Skip to content

Privacy notice

How personal information is collected, used, disclosed and retained through Timeslip, in terms of the Protection of Personal Information Act 4 of 2013.

Last updated 19 September 2026 · version 2026-09-19

1. Who we are

1.1 Timeslip (the “Service”) is operated by Warwick Brown (“we”, “us”, “our”). Our Information Officer for the purposes of the Protection of Personal Information Act 4 of 2013 (“POPIA”), registered with the Information Regulator, is Warwick Brown.

1.2 Enquiries about this notice, and requests made under it, may be sent to support@timeslip.co.za or by post to the address in the panel at the foot of this page.

1.3 This notice is addressed to the students and lecturers who use the Service, and to the university schools that adopt it (each a “School”).

2. Two roles: when we are the responsible party, and when we are only an operator

2.1 POPIA distinguishes between a responsible party, which determines the purpose and means of processing, and an operator, which processes on behalf of a responsible party. We act in both capacities, in respect of different information:

  • Claim and payroll records: we are an operator. The hours you have submitted, the timesheet generated from them, the signatures on it, the sealed PDF, and the audit trail recording who was emailed and who opened, signed or declined the timesheet, constitute your School's record of work for which it is paying. Your school is the responsible party for that record, and we process it on the school's instruction. A request to amend or delete a timesheet that has been submitted and signed is accordingly referred to your school, which decides it. The period for which the School retains a timesheet delivered to it is determined by the School under its own policies and those of the university, and not by us.
  • Account information: we are the responsible party. This comprises your email address and password, your session, the links we email to you, the record of messages sent to you, your push-notification subscriptions, your School membership and role, and the information we retain to secure the Service and to respond to support requests. This notice governs that information, and the rights in section 12 are exercisable against us.

2.2 Hours that you have logged but not yet submitted are visible only to you and may be deleted by you at any time. Once a timesheet has been submitted, it forms part of the School's record as described in 2.1.

3. What personal information we collect, and where it comes from

3.1 We collect only the information required to produce a timesheet and to operate an account.

3.2 Students

  • Name, university email address, student number and School.
  • The signature you draw once, which is applied to the timesheets you submit; and whether you have declared that you are an international student, which determines your monthly hour limit.
  • The hours logged: date, start and end time, duration, a description of the work, and the course concerned. For teaching-assistant work, the rate at which the claim is made.
  • Notes about your claims made and kept by the School office.

3.3 Lecturers

  • Name and university email address, as they appear on the timesheets you sign or approve.
  • Your signature, where the School still collects one.
  • On signing a timesheet: the time, the internet (IP) address from which you signed, and the browser used. This is retained solely as evidence of the authenticity of the signature should it be disputed.

3.4 All account holders

  • Your email address and your password. The password is stored only as a scrypt hash and never in readable form.
  • A session record while you are signed in, and short-lived records for email confirmation and password-reset links.
  • The School to which you belong, and your role in it.
  • A record of messages sent to you: recipient, subject, time, and whether delivery succeeded.
  • Where you enable notifications on a device or browser: the endpoint address supplied by that browser, and the keys used to encrypt what we send to it.
  • An audit trail of each timesheet (submitted, opened, signed, declined), with the email address of the person who performed each action.

3.5 This information is collected directly from you, save for the approved lecturer list, which is supplied by the School, and the School office's own notes about a claim.

3.6 We do not carry advertising, we do not sell or share personal information for the purposes of any third party, and we do not build a profile of you for any purpose other than the School's record of the work for which it is paying.

4. Why we collect it

4.1 Personal information is processed for the following purposes:

  • to enable you to log hours and to generate the timesheet your School requires;
  • to deliver that timesheet to the lecturer who must sign or approve it, and to the School office;
  • to be able to demonstrate, subsequently, that a signature on a document was genuinely given;
  • to create, operate and secure accounts, and to notify you about your own claims;
  • to prevent abuse and to respond to support requests; and
  • to comply with the record-keeping obligations that apply to us.

4.2 We do not sell personal information, we do not carry advertising, and personal information is not used to train any machine-learning model.

5. Is it voluntary?

5.1 Whether you are required to claim your hours through the Service is a matter between you and your School. Where the School does so require, you should ask the School what alternative process it offers.

