Data Processing Agreement (DPA)
Last updated: 08 August 2026
This DPA applies where TimeProf processes Personal Data on behalf of the Controller. It does not apply to processing for which TimeProf independently determines the purposes and means and therefore acts as a Controller, for example certain billing, security, service administration, legal compliance or direct customer-account activities.
1. Definitions
- “Controller” means the customer organisation that determines the purposes and means of processing Personal Data.
- “Processor” means Macfo Limited, operator of TimeProf, to the extent it processes Personal Data on behalf of the Controller.
- “Data Subject” means an identified or identifiable natural person, including employees, workers, contractors, agency workers, managers or other authorised users.
- “Personal Data” means personal data within the meaning of applicable UK Data Protection Laws.
- “Special Category Data” means special categories of personal data under Article 9 UK GDPR, including health data.
- “UK Data Protection Laws” means the UK GDPR, the Data Protection Act 2018, and other applicable UK privacy and data-protection legislation as amended from time to time.
- “UK GDPR” means the GDPR as it forms part of UK law and is defined for UK data-protection purposes under the Data Protection Act 2018, as amended.
- “Sub-processor” means another processor engaged by TimeProf to process Personal Data on behalf of the Controller.
- “Personal Data Breach” has the meaning given in UK Data Protection Laws.
- “Service” means the TimeProf website, administration portal, staff portal, mobile applications, APIs, workforce scheduling, attendance, leave, task, form, communication, notification and related services supplied to the Controller.
2. Scope, Subject Matter and Duration
The Processor will process Personal Data on behalf of the Controller solely to provide, secure, support and maintain the Service and to perform the processing described in this DPA and the main agreement.
Processing begins when the Controller starts using the Service or supplies Personal Data to TimeProf and continues for the duration of the relevant contract or subscription, together with any limited period required to return, export, securely delete or lawfully retain data following termination.
3. Controller Instructions
The Processor shall process Personal Data only on the Controller’s documented instructions, including instructions contained in the main agreement, this DPA, configured Service settings, support requests and other written instructions capable of being retained as a record.
This includes instructions relating to transfers of Personal Data outside the United Kingdom. If UK law requires TimeProf to process Personal Data other than on the Controller’s instructions, TimeProf will inform the Controller of that legal requirement before processing unless the law prohibits such notification on important grounds of public interest.
TimeProf will notify the Controller if, in its reasonable opinion, an instruction infringes applicable UK Data Protection Laws.
4. Nature and Purpose of Processing
The processing may include collection, recording, organisation, storage, retrieval, consultation, use, transmission, restriction, deletion and other operations necessary to provide the Service, including:
- Creating and managing staff, manager and administrator accounts.
- Authentication, multi-factor authentication, session management and account security.
- Rota creation, shift allocation, publishing, open-shift claims and shift responses.
- Recording availability, annual leave, sickness, training and other absence.
- Time and attendance, clock-in/out and geofence validation where enabled.
- Managing skills, qualifications, site assignments and workforce requirements.
- Managing tasks, task completion, digital forms, submissions and workflow records.
- Providing private and group chat, announcements, notes and notifications.
- Providing rota diagnostics, fatigue indicators, skills matching and workforce decision-support tools.
- Providing operational support, troubleshooting, security monitoring, auditability and service continuity.
- Mobile push-notification delivery, crash diagnostics and application telemetry where enabled.
5. Categories of Data Subjects
- Employees and workers of the Controller.
- Agency workers, temporary workers and contractors.
- Managers, supervisors and administrators.
- Applicants, former workers or other individuals where their data is lawfully entered into the Service.
- Other authorised users whose Personal Data is processed through the Controller’s use of TimeProf.
6. Types of Personal Data
- Identity: name, username, account ID, user ID, staff ID, role and profile photograph.
- Contact: email address, telephone number, postal address and postcode.
- Employment/workforce: employment status, dates, assigned sites, roles, skills, qualifications and training information.
- Rota and availability: shifts, rota history, preferences, availability, claims and responses.
- Leave and absence: holiday, sickness, training, other absence, approval/rejection status and related notes.
- Attendance: clock-in/out records, lateness, duration and method.
- Location: latitude, longitude, location accuracy and geofence validation information where enabled.
- Tasks and forms: assignments, completion records, notes, form responses and submissions.
- Communications: private/group chat messages, announcements, reactions, read status and notification information.
- Authentication/security: hashed passwords, token/session information, 2FA configuration, audit and security records.
- Device/technical: device or app-installation identifiers, push tokens, IP address, platform, OS/app version and technical logs.
- Usage/diagnostics: feature interactions, session information, crash data, stack traces and diagnostic telemetry where enabled.
