Questions
What you ask us.
FicharPyme implements Spanish employment law: article 34.9 of the Estatuto de los Trabajadores, Spain's Workers' Statute. It is not designed to meet the working-time record-keeping rules of any other country.
They are ordered by what you'll find least on the rest of the site. If you have read the other pages, the ones at the bottom will sound familiar; the ones at the top won't.
And this page grows: when someone asks something that wasn't here, we add it. If one is missing, ask us.
What happens to people who no longer work here?
They can still sign in, look, and download what is theirs. What they cannot do is clock in.
And that isn't our decision: the four years the law requires their record to be kept are four years in which that person keeps their right of access — article 15 of the GDPR—. Having to phone their former employer so someone will send them a PDF is not access.
Being able to request corrections has its reason too: someone who left on Tuesday has to be able to ask for Monday's clocking to be fixed. So does not being able to clock in: a clocking by someone who no longer works there is nobody's data, and once inside the record it is never deleted — the mistake would stay in the very record the company shows the Labour Inspectorate—.
Can
- See their own working days
- Download their whole record
- Ask for a clocking to be corrected
Cannot
- Clock in
- Request absences
- Add anything new
Did you use artificial intelligence to build FicharPyme?
Yes, to build it. And for nothing else. We separate the two carefully, because this is exactly where people get confused:
Yes, we use it to
Write the code
Both the application's and this site's, reviewed by us.
Translate into the four languages
And then people go over it.
It is used for none of this
- Nothing the application does
- Nothing this website does
- Your dealings with us: the person answering you is a person
No process in the application goes through an AI. Not the calculation of your working days, not the corrections, not the reports, not who sees what. There is no feature that sends anything to a model, and there won't be: your staff's clockings are nobody's training material.
We know the problems it is causing — code that looks right and isn't, confident answers that are wrong, people using it so they don't have to think—. That is why everything goes through review and tests, and why the legal figures on this site were checked one by one against the BOE, the Spanish official gazette. We think we were right to use it, and we would rather tell you than have you find out.
There are twelve of us and we have no employee representatives. Can we still use it?
Yes, and that is the normal case in a small business.
Article 34.9 says the organisation of the record is documented “by collective agreement, company agreement or, failing that, by the employer's decision after consulting the legal representatives of the workers”. If your company has none, the decision is yours, and the document is generated all the same from your own settings — with its date and its version, so you can show it—.
Is FicharPyme secure?
It is the most asked question and the worst answered, because it is almost always answered with adjectives. Here are facts instead, and the ones that don't depend on taking our word for it, you can check.
The short version: your data is in the European Union, your company has its own database and shares it with nobody, we keep only what is needed, the sensitive material is encrypted, and the backups have been tested.
- Where the data is
- On servers in the European Union. There are no international transfers.
- Your company, on its own
- Each company has its own database, not a column telling it apart inside a shared table. This is article 25 of the GDPR, and it means a failure at the company next door never reaches yours.
- The database
- PostgreSQL, which has been doing this for thirty years and holds up things a good deal larger than us.
- Passwords
- Stored with Argon2id. Not even we can see yours.
- Second factor
- Required for whoever manages the company, since they are the one who can change the settings.
- Sign-in attempts
- Progressive lockout: each failure costs more than the one before.
- The sensitive material, encrypted
- Medical certificates are encrypted on disk, not sitting in a folder in plain view.
- Only what is needed
- No data kept “just in case”. And after four years, only what the law no longer requires us to keep is purged.
- Backups
- Encrypted, in more than one place, and with restores tested — a backup nobody has ever restored is not a backup, it is a folder—.
- And the record cannot be touched
- Neither by accident nor on purpose: the database itself prevents it, and the integrity chain gives away where.
And what that means on the day something goes wrong
Which is what the question is really about: we keep little, we separate it by company, and we encrypt what would hurt most. If there were ever a breach, what anyone could walk away with would be as little as possible. That isn't achieved on the day of the incident: it is achieved by deciding it beforehand.
How many companies use it?
Few. We are new.
We would rather tell you than inflate a figure you couldn't check. What we can show you is that we use it ourselves for our own staff, and did so before we ever sold it — so if the law tightens tomorrow, it tightens on us first.
