GDPR Compliance
Last updated: March 1, 2026
1. Our Commitment to GDPR
Timedox is committed to protecting the privacy and rights of individuals in the European Union. We comply with the General Data Protection Regulation (GDPR) and process personal data lawfully, fairly, and transparently.
We act as a data processor on behalf of our customers (data controllers) when handling employee time tracking data.
2. Legal Basis for Processing
We process personal data based on the following legal grounds: performance of a contract (providing our service), legitimate interest (improving our platform), and consent (marketing communications).
For employee time tracking data, our customers are responsible for establishing the legal basis for collection. We process this data only as instructed by our customers.
3. Data Subject Rights
Under GDPR, EU residents have the right to access their personal data, rectify inaccurate data, erase their data (right to be forgotten), restrict processing, data portability, and object to processing.
To exercise any of these rights, employees should contact their employer (the data controller). Account administrators can also contact us directly at [email protected].
4. Data Processing Agreements
We offer Data Processing Agreements (DPAs) to all customers who require them. Our DPA outlines the scope, nature, and purpose of data processing, as well as the obligations of both parties.
To request a DPA, contact our legal team at [email protected].
5. International Data Transfers
Timedox's servers are located in the United States. For EU customers, we rely on Standard Contractual Clauses (SCCs) approved by the European Commission to ensure adequate protection for data transfers.
We continuously monitor developments in international data transfer regulations and update our practices accordingly.
6. Data Protection Officer
For GDPR-related inquiries, you can contact our Data Protection Officer at [email protected]. We aim to respond to all requests within 30 days.
7. Breach Notification
In the event of a personal data breach, we will notify affected data controllers within 72 hours of becoming aware of the breach, as required by GDPR Article 33.
We maintain detailed breach response procedures and conduct regular security assessments to minimize risk.