Skip to main content
TimeTied
The fine print

Privacy Policy

Filed by the clock instead of by topic. Walk one day with TimeTied and see, hour by hour, exactly what personal data has come into existence, who is holding it and when it disappears.

In force from 15 August 2026 · third edition · TIMETIED LTD, Company No. NI740404

Policies are normally filed by topic, which hides the one thing people actually want to know: at what point does information about me start existing, and in whose hands. TimeTied is a product about the shape of a day, so this document borrows that shape. Read from the top and you travel through a single ordinary Thursday — the phone wakes, a plan gets built, a timer runs, a sync happens, an invoice arrives, the day closes. Every stop states the data created at that instant, why it is allowed to exist, who can see it and when it goes. The matters that belong to no particular hour — borders, security, incidents, your rights — wait at the end of the day, where they can be read in one piece.

One note on scope before the alarm goes. The hours below cover two things at once: this website, and the TimeTied apps for iPhone and Android. Where a stop belongs to the app rather than the site, its opening line says so.

Before the alarm: whose day this is

Somebody has to be answerable before any of this begins, so start there.

The controller
Legal entityTIMETIED LTD, trading as TimeTied
Registered inNorthern Ireland
Company numberNI740404
Working fromBelfast
Privacy contacthello@gettimetied.it.com

TIMETIED LTD builds TimeTied and settles what becomes of the personal data described here. In UK GDPR vocabulary that makes us the controller: the purposes are ours to set, the means are ours to choose, and any question about either is ours to answer. A controller cannot pass that job along, and we do not try to. The distinction matters practically — a processor may only follow the written instructions it is given and decides nothing about the purpose of the work. Every supplier named later in this policy sits on the processor side of that line, with two exceptions flagged where they arise: the app stores, which run their own payment relationship with you, and our professional advisers, who owe their own duties.

Post reaches us at the office filed against company number NI740404 at Companies House. Everything to do with personal data goes to one address — hello@gettimetied.it.com — which a director reads rather than a ticket queue, and no part of data protection here is handed to anyone outside the company.

No statutory Data Protection Officer has been appointed. Article 37 compels one where the organisation is a public authority, where watching people in a regular, systematic way at scale is the core of what it does, or where special category and criminal-offence records pass through it in volume. A planning app that shows you your own diary answers to none of those descriptions. That assessment is revisited when the product changes, and a DPO with published contact details appears in this section the moment one is required.

Most outfits handling personal data by automated means owe the ICO a yearly fee and a place on its register of fee payers; the 2018 charges regulations are where that comes from. We meet it for as long as it attaches to us, and anyone running due diligence is welcome to ask for our current entry.

Inside this policy: the website at gettimetied.it.com and the TimeTied apps for iPhone and Android. Outside it: whatever Apple or Google do with the store account you hold with them, your handset maker's backup service, and any destination you reach by following a link away from here. Those answer to their own notices. Cookie and browser-storage detail lives in our Cookie Policy; the contractual side sits in the Terms of Use.

The people whose data passes through here are: readers of this site, people who ask for email updates, anyone who writes to us, people using the apps, and the named individuals who work at our suppliers and advisers. Nobody sends us files of somebody else's customers, and no clause below is written for that situation. A shared team workspace brings its own paperwork — an Article 28 addendum, a maintained sub-processor list, advance notice of changes — and that paperwork is published with the feature rather than after it.

06:40 — the app opens and knows nobody

In the app. The alarm goes, you unlock the phone, TimeTied opens. At this precise instant no personal data about you exists anywhere in our systems, and that is a design decision rather than a coincidence of the hour: planning a day here does not require an account.

What you make goes straight into a database held in the app's own private area on the handset — the sandbox container on iOS, the private data directory on Android. No other app installed on that phone can reach into it. Neither can we, for the simple reason that nothing has been transmitted. If the handset backs itself up to iCloud or to Google's backup service, that file travels with the backup, encrypted, under Apple's or Google's terms rather than ours; whether that backup runs at all is a switch on the device.