We have high turnover: 50 people come and go every year. Does that cost more?
No. Not a euro.
It is €200 a year per company, and it makes no difference whether 50 people passed through that year or it was always the same 12. We don't charge per employee, per hire, per account created or per account closed.
And this is more than a price: high turnover is precisely where a working-time record becomes hard to keep by hand, with mid-month starts, final settlements and people leaving with holiday still owed. Charging you more for the case where you need it most would be the opposite of how we see it.
Can other people see my hours?
No. Everyone sees their own.
Whoever runs a shift sees their team's, and only on the days they were in charge of it. The employee representatives see working days and totals for their remit with no ID number, no email address and no reason given for a correction. And the type of a medical absence is not visible to those who shouldn't see it: what shows is that the person is away and that it is covered, and that's all.
The Labour Inspectorate is coming this afternoon. What do I do?
You issue a temporary read-only credential, limited to the period they ask for. The inspector signs in and sees the record without you having to hand over anyone's account, and the credential is revoked when they are done.
And if you would rather hand it over in person, you export the complete package for the period, with its totals and its integrity check. What you won't have to do is put anything together that afternoon.
I forgot to clock out. Has the day been lost?
No. It gets corrected.
That day is left incomplete and at zero minutes — the application does not fill gaps with the contracted schedule, and it cannot: that is ruling SAN 22/2022—, and it is corrected with a reason, an author and a date. The original clocking is not deleted: both remain. Which is what makes fixing an oversight something that doesn't weaken the record.
We work off site, at clients' premises. Does it still work?
Yes: you clock in from the browser on your phone, wherever that person happens to be. And we don't know where they are: there is no geolocation, and there won't be. What we record is when, not where.
Do you make other software for small businesses?
Not today. There are two ideas in the works that may see the light in 2027, and when there is something it will be told here. In the meantime this is the only thing we sell, which is consistent with everything else: we would rather do one thing well than three by halves.
Isn't a four-digit PIN rather weak?
Yes. And anyone asking this has found the panel's weak spot.
First, which PIN we are talking about: it is not the way into FicharPyme. For that there is the usual password, with a second factor required for whoever manages the company, and that does not change. This PIN is an exception with a single use — typing it on the tablet the company leaves on its premises, to clock in and nothing else—. Away from that device it opens no doors.
Four digits are ten thousand combinations, and that is not many. It is weak on purpose: it has to be typed with one finger in three seconds, at the door and with people waiting behind. The real alternative is not a longer PIN — it is people not clocking in at all—.
So instead of pretending it is strong, what is limited is what can be done with it.
With someone else's PIN you can
- Clock their entry, their exit and their breaks
You cannot
- See their working days or their absences
- See their data or get into their portal
- Get in through the normal sign-in screen: only the tablet accepts the PIN
Each person sets it and removes it, from their own portal, and nobody else. Neither their manager nor their shift lead can set it for them or see it, and the reason is short: whoever can give you a PIN can clock in as you. It is stored like passwords, with Argon2id, and it cannot be recovered — a PIN is not remembered, it is replaced—.
Getting the PIN wrong does not lock anyone's account. It has its own counter, separate from the password one. That is not a detail: if they shared a counter, the tablet in the hallway would be a lever for locking anyone out, the manager first.
And guessable PINs are refused when they are set: 0000, 1234, four identical digits and any run of consecutive digits, up or down. You also have to be there in person: this is not attacked over the internet, you have to stand in the entrance, in full view of everyone, and type.
And the thing that holds up everything else: a false clock-in is never deleted. It is corrected, and the correction records who, when and why. The false entry stays in the record. That is uncomfortable, and it is exactly what makes the record worth anything.
If your company wants more guarantees than these, the place to add them is the physical one: a camera pointed at the entrance identifies whoever stands in front of the tablet far better than a long PIN nobody would type. That is your decision, not something we do or something the product needs, and it carries obligations of its own: informing the workforce and their legal representatives, a visible sign and proportionality — art. 89 of the LOPDGDD, the Spanish data protection act—.
