Govern workspace data
with privacy built into
every layer.
Map what is collected, why it is used, who can access it, where it is processed, how long it is retained, and how workers can understand, correct, challenge, or request their data.
ZoikoTime supports privacy controls and evidence. Customers remain responsible for lawful configuration, notices, consultation, and use.

Minimization, rights, access, retention,
residency, and audit — at a glance.

System-level invariants — not a one-line
marketing claim.

Tenant isolation
Deny cross-tenant access across data,
jobs, exports, and support.
Data minimization
Collection contracts allow only
approved fields.
Purpose limitation
Every category maps to an approved
purpose and basis.
Role enforcement
Server-side, deny-by-default, and
independently auditable.
Inventory, rights queue, access reviews,
retention, and residency — in one screen.

KPI row
Purpose/basis gaps, open rights
requests, access reviews due.
Rights queue
Request type, identity verification, due
date, and status.
Access review panel
Role, data scope, privileged access,
and remediation.
Residency & sharing
Region, sub-processors, transfer
mechanism, and support access.
Every category — source, purpose, basis,
sensitivity, retention, and owner.

Activation is blocked until purpose, basis, and
scope are complete.

Allowed
Approved timestamps, minimum device metadata, disclosed location
where necessary.
Prohibited
Hidden screenshots, keystroke content, webcam/microphone
surveillance, protected-trait inference.
Activation gate
Blocked until owner, purpose, basis, notice, and risk review are
complete.
Least privilege for admins. Full visibility for the
worker whose data it is.

Least privilege
Deny by default; managers see only permitted
operational records for their team.
Worker view
Own records, source, notices, corrections, and
case outcomes — never peer data.
Correction & challenge
Human review considers evidence; system output
is never the final adverse decision.
Secure intake, verification, deadlines, and
audited response.

Regions, holds, deletion evidence, sub-
processors, and disconnect behavior.

No "deleted everywhere" claim unless verified. Backups, integrations, and failures are shown explicitly.
Human-in-command AI. Contained,
assessed, and disclosed incidents.

AI cannot issue final discipline, termination, pay, promotion, or legal decisions. Sensitive inference — protected traits, health, emotion, union, or political signals — is
blocked by policy.
Configuration, review, and audit stay
separated by role.

| Action | Privacy Admin | Security | HR / Legal | Manager | Worker |
|---|---|---|---|---|---|
| Data inventory | ✓Full | ✓View | ✓View | Scoped | ✓Own data |
| Rights cases | ✓Full | ✓Full | Limited | No | ✓Own case |
| Retention / hold | ✓Full | Edit | ✓View | No | ✓Own outcome |
| Incident | ✓Full | ✓Full | ✓Full | Scoped | ✓Own notice |
Data inventory & purpose mapping
Basic on Entry/Team; custom multi-region on Enterprise.
Rights requests
Manual-assisted on Team; custom SLA on Enterprise.
Custom retention & legal hold
Available on Business and above.
Questions about Privacy & Data Protection

What is ZoikoTime Privacy & Data Protection?
What workforce data does ZoikoTime process?
Does ZoikoTime monitor employees?
Can workers see and correct their data?
How long is workforce data retained?
Does ZoikoTime guarantee GDPR or other legal compliance?

Give workforce data a governed home.
Request a guided demo, review the privacy framework, or contact our privacy team directly.