Two things follow from keeping it local-first, and the second is a real cost rather than a boast. Nothing you write is visible to us until you deliberately turn sync on at 11:40. And if the phone is lost before you do, the plan goes with it, because there is no copy here to hand back.

06:44 — you read this website first

Perhaps the app is not installed yet and you are on this page instead. A page request cannot be anonymous — a server has to learn where to post the reply — so it is worth being precise about the small amount that creates.

What a visit to gettimetied.it.com produces
Created at 06:44 Why it exists What permits it How long it lasts
IP address of the connection Returning the page to the right place, and recognising floods of automated traffic Legitimate interests, Art. 6(1)(f) — running a public website that stays up and unabused A short rolling window at the edge; we keep no separate copy
Browser and operating system string Serving markup and fonts a browser can actually render Legitimate interests, Art. 6(1)(f) As above
Path requested, timestamp, response code, referring page where the browser volunteers one Spotting broken links and attack patterns Legitimate interests, Art. 6(1)(f) As above
A strictly necessary security cookie, and only where the protection engages Sorting a reader from a script, and noting that a challenge has already been cleared Exempt from consent under Regulation 6(4) of PECR; Art. 6(1)(f) for the underlying processing Minutes to months depending on the item — the table in the Cookie Policy gives each one

Cloudflare, Inc. delivers these pages as static files from whichever edge location is nearest you and screens arriving traffic for attack patterns. They act on our written instructions as our processor. Nothing here counts your visit: no analytics product runs on this site, in any flavour — hosted, self-hosted or the sort that advertises itself as cookie-free — there is no visitor dashboard for anyone here to look at, and no page carries a measurement pixel.

Exactly one request leaves our own domain. The display and body typefaces come from Google's font service — fonts.googleapis.com for the stylesheet, fonts.gstatic.com for the files themselves. Handing a font file over means your IP address and browser string arrive at Google's servers, and that is the whole of it; the request carries no identifier from us and writes nothing to your device. Block both hostnames and every page stays perfectly readable in whatever your system reaches for instead.

A general rule, since legitimate interests recurs below: wherever we lean on it, the interest is named rather than gestured at, and a balancing exercise sits underneath. Is the processing genuinely necessary for that interest, is there a gentler route to the same result, and would your rights and reasonable expectations be run over by it. Ask about any one of those assessments and you will get the reasoning in ordinary English, and you can object under what you can require of us.

06:58 — an account, if you want one

In the app. Fifteen minutes in, you decide the plan should follow you to a second device. That needs an account, and an account is the first thing all day that puts your details on a server of ours.

Creating one produces: the email address you sign up with, a display name if you choose to set one, a stored verifier of your password rather than the password itself, the moment the account was made, and the preferences that ought to follow the person instead of the handset. The lawful basis is Article 6(1)(b), performance of a contract — you asked for an account and an account is what we are supplying. A verification message goes to the address so that a typo does not lock you out of your own data, and sign-in afterwards issues a session token to the device.

Where signing in through Apple or Google is offered, that route hands us a token and an address and nothing more. Apple's private relay option means the address may be a forwarding one that never reveals your real mailbox. That suits us entirely; a forwarding address reaches you just as well for the two or three messages we would ever send.

07:02 — how old is the person holding the phone

TimeTied is built for adults arranging adult obligations, and its age rules follow from that. Accounts are for people aged 16 or over. Below that age, consent-based processing under UK law needs the authorisation of someone holding parental responsibility, and a planning app has no business collecting it.

Nothing on this website is aimed at children, no part of it is styled to appeal to them, and the app asks nothing about a user's age beyond the age rating the store itself applies. We run no age-estimation technology, because doing so would mean collecting far more about you than the question is worth.

If we learn that an account belongs to somebody under 16, we close it and erase what is attached to it without waiting to be asked. A parent or guardian who thinks their child holds an account should write to hello@gettimetied.it.com and it gets dealt with ahead of the queue.

