Privacy Policy

How we collect, use and protect personal data when you use Posttime and visit posttime.uk.

1. Who we are

Posttime (“Posttime”, “we”, “us”, “our”) provides time-recording and billing software delivered as a web application at posttime.uk. We are the data controller for personal data collected through our website and for the account and billing data of our customers.

Our registered details are:

  • Trading name: Posttime
  • Registered company name: Yeti Trading and Holding Company Limited
  • Company number: 16962101 (registered in England & Wales)
  • Registered address: Garden Flat, 48 Lower Oldfield Park, Bath, BA2 3HP, United Kingdom
  • ICO registration number: ZC157856
  • Data protection contact: privacy@posttime.uk

2. Controller and processor roles

Posttime acts in two different capacities depending on the data:

  • As a controller: for data about our website visitors, prospects and the individual users who administer a customer account (for example, names and work email addresses, billing contacts and support correspondence).
  • As a processor: for the data our customers enter into the application, such as their own clients, matters, time entries and invoices. The customer (your firm) is the controller of that data and decides how it is used; we process it only on their documented instructions under our customer agreement and a data processing addendum.

3. Data we collect

CategoryExamples
Account dataName, work email, job role, firm name, and your single sign-on identifier (we use Google or Microsoft sign-in and do not store passwords)
Billing dataBilling contact, billing address, subscription plan, payment status (card details are handled by our payment provider, not stored by us)
Customer content (processed on your behalf)Your clients and matters, time entries, charge rates, invoices, leave records and any notes you enter
Usage dataLog-in times, pages used, feature usage, device and browser type, IP address
Support dataMessages, emails and attachments you send when you contact us
Website dataInformation you submit through forms on the site
Lead search account dataThe email address and single sign-on identifier of anyone who creates an account on our Companies House lead search to unlock CSV export, together with their purchase and download history
Companies House public register dataCompany name and number, incorporation date, status, SIC codes, and the registered office address as published on the Companies House public register. For many small and sole-director companies the registered office is the director’s home address, so this can be personal data

4. How and why we use data

  • To create and administer your account and provide the service.
  • To process subscriptions, take payment and issue receipts.
  • To provide support and respond to your enquiries.
  • To keep the service secure, prevent abuse and investigate incidents.
  • To improve and develop our features using aggregated, non-identifying usage data.
  • To send service messages (for example, important changes or security notices).
  • To send occasional marketing about Posttime where you have asked us to or are an existing customer, and you can opt out at any time.
  • To run our Companies House lead search: to let anyone search and filter the public register free of charge, and to hold an account so that CSV exports can be unlocked, paid for and metered.
  • To meet our legal, accounting and regulatory obligations.

5. Lawful bases

Where we act as a controller, we rely on the following lawful bases under Article 6 of the UK GDPR:

PurposeLawful basis
Providing the service and account administrationPerformance of a contract
Taking payment and keeping financial recordsContract / legal obligation
Security, fraud prevention and service improvementLegitimate interests
Marketing emailsConsent or legitimate interests (soft opt-in for existing customers)
Holding a lead search account and metering CSV exportsPerformance of a contract
Republishing Companies House public register data through the lead searchLegitimate interests (making information already published by law easier to search; the register is published for reuse and its addresses are already public)
Meeting legal and regulatory dutiesLegal obligation

6. Sharing & sub-processors

We never sell your personal data. We share it only with trusted providers who help us run the service, each bound by contract to protect it and use it only on our instructions. These include:

  • Cloud hosting and storage: to host the application and store data securely.
  • Payment processing: to take subscription payments.
  • Accounting integration: QuickBooks Online, where you choose to connect it, to push invoices you create.
  • Companies House: to look up registered company details when you add a client.
  • Email and support tools: to deliver service messages and handle support.

We may also disclose data where required by law, to enforce our agreements, or in connection with a merger, acquisition or sale of assets (with appropriate safeguards). Our current list of sub-processors, with their purpose, location and transfer safeguards, is published in full.

Shared bank-categorisation lookup

To make bank-transaction categorisation faster and more accurate, the application maintains a shared, aggregated lookup that learns which accounting category firms typically assign to a given payee. It is designed so that no individual firm’s data is exposed to another:

  • Only a normalised payee token is used: the bank narrative is stripped of references, numbers and anything shaped like a name, account number or sort code before it is eligible, so identifiers are removed at source.
  • Aggregation threshold: a payee-to-category mapping is only shared once several independent firms have each assigned the same category, and a category is only ever suggested for you to confirm, never applied automatically. A one-off entry never reaches the threshold, so it never leaves your firm.
  • No amounts, dates, counterparties’ account details or free text are included, and the lookup never reveals which firm made any given entry.

