Data portability and switching

Effective from 2026-09-12

The data you put into Tivero is yours. This page says what you can take with you, in what form, how switching provider works, and what is excluded from the export — with the reason for each exclusion.

1. What you can take with you

You can export the data you entered and the data the service produced from your use of it, together with the metadata that makes it meaningful. In practice:

  • people: employees and contractors, their employment details, teams and managers,
  • access: who has an account in the workspace, with which role and capabilities,
  • requests and absences: dates, amounts, statuses, comments and the per-day calculation,
  • approvals: workflows, steps, decisions, comments, delegations and reassignment history,
  • balances and limits: every balance movement and the current standing,
  • policies and configuration: absence types, policies, work locations, company days off,
  • reports and imports: export history, and import rows with their validation errors,
  • administrative history: the audit trail of administrative actions in your workspace,
  • billing: your company details, plan, billing period and seat-cost acknowledgements,
  • legal evidence: which version of the Terms, the DPA, the privacy notice and this register was accepted or presented.

2. In what form

Data is served as JSON through an open interface, free of charge, to you and to the destination provider you authorise. Every record carries a stable identifier and relationships are expressed with those identifiers, so the data set can be rebuilt on the other side rather than merely read.

Separately, the application lets administrators download absence summaries (CSV, XLSX) and reports on requests, balances, people and team absences (CSV), and subscribe to a read-only iCalendar feed of approved absences. Those are convenience exports; the switching interface is the complete one.

The full list of datasets, their contents and their structure is in the technical specification at /legal/data-portability/specification.

3. How switching works

Write to hello@tivero.app and say whether you are moving to another provider, to your own infrastructure, or asking for permanent erasure.

The workspace owner issues a credential in Settings → Privacy that lets the destination provider read the data. It has a limited validity, works for that one workspace only, cannot sign in to the application or change anything, and can be revoked at any time.

During the transitional period we give reasonable assistance to you and to the parties you authorise, maintain continuity of the service and the security of the data, including while it is transferred, and tell you about known risks to continuity. Configuration travels as data, but how it behaves depends on the destination service, and integration credentials are not ported — they have to be established again.

We charge nothing for switching, for the transfer, or for leaving.

4. Time periods

The notice period needed to start a switch does not exceed two months, and we require no minimum. We carry out the switch within a transitional period of no more than 30 calendar days; where that is technically unfeasible we tell you within 14 working days, justify it, and indicate an alternative period of no more than 7 months. Separately, you may extend the transitional period once.

After the transitional period ends you have at least 30 calendar days to retrieve your data. Once that period has expired and the switch has completed successfully, we permanently erase your exportable data and the data relating to you directly, subject to retention required by law.

The binding wording of these commitments is in the Terms of Service, under switching provider and porting data.

5. What cannot be exported, and why

The categories below are excluded, each for the reason given. They are internal to the provider, protect the security of the service, or are licensed from a third party rather than generated by you.

CategoryReason
security-sensitivecredential used to authorise the switching interface itself
provider internalthe provider's price list, not customer data
provider internalthe provider's feature catalogue
provider internalthe provider's plan definitions
provider internalplatform-wide operational notice
provider internalinternal deletion job queue
provider internalprovider-side commercial override
provider internalraw payment-provider event log
provider internalinternal billing operation queue
provider internalinternal billing state machine
provider internalinternal concurrency lease
provider internalinternal payment-action tracking; invoices themselves are with the payment provider
provider internalnotes written by platform staff for the provider's own operation of the service, not generated by the customer's use; a note about an identifiable person is handled as a GDPR access request, case by case
security-sensitivesecret feed token
security-sensitiveOAuth verifier and authorisation state
security-sensitiveOAuth nonce state
security-sensitiveencrypted provider credentials
provider internalinternal delivery queue
security-sensitiveshort-lived action token hashes
security-sensitiveshort-lived navigation token hashes
security-sensitiveplatform support session with token hash
security-sensitivedemo session token hash; demo tenants are synthetic
third-party protectedpublic-holiday reference data licensed from a third-party provider, not generated by the customer
third-party protectedpublic-holiday reference data licensed from a third-party provider
provider internalglobal statutory working-day reference data maintained by Tivero; not generated or co-generated by the customer's use of the service, and not customer data

6. Technical specification

The full, versioned list of datasets, their contents and their withheld fields — for you and for a destination provider — is at /legal/data-portability/specification. That document is the one the Terms incorporate as the specification of exportable and excluded data.

7. Contact

Switching requests and questions: hello@tivero.app.