Online Leave Management and Staff Development System - tracker2
tracker2 Online Leave Management System is used by numerous hospitals to monitor all types of Leave (Annual, Study, Special, Sick Leave). It monitors attendance at courses, mandatory and in-house training with e Portfolio for employee's appraisal, an Expenses module and a Trainer Accreditation module. It allows multiple levels of access.
Features
- Online Leave management, remote access, Secure login, secure backup
- Attendance record, mandatory training record, real-time analytics
- Calendar view, multiple level of access, leave clash alert
- Multiple types of Leave, annual, study, special, sick
- Trainer Accreditation module
- Financial governance and budget allocation per group of employees
- Course evaluation analytics
- Local Meeting Attendance Monitoring, QR code scanning
- e-Portfolio to support employee mandatory appraisal
- Expenses module, submission of receipts, notifications and authorisation of expenses
Benefits
- Remote Leave application, multiple levels of approval
- All Leave recorded in one place, online free flexible reports
- Calendar view by department or section, connects the whole organisation
- Recording Trainers accredited to GMC standards
- Secure audit trail for application process saving thousands of hours
- Manages budget allocation, live financial information and limitless reports
- Empowers employees to exercise governance managing their own leave
- Electronic record of in-house meetings through advance technology
- Employees benefit from integral e-Portfolio module to prepare appraisal
- Employees benefit from integrated expenses claim application process
Pricing
- Education pricing available
Service documents
Request an accessible format
Framework
G-Cloud 15
Service ID
5 4 2 5 3 0 2 8 3 9 0 0 4 0 8
Contact
CELLO SOFTWARE LIMITED
Hani Zakhour
Telephone: 0151 348 4035
Email: Info@cellosoftware.co.uk
About your service
- Service categories
-
Applications
Production and operations
- Other operations
Service industry and public sector operations
- Healthcare
- Education
- Other
- Multi cloud support
- Yes
Service scope
- Software add-on or extension
- No
- Cloud deployment model
-
- Public cloud
- Private cloud
- Service constraints
- Internet connection must be of reasonable speed. Up to date device hardware. Occasional service downtime for updates and maintenance. Although intuitive, the system manager will require training.
- System requirements
-
- Internet or 3G/4G/5G link
- Works on Windows and Mac OS X platforms
- Works on tablets, smartphones and other mobile devices
- Requires minimum input from System administrator
- Requires Annual software and support licence
- Requires a cloud hosting (provided by Cello Software partner)
- Requires a reasonable level of computer literacy
- Buyer hardware needs to be of reasonable specifications
- Access is granted via a valid logon issued by admin
User support
- Email or online ticketing support
- Yes
- Support response times
-
1st Response is immediate, 2nd response is within 24 hours. Same response at weekend.
Support Services shall be provided primarily to the Client’s Systems Administrator. The Company will provide support and advice through the following channels:
1. By email/telephone during normal working hours
9.00 – 17.00 Monday-Friday excluding public holidays
2. On-line support at weekend
3. On-site visits (Chargeable)
Further details are outlined in the Service level agreement - User can manage status and priority of support tickets
- No
- Phone support
- Yes
- Phone support availability
- 9 to 5 (UK time), Monday to Friday
- Web chat support
- No
- Onsite support
- Yes, at extra cost
- Support levels
-
Contact by the Client should in the first instance be by email to support@cellosoftware.co.uk
Requests for support by the Client will be classified in the following categories:
A Urgent (Red) eg: if the server is down;
B High Priority (Amber) eg: non-server software errors;
C Medium Priority (Green) eg: problems that can wait up to 5 days for resolution;
D Low Priority (Black) eg: requests for new functionality and software upgrades.
Support is charged annually and is included in the price of the licence.
A technical account manager is available to provide support in cases where first line support is not sufficient.
