This Data Processing Agreement ("DPA") forms part of the Terms of Service and applies to the processing of personal data by Teamspot App, a sole proprietorship established in The Netherlands ("Processor"), Chamber of Commerce (Netherlands): 92725066, on behalf of its customers ("Controller").
By using the Teamspot service, the Controller agrees to this DPA.
1. Definitions
- GDPR: Regulation (EU) 2016/679.
- Personal Data: Any information relating to an identified or identifiable natural person.
- Processing: Any operation performed on Personal Data as defined in the GDPR.
- Service: The Teamspot workforce management platform and related services such as implementation services.
Terms not defined here have the meaning given in the GDPR or the Terms of Service.
2. Roles of the Parties
The Controller determines the purposes and means of the processing of Customer Personal Data.
Teamspot acts as Processor and processes Customer Personal Data on behalf of and in accordance with the Controller's documented instructions. For limited business administration, billing, tax, legal compliance, fraud prevention, account-management, and business-contact data, Teamspot may act as an independent controller as described in Annex 1.
3. Subject Matter and Duration of Processing
3.1 Subject Matter
The subject matter of processing is the processing of Personal Data in connection with the provision of the Service, as further described in Annex 1.
3.2 Duration
Processing continues for the duration described in Annex 1, unless otherwise agreed or required by applicable law.
4. Nature and Purpose of Processing
Teamspot processes Personal Data only for the purposes described in Annex 1 and only in accordance with the Controller's documented instructions, the Agreement, and this DPA. Teamspot shall not use Personal Data for advertising, sale of data, profiling for Teamspot's own purposes, or unrelated commercial purposes.
5. Categories of Data Subjects and Personal Data
The categories of data subjects and categories of Personal Data are described in Annex 1.
6. Controller Obligations
The Controller is responsible for:
- Ensuring a valid legal basis for processing
- Informing data subjects about the processing
- Ensuring instructions provided to the Processor comply with GDPR
- Managing data subject rights requests
7. Processor Obligations and Deletion/Return of Data
Teamspot App shall, taking into account the nature of processing and the information available to Teamspot:
- Process Personal Data only on documented instructions from the Controller
- Ensure that persons authorized to process Personal Data are bound by confidentiality obligations or are under an appropriate statutory obligation of confidentiality.
- Implement appropriate technical and organizational security measures
- Assist the Controller, where reasonably possible, with:
- Data subject rights requests
- Data protection impact assessments
- Notify the Controller without undue delay after becoming aware of a personal data breach as further described in Annex 2
- Upon termination or expiry of the Service, Teamspot shall return or delete Personal Data in accordance with Annex 1, unless Union or Member State law requires storage.
Government access requests
Unless prohibited by law, Teamspot shall promptly notify the Controller of any legally binding request from a public authority for access to Personal Data. Teamspot shall review such requests and challenge them where Teamspot reasonably considers them unlawful or overbroad.
8. Sub-processors
The Controller grants Teamspot general written authorization to engage subprocessors necessary to provide the Service. Teamspot shall impose data protection obligations on subprocessors that are substantially equivalent to those set out in this DPA and shall remain responsible for the performance of its subprocessors.
Teamspot shall maintain an up-to-date list of subprocessors, including their identity, location, and processing activities, and make it available at https://teamspotapp.com/dpa or another notified location. Teamspot shall provide at least 30 days' prior notice of any intended addition or replacement of subprocessors. The Controller may object on reasonable data protection grounds within that period.
9. International Data Transfers
Personal Data may be processed within the European Economic Area (EEA) or, where required for specific services, outside the EEA.
Where Personal Data is transferred outside the EEA, Teamspot App ensures appropriate safeguards are in place in accordance with GDPR. Where Teamspot or its subprocessors transfer Personal Data outside the EEA to a country not subject to an adequacy decision, Teamspot shall ensure that the transfer is governed by the European Commission's Standard Contractual Clauses, as applicable, and shall implement supplementary measures where required by GDPR and applicable guidance.
10. Security Measures
Teamspot implements appropriate technical and organisational measures to protect Personal Data as described in Annex 2. Such measures are designed to ensure a level of security appropriate to the risk, taking into account the nature, scope, context, and purposes of the processing.
11. Audits
Teamspot shall make available to the Controller all information reasonably necessary to demonstrate compliance with this DPA and Article 28 GDPR.
The Controller may audit Teamspot's compliance with this DPA where required by law or where reasonably necessary and proportionate. Audits must be limited in scope, conducted during business hours, subject to reasonable prior notice, subject to appropriate confidentiality obligations, and not unreasonably disruptive to Teamspot's business, systems, or other customers.
12. Liability and Precedence
Liability arising under this DPA is subject to the limitations set out in the Terms of Service.
In the event of a conflict between this DPA and the Terms of Service regarding the processing of Personal Data, this DPA shall prevail.
