Legal
Data Processing Addendum
Last updated: 7 July 2026
Draft pending legal review. This document was drafted in-house to describe exactly what the Service does. It has not been reviewed by qualified counsel, it is not legal advice, and it will be finalised before the Service is offered in production.
This Data Processing Addendum ("DPA") forms part of, and is incorporated into, the Terms & Conditions ("Terms") between you ("Customer", "you") and Smart Solution Labz LLC, a limited liability company organised under the laws of the State of Wyoming, United States of America ("Smart Solution Labz", "we", "us"). It applies whenever we process personal data on your behalf in connection with the Service, and it is intended to satisfy Article 28(3) of Regulation (EU) 2016/679 ("GDPR") and, where applicable, the equivalent provisions of the UK GDPR and the Swiss FADP.
Capitalised terms not defined here have the meaning given in the Terms. "Controller", "processor", "sub-processor", "personal data", "processing", "data subject", "personal data breach" and "supervisory authority" have the meanings given in the GDPR. "Workspace Data" means the personal data contained in Customer Data that we process on your behalf in your Workspace.
Where there is a conflict, this DPA prevails over the Terms and the Privacy Policy in respect of the processing of Workspace Data; the Terms prevail on everything else.
1. Roles of the parties
| Party | Role for Workspace Data | Role for account, billing and Service-operation data |
|---|---|---|
| You (the Customer / employer) | Controller | Data subject / account holder |
| Smart Solution Labz LLC | Processor | Controller |
| Smartyn d.o.o. (Croatia) | Sub-processor (support, billing enquiries) | Our processor for billing, invoicing, sales and first-line support; independent controller of its own statutory invoicing and accounting records; our Article 27 EU representative |
| Google LLC / Google Ireland Limited | Sub-processor | Our processor |
| Worldline | Not applicable | Our processor for card payments |
You determine the purposes and means of processing Workspace Data. That includes deciding which people you invite into your Workspace, what you record about them, whether location check-in applies to them, how long you keep their records, and when those records are deleted. We provide the mechanism and act on your instructions; we do not decide those questions for you and we do not use Workspace Data for our own purposes.
For data about your account, your subscription, your payments, your use of the Service, diagnostics and our communications with you, we act as controller. That processing is described in the Privacy Policy and is not governed by this DPA.
2. Subject matter, duration, nature and purpose of the processing
Subject matter. The provision of the Service to you: a workforce, time-tracking, scheduling and client-management application.
Duration. For as long as your Workspace exists, plus the retention windows in Sections 6 and 15.
Nature and purpose. Hosting, storage, structuring, retrieval, display, transmission, backup, calculation (for example the automatic split of normal, night, weekend and overtime hours, and payroll figures derived from them), notification delivery, and deletion, in each case as necessary to provide the Service and to follow your instructions.
Processing operations we do not perform. We do not sell Workspace Data, do not use it to train models, do not use it for advertising or profiling, and do not disclose it to third parties except to the sub-processors listed in Section 11 or as required by law (Section 8.5).
3. Categories of data subjects and of personal data
This table is the description required by Article 28(3)(a) GDPR and mirrors our internal data map.
| Category of data subject | Categories of personal data |
|---|---|
| Your Members (employees, contractors, team members) | Identity and contact data (first and last name, email address, phone number), optional home address (country, city, postal code, street), optional date of birth and gender, employee identifier, role and permissions, hourly rate |
| Your Members (work records) | Working-time records (start and end times, the normal / night / weekend / overtime split, paid flag), check-in location (GPS coordinates and workplace radius) where you enable location check-in, absence and leave requests, payment and payroll records, documents you or the Member upload to their personnel file (for example employment contracts), notes and manager comments |
| Your Members (operational records) | Their name recorded as the creator, editor, approver or assignee of reservations, events, work orders, clients, notes, tasks and change-history entries |
| Your clients and business contacts | Name, phone number, email address, addresses, notes and attachments you record about them |
| Any individual named in content you upload | Whatever you choose to put in files, photographs, notes and attachments |
Special categories. The Service is not designed for special categories of personal data (Article 9 GDPR) or criminal-offence data (Article 10). Absence records may in practice reveal health information if you record a reason for sick leave, and personnel documents may contain whatever you upload. You decide what you put into the Service, and you are responsible for the additional safeguards such data requires.