Escalating is done automatically by our company’s first line support when it’s deemed necessary. - Support available to third parties
- No
Onboarding and offboarding
- Getting started
- The system manager is supported extensively in the period leading to the launch of the product. We work closely with the client to set up the system, starting with demographic data import. We continue with customisation and setting up the software to training which can be given either online or on site. The length of the session depends on the number of users attending. We normally train system managers and system administrators. Standard users require minimal training as the System is intuitive. User documentation is online in the form of help files which open in separate tabs. The help pages are sensitive to the current page in use. Online advice and telephone support with instructions are provided to all admin users once the system is purchased.
- Service documentation
- Yes
- Documentation formats
-
- HTML
- End-of-contract data extraction
- Data can be extracted via running multiple reports in commonly known format. This can be done on an individual user basis or for an entire group or section of users.
- End-of-contract process
-
The cost of the contract includes the import of demographic data of the users of the client organisation. It includes the first year license, support by email and for urgent matters as agreed with client by telephone. The contract price includes any updates for the year of the contract. Major updates are offered free for the remainder of the year but may be charged for at the anniversary of the contract.
At the end of the contract the user can either renew the contract or not renew the contract upon which the service and the access to the system is discontinued. Raw data will be available to extract within the period of the contract in a well recognised format, but not after the contract has terminated. Data as visible in the software is the propriety of Cello Software and cannot be made available in this format for extraction. The client data is destroyed by Cello Software after the end of the contract. - Documentation accessibility standard
- WCAG 2.2 AA
Using the service
- Web browser interface
- Yes
- Supported browsers
-
- Microsoft Edge
- Firefox
- Chrome
- Safari
- Opera
- Application to install
- No
- Designed for use on mobile devices
- Yes
- Differences between the mobile and desktop service
-
Staff users can use mobile devices for full access of service
Admin users can use the vast majority of features on mobile devices and full features on desktop devices only. - Service interface
- No
- User support accessibility
- WCAG 2.2 AA
- API
- Yes
- What users can and can't do using the API
-
Part of our software is reliant on an API technology but it is invisible to users. The main service is not provided via an API
One of the services modules (Local Meeting Attendance Monitoring System API) relies on users downloading our special App on their mobile device to record attendance at meetings. The users access the App through a login. The initial setup to the Local Meeting App is provided by the System Administrator. The user has full access to all system features - API documentation
- Yes
- API documentation formats
-
- HTML
- API sandbox or test environment
- No
- Customisation available
- Yes
- Description of customisation
-
System administrators can customise access to the system. This is far too complex to describe in detail but customisation is extensive for the purpose of accessing various levels of the software. Normally users must apply to System administrator for a variety of customised access views and functions depending on the level they are working at.
An approver has a separate set of customised access in comparison with a financial support individual or a section Manager, the combinations are vast. Top level admin can customise access and any one else who is given permission by the Senior Admin System Manager.
Scaling
- Independence of resources
- Cello Software uses an independent secure dedicated servers to host user data. The system has vast capacity, the sole limiting factor is internet speed and connectivity. Each organisation runs a separate account and therefore the strain on the system is somewhat distributed. Our largest organisation has 1800 employees. The total number of users is over 10 thousand. The server capacity is vastly in excess of the current requirement. Our ethos of data protection and user support by design ensures the system has ample flexibility.
Analytics
- Service usage metrics
- Yes
- Metrics types
- All admin users are able to view basic usage metrics on the dashboard. Other metrics are available by running reports. We use metrics to analyse popularity of courses for various groups of users in various specialties.
- Reporting types
-
- Real-time dashboards
- Reports on request
- Resource tagging
- Yes
- FOCUS resource tagging
- Yes
Resellers
- Supplier type
- Not a reseller
Staff security
- Staff security clearance
- Other security clearance
- Government security clearance
- Baseline Personnel Security Standard (BPSS)
Asset protection
- Knowledge of data storage and processing locations
- Yes
- Data storage and processing locations
- United Kingdom
- User control over data storage and processing locations
- No
- Datacentre security standards
- Complies with a recognised standard (for example CSA CCM version 4.0)
- Penetration testing frequency
- At least every 6 months
- Penetration testing approach
- In-house
- Protecting data at rest
-
- Physical access control, complying with SSAE-18 / ISAE 3402
- Physical access control, complying with another standard
- Encryption of all physical media
- Data sanitisation process
- Yes
- Equipment disposal approach
- In-house destruction process
- Data sanitisation type
-
- Deleted data can’t be directly accessed / Cryptographic Erasure
- Data Erasure
- Explicit overwriting of storage before reallocation / Secure Erase
Data importing and exporting
- Data export approach
- Data can be extracted via running multiple reports in commonly known format. This can be done in detailed way for individuals users or for an entire group or section of users.
