Who we are
Tandem is operated by [legal entity name, company number, registered address]. For most customer workforce, scheduling, attendance, location, form, and safety records, the customer company is the controller and Tandem acts as its processor. Tandem is the controller for direct account administration, billing, support, security, product communications, and its own website/service operations.
Contact: [privacy email]. Data protection contact: [DPO or privacy lead, if appointed].
Product scope
Tandem is designed for field workforce scheduling, attendance, geofenced visit tracking, forms, job records, safety workflows, and operational reporting. Tandem is not intended for healthcare use and must not be used to store protected health information, patient medical records, or other healthcare-regulated data. Customer companies must configure Tandem for lawful workforce monitoring, including any required worker notices, consultation, impact assessments, or retention rules.
Personal data we process
| Category | Examples | Typical purpose |
|---|---|---|
| Account and identity | Name, email, role, phone, profile settings, company membership | Authentication, access control, support, and account management |
| Workforce and schedule | Jobs, assignments, teams, roles, skills, regions, holidays, absences, certifications | Scheduling, dispatch, absence controls, workforce planning, and compliance records |
| Location and attendance | Clock-in location, geofence enter/exit, site radius state, visit segments, route/navigation prompts, location permission state | Arrival tracking, dynamic job duration, attendance audit, safety, and operational reporting |
| Job and form records | Job notes, checklists, required forms, photos, PDFs, attachments, accident reports | Work execution, evidence capture, closeout, reporting, and customer record keeping |
| Device and communications | Push tokens, app state, local app settings, support messages, logs | Notifications, troubleshooting, security, and service reliability |
| Website and app usage | Strictly necessary cookies, session storage, selected UI preferences, security logs | Authentication, fraud prevention, diagnostics, and service operation |
Sources of personal data
- Users and customer admins provide account, worker, role, job, site, form, and support information.
- Mobile devices provide location, notification, device, offline queue, and app-state information when enabled by the user and customer company.
- Customer companies may import or create worker, team, absence, holiday, certification, and schedule records.
- Tandem and its providers generate logs, audit records, security events, and support diagnostics while operating the service.
How we use data
- Provide the Tandem service and maintain customer workspaces.
- Authenticate users and enforce tenant, role, and worker access.
- Schedule jobs, teams, appointments, meetings, and worker visits.
- Capture assigned job-site arrivals and exits for geofenced jobs where tracking is enabled and the worker is clocked in or otherwise authorized.
- Manage forms, attachments, PDFs, certifications, breaks, absences, and safety workflows.
- Send operational notifications such as priority jobs, clock reminders, site arrival, workflow, and lone-worker alerts.
- Detect, investigate, and prevent security incidents, misuse, and service errors.
- Meet legal, tax, accounting, and contractual obligations.
Mobile location and background processing
Tandem Mobile may collect foreground and background location data to enable assigned job-site geofencing, automatic arrival/departure visit records, clock and attendance controls, navigation prompts, and lone-worker alerts. Background location is intended to be used only for work-related Tandem functions where the customer company has enabled the feature and the worker is clocked in, available, or otherwise covered by an explicit company policy or override.
Tandem is not designed for covert monitoring or continuous tracking outside work duties. Workers can manage device permissions in system settings, but some mobile workflows may not work without location or notification permissions.
Legal bases
| Processing | Typical legal basis where UK/EU GDPR applies |
|---|---|
| Providing the Tandem service to customer companies | Contract and legitimate interests |
| Customer workforce monitoring, attendance, location, forms, and safety records | The customer company's lawful basis, usually legitimate interests, legal obligation, contract, or consent where required by local law |
| Billing, tax, accounting, legal claims, and compliance | Contract, legal obligation, and legitimate interests |
| Security logs, abuse prevention, audit trails, and service diagnostics | Legitimate interests and legal obligation |
| Optional marketing or non-essential tracking if added later | Consent where required |
Customer companies are responsible for selecting and documenting the lawful basis for their employment-related processing, including location and attendance data.
Sharing and subprocessors
Customer data is shared with authorized users in the same customer workspace according to their role. We also use subprocessors for cloud hosting, database, authentication, storage, maps, mobile push delivery, error monitoring, and support. The current list is maintained at /subprocessors.
Retention
Customer workspace data is retained while the customer account is active, unless the customer configures or requests deletion earlier and Tandem is allowed to delete it. Location, visit, clock, form, safety, and audit records may be retained for customer operational, employment, contract, dispute, safety, and compliance purposes. Backups, audit logs, security logs, and legal records may be retained for limited periods needed for security, recovery, legal, tax, and accounting purposes. Exact production retention periods must be added before paid sale.
Your rights
Depending on your location, you may have rights to access, correct, delete, restrict, object to, or receive a copy of personal data. If your employer or contracting company uses Tandem, contact that company first because it controls most workforce records. You can also contact [privacy email].
Data deletion, correction, export, and restriction request details are available at /data-deletion.
Selling personal data and targeted advertising
Tandem is not designed to sell worker personal data or share it for cross-context behavioral advertising. If analytics, advertising, session replay, or similar non-essential tracking is added later, this notice and the Cookie Notice must be updated before those technologies run.
Children
Tandem is intended for business use by customer-authorized users. It is not directed to children and must not be used to knowingly collect children's personal data.
Security
Tandem uses tenant scoping, role-based access controls, Supabase row level security, signed file URLs, transport encryption in production, and operational security controls appropriate to a production test service. Tandem should complete production monitoring, incident response, backup/restore, upload scanning, and secret rotation before paid sale.
Automated decisions
Tandem may calculate operational statuses such as onsite, late, clocked in, available, blocked, or complete from schedule, clock, geofence, visit, form, and workflow records. Tandem is not designed to make legally significant automated employment decisions without customer review.
International transfers
Tandem and its subprocessors may process data in the UK, EEA, United States, or other locations. Where required, transfers must be protected by appropriate safeguards such as standard contractual clauses, adequacy regulations, or equivalent contractual measures.
Changes to this notice
Tandem may update this notice as the product, subprocessors, retention periods, or legal requirements change. Material updates should be versioned and may require users to accept the updated notice before continuing to use the service.
