Data Processing Agreement (DPA)
Last updated: July 2026 · PrivacyTerms
This DPA forms part of the Terms & Conditions between Divhaus, Romania (the "Processor") and the customer organisation operating a Teampus workspace (the "Controller"), and reflects the requirements of Art. 28 GDPR. It applies automatically to every company workspace.
1. Subject matter and roles
The Processor provides the Teampus time-tracking service. In doing so it processes personal data of the Controller's workspace members (employees, collaborators) on the Controller's behalf and documented instructions, which are given through the configuration and use of the Service.
2. Details of processing (Art. 28(3))
| Item | Description |
| Duration | For as long as the Controller's workspace exists, plus the backup rotation period (~14 days). |
| Nature & purpose | Hosting, storage, display, reporting, export, and backup of time-tracking records. |
| Data categories | Identification data (name, email), employment context (role, workspace membership), working-time data (entries, durations, descriptions, timesheets), administrative activity logs. |
| Data subjects | Workspace members (employees/collaborators of the Controller); the Controller's clients' names insofar as entered by the Controller. |
3. Processor obligations
- Process personal data only as needed to provide the Service and per the Controller's instructions, unless required otherwise by EU or Member State law.
- Ensure persons authorised to process the data are bound by confidentiality.
- Implement appropriate technical and organisational measures (Annex A).
- Assist the Controller, insofar as possible, in responding to data-subject requests — including through the built-in export and deletion tools.
- Assist the Controller with its Art. 32–36 obligations (security, breach notification, DPIAs) taking into account the nature of processing.
- Notify the Controller without undue delay after becoming aware of a personal data breach affecting the Controller's data.
- At termination (workspace deletion), delete the personal data as described in the Privacy Policy; residual copies in rotating backups are overwritten within ~14 days.
- Make available information reasonably necessary to demonstrate compliance with Art. 28 and allow audits, which shall in the first instance be satisfied through documentation.
4. Sub-processors
The Controller grants general authorisation to the following categories of sub-processors, all located in the EU: (a) hosting/infrastructure provider for the servers on which the Service runs; (b) email delivery infrastructure for transactional messages. The Processor will inform Controllers of intended changes (e.g., via this page), giving the opportunity to object.
5. International transfers
Personal data is stored and processed within the European Union. No transfers to third countries take place as part of the standard Service.
6. Liability and order of precedence
Liability under this DPA is subject to the limitations in the Terms & Conditions. In case of conflict between this DPA and the Terms regarding personal data processing, this DPA prevails.
Annex A — Technical and organisational measures
- Transport encryption (HTTPS/TLS) for all connections; HSTS-preloaded domain.
- Password storage using bcrypt; hashed, single-use, time-limited password-reset tokens.
- Logical tenant isolation: every query is scoped to the workspace (company) of the authenticated user.
- Role-based access control (administrator vs standard member) within each workspace.
- Administrative audit logging of data-modifying actions.
- Automated daily backups with ~14-day rotation, stored within the EU.
- Session invalidation on password change; server-side session storage.
If your organisation requires a countersigned copy of this DPA or has specific compliance questionnaires, contact
office@divhaus.ro.
← Back to Teampus