Legal

Data Processing Agreement

Last updated 27 August 2026

This agreement applies where TimeGate processes personal data on behalf of a customer. It supplements the terms of service and is intended to meet the requirements that apply to a processor under the GDPR and equivalent regimes.

It takes effect automatically when a customer subscribes. A countersigned copy is available on request at hello@timegate.me.

1. Roles and scope

The customer is the controller and determines the purposes and means of processing. TimeGate is the processor and acts only on documented instructions from the customer.

The instructions are the terms of service, this agreement, and the configuration the customer sets in the platform. Enabling a verification check, assigning a role, or setting a leave policy each constitute an instruction.

If we consider an instruction to breach data protection law, we will tell the customer and may suspend that processing until it is resolved.

2. Details of processing

The subject matter, duration, nature, purpose, categories of data and categories of data subject are set out in Annex A below.

3. Confidentiality

We ensure that personnel authorised to process personal data are bound by confidentiality obligations, and that access is limited to those who need it to deliver the service or to support the customer.

4. Security measures

We implement appropriate technical and organisational measures, taking into account the state of the art, the cost of implementation and the risk to data subjects. Those measures are described in Annex B below and on our security page.

Measures may change as the platform evolves. We will not make a change that materially reduces the overall level of security.

5. Sub-processors

The customer gives general authorisation for the engagement of sub-processors. The current list, with purpose and region, is published on our sub-processors page.

Each sub-processor is engaged under a written contract imposing data protection obligations no less protective than this agreement. We remain liable to the customer for the performance of each sub-processor.

We will give at least 30 days notice before adding or replacing a sub-processor. A customer may object on reasonable data protection grounds within that period. If we cannot resolve the objection, the customer may terminate the affected part of the subscription without penalty for the unexpired term.

6. Data subject requests

The platform allows the customer to access, correct, export and delete the records it holds, which lets the customer respond to requests directly.

Where a data subject contacts us instead, we will not respond substantively. We will forward the request to the customer without undue delay and assist the customer in responding, taking into account the nature of the processing.

7. Personal data breach

We will notify the customer without undue delay after becoming aware of a personal data breach affecting their data.

The notification will describe the nature of the breach, the categories and approximate number of data subjects and records affected so far as known, the likely consequences, and the measures taken or proposed. Where the full picture is not available at once, information will be provided in phases.

We will assist the customer in meeting its own notification obligations to supervisory authorities and data subjects.

8. Assistance

Taking into account the nature of processing and the information available to us, we will assist the customer with data protection impact assessments and with prior consultation of a supervisory authority, where those obligations arise from the use of TimeGate.

9. Audits and information

We will make available the information reasonably necessary to demonstrate compliance with this agreement, and will contribute to audits conducted by the customer or an auditor it appoints.

Audits are limited to once per twelve months unless a breach or a regulator requires otherwise, must be scheduled with reasonable notice, must not disrupt operations, and are subject to confidentiality. We do not currently hold a third-party certification or audit report that can be provided in place of an audit, and we say so plainly rather than implying otherwise.

10. International transfers

Production infrastructure is located in the United States. Personal data originating in the EEA, the UK, or another jurisdiction with transfer restrictions will therefore be transferred outside its country of origin.

Where such a transfer requires a safeguard, the parties rely on the standard contractual clauses approved by the European Commission, and the UK International Data Transfer Addendum where the UK regime applies, each incorporated by reference with the customer as data exporter and TimeGate as data importer. Annex A supplies the required processing details and Annex B the required security description.

A customer with a data residency requirement should raise it before rollout, because meeting it would require a different deployment.

11. Deletion and return

During the subscription, the customer can export its data at any time through the platform.

On termination we make the data available for export for 30 days, and then delete or irreversibly anonymise it on request. We do not currently operate an automated purge schedule, so deletion is performed when requested rather than automatically. Where a customer requires automated deletion on a defined schedule, it must be agreed in writing.

Copies may persist in encrypted backups until those backups are rotated in the ordinary course. Backup copies remain subject to this agreement until they are overwritten.

We may retain personal data where law requires it, and in that case only for as long as required and only for that purpose.

12. Liability and precedence

The liability provisions of the terms of service apply to this agreement.

Where this agreement conflicts with the terms of service on the processing of personal data, this agreement prevails. Where it conflicts with the standard contractual clauses, the clauses prevail.

Annex A: details of processing

Required by data protection law and by the standard contractual clauses.

  • Subject matter: provision of the TimeGate workforce attendance and leave platform.
  • Duration: the term of the subscription, plus the export and deletion period described in section 11.
  • Nature and purpose: recording and verifying attendance, managing leave and approvals, recording disciplinary warnings, producing payroll input, and providing reporting to the customer.
  • Categories of data subject: employees, contractors and other workers of the customer, and the customer administrative and HR users.
  • Categories of personal data: identity and employment data; attendance events including timestamps and branch; location coordinates and accuracy at the moment of a punch; Wi-Fi network identifiers at the moment of a punch; device platform, model, operating system, application version, hashed device fingerprint and push token; IP address and user agent; leave requests, balances, approval history and attachments; disciplinary warnings; compensation, payroll and bank details; authentication data in hashed form; and audit records.
  • Special category data: not required by the platform. Where a customer requires employees to attach medical certificates to sick leave, health data may be contained in those attachments. The customer is responsible for the lawful basis and any condition for processing that applies.
  • Frequency: continuous for the duration of the subscription.
  • Sub-processors: as listed on the sub-processors page, for the purposes stated there.

Annex B: technical and organisational measures

A summary. The security page describes each item in more detail, including what is not yet in place.

  • Encryption in transit: TLS for all traffic between the applications and our servers.
  • Encryption at rest: storage and backups encrypted by the infrastructure provider, with field-level encryption for bank account numbers and SWIFT or routing values using a key held outside the database.
  • Authentication: bcrypt password hashing with per-user salts, 15 minute access tokens, hashed refresh tokens with a 14 day lifetime, optional multi-factor authentication, and hashed one-time codes with attempt limits and lockout for mobile sign-in.
  • Access control: tenant isolation scoped by company, role-based permissions inside each tenant, and least-privilege access to production for our own personnel.
  • Rate limiting and origin control: API rate limiting and a cross-origin allowlist.
  • Logging and traceability: audit logging of dashboard actions with actor, role, before and after state, IP address, user agent and correlation identifier.
  • Environment separation: distinct databases and cache namespaces for development, staging and production.
  • Resilience: cache circuit breaker so that a degraded cache backend is bypassed rather than allowed to degrade every request.
  • Integrity of records: server-side timestamps recorded alongside client timestamps, offline punches marked as such, and adjustments attributed to the user who made them.

How to execute this agreement

This agreement applies from the start of the subscription without further signature. If your procurement process requires a signed copy, or requires the standard contractual clauses as a separate executed document, email hello@timegate.me and we will provide one.