This Data Processing Addendum ("DPA") is incorporated into and forms part of the Terms of Service or other agreement (the "Agreement") between 12PM d.o.o., a company organized under the laws of Croatia ("Processor", "we"), and the Customer identified in the Agreement ("Controller", "Customer"), governing the processing by Processor of Personal Data on behalf of Controller in connection with the TimeCardCruncher service (the "Service").
In the event of any conflict between this DPA and the Agreement, this DPA controls with respect to the processing of Personal Data.
The Service is offered only to businesses established and operating in the United States, and is intended for the processing of Personal Data of individuals located in the United States. Controller represents and warrants that it will not submit to the Service Personal Data of individuals located in the European Economic Area, the United Kingdom, or Switzerland, or any other Personal Data the processing of which is subject to the EU General Data Protection Regulation ("GDPR"), the UK GDPR, or equivalent laws, without Processor's prior written agreement. Access to the Service is additionally restricted by network-level controls that prevent connections from the European Economic Area, the United Kingdom, and Switzerland to all account, registration, and API endpoints.
Processor has not implemented, and this DPA does not provide, the additional measures required for GDPR or UK GDPR compliance, including (without limitation) Article 28 standard contract terms in their full form, standard contractual clauses or other approved cross-border transfer mechanisms, the appointment of an EU/UK representative, or the data subject rights handling timelines required by those laws. If Controller breaches this Section, Controller is solely responsible for any resulting non-compliance and will indemnify Processor as set out in the Agreement.
Capitalized terms not defined here have the meanings given to them in the Agreement or, where applicable, in Data Protection Laws.
With respect to Personal Data submitted to the Service by Controller (typically timecard records relating to Controller's workers), Controller acts as the controller (or "business" under the CCPA) and Processor acts as the processor (or "service provider" under the CCPA). The parties acknowledge that Processor processes Personal Data only on behalf of Controller and only for the purposes set out in this DPA and the Agreement.
| Subject matter | Processing of Personal Data submitted by Controller to the Service. |
|---|---|
| Duration | For the term of the Agreement, plus any post-termination period required for return or deletion of Personal Data as set out in this DPA. |
| Nature and purpose | Ingestion, storage, classification of hours under configurable overtime rules, generation of invoices, and related back-office processing on Controller's behalf. |
| Categories of data subjects | Controller's employees and contingent workers (and, indirectly, Controller's end-clients to the extent identified on invoices). |
| Categories of Personal Data | Worker name and internal identifier; hours worked, dates and times of shifts, shift classifications; pay rate; assignment or end-client information. |
| Sensitive / special category data | None requested or required by the Service. Controller is responsible for not submitting government identifiers (e.g. Social Security Numbers), payment account numbers, or special categories of data. |
Processor will:
Processor will implement and maintain appropriate technical and organizational measures designed to protect Personal Data against unauthorized or unlawful processing and against accidental loss, destruction, damage, alteration, or disclosure. Current measures include those described in Annex II.
Controller acknowledges that the Service is designed to treat submitted timecard data as read-only for processing purposes, and that Personal Data may be stored without field-level encryption at rest, mitigated by infrastructure-level encryption, tenant isolation, and strict access controls.
Controller provides general authorization for Processor to engage Sub-processors to process Personal Data, subject to the conditions in this Section 6. The current list of Sub-processors is set out in Annex III.
Processor will: (a) impose data protection obligations on each Sub-processor that are no less protective than those in this DPA; and (b) remain liable to Controller for the acts and omissions of its Sub-processors to the same extent as if performed by Processor.
Processor will provide Controller with notice of the addition or replacement of any Sub-processor (for example, by updating Annex III or via the Service) before that Sub-processor begins processing Personal Data. If Controller has a reasonable, data-protection-related objection to a new Sub-processor, Controller may notify Processor in writing within fifteen (15) days. The parties will work together in good faith to resolve the objection. If they cannot, Controller may terminate the affected portion of the Service without penalty.
When the Service is converted from a free service to a paid service under Section 6 of the Terms of Service, Processor will engage a payment processor for the processing of Customer billing and payment information. That payment processor will be identified in Annex III in connection with — and at least thirty (30) days before the effective date stated in — the Conversion Notice described in Section 6.2 of the Terms of Service. The payment processor processes Customer billing information (as described in the Privacy Policy) and will not process Worker Data covered by this DPA. Processor will not route or disclose Worker Data to the payment processor.
Taking into account the nature of the processing, Processor will provide reasonable assistance to enable Controller to respond to requests from data subjects to exercise their rights under Data Protection Laws (such as access, correction, deletion, or portability). If Processor receives a data subject request that relates to Personal Data processed on Controller's behalf, Processor will, where lawfully permitted, refer the data subject to Controller and notify Controller without undue delay.
