Skip to main content

Help us improve the Digital Marketplace - send your feedback

TE-CON B.V.

eHour

eHour is cloud-based timesheet, attendance and project time tracking software for public sector organisations. It captures working time, start and end times, billable and non-billable hours and expenses, manages approvals and project budgets, and provides auditable management and financial reporting for transparent cost control.

Features

  • Weekly timesheets, timers and Jira-based time tracking
  • Project, task and activity time recording
  • Attendance tracking using start and end times
  • Billable and non-billable hours, rates, costs and revenue
  • Time and financial project budgets with progress monitoring
  • Expense recording with receipt capture and approval
  • Timesheet approvals, automatic reminders and locked approved hours
  • Real-time reporting, dashboards, exports, API and Power BI access
  • Role-based access, SSO and automated SCIM user provisioning
  • Secure service with ISO 27001 certified information security

Benefits

  • Make timesheet and attendance recording simple for employees
  • Reduce missing and late timesheets through reminders and easy entry
  • Keep approved hours final, auditable and ready for further processing
  • Provide reliable time and expense data for payroll and invoicing
  • Monitor project budgets, costs, revenue and utilisation in real time
  • Identify budget overruns and unrecorded time earlier
  • Improve financial accountability across teams and departments
  • Give managers timely insight without manually combining spreadsheets
  • Reduce user administration through SSO, SCIM and role-based access
  • Support internal controls, working-time policies and audit requirements

Pricing

Service documents

Request an accessible format
If you use assistive technology (such as a screen reader) and need versions of these documents in a more accessible format, email the supplier at info@ehour.com. Tell them what format you need. It will help if you say what assistive technology you use.

Framework

G-Cloud 15

Service ID

6 3 8 1 2 3 3 5 2 0 2 7 4 0 1

Contact

TE-CON B.V. Thies Edeling
Telephone: +31 202615286
Email: info@ehour.com

About your service

Service categories

Applications

Enterprise resource management

  • Enterprise performance management
  • Project and portfolio management
Multi cloud support
No

Service scope

Software add-on or extension
No
Cloud deployment model
Public cloud
Service constraints
There are no material service constraints. The service is available to users via a standard web browser and is maintained without planned customer-specific downtime.
System requirements
  • Modern web browser with JavaScript and cookies enabled
  • Internet connection to access the cloud-based service
  • Email access for notifications and account communication
  • User account with role-based access permissions

User support

Email or online ticketing support
Yes
Support response times
One business day
User can manage status and priority of support tickets
No
Phone support
No
Web chat support
Yes
Web chat support availability
9 to 5 (UK time), Monday to Friday
Web chat support accessibility standard
None or don’t know
How the web chat support is accessible
The web chat is provided through an in-application widget that allows users to communicate directly with a support operative using text-based messaging. The service does not require voice interaction. Accessibility features depend on the user’s device, browser and any assistive technologies in use. No formal accessibility standard is currently certified for the web chat component.
Web chat accessibility testing
No formal testing of the web chat has been conducted with assistive technology users. The web chat functionality is provided as a standard text-based widget within the application. Any accessibility experienced by users depends on their device, browser and assistive technologies in use.
Onsite support
No
Support levels
The service is provided with a single, standard level of support for all customers. Support is included in the service subscription at no additional cost. There are no tiered support levels.

Support is provided via email and in-application web chat during standard business hours (9am to 5pm UK time, Monday to Friday). Response times are provided on a best-efforts basis.

The service does not include a dedicated Technical Account Manager or Cloud Support Engineer. All customers receive the same level of support from the support team.
Support available to third parties
Yes
AI chatbot
No

Onboarding and offboarding

Getting started
Users are supported through in-application onboarding that guides them through initial setup and core functionality. This is complemented by online “Getting Started” guides and user documentation available via the knowledge base.

Additional support is available via email or web chat during business hours. No on-site training is required to start using the service.
Service documentation
Yes
Documentation formats
HTML
End-of-contract data extraction
At the end of the contract, users can extract their data directly from the service using built-in export functionality.

Standard exports are available for reports, projects, clients, users and teams in commonly used file formats suitable for offline use and import into other systems. Data can be exported by authorised users prior to contract termination.

No specialist tools are required to perform data extraction.
End-of-contract process
At the end of the contract, access to the service will cease in line with the agreed contract end date.

Prior to contract termination, authorised users can export their data using the standard export functionality included in the service. This includes reports and core configuration data such as projects, clients, users and teams.

Data extraction using the standard export features is included in the contract price. No mandatory exit fees apply.

Following contract termination, customer data is retained for a limited period in accordance with our data retention policy, after which it is securely deleted.