07:12 — the plan gets built

In the app. Coffee in hand, you lay the day out: a two-hour block for the proposal, half an hour of email, the school run, a run of your own if the afternoon holds. Each block carries a title, a start and an end, a colour, an area label, sometimes a note. Templates repeat the routine ones. Tasks waiting for a slot sit in the tray.

This is the most personal material in the product and deserves saying plainly: a day's schedule tells a reader an enormous amount about a life. Who you see, what you treat as urgent, when you are at home, what you are avoiding. It is handled accordingly.

Where you hold an account with sync switched on, the lawful basis for holding this content is Article 6(1)(b) — the contract is that we keep your plan and give it back on every device you own. Where you do not, the content never leaves the handset and we hold none of it.

Free text, and Article 9. A block title is an empty box, so nothing stops sensitive things going in one. "Physio, 3pm" says something about health. "Mosque" or "Mass" says something about religious belief. "Counselling" says a good deal. Article 9 calls these special category data and holds them to a higher bar. We do not solicit them, do not scan for them, do not index on them and do not act on them — but if you type one, it exists, and we hold it because holding your plan is precisely what you asked us to do. Anyone who would rather keep such an entry off a server can leave sync off, or title the block something only they will understand.

Nobody at TIMETIED LTD reads your content as a matter of routine. Support staff cannot open an account's blocks, no one browses user data out of curiosity, and the single exception is a specific fault you report and expressly ask us to look into — which happens with your knowledge and leaves a record. None of it trains a machine-learning model: not ours, not a supplier's, not in aggregate, not after some hand-waving about anonymisation.

07:30 — three prompts, all refusable

In the app. The app now needs to ask you for things, and it asks at the moment a feature is first reached for, never as a stack of dialogs thrown at you on day one. Every one of them can be refused, and the core of the product keeps working when they are.

Permissions the TimeTied apps request
Prompt What it unlocks Saying no costs you Changing your mind, iOS Changing your mind, Android
Notifications Lead-in nudges before a block, focus-session cues, an end-of-day prompt if you set one Nothing but the alerts; reminders then only surface while the app is open in front of you Settings → Notifications → TimeTied Settings → Apps → TimeTied → Notifications
Calendar, read-only Showing existing meetings beside your blocks so the plan avoids double-booking The plan view shows only what you entered here; you compare against your calendar yourself Settings → Privacy & Security → Calendars Settings → Apps → TimeTied → Permissions, then Calendar
App Tracking Transparency Nothing, and it should never appear — see below Not applicable Settings → Privacy & Security → Tracking Not applicable — Android has no equivalent prompt

The permission dialogs are the operating system asking on our behalf, and granting one is your consent under Article 6(1)(a) to the processing it enables. Consent given at 07:30 can be taken back at 07:31, from the system settings rather than from us, and the app carries on without it.

On App Tracking Transparency: iOS raises that prompt only where an app follows you across other companies' apps and websites, or hands data to a data broker. TimeTied does neither, so there is nothing for the prompt to ask and our declaration to Apple records no data used for tracking. If you never see that dialog in TimeTied, that is the reason, and it is the answer we mean to keep giving.

08:00 — the first reminder fires

In the app. Ten minutes before the first block, the phone buzzes. Almost every alert TimeTied produces is a local notification: the app asks the operating system to raise it at a stated time, the text is composed on the handset, and nothing about it travels anywhere.

A small number of messages genuinely have to originate on a server — a sync conflict needing your decision, a subscription that failed to renew. Those ride Apple Push Notification service or Firebase Cloud Messaging, because on iOS and Android no other road exists. Delivery needs a push token, which identifies an installation on a device rather than a person; we hold it against your account until the platform retires it or the account closes. What we hand to Apple or Google to carry is deliberately thin, and never the contents of a block.

Switch notifications off at system level and the whole mechanism stops, with no message reaching you by another route.

09:15 — a focus session runs

In the app. You start a timer on the proposal block. When it stops, a session record exists: which block it belonged to, when it started and finished, how long it ran, whether breaks were taken, whether it completed or was abandoned, and the note you jotted at the end if you jotted one.

These records are the raw material of the figures at 19:45. Without an account they stay on the handset and go no further. With sync on, they travel the same road as the rest of your content and live under the same rules.

