ChronticChrontic Web Application — Art. 28 GDPR
Last Updated: September 7, 2026
This Data Processing Agreement ("DPA") forms part of and is incorporated into the Chrontic Terms of Service. It applies automatically when your company creates a Chrontic account and uses the Service to process personal data, without requiring a separately signed copy. It reflects the requirements of Art. 28 GDPR for the processing Chrontic UG (haftungsbeschränkt) ("Processor", "we") carries out on behalf of your company ("Controller", "you").
Chrontic processes personal data on your behalf for as long as your company maintains an active Chrontic account, plus any retention period described in Section 8 (Deletion & Return of Data) after the account is closed.
Processing consists of storing, organizing, and displaying employee time-tracking, project, and leave data so that you can manage employee time, projects, and productivity. Where you connect optional integrations (Jira, Outlook, Tempo), processing also includes reading or writing ticket, calendar, or worklog data from those services on your instruction.
See our Privacy Policy for the full description of data collected.
Chrontic will:
You give Chrontic a general written authorization to engage the sub-processors listed on our Subprocessors page. Sub-processors are bound by contract to data protection obligations consistent with this DPA, and we remain fully liable to you for their performance.
Before we add or replace a sub-processor, we will announce the change on that page at least 30 days in advance, and will notify you by email if you have asked us to. Within those 30 days you may object to the change on reasonable data protection grounds. If you object and we cannot offer you a commercially reasonable alternative, you may terminate the affected part of the Service for cause, with a pro-rata refund of any fees paid for the unused remainder of your billing period.
Chrontic's own infrastructure is hosted in Germany, within the EU. Where a sub-processor transfers personal data outside the EU/EEA, that transfer is governed by the Standard Contractual Clauses adopted under European Commission Implementing Decision (EU) 2021/914 (Module 2: Controller-to-Processor, or Module 3: Processor-to-Processor, as applicable to that sub-processor's role), or another transfer mechanism recognized under Art. 44–49 GDPR.
Chrontic will notify you without undue delay after becoming aware of a personal data breach affecting your data, and provide information reasonably available to help you meet your own notification obligations under Art. 33/34 GDPR.
At the end of the provision of services, you choose whether we delete the personal data or return it to you. Tell us which before closing the account:
Time entry and leave records are not deleted together with the identifying data: they are retained in pseudonymized form, no longer attributable to a named individual without additional information. We retain them on your documented instruction, because as the employer you are typically subject to statutory retention duties for wage and working-time records (for example §257 HGB, §147 AO, and §41 EStG, which run for six to ten years from the end of the relevant calendar year). If you are not subject to such duties, or they have expired, instruct us in writing at support@chrontic.com and we will delete those records too.
We do not currently operate an automated schedule that purges pseudonymized records once their retention period ends. Deletion beyond what is described above happens on your written instruction.
Liability under this DPA follows the limitation of liability set out in our Terms of Service. This DPA is governed by the laws of Germany, with the courts of Berlin having exclusive jurisdiction, except where mandatory law provides otherwise.
We review these measures periodically and may update them, provided the level of protection is not reduced.
Chrontic UG (haftungsbeschränkt)
Kolonnenstraße 8, 10827 Berlin, Germany
Managing Director: Abdullah Sohrab Khan
Email: support@chrontic.com