Any additional support beyond standard data export, such as bespoke data extraction or extended data retention, can be discussed separately and may incur additional costs if requested.
Documentation accessibility standard
None or don’t know
How the documentation is accessible
Onboarding and offboarding documentation is provided through a web-based HTML knowledge base. The documentation is accessible via standard web browsers without the need for additional software or downloads. Content is text-based and structured for online reading.

Accessibility depends on the user’s browser, device and any assistive technologies in use. No formal accessibility standard has been certified.

Using the service

Web browser interface
Yes
Supported browsers
  • Microsoft Edge
  • Firefox
  • Chrome
  • Safari
  • Opera
Application to install
No
Designed for use on mobile devices
Yes
Differences between the mobile and desktop service
The mobile version supports time tracking. Reporting, configuration and administrative management are provided via the desktop service.
Service interface
Yes
User support accessibility
None or don’t know
Description of service interface
The service provides a web-based user interface accessible via standard web browsers, allowing users to record time, manage projects, and view reports. In addition, a REST-based API is available to support integrations with third-party systems.
Accessibility standards
None or don’t know
Description of accessibility
No formal testing has been conducted specifically with users of assistive technologies. The service interface is accessed through standard web browsers and relies on the accessibility features provided by the user’s operating system, browser, and any assistive technologies in use. Accessibility feedback may be addressed on a case-by-case basis if raised by users.
Accessibility testing
No formal testing has been conducted specifically with users of assistive technologies.
API
Yes
What users can and can't do using the API
The API allows authorised users to manage core entities including clients, projects, tasks, users and teams. It supports creating and updating time entries and expenses, and retrieving data for reporting purposes.

The API can be used for system integration and automation, including user lifecycle management through SCIM. All actions are subject to authentication, role-based permissions and validation rules. Certain configuration and administrative functions remain available only through the web interface.
API documentation
Yes
API documentation formats
  • Open API (also known as Swagger)
  • HTML
API sandbox or test environment
Yes
Customisation available
No

Scaling

Independence of resources
The service is delivered on a multi-tenant cloud architecture hosted on AWS. Capacity is managed through automatic scaling of compute resources based on demand, ensuring consistent performance as usage increases.

Analytics

Service usage metrics
No

Resellers

Supplier type
Not a reseller

Staff security

Staff security clearance
Other security clearance
Government security clearance
None

Asset protection

Knowledge of data storage and processing locations
Yes
Data storage and processing locations
European Economic Area (EEA)
User control over data storage and processing locations
No
Datacentre security standards
Managed by a third party
Penetration testing frequency
At least once a year
Penetration testing approach
Another external penetration testing organisation
Protecting data at rest
Encryption of all physical media
Data sanitisation process
Yes
Equipment disposal approach
Complying with a recognised standard, for example CSA CCM v4.0, CAS (Sanitisation) or ISO/IEC 27001
Data sanitisation type
  • Deleted data can’t be directly accessed / Cryptographic Erasure
  • Data Erasure

Data importing and exporting

Data export approach
Users can export their data using built-in export functionality within the service and via the API.

Standard exports are available for reports and configuration data, including projects, clients, users and teams. Reports can be exported in common formats such as CSV, Excel and PDF.

The API allows programmatic access to data for automated extraction and integration with external systems.
Data export formats
  • CSV
  • Other
Other data export formats
XLSX
Data import formats
Other
Other data import formats
XLSX

Data-in-transit protection

Data protection between buyer and supplier networks
TLS (version 1.2 or above)
Data protection within supplier network
TLS (version 1.2 or above)

Availability and resilience

Guaranteed availability
The service is provided on a best-efforts basis. eHour uses best efforts to maintain 99.5% availability during business hours (09:00–18:00 CET).

Planned maintenance is carried out outside business hours wherever reasonably possible and is announced in advance when feasible.

No formal service credits or refunds are provided if the availability target is not met. Availability commitments and maintenance arrangements are governed by the applicable terms and conditions.
Approach to resilience
The service is hosted on AWS and designed for resilience using managed cloud infrastructure. The platform uses redundant components and automatic scaling to handle varying load and reduce the impact of failures. Backup and recovery procedures are in place to support service continuity.
Outage reporting
Service availability and incidents are communicated via a public status dashboard. The dashboard provides up-to-date information on current incidents, planned maintenance and historical outages.

Identity and authentication

User authentication needed
Yes
User authentication
  • Multi-Factor Authentication (MFA)
  • Identity federation with existing provider (for example Google Apps)
  • Username or password
Access restrictions in management interfaces and support channels
Access to management interfaces is restricted to authenticated users within the application.

For support requests, user identity is verified by matching the request against the registered account details, such as the email address associated with the user or organisation. Account-specific actions are only performed after successful verification.

