This Data Processing Addendum ("DPA") forms part of the TimeOff.Management Terms of Service and any online subscription, account, trial, order, invoice or other agreement under which TimeOff.Management provides its services to the Customer.
By creating a TimeOff.Management account, using the service or continuing to use the service, the Customer agrees to this DPA.
1. Parties
This DPA is entered into between:
- The Customer, being the organisation that creates or operates a TimeOff.Management account, acting as the Data Controller; and
- TimeOff.Management, the provider of the service, acting as the Data Processor.
Together, the Customer and TimeOff.Management are referred to as the "Parties".
2. Purpose of this DPA
The Customer may add personal data about its employees, contractors, managers and other authorised users to TimeOff.Management.
The Customer decides:
- what personal data is entered;
- why the personal data is processed;
- who may access the personal data;
- how long the Customer wishes to use the service; and
- when records should be edited, exported or deleted.
TimeOff.Management processes this personal data only to provide, maintain, secure and support the service.
3. Data protection laws
Each Party must comply with the data protection laws that apply to it.
These may include:
- the UK General Data Protection Regulation;
- the Data Protection Act 2018;
- the EU General Data Protection Regulation, where applicable; and
- any replacement or related data protection legislation.
Terms such as "Controller", "Processor", "Personal Data", "Data Subject", "Processing", "Personal Data Breach" and "Supervisory Authority" have the meanings given to them under the applicable data protection laws.
4. Customer responsibilities
The Customer is responsible for ensuring that:
- it has a lawful basis for collecting and processing personal data through TimeOff.Management;
- employees and other Data Subjects receive any required privacy information;
- the personal data entered into the service is relevant and appropriate;
- user accounts and permissions are assigned correctly;
- access is removed when a user no longer requires it;
- information is not retained for longer than the Customer needs it; and
- the Customer's use of TimeOff.Management complies with applicable employment, privacy and data protection laws.
The Customer's use of the service constitutes documented instructions to TimeOff.Management to process Customer Personal Data as described in this DPA and the main agreement.
5. TimeOff.Management obligations
TimeOff.Management will:
- process Customer Personal Data only on the Customer's documented instructions;
- process the data only as required to provide, secure, maintain and support the service;
- not sell Customer Personal Data;
- not use Customer Personal Data for advertising;
- ensure that people authorised to process Customer Personal Data are subject to appropriate confidentiality obligations;
- maintain appropriate technical and organisational security measures;
- assist the Customer with reasonable data protection requests;
- notify the Customer of a Personal Data Breach as described in this DPA; and
- delete or return Customer Personal Data at the end of the service, subject to legal and technical retention requirements.
If applicable law requires TimeOff.Management to process Customer Personal Data other than on the Customer's documented instructions, TimeOff.Management will inform the Customer of that legal requirement before the processing takes place, unless the law prohibits this on important grounds of public interest.
If TimeOff.Management believes that a Customer instruction breaches applicable data protection law, TimeOff.Management will immediately inform the Customer, unless informing the Customer is prohibited by law. TimeOff.Management may suspend the affected processing until the instruction is confirmed, amended or withdrawn.
6. Details of the processing
Subject matter
Providing the TimeOff.Management leave and absence management service.
Duration
For the period during which the Customer has an active account, subscription or trial, plus any limited period required for deletion, backup rotation or legal compliance.
Nature of the processing
The processing may include:
- collecting;
- recording;
- organising;
- storing;
- viewing;
- updating;
- calculating leave allowances;
- processing leave and absence requests;
- generating reports;
- sending service notifications;
- exporting records;
- restricting access; and
- deleting personal data.
Purpose of the processing
The purpose is to allow the Customer to manage employee leave, absence, working schedules, approvals, allowances, calendars, records and related reports.
7. Types of personal data
Depending on how the Customer configures the service, Customer Personal Data may include:
- employee names;
- work email addresses;
- employee identifiers;
- departments;
- locations;
- employment dates;
- job-related information;
- manager and supervisor relationships;
- working schedules;
- leave allowances;
- leave and absence dates;
- leave types;
- request comments;
- approval decisions;
- attachments or notes entered by the Customer;
- absence records;
- sickness records;
- account activity; and
- technical information required to operate and secure user accounts.
The Customer should avoid entering unnecessary personal information into comments, notes or custom fields.
8. Categories of Data Subjects
Data Subjects may include:
- employees;
- workers;
- contractors;
- managers;
- supervisors;
- administrators;
- former employees whose records are retained by the Customer; and
- other authorised users added by the Customer.
9. Confidentiality
TimeOff.Management will limit access to Customer Personal Data to people who need that access to provide, maintain, secure or support the service.
Anyone authorised to access Customer Personal Data must be subject to confidentiality obligations.
TimeOff.Management will not disclose Customer Personal Data to another party unless:
- the Customer instructs TimeOff.Management to do so;
- disclosure is required to provide the service;
- disclosure is required by law; or
- disclosure is necessary to protect the security, rights or integrity of the service.
