ChronticChrontic Web Application — Art. 28 GDPR
Last Updated: July 26, 2026
This Data Processing Agreement ("DPA") forms part of and is incorporated into the Chrontic Terms of Service. It applies automatically when your company creates a Chrontic account and uses the Service to process personal data, without requiring a separately signed copy. It reflects the requirements of Art. 28 GDPR for the processing Chrontic UG (haftungsbeschränkt) ("Processor", "we") carries out on behalf of your company ("Controller", "you").
Chrontic processes personal data on your behalf for as long as your company maintains an active Chrontic account, plus any retention period described in Section 8 (Deletion & Return of Data) after the account is closed.
Processing consists of storing, organizing, and displaying employee time-tracking, project, and leave data so that you can manage employee time, projects, and productivity. Where you connect optional integrations (Jira, Outlook, Tempo), processing also includes reading or writing ticket, calendar, or worklog data from those services on your instruction.
See our Privacy Policy for the full description of data collected.
Chrontic will:
You authorize Chrontic to engage the sub-processors listed on our Subprocessors page. We'll update that page when sub-processors are added or removed. Sub-processors are bound by data protection obligations consistent with this DPA.
Chrontic's own infrastructure is hosted in Germany, within the EU. Where a sub-processor transfers personal data outside the EU/EEA, that transfer is governed by the Standard Contractual Clauses adopted under European Commission Implementing Decision (EU) 2021/914 (Module 2: Controller-to-Processor, or Module 3: Processor-to-Processor, as applicable to that sub-processor's role), or another transfer mechanism recognized under Art. 44–49 GDPR.
Chrontic will notify you without undue delay after becoming aware of a personal data breach affecting your data, and provide information reasonably available to help you meet your own notification obligations under Art. 33/34 GDPR.
When your company closes its Chrontic account, employee personal data is anonymized; time entry and leave records are retained in pseudonymized form for statutory payroll/tax purposes rather than deleted outright. You can request export of a user's data before closing the account via the admin export feature. We don't currently apply an additional automated deletion schedule beyond this.
Liability under this DPA follows the limitation of liability set out in our Terms of Service. This DPA is governed by the laws of Germany, with the courts of Berlin having exclusive jurisdiction, except where mandatory law provides otherwise.
Chrontic UG (haftungsbeschränkt)
Kolonnenstraße 8, 10827 Berlin, Germany
Managing Director: Abdullah Sohrab Khan
Email: support@chrontic.com