We act as processor for this feature and rely on it as a legitimate interest in providing an accurate, improving service. It operates only between firms of a comparable size using the same national tax taxonomy.

Companies House lead search and CSV export

Our lead search lets anyone search companies taken from the Companies House public register. That data is published by Companies House under the Open Government Licence and is free to reuse. Two points about personal data apply:

  • Registered office addresses. The register includes each company’s registered office. For many small and sole-director companies that is the director’s home address. We show and export it exactly as Companies House publishes it, and we do not add, infer or enrich any address, name or contact detail that is not on the register. If a registered office is wrong or should be suppressed, that is corrected at Companies House and the correction reaches us when we next refresh the data; you can also email privacy@posttime.uk and we will remove a record from the search.
  • Your account. Searching and filtering are free and need no account. We ask for an email address only when you download a CSV, so that we can meter and charge for downloads and contact you about them. We are the controller of that account data. We do not sell it, and we do not use it for marketing unrelated to the lead search.

Once you download a CSV, you decide what happens to it, and you become the controller of the data in it. Companies House data being public does not make every use of it lawful. In particular, if you use an export to make contact you are responsible for: honouring opt-outs and any objection to direct marketing; screening sole traders and other individual subscribers against the Mailing Preference Service and, for telephone contact, the Telephone Preference Service or Corporate TPS; telling the people you contact where you got their details and how to object; and complying with the UK GDPR and PECR generally. We do not do any of that on your behalf.

7. International transfers

We aim to keep personal data within the UK or European Economic Area. Where data is transferred outside the UK, we ensure an appropriate safeguard is in place, such as an adequacy decision, the UK International Data Transfer Agreement, or Standard Contractual Clauses with the UK Addendum.

8. Retention

We keep personal data only for as long as necessary:

  • Account & customer content: for the life of your subscription and then deleted or returned within 90 days of termination, unless you ask us to delete it sooner.
  • Billing records: kept for at least six years to meet UK tax and accounting requirements.
  • Support correspondence: typically up to 24 months.
  • Lead search accounts: for as long as the account is in use and then 12 months after the last download, except for the purchase records we must keep for six years for tax. Ask us at privacy@posttime.uk and we will close and delete an account sooner.
  • Companies House register data: held as a refreshed copy of the current public register, replaced each time it is updated; we do not keep a history of removed records.

9. Security

We use appropriate technical and organisational measures to protect personal data, including encryption in transit, role-based access controls, secure authentication and regular backups. For more detail see our Security & data protection page. No system is completely secure, but we work hard to protect your information and will notify you and the ICO of a personal data breach where we are legally required to do so.

10. Your rights

Subject to certain conditions, you have the right to:

  • be informed about how your data is used;
  • access a copy of your data;
  • have inaccurate data corrected;
  • have your data erased;
  • restrict or object to processing;
  • data portability;
  • withdraw consent at any time; and
  • not be subject to solely automated decisions with legal effects (we do not carry out such decisions).

To exercise any of these rights, email privacy@posttime.uk. We will respond within one month. Where the data relates to a customer’s account content (where we are a processor), we will refer your request to the relevant firm.

11. Cookies

This website sets no cookies and uses no analytics. Signing in to the application sets a single strictly necessary cookie. See our Cookie policy Data processing terms Accessibility.

12. Children

Posttime is a business tool and is not intended for, or directed at, children. We do not knowingly collect data about anyone under 16.

13. Changes to this policy

We may update this policy from time to time. We will post the new version here and, where changes are significant, notify you by email or in the app. The “last updated” date shows when it last changed.

14. Contact & complaints

If you have any questions or concerns about how we handle your data, please contact us first at privacy@posttime.uk or by post at Yeti Trading and Holding Company Limited, Garden Flat, 48 Lower Oldfield Park, Bath, BA2 3HP, United Kingdom.

You also have the right to complain to the UK’s supervisory authority, the Information Commissioner’s Office (ICO), at ico.org.uk or by calling 0303 123 1113.