11:40 — sync, and the moment data leaves the phone

In the app. Nothing you wrote this morning has moved. Turning on cross-device sync changes that, which makes it the most consequential switch in the app — so it stays off until you deliberately turn it on.

From then, blocks, tasks, templates, focus sessions, area labels and settings are copied to our servers so a second device can pick them up, keyed to your account identifier. In flight they are encrypted with current TLS; at rest they sit on encrypted storage. Where the hosting provider lets us pick a region, we pick the UK, or the EEA if that is the closest option. The provider runs infrastructure under an Article 28 written contract as our processor: instructions only, staff under confidentiality obligations, approved sub-processors, help with your rights requests, and deletion or return when the engagement ends.

Turning sync back off stops the flow. It does not by itself remove what already arrived — that takes the route described at the day you leave.

12:30 — a meeting appears beside your blocks

In the app. You connected the phone's calendar earlier, so a client call now shows up alongside what you laid out, and the 2 p.m. block you were about to create would have collided with it.

Calendar access is read-only and entirely optional. The app reads what the plan view needs to draw an event: its identifier, title, start and end, and which calendar it came from. We never write to your calendar, never create events, never move or delete one.

Other people live in a calendar, which is the part worth being careful about. An invitation carries the organiser's address and often a list of attendees. We keep as little of that as the display requires: no contact list is built out of it, nobody found there is ever emailed by us, and none of it is enriched, matched or cross-referenced against anything. Those individuals never asked us for anything, and the least we owe them is not to accumulate them.

Disconnect the calendar in the app, or revoke the permission at system level, and the cached references are cleared at the next sync. No purpose for them survives the disconnection.

14:05 — something breaks

In the app. A block refuses to resize and the app closes itself. What that produces depends on a choice you made when you set the phone up.

Crash reports reach us through the platform's own developer reporting, and only where you left that sharing enabled — "Share with App Developers" on iOS, the equivalent switch in Android's settings. A report holds a stack trace, the app version, the OS version, the device model and a timestamp. It describes a fault, not a person, and it carries none of your blocks. We keep them 90 days, long enough to chase a defect across a release cycle, then delete or aggregate them beyond identification.

The apps generate a random install identifier so that two crash reports from the same installation can be recognised as related. Reinstalling the app produces a new one. It is never joined to an advertising identifier, because we do not collect one: TimeTied reads neither the iOS advertising identifier, the IDFA, nor its Android counterpart, and neither app carries an advertising SDK, an attribution SDK or a split-testing SDK.

TimeTied carries no product analytics at all. Should they ever arrive, they will be counts of the plainest kind — a screen opened, a feature used — with no block contents attached, and the supplier will be named in the recipients table below in the same release that introduces them rather than in a later edit of this page.

15:20 — you write to us

You email hello@gettimetied.it.com about the block that would not resize. That message is now personal data too: your address, whatever you wrote, and anything attached.

Where the exchange concerns a product you hold, the basis is Article 6(1)(b); where it concerns something else — a press question, a partnership, a general query — Article 6(1)(f) carries it, the interest being that people who take the trouble to write deserve a reply. Correspondence is kept for 24 months after the last message in the thread, which covers a problem that recurs and a question about a purchase made a while ago, then deleted.

Mail for our domain runs through a provider acting as our processor, stored in the UK, or in the EEA where that is the region on offer. Two practical requests: never send us a password, since we will never ask for one and cannot use it; and remember that a screenshot of a schedule usually contains a good deal more than the bug. Anything you do send is treated as content, with the same care as the rest.

17:00 — you subscribe

In the app. The free tier has done its job and you take out a paid one. The route that purchase travels has a direct privacy consequence worth stating flatly.

Your card number, bank details, billing address and payment credentials never arrive at TIMETIED LTD. The transaction happens inside Apple's or Google's payment system, where they act as merchant of record and as independent controllers of the payment relationship, under their own privacy notices rather than this one. We could not disclose your card details if a court ordered it, because we have never held them.

