Pilot version. This notice applies to the ClockFence pilot service. It has been prepared with care but has not yet been reviewed by a solicitor or data protection adviser; it will be reviewed and reissued before ClockFence is offered commercially. Questions about it are welcome at privacy@clockfence.co.uk.
Last updated: 8 September 2026
Who we are: ClockFence is provided by Meridia Projects Ltd, a company registered in England and Wales (company number 17434937) with its registered office at 4-6 Greatorex Street, London, England, E1 5NF. In this notice, "we", "us" and "Meridia" mean Meridia Projects Ltd.
Contact for privacy matters: privacy@clockfence.co.uk
1. Who this notice is for
ClockFence is a clock-in and clock-out app used by construction contractors to record when their workers arrive at and leave a site. Because of the way the service works, we handle personal data in two different roles, and this notice is split into two parts accordingly.
- Part A is for people who set up and manage a ClockFence account for their business (account holders, managers, supervisors and billing contacts). For this data, Meridia is the controller: we decide how and why it is used.
- Part B is for workers (employees and self-employed CIS subcontractors) who clock in and out using ClockFence. For this data, Meridia is a processor: we handle it only on the instructions of the company you work for, which is the controller.
If you are a manager who also clocks in and out on site, both parts apply to you.
Part A: Account holders and managers (Meridia as controller)
A1. What we collect
When a company signs up for ClockFence and while it uses the service, we collect:
| Category | Examples |
|---|---|
| Account details | Name, work email address, phone number, job title, company name and address |
| Login and security data | Hashed password or PIN, session cookie identifier, sign-in times, IP address, device and browser type |
| Billing data | Plan, invoices, payment status, VAT number. Card details are entered directly into Stripe; Meridia never sees or stores full card numbers |
| Usage data | Sites created, settings changed, exception reviews and notes written, CSV exports run, support requests |
| Communications | Emails and support messages you send us, and your marketing preferences |
A2. Why we use it and our lawful basis
| Purpose | Lawful basis (UK GDPR Article 6) |
|---|---|
| Creating and running your account, providing the app, sending service messages (for example, downtime notices or security alerts) | Performance of a contract with you |
| Taking payment, issuing invoices, chasing unpaid amounts, keeping tax and accounting records | Performance of a contract; legal obligation (tax and company law) |
| Answering support requests and fixing problems | Performance of a contract; legitimate interests (running a reliable service) |
| Keeping the service secure, preventing fraud and misuse, investigating suspicious activity | Legitimate interests (protecting our customers, workers and systems) |
| Improving the product using aggregated or de-identified usage statistics | Legitimate interests (understanding how the product is used) |
| Sending product news and marketing emails | Consent. We only send marketing where you have opted in, and you can opt out at any time using the link in each email or by contacting us |
| Establishing, exercising or defending legal claims | Legitimate interests |
Where we rely on legitimate interests, we have considered the impact on you and concluded that our use is proportionate and would be reasonably expected. You can ask for a copy of our assessment by contacting privacy@clockfence.co.uk.
A3. Who we share it with
We do not sell personal data. We share it only with:
- Service providers (sub-processors) acting on our instructions. Our current list is in section C4 below. This includes our hosting provider, our database provider (Supabase, EU region) and Stripe for payments.
- Professional advisers such as accountants, insurers and solicitors where necessary.
- Regulators, courts and law enforcement where we are legally required to do so.
- A buyer or successor if Meridia or the ClockFence business is sold or reorganised. We would tell you before your data became subject to a different privacy notice.
A4. How long we keep it
| Data | Retention |
|---|---|
| Account and profile data | For the life of the contract, then deleted 30 days after the contract ends (except as needed below) |
| Billing records and invoices | 6 years after the end of the financial year they relate to (HMRC requirement) |
| Session tokens | 90 days from issue, or earlier if you sign out |
| Support correspondence | 2 years after the ticket is closed |
| Marketing preferences | Until you withdraw consent, plus a suppression record so we do not contact you again |
Part B: Workers who clock in and out (Meridia as processor)
B1. Your employer or contractor is responsible
If you clock in and out using ClockFence, the company that added you to the system (your employer, or the contractor you subcontract to) is the controller of your data. They decide to use ClockFence, choose the settings that apply to you (such as whether a selfie is required), and are responsible for telling you about it and for handling your rights requests.
