---
title: Data processing agreement | TimeClockApp
canonical: https://timeclockapp.es/en/legal/dpa
language: en
llms: https://timeclockapp.es/en/llms.txt
---

# Data processing agreement

Draft GDPR Article 28 agreement between each client company as controller and the TimeClockApp provider as processor.

## 1. Parties purpose and duration

Controller: client company. Processor: [PENDING ADVISER: provider identity]. Purpose: supply TimeClockApp under documented instructions. Duration: service term plus applicable return, restriction or deletion period.

## 2. Nature purpose and people

Hosting, organization, authorized changes, reporting, support, backup and deletion for timekeeping and workforce management. People include workers and authorized customer users.

## 3. Data categories

Work identity and contact, credentials, company and site, schedules, time records, breaks, leave, incidents, changes, reports, technical evidence and point-in-time location when enabled.

## 4. Instructions and confidentiality

The processor acts only on documented instructions, flags instructions it believes unlawful and limits access to authorized personnel under confidentiality.

## 5. Security

Access control, tenant separation, encryption in transit, password hashing, audit logs, vulnerability management, backups and recovery. The final technical annex states verified scope, frequency and responsibility.

## 6. Sub-processors and transfers

The approved list states provider, service, country, data and safeguard. Customers authorize sub-processing under the agreed mechanism and receive change notice with an objection period. International transfers require a valid safeguard.

## 7. Rights and cooperation

The processor forwards requests to the controller and assists with search, export, correction, restriction and deletion within the contractual deadline.

## 8. Personal data breaches

The processor notifies the controller without undue delay after awareness, including nature, categories, approximate scale, consequences, measures and contact. The internal deadline must support the controller's 72-hour assessment.

## 9. Assessments audits and evidence

The processor assists with risk and impact assessments and provides reasonable audit information under confidentiality and agreed conditions.

## 10. Return restriction and deletion

At termination the customer may export data. Data is then returned or deleted at its choice unless documented law requires restricted retention, with evidence supplied where appropriate.

## 11. Pending annexes

Instructions, inventory, sub-processors, transfers, technical controls, contacts, deadlines, location, assistance and return format: [PENDING LAWYER AND FINAL CONFIGURATION].

TimeClockApp is not a substitute for legal, employment, tax, or accounting advice.