4. Your instructions
4.1 Documented instructions. We process Workspace Data only on your documented instructions, including for transfers to a third country, unless required to do otherwise by Union or Member State law to which we are subject; in that case we will inform you before processing, unless that law prohibits it on important grounds of public interest. Your documented instructions consist of: (a) the Terms and this DPA; (b) your configuration of, and use of the features of, the Service, including the deletion controls in Section 5; and (c) any further written instruction we accept in writing.
4.2 Unlawful instructions. We will inform you if, in our opinion, an instruction infringes the GDPR or other Union or Member State data-protection law. We may suspend the execution of an instruction while that question is resolved. We are not obliged to give you legal advice, to assess whether a deletion is permitted under your own retention obligations, or to check whether a Member has a right to have a record erased; those are your decisions as controller.
4.3 Persons authorised to instruct. An instruction is validly given when it is issued through the Service by a user to whom you have granted Administrator rights, or in writing by a person you have identified to us as authorised. You are responsible for the rights you grant inside your Workspace and for keeping Administrator credentials secure. We act on the authority the Service shows us; we cannot know whether an internal approval you require was actually obtained.
4.4 Individuals cannot instruct us about your data. A Member who asks us to delete, change or hand over records held in your Workspace is not our controller. We will not act on such a request; we will refer the individual to you and, where we consider it appropriate, tell you that the request was made. Section 8 describes the procedure.
5. In-product deletion controls are your instructions
5.1 The controls. The Service gives Administrators controls that permanently delete personal data. Using one of them is a documented instruction from you to us under Article 28(3)(a) GDPR, given at the moment the control is confirmed:
| Control | What you are instructing us to do |
|---|---|
| Remove a Member - Archive | Withdraw the Member's access to the Workspace immediately and mark the membership archived. Nothing is deleted; the action is reversible at any time. |
| Remove a Member - Delete data | Withdraw access immediately and, after a cancellable window of 40 days, permanently delete that Member's personnel record in your Workspace: profile fields, manager notes, uploaded personnel documents and the underlying files, and their own absence and leave requests. |
| Delete data - also delete work records | A separate switch inside the Delete data flow, off by default, with its own warning and its own typed confirmation. It extends the same instruction to the Member's working-time records, their change history, the attachments filed against them, and their payment and payroll records. |
| Delete a Workspace | Delete the Workspace and everything in it, subject to the vote and grace mechanics described in the Service. |
| Ownership transfer | Move the owner role of a Workspace to another Member, subject to Section 6.4. |
5.2 Confirmation friction is not a legal check. The destructive controls require the Administrator to type the Member's first and last name, and the work-records switch requires a second, separate typed confirmation on its own screen. These are safeguards against mistake and against a compromised Administrator account. They are not, and must not be relied on as, a check that the deletion is lawful. We do not assess whether a statutory retention period still applies to the records you are deleting.
5.3 Default is to keep. Removing a Member never deletes work records unless you switch that on. Where you do not choose, the Service keeps the data. Nothing in the Service deletes Workspace Data on its own initiative, except the post-termination deletion in Section 15.
5.4 Your warranty. You warrant that you are entitled to give each such instruction, that you have considered your own retention obligations before giving it, and that giving it does not breach any law, contract, works agreement or court order applicable to you. Section 17 sets out the indemnity that goes with that warranty.