Meridia stores and processes your data on that company's behalf under a written data processing agreement. We do not use your data for our own purposes, and we do not share it with anyone other than the sub-processors listed in section C4 or where the law requires.
Your employer must inform you. Under UK GDPR your employer or contractor has to tell you clearly that they use ClockFence, what is recorded and why, before you start using it. The ICO's guidance on monitoring workers explains what employers must do: ICO guidance on monitoring workers. If you have not been told, ask your manager.
B2. What is collected about you
| Category | Details |
|---|---|
| Identity | Your name, trade, role and employment type (employed or self-employed CIS subcontractor), as entered by your employer |
| PIN | The 4 to 6 digit PIN you use to sign in. It is stored in hashed form, so we cannot read it back |
| Clock events | The date and time each time you press Clock In or Clock Out |
| Location at clock events | Your phone's GPS position (latitude, longitude and an accuracy figure) at the exact moment you press Clock In or Clock Out. The server compares this with the boundary your employer has drawn for the site and records the distance from the site |
| Flags | Automatic markers on a clock event, such as: outside boundary, late start, early finish, no clock-out, low GPS accuracy, late sync (recorded offline and uploaded later), or simulated location detected |
| Selfie photo | Only if your employer has switched on the selfie requirement for that site. The photo is taken at clock-in and attached to the event |
| Notes | Any free-text note you choose to add to a clock event, and any review note a manager adds when checking an exception |
| Device and session data | A session cookie so you do not have to sign in every time, and basic technical information (browser type, IP address) in server logs |
B3. Location is captured only when you clock in or out
ClockFence does not track you. It only reads your location at the moment you press Clock In or Clock Out, sends that single reading to the server, and does not ask for your location again until the next time you press a button. There is no background tracking, no route recording and no monitoring between clock events. If you deny location permission, the app will tell you and the clock event may be flagged for your manager to review.
We treat location data as intrusive even though it is not "special category" data under UK GDPR, which is why we collect it only at the two moments needed to confirm attendance.
B4. Why your employer uses this data
Typically your employer uses ClockFence to:
- keep accurate records of hours worked for payroll, CIS returns and HMRC record-keeping;
- confirm that workers were on the correct site;
- produce weekly timesheets and export them for payroll or invoicing;
- review exceptions (for example, a clock-in far outside the site boundary) and record the outcome;
- meet health and safety duties to know who is on site.
Your employer must identify its own lawful basis for this. Meridia cannot do that for them.
B5. How long your data is kept
The retention periods below are Meridia's defaults. Your employer can shorten some of them and may have its own reasons to keep records longer.
| Data | Default retention |
|---|---|
| Clock events and timesheets, including the location coordinates and flags attached to each event | 6 years, to meet HMRC and CIS record-keeping duties and the time limits for employment claims |
| Selfie photos | 90 days, then deleted automatically. Your employer can set a shorter or longer period |
| Session tokens | 90 days, or earlier if you sign out |
| Your worker profile (name, trade, role, hashed PIN) | Until your employer removes you, and in any case within 30 days of the end of their contract with us, subject to the timesheet retention above |
B6. How to exercise your rights
Because your employer is the controller, please send access, correction, deletion or objection requests to them in the first instance. They can pull your full record from ClockFence using built-in export tools. If you contact us directly, we will pass your request to your employer promptly and tell you we have done so, unless we are legally required to act ourselves.
Part C: Information that applies to everyone
C1. Your rights
Under UK GDPR you have the right to:
- Access the personal data held about you and receive a copy.
- Rectification of inaccurate or incomplete data.
- Erasure of your data in certain circumstances (for example, where it is no longer needed).
- Restriction of processing while a dispute about accuracy or use is resolved.
- Object to processing based on legitimate interests, and to direct marketing at any time.
- Data portability of data you provided to us that we process by automated means under a contract or consent.
