Infrastructure and data transfer
Protecting your information and your privacy is very important to Timen. Our infrastructure partners Amazon and Heroku are certified under ISO 27001, SOC 2 and FISMA. The physical infrastructure is hosted and managed within Amazon's secure data centers in the United States and utilize the Amazon Web Service (AWS) technology. Amazon continually manages risk and undergoes recurring assessments to ensure compliance with industry standards. Personal data leaving the EEA, the UK or Switzerland is transferred under the EU-US Data Privacy Framework where the recipient is certified under it, and otherwise under the Standard Contractual Clauses. Every company that touches your data is named in Annex III of our data processing agreement.
Timen as the data processor
The client data you store in Timen is your data subject and you are considered the data controller for this personal data. Our data processing agreement is the written data processing contract required by GDPR Article 28. It is pre-signed and already in force, so there is nothing for you to sign, and it lists every subprocessor we use. Timen will only process your client data based on your instructions as the data controller.
Timen as the data controller
Timen acts as the data controller for the personal data we collect about our web app, mobile apps, and website users. We process data that is necessary for us to perform our contract with you (GDPR Article 6(1)(b)). We also process data to meet our obligations under the law (GDPR Article 6(1)(c)) - this involves financial data and information that we need to meet our accountability obligations under the GDPR. Timen is committed to respecting all your rights under the GDPR as the controller for your personal data.
Data portability and deletion
You can get your data out and delete it yourself, without asking us.
- Report export - download any report as CSV or PDF, for whatever date range, project, client or person you filter to.
- Invoice export - download an invoice as PDF or CSV, including the QuickBooks and Xero formats, or send it straight to your accounting system.
- API - read your time entries, projects, clients, tags and team members as JSON through the Timen API.
- Access and correction - your own profile details are editable on your profile page at any time.
- Record deletion - delete time entries, projects, clients, tags and invoices in the app, and remove people from your team.
- Account deletion - delete your whole account from the Timen iPhone or Android app, or through the API. Cancelling deletes all of your content immediately and irrevocably, so export anything you want to keep first. If you own a team with other members in it, hand ownership over before you delete, so your colleagues' work survives.
If someone asks you to exercise their GDPR rights over data held in your Timen account, you handle that request as the controller. If they come to us instead, we will point them to you and pass the request on rather than answering it ourselves.
Going forward
We continue to improve our procedures and systems. We'll monitor our GDPR compliance from privacy-related regulatory bodies and will adjust our systems accordingly if need. We'll update this page as necessary and if you have any question then you can reach us at support@gettimen.com.