Data Processing Agreement
Last updated 5 October 2026
This Data Processing Agreement (DPA) is part of the TempusLog terms. It applies when a customer uses TempusLog to process personal data covered by the EU or UK GDPR. It is in force from the moment a workspace is created; there is nothing to sign. If your company needs a signed copy, email contact@mile.dev.
1. Roles
- Customer (controller): the owner of a TempusLog workspace, on behalf of the organization it belongs to.
- mile.dev (processor): runs TempusLog and processes personal data in the workspace on the customer's behalf.
For account data (sign in, email address, password) mile.dev is the controller, as the privacy policy describes.
2. What is processed
- Purpose: providing TempusLog: storing time entries, showing reports and exports, managing the team, sending the emails the service needs.
- Data subjects: the customer's team members and invited people, and any people named in projects, clients or entry descriptions.
- Personal data: names, email addresses, roles, time entries (dates, times, durations, descriptions), project and client names, and technical data such as IP addresses in security logs.
- Special categories: none are needed. Customers should not put health or other sensitive data in entry descriptions.
- Duration: as long as the workspace exists, plus the deletion periods in section 8.
3. Instructions
mile.dev processes the data only on the customer's documented instructions: the terms, this DPA, and what the customer does in the app. If an instruction appears to break data protection law, mile.dev tells the customer. mile.dev does not sell the data, show ads, or use it to train AI models.
4. Confidentiality
Only people at mile.dev who need access to run the service have it, and they are bound to confidentiality. Staff access to a workspace through the app (for support) is logged.
5. Security
mile.dev keeps appropriate technical and organizational measures (GDPR Art. 32), including:
- All traffic encrypted with HTTPS (TLS), with HSTS and strict security headers.
- Passwords stored only as secure hashes. Clockify API keys encrypted, and deleted when an import ends.
- Every workspace's data separated by access checks on every request, with roles for who sees what.
- Staff admin access needs two-factor authentication; admin actions are recorded in an audit log.
- Servers in the EU with automatic security updates, a firewall, and SSH by key only.
- Daily encrypted snapshots of the whole server, kept for 7 days.
- Monitoring for errors and uptime, and limits against abuse (rate limits, bot checks).
More detail on the security page.
6. Subprocessors
The customer authorizes mile.dev to use the subprocessors below. Each is bound by a data processing agreement with terms that protect the data at least as well as this one.
| Subprocessor | What for | Where |
|---|---|---|
| Amazon Web Services | Hosting, database, server snapshots, email (Amazon SES) | Frankfurt, Germany (EU) |
| Resend | Sending app emails (invites, sign in, notices) | EU region (Ireland) |
| Sentry | Error reports, without names, email addresses or entered text | Frankfurt, Germany (EU) |
| Cloudflare | Turnstile bot check on sign up and password reset | Global network |
| Sign in with Google, only for people who choose it | Global |
Before adding or replacing a subprocessor, mile.dev updates this page and emails workspace owners at least 14 days ahead. A customer who objects on reasonable data protection grounds can tell us; if we can't solve it, the customer can delete the workspace and stop using TempusLog.
7. Transfers outside the EU
Workspace data is stored in Frankfurt, Germany. Where a subprocessor is based outside the EU or may access data from there, the transfer is covered by the EU-US Data Privacy Framework or the EU Standard Contractual Clauses.
8. Deletion
The customer can delete projects, clients, people's time or the whole workspace at any time in the app. Deleted data is removed from the live database right away and is gone from server snapshots within 7 days.
9. Helping the customer
- People's requests: owners and admins can view, correct, export (CSV and PDF reports) and delete data in the app. For anything the app can't do, mile.dev helps on request.
- Breaches: mile.dev tells the customer without undue delay, and within 48 hours of becoming aware of a personal data breach affecting their workspace, with what is known and what is being done.
- Assessments: mile.dev gives reasonable help with data protection impact assessments and consultations with authorities.
10. Audits
mile.dev answers reasonable written questions about how it protects the data, and makes available the information needed to show it meets this DPA. On-site audits can be agreed when the law or an authority requires them, with reasonable notice.
11. Liability and order
Liability under this DPA follows the terms. If this DPA and the terms conflict on personal data, this DPA wins.
Contact
Questions about this DPA or data protection: contact@mile.dev.