- Data export formats
-
- CSV
- Other
- Other data export formats
-
- .xmls
- .docx
- Data import formats
-
- CSV
- Other
- Other data import formats
- .xmls
Data-in-transit protection
- Data protection between buyer and supplier networks
-
- TLS (version 1.2 or above)
- Other
- Other protection between networks
- The buyer network is not used to store data. Clients data are stored on a secure dedicated servers by our hosting company. All connections are standard https secure connections. All files are zipped and encrypted with defined encrypting key before sending to the Backup server. The algorithm that is used to encrypt the files is Advanced Encryption Standard (AES), with 256-bit block ciphers. All communications between Backup Server and the Data Server are transported in a 128-bit SSL (Secure Socket Layer) channel. All data is protected at rest. Our website is protected by a 2048-bit key security certificate from Digicert.
- Data protection within supplier network
-
- TLS (version 1.2 or above)
- Other
- Other protection within supplier network
- We do not have an internal network. Dropbox is used for sharing documents. Dropbox files at rest are encrypted using 256-bit Advanced Encryption Standard (AES). To protect data in transit between Dropbox apps (currently desktop, mobile, API, or web) and our servers, Dropbox uses Secure Sockets Layer (SSL)/Transport Layer Security (TLS) for data transfer, creating a secure tunnel protected by 128-bit or higher Advanced Encryption Standard (AES) encryption. Similarly, data in transit between our hosting company and the clients are encrypted via SSL/TLS version 1.2 or above
Availability and resilience
- Guaranteed availability
-
The Company will make all reasonable endeavours to ensure a 99%availability. We respond to incidents as follows:
i an acknowledgement of receipt of the message within 1 working hour;
ii an initial response within 24 hours;
iii a detailed response within 48 hours from the initial response including an estimated time for fixing the problem. If no fault is found, the user will be contacted to ascertain the nature of the fault to decide whether the fault can be attributed to an element of the software or its environment.
The Company is not responsible for problems caused by matters outside its control; this includes local network problems, misuse of software, inappropriate use of the software, lack of assistance from the Client and matters of force majeure. The problem generating the support call shall be deemed resolved once the Client Systems Administrator and the Company has declared it so. Should the period of availability be affected for over 24 hours an appropriate refund can be made to the client. - Approach to resilience
- Available on request
- Outage reporting
- The company subscribes to a server Management system "Uptime Robot", which monitors our servers 24/7. There is an API, Email alerts and text messages alerts in addition to website news alert. Outages are investigated immediately. Minor outages less than 5 min are left to run their course moderate and severe outages are communicated to clients via email alerts
Identity and authentication
- User authentication needed
- Yes
- User authentication
-
- Multi-Factor Authentication (MFA)
- Username or password
- Access restrictions in management interfaces and support channels
- The system is standalone. It does not currently interact with other interfaces or other support channels. Access to management channels within the company is restricted to certain individuals on need to know basis.
- Access restriction testing frequency
- At least every 6 months
- Management access authentication
-
- Multi-Factor Authentication (MFA)
- Username or password
Audit information for users
- Access to user activity audit information
- Users contact the support team to get audit information
- How long user audit data is stored for
- Between 1 month and 6 months
- Access to supplier activity audit information
- Users contact the support team to get audit information
- How long supplier audit data is stored for
- Between 1 month and 6 months
- How long system logs are stored for
- Between 1 month and 6 months
Security governance
- Named board-level person responsible for service security
- Yes
- Security governance certified
- Yes
- Security governance standards
- Other
- Other security governance standards
- Cyber security essentials issued by Cybersecurity UK IASME. The NHS Data Security and Protection Toolkit (DSPT). Conform to National Data Guardian’s (NDG) data security standards.
