Temprix
the product01AvailabilityHow each person's time is recorded, as a fraction.02CoverageThe forward number, and alerts when it moves.03ReportsWhere the time actually went.SecurityData residency, roles and the audit log.
ChangelogWhat shipped, as it ships.
PricingContact
Log inSign up
Temprix

Product

01AvailabilityHow each person's time is recorded, as a fraction.02CoverageThe forward number, and alerts when it moves.03ReportsWhere the time actually went.SecurityData residency, roles and the audit log.

Resources

ChangelogWhat shipped, as it ships.
PricingContact
Log inSign up

On this page

DefinitionsScope and RolesDetails of ProcessingInstructionsConfidentialitySecurity of ProcessingData Subject RequestsAssistance with Security, Breach Notification, and DPIAsPersonal Data Breach NotificationAudit RightsInternational TransfersLiabilityReturn or Deletion of Personal DataTermGoverning Law and JurisdictionOrder of Precedence
Legal

Data Processing Agreement

Last updated: Jul 9, 2026

This Data Processing Agreement (“DPA”) is entered into between the Customer and Temprix (as defined in the Terms of Service), and is incorporated by reference into the Terms of Service. This DPA applies to Temprix’s processing of Personal Data as a Processor on behalf of the Customer in connection with the Service.

Definitions

Capitalized terms not defined in this DPA have the meanings given in the Terms of Service. In this DPA:

“Applicable Data Protection Law” means the GDPR and any other data protection or privacy law applicable to the Processing of Personal Data under this DPA.

“Controller”, “Processor”, “Data Subject”, “Processing”, and “Personal Data Breach” have the meanings given in the GDPR.

“GDPR” means Regulation (EU) 2016/679 (General Data Protection Regulation).

“Instructions” means the documented instructions of the Customer regarding the Processing of Personal Data, as set out in this DPA, the Terms of Service, and the Customer’s configuration and use of the Service.

“Personal Data” means, for the purposes of this DPA, personal data (as defined in the GDPR) comprised in Customer Data.

“SCCs” means the Standard Contractual Clauses adopted by the European Commission (Implementing Decision (EU) 2021/914), or any successor mechanism recognized under Article 46 GDPR.

“Sub-processor” means any processor engaged by Temprix to process Personal Data on behalf of the Customer in connection with the Service.

Scope and Roles

    1. This DPA applies to Temprix’s Processing of Personal Data comprised in Customer Data, as further described in Annex I. For this Processing, the Customer is the Controller and Temprix is the Processor.
    2. This DPA does not apply to Temprix’s Processing of the Workspace Owner’s own account, billing, and contact information, which Temprix Processes as an independent Controller for its own business purposes (account administration, invoicing, and tax compliance), as described in the Privacy Policy.
    3. This DPA does not apply to Service Data (as defined in the Terms of Service), which is aggregated and anonymized and does not constitute Personal Data.

Details of Processing

The subject-matter, duration, nature and purpose of Processing, the categories of Data Subjects, and the types of Personal Data are described in Annex I. The obligations and rights of the Customer as Controller are set out in this DPA and the Terms of Service.

Instructions

    1. Temprix will Process Personal Data only on the Customer’s documented Instructions, including with regard to transfers of Personal Data to a third country, unless required to do so by applicable law. In such case, Temprix will inform the Customer of that legal requirement before Processing, unless the law prohibits this on important grounds of public interest.
    2. Temprix will immediately inform the Customer if, in its opinion, an Instruction infringes Applicable Data Protection Law.
    3. The Customer’s use of the Service’s configuration options (including the creation of event categories, event types, and free-text fields such as event titles and notes) constitutes part of the Customer’s Instructions. The Customer is responsible for ensuring that any Personal Data it or its Members choose to submit through the Service — including any special category data under Article 9 GDPR (e.g., health-related data arising from Customer-configured event types such as sick leave) — has an appropriate lawful basis. Temprix applies the security measures described in Annex III uniformly to all Customer Data, regardless of category or sensitivity.
    4. Customer Data may incidentally include Personal Data relating to individuals other than Members (for example, where a Member includes a third party’s name in a free-text field). The Customer is responsible for ensuring a lawful basis for any such incidental collection. Temprix has no independent means of identifying such individuals and assumes no obligation to respond to their rights directly (see Section 7).

