GDPR Compliance

How TimeNova supports GDPR-aligned data handling

An overview of how TimeNova’s features and practices are designed to help EU/EEA customers meet their obligations under the General Data Protection Regulation (GDPR). This page describes practices, not a formal certification.

Last updated July 17, 2026

At a glance

Roles

For most workspace data, the customer is the controller and TimeNova is the processor.

Legal bases

Customers choose the appropriate legal basis for monitoring and data use.

Rights support

Product features and support workflows support access, export, and deletion requests.

Section 1

Introduction

The GDPR applies to processing personal data of individuals in the EU/EEA. There is no independent "GDPR certification" body; this page describes how TimeNova’s practices are designed to align with GDPR principles, alongside the Privacy Policy and Data Processing Agreement.

Section 2

Controller and processor roles

For most workplace and team-member data, the customer organization is the controller: it decides why TimeNova is used and how monitoring is configured. TimeNova acts as the processor, handling data according to customer instructions and the Data Processing Agreement.

Section 4

Data subject rights

GDPR recognizes a set of rights for individuals. TimeNova supports these in the following ways:

  • Access and portability: workspace data can be exported through product features.
  • Rectification: profile and workspace data can generally be corrected by an administrator.
  • Erasure and restriction: deletion workflows are available, subject to backup and legal-retention constraints.
  • Objection: organization-specific requests are typically routed to the relevant workspace administrator, since they control most of the underlying data.

Section 5

Security measures

Technical and organizational measures are described in more detail on the Security page.

Section 6

International transfers

Cross-border transfer mechanisms are described on the Data Transfer Compliance page.

Section 7

Breach notification

TimeNova aims to notify affected customers without undue delay after confirming a security incident involving personal data, consistent with the Data Processing Agreement and applicable law.

Section 8

Privacy inquiries and contact

Questions about GDPR-related practices, including requests to reach any appointed privacy contact, can be directed through official TimeNova support channels.

Section 9

Changes

TimeNova may update this page as GDPR guidance, product features, or sub-processors change.