Parties and status of this agreement
This Data Processing Agreement (the "DPA") is entered into between:
Template OÜ, a private limited company registered in the Republic of Estonia under registry code 14110689, VAT identification number EE101937247, with its registered office at Tornimäe tn 7-79, 10145 Tallinn, Estonia, trading as Timen (the "Processor", "Timen", "we", "us");
and the Customer identified in the applicable Timen account (the "Controller", "Customer", "you"),
each a "Party" and together the "Parties".
How this DPA takes effect
1. This DPA is incorporated into and forms part of the Timen Terms of Service (the "Agreement"). It is pre-signed by Timen and takes effect automatically, without any further signature or notice, for every Customer that acts as a controller of personal data subject to Data Protection Law and that uses the Service on or after the effective date stated at the foot of this page.
2. If your procurement process requires an executed copy, write to support@gettimen.com and we will return a countersigned copy showing both parties' details, which you can print or save as a PDF. An executed copy records the same terms as this page and does not change them.
3. Order of precedence. In the event of any conflict between this DPA and the Terms of Service or the Privacy Policy, this DPA prevails in respect of the processing of Customer Personal Data. For the avoidance of doubt, this DPA governs Timen's role as processor of the data you place in the Service, and supersedes any statement elsewhere in the Agreement to the effect that Timen does not act as a processor of that data.
1. Definitions
1.1. "Data Protection Law" means all laws applicable to the processing of personal data under this DPA, including Regulation (EU) 2016/679 (the "GDPR"), the Estonian Personal Data Protection Act, the GDPR as incorporated into the law of the United Kingdom (the "UK GDPR") and the Swiss Federal Act on Data Protection (the "FADP"), in each case as applicable.
1.2. "Customer Personal Data" means personal data contained in Customer Data that Timen processes on the Customer's behalf in the course of providing the Service.
1.3. "Customer Data" means all content and data that the Customer or its End Users submit to, store in, or generate through the Service - including time entries and their descriptions, projects, clients and their contact and billing details, tags, invoices and their line items, reports, team member records and profile images.
1.4. "End User" means any individual the Customer authorises to use the Service under the Customer's account, including employees, contractors and clients.
1.5. "Service" means the Timen time tracking service made available at gettimen.com and its subdomains, together with the Timen mobile applications, browser extensions, API and MCP server.
1.6. "Subprocessor" means any processor engaged by Timen to process Customer Personal Data.
1.7. "SCCs" means the standard contractual clauses annexed to European Commission Implementing Decision (EU) 2021/914.
1.8. The terms "controller", "processor", "data subject", "personal data", "processing", "personal data breach" and "supervisory authority" have the meanings given to them in the GDPR.
2. Roles and scope
2.1. Customer as controller. As between the Parties, the Customer is the controller of Customer Personal Data and Timen is the processor. The Customer determines the purposes and means of the processing, decides what personal data is placed into the Service, and decides who may access it.
2.2. Timen as controller. Timen acts as a controller in its own right for account, billing, security and website data it collects about its customers and their users - for example account registration details, support payment records, authentication logs, support correspondence and website analytics. That processing is described in the Privacy Policy and is outside the scope of this DPA.
2.3. Subject matter and duration. The subject matter, duration, nature and purpose of the processing, the types of personal data and the categories of data subjects are set out in Annex I.
2.4. Special categories. The Service is a general-purpose time tracking tool and is not designed or intended for the processing of special categories of personal data within the meaning of Article 9 GDPR, or of personal data relating to criminal convictions and offences within the meaning of Article 10 GDPR. The Customer must not submit such data to the Service unless the Parties have agreed additional measures in writing.
3. Timen's obligations as processor
3.1. Documented instructions. Timen will process Customer Personal Data only on documented instructions from the Customer, including with regard to transfers to a third country. The Agreement, this DPA, and the Customer's use and configuration of the Service through its features and settings together constitute the Customer's complete and final documented instructions.
3.2. Timen will inform the Customer if, in its opinion, an instruction infringes Data Protection Law, unless prohibited from doing so by law. Timen is not obliged to carry out an instruction it considers unlawful.
3.3. Processing required by law. Where Timen is required by Union or Member State law to process Customer Personal Data other than on the Customer's instructions, Timen will inform the Customer of that legal requirement before processing, unless the law prohibits such information on important grounds of public interest.
3.4. Confidentiality. Timen will ensure that persons authorised to process Customer Personal Data are bound by an appropriate obligation of confidentiality, and will limit access to those personnel who need it to provide, secure or support the Service.
