# Data Processing Agreement (Template)

**Between:** [CUSTOMER LEGAL NAME], with its registered address at
[CUSTOMER ADDRESS] ("**Controller**")

**And:** ByteTech OÜ, a company registered in Estonia, operating the
Tempora service ("**Processor**", "**Tempora**")

This Data Processing Agreement ("**DPA**") supplements the Terms of
Service (or other written agreement) between Controller and Processor
governing Controller's use of Tempora (the "**Agreement**") and applies
whenever Processor processes Personal Data on behalf of Controller in
connection with the Agreement.

**This is a template, not a signed or binding legal document.** It is
provided as a starting point for negotiation. Before signing, both
parties should have this reviewed by qualified legal counsel familiar
with applicable data protection law (including, where relevant, the
EU General Data Protection Regulation ("**GDPR**")).

---

## 1. Subject matter and duration

This DPA governs Processor's processing of Personal Data on
Controller's behalf for as long as Processor provides the Tempora
service to Controller under the Agreement, and for any period
thereafter during which Processor retains Personal Data in accordance
with Section 8.

## 2. Nature and purpose of processing

Processor processes Personal Data solely to provide the Tempora
service: employee scheduling, shift management, time and attendance
tracking, certification/compliance tracking, and (if enabled) client
billing based on hours worked.

## 3. Categories of data subjects

- Controller's employees, contractors, and other workers scheduled
  through Tempora.
- Controller's own personnel who use Tempora as administrators or
  managers.

## 4. Categories of personal data

- Identity and contact data: name, email address, phone number.
- Employment data: job title, department, work schedule, shift
  attendance/check-in records.
- Certification data: certification type, issue/expiry dates, and any
  uploaded supporting documents.
- Date of birth, where entered by Controller.
- Employee requests: time off, shift swaps, schedule changes and shift
  preferences, with any note the data subject adds.
- Location at check-in/check-out: the browser-reported location at
  that moment, only where Controller has configured a work-site
  location and the data subject's browser permits it.
- Sick-leave data: the dates of a reported sick leave, an optional
  note, the shifts affected, and -- only where Controller has enabled
  the requirement -- a medical certificate uploaded by the data
  subject.
- Account credentials (processed by Processor's authentication
  subprocessor; never stored in plain text).

**Special categories of data (GDPR Art. 9).** Sick-leave data and
medical certificates are data concerning health. Processor processes
them only to provide the sick-leave feature and only as instructed by
Controller. Controller is responsible for having a legal basis under
GDPR Art. 9(2) (typically Art. 9(2)(b), obligations in the field of
employment law) and for enabling the medical-certificate requirement
only where the law applicable to Controller permits it. Tempora never
asks for a diagnosis, and Controller should not require one through
Tempora. In addition to the measures in Section 5, Processor applies
these safeguards to health data:

- Access is limited to the data subject and Controller's owner and
  administrator accounts; it is never shown to other employees.
- It is never included in emails or push notifications.
- Medical certificate files are stored in private object storage,
  partitioned per Controller, and are only retrievable through
  individually authorized links that expire after a few minutes.
- Medical certificates and sick-leave notes are deleted when the data
  subject's personal data is erased, and when Controller's account is
  erased.

Apart from the above, Processor does not require or request special
categories of data or criminal-record data, and Controller should not
enter such data into Tempora.

## 5. Processor's obligations

Processor shall:

a. Process Personal Data only on documented instructions from
   Controller, including regarding transfers to a third country,
   unless required to do otherwise by applicable law.
b. Ensure persons authorized to process Personal Data have committed
   themselves to confidentiality.
c. Implement appropriate technical and organizational measures to
   ensure a level of security appropriate to the risk, as summarized
   in Processor's [Security & Trust page](https://www.YOUR-DOMAIN.example/trust)
   [REPLACE WITH ACTUAL PRODUCTION DOMAIN BEFORE USE].
d. Assist Controller, insofar as reasonably possible, in fulfilling
   Controller's obligations to respond to data subject rights
   requests (access, rectification, erasure, restriction, portability,
   objection).
e. Assist Controller in ensuring compliance with security,
   breach-notification, and data protection impact assessment
   obligations, taking into account the nature of processing and the
   information available to Processor.
f. At Controller's choice, delete or return all Personal Data after
   the end of the provision of services, and delete existing copies,
   except where applicable law requires retention (see Section 8).
g. Make available to Controller all information reasonably necessary
   to demonstrate compliance with this DPA, and allow for and
   contribute to audits, including inspections, conducted by
   Controller or an auditor mandated by Controller, subject to
   reasonable advance notice and confidentiality.

## 6. Subprocessors

Controller provides general authorization for Processor to engage the
following subprocessors, each limited to the stated purpose:

| Subprocessor | Purpose | Location |
|---|---|---|
| Supabase | Authentication, database hosting | See Supabase's published data residency options |
| Vercel | Application hosting, edge network | Global CDN / configurable region |
| Stripe | Payment processing, billing | Global |
| Resend | Transactional email delivery | Global |
| Cloudflare (R2) | Storage of uploaded certification files and sick-leave medical certificates | Global |
| Google (Gemini API) | AI assistant feature (only if enabled by Controller) | Global |
| Sentry | Error tracking | Global |

Processor shall notify Controller of any intended changes concerning
the addition or replacement of subprocessors, giving Controller the
opportunity to object on reasonable grounds.

## 7. International transfers

Where Personal Data is transferred outside the European Economic Area,
Processor shall ensure an appropriate transfer mechanism is in place
(such as the European Commission's Standard Contractual Clauses) with
the relevant subprocessor.

## 8. Data retention and deletion

Processor retains Personal Data for as long as Controller's account
remains active. Upon termination of the Agreement, Processor shall,
at Controller's election, delete or return Personal Data within a
commercially reasonable period, except for data Processor is required
to retain for legal, tax, or accounting purposes, which shall be
retained only for as long as legally required and then deleted.

## 9. Personal data breach notification

Processor shall notify Controller without undue delay after becoming
aware of a Personal Data breach affecting Controller's data, providing
the information reasonably available to enable Controller to meet any
of its own notification obligations.

## 10. Liability

Liability under this DPA is governed by the liability provisions of
the Agreement, unless otherwise required by applicable law.

## 11. Governing law

This DPA is governed by the laws of Estonia, without prejudice to any
mandatory data protection law of the jurisdiction in which Controller
or the relevant data subjects are located.

---

**Signed for and on behalf of Controller**

Name: ______________________  Title: ______________________

Date: ______________________  Signature: ______________________

**Signed for and on behalf of Processor (ByteTech OÜ)**

Name: ______________________  Title: ______________________

Date: ______________________  Signature: ______________________