5.2 A university email address is mandatory in order to hold an account. Your name, student number and the hours themselves are mandatory in order to submit a claim, because a timesheet cannot be produced without them.

5.3 The following are optional, and the Service functions without them: notifications on a device or browser; the statistics and leaderboard screens (section 15); and the display preferences described in section 14. Your express confirmation is required before a timesheet is submitted, and you may stop using the Service at any time.

6. Our lawful basis (POPIA section 11)

6.1 In respect of account information and the security of the Service, we rely on processing being necessary to provide the Service you have requested and on our legitimate interest in operating and securing it (section 11(1)(b) and (f)), and on your consent where you have given it, for example by enabling notifications (section 11(1)(a)).

6.2 In respect of claim and payroll records, we process on the authority and instruction of the School as its operator (section 20). The School bears the justification for that processing, and the express confirmation given before a timesheet is submitted is obtained and recorded on the School's behalf.

6.3 Where a record must be retained in order to comply with an obligation imposed by law, we rely on section 11(1)(c).

7. Who sees it

7.1 Access is limited by role. A student has access to their own hours and timesheets. A lecturer has access to the timesheets addressed to them. The School office has access to the records of its own School. No School has access to the records of another.

7.2 Submission of a timesheet discloses it: the lecturers named on it see the hours claimed against their courses, and the School office receives the completed timesheet. Your express agreement to that disclosure is obtained before anything is sent.

7.3 Until a student submits a block of hours, the School office and the person operating the installation see how many hours have been logged and not what the student recorded about them. The description of the work done and the times of day it was done are not available to them on any screen, in any download or in any export until the student submits the block or, where the School sends timesheets by hand, until the student marks the block as finished or the office records that the paperwork has arrived. The date, the number of hours, the course and the lecturer remain available throughout, because the School needs them in order to see who is behind and whom to ask about it.

7.4 The person operating the installation has access to the data for the purposes of running the Service and responding to support requests, and may view the Service as another user in order to reproduce a reported fault. Every such session is recorded, and such a session cannot be used to alter anything on a student's behalf.

7.5 In such a session the entries described in clause 7.3 are withheld in the same way, and the Service displays a placeholder in place of the description and the times. The person operating the installation may set that withholding aside for the duration of a single session where it is necessary in order to answer a support request, and must record a reason for doing so. The reason, the account viewed and the time are recorded, and that record is retained for three years.

8. Operators we use, and who else it passes through

8.1 Personal information passes to the five categories of recipient listed below and to no others, in each case solely for the purpose of delivering the Service. The Service uses no analytics, no trackers, no advertising and no third-party fonts or scripts. Every font and image is served from our own server.

  • Hosting provider. The Service runs on a virtual server rented from Microsoft Azure, in its South Africa North (Johannesburg) region. The database, the sealed timesheets and the daily backups are stored on that server. Microsoft provides the infrastructure and does not have access to the contents in the ordinary course.
  • Mail host. Email is sent through the mailbox associated with the Service's own domain, at a South African provider, over an encrypted connection. Messages may contain names, hours and, in some cases, a timesheet.
  • Resend, only where no mail host is configured. A deployment may fall back to an HTTP mail service hosted outside South Africa. On that route the contents of a message leave the Republic in order to be delivered, which is a transborder flow in terms of POPIA section 72 (see section 9). The fallback is used only where the mail host above has not been configured.
  • Your browser's push service, where you enable push notifications: Apple, Google or Mozilla, depending on your device. The payload is encrypted so that only your own browser can read it. The push service is able to determine that a message is being delivered to your device, but not its contents.
  • Backup storage. A copy of each nightly backup archive may be sent to a second machine to protect the School's records against loss. That copy contains all of the information described in this notice. Where the deployment is configured with an encryption key, the archive is encrypted before it is sent, and the receiving machine holds it without being able to read it.

