We value your privacy. TimeProf uses cookies and personal data to operate this platform. Please review our Privacy Policy , Cookie Policy and Terms of Service .

Data Processing Agreement (DPA)

Last updated: 08 August 2026

This Data Processing Agreement (“DPA”) forms part of the contract, subscription agreement, order form or other agreement governing use of the TimeProf Service between Macfo Limited, operator of TimeProf (“Processor”, “TimeProf”, “we”, “us”) and the customer organisation using the Service (“Controller”).

This DPA applies where TimeProf processes Personal Data on behalf of the Controller. It does not apply to processing for which TimeProf independently determines the purposes and means and therefore acts as a Controller, for example certain billing, security, service administration, legal compliance or direct customer-account activities.


1. Definitions

2. Scope, Subject Matter and Duration

The Processor will process Personal Data on behalf of the Controller solely to provide, secure, support and maintain the Service and to perform the processing described in this DPA and the main agreement.

Processing begins when the Controller starts using the Service or supplies Personal Data to TimeProf and continues for the duration of the relevant contract or subscription, together with any limited period required to return, export, securely delete or lawfully retain data following termination.

3. Controller Instructions

The Processor shall process Personal Data only on the Controller’s documented instructions, including instructions contained in the main agreement, this DPA, configured Service settings, support requests and other written instructions capable of being retained as a record.

This includes instructions relating to transfers of Personal Data outside the United Kingdom. If UK law requires TimeProf to process Personal Data other than on the Controller’s instructions, TimeProf will inform the Controller of that legal requirement before processing unless the law prohibits such notification on important grounds of public interest.

TimeProf will notify the Controller if, in its reasonable opinion, an instruction infringes applicable UK Data Protection Laws.

4. Nature and Purpose of Processing

The processing may include collection, recording, organisation, storage, retrieval, consultation, use, transmission, restriction, deletion and other operations necessary to provide the Service, including:

5. Categories of Data Subjects

6. Types of Personal Data

7. Special Category Data

The Service may process Special Category Data where the Controller uses sickness or other functionality that contains health-related information. The Controller is responsible for determining and documenting an appropriate Article 6 lawful basis and, where required, an Article 9 UK GDPR condition and any additional Data Protection Act 2018 requirements.

The Controller shall ensure that only Personal Data necessary for its legitimate purposes is entered into TimeProf and that access to health or other sensitive information is limited to appropriately authorised users.

8. Controller Obligations and Rights

The Controller shall:

The Controller has the rights granted by Article 28 UK GDPR and this DPA, including the right to issue lawful documented instructions, receive compliance information, object to proposed Sub-processors in accordance with this DPA, request assistance with Data Subject rights, request return or deletion of Personal Data on termination, and exercise audit rights.

9. Processor Obligations

The Processor shall:

10. Confidentiality

TimeProf will ensure that personnel authorised to process Personal Data have committed themselves to confidentiality or are subject to an appropriate statutory duty of confidentiality. Access will be limited according to role and business need.

11. Sub-processing

The Controller grants TimeProf general written authorisation to use Sub-processors that are reasonably necessary to provide, secure, support or maintain the Service.

TimeProf will maintain a current record of relevant Sub-processors and will provide that information to the Controller on request. The current Service may use providers for functions such as cloud hosting and infrastructure, secure storage/backups, transactional email, mobile analytics, crash diagnostics and push-notification delivery.

Before appointing a new Sub-processor that will materially process Controller Personal Data, or replacing an existing one, TimeProf will provide reasonable prior notice where required and give the Controller a reasonable opportunity to raise a documented data-protection objection.

TimeProf will enter into a written agreement with each Sub-processor that imposes data-protection obligations offering an equivalent level of protection for the relevant Personal Data as required by Article 28 UK GDPR. TimeProf remains responsible to the Controller for the performance of its Sub-processors to the extent required by applicable law.

12. International Transfers

TimeProf will not make a restricted transfer of Controller Personal Data outside the United Kingdom except on the Controller’s documented instructions and in compliance with applicable UK transfer rules.

Where required, appropriate transfer mechanisms may include UK adequacy regulations, the International Data Transfer Agreement (IDTA), the UK International Data Transfer Addendum to the EU Standard Contractual Clauses, binding corporate rules, or another lawful safeguard or exception.

Where a transfer mechanism requires a transfer risk assessment / data protection test, TimeProf will take reasonable steps to ensure the required assessment and supplementary measures are addressed for the transfer for which it is responsible.