3.5. No monitoring of content. Timen does not routinely access, monitor or review the contents of Customer accounts. Access occurs only where reasonably necessary - for example to provide support the Customer has requested, to investigate a security incident, to prevent illegal or harmful activity, or to comply with a legal obligation.
3.6. No sale of data. Timen does not sell Customer Personal Data, does not share it for cross-context behavioural advertising, and does not use it to train machine learning or artificial intelligence models for its own purposes or for the benefit of any third party.
4. Security
4.1. Timen will implement and maintain appropriate technical and organisational measures to ensure a level of security appropriate to the risk, taking into account the state of the art, the costs of implementation, and the nature, scope, context and purposes of processing, as required by Article 32 GDPR. The measures in force are described in Annex II and further on our security page.
4.2. Timen may update the measures in Annex II from time to time, provided that no update materially reduces the overall level of security of the Service.
4.3. Customer responsibilities. The Customer is responsible for its own use of the Service, including safeguarding account credentials, assigning roles and permissions appropriately, managing which End Users can access which projects, deciding whether to publish an invoice at a public share link and when to revoke it, and promptly removing access for people who no longer need it.
5. Subprocessors
5.1. General authorisation. The Customer grants Timen general authorisation to engage Subprocessors for the purposes of providing the Service. The Subprocessors engaged as at the effective date of this DPA are listed in Annex III.
5.2. Terms imposed on Subprocessors. Timen will enter into a written agreement with each Subprocessor imposing data protection obligations that offer a level of protection substantially equivalent to those in this DPA, and will remain fully liable to the Customer for the performance of each Subprocessor's obligations.
5.3. Changes and notice. Timen will give the Customer at least thirty (30) days' notice before adding or replacing a Subprocessor. Notice will be given by updating Annex III on this page and by email to the account owner's registered address.
5.4. Objection. The Customer may object to a proposed new Subprocessor on reasonable data protection grounds by writing to support@gettimen.com within thirty (30) days of the notice. The Parties will discuss the objection in good faith. If Timen cannot make the Service reasonably available without the objected-to Subprocessor, the Customer may stop using the Service and delete its account. The Service is provided free of charge, so no refund of fees arises; a Customer that holds a monthly support subscription may cancel it at any time in the billing portal. This is the Customer's sole and exclusive remedy for such an objection.
5.5. Timen may replace a Subprocessor without advance notice where the change is required to address a serious security risk or where the existing Subprocessor ceases to provide the relevant service, in which case Timen will notify the Customer as soon as reasonably practicable.
6. International transfers
6.1. The Service is hosted in the United States. By using the Service the Customer instructs Timen to transfer Customer Personal Data to the United States and to the other locations identified in Annex III.
6.2. Where Customer Personal Data originating in the European Economic Area, the United Kingdom or Switzerland is transferred to a country that is not the subject of an adequacy decision, the transfer is made under one of the following, in this order of preference:
- the EU-U.S. Data Privacy Framework and its UK Extension and Swiss-U.S. counterpart, where the recipient is certified under that framework for the relevant category of data; or
- the SCCs, Module Two (controller to processor) where the Customer is a controller and Module Three (processor to processor) where the Customer is itself a processor, which are hereby incorporated into this DPA by reference and completed as set out in clause 6.3.
6.3. Where the SCCs apply:
- the Customer is the data exporter and Timen is the data importer;
- the optional docking clause in Clause 7 applies;
- in Clause 9, Option 2 (general written authorisation) applies, with the notice period set out in clause 5.3 above;
- in Clause 11, the optional independent dispute resolution provision does not apply;
- in Clause 17, the governing law is the law of the Republic of Estonia;
- in Clause 18(b), the forum for disputes is the courts of the Republic of Estonia;
- Annexes I, II and III to the SCCs are populated by Annex I, Annex II and Annex III of this DPA respectively.
6.4. UK transfers. Transfers subject to the UK GDPR are made under the International Data Transfer Addendum to the SCCs issued by the UK Information Commissioner, which is incorporated by reference and completed using the information in this DPA.
6.5. Swiss transfers. For transfers subject to the FADP, references in the SCCs to the GDPR are read as references to the FADP, the competent authority is the Swiss Federal Data Protection and Information Commissioner, and the term "Member State" is read so as not to deprive data subjects in Switzerland of the right to bring proceedings in their place of habitual residence.
7. Data subject rights
7.1. The Service gives the Customer direct control over Customer Personal Data. Through the Service the Customer can access, correct, export and delete data without needing to involve Timen, including exporting reports as CSV and PDF, exporting invoices as PDF and CSV, reading account data through the API, and deleting time entries, projects, clients, tags, invoices and whole accounts.
