Skip to content
timastra
ProductsPricingDemosMobile appsSupportAbout
Open the site Menu
ProductsPricingDemosMobile appsSupportAbout
Get in touchContact→

Legal

Data processing agreement

Last updated: September 29, 2026

On this page

  • Parties and scope
  • Roles
  • Customer instructions
  • Details of processing
  • Confidentiality and security
  • Sub-processors
  • International transfers
  • Assistance and data subject requests
  • Personal data breaches
  • Deletion and return
  • Information and audits
  • Philippine Data Privacy Act
  • Term and precedence

Parties and scope

This agreement forms part of the customer service agreement and is accepted with it. Customers who need a countersigned copy can email support@timastra.com. This agreement is between Timastra LLC, 5830 E 2nd St, Ste 7000 #38687, Casper, WY 82609, US ("Timastra"), and the business that subscribes to a Timastra hosted product ("the customer"). It applies when Timastra processes personal data in the customer's workspace while providing Timastra Collect, Inventory, Expenses, HRIS, Bookings, Commerce, Sentinel or Schedule Online. It does not apply to the Schedule and Deskrun desktop apps, whose data stays on the customer's computers, or to information Timastra handles as a controller, such as account, billing and support records, which the privacy policy covers.

Roles

The customer is the controller of personal data in its workspace. Timastra is the processor. The customer is responsible for having a lawful basis for that data and for giving the people concerned any notices the law requires.

Customer instructions

Timastra processes workspace personal data only to provide, secure, support and back up the product, and otherwise only on the customer's documented instructions. Using the product's features and settings is an instruction. Timastra will tell the customer if it believes an instruction breaks data protection law, and will not use workspace data for advertising, sale or training models.

Details of processing

  • Subject matter and duration: providing the subscribed product for the subscription term and the deletion period below.
  • Nature and purpose: hosting, storage, retrieval, display, calculation, email delivery, backup and support as the product describes.
  • Data subjects: the customer's staff and users, and the people whose records the customer keeps, such as its customers, employees, suppliers, shoppers or teachers and students.
  • Categories of data: those listed on each product's privacy page. HRIS can hold government identifiers and pay records; the customer should upload special-category data only where the product is designed for it.

Confidentiality and security

People authorized to process workspace data are bound by confidentiality. Timastra keeps technical and organizational measures appropriate to the risk, including encryption in transit, encrypted backups, network access restricted to Cloudflare, role-based access, multi-factor authentication where the product offers it, security updates and daily image scanning. Data & security describes them.

Sub-processors

The customer authorizes the sub-processors on the sub-processor list. Each sub-processor processes the data under its own data processing terms, and Timastra remains responsible for them. Timastra updates the list at least 30 days before a new sub-processor starts processing workspace data, and emails customers who have asked to be told; a customer may object on reasonable data protection grounds, and if the objection cannot be resolved, may end the affected subscription.

International transfers

Workspace data is hosted in Singapore, with encrypted backups in Cloudflare R2's Asia-Pacific region; email is sent through Resend's Tokyo region; Timastra is managed from the United States and the Philippines. For personal data subject to the EU GDPR, the parties enter into Module 2 (controller to processor) of the EU standard contractual clauses (Commission Implementing Decision 2021/914), with the customer as exporter and Timastra as importer; clause 7 (docking) applies, the option in clause 9(a) is general authorization with the notice period above, clause 11 has no optional language, and clauses 17 and 18 choose the law and courts of Ireland. Annex I is the details of processing in this agreement, Annex II the security measures above, and Annex III the sub-processor list. For UK data, the UK International Data Transfer Addendum applies to those clauses. Onward transfers to sub-processors rely on the transfer safeguards in their data processing terms.

Assistance and data subject requests

Timastra will pass on to the customer any request it receives from a data subject about workspace data, and will help the customer answer such requests, carry out impact assessments and consult authorities, taking into account the nature of the processing.

Personal data breaches

Timastra will notify the customer without undue delay, and in any case within 48 hours, after becoming aware of a personal data breach affecting workspace data, with the information then available, and will keep it informed as more becomes known.

Deletion and return

When a subscription ends, the customer can export its data through the product or ask support for an export. Timastra then deletes workspace data from the live service on request, or at the end of the product's retention period. Backups are kept for 14 daily, 4 weekly and 3 monthly copies, so deleted data expires from backups within about 3 months. Data the law requires Timastra to keep is retained only for that purpose.

Information and audits

Timastra will make available the information reasonably needed to show compliance with this agreement, and will answer reasonable written security questionnaires. On-site audits need prior written agreement on scope, timing, confidentiality and cost.

Philippine Data Privacy Act

Where the customer is a personal information controller under the Philippine Data Privacy Act of 2012 (Republic Act 10173), Timastra acts as its personal information processor, and this agreement is the outsourcing agreement the Act's implementing rules require. Timastra processes the data only for the purposes above, keeps the security measures described, notifies the customer of a breach within the 48 hours above so the customer can meet its 72-hour duty to the National Privacy Commission, helps the customer answer data subjects and the Commission, and returns or deletes the data at the end of the service as described. Privacy questions go to Timastra's data protection contact at support@timastra.com.

Term and precedence

This agreement lasts as long as Timastra processes workspace personal data for the customer. If it conflicts with the product terms on the processing of personal data, this agreement prevails.

timastra

Focused software for business, schools and everyday life.

Explore

ProductsPricingExplore demosMobile appsAboutContact

Get help

Product supportApp privacy & supportAccount & data deletionService status

Policies

Payments & refundsData & securityPrivacyTerms

© 2026 Timastra LLC
Independent software studio.

↑