8.2 We do not otherwise disclose personal information, except as described in this notice or as required by law.

9. Information that crosses a border (POPIA section 72)

9.1 The server and the mail host are located in South Africa. In the ordinary course, therefore, personal information is not transferred outside the Republic. The exceptions, each arising from section 8, are as follows:

  • Resend fallback. Where a deployment operates without its own mail host, the contents of a message (a name, hours and, in some cases, a timesheet) are sent to a service outside South Africa for delivery. We rely on section 72(1)(a): that service is bound by written terms to protect the information and to use it only to deliver the message.
  • Push services. Apple, Google and Mozilla are located outside South Africa. They receive the endpoint address supplied by your browser and a payload encrypted so that only your browser can open it, which is the minimum the Web Push standard permits. Where notifications are disabled, or have never been enabled, nothing is sent to them.
  • Offsite backup, where sent abroad. Where a deployment copies its nightly archive to a machine in another country, that copy constitutes a transfer of all of the information described in this notice. On this deployment the destination is a machine under our control, and where an encryption key is configured the archive is encrypted before it is sent.

10. How long it is kept

10.1 Personal information is retained for the following periods:

  • Signatures and the signing trail. 180 days after a timesheet is completed, the student's signature on it, each lecturer's signature, the IP address and browser recorded with each signature, and the sealed PDF held on our server are erased. A record that the timesheet was completed, and a cryptographic fingerprint of the document, are retained so that a copy held by any person can still be verified.
  • The signature on your profile, being the signature you draw once and reuse, is cleared after 180 days during which nothing has been logged.
  • An unfinished logbook, claim month or research year is deleted one year after it was abandoned.
  • The audit trail of a completed timesheet (who was emailed, who opened it, who signed) is retained for three years and then purged. A timesheet still in progress retains its full trail.
  • Emails. The contents of a queued message are erased after 60 days, and the record of the message is deleted after 180 days.
  • Links and sessions. An email confirmation link is valid for 24 hours; a password-reset link for one hour and for a single use; a signing link for 60 days; and a signed-in session for 30 days.
  • Hours and timesheets are retained for as long as the School requires them as a record of work for which it has paid. They are deleted on your request, subject to section 2, or when the School ceases to use the Service.
  • Backups are taken daily and expire on their own schedule: nightly archives after approximately fourteen days, and a smaller set taken at each release, retained by count. A backup is a point-in-time copy and is never edited. Information deleted from the Service accordingly remains in any backup taken before the deletion until that backup expires, wherever it is held, including any copy held on a second machine.

10.2 A timesheet delivered to your School is the School's record from the time of delivery, and the period for which the School retains it is determined by the School under its own policies (section 2).

11. How it is kept, and what happens if something goes wrong

11.1 Sign-in is restricted to university email addresses. Passwords are stored as scrypt hashes. Session, password-reset and signing tokens are stored only as hashes, so that a copy of the database does not yield usable credentials. Signing links are single-use, expire, and are encrypted at rest.

11.2 Connections to your browser and to the mail host are encrypted in transit. Access is rate-limited, input is limited in size, and the Service loads no resources from any origin other than its own. Completed timesheets are sealed so that any alteration can be detected. These are the appropriate, reasonable technical and organisational measures contemplated by POPIA section 19, having regard to the size of the Service.

11.3 Security compromises. Where there are reasonable grounds to believe that personal information has been accessed or acquired by an unauthorised person, we will notify the affected School without undue delay, so that it can meet its obligations under POPIA section 22 in respect of the records for which it is responsible. In respect of the information for which we are responsible (account, sign-in and support information), we will notify the Information Regulator and the data subjects affected, as section 22 requires, as soon as reasonably possible after the discovery of the compromise.

11.4 The Service is a beta release operated by a sole proprietor on a single server, as stated in the terms. That applies to its security as it does to its other features.

12. Your rights, and how to use them

12.1 Under POPIA you have the right to:

  • be told what personal information we hold about you, and to receive a copy of it;
  • request the correction of information that is inaccurate;
  • request the deletion of information we hold about you;
  • object to the processing of your information for a particular purpose; and
  • withdraw a consent you have given, without affecting the lawfulness of processing carried out before the withdrawal.

12.2 These rights may be exercised free of charge. No prescribed form is required, and you may use any reasonable channel.

12.3 Two of these rights may be exercised within the Service. Your data provides a copy, as a single file, of everything held under your email address, and is where a request for deletion is made. That page states what the file excludes and why.

12.4 Any other request, including a correction, an objection to a particular use, or a concern that something was not removed following a deletion, may be sent to support@timeslip.co.za from the email address under which the account is held, or by post to the address at the foot of this page. We will act on a request to correct or delete, and inform you of the action taken, within 30 days (POPIA sections 5, 11(3) and 23 to 25, as strengthened by the 2025 Amendment Regulations).

