Teampus

Privacy & Cookie Policy

Last updated: July 2026 · TermsData Processing Agreement

1. Who we are

Teampus (teampus.app) is a time-tracking application operated by Divhaus (Romania) — the "Provider", "we". For any privacy matter contact office@divhaus.ro.

Where you use Teampus as an employee or member of a company workspace, that company is the data controller of the workspace data and we act as its processor under the Data Processing Agreement. For account registration data and our own operations, we act as controller.

2. What data we process

3. Purposes and legal bases (GDPR Art. 6)

PurposeLegal basis
Providing the time-tracking service (accounts, entries, reports, exports)Contract performance — Art. 6(1)(b)
Security, session management, audit logging, backupsLegitimate interest — Art. 6(1)(f)
Notifying the operator of new registrationsLegitimate interest — Art. 6(1)(f)
Password-reset emailsContract performance — Art. 6(1)(b)
Compliance with legal obligationsLegal obligation — Art. 6(1)(c)

4. Cookies

Teampus uses only strictly necessary cookies. There are no analytics, marketing, or third-party cookies.

CookiePurposeDuration
connect.sidKeeps you signed in (session)7 days
tp_consentRemembers that you dismissed the cookie notice12 months
tp_themeRemembers your light/dark appearance choice12 months
tp_wizRemembers that you dismissed the setup guide12 months

Because these are essential for the service to function (or store a preference you explicitly chose), they do not require consent under the ePrivacy rules; the banner is shown for transparency.

5. Storage, backups and retention

6. Recipients

We do not sell personal data and do not use it for advertising. Data is disclosed only to: (a) our hosting infrastructure provider (EU); (b) our email delivery provider, solely to send transactional messages such as password resets; (c) authorities where the law requires it.

7. Your rights

Under the GDPR you have the right of access, rectification, erasure, restriction, portability, and objection, and the right to lodge a complaint with a supervisory authority — in Romania, ANSPDCP (dataprotection.ro).

Teampus provides self-service tools for the most common rights: Settings → Privacy & data lets you export a complete copy of your data (JSON) and delete your account — or, for administrators, the entire company workspace. For anything else, email office@divhaus.ro; we respond within 30 days.

If your data is managed inside a company workspace, requests may need to be addressed to your company administrator (the controller); we will assist them as processor.

8. Security

Passwords are stored using bcrypt hashing; password-reset tokens are stored hashed, are single-use and expire after 1 hour; sessions are invalidated on password change; access to workspace data is isolated per company; administrative actions are logged.

9. Changes

We may update this policy as the service evolves. Material changes will be announced in the application. The "Last updated" date above reflects the current version.

← Back to Teampus