Data portability and switching
Effective from 2026-09-12
The data you put into Tivero is yours. This page says what you can take with you, in what form, how switching provider works, and what is excluded from the export — with the reason for each exclusion.
1. What you can take with you
You can export the data you entered and the data the service produced from your use of it, together with the metadata that makes it meaningful. In practice:
- people: employees and contractors, their employment details, teams and managers,
- access: who has an account in the workspace, with which role and capabilities,
- requests and absences: dates, amounts, statuses, comments and the per-day calculation,
- approvals: workflows, steps, decisions, comments, delegations and reassignment history,
- balances and limits: every balance movement and the current standing,
- policies and configuration: absence types, policies, work locations, company days off,
- reports and imports: export history, and import rows with their validation errors,
- administrative history: the audit trail of administrative actions in your workspace,
- billing: your company details, plan, billing period and seat-cost acknowledgements,
- legal evidence: which version of the Terms, the DPA, the privacy notice and this register was accepted or presented.
2. In what form
Data is served as JSON through an open interface, free of charge, to you and to the destination provider you authorise. Every record carries a stable identifier and relationships are expressed with those identifiers, so the data set can be rebuilt on the other side rather than merely read.
Separately, the application lets administrators download absence summaries (CSV, XLSX) and reports on requests, balances, people and team absences (CSV), and subscribe to a read-only iCalendar feed of approved absences. Those are convenience exports; the switching interface is the complete one.
The full list of datasets, their contents and their structure is in the technical specification at /legal/data-portability/specification.
3. How switching works
Write to hello@tivero.app and say whether you are moving to another provider, to your own infrastructure, or asking for permanent erasure.
The workspace owner issues a credential in Settings → Privacy that lets the destination provider read the data. It has a limited validity, works for that one workspace only, cannot sign in to the application or change anything, and can be revoked at any time.
During the transitional period we give reasonable assistance to you and to the parties you authorise, maintain continuity of the service and the security of the data, including while it is transferred, and tell you about known risks to continuity. Configuration travels as data, but how it behaves depends on the destination service, and integration credentials are not ported — they have to be established again.
We charge nothing for switching, for the transfer, or for leaving.
4. Time periods
The notice period needed to start a switch does not exceed two months, and we require no minimum. We carry out the switch within a transitional period of no more than 30 calendar days; where that is technically unfeasible we tell you within 14 working days, justify it, and indicate an alternative period of no more than 7 months. Separately, you may extend the transitional period once.
After the transitional period ends you have at least 30 calendar days to retrieve your data. Once that period has expired and the switch has completed successfully, we permanently erase your exportable data and the data relating to you directly, subject to retention required by law.
The binding wording of these commitments is in the Terms of Service, under switching provider and porting data.
5. What cannot be exported, and why
The categories below are excluded, each for the reason given. They are internal to the provider, protect the security of the service, or are licensed from a third party rather than generated by you.
| Category | Reason |
|---|---|
| security-sensitive | credential used to authorise the switching interface itself |
| provider internal | the provider's price list, not customer data |
| provider internal | the provider's feature catalogue |
| provider internal | the provider's plan definitions |
| provider internal | platform-wide operational notice |
| provider internal | internal deletion job queue |
| provider internal | provider-side commercial override |
| provider internal | raw payment-provider event log |
| provider internal | internal billing operation queue |
| provider internal | internal billing state machine |
| provider internal | internal concurrency lease |
| provider internal | internal payment-action tracking; invoices themselves are with the payment provider |
| provider internal | notes written by platform staff for the provider's own operation of the service, not generated by the customer's use; a note about an identifiable person is handled as a GDPR access request, case by case |
| security-sensitive | secret feed token |
| security-sensitive | OAuth verifier and authorisation state |
| security-sensitive | OAuth nonce state |
| security-sensitive | encrypted provider credentials |
| provider internal | internal delivery queue |
| security-sensitive | short-lived action token hashes |
| security-sensitive | short-lived navigation token hashes |
| security-sensitive | platform support session with token hash |
| security-sensitive | demo session token hash; demo tenants are synthetic |
| third-party protected | public-holiday reference data licensed from a third-party provider, not generated by the customer |
| third-party protected | public-holiday reference data licensed from a third-party provider |
| provider internal | global statutory working-day reference data maintained by Tivero; not generated or co-generated by the customer's use of the service, and not customer data |
6. Technical specification
The full, versioned list of datasets, their contents and their withheld fields — for you and for a destination provider — is at /legal/data-portability/specification. That document is the one the Terms incorporate as the specification of exportable and excluded data.
7. Contact
Switching requests and questions: hello@tivero.app.