7.2. Taking into account the nature of the processing, Timen will assist the Customer by appropriate technical and organisational measures, insofar as this is possible, in fulfilling the Customer's obligation to respond to requests to exercise data subject rights under Chapter III of the GDPR.
7.3. If Timen receives a request from a data subject relating to Customer Personal Data, Timen will not respond to the request itself except to confirm that the request should be directed to the Customer, and will forward the request to the Customer without undue delay.
8. Personal data breaches
8.1. Timen will notify the Customer without undue delay, and in any event within seventy-two (72) hours, after becoming aware of a personal data breach affecting Customer Personal Data.
8.2. The notification will describe, to the extent known at the time and to the extent Timen is able to provide it: the nature of the breach including the categories and approximate number of data subjects and records concerned; the likely consequences; the measures taken or proposed to address the breach and mitigate its effects; and a contact point for further information. Where the information cannot be provided at once, it will be provided in phases without further undue delay.
8.3. Timen will take reasonable steps to contain and remediate the breach, and will cooperate with the Customer and provide reasonable assistance with any notification the Customer must make to a supervisory authority or to data subjects.
8.4. A notification under this clause is not an acknowledgement by Timen of fault or liability.
9. Impact assessments and prior consultation
9.1. Taking into account the nature of the processing and the information available to it, Timen will provide the Customer with reasonable assistance with data protection impact assessments under Article 35 GDPR and with prior consultation of supervisory authorities under Article 36 GDPR, in each case solely in relation to the processing of Customer Personal Data by Timen.
10. Return and deletion of data
10.1. The Customer may export Customer Data at any time during the term of the Agreement using the export features of the Service and the API.
10.2. Cancellation deletes your data immediately. As set out in the Terms of Service, cancelling the Service results in the immediate and irrevocable deletion of Customer Content. The Customer should export any data it wishes to keep before cancelling. Timen does not offer a post-termination retrieval window and cannot recover data once an account has been cancelled. Deleting an individual account also deletes any team in which that person is the only remaining member; a team that still has other members survives, and Timen will ask an owner to transfer ownership first rather than destroy their colleagues' work.
10.3. Residual copies of Customer Personal Data may persist in routine encrypted backups for a limited period after deletion, and are overwritten in the ordinary course of the backup rotation. Until they are overwritten, Timen continues to protect such copies in accordance with this DPA and does not process them for any purpose other than restoration and business continuity.
10.4. Timen may retain Customer Personal Data to the extent required by Union or Member State law, and in that case will continue to protect it and will process it only to the extent and for the period required by that law.
11. Audits and information
11.1. Timen will make available to the Customer all information reasonably necessary to demonstrate compliance with Article 28 GDPR, including this DPA, the information published on our security page, and the compliance certifications and reports of its infrastructure Subprocessors.
11.2. Timen will allow for and contribute to audits, including inspections, conducted by the Customer or another auditor mandated by the Customer. Such audits are subject to the following, to the extent permitted by Data Protection Law:
- the Customer gives at least thirty (30) days' written notice;
- audits take place during normal business hours, no more than once in any twelve (12) month period, except where required by a supervisory authority or following a personal data breach affecting the Customer;
- the auditor is not a competitor of Timen and is bound by confidentiality obligations;
- the audit is limited to Timen's own systems and processes, does not extend to the data centres or systems of Subprocessors, and does not grant access to the data of any other customer;
- the Customer bears its own costs and reimburses Timen's reasonable costs for time spent beyond the provision of existing documentation.
11.3. The Parties agree that the information and documentation described in clause 11.1 will ordinarily satisfy the Customer's audit rights, and that an on-site inspection will be exercised only where that information is demonstrably insufficient.
12. Customer obligations
12.1. The Customer warrants that it has a valid legal basis for the processing of Customer Personal Data, that it has provided all notices and obtained all consents required under Data Protection Law, and that its instructions to Timen comply with Data Protection Law.
12.2. The Customer is responsible for the accuracy, quality and legality of Customer Personal Data and the means by which it acquired it.
12.3. The Customer must not submit to the Service any personal data whose sensitivity or regulatory status exceeds what a general-purpose time tracking tool is designed to handle, including the categories described in clause 2.4.
12.4. Where the Customer is itself a processor acting on behalf of a third-party controller, the Customer warrants that it has that controller's authorisation to engage Timen as a subprocessor on the terms of this DPA.
13. Term, liability and governing law
13.1. Term. This DPA takes effect on the date the Customer first uses the Service on or after the effective date below, and continues for as long as Timen processes Customer Personal Data. Clauses that by their nature should survive termination do so.
