Data Processing Addendum.
1Applicability
This Addendum applies to Customer Personal Data processed by timeware UK Ltd in the course of providing the timeware® HRMS cloud service under the Agreement. In respect of that data, the Customer is the Controller and timeware UK Ltd is a Processor. Each party shall comply with its obligations under UK GDPR and the Data Protection Act 2018.
This Addendum applies to the timeware® HRMS cloud service. Customers running timeware® Professional on their own infrastructure remain covered by the on-premise addendum, under which customer data is hosted in the customer’s environment.
2Details of processing
| Subject matter | Provision of the timeware® HRMS cloud service: HR records, time and attendance, leave management, reporting, communication and related modules, together with the managed service. |
| Duration | The term of the Agreement, plus the return and deletion period in section 10. |
| Nature and purpose | Hosting, storage, processing and display of workforce data to deliver the service; support and managed-service activity on the Customer’s instruction; migration services from timeware® Professional where agreed. |
| Data subjects | The Customer’s employees, workers, contractors and other staff recorded in the system. |
| Categories of data | Identification and contact details; employment records (role, department, site, working patterns); clocking and attendance records; leave, absence and related records; timesheets and pay-affecting data; documents and photos the Customer stores; badge numbers and device credentials. |
| Special category data | Where the Customer enables them: absence records that reveal health information (for example sickness and return-to-work records), and biometric templates used for attendance verification on Suprema devices. The Customer is responsible for establishing a lawful basis for these. |
3Instructions
timeware UK Ltd shall process Customer Personal Data only on the Customer’s documented instructions: (a) as set out in the Agreement and as necessary to provide the service; (b) as necessary to comply with applicable law; and (c) as otherwise agreed in writing. We will inform the Customer if, in our opinion, an instruction infringes UK GDPR or other applicable data protection law.
4Confidentiality
All timeware UK Ltd personnel engaged in processing Customer Personal Data are bound by a strict duty of confidentiality. Support and managed-service staff access a customer tenant only for the purpose of the work requested.
5Security of processing
timeware UK Ltd implements appropriate technical and organisational measures, including:
- UK-only hosting on Microsoft Azure: primary region UK South (London), disaster recovery UK West (Cardiff). Every Azure service the platform uses is deployed exclusively in UK regions.
- One tenant per database: each customer’s data is held in its own dedicated Azure SQL database, never shared, with automated build-pipeline tests preventing cross-tenant access.
- Encryption at rest (AES-256 Transparent Data Encryption) and in transit (TLS 1.2 minimum); secrets held in Azure Key Vault with Managed Identity between services.
- Edge protection via Azure Front Door Premium with Web Application Firewall and DDoS protection; Microsoft Defender threat detection and malware scanning on SQL and Storage.
- Immutable, forensic audit logging (user actions, old and new values) with SQL-level WORM policy, and hard-delete prevention.
- 35-day point-in-time restore plus weekly, monthly and yearly backups, with geo-redundant storage replicated from UK South to UK West.
- Single Sign-On via Microsoft Entra ID, multi-factor authentication, account lockout and password policies, and per-user rate limiting.
- Certified management systems: ISO 27001, ISO 9001 and ISO 14001, plus Cyber Essentials Plus.
6Sub-processors
The Customer authorises the following sub-processors. timeware UK Ltd will give at least 30 days’ prior written notice of any intended change, allowing the Customer to object before the change takes effect, and will impose written terms on every sub-processor that meet the requirements of this Addendum.
| Microsoft Azure | Cloud hosting and platform services. All Customer Personal Data is stored in UK regions (UK South, UK West). |
| Sentry | Error diagnostics, hosted in the EU (Frankfurt). Configurable per tenant and can be disabled on request; diagnostic events are minimised and are not a store of workforce records. |
7International transfers
Customer Personal Data is stored in the United Kingdom. timeware UK Ltd will not transfer Customer Personal Data outside the UK, except to the EEA (covered by UK adequacy regulations) or where an Article 46 UK GDPR transfer mechanism, such as the UK International Data Transfer Agreement or Addendum, is in place with the recipient. The only routine non-UK processing is the optional EU-hosted error diagnostics in section 6.
8Assistance and data subject rights
Taking into account the nature of the processing, timeware UK Ltd will assist the Customer with appropriate technical and organisational measures in responding to data subject requests, and in meeting the Customer’s obligations relating to security of processing, breach notification and data protection impact assessments. The platform’s configurable retention, purging and GDPR controls support this directly.
9Personal data breach
timeware UK Ltd will notify the Customer without undue delay after becoming aware of a personal data breach affecting Customer Personal Data, and will provide the information reasonably required for the Customer to meet its own notification obligations, including, so far as known: the nature of the breach, the categories and approximate numbers of data subjects and records affected, the likely consequences, and the measures taken or proposed to address it.
10Return and deletion
On termination of the Agreement, timeware UK Ltd will, at the Customer’s choice, return Customer Personal Data as a full structured export: machine-readable files for every module (people, employment records, clockings, timesheets, leave and absence, audit history), together with the documents and photos stored in the service, produced by the managed service as part of offboarding.
Because each customer has its own dedicated database, timeware UK Ltd can additionally supply a complete copy of that database on request, by written agreement. The database schema and structures within such a copy remain timeware UK Ltd’s intellectual property and are supplied in confidence, for the Customer’s own archival and continuity purposes only.
Following return, timeware UK Ltd will delete Customer Personal Data from the live service, subject to backup cycles and any retention required by law. Data retention within the service is configurable by the Customer throughout the term, with scheduled purging of soft-deleted records.
11Audits
timeware UK Ltd will make available the information necessary to demonstrate compliance with this Addendum, and will allow for and contribute to audits and inspections conducted by the Customer or its appointed auditor, on reasonable notice. The IT security briefing at Security & Infrastructure is the standing summary of the measures in section 5.
12General
This Addendum forms part of the Agreement. In respect of the processing of Customer Personal Data, it takes precedence over any conflicting term of the Agreement. It may be varied only in writing signed by both parties. Data protection queries may be raised with timeware UK Ltd through the Customer’s account manager or the support desk.