▶ Getting started · 8 min read
An employee leaves: deactivate, leaving date, what remains
Why there is no “Delete”
Anyone who leaves the business is deactivated in Zeitflex, not deleted. § 16 Abs. 2 ArbZG (German Working Hours Act) and § 17 Abs. 1 MiLoG (German Minimum Wage Act) require working-time records to be kept for two years, payroll records even for six (§ 41 Abs. 1 EStG, German Income Tax Act). Deleting the person's record would take all time entries with it. Hence: login access ends immediately, the times remain, the name disappears after a set period.
Beforehand: the data access report
As long as the name is in the system, the person can download their data access report under Art. 15 GDPR themselves: Settings → Data export → Download data copy (three times per hour). If they no longer have access, create the report under Employees via Data report — if the person has switched on app notifications, they receive a message about it. What is included is explained under What Zeitflex stores about me.
Recording the departure
- Open Employees on the left.
- In the person's row, click Offboard.
- Enter the last day of employment (format YYYY-MM-DD).
- Read the confirmation question and confirm.
The owner's account cannot be deactivated — without an owner there would be nobody to manage the business. There is no button for a change of owner; please contact Support for that.
“Notice effective”: a date in the future
The normal case is that you know in advance: at the beginning of July it is settled that someone is leaving on 31 July. Enter this date — the person carries on working and clocking in and out as normal until then. On the following day, the nightly run ends their access automatically. Until then, they appear in the list with the note “notice effective …”.
If the date is today or earlier, the departure takes effect immediately: access ends, and open phone sessions are revoked.
Former employees then appear under Employees in the Archive view — with the leaving date and the date on which the name becomes a pseudonym.
What happens immediately
| Area | Effect |
|---|---|
| Sign-in to app and browser | Ends immediately: phone sessions are revoked (the last key expires after 15 minutes at most); in the browser the block takes effect within 30 seconds. |
| Terminal PIN | The person no longer appears in the terminal's tile list. Clock-ins and clock-outs that a tablet collected offline are rejected when they are synced — with a note to report to the office. |
| Shift reminders | The reminder 45 minutes before the start of the shift no longer happens. |
| Announcements | Former employees are no longer a target group and do not count in the read status. |
| Times, absences, pay items | Are kept — in the timesheet, month-end close and audit folder. |
| Change log | Records the leaving date and the date of anonymisation. |
What it costs — and from when it no longer does
In Starter and Pro, Zeitflex bills per active employee. Once a day, Zeitflex compares the billed quantity with the people actually active — effective from the next billing period, without a prorated interim invoice in either direction:
- Anyone who leaves during the period is counted until its end; there is no credit for remaining days. A new hire costs nothing extra until the end of the period.
- At least one seat is always billed — even if nobody is active between two seasons.
- Open invitations count towards the plan's seat limit, but towards the invoice only once the person is active.
Plans at a glance: Plans and prices.
Remaining vacation
Zeitflex calculates the vacation entitlement using the one-twelfth principle (§ 5 BUrlG, German Federal Leave Act, simplified): only full months of employment in the calendar year count — joining on the 1st at the latest, leaving on the last day of the month at the earliest. Pro-rata days = annual vacation × full months ÷ 12, rounded to half days; approved vacation days are deducted.
The person can see the figure themselves in the mobile app on the Times tab. There is no remaining-vacation display per person for management in the web app — work out the figure there from annual vacation, full months and the approved days under Absences.
What Zeitflex does not do: no payment in lieu of vacation in euros, no distinction between the first and second half of the year, no special rules from collective agreements. The figure is a calculation aid, not the basis for a payout.
After three months: anonymisation
Three months after the leaving date, the daily deletion run replaces the identifying data with a pseudonym: “Ehemalige Person” (German for “former person”) plus a fixed code. Three months, because follow-up payroll items — payment in lieu of vacation, correction payroll runs, final pay statement — experience shows arise up to a quarter after leaving.
| Replaced or cleared | Kept |
|---|---|
| Name, email address, profile picture | All time entries including correction history |
| Password, terminal PIN | Absences, pay items, locked months |
| Personnel number, date of birth | Employment type, hourly wage, weekly target, joining and leaving date, role |
| Sick notes, photo records, other files | Employment contract, safety briefing records, application documents — until the end of their own period |
The right-hand column is kept because without the hourly wage and weekly target the pay line that has to be retained would no longer be traceable (“20 hours at what rate?”).
If a person requests deletion before the three months are up (Art. 17 GDPR), trigger it manually: Archive view → Anonymise → enter the reason (5 to 300 characters). This only works for former employees, never for the owner and never for your own account.
The personnel file survives pseudonymisation
Until September 2026, three months after someone left, the nightly run deleted all of the person's files — including the employment contract, for which ten years apply. That was a mistake, and it has been fixed:
| Document | What happens |
|---|---|
| Employment contract, amendments, certificates | Kept until 10 years after leaving |
| Safety briefing records | Kept until 3 years after the year of leaving |
| Application documents (of hired people) | Kept like the contract |
| Sick notes | Deleted along with them — health data without a retention obligation |
| Photo records, other files | Deleted along with them |
The remaining documents are then attached to the pseudonym, no longer to the name. The periods start with the leaving date, not with the day of upload — which is why the correct leaving date matters more than it seems.
What remains and for how long
| Data | Period | Legal basis |
|---|---|---|
| Name, email, personnel number | 3 months from leaving, then pseudonym | § 26 Abs. 1 BDSG (German Federal Data Protection Act), Art. 17(1)(a) GDPR |
| Working times, correction history, absences | at least 24 months from recording | § 16 Abs. 2 ArbZG, § 17 Abs. 1 MiLoG |
| Payroll records (locked months, pay items, export logs) | 72 months from 31 Dec of the year of the last payment of pay | § 41 Abs. 1 EStG, § 257 Abs. 4 HGB (German Commercial Code), § 147 Abs. 3 AO (German Fiscal Code) |
Zeitflex does not automatically delete working times and payroll records after these periods — they are minimum values (Retention periods). The person still appears in the audit folder of an old month, after anonymisation under their pseudonym (Customs inspection).
Is the person coming back?
Seasonal workers come back — as long as the account has not yet been anonymised, you can bring the person back with one click:
- Set the view at the top to Archive.
- Click Reactivate next to the person.
They can clock in again immediately, the leaving date is removed, and all previous times still belong to them. The seat counts as an active seat again from now on — if your plan does not cover it, Zeitflex tells you before anything is changed.
Still stuck?
For questions about a specific departure, write to Support — the periods are explained under Retention periods, the costs under Plans and prices.
Last checked on . We check every article against the application — if something no longer matches, that is a bug and not a difference of opinion.
Was this helpful?
Related articles
- Inviting employeesAccess via invitation link or terminal PIN, assigning roles correctly, date of birth only when needed — and what to do if someone cannot find the invitation.
- Retention periodsHow long working-time data, sick notes and payroll records must be kept, which periods Zeitflex has set for each type of data, and what the nightly deletion run does.
- Plans and pricesWhat Free, Starter and Pro include, how the price per active employee comes about, how monthly and annual payment differ and from when Enterprise applies.
- What Zeitflex stores about me — the data access reportEvery person obtains their own access report under Art. 15 GDPR themselves — readable and as a file, without going through the business.