Confidentiality

Temprix ensures that persons authorized to Process Personal Data have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality.

Security of Processing

Temprix implements the technical and organizational measures described in Annex III (the “Security Measures”), taking into account the state of the art, the costs of implementation, and the nature, scope, context, and purposes of Processing, as well as the risks to Data Subjects. Temprix will not materially decrease the overall security of the Security Measures without providing the Customer with reasonable prior notice.

Data Subject Requests

    1. Taking into account the nature of the Processing, Temprix will provide reasonable assistance to the Customer, via the Service’s available functionality and support channels, to enable the Customer to respond to requests from Data Subjects exercising their rights under Applicable Data Protection Law.
    2. If Temprix receives a request directly from a Data Subject relating to Customer Data, Temprix will not respond to the request substantively, and will instead forward it to the Customer without undue delay (and in any event within five (5) business days), instructing the Data Subject to contact the Customer directly.

Assistance with Security, Breach Notification, and DPIAs

Taking into account the nature of Processing and the information reasonably available to it, Temprix will provide reasonable assistance to the Customer with the Customer’s obligations under Articles 32 to 36 GDPR, including data protection impact assessments and prior consultation with supervisory authorities, using the documentation made available under Section 10 (Audit Rights) and Annex III.

Personal Data Breach Notification

Temprix will notify the Customer of a Personal Data Breach affecting Customer Data without undue delay, and in any event no later than forty-eight (48) hours after becoming aware of it. Notification will be made by email to the Workspace Owner. The notification will include, to the extent then known, the information reasonably required to enable the Customer to comply with its own notification obligations under Applicable Data Protection Law. Temprix will provide updates as further information becomes available.

Audit Rights

    1. On written request, Temprix will make available to the Customer its then-current Security Overview and other documentation reasonably necessary to demonstrate compliance with this DPA.
    2. If the documentation provided under Section 10.1 is not sufficient to demonstrate compliance, the Customer may conduct, or appoint a third-party auditor (subject to confidentiality obligations) to conduct, an audit of Temprix’s relevant Processing activities, no more than once every twelve (12) months, on at least thirty (30) days’ written notice, during normal business hours, and without unreasonably disrupting Temprix’s operations. The Customer bears the reasonable costs of any such audit, unless the audit identifies material non-compliance by Temprix with this DPA, in which case Temprix bears those costs.

Sub-processors

    1. The Customer provides Temprix with general written authorization to engage the Sub-processors listed in Annex II (Authorized Sub-processors) to Process Personal Data in connection with the Service. Annex II is the authoritative list of Temprix’s Sub-processors and may be updated by Temprix from time to time in accordance with this Section 11.
    2. Temprix will update Annex II and notify the Workspace Owner by email at least fifteen (15) days before engaging a new Sub-processor. If the Customer has a reasonable data-protection-related objection to a new Sub-processor, it may object in writing to privacy@temprix.app within the notice period; the parties will work in good faith to resolve the objection, and if it cannot be resolved, the Customer’s sole remedy is to terminate the affected Subscription in accordance with the Terms of Service.
    3. Temprix imposes data protection obligations on its Sub-processors that are materially equivalent to those set out in this DPA. Temprix’s use of Amazon Web Services (“AWS”) as a Sub-processor is governed by the AWS GDPR Data Processing Addendum, which is automatically incorporated into the AWS Service Terms and includes Standard Contractual Clauses covering AWS’s processing of Customer Data outside the European Economic Area. Because Sub-processors have no direct relationship with the Customer, Temprix acts as the Customer’s point of contact for any matters arising from these sub-processing arrangements.
    4. Temprix remains liable to the Customer for the performance of its Sub-processors’ obligations, to the extent set out in Section 13 (Liability).