What the stores pass back to us is entitlement information: a transaction identifier, which product was bought, the purchase and expiry dates, whether it is set to renew, the platform, the store-account country, and signals about refunds, cancellations or failed billing. We use it to switch on the right features, keep them consistent across your devices, answer a billing question and keep the accounts the law requires. The basis is contract for the first three of those, and legal obligation under Article 6(1)(c) for the last — the Companies Act 2006 and HMRC between them set six years, measured from the point that financial year closed, and the duty outlives your account.

Subscriptions renew until cancelled, and cancelling happens in the store rather than here: App Store → Settings → your name → Subscriptions, or Play Store → profile → Payments & subscriptions, with a full day still in hand before the period ends. Deleting the app cancels nothing. Refunds are Apple's or Google's to give under their policies; we will help you ask. Your rights under the Consumer Rights Act 2015 and the Consumer Contracts Regulations 2013 stand regardless, and the Terms of Use set them out.

19:45 — the day gets reviewed

In the app. The evening summary appears: your plan against the hours you truly spent, totals by area, the focus figure, a streak if you have one going.

Every figure there is arithmetic performed on what you entered. A calculation shown to you is not a decision made about you. Nothing in TimeTied produces a legal effect or anything close to one: no score attaches to you, nothing ranks you against other users, no eligibility for anything is determined, and no figure is shared with a soul. That is the substance of Article 22, which hands you a right against being subjected to purely automated decisions carrying legal or comparably serious consequences — a right that has nothing to bite on here, and which stays available if that ever stops being true.

The one automated judgement anywhere in the picture happens at the network layer, where traffic that behaves like a script may be challenged before a page is served. It assesses the request rather than the requester, and a human is reachable at hello@gettimetied.it.com whenever it gets someone wrong.

22:30 — lights out: the full inventory

The day is done. Everything created along the way is listed below with the date it stops existing. Where a period comes from law we name the law; where it is our judgement we give the reason.

What now exists, and how long it lasts
Record Made at Kept for Because
Account details — address, display name, password verifier, settings 06:58 The life of the account; erased within 30 days of a verified deletion request Needed to run the service, and pointless to hold once you have gone
Blocks, tasks, templates, notes and focus sessions held on the handset 07:12 onward Until you delete the item or remove the app It is yours and it is on your device; no copy exists here unless sync is on
The same content copied server-side for sync 11:40 As the account; out of rotating backups within a further 30 days Backups roll over rather than being edited record by record
Cached calendar references 12:30 Cleared at the first sync after you disconnect the calendar Nothing to display means nothing to keep
Push token 08:00 Until the platform invalidates it or the account closes A dead token delivers nothing to anyone
Crash and diagnostic reports 14:05 90 days, then deleted or aggregated past identification One release cycle is long enough to find and fix the fault
Support correspondence 15:20 24 months after the final message in the thread Recurring problems and later questions about the same purchase
Entitlement records from the stores 17:00 While the entitlement is live, then with the accounting records below Features have to match what was actually bought
Accounting and transaction records 17:00 Six years, measured from the point that financial year closed Companies Act 2006 record-keeping and HMRC requirements
Email-updates sign-up Whenever you asked Until you withdraw consent, or 24 months after the last message we sent you Consent-based, and an address that hears nothing back earns no keeping
Website server and security logs 06:44 The short rolling window our edge provider operates Abuse detection; no separate copy is taken by us
Record of a rights request and what we did about it Whenever you ask Up to 3 years Accountability under Art. 5(2) — we must be able to show it was handled
Record of a personal data breach 03:00 Six years from the incident Art. 33(5) requires a record of every one, notified or not
Anything caught up in a live dispute Whenever it arises Until resolved and the limitation period has run — generally six years for contract claims in Northern Ireland Establishing, exercising or defending legal claims

When a period runs out the record is deleted, or stripped until nothing in it can point back to a person. Figures that have genuinely become anonymous may stay indefinitely, the material having ceased to be personal data with nobody left inside it to protect.

