Chrontic

Data Processing Agreement

Chrontic Web Application — Art. 28 GDPR

Last Updated: September 7, 2026

Incorporation

This Data Processing Agreement ("DPA") forms part of and is incorporated into the Chrontic Terms of Service. It applies automatically when your company creates a Chrontic account and uses the Service to process personal data, without requiring a separately signed copy. It reflects the requirements of Art. 28 GDPR for the processing Chrontic UG (haftungsbeschränkt) ("Processor", "we") carries out on behalf of your company ("Controller", "you").

1. Subject Matter & Duration

Chrontic processes personal data on your behalf for as long as your company maintains an active Chrontic account, plus any retention period described in Section 8 (Deletion & Return of Data) after the account is closed.

2. Nature & Purpose of Processing

Processing consists of storing, organizing, and displaying employee time-tracking, project, and leave data so that you can manage employee time, projects, and productivity. Where you connect optional integrations (Jira, Outlook, Tempo), processing also includes reading or writing ticket, calendar, or worklog data from those services on your instruction.

3. Categories of Data Subjects & Personal Data

  • Data subjects: your employees, contractors, and admin users
  • Personal data: name, email, employment data (employee ID, cost center, payroll code, hire date, salary/hourly rate where entered), time entries, leave requests and balances, organizational unit, job title, and any data synced from connected integrations

See our Privacy Policy for the full description of data collected.

4. Processor Obligations

Chrontic will:

  • process personal data only on your documented instructions, including regarding international transfers, unless required otherwise by EU or member-state law;
  • ensure persons authorized to process the data are bound by confidentiality;
  • inform you immediately if, in our opinion, an instruction infringes the GDPR or other applicable EU or member-state data protection law;
  • implement the technical and organizational security measures set out in Annex 1 to this DPA, in accordance with Art. 32 GDPR;
  • engage sub-processors only as authorized under Section 5;
  • assist you, taking into account the nature of processing, in responding to data subject requests (access, rectification, erasure, restriction, portability, and objection);
  • assist you with your obligations regarding security, breach notification, and data protection impact assessments under Art. 32–36 GDPR;
  • delete or return personal data at the end of the provision of services, as described in Section 8; and
  • make available information reasonably necessary to demonstrate compliance with this DPA, and allow for audits, including inspections, conducted by you or an auditor you mandate, subject to at least 30 days' written notice and confidentiality; such audits may be conducted no more than once per calendar year, except following a personal data breach affecting your data, in which case this limit does not apply.

5. Sub-processors

You give Chrontic a general written authorization to engage the sub-processors listed on our Subprocessors page. Sub-processors are bound by contract to data protection obligations consistent with this DPA, and we remain fully liable to you for their performance.

Before we add or replace a sub-processor, we will announce the change on that page at least 30 days in advance, and will notify you by email if you have asked us to. Within those 30 days you may object to the change on reasonable data protection grounds. If you object and we cannot offer you a commercially reasonable alternative, you may terminate the affected part of the Service for cause, with a pro-rata refund of any fees paid for the unused remainder of your billing period.

6. International Transfers

Chrontic's own infrastructure is hosted in Germany, within the EU. Where a sub-processor transfers personal data outside the EU/EEA, that transfer is governed by the Standard Contractual Clauses adopted under European Commission Implementing Decision (EU) 2021/914 (Module 2: Controller-to-Processor, or Module 3: Processor-to-Processor, as applicable to that sub-processor's role), or another transfer mechanism recognized under Art. 44–49 GDPR.

7. Personal Data Breach Notification

Chrontic will notify you without undue delay after becoming aware of a personal data breach affecting your data, and provide information reasonably available to help you meet your own notification obligations under Art. 33/34 GDPR.

8. Deletion & Return of Data

At the end of the provision of services, you choose whether we delete the personal data or return it to you. Tell us which before closing the account:

  • Return: the admin export feature produces a machine-readable export of a user's profile, time entries, leave requests, and leave balances. Export the users you need before closing the account.
  • Deletion: closing the account anonymizes every user in the organization — names, email addresses, and other identifying profile fields are irreversibly scrubbed, and stored integration credentials are deleted.

Time entry and leave records are not deleted together with the identifying data: they are retained in pseudonymized form, no longer attributable to a named individual without additional information. We retain them on your documented instruction, because as the employer you are typically subject to statutory retention duties for wage and working-time records (for example §257 HGB, §147 AO, and §41 EStG, which run for six to ten years from the end of the relevant calendar year). If you are not subject to such duties, or they have expired, instruct us in writing at support@chrontic.com and we will delete those records too.

We do not currently operate an automated schedule that purges pseudonymized records once their retention period ends. Deletion beyond what is described above happens on your written instruction.

9. Liability & Governing Law

Liability under this DPA follows the limitation of liability set out in our Terms of Service. This DPA is governed by the laws of Germany, with the courts of Berlin having exclusive jurisdiction, except where mandatory law provides otherwise.

Annex 1 — Technical and Organizational Measures (Art. 32 GDPR)

We review these measures periodically and may update them, provided the level of protection is not reduced.

Pseudonymization and encryption

  • All traffic between users and the Service is encrypted in transit (HTTPS/TLS); plain HTTP requests are redirected.
  • Passwords are stored as bcrypt hashes and are never stored or recoverable in clear text.
  • Database backups are compressed and encrypted (GPG) before storage.
  • Account closure irreversibly anonymizes identifying data, leaving time and leave records pseudonymized.

Confidentiality and access control

  • Multi-tenant isolation: every data query is scoped to the requesting account's own organization.
  • A permission model based on named roles, checked per action and per record, governs which employees' data a given user can see or change.
  • Authenticated API access only; all endpoints require a valid token.
  • An audit log records administrative access to another identified user's personal data — export, anonymization, account closure, and edits to another user's profile.
  • Production server access is restricted to named administrators using SSH key authentication behind a firewall.

Availability and resilience

  • Daily automated database backups with defined retention, plus provider-level disk snapshots.
  • A documented restore procedure for the production database.

Evaluation and review

  • Automated backend and frontend test suites run against every change, including tests that assert access-control and tenant-isolation restrictions hold.
  • Hosting and data storage take place in Germany, within the EU (see Subprocessors).

Company Information

Chrontic UG (haftungsbeschränkt)
Kolonnenstraße 8, 10827 Berlin, Germany
Managing Director: Abdullah Sohrab Khan
Email: support@chrontic.com