- Withdraw consent at any time where consent is the basis for processing, without affecting earlier processing.
- Not be subject to solely automated decisions with legal or similarly significant effects. ClockFence's flags (such as "outside boundary") are prompts for a human manager to review; they do not by themselves make decisions about pay or discipline.
To exercise these rights with Meridia as controller, email privacy@clockfence.co.uk. We will respond within one month. We may ask for proof of identity. If a request is complex we may extend by up to two further months and will tell you why.
C2. Complaints
If you are unhappy with how we have handled your data, please contact us first at privacy@clockfence.co.uk so we can try to put things right. You also have the right to complain to the Information Commissioner's Office (ICO), the UK's data protection regulator, at ico.org.uk, by telephone on 0303 123 1113, or by post to Information Commissioner's Office, Wycliffe House, Water Lane, Wilmslow, Cheshire SK9 5AF.
C3. Where your data is stored and international transfers
ClockFence is hosted on cloud infrastructure located in the United Kingdom or the European Economic Area (EEA). Our managed database is hosted by Supabase in an EU region. Transfers between the UK and the EEA are permitted under the UK's adequacy regulations.
Some of our sub-processors (for example, Stripe) are part of groups headquartered outside the UK and may provide support from other countries. Where personal data is transferred outside the UK to a country not covered by UK adequacy regulations, we rely on the ICO's International Data Transfer Agreement (IDTA) or the UK Addendum to the EU Standard Contractual Clauses, together with a transfer risk assessment. You can request details of the safeguards in place by emailing privacy@clockfence.co.uk.
C4. Sub-processors
| Sub-processor | Purpose | Location |
|---|---|---|
| Supabase, Inc. | Managed PostgreSQL database holding all account, worker and clock-in data, including selfie photos, and nightly backups | United Kingdom (AWS London region) |
| Perplexity AI, Inc. | Application hosting for the pilot service (the app server that processes requests; no customer data is stored at rest beyond short-lived server logs). To be replaced by UK/EU hosting before general release | United States, under the UK Addendum to the EU Standard Contractual Clauses |
| Resend, Inc. | Transactional email: account invitations, password resets and backup delivery | EU region (Ireland) |
| Stripe Payments Europe Ltd | Payment processing and invoicing for customer accounts. Stripe handles card details directly; Meridia never sees them | Ireland (with group support outside the UK under appropriate safeguards) |
We will update this list and give customers at least 30 days' notice before adding or changing a sub-processor.
C5. Cookies
ClockFence uses one strictly necessary cookie, named __Host-onsite. It keeps you signed in and is marked HttpOnly and Secure so it cannot be read by scripts or sent over an unencrypted connection. It expires after 90 days or when you sign out. Because it is essential to provide the service you have asked for, consent is not required under the Privacy and Electronic Communications Regulations. We do not use analytics, advertising or tracking cookies. If we introduce any non-essential cookies in future we will ask for your consent first.
C6. Security
We use encryption in transit (TLS) for all connections, hashed storage of PINs and passwords, sign-in lockout after repeated failed attempts, role-based access so that managers see only their own company's data, encrypted backups, and an audit trail of manager reviews. No system is completely secure, and if we become aware of a breach affecting your data we will act in line with our breach procedure and, where required, notify the controller and the ICO.
C7. Children
ClockFence is a workplace tool and is not intended for anyone under 16. We do not knowingly collect data about children. If you believe a child's data has been entered into ClockFence, contact privacy@clockfence.co.uk and we will work with the controller to remove it.
C8. Changes to this notice
We may update this notice from time to time. Minor changes will be shown by updating the date at the top. For significant changes we will email account holders and, where we are the controller, give reasonable notice before the change takes effect. Controllers using ClockFence are responsible for passing on relevant changes to their workers. Previous versions are available on request.
C9. Contact
Meridia Projects Ltd 4-6 Greatorex Street, London, England, E1 5NF Email: privacy@clockfence.co.uk
We have not appointed a statutory Data Protection Officer because we do not meet the criteria that make one mandatory. The privacy@ mailbox is monitored by the person responsible for data protection at Meridia.