13. Technical and Organisational Security Measures

Taking account of the state of the art, implementation costs, nature, scope, context and purposes of processing, and risks to individuals, TimeProf will maintain appropriate technical and organisational measures. Depending on the relevant Service component, these may include:

Security measures may evolve over time, provided that TimeProf does not materially reduce the overall level of protection for Controller Personal Data.

14. Data Subject Rights

Taking account of the nature of the processing, TimeProf will provide reasonable assistance through appropriate technical and organisational measures to help the Controller respond to requests to exercise Data Subject rights.

If TimeProf receives a request directly from a Data Subject relating to Personal Data processed on behalf of the Controller, TimeProf will, where appropriate, refer the request to the Controller and will not independently determine the outcome of the request unless required by law or acting as a Controller for the relevant processing.

15. Personal Data Breaches

TimeProf will notify the Controller without undue delay after becoming aware of a Personal Data Breach affecting Personal Data processed on behalf of the Controller.

To the extent information is available, the notification will include information reasonably necessary to help the Controller meet its obligations, such as:

Where all information is not available at the same time, TimeProf may provide it in phases without undue further delay.

16. Assistance with Security, DPIAs and Regulatory Consultation

Taking account of the nature of processing and the information available to TimeProf, the Processor will provide reasonable assistance to the Controller with:

17. Audits and Compliance Information

TimeProf will make available to the Controller information reasonably necessary to demonstrate compliance with the Processor obligations in Article 28 UK GDPR.

The Processor will allow for and contribute to audits and inspections conducted by the Controller or an independent auditor appointed by the Controller. Except where a regulator, security incident or material compliance concern requires otherwise, audits should be conducted on reasonable prior notice, during normal business hours, subject to confidentiality and security requirements, and in a manner designed to minimise disruption to the Service and other customers.

Where appropriate, TimeProf may first satisfy an audit request by providing available policies, security information, compliance responses, independent assurance or other documentary evidence.

18. Return and Deletion of Personal Data

At the end of the Services involving processing, and at the Controller’s choice, TimeProf will return or delete Personal Data processed on behalf of the Controller and delete existing copies, unless applicable UK law requires continued storage of that Personal Data.

Deletion from backups may occur through the normal secure backup lifecycle where immediate deletion from immutable or disaster-recovery backups is not technically practicable, provided retained backup data remains protected and is not restored for ordinary business use.

19. Processor Records and Co-operation

TimeProf will maintain records of processing activities required of processors and will co-operate with the Information Commissioner’s Office or another competent supervisory authority where required by applicable law.

20. Liability

Liability between the parties is governed by the liability provisions of the main service agreement, subject to any rights or liabilities that cannot lawfully be excluded or limited under applicable law.

21. Precedence and Changes

If there is a conflict between this DPA and the main service agreement in relation to the processing of Personal Data on behalf of the Controller, this DPA will prevail to the extent of that conflict.

TimeProf may update this DPA where reasonably necessary to reflect changes in applicable law, regulatory guidance, the Service or Sub-processors, provided that an update does not materially reduce the protection afforded to Controller Personal Data. Material contractual changes will be communicated in accordance with the main agreement.


Schedule 1 – Processing Details

Subject matter Provision of the TimeProf workforce-management Service.
Duration For the term of the Controller’s subscription/contract plus the period required for lawful return, deletion, backup expiry or retention.
Nature of processing Collection, storage, organisation, retrieval, display, use, transmission, analysis, restriction, deletion and other operations required to provide the Service.
Purpose Workforce scheduling, attendance, leave, tasks/forms, communications, notifications, security, support, diagnostics and related Service functionality.
Data Subjects Employees, workers, contractors, agency staff, managers, administrators and other authorised individuals whose data is entered by the Controller.
Personal Data As described in section 6 of this DPA.
Special Category Data Health/sickness information where the Controller uses functionality that records health-related absence or notes.

Schedule 2 – Sub-processors

TimeProf uses service providers to support delivery of the Service. The exact list may change over time in accordance with section 11. A current Sub-processor list can be requested by emailing privacy@timeprof.co.uk.

Categories of Sub-processors may include cloud hosting/infrastructure, database/storage, transactional email, mobile analytics, crash diagnostics and push-notification providers.


For questions about this DPA or to request the current Sub-processor list, contact: privacy@timeprof.co.uk.