13.2. Liability. Each Party's liability under or in connection with this DPA is subject to the exclusions and limitations of liability set out in the Agreement. Nothing in this DPA limits any liability that cannot be limited under Data Protection Law, including a data subject's rights under Articles 79 and 82 GDPR.
13.3. Changes. Timen may update this DPA where necessary to reflect a change in Data Protection Law, in the Subprocessors it engages, or in the Service. Timen will notify the Customer of material changes by email to the account owner's registered address and by updating the effective date below.
13.4. Severability. If any provision of this DPA is held invalid or unenforceable, the remainder continues in full force and effect.
13.5. Governing law and jurisdiction. This DPA is governed by Estonian law and disputes are resolved as set out in the Terms of Service, save that where the SCCs apply, clauses 17 and 18 of the SCCs prevail in respect of the matters they govern.
13.6. Contact. Data protection enquiries, including subprocessor objections and audit requests, should be sent to support@gettimen.com.
Annex I - Details of the processing
This annex populates Annex I to the SCCs where those clauses apply.
A. List of Parties
Data exporter: the Customer, as identified in its Timen account. Role: controller (or processor, where the Customer acts on behalf of a third-party controller). Contact: the account owner's registered email address. Activities relevant to the transfer: use of the Service for time tracking.
Data importer: Template OÜ (trading as Timen), Tornimäe tn 7-79, 10145 Tallinn, Estonia. Role: processor. Contact: support@gettimen.com. Activities relevant to the transfer: provision, hosting, support and maintenance of the Service.
B. Description of the transfer
| Subject matter | Provision of the Timen time tracking service to the Customer. |
|---|---|
| Duration | The term of the Agreement, plus the limited period described in clause 10.3 for backup rotation. |
| Nature and purpose | Hosting, storage, transmission, indexing, search, backup, reporting, invoicing, display and other processing necessary to make the Service available to the Customer and its End Users, together with support, security monitoring and troubleshooting at the Customer's request. |
| Categories of data subjects | The Customer's End Users (employees, contractors and administrators); the Customer's own clients and contacts where the Customer records them in the Service; any other individual the Customer or its End Users choose to reference in Customer Data. |
| Categories of personal data |
The content categories are determined by the Customer, not by Timen. |
| Sensitive data | None is intended or required. See clause 2.4. |
| Frequency of transfer | Continuous, for the duration of the Agreement. |
| Retention | For the term of the Agreement. Deleted immediately on cancellation, subject to clauses 10.2 to 10.4. |
| Onward transfers | To the Subprocessors listed in Annex III, for the purposes and periods stated there. |
C. Competent supervisory authority
Where the SCCs apply and the data exporter is established in the European Union, the competent supervisory authority is that of the Member State in which the data exporter is established. Where the data exporter is not established in the EU but has appointed a representative under Article 27 GDPR, it is the authority of the Member State in which the representative is established. Timen's own lead supervisory authority is the Estonian Data Protection Inspectorate (Andmekaitse Inspektsioon).
Annex II - Technical and organisational measures
This annex populates Annex II to the SCCs where those clauses apply. Further detail is published on our security page.
| Measure | Description |
|---|---|
| Encryption in transit | All access to the Service is over HTTPS with TLS. HTTP requests are redirected to HTTPS and HSTS is enforced. Connections to the database and to internal services are encrypted. |
| Encryption at rest | Database storage, files and backups are encrypted at rest by the infrastructure providers. Passwords are stored as salted bcrypt hashes and are never stored or transmitted in plain text. Access and refresh tokens for connected accounting and import providers are encrypted at the application layer in addition to the storage encryption. |
| Access control - Customer | Per-user accounts with individual credentials; role-based permissions at team level with per-member overrides; granular control over which End Users can access which projects; single sign-on via Google and Apple; session management and sign-out; optional timesheet locking to close a past period to edits. |
| Access control - Timen personnel | Access to production systems is limited to the small number of personnel who require it, is protected by multi-factor authentication, and is granted on a least-privilege basis. Access is revoked promptly when no longer required. Personnel are bound by confidentiality obligations. |
| Tenant separation | Customer accounts are logically separated at the application layer. Every request is scoped to the authenticated user's team and to that user's project permissions. |
| Physical security | Hosted in Amazon Web Services data centres, which operate multi-layered physical access control including perimeter controls, video surveillance, intrusion detection and multi-factor access for staff, with all access logged and audited. Timen personnel have no physical access to the hardware. |
| Certifications of infrastructure providers | The data centres underlying the Service are accredited under ISO 27001, SOC 1 and SOC 2 / SSAE 16 / ISAE 3402, PCI DSS Level 1, FISMA Moderate and Sarbanes-Oxley. |