Where legally permitted, TimeOff.Management will inform the Customer before disclosing Customer Personal Data in response to a legally binding request.
10. Security measures
TimeOff.Management will maintain technical and organisational measures designed to protect Customer Personal Data against:
- unauthorised access;
- accidental loss;
- unlawful disclosure;
- alteration;
- destruction; and
- other unlawful processing.
These measures include, where appropriate:
- secure HTTPS and TLS connections;
- access controls;
- authenticated user accounts;
- permission-based access;
- separation of Customer accounts;
- restrictions on administrative access;
- software updates and security maintenance;
- backups;
- monitoring and investigation of security incidents;
- confidentiality requirements;
- secure development and deployment practices; and
- procedures for restoring service following an incident.
Customer data is encrypted in transit using HTTPS and TLS.
The Customer remains responsible for:
- choosing strong passwords;
- protecting login details;
- configuring access permissions;
- removing access from former employees;
- protecting exported files; and
- ensuring that users do not share accounts.
11. Hosting and data location
The TimeOff.Management application and primary customer database are hosted by DigitalOcean.
The primary hosting location is DigitalOcean's London data centre, including the LON1 region, in the United Kingdom.
TimeOff.Management does not routinely move or store the main Customer Personal Data outside the United Kingdom.
12. Backups
TimeOff.Management maintains backups to support service recovery and business continuity.
Backups are normally retained for up to five days. Older backups are automatically overwritten or deleted as part of the normal backup rotation.
Because backups are designed for service recovery, it may not be possible to remove an individual record from an existing backup immediately.
Where Customer Personal Data has been deleted from the active system, the deleted information will leave the backup environment when the relevant backup is overwritten, normally within five days.
Backups will not be restored except where reasonably necessary for disaster recovery, system recovery or security investigation.
13. Sub-processors
The Customer authorises TimeOff.Management to use sub-processors where reasonably required to provide the service.
The current main sub-processors are:
| Sub-processor | Purpose | Processing location |
|---|---|---|
| DigitalOcean | Cloud infrastructure, servers, database hosting, storage and backups | London, United Kingdom |
| Mailgun | Transactional email and service notifications | European Union |
TimeOff.Management will ensure that each sub-processor processing Customer Personal Data is bound by written data protection and confidentiality obligations substantially the same as those set out in this DPA.
TimeOff.Management remains fully responsible to the Customer where a sub-processor fails to fulfil those obligations.
TimeOff.Management may replace or add a sub-processor where reasonably necessary.
TimeOff.Management will inform the Customer of any intended addition or replacement of a sub-processor before the change takes effect, through the website, service, account communication or email, giving the Customer the opportunity to object.
The Customer may raise a reasonable data protection objection. The Parties will work in good faith to resolve it.
If no reasonable solution is available, the Customer may stop using the affected service and close its account.
14. Personal Data Breaches
TimeOff.Management will notify the Customer without undue delay after becoming aware of a Personal Data Breach affecting Customer Personal Data.
TimeOff.Management will aim to provide the initial notification within 48 hours of becoming aware of the breach.
The notification will include the information reasonably available at the time, which may include:
- the nature of the breach;
- the types of personal data affected;
- the approximate number of records or Data Subjects affected;
- the likely consequences;
- steps taken or proposed to contain the breach; and
- contact details for further information.
Information may be provided in stages where all details are not immediately available.
TimeOff.Management will take reasonable steps to investigate, contain and reduce the effects of the breach.
The Customer remains responsible for deciding whether the breach must be reported to a Supervisory Authority or communicated to affected Data Subjects.
A notification under this section does not constitute an admission of fault or liability.
15. Data Subject requests
Taking into account the nature of the processing, TimeOff.Management will provide reasonable assistance to help the Customer respond to requests from Data Subjects.
These may include requests for:
- access;
- correction;
- deletion;
- restriction;
- objection; and
- data portability.
Where a Data Subject contacts TimeOff.Management directly about Customer Personal Data, TimeOff.Management will notify the relevant Customer without undue delay, where that Customer can reasonably be identified, and may refer the person to that Customer.
TimeOff.Management will not independently respond to the request unless required by law or authorised by the Customer.
The Customer can access, update, export and delete much of its data directly through the service.
16. Assistance with compliance
Taking into account the nature of the processing and the information available to it, TimeOff.Management will provide reasonable assistance with:
- security assessments;
- Personal Data Breach investigations;
- Data Protection Impact Assessments;
- consultations with Supervisory Authorities; and
- other obligations under applicable data protection laws.
TimeOff.Management may charge reasonable costs where a request requires significant work beyond the normal operation of the service.
17. Data exports
The Customer may export available records using the reporting and export functions provided by TimeOff.Management.
The Customer should complete any required exports before closing its account.
Exported files are controlled by the Customer. The Customer is responsible for storing, sharing and deleting exported information securely.
18. Return and deletion of data
During the subscription or trial, the Customer may edit or delete records using the service's available controls.