In-application support features are only available to authenticated users.
Access restriction testing frequency
At least once a year
Management access authentication
  • Multi-Factor Authentication (MFA)
  • Identity federation with existing provider (for example Google Apps)
  • Username or password

Audit information for users

Access to user activity audit information
Users have access to real-time audit information
How long user audit data is stored for
At least 12 months
Access to supplier activity audit information
Users have access to real-time audit information
How long supplier audit data is stored for
At least 12 months
How long system logs are stored for
Between 6 months and 12 months

Security governance

Named board-level person responsible for service security
Yes
Security governance certified
Yes
Security governance standards
ISO/IEC 27001
Information security policies and processes
We operate an ISO/IEC 27001:2022 certified Information Security Management System (ISMS). This includes documented information security policies and procedures such as access control, incident management, change management and vulnerability management.

Information security responsibilities are formally assigned and compliance is monitored through defined procedures, logging, reviews and internal and external audits.
Software Security Code of Practice
Yes

Operational security

Configuration and change management standard
Supplier-defined controls
Configuration and change management approach
Configuration and changes are managed through defined internal change management procedures aligned with our ISO 27001 certified ISMS. Service components and configurations are version-controlled and tracked throughout their lifecycle.

All changes are reviewed before implementation, including an assessment of potential security and operational impact. Changes are tested prior to deployment and are rolled out in a controlled manner to minimise risk and service disruption.
Vulnerability management type
Supplier-defined controls
Vulnerability management approach
Vulnerabilities are identified through a combination of automated dependency scanning, cloud provider security notifications, and periodic external penetration testing. Potential impact is assessed based on risk and exposure. Security patches are prioritised and deployed as part of our regular release and maintenance process, with critical fixes applied as soon as reasonably possible. Information about emerging threats is sourced from trusted vendors, security advisories, and penetration test reports. All identified vulnerabilities are tracked and remediated in line with our internal security procedures.
Protective monitoring type
Supplier-defined controls
Protective monitoring approach
The service uses protective monitoring based on application and infrastructure logging. Logs and audit trails are continuously collected and reviewed to identify unusual activity, access anomalies or potential security incidents. Automated alerts are configured for critical events. When a potential compromise is identified, it is investigated promptly and handled according to the incident management process. Mitigating actions are taken where required and incidents are recorded and reviewed. Initial response to security incidents typically occurs within 24 hours.
Incident management type
Supplier-defined controls
Incident management approach
We operate a defined incident management process aligned with ISO 27001. Common security and availability incidents follow documented procedures. Users can report incidents via email or in-application support. All incidents are logged, assessed for impact, and assigned an owner. Where required, affected customers are informed of incidents and progress updates. Post-incident reviews are performed to identify root causes and corrective actions, and incident records are retained for audit purposes.
Post-quantum cryptography secure
No

Secure development

Approach to secure software development best practice
Independent review of processes (for example CESG CPA Build Standard, ISO/IEC 27034, ISO/IEC 27001 or CSA CCM v4.0)

Public sector networks

Connection to public sector networks
No

Pricing

Discount for educational organisations
No
Free trial available
Yes
Description of free trial
A 14-day free trial is available with full access to all features. A paid subscription is required after the trial period ends.
Link to free trial
https://getehour.com/signup/

Discount percentage by annual call-off contract value (excluding VAT)

Less than £250,000
10%
Between £250,000 and £500,000
10%
Between £500,001 and £1,000,000
10%
Between £1,000,001 and £2,500,000
10%
Between £2,500,001 and £5,000,000
10%
Over £5,000,001
10%

Non-mandatory Standards and certifications

ISO/IEC 27001 certification
Yes
Who accredited the ISO/IEC 27001
British Assessment Bureau
ISO/IEC 27001 accreditation date
Thursday 17 October 2024
What the ISO/IEC 27001 doesn’t cover
Not applicable. The ISO/IEC 27001 certification covers the full scope of the eHour SaaS service, including development, hosting, operations, and support.
ISO 28000:2022 certification
No
ISO 9001 certification
No
Quality management systems (QMS)
Yes
CSA STAR certification
No
PCI certification
No
Cyber essentials
No
Cyber Essentials Alternative
None of the criteria
Cyber essentials plus
No
Cyber Essentials Alternative
None of the criteria
Other security certifications
No

Social value

Section B - Commitment for Future: Delivery
  • Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.

    Policy Outcome 1: Fair work: That offers fair wages and good working conditions. Help people get a job, stay in work, and progress in their careers, with good employment opportunities across the country. Notes: Where there is a large proportion of labour costs in the contract, commercial teams should consider MAC in Outcome 1 as a priority

    • New or retained jobs on the contract workforce in the relevant area that meet the criteria set out in MAC 1b, 1c and 1d

Service documents

Request an accessible format
If you use assistive technology (such as a screen reader) and need versions of these documents in a more accessible format, email the supplier at info@ehour.com. Tell them what format you need. It will help if you say what assistive technology you use.