5.5 Our limited right to refuse. We may refuse or delay an instruction only where: (a) Section 4.2 applies; (b) executing it would breach a legal obligation binding on us, or an order of a competent authority or court notified to us; (c) the instruction is given by someone who is not authorised under Section 4.3; or (d) execution would compromise the security or integrity of the Service for other customers. We will tell you if we do, and why, unless prohibited by law.
6. Retention windows and what survives a deletion
The Service does not execute destructive instructions immediately. The windows below are safety mechanisms against error and against account takeover. They are part of the Service, not a promise to retain your data for any particular purpose or period beyond them.
6.1 Member removal (40 days). Access is withdrawn immediately in both modes: the Member's access rights are revoked and their live sessions are ended. An archived membership stays intact and can be restored at any time. A membership marked for deletion enters a window of 40 days during which any Administrator of your Workspace can cancel the deletion and restore the membership in full. The exact date is shown in the Service. Once the window expires, a scheduled job performs the deletion and it cannot be reversed.
6.2 What is permanently deleted. On expiry of the window we delete, in your Workspace: the Member's profile fields and contact details, the manager notes on their card, the personnel documents attached to their card and the underlying stored files, and their own absence and leave requests. If you switched on the work-records option, we additionally delete their working-time records and the change history of those records, the files attached to those records, and their payment and payroll records.
6.3 What survives, and why. After the deletion completes, the following remain in your Workspace, and you remain their controller:
- A minimal membership record ("tombstone") holding the person's first and last name and the technical flags describing the removal, so that the Service can render historical entries correctly and existing references do not break. It contains no contact details, no address, no date of birth, no gender, no permissions and no files.
- Your operational records that name the person - reservations, events, work orders, clients, notes, tasks and change-history entries created, edited or approved by them. These are your business records; the name recorded in them is part of the record and is never rewritten. The Service displays the name of a former Member in a muted style, which is a display convention and not a change to the record.
- The removal log described in Section 6.5.
- Working-time and payroll records, unless you switched on the work-records option.
6.4 Ownership transfer (8 days). Transferring ownership of a Workspace requires all three of: a fresh re-authentication by the current owner at the moment of the request; an explicit acceptance by the person receiving ownership; and a waiting period of 8 days that cannot be shortened, including by that acceptance. During the waiting period the current owner can cancel the transfer with one action from any session. The same three requirements apply where a transfer is requested as part of deleting the owner's own account. If the recipient does not accept before the period expires, the transfer lapses and ownership does not move.
6.5 The removal log. Every removal, cancellation, reactivation and permanent deletion is recorded in a log inside your Workspace that only our servers can write to and that Administrators can read. Each entry records who acted, on whom, in which mode, whether work records were included, when, and the outcome. After a permanent deletion, this log is the only remaining evidence of who ordered it. The log is retained and is not deleted in response to a deletion instruction, because it is the technical and organisational measure by which both of us can demonstrate which instructions were given and executed (Articles 5(2), 28(3)(h) and 32 GDPR), and because we and you both have a legitimate interest in being able to establish, exercise or defend legal claims about it. It survives the deletion of the Member and of your subscription, and it is deleted when the Workspace itself is deleted under Section 15.
6.6 Account deletion by an individual. A person can delete their personal Clocker account in the app or at https://clocker.cloud/delete-account/. That is an instruction to us as controller of their account data, and it deletes their sign-in credentials, their personal profile and their membership of every Workspace after a grace period of 40 days, during which they can restore the account by signing in again. It does not delete your records. Their first and last name remain on their employee card in your Workspace, their working-time, payroll and personnel records remain untouched, and your operational records that name them are unaffected. We refer any request they make about those records to you (Section 8).
7. Confidentiality
We ensure that persons authorised to process Workspace Data have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality. Access to production systems is limited to personnel who need it to provide, secure or support the Service, and is withdrawn when it is no longer needed. The same obligation is imposed on our sub-processors by contract.
8. Data subject requests
8.1 Your tools first. The Service is designed so that you can answer most requests yourself: Administrators can read, correct, export and delete the records in their Workspace without our involvement.