7. Special Category Data
The Service may process Special Category Data where the Controller uses sickness or other functionality that contains health-related information. The Controller is responsible for determining and documenting an appropriate Article 6 lawful basis and, where required, an Article 9 UK GDPR condition and any additional Data Protection Act 2018 requirements.
The Controller shall ensure that only Personal Data necessary for its legitimate purposes is entered into TimeProf and that access to health or other sensitive information is limited to appropriately authorised users.
8. Controller Obligations and Rights
The Controller shall:
- Comply with applicable UK Data Protection Laws in its use of the Service.
- Ensure that its instructions to TimeProf are lawful.
- Identify and document an appropriate lawful basis for its processing.
- Identify any required Article 9 condition for Special Category Data.
- Provide appropriate privacy information to Data Subjects.
- Ensure Personal Data supplied to TimeProf is adequate, relevant and limited to what is necessary.
- Maintain appropriate user-access permissions and promptly remove access no longer required.
- Respond to Data Subject requests and regulatory obligations for which it is responsible as Controller.
- Determine whether a DPIA or other risk assessment is required for its intended use of the Service.
The Controller has the rights granted by Article 28 UK GDPR and this DPA, including the right to issue lawful documented instructions, receive compliance information, object to proposed Sub-processors in accordance with this DPA, request assistance with Data Subject rights, request return or deletion of Personal Data on termination, and exercise audit rights.
9. Processor Obligations
The Processor shall:
- Process Personal Data only on documented instructions from the Controller, except where UK law requires otherwise.
- Ensure persons authorised to process Personal Data are subject to appropriate confidentiality obligations.
- Implement appropriate technical and organisational measures in accordance with Article 32 UK GDPR.
- Assist the Controller, taking account of the nature of processing, with appropriate technical and organisational measures for Data Subject rights requests.
- Assist the Controller with security, Personal Data Breach, DPIA and prior-consultation obligations under Articles 32 to 36 UK GDPR where applicable.
- Maintain records required of processors under applicable UK Data Protection Laws.
- Make available information reasonably necessary to demonstrate compliance with Article 28 UK GDPR.
- Notify the Controller if an instruction appears to infringe applicable UK Data Protection Laws.
10. Confidentiality
TimeProf will ensure that personnel authorised to process Personal Data have committed themselves to confidentiality or are subject to an appropriate statutory duty of confidentiality. Access will be limited according to role and business need.
11. Sub-processing
The Controller grants TimeProf general written authorisation to use Sub-processors that are reasonably necessary to provide, secure, support or maintain the Service.
TimeProf will maintain a current record of relevant Sub-processors and will provide that information to the Controller on request. The current Service may use providers for functions such as cloud hosting and infrastructure, secure storage/backups, transactional email, mobile analytics, crash diagnostics and push-notification delivery.
Before appointing a new Sub-processor that will materially process Controller Personal Data, or replacing an existing one, TimeProf will provide reasonable prior notice where required and give the Controller a reasonable opportunity to raise a documented data-protection objection.
TimeProf will enter into a written agreement with each Sub-processor that imposes data-protection obligations offering an equivalent level of protection for the relevant Personal Data as required by Article 28 UK GDPR. TimeProf remains responsible to the Controller for the performance of its Sub-processors to the extent required by applicable law.
12. International Transfers
TimeProf will not make a restricted transfer of Controller Personal Data outside the United Kingdom except on the Controller’s documented instructions and in compliance with applicable UK transfer rules.
Where required, appropriate transfer mechanisms may include UK adequacy regulations, the International Data Transfer Agreement (IDTA), the UK International Data Transfer Addendum to the EU Standard Contractual Clauses, binding corporate rules, or another lawful safeguard or exception.
Where a transfer mechanism requires a transfer risk assessment / data protection test, TimeProf will take reasonable steps to ensure the required assessment and supplementary measures are addressed for the transfer for which it is responsible.
13. Technical and Organisational Security Measures
Taking account of the state of the art, implementation costs, nature, scope, context and purposes of processing, and risks to individuals, TimeProf will maintain appropriate technical and organisational measures. Depending on the relevant Service component, these may include:
- Encryption in transit using industry-standard transport security.
- Encryption at rest where supported and appropriate for the relevant storage service.
- Role-based access controls and least-privilege principles.
- Multi-factor authentication and secure authentication controls.
- Tenant isolation and authorisation controls.
- Secure password hashing and controlled secrets/credential handling.
- Logging, monitoring and audit trails for security-relevant activity.
- Backup, restoration and service-continuity measures appropriate to the Service.
- Vulnerability, patching and dependency-management processes.
- Access restriction for administrative and support personnel.
