Legal

Privacy Policy

Effective 22 June 2026

This policy explains how we handle personal data and the rights you have under the GDPR and other privacy laws. We process personal data lawfully, fairly and transparently.

01Overview

This Privacy Policy explains how Mallorn Technical Services ("In A Tick", "we", "us" or "our") collects, uses, discloses and protects personal data in connection with the In A Tick websites, applications, APIs and related services (the "Service"). It also describes the rights available to individuals under the EU and UK General Data Protection Regulation ("GDPR") and other applicable privacy laws.

"Personal data" means any information relating to an identified or identifiable natural person. We are committed to processing personal data lawfully, fairly and transparently.

02Controller and processor roles

Our role under the GDPR depends on the data in question.

Where we are a processor

When a customer organisation uses the Service to manage its workforce, it uploads data about its employees and contractors — such as names, timesheets, regions, hours and overtime calculations ("Customer Data"). For this data the customer organisation is the data controller and decides why and how the data is processed. We act as a data processor and process Customer Data only on the customer's documented instructions, as set out in our Terms of Service and any data processing terms. If you are an employee or contractor of one of our customers, please direct privacy requests to your employer in the first instance; we will assist them in responding.

Where we are a controller

We act as a data controller for personal data we determine the purposes of, including data about account holders and administrators who register for the Service, website visitors, and people who contact us for support or sales. The rest of this policy describes that controller processing.

03Personal data we collect

Information you provide

  • Account data — your name, work email address, organisation name and workspace settings when you register or are invited.
  • Authentication data — we support passwordless email and magic links, passwords, multi-factor authentication (MFA) and, on eligible plans, SAML single sign-on. Depending on the method you use, we process your email, hashed password, MFA enrolment and verification data, SAML identifiers, and authentication events. We never store passwords in plain text.
  • Communications — messages, support requests and feedback you send us, and the contact details you provide.

Information we collect automatically

  • Usage and device data — IP address, browser and device type, pages viewed, and actions taken, collected to operate and secure the Service.
  • Log and audit data — records of significant events (sign-in, approvals, administrative actions) used for security and integrity.
  • Cookies and similar technologies — strictly necessary cookies to keep you signed in and protect the Service. See the Cookies section below.

We do not intentionally collect special categories of personal data (such as health or biometric data) about account holders, and we ask that you do not submit such data except where strictly required and lawful.

04How we use personal data

  • to provide, maintain and improve the Service and your account;
  • to authenticate you and keep the Service and its data secure;
  • to respond to your enquiries and provide customer support;
  • to send service and administrative messages, and — where permitted — product updates you have asked for;
  • to monitor usage, prevent fraud and abuse, and ensure tenant isolation;
  • to comply with legal obligations and enforce our Terms.

06How we share personal data

We do not sell personal data. We share it only as needed and with appropriate safeguards:

  • Service providers (sub-processors) — infrastructure, database hosting, authentication and email-delivery providers that process data on our behalf under contract.
  • Identity providers (SSO) — where your organisation enables SAML single sign-on, authentication is handled by the identity provider your organisation configures, and limited identifiers (such as your email and a unique user identifier) are exchanged with it to sign you in.
  • Within your organisation — administrators of your workspace can access account and activity data for users in that workspace.
  • Legal and safety — where required by law, to enforce our Terms, or to protect the rights, safety and security of users and the public.
  • Business transfers — in connection with a merger, acquisition or sale of assets, subject to this policy.

07Sub-processors

We engage a limited set of sub-processors to deliver the Service, including cloud database and hosting infrastructure and transactional email delivery. We require each sub-processor, by contract, to provide a level of data protection consistent with this policy and the GDPR. A current list of sub-processors is available on request at support@inatick.app, and where we act as a processor we will give affected customers reasonable notice of new sub-processors.

Where your organisation enables SAML single sign-on, the identity provider it configures acts as an independent controller for the authentication it performs, and your organisation's agreement with that provider — not this policy — governs how it handles your data.