8.2 Referral. If a data subject contacts us directly about Workspace Data, we will not respond substantively on your behalf. We will confirm receipt, tell the person that their employer or the organisation running the Workspace is the controller, direct them to you, and, where we consider it appropriate and lawful, notify you that the request was made.
8.3 Identity. We do not verify the identity of a data subject on your behalf. Where we hold enough information to identify which Workspace a request concerns, we say so to you and nothing more.
8.4 Assistance. Taking into account the nature of the processing, we assist you by appropriate technical and organisational measures, insofar as this is possible, in fulfilling your obligation to respond to requests under Chapter III GDPR. Where a request cannot be answered with the tools in the Service, we will provide reasonable assistance; we may charge our reasonable costs for assistance that is repetitive, disproportionate or requires engineering work.
8.5 Authority and law-enforcement requests. If we receive a binding request from a public authority, a court or law enforcement for Workspace Data, we will: verify the request and its legal basis; challenge it where we consider it unlawful, overbroad or not addressed to the correct party; direct the requester to you wherever the request can properly be addressed to you as controller; disclose only the minimum required; and notify you before disclosure, unless we are legally prohibited from doing so, in which case we will notify you as soon as the prohibition allows.
9. Assistance with your other obligations
Taking into account the nature of the processing and the information available to us, we assist you in ensuring compliance with your obligations under Articles 32 to 36 GDPR: security of processing, notification of personal data breaches, communication of a breach to data subjects, data protection impact assessments, and prior consultation with a supervisory authority. This DPA, the Privacy Policy and the security description in Section 10 are intended to be sufficient information for you to carry out an impact assessment of your use of the Service; we will answer reasonable further questions in writing.
10. Security measures
We implement appropriate technical and organisational measures to ensure a level of security appropriate to the risk, taking into account the state of the art, the costs of implementation, and the nature, scope, context and purposes of processing. This section is the description required by Article 28(3)(c) and Article 32 GDPR. The measures may change as the Service evolves; we will not reduce the overall level of security.
| Area | Measure |
|---|---|
| Access control (tenant isolation) | Every request is authorised against cryptographically signed access claims carried in the user's sign-in token. Server-side security rules evaluate those claims on every read and write, so a user can only reach the Workspaces they are a member of, with the rights their role gives them. |
| Withdrawal of access | Removing a Member strips their access claims and revokes their existing session tokens, so access ends immediately rather than at the next sign-in. |
| Server-mediated lifecycle operations | Membership removal, cancellation, permanent deletion and ownership transfer can only be performed by server-side functions that re-check authority; the client application cannot perform them directly, and the security rules reject client writes to the fields that control them. |
| Audit logging | Removals, cancellations, reactivations and permanent deletions are written to an append-only, server-only log per Workspace (Section 6.5). Change-history records exist for time records, reservations and client records. |
| Encryption | Data is encrypted in transit (TLS). Data at rest is encrypted by our infrastructure provider using its standard key management. |
| Data residency | The database and file storage that hold Workspace Data are hosted in the European Union (Google Cloud region europe-west3, Frankfurt). Authentication credentials are processed in the United States (Section 14). |
| Abuse prevention | Device and application attestation on the mobile and web clients, rate limiting and abuse detection at the infrastructure layer. |
| Least privilege | Administrative access to production data is limited to personnel who need it and is withdrawn when the need ends. |
| Resilience and restoration | Managed, replicated infrastructure with provider-side backups; deletion jobs are idempotent and resume after failure rather than leaving a partially deleted record. |
| Testing | Changes to security rules and to deletion logic are reviewed and tested before release, and the deployed rules are verified against the intended rules after each deployment. |
Pseudonymisation and anonymisation. We do not represent that Workspace Data is pseudonymised or anonymised. The deliberate design of the Service is that a former Member's name remains legible on your records (Section 6.3).