Quiet hours: who else has touched any of it

While you slept, a handful of organisations held some part of the day. Every one of them is listed here, with the role it plays.

Recipients, and what each is for
Who Doing what Touching which part of the day In what role Where
Cloudflare, Inc. Serving this website, DNS, and screening traffic for abuse The 06:44 request logs Our processor Global edge network, US-headquartered
Apple Inc. App Store distribution, in-app purchase billing, push delivery, crash reporting where you left it on Entitlements, push tokens, diagnostics Controller in its own right for store purchases and payment Ireland and the USA
Google LLC / Google Ireland Ltd Play distribution and billing, Firebase Cloud Messaging, platform diagnostics, and the font files this page loads The Android equivalents of the above, plus the 06:44 font request Controller in its own right for Play purchases; our processor for messaging Ireland and the USA
Our mail provider Carrying and storing correspondence sent to our domain The 15:20 exchange Our processor United Kingdom or EEA where the service offers it
Our hosting and database provider Running the sync backend for accounts that enable it Everything copied at 11:40 Our processor United Kingdom or EEA region where selectable
Accountant and professional advisers Statutory accounts, tax filings, legal advice when needed The 17:00 transaction records Independent controllers in their own professional capacity United Kingdom
Courts, regulators, law enforcement Only where the law compels disclosure, or where it is needed to bring or defend a legal claim Whatever a valid demand actually reaches Independent controllers UK, or a jurisdiction with proper authority
A buyer, if the business changed hands Sale or reorganisation of the company, or of what it owns Data belonging to the part transferred Controller once transferred Disclosed at the time, with notice in advance where required

A demand from an authority gets checked before it gets answered: we look at whether the request is valid, whether the body making it has power to make it, and whether its scope is narrower than what was asked for. Where we are lawfully able to tell you about it, we will.

We do not sell personal data. Not in the everyday meaning of the phrase, and not in the wider sense some overseas privacy statutes give the word. No advertising network, data broker, enrichment service or list vendor receives anything from us, and none ever will while the table above is accurate.

Quiet hours: when data crosses a border

Some of those organisations operate outside the United Kingdom. Chapter V of the UK GDPR demands an appropriate safeguard whenever personal data leaves it, and which safeguard applies depends on where it is going.

Safeguards by destination
Destination What holds it up In practice
The EEA and other countries covered by UK adequacy regulations UK adequacy regulations, Art. 45 and s.17A of the Data Protection Act 2018 Nothing further is needed while the finding holds; we watch for it changing
A US organisation holding live certification under the UK Extension to the EU–US Data Privacy Framework That certification, for as long as it stands We check the certification is live and actually covers the data before relying on it
Anywhere else without adequacy — a supplier's support team in another country, for instance The UK International Data Transfer Agreement, or the UK Addendum where the supplier's paperwork is built on the EU Standard Contractual Clauses Both are approved instruments under Art. 46; which one applies depends on the supplier's own contract
Any transfer resting on the IDTA or the Addendum A transfer risk assessment, completed before the data moves Weighs how far authorities at the far end can reach in, how sensitive and how bulky the data is, and what encryption and access control add on top
An occasional one-off transfer needed to perform your contract An Article 49 derogation Used only where nothing else is available, for that transfer alone, never as a standing arrangement

Ask which of these covers a particular supplier and you will be told. Where an IDTA or the Addendum is the answer, we will send a copy with the commercial terms blanked out.

Quiet hours: what keeps it safe

Security has to be appropriate to the risk, which is the standard Article 32 sets. What follows is what is actually in place, rather than a wish list.

Found a flaw? Write to hello@gettimetied.it.com. Anyone who reports a flaw honestly, leaves us a reasonable run at fixing it before going public, and neither takes nor breaks anything on the way has nothing to fear from us.

03:00 — the hour something goes wrong

A personal data breach means a security failure that wrecks personal data, mislays it, alters it, exposes it, or lets somebody at it who had no business being there. Incidents rarely announce themselves at a convenient hour, so the procedure runs regardless of the clock.

