Data Processing Agreement

Data processing terms for customer-controlled data

A B2B overview of how TimeNova processes personal data on behalf of customer organizations using the platform.

Last updated July 17, 2026

At a glance

Scope

Applies to customer-controlled personal data processed through TimeNova.

Instructions

Customer settings, product actions, and agreements guide processing.

Assistance

TimeNova supports customer requests through product and support workflows.

Section 1

Purpose and scope

This DPA applies when TimeNova processes personal data on behalf of a customer organization. It supplements the Terms of Service or other written agreement between the parties.

Section 2

Controller and processor roles

The customer is the controller or business for organization-controlled data. TimeNova is the processor or service provider that processes personal data according to customer instructions and the agreement.

Customer instructions include workspace configuration, user invitations, role assignments, monitoring policies, integration setup, support requests, and documented contract terms.

Section 3

Annex A: processing details

The processing details below summarize TimeNova product capabilities at a business level.

ItemDescription
Subject matterCloud time tracking, desktop-agent synchronization, screenshots, activity analytics, reports, billing administration, and team management.
Nature and purposeCollecting, hosting, organizing, securing, displaying, exporting, and deleting data needed to operate TimeNova.
DurationFor the term of the customer agreement and any post-termination retention, deletion, backup, or legal-obligation period.
Data subjectsCustomer admins, employees, contractors, client users, invited members, and support contacts.
Customer instructionsSettings and actions taken in the product, support instructions, integration actions, and signed agreement terms.

Section 4

Annex B: categories of data

Depending on enabled features, customer data may include these categories.

  • Identity and contact data such as names, emails, roles, and profile information.
  • Work data such as organizations, teams, projects, tasks, notes, approvals, goals, and schedules.
  • Tracking data such as time entries, live work status, activity levels, idle events, app/window context, and browser-domain context.
  • Screenshot data such as images, timestamps, display metadata, annotations, and delete status.
  • Security, audit, billing, notification, integration, support, and diagnostic information.

Section 5

Technical and organizational measures

TimeNova will maintain reasonable technical and organizational measures designed to protect personal data against unauthorized access, loss, misuse, and alteration.

  • Authentication, session protection, optional multi-factor authentication, and role-based access controls.
  • Organization-level data separation and project/client access controls.
  • Controlled screenshot access and policy-based monitoring settings.
  • Auditability and operational logging for accountability and troubleshooting.
  • Protected desktop-agent credential storage and secure sync behavior.

Section 6

Sub-processors

TimeNova may use sub-processors to provide hosting, storage, email, billing, support, diagnostics, and integration functionality. Customer-facing sub-processor details should be maintained through a private agreement, customer notice, or published list when available.

CategoryPurposeNotes
InfrastructureApplication hosting, compute, networking, data storage, and backups.Provider details may depend on deployment.
BillingSubscription management, checkout, invoicing, and payment workflows.Payment processors handle payment details under their own terms.
Email and supportTransactional messages, support communications, and service notifications.Used to operate and support TimeNova.
Customer-selected integrationsProject-management, webhook, or reporting workflows selected by the customer.Enabled only when configured by the customer.

Section 7

International transfers

Personal data may be processed in countries where TimeNova, its providers, or sub-processors operate. Where required, the parties will use an appropriate lawful transfer mechanism.

Section 8

Data-subject requests and incidents

Because the customer controls organization data, the customer is responsible for responding to data-subject requests. TimeNova will provide reasonable assistance through product features, exports, deletion workflows, and support.

TimeNova will notify affected customers without undue delay after confirming a security incident involving customer personal data, consistent with applicable law and the agreement.

Section 9

Audit, deletion, and return

TimeNova may provide security summaries, documentation, or reasonable questionnaire responses unless a signed agreement provides otherwise. On termination or request, customer data will be deleted or returned according to product capabilities, backup retention, legal obligations, and the agreement.

Section 10

Customer responsibilities

Customers must configure TimeNova lawfully, maintain administrator access controls, provide required notices, choose appropriate monitoring settings, avoid unnecessary sensitive data, and keep endpoint devices secure.

Continue reviewing

Related policies

Back to top