This Privacy Policy explains how 12PM d.o.o., a company organized under the laws of Croatia ("TimeCardCruncher", "we", "us"), collects, uses, and shares personal information in connection with the TimeCardCruncher service (the "Service"), our website, and related communications.
TimeCardCruncher provides timecard processing, overtime classification, and invoice generation services to business customers (typically staffing agencies). This Policy applies to two distinct categories of personal information: (1) information about our Customers and the individuals using their accounts ("Customer Account Data") and (2) information about Customer's workers contained in timecard records that Customer submits to the Service ("Worker Data"). Different parts of this Policy apply to each.
The Service is designed for, and offered only to, businesses established and operating in the United States, and is built around U.S. payroll, overtime, and invoicing rules. The Service is not designed or intended for use by persons or businesses located in the European Economic Area, the United Kingdom, or Switzerland, or for the processing of personal data subject to the EU General Data Protection Regulation ("GDPR"), the UK GDPR, or equivalent laws. Access to the Service is technically restricted by network-level controls and is not available from the European Economic Area, the United Kingdom, or Switzerland. Public legal pages such as this Privacy Policy, our Terms of Service, our Data Processing Addendum, and our Impressum remain accessible globally for transparency purposes.
This Privacy Policy is written for that U.S. context. If a customer registers for or uses the Service in breach of these geographic restrictions (as set out in our Terms of Service), we may suspend or terminate the account and delete the related data. Customers are solely responsible for ensuring that their use of the Service complies with applicable law in their own jurisdiction.
For Customer Account Data (for example, the name, email, and login credentials of a Customer's administrator), we act as a controller and process that information for our own purposes as described in this Policy.
For Worker Data (for example, a worker's name, hours worked, and pay rate submitted by Customer), we act as a service provider / processor on behalf of the Customer. The Customer is the controller of Worker Data and is responsible for providing notice to and, where required, obtaining consent from those workers. Our processing of Worker Data is governed by our Data Processing Addendum (the "DPA") and by these terms only to the extent consistent with the DPA.
When you create an account, contact us, or use the Service, we may collect:
When Customer uses the Service, Customer submits timecard records to us. These records typically contain:
We do not require, and do not intentionally collect, government identifiers (such as Social Security Numbers), payment account numbers for workers, or special categories of data (such as health, biometric, or union membership data) as part of Worker Data. Customer is responsible for not submitting such information to the Service.
The Service is not designed or intended to receive, store, or process Protected Health Information ("PHI") as defined under the Health Insurance Portability and Accountability Act ("HIPAA"). Customer agrees not to submit PHI to the Service. We are not a HIPAA Business Associate and have not entered into a Business Associate Agreement with Customer. If Customer requires HIPAA-compliant processing, Customer must not use the Service for that data.
Our website and Service use cookies and similar technologies to operate the Service, remember preferences, and measure traffic. Where required by law, we will request your consent before setting non-essential cookies and provide controls for managing them.
We use Customer Account Data to:
We use Worker Data only to provide the Service to the Customer that submitted it — that is, to classify hours, calculate pay-related figures, generate invoices, and store the resulting records on Customer's behalf — and to comply with law. We do not use Worker Data to train machine learning models, build profiles for our own commercial purposes, or sell or rent it.
Where data protection laws require a legal basis for processing Customer Account Data, we rely on:
We share information only as follows:
We do not sell personal information, and we do not "share" personal information for cross-context behavioral advertising, as those terms are defined under the California Consumer Privacy Act ("CCPA") and similar U.S. state laws.
We host the Service on Microsoft Azure data centers located in the United States. Personal information is stored on those U.S.-based systems and is not stored on systems located outside the United States. Because we are established outside the United States, our personnel in Croatia may access the Service in the course of operating it; such access is limited to authorized personnel under written confidentiality obligations and least-privilege access controls, and is restricted to administrative, support, and security purposes.
The Service is offered only to U.S.-based businesses, and the DPA reflects that scope: no cross-border transfer mechanism under EU, UK, or Swiss data protection law is required or provided. See the DPA for details.
We maintain administrative, technical, and organizational measures designed to protect personal information against unauthorized access, alteration, disclosure, or destruction. These include access controls, tenant isolation, audit logging, encryption in transit, and least-privilege access for personnel.