13. Governing Law
This DPA is governed by the laws of The Netherlands.
Any disputes shall be submitted to the exclusive jurisdiction of the courts of Utrecht, The Netherlands.
14. Contact
For data protection matters, contact:
Teamspot App
Privacy contact: info@teamspotapp.com
Annexes
The following annexes form an integral part of this DPA. Click each annex to expand.
Annex 1 — Processing Details
1. Service, Subject Matter, Nature, and Purpose of Processing
Teamspot App provides a workforce management software platform and related implementation services, including workforce scheduling, shift planning, time tracking, clock-in and clock-out functionality, absence and leave management, internal messaging, reporting, payroll export, customer support, and related professional services.
Teamspot App processes Personal Data on behalf of the Customer to provide, operate, maintain, secure, support, troubleshoot, and improve the Service in accordance with the Controller's documented instructions.
The purposes of processing include account creation and administration, user authentication, workforce scheduling, shift planning, time tracking, clock-in and clock-out, absence and leave management, internal communication, notifications, reporting and analytics for the Customer, payroll export, customer support, troubleshooting, bug fixing, security monitoring, billing and subscription management, legal compliance, product improvement using anonymized or aggregated data, and implementation or related professional services.
The Controller's documented instructions include the DPA, Terms of Service, Order Form, product configuration, admin settings, support requests, written instructions, and other documented instructions agreed between the parties.
2. Duration, Export, Return, Deletion, and Retention
Processing starts at the beginning of the contract period and continues for the duration of the Agreement, unless otherwise agreed or required by applicable law.
During the term of the Agreement, and for 30 days following termination or expiry, the Customer may export Personal Data from the Service where export functionality is available, or request Teamspot App's reasonable assistance with export. Supported export formats may include CSV, Excel, PDF, and JSON.
Upon termination or expiry of the Agreement, the Customer may request return or deletion of Personal Data. If the Customer does not request return within 30 days after termination or expiry, Teamspot App will delete the Personal Data unless retention is required by Union or Member State law.
Deleted Personal Data may remain in backups for up to 7 days, after which it is removed through the ordinary backup rotation process.
Billing records may be retained for 7 years where required for legal, tax, accounting, or administrative purposes. Teamspot App may retain anonymized data where such data no longer constitutes Personal Data under the GDPR.
Upon request, Teamspot App may provide written confirmation or a deletion certificate confirming completion of deletion, subject to reasonable verification and operational limitations.
3. Categories of Data Subjects and Personal Data
Teamspot App may process Personal Data relating to the following categories of data subjects:
- employees, workers, contractors, managers, administrators, and other authorized users of the Customer;
- invited, deactivated, and pending-deletion users;
- job applicants or draft employees entered into the Service before invitation;
- Customer account owners, billing contacts, support requesters, and other authorized business contacts;
- end-users of shared kiosk devices operated by the Customer.
Depending on the Customer's configuration and use of the Service, Teamspot App may process the following categories of Personal Data:
- identity and contact data, such as name, email address, profile picture, employee number, role, job title, assigned location, team, preferred language, and related organizational information;
- authentication and account-security data, such as hashed passwords, verification status, two-factor authentication status, login timestamps, trusted-device data, session data, and other auditable authentication data;
- employment and contractual data, such as employment dates, role, contractual working time, employee category, hourly wage, wage codes, payroll multipliers, and related employment information;
- scheduling, availability, absence, and leave data, such as planned shifts, workplace, shift notes, recurring patterns, open-shift applications, swap requests, availability preferences, absence type, absence dates, absence reason, approval status, and balance impact;
- time-tracking data, such as clock-in and clock-out times, breaks, source of entry, net hours, overtime, evaluated time segments, work-location information, travel-time information, and timesheet approval history;
- communication and collaboration data, such as direct and group messages, message content, sender and recipient information, timestamps, and related metadata;
- device, technical, and usage data, such as push-notification tokens, calendar-sync mappings, IP address, user agent, request metadata, device/browser metadata, and security or diagnostic data;
- payroll export and financial calculation data, such as worked hours, wage code, multiplier, hourly rate, currency, computed cost per employee per pay period, and payroll export metadata;
- Customer and billing contact data, such as contact name, email address, phone number, billing details, account owner details, and support requester details.
The Service is not intended for use by minors. If the Customer adds minors to the Service, the Customer is responsible for ensuring that such use complies with applicable law.
4. Sensitive, Criminal-Offence, and Location Data
Teamspot App does not intentionally require or collect special categories of Personal Data within the meaning of Article 9 GDPR, and the Service is not designed to process medical diagnoses, medical certificates, health records, pregnancy information, disability information, occupational health information, trade union membership, religious beliefs, ethnic origin, biometric data, genetic data, or similar sensitive information.
