For business customers

Data Processing Addendum

Effective 12 September 2026

Published in English only; this is the operative version. Write to info@sp33c.tech for a countersigned copy.

For customers who use TimeWarp to record work done for their own clients. It sets out how we process that data on your instructions, under Article 28 GDPR.

01Who is who

This Addendum is between you (the Controller) and sp33c.tech (the Processor, "we"). It forms part of the Terms of Use and applies whenever you use TimeWarp to record personal data about people who are not you — most commonly your own clients and their contacts.

It does not govern your own account data (your email address, your plan, your device tokens). For that we are the controller in our own right, and our Privacy Policy applies.

Where this Addendum and the Terms of Use conflict on the processing of your clients' data, this Addendum prevails.

02Subject matter, duration, nature and purpose

Subject matter: providing the TimeWarp time-tracking and invoicing service.Duration: for as long as you hold an account, plus any retention period you have configured.Nature and purpose: storage, organisation, retrieval and transmission of the records you create, so that you can read your timetable, export it, and issue invoices from it. We do not analyse your content for any purpose of our own, and we do not use it to train any model.

03Categories of data and data subjects

Data subjects: your clients and their contact persons; anyone you name in a note.Categories of personal data: a company or person name; optionally a postal address, email address, tax or VAT identification number, hourly rate and invoice language; free-text notes you attach to time entries; and, if you run the macOS capturer, the names and window titles of applications active on your Mac.

TimeWarp is not designed for special categories of personal data under Art. 9 GDPR, nor for criminal-offence data under Art. 10. Free-text fields accept whatever you type, so the obligation not to put such data there is yours — and our advice is not to. See Security for the controls that help you keep it out.

04Your instructions

We process your clients' data only on your documented instructions. Your use of the service is that instruction: creating, editing, exporting and deleting records, and configuring exports and integrations, are all instructions to process accordingly.

We will tell you if we believe an instruction infringes the GDPR or other Union or Member State data-protection law. We will not process the data for any other purpose, and we will not disclose it to anyone except as set out here or as required by law — in which case we will inform you first unless the law forbids it.

05Connecting an AI assistant is your instruction, not our sub-processing

TimeWarp can be connected to an AI assistant of your choosing over the Model Context Protocol. If you do that, the assistant can read your focuses, notes, time entries, customers and invoices, and act on your behalf.

The operator of that assistant is an independent controller, not our sub-processor. You instruct us to disclose the data to them; we have no agreement with them covering it, we cannot see or limit what they do with it, and they may process it outside the EU under their own terms. Before connecting one, satisfy yourself that doing so is lawful for the data you hold — including under any agreement you have with your own clients.

You can end the connection at any time under Settings → Connected apps. Nothing is disclosed to any AI provider unless you connect one.

06Confidentiality

Everyone we authorise to process your clients' data is bound by an obligation of confidentiality that survives the end of their engagement. Access is limited to the people who need it to run and support the service.

07Security (Art. 32)

We implement appropriate technical and organisational measures, described in full on our Security page and summarised here: data encrypted in transit and at rest; each account's records held in their own partition, keyed by an identity taken from a verified token and never from a request body; least-privilege access to production; rate limiting and account lockout on authentication; daily backups of the data tables.

08Sub-processors

You give a general authorisation for us to engage sub-processors. The current list is published at /subprocessors and forms part of this Addendum.

We will give you at least 30 days' notice by email before a new or replacement sub-processor starts processing. If you object on reasonable data-protection grounds within that period we will work with you to find a solution; if none is workable, you may terminate the affected part of the service and we will refund any prepaid, unused fees for it.

Each sub-processor is engaged under a written contract imposing data-protection obligations no less protective than those in this Addendum, and we remain fully liable to you for their performance.

09Assisting you

Data-subject requests (Arts. 12–23): the service is built so that you can answer most of them yourself — every record you hold is readable, editable and exportable in the app, and exports are available as Excel, CSV or a linked Google Sheet. Where you still need us, we will assist you by appropriate technical and organisational measures, taking into account the nature of the processing.Arts. 32–36: we will assist you in ensuring compliance with security of processing, breach notification, data-protection impact assessments and prior consultation, taking into account the nature of processing and the information available to us.Personal-data breaches: we will notify you without undue delay after becoming aware of a breach affecting your clients' data, with the information we hold at that point, and will follow up as more becomes known. Notifications go to your account email address; keep it current.

10Deletion and return

You can export your data at any time, in a format you own, without asking us.

Deleting your account from the app deletes your records: it removes every row in your partition across both data tables — focuses, time entries, customers, invoices, business details, connected-app records — and deletes your identity from our authentication directory. Any Google connection you authorised is revoked.

Backups are retained for 10 days and expire on their own; we do not restore individual accounts from them. Server logs are operational and contain no record content.

11Audit and information

On written request, and no more than once in any twelve-month period unless a supervisory authority requires otherwise, we will make available the information necessary to demonstrate compliance with Art. 28 — including the documentation on Security and Sub-processors, and answers to a reasonable security questionnaire.

TimeWarp is a small operation. We do not hold a SOC 2 report or an ISO 27001 certificate, and we will not claim to. If your procurement requires one, tell us before you buy rather than after.

12International transfers

Your clients' data is stored in the European Union. Where a sub-processor is established outside the EEA, the transfer is covered by the safeguard named for it on the sub-processor list — in every current case the European Commission's Standard Contractual Clauses, or the EU-US Data Privacy Framework where applicable.

13Term, and how to sign it

This Addendum takes effect when you begin using TimeWarp for your clients' data and continues until your account is deleted. If we change it materially, we will publish the new version here and notify customers who have a signed copy.

If your organisation needs a countersigned copy, or your own DPA reviewed, write to info@sp33c.tech and say which. We are not going to pretend a click-through is a signature.

14Contact

Questions about this Addendum go to info@sp33c.tech.