- Information security policies and processes
- We are registered with the Information Commissioner's Office (ICO). We comply with the ICO GDPR criteria for security breach reporting. The company Data Protection Officer, Board level, ensures that policies are adhered to. The details are outlined in a document called "Data Breach Policy - Cello Software". See Below an extract paragraph 4 from this document. (4. The Data protection officer will first ascertain if the breach is still occurring. If so, appropriate steps will be taken immediately to minimise the effects of the breach. An assessment will be carried out to establish the severity of the breach and the nature of further investigation required. Consideration will be given as to whether the police should be informed. Advice from appropriate experts will be sought if necessary. A suitable course of action will be taken to ensure a resolution to the breach.)
- Software Security Code of Practice
- Yes
Operational security
- Configuration and change management standard
- Supplier-defined controls
- Configuration and change management approach
- Cello Software is and has been conversant with the concept of Privacy by Design. Our software is accessed only via secure connections. Updates are tested on secure devices. Our service and support is monitored through its lifecycle. Any change to service will need to meet our security criteria and the approval of our DPO
- Vulnerability management type
- Supplier-defined controls
- Vulnerability management approach
-
Any unusual activities attempts to login, visible through our log.
‘Critical’ patches are deployed within hours.
‘Important’ patches are deployed within 2 weeks of a patch becoming available.
‘Other’ patches are deployed within 8 weeks of a patch becoming available.
This is part of our declaration for attaining the Cyber security essential level.
Information about threats is obtained from IT blogs and our antivirus software news bulletins - Protective monitoring type
- Supplier-defined controls
- Protective monitoring approach
-
Any multiple attempts of unauthorised access to the system such as brute-force password guessing, will result in throttling and account locking after 3 attempts. Suspicious activities appear on the log.
We investigate against all users' record. We respond urgently to potential threats and incidents - Incident management type
- Supplier-defined controls
- Incident management approach
- We have a routine reporting process described in our Business Contingency Plan. Our users may report by email or in major breaches they would contact us by phone. We write to our users and inform them in a report what has taken place and how we addressed the incident.
- Post-quantum cryptography secure
- No
Secure development
- Approach to secure software development best practice
- Supplier-defined process
Public sector networks
- Connection to public sector networks
- No
Pricing
- Discount for educational organisations
- Yes
- Free trial available
- No
Discount percentage by annual call-off contract value (excluding VAT)
- Less than £250,000
- 2%
- Between £250,000 and £500,000
- 4%
- Between £500,001 and £1,000,000
- 6%
- Between £1,000,001 and £2,500,000
- 8%
- Between £2,500,001 and £5,000,000
- 10%
- Over £5,000,001
- 12%
Non-mandatory Standards and certifications
- ISO/IEC 27001 certification
- No
- ISO 28000:2022 certification
- No
- ISO 9001 certification
- No
- Quality management systems (QMS)
- Yes
- CSA STAR certification
- No
- PCI certification
- No
- Cyber essentials
- Yes
- Please provide your Cyber Essentials Certificate Number
- 83aa43a7-6bc5-437e-a5ba-f3f354e65a1a
- Cyber essentials plus
- No
- Cyber Essentials Alternative
- None of the criteria
- Other security certifications
- Yes
- Any other security certifications
-
- NHS Data Security and Protection Toolkit (DSPT)
- Conformed to National Data Guardian’s (NDG) data security standards
Social value
- Section B - Commitment for Future: Delivery
-
-
Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.
