Draft — pending legal entity details. This page is not yet finalised: the operating company name, number, registered address and ICO registration have not been confirmed.

Privacy Policy

Last updated 17 September 2026

This policy explains what personal data Fortis Time Management collects when you and your team use the product, why we collect it, who we share it with, and the rights you have over it.

Who we are

Fortis Time Management is operated by Fortis Tech Limited (company number 07298301), registered office 18 Callywith Gate, Launceston Road, Bodmin, England, PL31 2RQ ("Fortis Time Management", "we", "us"). Our ICO registration number is [TBC].

If you have any question about this document, email us at support@fortistime.co.uk.

What this policy covers

This policy covers the Fortis Time Management web application (fortistime.co.uk), our marketing pages, and the support channels we offer. It applies to the account holders, team members and administrators who use Fortis Time Management ("you"), and it explains, at a high level, how we handle the client and contact details your organisation enters into Fortis Time Management about the people it works with.

Fortis Time Management is business software used by professional services firms to track time and manage profitability. It is not aimed at consumers and we do not knowingly collect data from children.

Information we collect

Account and workspace data

  • Name and work email address, used to sign you in and identify you within your workspace.
  • Password (Supabase Auth stores this as a salted hash — Fortis Time Management never sees or stores it in plain text) and, if you turn it on, a time-based one-time-passcode (TOTP) authenticator for two-factor sign-in.
  • Your role and permissions within each workspace or team you belong to.

Time, billing and client data your organisation enters

  • Time entries: dates, durations, work type, notes and the project/client/task they're logged against.
  • Charge-out rates and (for admins) internal cost rates used to calculate profitability.
  • Client and project records, including names, contacts and billing addresses your organisation adds.
  • Invoices generated in Fortis Time Management, and — if you connect Xero — the invoices and contacts you push to or import from your Xero organisation.

Support and communications

  • Messages you send us by email or, once it launches, through the in-app AI help chat (see "Sub-processors" below — these messages are processed by Anthropic to generate a reply).

Technical data

  • Standard web server and application logs (IP address, browser type, pages requested, timestamps) used for security and fault-finding.

How we use your information

We use personal data to:

  • Provide the Fortis Time Management service — timers, timesheets, approvals, budgets, live profitability and reporting.
  • Generate invoices and, where you choose to connect it, push them to or pull contacts from Xero.
  • Power the in-app AI help chat once it launches, by sending your message (and relevant account context) to Anthropic so it can answer.
  • Process subscription payments once Stripe billing launches.
  • Respond to support requests.
  • Keep the service secure — detect abuse, enforce two-factor authentication where enabled, and maintain audit logs.
  • Meet our own legal and accounting obligations (for example, retaining invoice records).

Our legal bases for this processing are performance of our contract with your organisation (providing the service you've subscribed to), our legitimate interests in running and securing the service, and compliance with legal obligations such as tax record-keeping.

Cookies and local storage

Fortis Time Management does not use advertising or analytics cookies, and we do not run any third-party tracking or analytics scripts. There are currently no cookie-consent choices to make because we don't set tracking cookies.

We do use your browser's local storage (not cookies) for things that are strictly necessary to run the app: keeping you signed in between visits, remembering which workspace you last used, and holding a temporary copy of the guided demo so it survives a refresh. This data stays on your device and is never sent to a third party.

Our web pages load fonts from Google Fonts (fonts.googleapis.com / fonts.gstatic.com). Loading a font from Google's servers means your browser makes a request to Google, which can see your IP address at that moment — this happens purely to display the correct typeface and Fortis Time Management does not use it for tracking.

Who we share data with — sub-processors

We use a small number of specialist providers to run Fortis Time Management. Each one only processes the data needed to perform its function, under a data processing agreement:

  • Supabase — Database, authentication and file storage that holds your workspace data. Location: London, UK (eu-west-2 region).
  • Vercel — Hosts the Fortis Time Management website and application and serves it via a content delivery network. Location: Primarily United States, served through a global edge network; transfers are safeguarded under the UK International Data Transfer Addendum and the EU Standard Contractual Clauses.
  • Stripe — Processes subscription payments. Card and bank details go straight to Stripe — Fortis Time Management never receives or stores them. Location: United States / Ireland, under Stripe's own data processing terms.
  • Anthropic — Processes the messages you send to the in-app AI help chat in order to generate a reply. Under Anthropic's commercial API terms, content submitted through the API is not used to train Anthropic's models. Location: United States.
  • Xero — Only used if you choose to connect your organisation's Xero account: receives the contacts and invoices you push, or supplies the contacts you import. Location: Primarily UK / global, under Xero's own privacy policy — Xero is your data controller for that connection.
  • Email support provider — Sends and receives support emails when you contact us. Location: [TBC].

We'll update this list, and give at least 30 days' notice to customers under our Data Processing Agreement, before adding a new sub-processor that will handle personal data.

International transfers

Your core workspace data (accounts, time entries, clients, invoices) is hosted by Supabase in London, UK. Some sub-processors — notably Vercel, Stripe and Anthropic — operate primarily from the United States. Where personal data leaves the UK, we rely on recognised safeguards such as the UK International Data Transfer Addendum or the EU Standard Contractual Clauses, as set out in each provider's own data processing terms.

How long we keep data

We keep your data for as long as your workspace subscription is active, plus a reasonable period afterwards to allow you to reactivate, meet our accounting and legal obligations, and resolve any disputes. If you ask us to delete your account, we'll delete or anonymise personal data within 30 days, except where we're required to keep it for longer (for example, financial records we must retain by law).

Your rights

Under UK GDPR, you have the right to:

  • Ask us what personal data we hold about you, and get a copy of it (right of access).
  • Ask us to correct inaccurate data (rectification).
  • Ask us to delete your data, subject to our legal retention obligations (erasure).
  • Ask us to restrict or object to certain processing.
  • Receive your data in a portable format (data portability) — Fortis Time Management also lets you export your own data directly from the app at any time.

To exercise any of these rights, email support@fortistime.co.uk. If your organisation controls the data (most client and time data is entered and controlled by your employer as our customer), we may direct your request to them. You also have the right to complain to the UK Information Commissioner's Office (ico.org.uk) at any time.

How we protect your data

  • All traffic to Fortis Time Management is encrypted in transit (TLS).
  • Data at rest is encrypted by our database provider, Supabase.
  • Postgres Row Level Security keeps every workspace's data separated from every other workspace's, enforced at the database layer.
  • Optional two-factor authentication (TOTP) is available on every account.
  • Access to production data is limited to the people who need it to run the service.
  • Automated daily backups are taken, with an off-site copy kept overnight, so data can be restored if something goes wrong.

Changes to this policy

We'll post any changes to this page and update the "last updated" date. If a change is material, we'll let workspace admins know by email.

Contact us

Questions about this policy or your data: support@fortistime.co.uk.

Also see: Terms · DPA