TimerOff

Data Processing Agreement

Version 1.0 · Last updated: September 2026

This Data Processing Agreement ("DPA") forms part of the Terms of Service between TimerOff ("Processor", "we") and the employer organisation that operates a TimerOff workspace ("Controller", "you"). It applies automatically to every TimerOff plan and is designed to meet Article 28 of the UK GDPR and the EU GDPR (Regulation (EU) 2016/679).

1. Roles of the Parties

You are the Controller of the personal data of your employees processed in your workspace and determine the purposes and means of that processing. We act solely as Processor, processing personal data on your documented instructions — which are the instructions given through the normal use of the service and this DPA.

2. Subject Matter, Duration, Nature and Purpose

Subject matter: provision of overtime and time-off-in-lieu (TOIL) recording, approval and reporting software.

Duration: for as long as your workspace remains active, plus the retention period in section 9.

Nature and purpose: collection, storage, organisation, retrieval, transmission (notifications), export and deletion of workspace records so that overtime can be converted into time off and evidenced.

3. Categories of Data Subjects and Personal Data

Data subjects: your employees, managers and any administrator you invite.

Personal data: name, work email address, job title, employee code, company association, authentication identifiers, overtime entries, time-off requests and employer comments, balances, and — where an employee chooses to use the shift tracker — clock-in and clock-out timestamps together with the device-reported latitude, longitude and accuracy at those moments.

Special category data: none is requested by the service. You must not enter health, religious, biometric or other special category data into free-text fields. Location data is processed only at the moment an employee actively clocks in or out; we do not track continuous location.

4. Processor Obligations

  • Process personal data only on your instructions and for the purposes above, and not for our own purposes.
  • Ensure personnel with access are bound by confidentiality obligations.
  • Implement the technical and organisational measures described in section 5.
  • Assist you, at your cost where material effort is required, with data subject requests, data protection impact assessments and regulator enquiries.
  • Notify you without undue delay, and in any case within 72 hours of becoming aware, of any personal data breach affecting your workspace, with the information available to us at that time.
  • Make available the information necessary to demonstrate compliance and allow audits under reasonable notice, no more than once per year unless required by a regulator.

5. Security Measures

  • Encryption in transit (TLS) for all traffic and encryption at rest for the database and backups.
  • Row-level security in the database so records are only readable by the employee they belong to and that employee's employer workspace.
  • Authentication with hashed credentials; role separation between employee, employer and platform administrator.
  • Least-privilege access for our personnel, granted only where needed for support or maintenance.
  • Logical separation of workspaces; automated daily backups with point-in-time recovery.
  • Monitoring, logging and security scanning of the application and database.

6. Subprocessors

You give general written authorisation for us to engage the subprocessors below. We impose data protection terms on each of them that are no less protective than this DPA, and we remain responsible for their performance.

  • Supabase / Amazon Web Services — managed database, authentication and file storage (hosting region: EU).
  • Cloudflare — content delivery, DNS and edge application hosting.
  • Resend — transactional and notification email delivery.
  • Google (AdSense, Analytics) — public marketing pages only; never loaded on signed-in workspace screens.

We will give you at least 30 days' notice by email before adding or replacing a subprocessor. If you reasonably object on data protection grounds, you may terminate the affected service without penalty for the remainder of the paid period.

7. International Transfers

Workspace data is stored in the European Union. Where a subprocessor processes personal data outside the UK or EEA, that transfer is covered by the European Commission's Standard Contractual Clauses together with the UK International Data Transfer Addendum, plus supplementary measures such as encryption in transit and at rest. A copy of the relevant clauses is available on request.

8. Data Subject Rights

The service gives you direct tools to access, correct and export workspace records. Where an employee exercises a right of access, rectification, erasure, restriction, portability or objection, we will assist you in responding within the statutory deadline. If a data subject contacts us directly, we will refer them to you and will not respond substantively unless legally required.

9. Retention, Return and Deletion

Records remain available while your workspace is active. On termination, or on your written instruction, we will delete or return workspace personal data within 30 days, except where storage is required by law. Backups containing deleted data expire on a rolling 30-day cycle. On the Free plan, records older than 12 months are not displayed in the application but are not deleted; you can request an export at any time.

10. Employment Law Note

You remain responsible for the lawful basis of your overtime and TOIL practices, for informing your employees about the shift tracker before they use it (including the fact that location is recorded at clock-in and clock-out), and for ensuring your arrangements comply with local working-time and employment law.

11. Liability and Precedence

Liability under this DPA is subject to the limitations in the Terms of Service. If there is a conflict between this DPA and the Terms of Service on the processing of personal data, this DPA prevails.

12. Accepting and Signing

Using TimerOff as an employer constitutes acceptance of this DPA and no signature is required. If your organisation needs a countersigned copy, or a DPIA pack for your own records (included on the Pro plan), email support@timeroff.com with your company name, registered address and the name of your data protection contact, and we will return a signed version.

Contact

Data protection enquiries: support@timeroff.com. See also our Privacy Policy.