| Resilience and availability | The platform maintains redundancy to avoid single points of failure, replaces failed components automatically, and operates across multiple data centres. In an outage, applications and databases are redeployed from current system images and restored from backups. |
| Backup and restoration | Continuous protection through write-ahead logging, with logs shipped to multi-data-centre, high-durability storage. Databases can be recovered to within seconds of their last known state. Backups are encrypted and access-controlled. |
| Logging and monitoring | Application error monitoring and performance monitoring. Authentication events are recorded, including sign-in time and originating IP address. |
| Secure development | Framework-level protection against common web vulnerabilities including SQL injection, cross-site scripting, cross-site request forgery and clickjacking. Static security analysis and dependency vulnerability auditing run as part of the build. Dependencies are kept current and security updates applied. Changes are reviewed before release. |
| Third-party token handling | A token for an accounting destination is obtained for a single export and revoked at the provider once that export completes, so no accounting credential is retained between exports. Access to the Service by an AI assistant runs through OAuth 2.1 as the End User who authorised it, is bound by that End User's existing permissions, and can be revoked by them at any time. |
| Abuse prevention | Per-IP and per-user rate limiting on the API, on sign-in and on signup; input sanitisation on user-supplied content. |
| Data minimisation and deletion | Self-service export of reports as CSV and PDF, of invoices as PDF and CSV, and of account data through the API; self-service deletion of records and of the whole account; immediate deletion of Customer Content on cancellation. |
| Subprocessor governance | Written data protection terms with each Subprocessor, assessment before engagement, and the published list and change-notification process in clause 5. |
Annex III - Subprocessors
This annex populates Annex III to the SCCs where those clauses apply. It lists the Subprocessors that may process Customer Personal Data. Changes are notified in accordance with clause 5.3.
Infrastructure
| Subprocessor | Purpose | Data processed | Location |
|---|---|---|---|
| Salesforce, Inc. Heroku |
Application hosting platform and managed PostgreSQL database | All Customer Personal Data | United States |
| Amazon Web Services, Inc. | Underlying data centres; outbound email delivery through Amazon SES; content delivery network for static assets | All Customer Personal Data | United States |
Service features
| Subprocessor | Purpose | Data processed | Location |
|---|---|---|---|
| FreeIPAPI | Resolving a sign-in IP address to an approximate country, region and city, so that a person can recognise their own sessions | IP address only. No account identifier, name or email address is sent | Germany (EU) |
| Stripe, Inc. | Payment processing and subscription management for voluntary support payments | Billing contact name, email address, billing address and transaction records. Card details are collected and held by Stripe; Timen never receives or stores them | United States |
Operations and support
| Subprocessor | Purpose | Data processed | Location |
|---|---|---|---|
| SmartBear Software Bugsnag |
Application error and crash monitoring | Diagnostic data attached to errors: user identifier and email address, request path and parameters, browser and device information, stack traces | United States |
| Scout Monitoring Scout APM |
Application performance monitoring | Request metadata, timing traces and database query patterns; incidental identifiers appearing in request paths | United States |
Not subprocessors: integrations you switch on
Timen offers optional integrations that send data to, or receive data from, third-party services. These operate only when the Customer or an End User connects them, and the data flow is an instruction given by the Customer to that third party, not a subprocessing arrangement by Timen. The Customer is responsible for its own relationship with those providers, and their terms and privacy policies govern what they do with the data.
Such integrations currently include:
- Sign-in: Google, Apple
- Accounting and invoicing: QuickBooks Online, Xero, FreshBooks, Wave. An invoice is sent only when the Customer picks that destination from the Export menu, and the connection is reauthorised each time
- Import sources: Clockify, Harvest, Toggl, Timely, Hubstaff, Jibble. These are read on a schedule while the Customer keeps the connection open
- AI assistants: ChatGPT, Claude and other assistants connected to the Timen MCP server at mcp.gettimen.com. The connection acts as the End User who authorised it and is bound by that End User's existing permissions. What the assistant sends and what Timen returns is set out in the Privacy Policy
The Timen browser extension is not an integration in this sense and sends nothing to any third party. It runs only on the websites an End User has explicitly enabled, reads the page only to describe the work being timed, and communicates only with Timen's own servers. This is described in full in the Privacy Policy.
Timen as controller
Timen also uses vendors for processing in which it acts as a controller in its own right rather than as the Customer's processor - for example website and product analytics (Google Analytics) and first-touch marketing attribution. These are not subprocessors of Customer Personal Data and are outside the scope of this DPA. They are covered by the Privacy Policy.
Effective and last revised: September 10, 2026.