API Terms
All Toogether Ltd. Version 1 (api-terms-v1), 29 September 2026. Accepted by an HR admin each time they create API credentials.
These terms apply when your organisation uses the Alltoogether API to read its own data into its own systems. They add to our Terms of Service and the data processing terms incorporated in them. Where they differ on use of the API, these terms apply.
1. Who is responsible for what
1.1 Your organisation is the controller of the personal data about its people. We process it on your organisation's behalf.
1.2 Creating API credentials, and each request made with them, is your organisation's instruction to us to send the data described in section 2 to the system that holds those credentials.
1.3 Once data has left Alltoogether through the API, it is in your systems and under your control. Your organisation is responsible for it there: keeping it secure, who can see it, how long it is kept, any transfer outside the UK, answering requests from your people about their data, and telling them how their data is used.
2. What the API provides
2.1 Read-only access to your own organisation's data, and nothing else:
- Employees: names, job title, department, employment status, start and leaving dates, and bank holiday calendar.
- Annual leave: annual leave bookings and balances, and your annual leave types.
- Holidays: bank holidays for the calendars your people follow, and your company closure days.
2.2 The API never provides pay or reward, date of birth, sex or gender, nationality, National Insurance numbers, home addresses, personal contact details, risk scores, notes or reasons, sickness, or any leave other than annual leave. It cannot change anything in Alltoogether.
3. Credentials
3.1 Only your HR admins can create or revoke API credentials. Every HR admin in your organisation is notified whenever credentials are created.
3.2 Your organisation is responsible for every request made with its credentials. Keep the client secret in a secret store, such as your system's secret settings. Never put it in a spreadsheet cell, a document, an email, source code or a web page.
3.3 If you think a secret has been seen by anyone who should not have it, revoke those credentials straight away in Settings, API access, and tell us at support@alltoogether.com without undue delay.
3.4 Credentials expire after the period chosen when they were created, at most one year.
4. What we do
4.1 We limit every request to your organisation, record every request (which credentials, when, from where and what was read) and keep those records as part of our access log.
4.2 We apply rate limits, and we may suspend credentials or API access where we see misuse or a security risk. We will tell your HR admins when we do.
4.3 We may add to the API. We will give your HR admins reasonable notice before changing or removing anything your systems may rely on.
5. Ending API access
5.1 Your HR admins can revoke any credentials at any time. Alltoogether can switch API access off for your organisation at your request or under section 4.2, and it ends with your account. Switching it off stops every set of credentials at once.
6. Changes to these terms
6.1 If we change these terms we will publish a new version here. Credentials you already have keep working under the version accepted when they were created; new credentials need the current version.