08International data transfers

We are based in Western Australia, Australia and may process personal data in Australia and in other countries where we or our sub-processors operate. When we transfer personal data out of the European Economic Area, the United Kingdom or Switzerland, we put in place an appropriate transfer mechanism — such as the European Commission's Standard Contractual Clauses (and the UK Addendum where relevant) — together with any supplementary measures required to ensure an adequate level of protection. You may request information about these safeguards at support@inatick.app.

09Data retention

We retain personal data only for as long as necessary for the purposes described in this policy, including to provide the Service, comply with our legal obligations, resolve disputes and enforce our agreements. When we act as a processor, we retain Customer Data in accordance with the customer's instructions and our Terms. When data is no longer needed, we delete it or anonymise it. We will make Customer Data available for export for a reasonable period after account termination before deletion.

10Your privacy rights

Subject to applicable law, and in particular where the GDPR applies, you have the following rights in relation to your personal data:

  • Access — to obtain confirmation of whether we process your data and a copy of it.
  • Rectification — to have inaccurate or incomplete data corrected.
  • Erasure — to have your data deleted in certain circumstances ("right to be forgotten").
  • Restriction — to limit how we process your data in certain circumstances.
  • Portability — to receive your data in a structured, commonly used, machine-readable format and to have it transmitted to another controller where technically feasible.
  • Objection — to object to processing based on legitimate interests, and to object to direct marketing at any time.
  • Withdraw consent — to withdraw consent at any time where processing is based on consent, without affecting prior processing.
  • Complain — to lodge a complaint with a supervisory authority (see Complaints below).

To exercise these rights, contact us at support@inatick.app. We will respond within the timeframes required by law (generally within one month under the GDPR). We will not discriminate against you for exercising your rights. If your data was provided to us by an organisation using the Service (where we act as processor), we will refer your request to that organisation and assist them in responding.

11Automated processing

The Service applies the overtime rules and thresholds configured by a customer organisation to calculate hours and rate codes. These calculations support human review and approval — every timesheet is approved by an authorised person — and we do not use them to make decisions producing legal or similarly significant effects about you without human involvement. We do not carry out automated decision-making within the meaning of Article 22 of the GDPR for account holders.

12Security

We implement appropriate technical and organisational measures to protect personal data, including encryption in transit and at rest, database-level row-level security to enforce tenant isolation, zero-trust server-side validation of every action, access controls and audit logging. No method of transmission or storage is completely secure, and we cannot guarantee absolute security. If we become aware of a personal data breach, we will notify affected parties and regulators as required by law.

13Cookies

We use strictly necessary cookies to authenticate you, maintain your session and protect the Service. These are required for the Service to function and do not require consent. If we introduce analytics or other non-essential cookies, we will request your consent and provide controls to manage them. You can also control cookies through your browser settings, though disabling necessary cookies may prevent you from signing in.

14Children's privacy

The Service is intended for use by organisations and their workforce and is not directed to children. We do not knowingly collect personal data from anyone under 16. If you believe a child has provided us with personal data, contact us and we will take appropriate steps to delete it.

15Changes to this policy

We may update this Privacy Policy from time to time. If we make material changes, we will notify you by reasonable means, such as by email or an in-product notice, before the changes take effect. The "Effective" date above indicates when this policy was last revised. Your continued use of the Service after the effective date constitutes acceptance of the updated policy.

16Complaints

If you have concerns about how we handle your personal data, please contact us first at support@inatick.app so we can try to resolve them. If you are in the European Economic Area, the United Kingdom or Switzerland, you also have the right to lodge a complaint with your local data protection supervisory authority. In Australia, you may contact the Office of the Australian Information Commissioner (OAIC).

17Contact us

Mallorn Technical Services is the controller responsible for personal data described in this policy. For privacy questions or to exercise your rights, contact us at support@inatick.app (general enquiries: support@inatick.app). If we are required to appoint an EU or UK representative under Article 27 of the GDPR, their contact details will be published here.

This Privacy Policy forms part of our Terms of Service. Read the Terms of Service for the full agreement that governs your use of In A Tick.