12.5 A deletion does not extend to the following: a timesheet already delivered to your School, which is the School's document and is deleted by the School (we refer such a request to it, as section 2 explains); and a backup, which retains a copy until it expires (section 10).

13. Complaints to the Information Regulator

13.1 If you are dissatisfied with the manner in which we have processed your personal information, you may lodge a complaint with the Information Regulator (South Africa), whether or not you have first raised the matter with us:

  • Email (POPIA complaints): POPIAComplaints@inforegulator.org.za
  • Email (general enquiries): enquiries@inforegulator.org.za
  • Website: inforegulator.org.za · Telephone: 010 023 5200 / 0800 017 160 (toll-free)
  • Address: Woodmead North Office Park, 54 Maxwell Drive, Woodmead, Johannesburg, 2191 (postal: P.O. Box 31533, Braamfontein, Johannesburg, 2017)

14. Cookies and what is stored in your browser

14.1 The Service sets no tracking cookies, uses no third-party analytics and carries no advertising. Its content security policy permits scripts from its own origin only. It sets the following three first-party cookies and no others:

  • pma_session: keeps you signed in and carries the protection against cross-site request forgery. It is strictly necessary, in that sign-in is not possible without it. It is HttpOnly, SameSite=Lax, and Secure in production. It lasts for a maximum of 30 days and is cleared on sign-out.
  • pma_theme: records your choice of light theme, dark theme or your device's setting, for one year. It is a cookie, rather than browser storage, so that the page is rendered in the correct theme from the first paint.
  • pma_ta_hours: records whether the block page displays teaching-assistant hours alongside the others. It is set when you use that switch and lasts for one year.

14.2 The second and third cookies record a display preference only. They contain the value you selected and no identifier, and cannot be used to track you. We rely on POPIA section 11(1)(b) and (f), and not on consent, for all three cookies, because none of them tracks, profiles or advertises. For that reason there is no cookie banner. Blocking the session cookie prevents sign-in. Blocking the other two results only in the loss of the preference.

14.3 The following are stored by your browser and are never transmitted to us: a draft on the no-account quick form, where a School has enabled that form; a record that you dismissed the "add to home screen" suggestion; and, for a lecturer, a record that the welcome card was dismissed, which lasts only until the tab is closed. Clearing your browser's site data removes all of them.

15. Leaderboards are opt-in

15.1 Where a deployment has the statistics and leaderboard screens enabled, participation is voluntary. You appear on a leaderboard only if you join it, and you do so under a handle of your choosing. No information that identifies you (your email address, name or student number) leaves your School for the cross-school leaderboard. Only the handle and the figures attributed to it are published.

15.2 Hours are never ranked. The figures published reflect habits only: logging on the day worked, months marked as complete, and timesheets submitted on time. You may leave at any time. Each leaderboard is rebuilt in full on every pass, so that leaving removes you from it.

16. Children and special personal information

16.1 The Service is intended for registered university students and university staff and is not directed at children. We do not knowingly collect the personal information of a child. If you believe that we hold such information, please notify us and it will be deleted.

16.2 We do not request special personal information as defined in POPIA (including information concerning health, religious or philosophical beliefs, race or ethnic origin, or trade-union membership), and the Service contains no field for it. The Service does record whether you are an international student, solely because that determines your monthly hour limit. Please do not include special personal information in any free-text description of your work.

17. Asking for a record (PAIA)

A request for access to a record, as distinct from a request concerning your own personal information, is made under the Promotion of Access to Information Act 2 of 2000. The procedure, the applicable fees and the categories of record we hold are set out in the PAIA manual. A request under POPIA concerning your own personal information, as described in section 12, is free of charge and requires no form.

18. Changes to this notice

This notice bears the same version as the terms, shown at the head of this page. Where it is amended in a material respect, account holders will be asked to accept the amended version when they next sign in.

Who we are

Our identifying details, as section 43 of the Electronic Communications and Transactions Act 25 of 2002 asks for them.

Name
Warwick Brown (sole proprietor, no CIPC registration), trading as Timeslip
Address
18 Murray Avenue, Morningside Manor, Sandton, Gauteng, South Africa
Contact
General: support@timeslip.co.za
Information Officer (POPIA)
Warwick Brown
Website
timeslip.co.za