Worker Data submitted to the Service is treated as read-only for processing purposes: it is ingested, used to compute classification and invoice outputs, and otherwise not modified or used for other purposes. Note that some Worker Data fields may be stored without field-level encryption at rest; we mitigate this with infrastructure-level encryption, strict access controls, and tenant isolation. No system can be guaranteed to be completely secure, and we cannot guarantee absolute security.
We retain Customer Account Data for as long as the account is active and for a reasonable period afterward to comply with legal obligations, resolve disputes, and enforce agreements.
Worker Data is retained on Customer's behalf for as long as Customer instructs. Customers may delete Worker Data at any time through the Service. On deletion, we remove the data from active systems and from backups in accordance with our deletion and backup rotation practices, typically within 30 days. On termination of a Customer's account, we will delete Worker Data in accordance with the DPA.
During any Conversion Notice period (Terms of Service, Section 6) and during any post-conversion Lockout grace period (Terms of Service, Section 6.4), Customer's in-product data-export, download, and account-cancellation controls then available in the Service remain accessible so that Customer can export or delete data before the account is terminated.
Depending on where you live, you may have rights with respect to personal information about you, including the right to access, correct, delete, or obtain a copy of that information, and to object to or restrict certain processing. To exercise these rights, contact us at [email protected]. We will respond within the time required by applicable law.
If your information was provided to us as Worker Data by a Customer (for example, your employer or staffing agency), please direct your request to that Customer in the first instance. We will assist the Customer in responding as required by the DPA.
Depending on the United States state in which Customer's authorized users or other individuals reside, additional privacy rights may apply. The following summary covers the principal state privacy laws in effect as of the date of this Policy. Where state law provides rights, those rights apply to Customer Account Data that we hold as a controller. For Worker Data that we hold as a processor on behalf of Customer, individuals should direct requests to Customer in the first instance, and we will assist Customer in responding as required by the DPA.
California (CCPA, as amended by CPRA): Right to know, right to delete, right to correct, right to opt out of sale or sharing, right to limit use of sensitive personal information, right to non-discrimination, right to data portability.
Virginia (VCDPA), Colorado (CPA), Connecticut (CTDPA), Utah (UCPA), Texas (TDPSA), Oregon (OCPA), Montana (MCDPA), New Hampshire (NHPA), Delaware (DPDPA), Iowa (ICDPA), Tennessee (TIPA), Indiana (INCDPA): Rights generally include access, correction, deletion, portability, and opt-out of targeted advertising, sale, or profiling, subject to the specifics and exceptions of each statute.
We do not sell personal information and we do not "share" personal information for cross-context behavioral advertising as those terms are defined under any of the above state laws. We do not engage in profiling that produces legal or similarly significant effects. We do not knowingly process the personal information of individuals under sixteen (16) years of age.
To exercise rights under any of these laws, contact us at [email protected]. We will verify the request as required by applicable law and respond within the period required by the applicable statute. If we deny a request, we will inform you of the basis for the denial and your appeal rights, where applicable.
Where this Policy is updated to reflect the collection of billing or payment-related personal information following conversion of the Service to a paid plan under Section 6 of the Terms of Service, the updated Policy will identify the categories of personal information collected (including any that may be characterized as "sensitive personal information" under California law and analogous categories under other state privacy laws), the categories of recipients (including the payment processor), and the retention periods applicable to each category, and Processor will provide a Notice at Collection at or before the point at which any such information is collected.
The Service is not directed to children under 16, and we do not knowingly collect personal information from children. If you believe a child has provided us with personal information, please contact us so we can take appropriate action.
We may update this Policy from time to time. We will post the updated Policy with a new "Last updated" date and, for material changes, will provide reasonable advance notice (for example, by email or in-product notice).
Where a change to this Policy is occasioned by the conversion of the Service from a free service to a paid service under Section 6 of our Terms of Service — including, in particular, the identification of any new payment-processor sub-processor in the DPA — we will communicate that change together with, and on the same minimum 30-day notice period as, the Conversion Notice described in Section 6.2 of the Terms.
If you have questions or complaints about this Policy or our handling of personal information, please contact us at: