Legal Data processing agreement Last updated: October 4, 2026 Read or download the October 4, 2026 legal documents [https://timastra.com/legal/releases/2026-10-04/index.html]. The dated archive preserves this release; your order or acceptance record identifies the documents that apply to you. On this page Parties and scope [#parties-and-scope] Roles [#roles] Customer instructions [#instructions] Details of processing [#details-of-processing] Confidentiality and security [#confidentiality-and-security] Sub-processors [#sub-processors] International transfers [#transfers] Assistance and data subject requests [#assistance] Personal data breaches [#breach-notification] Deletion and return [#deletion-and-return] Information and audits [#audits] Philippine Data Privacy Act [#philippines] Term and precedence [#term-and-precedence] Parties and scope This agreement forms part of the customer service agreement [https://timastra.com/legal/releases/2026-10-04/documents/service-agreement.html] and is accepted with it. Customers who need a countersigned copy can email support@timastra.com [mailto:support@timastra.com?subject=DPA%20request]. This agreement is between Timastra LLC, 5830 E 2nd St, Ste 7000 #38687, Casper, WY 82609, US ("Timastra"), and the business that subscribes to a Timastra hosted product ("the customer"). It applies when Timastra processes personal data in the customer's workspace while providing Timastra Collect, Inventory, Expenses, HRIS, Bookings, Commerce, Sentinel or Schedule Online. It does not apply to the Schedule and Deskrun desktop apps, whose data stays on the customer's computers, or to information Timastra handles as a controller, such as account, billing and support records, which the privacy policy [https://timastra.com/legal/releases/2026-10-04/documents/privacy.html] covers. Roles The customer is the controller of personal data in its workspace. Timastra is the processor. The customer is responsible for having a lawful basis for that data and for giving the people concerned any notices the law requires. Customer instructions Timastra processes workspace personal data only to provide, secure, support and back up the product, and otherwise only on the customer's documented instructions. Using the product's features and settings is an instruction. Timastra will tell the customer if it believes an instruction breaks data protection law, and will not use workspace data for advertising, sale or training models. Details of processing Subject matter and duration: providing the subscribed product for the subscription term and the deletion period below. Nature and purpose: hosting, storage, retrieval, display, calculation, email delivery, backup and support as the product describes. Data subjects: the customer's staff and users, and the people whose records the customer keeps, such as its customers, employees, suppliers, shoppers or teachers and students. Categories of data: those listed on each product's privacy page. HRIS can hold government identifiers and pay records; the customer should upload special-category data only where the product is designed for it. Confidentiality and security People authorized to process workspace data are bound by confidentiality. Timastra keeps technical and organizational measures appropriate to the risk, including encryption in transit, encrypted backups, network access restricted to Cloudflare, role-based access, multi-factor authentication where the product offers it, security updates and daily image scanning. Data & security [https://timastra.com/security] describes them. Sub-processors The customer authorizes the sub-processors on the sub-processor list [https://timastra.com/legal/releases/2026-10-04/documents/subprocessors.html]. Timastra must bind each sub-processor to the data-protection obligations required for the processing, including equivalent confidentiality, security, assistance and deletion obligations, and remains responsible for its performance. Timastra will notify every affected customer by email at least 30 days before adding or replacing a sub-processor that processes workspace data, with information needed to assess the change and an opportunity to object on reasonable data-protection grounds. Updating the public list alone is not that notice. If an objection cannot be resolved, the customer may end the affected subscription. International transfers Workspace data is hosted in Singapore, with encrypted backups in Cloudflare R2's Asia-Pacific region; email is sent through Resend's Tokyo region; Timastra is managed from the United States and the Philippines. Where EU or UK transfer rules apply, the parties must establish an applicable transfer mechanism before the affected processing. This requires the actual exporter/importer roles, any applicable SCC module and options, completed party/processing/security annexes, destination and onward-transfer assessment, and an executed UK instrument where required. This public page does not establish that those agreements or assessments have been completed for a particular customer. Request the customer-specific processing and transfer pack through support and record its approval before affected processing starts. Assistance and data subject requests Timastra will pass on to the customer any request it receives from a data subject about workspace data, and will help the customer answer such requests, carry out impact assessments and consult authorities, taking into account the nature of the processing. Personal data breaches Timastra will notify the customer without undue delay, and in any case within 48 hours, after becoming aware of a personal data breach affecting workspace data, with the information then available, and will keep it informed as more becomes known. Deletion and return At the end of the processing service, the customer chooses return or deletion of workspace personal data. The customer can export through the product or ask support for a return. Timastra must then delete the personal data and existing copies unless applicable law requires retention. A cancellation or disabled login alone is not deletion. Any legally retained data must be limited to that purpose; backup copies awaiting disposal must be restricted from ordinary use. Recovery must reconcile completed deletion requests before reopening access. The standard managed backup rotation selects 14 daily, 4 weekly and 3 monthly copies. That rotation alone does not establish an expiry date for every copy: protected release snapshots, legacy backups, provider recovery history and separately retained operator copies have separate schedules. The published policies do not currently specify one maximum disposal period covering all those copies. Timastra identifies the affected live data and copies, documented retention grounds and expected disposal in its response. If your processing requires a fixed disposal deadline, obtain a documented product-specific schedule before providing personal data; do not infer that deadline from the backup count. Information and audits Timastra will make available the information needed to demonstrate compliance with this agreement and will allow and contribute to audits, including inspections, by the customer or an auditor it mandates where applicable data-protection law requires. The parties may agree reasonable arrangements for scope, timing, confidentiality and cost, but those arrangements must not prevent legally required audit or inspection rights. Timastra will also answer reasonable written security questionnaires. Philippine Data Privacy Act Where the customer is a personal information controller under the Philippine Data Privacy Act of 2012 (Republic Act 10173), Timastra acts as its personal information processor, and this agreement sets the outsourcing terms for that processing. Timastra processes the data only for the purposes above, keeps the security measures described, notifies the customer of a breach within the 48 hours above so the customer can assess and meet any applicable notification duty, helps the customer answer data subjects and the Commission, and returns or deletes the data at the end of the service as described. Philippine law requires notification within 72 hours for breaches meeting its notification criteria; not every incident requires notification to the Commission. Privacy questions go to Timastra's data protection contact at support@timastra.com [mailto:support@timastra.com?subject=Data%20protection%20question]. Term and precedence This agreement lasts as long as Timastra processes workspace personal data for the customer. If it conflicts with the product terms on the processing of personal data, this agreement prevails.