11. Sub-processors
11.1 General authorisation. You give us general written authorisation to engage sub-processors, subject to this Section.
11.2 Current sub-processors.
| Sub-processor | Role | Processing location |
|---|---|---|
| Google LLC / Google Ireland Limited (Firebase, Google Cloud) | Hosting, database, file storage, serverless functions, authentication, push messaging, crash diagnostics and (where the user has opted in) analytics. Engaged under the Google Cloud Data Processing Addendum. | European Union (europe-west3) for database and file storage; United States for authentication; other regions for messaging and diagnostics |
| Smartyn d.o.o. (Croatia) | Authorised reseller, merchant of record and first-line support. May access Workspace Data only where necessary to resolve a support request. | Croatia (EU) |
| Worldline | Card payment processing for subscriptions. Does not receive Workspace Data. | European Union |
11.3 Obligations we impose. We conclude a written contract with each sub-processor imposing data-protection obligations that are in substance no less protective than those in this DPA, and we remain fully liable to you for the performance of that sub-processor's obligations.
11.4 Changes and objection. We will give you at least 30 days' notice before adding or replacing a sub-processor, by email to your Account address or through the Service. If you have a reasonable, data-protection-related objection, tell us within those 30 days and we will work with you in good faith to find a solution. If none is available, you may terminate the affected part of the Service, and we will refund any prepaid fees covering the period after termination.
12. Personal data breaches
We will notify you without undue delay after becoming aware of a personal data breach affecting Workspace Data, and in any event within 48 hours of becoming aware where the breach is likely to result in a risk to the rights and freedoms of data subjects. The notification will describe, so far as known at the time, the nature of the breach, the categories and approximate number of data subjects and records concerned, the likely consequences, and the measures taken or proposed. We will provide further information as our investigation progresses, and we will assist you with your own notification obligations under Articles 33 and 34 GDPR. Notifying you is not an acknowledgement of fault or liability. It is your responsibility, as controller, to notify your supervisory authority and, where required, the affected individuals.
13. Audits and information
13.1 Information. We make available to you the information necessary to demonstrate compliance with Article 28 GDPR, in the form of this DPA, the Privacy Policy, the security description in Section 10, our sub-processors' third-party audit reports and certifications where we are permitted to share them, and written answers to a reasonable security questionnaire not more than once in any 12-month period.
13.2 Audits. Where that information is genuinely insufficient, you or an independent auditor you mandate (who must not be our competitor and must be bound by confidentiality) may audit our processing of Workspace Data, on at least 30 days' written notice, during normal business hours, not more than once in any 12-month period, without unreasonably disrupting the Service or the data of other customers, and at your cost. We may require a shorter notice period to be agreed where a supervisory authority has ordered the audit or where a personal data breach has occurred.
13.3 Scope limits. An audit may not extend to the premises or systems of our sub-processors (for those we will provide the reports we hold), to data of other customers, or to information whose disclosure would breach a legal or contractual confidentiality obligation.
14. International transfers
Workspace Data held in the database and file storage is stored in the European Union. Authentication data (email address, password hash, telephone number where used for sign-in, federated sign-in identifiers, and the IP addresses and timestamps of sign-in events) is processed by Google in the United States, regardless of the region of the database, because the authentication service is only offered there. Push messaging and crash diagnostics may also be processed outside the European Economic Area. We are established in the United States and our personnel access the Service from there.
Where personal data is transferred to or accessed from a third country, we rely on the transfer mechanisms in Chapter V GDPR: the European Commission's Standard Contractual Clauses (Module Two, controller to processor, between you and us; Module Three, processor to processor, between us and our sub-processors) together with the supplementary measures described in Section 10, and/or an applicable adequacy decision. You instruct us to carry out those transfers to the extent necessary to provide the Service. The Standard Contractual Clauses concluded between us and Google under the Google Cloud Data Processing Addendum apply to the Google transfers. On request we will provide the transfer documentation we are permitted to share.