Because we are the controller throughout, the duty to tell you is ours. It is not passed to a supplier, and it does not wait for the last detail to be nailed down — an incomplete notification inside the deadline beats a tidy one after it.

The day you leave

At some point you stop using TimeTied, and the whole of the above should stop existing. Two routes lead there.

In the app: Settings → Account → Delete account. You confirm, you re-authenticate, and the account is marked for deletion straight away; you are signed out on every device and sync stops. Both stores require an in-app deletion route, and we would provide one regardless.

By email: write to hello@gettimetied.it.com from the address the account uses, saying you want it deleted. Writing from that address is normally all the identity checking needed.

Then: the server-side copy of your content and account is erased within 30 days, and rolls out of encrypted backups within a further 30 as those backups cycle. Anything held on your own handset goes when you delete the app — deleting an account cannot reach into a device we have no sight of, so uninstalling is the step that finishes the job there.

A short list survives deletion, each item for a stated reason: accounting and transaction records, held six years from the end of the financial year (17:00); a minimal suppression record if you opted out of mail, being your address and the fact that you opted out, kept precisely so we do not contact you again by accident; the record of your deletion request itself, so we can show it was honoured; incident records under Article 33(5); and anything genuinely caught up in a live legal claim. Nothing on that list is used for any other purpose.

Taking your data with you. Ask and you get your content in a structured, commonly used, machine-readable file — the portability right at Article 20, done as a working export rather than a formality. Ask before you delete, since the export cannot be produced from data that no longer exists.

Any hour: what the store listings declare

Both stores make developers publish a structured summary of what an app collects, and both are checked against this policy before every release.

Any hour: what you can require of us

These rights belong to you at every hour of the day described above. Using one costs nothing and never worsens the service you get.

Asking. Email hello@gettimetied.it.com and say which right you want and what you are after; a narrower question usually produces a faster and more useful answer. There is no form to complete, no particular wording to use, and no need to cite the legislation for a request to count.

Checking it is you. Before anything is disclosed or deleted we have to be satisfied we are dealing with the right person, since handing your schedule to an impostor would be the worse failure. Writing from the address linked to your account normally settles it. Where we cannot match a request to an account we may ask for a little more, we ask for as little as settles it, identity documents are not demanded as a matter of course, and the response clock starts once that much is in hand.

Timing. We answer a valid request inside one month. Knotty requests, and batches of several landing at once, can stretch that by two further months at most; take an extension and we tell you inside the first month, with the reason for it.

When we might say no. Asking costs nothing. Only a manifestly unfounded or excessive request — the same one repeated without new grounds, typically — can attract a reasonable administrative charge or be turned away outright. Material may also be held back where an exemption in the Data Protection Act 2018 bites, or where letting it go would trample somebody else's rights; you still receive everything releasable, together with an account of what stayed behind and why. Say no and we give you the reasoning, plus the routes below.

Somebody asking for you. A solicitor, relative or friend can make a request on your behalf with reasonable evidence of their authority, such as a signed authority or a power of attorney. The answer normally goes to you rather than to them, unless you tell us otherwise.

If we get it wrong: the ICO

Start with us, at hello@gettimetied.it.com. A complaint that lands here can usually be fixed here, and faster than anywhere else. You are not obliged to come to us first, though, and you can go to the UK's supervisory authority at any point.

Information Commissioner's Office
PostInformation Commissioner's Office (the ICO), Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF
Helpline0303 123 1113
Onlineico.org.uk

Complaining to the ICO carries no charge, and it does not close off your separate right to a remedy through the courts.

Email updates, and other mail

Our marketing amounts to a single mailing list, and it only exists because you asked to be on it.

When this policy changes

This page changes when the product does, when a supplier changes, or when the law moves. Every edition carries its effective date and version at the top.

Version 3.0, effective 15 August 2026. This edition restructures the policy around the day it describes and expands the inventory, the recipient list and the transfer safeguards. It replaces the edition dated 5 August 2026.

Reaching a person

Putting the word "privacy" in the subject line genuinely helps — it routes the message to the right person on the first hop and starts the clock on the correct day.