Policy Outcome 1: Fair work: That offers fair wages and good working conditions. Help people get a job, stay in work, and progress in their careers, with good employment opportunities across the country. Notes: Where there is a large proportion of labour costs in the contract, commercial teams should consider MAC in Outcome 1 as a priority
- New or retained jobs on the contract workforce in the relevant area that meet the criteria set out in MAC 1b, 1c and 1d
- Providing opportunities for, and measuring and monitoring of, staff workforce conditions over time, including employee engagement, involvement in decision-making and satisfaction and adapting to any changes in the results, with clear processes for acting on issues identified
- Monitoring and reporting of gender and ethnicity pay gaps and plans to address them where necessary
- Understanding of in-work progression issues affecting the market, industry or sector relevant to the contract, and in the supplier’s own organisation and those of its key sub-contractors
- Understanding of the modern slavery risks and issues affecting the market, industry, sector or country (of origin or of source) relevant to the contract, and the workforce in the supplier’s own organisation and those of its key subcontractors
- How the supplier will work with NGOs, trade unions or other businesses to address modern slavery risk
-
Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.
Policy Outcome 2: Skills for growth: Supporting growth sectors and addressing skills gaps.
- Understanding of employment and relevant skills issues, and of the education and training issues relating to the contract. Illustrative examples: demographics, skills shortages, new opportunities in high growth sectors, geographic/local community and skills/employment challenges
-
Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.
Policy Outcome 3: Resilient, innovative and flexible supply chains: Support economic growth through enabling resilient businesses, opportunities for small businesses and voluntary, community and social enterprises
- Understanding of the types of businesses in the market and the level of participation by new businesses, entrepreneurs, start-ups, SMEs, VCSEs and mutuals
- Ensuring accessibility to contracting and subcontracting opportunities for disabled business owners and employees
- Understanding of local demographics, needs and opportunities for the co-design of the goods, services and works to be delivered under the contract
-
Mission: Make Britain a clean energy superpower: To cut bills, create jobs and deliver security with cheaper, zero-carbon electricity by 2030, accelerating to net zero
Policy Outcome 4: Sustainable procurement practices: Reducing carbon footprints, minimising waste, and promoting the use of clean energy and green technologies.
- Understanding of opportunities for additional environmental benefits delivery in the performance of the contract, including working towards net zero carbon emissions and use of clean energy and green technologies
- Understanding of how to influence staff, suppliers, customers, communities and/or any other appropriate stakeholders through the delivery of the contract to support climate and nature protection and improvement
-
Mission: Break down barriers to opportunity: By reforming our childcare and education systems, to make sure there is no class ceiling on the ambitions of young people in Britain
Policy Outcome 6: Employment and training: For those who face barriers to employment
- Understanding of employment and skills issues, and of the skills and employment shortages of high growth sectors relating to the contract
- Understanding of the issues affecting the representation of disabled people in the workforce in the market, industry or sector relevant to the contract, and in the supplier’s own organisation and those of its key sub-contractors
- Inclusive and accessible recruitment practices, and retention-focused activities, including those provided in the Guide for line managers on recruiting, managing and developing people with a disability or health condition
- Working conditions which promote an inclusive working environment and promote retention and progression
- Understanding of the issues affecting inequality in employment, skills and pay in the market, industry or sector relevant to the contract, and in the supplier’s own organisation and those of its key sub-contractors. Measures to tackle inequality in employment, skills and pay in the contract workforce
-
Mission: Break down barriers to opportunity: By reforming our childcare and education systems, to make sure there is no class ceiling on the ambitions of young people in Britain
Policy Outcome 7: Creating a pipeline of opportunities: For the contract workforce, reducing barriers to entry for under-represented groups.
- Understanding of the issues affecting the development of new skills by target cohort
- Understanding of the underlying factors affecting improvements to reduce barriers to entry and training schemes for the target cohort(s) related to the contract workforce
- Understanding of issues relating to entering the contract workforce
-
Mission: Build an NHS fit for the future: That is there when people need it; with fewer lives lost to the biggest killers; in a fairer Britain, where everyone lives well for longer.
Policy Outcome 8: Increasing productivity through physical and mental wellbeing: In the supply chain and communities in the relevant area.
- Understanding of issues relating to health and wellbeing, including physical and mental health, in the contract workforce
- Understanding barriers to access to health and social care services or employment opportunities e.g. digital inclusion
-