15. Deletion and return of Workspace Data
15.1 Export before you leave. You can export your Workspace Data from the Service at any time while your Workspace is active. Do that before terminating; the export tools are the return mechanism contemplated by Article 28(3)(g) GDPR.
15.2 After a Free Trial or Subscription ends. We keep your Workspace and its Customer Data for 80 days after expiry or termination, so that you can subscribe or resubscribe within that window and continue where you left off, and so that an accidental or disputed termination does not destroy your records. After those 80 days we delete the Workspace and its Customer Data, including the removal log.
15.3 Backups. Copies of deleted data may persist in routine backups for a limited period and are overwritten on a rolling basis. While they exist, they remain subject to this DPA and are not restored into the Service except as part of a disaster recovery of the whole system.
15.4 What we keep. After deletion we retain only: data we process as controller under the Privacy Policy (account, billing and diagnostics data), records we are required by law to keep, in particular invoicing and accounting records held by Smartyn d.o.o. as an independent controller, and information necessary to establish, exercise or defend legal claims. We do not retain Workspace Data for any other purpose.
15.5 Earlier deletion on request. You may instruct us in writing to delete the Workspace before the 80-day period expires, and we will do so within a reasonable period.
16. Your obligations as controller
You warrant and undertake that: you have a lawful basis for each processing operation you carry out through the Service; you have given your Members the information required by Articles 13 and 14 GDPR, including about location check-in if you enable it, and about the fact that their name remains on your records after they leave; you have carried out any impact assessment, works-council consultation or employee-representation procedure required in your jurisdiction; you will not put into the Service special categories of personal data or criminal-offence data without the additional safeguards those require; and your instructions to us will comply with data-protection law.
17. Indemnity for your instructions
To the extent permitted by law, you will defend, indemnify and hold harmless Smart Solution Labz LLC and Smartyn d.o.o. and their officers, employees and agents against any claim, investigation, fine, damage, loss or reasonable cost (including legal fees) arising out of or relating to: an instruction you gave us to delete or retain Workspace Data, including any instruction given through the deletion controls in Section 5; your failure to observe a retention obligation of your own; the absence of a lawful basis for a processing operation you carried out through the Service; or your failure to inform your Members as required by Section 16. This is in addition to the indemnity in Section 17 of the Terms.
18. Liability
Each party's liability under or in connection with this DPA is subject to the exclusions and limitations of liability in the Terms. Nothing in this DPA limits any liability that cannot be limited under applicable law, including a data subject's rights under Article 82 GDPR.
19. EU representative
Smartyn d.o.o., Vladimira Nazora 1b, 40317 Podturen, Croatia (email: info@s-labz.com), is our representative in the European Union under Article 27 GDPR. You and supervisory authorities may contact the representative on all matters relating to the processing of personal data, in addition to or instead of contacting us.
20. Term, changes and precedence
This DPA takes effect when you accept the Terms and continues for as long as we process Workspace Data on your behalf. Sections 6.5, 7, 12, 15, 17 and 18 survive its termination. We may update this DPA where required by law, by a supervisory authority, or to reflect a change in the Service; where a change is material we will give reasonable advance notice through the Service or by email. If a provision of this DPA is held invalid, the rest remains in force. This DPA is provided in English and Croatian; the English version is authoritative.
21. Contact
Data protection contact:
Smart Solution Labz LLC
30 N Gould St, Ste R, Sheridan, WY 82801, USA
Email: info@s-labz.com
EU representative (Article 27 GDPR):
Smartyn d.o.o., Vladimira Nazora 1b, 40317 Podturen, Croatia
Email: info@s-labz.com
Supervisory authority for the representative's establishment: the Croatian Personal Data Protection Agency (Agencija za zaštitu osobnih podataka - AZOP). You may also complain to the supervisory authority of your own habitual residence or place of work.