Legal

Data Processing Agreement

Our standard DPA for customers processing personal data of EU/UK or other data-protected subjects through TempoShift.

Version 2026-01. Available for signature on request.

How to sign this DPA. Email legal@appsinclouds.com with your company's legal entity name and address. We'll send a countersigned copy within two business days. The DPA forms part of your TempoShift subscription agreement.

1. Subject matter & duration

This Data Processing Agreement ("DPA") forms part of the agreement between the customer ("Controller") and Apps in Clouds, Inc. ("Processor", "TempoShift") for the provision of the TempoShift service. It applies for as long as TempoShift processes personal data on behalf of the Controller.

2. Nature & purpose of processing

TempoShift processes personal data to provide a workforce-operations service: time-off management, schedule visibility, approval routing, and timesheet correction. Processing is automated and ongoing for the duration of the subscription.

3. Categories of personal data

  • Identification data: name, work email, employee ID.
  • Employment data: job title, manager, department, location, employment status.
  • Time-off data: leave requests, balances, accruals, types of leave.
  • Activity data: timesheet entries, corrections, audit logs.
  • Technical data: IP address, user agent, device identifiers.

4. Categories of data subjects

Employees, contractors, and other workforce members of the Controller's organization.

5. Processor obligations

TempoShift agrees to:

  • Process personal data only on documented instructions from the Controller, including for transfers, unless required by law.
  • Ensure that personnel authorized to process the data are bound by confidentiality.
  • Implement appropriate technical and organizational security measures (see Annex A below).
  • Not engage sub-processors without prior general written authorization. Current sub-processors are listed at /sub-processors.
  • Assist the Controller in responding to data subject requests.
  • Notify the Controller without undue delay (and within 72 hours) of any personal data breach.
  • At the Controller's choice, delete or return all personal data after the end of the service, subject to legal retention requirements.
  • Make available all information necessary to demonstrate compliance, and allow for audits at reasonable notice.

6. Sub-processors

TempoShift maintains a public list of sub-processors at /sub-processors. We will notify Controllers at least 30 days before engaging a new sub-processor; you may object during that window and, if we can't accommodate the objection, terminate the affected portion of the agreement.

7. International transfers

If personal data is transferred outside the EEA, UK, or Switzerland, the parties agree to incorporate the European Commission's Standard Contractual Clauses (Decision 2021/914) as Module Two (Controller to Processor), and to comply with any supplementary measures required by data protection authorities.

8. Audit rights

The Controller may audit TempoShift's compliance with this DPA once per year (or more often if there's a reasonable suspicion of breach), at the Controller's expense, on at least 30 days' notice. To minimize disruption, TempoShift may satisfy this obligation by providing the most recent SOC 2 Type II report and responses to a reasonable due-diligence questionnaire.

9. Liability

Each party's liability under this DPA is subject to the liability cap in the underlying TempoShift subscription agreement.

10. Termination

This DPA terminates automatically when the underlying subscription terminates. Within 30 days of termination, the Controller may export all personal data via the in-product CSV export. After that period, TempoShift will delete the data within 90 days, except where law requires retention.


Annex A — Technical & organizational measures

  • AES-256 encryption at rest; TLS 1.3 in transit.
  • Logical multi-tenant isolation enforced at the application and database level.
  • Role-based access control with least-privilege for personnel.
  • SSO with hardware-key MFA for personnel access to production.
  • Continuous vulnerability scanning, static analysis, and annual third-party penetration testing.
  • SOC 2 Type II independent annual audit.
  • 72-hour breach notification commitment.
  • Documented incident response and business continuity plans, tested quarterly.