When the service ends, the Customer may request the return or deletion of Customer Personal Data.
Where the Customer chooses return, TimeOff.Management will provide a copy of the Customer Personal Data it holds in a commonly used electronic format within a reasonable period, before deleting it from the active service.
The service's reporting and export features are the normal means of return. Where retained Customer Personal Data is not covered by those features, TimeOff.Management will provide it on request, and may charge reasonable costs where a return request requires significant work beyond the service's normal export features.
Following account closure or a valid deletion request, TimeOff.Management will delete Customer Personal Data from the active service within a reasonable period, unless:
- the Customer asks TimeOff.Management to retain it;
- retention is required by law;
- the data is needed to establish, exercise or defend legal claims;
- limited information is required for fraud prevention or security; or
- the information remains temporarily within backup rotation.
Where retention is required by law, TimeOff.Management will inform the Customer of that legal requirement, unless the law prohibits this.
Data remaining in backups will normally be overwritten or deleted within five days.
TimeOff.Management may retain basic account, billing and transaction information where required for tax, accounting, fraud prevention or legal purposes.
19. International data transfers
TimeOff.Management does not routinely transfer or host the main Customer Personal Data outside the United Kingdom.
If TimeOff.Management introduces processing that involves an international transfer, it will ensure that an appropriate transfer mechanism is in place where required.
This may include:
- an adequacy regulation or decision;
- the UK International Data Transfer Agreement;
- the UK Addendum to the EU Standard Contractual Clauses;
- the EU Standard Contractual Clauses; or
- another legally recognised safeguard.
20. Audits and information
TimeOff.Management will provide information reasonably necessary to demonstrate compliance with this DPA.
The Customer should first use the information, policies, security descriptions and supporting documents made available by TimeOff.Management.
Where that information is not sufficient, the Customer may request an audit.
Unless an audit is required by a Supervisory Authority, or the Customer has reasonable grounds to suspect a Personal Data Breach or a material breach of this DPA affecting Customer Personal Data, an audit may take place no more than once in any 12-month period.
For any audit:
- the Customer must provide at least 30 days' written notice, or a shorter period that is reasonable where the audit follows a suspected Personal Data Breach or is required by a Supervisory Authority;
- the audit must take place during normal business hours;
- the audit must not unreasonably disrupt TimeOff.Management;
- the auditor must be independent and subject to confidentiality obligations; and
- the Customer must pay its own audit costs and any reasonable costs incurred by TimeOff.Management.
An audit must not provide access to:
- information relating to another customer;
- TimeOff.Management trade secrets;
- source code;
- information that would weaken service security; or
- personal data that is not relevant to the audit.
TimeOff.Management may offer to satisfy an audit request by providing an independent report, security response, written evidence or other appropriate compliance information. Where that information reasonably demonstrates compliance with this DPA, no further audit will be required.
21. Records and regulatory cooperation
TimeOff.Management will maintain records of its processing activities where required by applicable law.
TimeOff.Management will cooperate with a competent Supervisory Authority where legally required.
The Customer is responsible for maintaining its own Controller records and for identifying TimeOff.Management as a Processor where necessary.
22. Liability
Each Party's liability under this DPA is subject to the exclusions, limitations and liability provisions in the main agreement between the Parties.
Nothing in this DPA limits liability where that limitation is prohibited by law.
23. Duration and termination
This DPA begins when the Customer creates an account, starts a trial, accepts an order or otherwise begins using TimeOff.Management.
It continues for as long as TimeOff.Management processes Customer Personal Data on behalf of the Customer.
Provisions that must continue after termination, including confidentiality, deletion, legal retention and liability provisions, will remain in effect.
24. Changes to this DPA
TimeOff.Management may update this DPA to reflect:
- changes to the service;
- changes to data protection laws;
- changes to sub-processors;
- changes to security or hosting arrangements; or
- guidance from a Supervisory Authority.
Material changes will be communicated through the website, service, account notification or email.
Continued use of the service after an updated DPA takes effect constitutes acceptance of the updated DPA, to the extent permitted by law.
25. Order of precedence
A specifically negotiated written agreement between the Parties will take priority over this DPA.
Otherwise, if there is a conflict between this DPA and another part of the agreement relating specifically to the processing of personal data, this DPA will take priority.
All other terms of the main agreement remain unchanged.
26. Governing law
This DPA is governed by the same law and jurisdiction as the TimeOff.Management Terms of Service.
Unless another agreement states otherwise, this DPA is governed by the laws of England and Wales, and the courts of England and Wales will have jurisdiction.
27. Contact details
Questions about this DPA or the processing of Customer Personal Data should be sent to:
TimeOff.Management
Email: info@timeoff.management
28. Acceptance and signatures
This DPA is designed to be accepted electronically as part of the TimeOff.Management Terms of Service. A separate signature is not normally required.
Where a signed copy is required, please contact us at info@timeoff.management and we will arrange a countersigned copy.