Data processing agreement under Art. 28 GDPR
As at 23 September 2026
This agreement applies to cloud operation of irot Time. Anyone running irot Time on their own premises does not need it: the Provider then receives no personal data.
It is concluded between the customer as controller and
Jasmann Werk 52, owner Muhammad Saeed, Elberfelder Straße 72, 42553 Velbert, Germany, e-mail time@irot.com, as processor,
together with the contract for cloud operation (§ 9 of the terms) and applies in electronic form (Art. 28(9) GDPR). On request the parties will additionally sign it.
1. Subject matter and duration
(1) The processor operates the irot Time software for the controller as a dedicated instance with its own database, processing personal data on the controller’s behalf.
(2) The duration corresponds to the term of the main contract plus the period for export and deletion under clause 9.
2. Nature, purpose, data subjects, data
- Purpose: recording and evaluating working time, absences and shifts; preparing payroll; records under § 16(2) of the German Working Time Act and § 17 of the German Minimum Wage Act.
- Nature of the processing: collecting, storing, calculating, displaying, transmitting to recipients designated by the controller (such as its tax adviser), exporting, backing up, deleting.
- Data subjects: the controller’s employees; administrative users; people from the controller’s tax advisers whom it has invited.
- Categories of data: name, payroll number, work e-mail address, start and end of employment, department, line managers, target hours, clocking times, breaks, working days, premiums, holiday and other absences, correction requests, rota and shift swaps, project times, terminal PIN and passwords (as a hash only), card number, photograph (voluntary), audit log.
- With the Payroll & DATEV module additionally: date of birth, address, tax identification number, tax class, child allowances, social insurance number, health insurer, contribution groups, bank details, remuneration.
- Special categories (Art. 9 GDPR): periods of incapacity for work (start, end, and the connection relevant for continued pay) — no diagnoses; with the Payroll & DATEV module, the church tax attribute (religious denomination).
- Importing employees from payslips: payslips — including scanned or photographed ones — are read by the controller’s own browser (for scans, by text recognition running in the browser); the document does not reach the processor. Only documents the browser cannot read are transmitted for recognition to the sub-processor named in Annex 2 — exclusively with the AI module switched on and with consent for each individual operation. The document may in that case contain every category of data on a payslip, including the church tax attribute. Only the following are imported: payroll number, name, date of birth and start date, weekly hours, holiday entitlement, department, cost centre, and adviser and client numbers. Where the browser reads the payslip itself, the controller may additionally import the payroll master data (address, tax identification number, tax class, child allowances, church tax attribute, social insurance number, health insurer, contribution groups, bank details, remuneration) into its employees’ records; this requires the Payroll & DATEV module and happens only on express selection. These details never go to the sub-processor: only the fields listed above come back via the AI route. The processor does not store the document; retention at the sub-processor is governed by its own terms (Annex 2).
3. Instructions
The processor processes the data only on documented instructions from the controller, unless legally obliged to do otherwise; in that case it gives prior notice unless the law forbids it. The controller’s use of the software counts as an instruction. If the processor considers an instruction unlawful, it says so without undue delay.
4. Confidentiality
Persons with access to the data are bound to confidentiality. The processor accesses a customer instance only where the controller wishes it for support or fault-fixing, or to avert a malfunction.
5. Technical and organisational measures (Art. 32 GDPR)
The measures are set out in Annex 1. The processor may develop them further as long as the level of protection does not fall.
6. Sub-processors
(1) The controller approves the sub-processors named in Annex 2.
(2) The processor gives at least four weeks’ notice in text form of new or replaced sub-processors. The controller may object for important data protection reasons; if no agreement is reached, it may terminate the main contract.
(3) The data is processed in Germany. A transfer to a country outside the EU and the EEA takes place only with the AI module, if the controller switches it on (Annex 2).
7. Assistance
The processor assists the controller with data subject requests (Arts. 15 to 22 GDPR) — irot Time provides the Art. 15 information at one click, a full data export and a check of retention periods — with the security of processing, with notifications of breaches (Arts. 33, 34 GDPR) and with a data protection impact assessment (Art. 35 GDPR), to the extent information is available to it.
8. Personal data breaches
The processor reports a personal data breach without undue delay, and at the latest 24 hours after becoming aware of it, with the information required by Art. 33(3) GDPR so far as known.
9. End of the processing
After the main contract ends, the controller may export all data within 30 days (Settings → Data export; on request the processor provides the export). After that the processor deletes the instance; backups are deleted when their retention period expires (Annex 1). The processor confirms deletion in text form on request.
10. Evidence and audits
The processor provides the information needed to demonstrate compliance with Art. 28 GDPR and allows audits after prior notice and with reasonable notice periods, as a rule by producing documentation.
11. Liability
Art. 82 GDPR applies.
Annex 1 – Technical and organisational measures
Confidentiality
- Servers in the data centre of Hetzner Online GmbH in Falkenstein, Germany, certified to ISO 27001; physical and logical entry controls there follow their measures.
- Server access only by SSH key; no password login.
- Each customer gets its own application with its own database; no shared database across customers.
- The database is reachable only on the internal container network, with no port exposed externally.
- Connections encrypted only (HTTPS with TLS, HSTS); e-mails from the application only over an encrypted connection (STARTTLS mandatory).
- Passwords and PINs stored only as hashes; hashes never leave the interface.
- Role model: employees see only their own data; periods of incapacity for work are visible only to management and administration; the tax adviser’s access is limited to released months.
- Clocking terminals only after pairing by the administration, and can be blocked at any time; the PIN serves only for clocking, and the terminal shows personal data only after the personal password.
- Logins are rate-limited against brute-force attempts.
Integrity
- Changes to clocking times only with a reason; the audit log is only appended to, never altered.
- Plausibility checks on entries; employees cannot backdate.
Availability and resilience
- Daily backup of each instance (database, photographs, configuration), encrypted with age; the private key is not kept on the server. Retention 30 days; a failed run is logged as a failure.
- Automatic restart of the services.
Procedures for regular review
- Automated tests, including of the access rules, on every change; a check before every release.
Annex 2 – Sub-processors
- Hetzner Online GmbH, Industriestr. 25, 91710 Gunzenhausen, Germany – operation of the servers (Falkenstein data centre). Place of processing: Germany.
- Heinlein Hosting GmbH (mailbox.org), Schwedter Straße 8/9A, 10119 Berlin, Germany – sending the application’s e-mails (account mails such as "forgotten password", notifications, and on the controller’s instruction payroll files to its tax adviser). Place of processing: Germany.
- Anthropic Ireland, Limited – only where the AI module is booked and switched on by the controller: answering requests to the AI functions (Claude), including recognition of payslips the browser cannot read itself (only with consent for each operation, clause 2). Processing may also take place in the USA; the basis is Anthropic’s Data Processing Addendum with the EU standard contractual clauses.
On the AI module: it stays off until the controller’s administration expressly switches it on; the time and the account are recorded. Only the data needed for the particular question goes to the AI, by default with payroll numbers instead of names. Health data (sickness and its reasons) is never transmitted.
Payment service providers are not sub-processors: they process only the customer’s contract and payment data, not the data of its employees. The weather and public holiday display on the time clock queries public services using only the company’s postcode or town, with no personal data.
Binding version: Vertrag zur Auftragsverarbeitung (German). See also the terms and the privacy policy.