Chrontic

Data Processing Agreement

Chrontic Web Application — Art. 28 GDPR

Last Updated: July 26, 2026

Incorporation

This Data Processing Agreement ("DPA") forms part of and is incorporated into the Chrontic Terms of Service. It applies automatically when your company creates a Chrontic account and uses the Service to process personal data, without requiring a separately signed copy. It reflects the requirements of Art. 28 GDPR for the processing Chrontic UG (haftungsbeschränkt) ("Processor", "we") carries out on behalf of your company ("Controller", "you").

1. Subject Matter & Duration

Chrontic processes personal data on your behalf for as long as your company maintains an active Chrontic account, plus any retention period described in Section 8 (Deletion & Return of Data) after the account is closed.

2. Nature & Purpose of Processing

Processing consists of storing, organizing, and displaying employee time-tracking, project, and leave data so that you can manage employee time, projects, and productivity. Where you connect optional integrations (Jira, Outlook, Tempo), processing also includes reading or writing ticket, calendar, or worklog data from those services on your instruction.

3. Categories of Data Subjects & Personal Data

  • Data subjects: your employees, contractors, and admin users
  • Personal data: name, email, employment data (employee ID, cost center, payroll code, hire date, salary/hourly rate where entered), time entries, leave requests and balances, organizational unit, job title, and any data synced from connected integrations

See our Privacy Policy for the full description of data collected.

4. Processor Obligations

Chrontic will:

  • process personal data only on your documented instructions, including regarding international transfers, unless required otherwise by EU or member-state law;
  • ensure persons authorized to process the data are bound by confidentiality;
  • implement appropriate technical and organizational security measures, including bcrypt password hashing, role-based access control, and merchant-scoped data isolation;
  • engage sub-processors only as authorized under Section 5;
  • assist you, taking into account the nature of processing, in responding to data subject requests (access, erasure, rectification, portability);
  • assist you with your obligations regarding security and personal data breach notification;
  • delete or return personal data at the end of the provision of services, as described in Section 8; and
  • make available information reasonably necessary to demonstrate compliance with this DPA, and allow for audits, including inspections, conducted by you or an auditor you mandate, subject to at least 30 days' written notice and confidentiality; such audits may be conducted no more than once per calendar year, except following a personal data breach affecting your data, in which case this limit does not apply.

5. Sub-processors

You authorize Chrontic to engage the sub-processors listed on our Subprocessors page. We'll update that page when sub-processors are added or removed. Sub-processors are bound by data protection obligations consistent with this DPA.

6. International Transfers

Chrontic's own infrastructure is hosted in Germany, within the EU. Where a sub-processor transfers personal data outside the EU/EEA, that transfer is governed by the Standard Contractual Clauses adopted under European Commission Implementing Decision (EU) 2021/914 (Module 2: Controller-to-Processor, or Module 3: Processor-to-Processor, as applicable to that sub-processor's role), or another transfer mechanism recognized under Art. 44–49 GDPR.

7. Personal Data Breach Notification

Chrontic will notify you without undue delay after becoming aware of a personal data breach affecting your data, and provide information reasonably available to help you meet your own notification obligations under Art. 33/34 GDPR.

8. Deletion & Return of Data

When your company closes its Chrontic account, employee personal data is anonymized; time entry and leave records are retained in pseudonymized form for statutory payroll/tax purposes rather than deleted outright. You can request export of a user's data before closing the account via the admin export feature. We don't currently apply an additional automated deletion schedule beyond this.

9. Liability & Governing Law

Liability under this DPA follows the limitation of liability set out in our Terms of Service. This DPA is governed by the laws of Germany, with the courts of Berlin having exclusive jurisdiction, except where mandatory law provides otherwise.

Company Information

Chrontic UG (haftungsbeschränkt)
Kolonnenstraße 8, 10827 Berlin, Germany
Managing Director: Abdullah Sohrab Khan
Email: support@chrontic.com