- Incident-management and Personal Data Breach response procedures.
Security measures may evolve over time, provided that TimeProf does not materially reduce the overall level of protection for Controller Personal Data.
14. Data Subject Rights
Taking account of the nature of the processing, TimeProf will provide reasonable assistance through appropriate technical and organisational measures to help the Controller respond to requests to exercise Data Subject rights.
If TimeProf receives a request directly from a Data Subject relating to Personal Data processed on behalf of the Controller, TimeProf will, where appropriate, refer the request to the Controller and will not independently determine the outcome of the request unless required by law or acting as a Controller for the relevant processing.
15. Personal Data Breaches
TimeProf will notify the Controller without undue delay after becoming aware of a Personal Data Breach affecting Personal Data processed on behalf of the Controller.
To the extent information is available, the notification will include information reasonably necessary to help the Controller meet its obligations, such as:
- The nature of the Personal Data Breach.
- The categories of Personal Data and Data Subjects affected.
- The likely consequences of the breach.
- Measures taken or proposed to contain, investigate and mitigate the breach.
- A contact point for further information.
Where all information is not available at the same time, TimeProf may provide it in phases without undue further delay.
16. Assistance with Security, DPIAs and Regulatory Consultation
Taking account of the nature of processing and the information available to TimeProf, the Processor will provide reasonable assistance to the Controller with:
- Article 32 security obligations.
- Personal Data Breach assessment and notification obligations.
- Data Protection Impact Assessments under Article 35 UK GDPR.
- Prior consultation with the ICO under Article 36 UK GDPR where required.
17. Audits and Compliance Information
TimeProf will make available to the Controller information reasonably necessary to demonstrate compliance with the Processor obligations in Article 28 UK GDPR.
The Processor will allow for and contribute to audits and inspections conducted by the Controller or an independent auditor appointed by the Controller. Except where a regulator, security incident or material compliance concern requires otherwise, audits should be conducted on reasonable prior notice, during normal business hours, subject to confidentiality and security requirements, and in a manner designed to minimise disruption to the Service and other customers.
Where appropriate, TimeProf may first satisfy an audit request by providing available policies, security information, compliance responses, independent assurance or other documentary evidence.
18. Return and Deletion of Personal Data
At the end of the Services involving processing, and at the Controller’s choice, TimeProf will return or delete Personal Data processed on behalf of the Controller and delete existing copies, unless applicable UK law requires continued storage of that Personal Data.
Deletion from backups may occur through the normal secure backup lifecycle where immediate deletion from immutable or disaster-recovery backups is not technically practicable, provided retained backup data remains protected and is not restored for ordinary business use.
19. Processor Records and Co-operation
TimeProf will maintain records of processing activities required of processors and will co-operate with the Information Commissioner’s Office or another competent supervisory authority where required by applicable law.
20. Liability
Liability between the parties is governed by the liability provisions of the main service agreement, subject to any rights or liabilities that cannot lawfully be excluded or limited under applicable law.
21. Precedence and Changes
If there is a conflict between this DPA and the main service agreement in relation to the processing of Personal Data on behalf of the Controller, this DPA will prevail to the extent of that conflict.
TimeProf may update this DPA where reasonably necessary to reflect changes in applicable law, regulatory guidance, the Service or Sub-processors, provided that an update does not materially reduce the protection afforded to Controller Personal Data. Material contractual changes will be communicated in accordance with the main agreement.
Schedule 1 – Processing Details
| Subject matter | Provision of the TimeProf workforce-management Service. |
|---|---|
| Duration | For the term of the Controller’s subscription/contract plus the period required for lawful return, deletion, backup expiry or retention. |
| Nature of processing | Collection, storage, organisation, retrieval, display, use, transmission, analysis, restriction, deletion and other operations required to provide the Service. |
| Purpose | Workforce scheduling, attendance, leave, tasks/forms, communications, notifications, security, support, diagnostics and related Service functionality. |
| Data Subjects | Employees, workers, contractors, agency staff, managers, administrators and other authorised individuals whose data is entered by the Controller. |
| Personal Data | As described in section 6 of this DPA. |
| Special Category Data | Health/sickness information where the Controller uses functionality that records health-related absence or notes. |
Schedule 2 – Sub-processors
TimeProf uses service providers to support delivery of the Service. The exact list may change over time in accordance with section 11. A current Sub-processor list can be requested by emailing privacy@timeprof.co.uk.
Categories of Sub-processors may include cloud hosting/infrastructure, database/storage, transactional email, mobile analytics, crash diagnostics and push-notification providers.
For questions about this DPA or to request the current Sub-processor list, contact: privacy@timeprof.co.uk.