ShiftCycle Privacy Policy

Effective date: 10 April 2026

1 Who we are

ShiftCycle is a workforce-management and agency-collaboration platform operated by AILZE LTD, registered in England and Wales under company number 14108522, at:

8 Hardy Close, Barbury Business Centre

Preston, Lancashire, PR2 2XP

Privacy enquiries may be sent to admin@ailze.co.uk.

AILZE LTD is registered with the Information Commissioner's Office under reference ZC217506.

ICO Registration: ZC217506

2 What ShiftCycle does

ShiftCycle supports workforce scheduling, shift allocation, clock-in/clock-out attendance, timesheets, availability and leave requests, client workforce requests, notifications, reporting and recruitment-agency operations.

It also includes a Connection / Partner module through which independent client organisations, recruitment agencies, labour providers and approved subcontract agencies may establish trusted relationships and route authorised workforce requests while keeping their own workforce operations separate.

3 Personal information we may process

Depending on how ShiftCycle is used, we may process:

  • Identity and contact data: name, contact details, username, account and organisation information.
  • Workforce data: employee or worker identifiers, roles, assigned jobs, shifts, schedules and operational notes.
  • Attendance and timesheet data: clock-in/out records, hours worked, attendance history and audit information.
  • Availability and leave data: unavailable dates, preferred working periods and holiday/leave requests.
  • Client and agency data: workforce requests, order details, fulfilment status, connected organisation details and authorised partner-routing records.
  • Technical and security data: login records, IP/device information, session data, permission records, notifications and administrative audit logs.

Where enabled, information used for payroll exports, mapping/integration services or other customer-configured operational functions.

Customers should not place special-category or criminal-offence information into ShiftCycle unless it is genuinely required, lawful, appropriately protected and covered by the customer's own privacy information and data-protection procedures.

4 Controller and processor roles

The data-protection role depends on the processing activity.

A customer organisation will normally determine why its employee, worker, client and staffing data is used and will therefore normally act as controller for that operational information.

Where AILZE LTD processes that information only to provide ShiftCycle on the customer's documented instructions, AILZE LTD acts as processor.

AILZE LTD acts as controller for its own account administration, service security, billing, legal compliance, support and similar purposes for which it determines the purpose and means of processing.

5 Purposes and lawful bases

Personal information may be used to:

  • provide and secure the platform;
  • authenticate users;
  • schedule work;
  • record attendance and timesheets;
  • manage availability;
  • process client workforce requests;
  • enable approved agency and partner collaboration;
  • generate reports and notifications;
  • provide support;
  • investigate misuse;
  • comply with legal obligations; and
  • maintain or improve the service.

The applicable lawful basis depends on the purpose and may include contract, legal obligation, legitimate interests or consent where consent is appropriate.

Customer organisations remain responsible for identifying their own lawful basis for processing workforce information.

6 Connection / Partner module and data sharing

The Connection / Partner module is designed for controlled inter-organisational collaboration, not unrestricted database sharing.

Connections should be created through approval between participating organisations.

A client may send an authorised workforce requirement to a connected agency, and an agency may route an authorised part of a requirement to an approved partner where additional capacity is needed.

Each organisation continues to control its own employees and workforce records.

Partner connections do not merge organisation databases. ShiftCycle is designed so that partner users receive only the authorised request or status information needed for the collaboration, while transferred requests remain traceable through system records and audit controls.

Each participating organisation is responsible for ensuring it has a lawful basis for any personal information it shares or receives through a connection.

7 Who information may be shared with

Information may be shared with:

  • the customer organisation and its authorised administrators, managers and coordinators;
  • employees or workers, limited to their authorised account, shift, attendance and availability information;
  • client users and approved partner organisations, only to the extent required for authorised workforce requests and fulfilment;
  • hosting, backup, email, security, mapping, payroll-export or other service providers used to operate enabled functions;
  • professional advisers, regulators, law-enforcement bodies or public authorities where disclosure is required or permitted by law.

Where a supplier processes personal information outside the UK, appropriate UK data-transfer safeguards will be used where required.

8 Retention and deletion

Operational workforce data is retained according to:

  • the customer organisation's instructions;
  • contractual requirements;
  • account configuration; and
  • applicable legal or record-keeping obligations.

On account closure or contract termination, information may be retained for a limited period for backup, security, dispute, accounting or legal purposes before secure deletion or anonymisation.

AILZE LTD keeps its own account, security and business records only for as long as reasonably necessary for the purpose for which they are held.

9 Security

ShiftCycle uses technical and organisational controls designed to protect information, including:

  • authentication;
  • encrypted password storage;
  • secure sessions;
  • role-based authorisation;
  • organisation-specific permissions;
  • input validation;
  • data-access checks; and
  • audit logging for significant administrative activity.

Multi-tenant controls are intended to keep each organisation's operational records logically separated unless an explicit authorised connection permits defined information to be exchanged.

10 Your rights

Depending on the circumstances, individuals may have rights of:

  • access;
  • rectification;
  • erasure;
  • restriction;
  • portability; and
  • objection.

Individuals may also withdraw consent where processing relies on consent.

Requests concerning workforce data should normally be directed first to the employer, agency or customer organisation that controls that information.

AILZE LTD will assist customers with valid requests where required.

You may also complain to the Information Commissioner's Office.

11 Cookies, changes and contact

ShiftCycle may use strictly necessary cookies or similar technologies for authentication, security and session management.

Non-essential analytics or similar technologies will be used only where the required information and consent have been provided.

We may update this Privacy Policy when the platform, legal requirements or processing activities change.

Contact:

AILZE LTD

8 Hardy Close, Barbury Business Centre

Preston, Lancashire, PR2 2XP

admin@ailze.co.uk

ICO Registration: ZC217506