International Transfers

    1. Temprix processes Customer Data in the Data Region selected by the Customer at Workspace creation, except for (a) authentication and identity data, (b) limited operational and pseudonymized account data, and (c) technical diagnostic and error-monitoring data (such as an account identifier used to correlate error reports for support purposes), each of which is processed globally, including in the United States, as described in the Terms of Service and Privacy Policy.
    2. Transfers of Personal Data to Sub-processors located in third countries (including the United States) are covered by the SCCs or another valid transfer mechanism under Article 46 GDPR incorporated into Temprix’s agreement with the relevant Sub-processor, including the SCCs incorporated into the AWS GDPR Data Processing Addendum described in Section 11.3.
    3. Where any other Processing of Personal Data by Temprix requires a transfer mechanism under Chapter V GDPR, Temprix will, upon the Customer’s request, execute the SCCs or rely on another valid transfer mechanism under Article 46 GDPR with respect to that transfer.

Liability

Each party’s liability arising out of this DPA is subject to the limitations and exclusions set out in Section 11 (Limitation of Liability) of the Terms of Service, including the increased cap applicable to breaches of data protection obligations.

Return or Deletion of Personal Data

    1. Following termination or expiry of the Agreement, Temprix will retain Customer Data, make it available for export (where export functionality is available), and delete it, in each case in accordance with Section 12 (Termination) of the Terms of Service.
    2. On written request following the completion of deletion under Section 14.1, Temprix will provide the Customer with written confirmation that deletion has occurred.

Term

This DPA takes effect on the date the Customer accepts the Terms of Service and remains in effect for as long as Temprix Processes Personal Data on the Customer’s behalf, notwithstanding any earlier termination or expiry of the Terms of Service.

Governing Law and Jurisdiction

This DPA is governed by the laws of the Netherlands and subject to the exclusive jurisdiction of the competent courts of Rotterdam, the Netherlands, consistent with Section 13 of the Terms of Service.

Order of Precedence

In the event of a conflict between this DPA and the Terms of Service with respect to the Processing of Personal Data, this DPA prevails, consistent with the Order of Precedence clause in Section 15 (General Provisions) of the Terms of Service.


Annex I: Details of Processing

Subject matter: Temprix’s provision of the Service, including the hosting, storage, and processing of Customer Data to enable workforce capacity planning functionality.

Duration: For the duration of the Agreement, plus the retention period set out in Section 12 of the Terms of Service.

Nature and purpose of Processing: Storage, retrieval, organization, and display of Customer Data to provide the Service, including account and workspace management, team and member scheduling, capacity calculation, and related notifications.

Categories of Data Subjects:

  • Members of the Customer’s Workspace, including individuals with pending invitations who have not yet accepted
  • Incidentally, other individuals whose Personal Data may appear in free-text fields (e.g., event titles or notes) at the discretion of Members, for whom the Customer is responsible for ensuring a lawful basis for collection

Categories of Personal Data:

  • Identity and contact data: name, email address
  • Workspace role and status data: role, membership status, team assignments
  • Scheduling and capacity data: event dates, times, time zones, event categories and types, capacity modifiers, recurrence details, and free-text titles/notes
  • Special categories of Personal Data: depending on the Customer’s configuration of event types (e.g., sick leave, medical incapacity), Customer Data may include information revealing health status. The Customer is responsible for ensuring an appropriate legal basis for processing such data under Article 9 GDPR.
  • Usage and audit data: account activity, audit log entries reflecting changes to Workspace data

Annex II: Authorized Sub-processors

This Annex is the authoritative list of Temprix’s Sub-processors. It is updated in place in accordance with Section 11 of this DPA; Temprix notifies the Workspace Owner by email at least fifteen (15) days before a new Sub-processor is added.

Sub-processor Purpose Location of Processing
Amazon Web Services EMEA SARL Cloud hosting European Union / United States
Stripe Payments Europe, Limited Payments United States
Functional Software, Inc. d/b/a Sentry Cloud monitoring European Union
Slack Technologies Limited Collaboration and community United States
Google Ireland Limited Productivity / collaboration European Union

Annex III: Security Measures

Temprix’s technical and organizational security measures are described in its published Security Overview, which is incorporated into this DPA by reference and updated from time to time in accordance with Section 6 of this DPA.

Temprix

Capacity planning for support and operations teams.

Product

AvailabilityCoverageReportsSecurityPricing

Resources

ChangelogContactFounder's note

Legal

Terms of ServicePrivacy PolicyAcceptable Use PolicyDPA
© 2026 Temprix. Made in the Netherlands.no cookies · no cross-site tracking