The export, download, and deletion controls then available in the Service (currently including per-batch and per-batch-group "Download All" archives, per-invoice PDF downloads, and tenant data purge) are designed to enable Controller to respond to data subject rights requests it receives in respect of Worker Data within the timelines required by applicable Data Protection Laws. If Controller requires additional assistance to respond to a specific data subject request, Processor will provide reasonable assistance as set out in this Section 7.
Processor will notify Controller without undue delay, and in any event within seventy-two (72) hours, after becoming aware of a Security Incident affecting Personal Data. The notification will include, to the extent then known, the nature and approximate scope of the Security Incident, the categories and approximate number of data subjects and records concerned, the likely consequences, and the measures taken or proposed to address the incident and mitigate its effects.
Processor will reasonably assist Controller with Controller's obligations to investigate, mitigate, and notify regulators or data subjects, as required by Data Protection Laws.
Processor will make available to Controller information reasonably necessary to demonstrate compliance with this DPA, including, where available, third-party audit reports or summaries.
No more than once per twelve (12) month period, and on at least thirty (30) days' prior written notice, Controller may submit a reasonable written audit questionnaire to Processor regarding Processor's processing of Personal Data. Any on-site audit must be coordinated with Processor in advance, conducted during normal business hours, conducted under reasonable confidentiality obligations, and not unreasonably interfere with Processor's operations. The cost of any on-site audit will be borne by Controller, except where the audit reveals material non-compliance attributable to Processor.
Personal Data is hosted and primarily processed on Microsoft Azure infrastructure located in the United States. Limited administrative and support access from Processor's premises in Croatia is restricted to authorized personnel under written confidentiality obligations and least-privilege access controls.
Consistent with the Scope and Exclusion of EU/UK Personal Data section of this DPA, no Personal Data subject to the GDPR, the UK GDPR, or equivalent laws is processed under this DPA, and no cross-border transfer mechanism under those laws is required or provided. If, despite the technical and contractual restrictions described in this DPA and in the Agreement, Controller submits Personal Data subject to those laws, Controller is solely responsible for any resulting non-compliance.
Controller may delete Personal Data through the functionality of the Service at any time. On termination or expiration of the Agreement, Processor will, at Controller's choice, return or delete Personal Data, except to the extent applicable law requires retention. Following termination, Personal Data remaining in active systems will be deleted within 30 days and will be removed from backups in the ordinary course of backup rotation, after which any retained copies will continue to be subject to the confidentiality and security obligations of this DPA until deleted.
Each party's liability under or in connection with this DPA, whether in contract, tort, or under any other theory of liability, is subject to the limitations and exclusions of liability set out in the Agreement, except to the extent such limitations would not be permitted by Data Protection Laws.
This DPA takes effect on the effective date of the Agreement and remains in effect until the Personal Data has been deleted or returned in accordance with Section 11. In the event of any conflict between this DPA and the Agreement with respect to the processing of Personal Data, this DPA prevails.
| Controller | The Customer identified in the Agreement. |
|---|---|
| Processor | 12PM d.o.o., a company organized under the laws of Croatia. |
| Subject matter and duration | As set out in Section 3 and the Agreement. |
| Nature and purpose of processing | Provision of the TimeCardCruncher service: ingestion of timecard data, classification of hours, generation of invoices, and storage of resulting records on Controller's behalf. |
| Types of Personal Data | Worker name and internal identifier; hours, shift dates and times, shift classifications; pay rate; assignment or end-client information. |
| Categories of data subjects | Workers (employees and contingent workers) of Controller; indirectly, Controller's end-client contacts to the extent identified on invoices. |
| Frequency of processing | Continuous, on a per-batch basis driven by Controller's submissions. |
Processor maintains the following measures, which it may update from time to time provided that the overall level of security is not materially diminished:
The following Sub-processors are authorized to process Personal Data in connection with the Service. Processor may update this list in accordance with Section 6.
| Sub-processor | Purpose and location |
|---|---|
| Microsoft Corporation (Microsoft Azure) | Cloud hosting, compute, storage (including Azure Blob Storage), Application Insights observability, and related platform services. Region: United States. |
| Twilio SendGrid | Transactional email delivery (account confirmation, password reset, system notifications). Region: United States. |
| Cloudflare, Inc. | Bot mitigation on registration / login / password-reset forms (Cloudflare Turnstile). Region: United States / global edge. |
| Syncfusion, Inc. | Document rendering library (DocIORenderer) used for invoice PDF generation. Operates in-process; no Personal Data is transmitted to Syncfusion infrastructure. |
Anticipated future sub-processor (informational; not currently engaged)
Processor does not currently engage a payment processor and no Customer billing or payment information is processed under this DPA today. When the Service is converted from a free service to a paid service under Section 6 of the Terms of Service, Processor will engage a PCI-DSS-compliant payment processor solely for the processing of Customer billing and payment information (as described in the Privacy Policy). The specific processor and its operating region will be identified in the Conversion Notice and added to the table above no later than thirty (30) days before the effective date of the conversion, on the terms of, and subject to the objection right set out in, Section 6 of this DPA. The payment processor will not process Worker Data covered by this DPA.