However, depending on the Customer's configuration and use of the Service, users may be able to enter free-text notes, upload documents, or submit absence-related information that may reveal special categories of Personal Data. Special categories of Personal Data are not required for use of the Service. If the Customer or its users submit such data into the Service, the Customer is responsible for ensuring that the processing is lawful, necessary, proportionate, properly documented, and supported by a valid legal basis and, where required, an applicable Article 9 GDPR condition.
The Service is not designed to process criminal offence data. The Customer shall not use the Service to process criminal offence data, background-check information, disciplinary records, misconduct records, security incident records, or similar information unless expressly agreed in writing with Teamspot App and permitted by applicable law.
Teamspot App may process limited work-location, travel-time, or clock-in/clock-out location data where relevant to scheduling, time tracking, geofencing, workforce management, or payroll export functionality. Teamspot App does not perform continuous employee location tracking. The Customer is responsible for ensuring that any use of location-related functionality is lawful, transparent, necessary, and proportionate, and that affected data subjects are properly informed.
5. Processing Roles and Restrictions on Use
For Customer employee, workforce, scheduling, time-tracking, absence, messaging, reporting, and payroll-export data, the Customer acts as Controller and Teamspot App acts as Processor.
For limited business administration, billing, tax, legal compliance, fraud prevention, account-management, and business-contact data, Teamspot App may act as an independent controller where it determines the purposes and means of such processing under applicable law.
Teamspot App may use anonymized or aggregated data for product performance analysis, Service improvement, and benchmarking, provided that such data does not identify the Customer, individual users, employees, workers, or other data subjects and no longer constitutes Personal Data under the GDPR.
Teamspot App shall not use Customer Personal Data for AI model training without the Customer's explicit prior consent.
Annex 2 — Technical and Organisational Measures
1. General Security, Hosting, and Data Segregation
Teamspot implements appropriate technical and organisational measures designed to protect Personal Data against accidental or unlawful destruction, loss, alteration, unauthorized disclosure, or unauthorized access. The measures are designed to ensure a level of security appropriate to the risk, taking into account the nature, scope, context, and purposes of the processing.
Teamspot may update these measures from time to time, provided that such updates do not materially reduce the overall level of protection for Customer Personal Data.
Teamspot uses reputable cloud infrastructure and managed platform providers for hosting, database, storage, authentication, and related infrastructure services. The Teamspot application infrastructure and production database are hosted in the European Union. Production, staging, and development environments are separated, and production Customer Personal Data is not copied into staging or development environments.
Teamspot is a multi-tenant software-as-a-service platform. Customer data is logically segregated by customer or tenant identifiers, and access-control rules are enforced at the application and database level. Users may access only the data associated with their organization and assigned role.
2. Encryption, Authentication, and Access Control
Teamspot protects Personal Data in transit using HTTPS/TLS and applies encryption at rest for production database and storage infrastructure. Certain sensitive application-level values may be additionally encrypted at application level.
User passwords are hashed using industry-standard password hashing methods managed by Teamspot's authentication provider. Plaintext passwords are not processed by Teamspot application code. Secrets, credentials, and service credentials are stored securely and are not stored in source code.
Access to production systems and Customer Personal Data is restricted to authorized personnel with a business need and is granted based on least privilege. Internal administrative access is protected by multi-factor authentication. Administrative access is provided through individual accounts where technically and operationally feasible, and access rights are revoked when no longer required.
Teamspot supports role-based access controls to limit user access based on the user's role within the Customer's organization.
3. Logging, Monitoring, Audit Trails, and Support Access
Teamspot maintains security and operational logging to support security monitoring, troubleshooting, auditability, and compliance.
Logged events may include role and permission changes, administrative actions, support or impersonation access, document access and downloads, user deletion or deactivation, administrative overrides, relevant data exports, suspicious access patterns, blocked or restricted actions, operational events, and authentication or platform events.
Teamspot maintains an internal audit trail for critical actions. Certain audit-trail records are designed to be immutable and append-only. Access to logs is restricted to authorized personnel.
Teamspot support personnel may access Customer Personal Data only where necessary to provide support, troubleshoot issues, perform implementation services, investigate security matters, or act on the Customer's documented instructions. Support access is performed through controlled and audited access mechanisms. Support and impersonation events are logged.
4. Backups and Restoration
Production data is backed up regularly. Backups are protected using encryption at rest and retained for up to 7 days.
Deleted Customer Personal Data may remain in backups for up to 7 days, after which it is removed through the ordinary backup rotation process.
Teamspot maintains backup and restoration processes appropriate to the nature and size of the Service.
5. Secure Development and Vulnerability Management
Teamspot maintains separated development, staging, and production environments and does not copy production Customer Personal Data into staging or development environments.
Teamspot applies secure development practices appropriate to its size and risk profile, including access controls for production systems, dependency scanning, controlled deployment practices, security review of relevant changes, secure storage of secrets and credentials, avoidance of secrets in source code, server-side authorization checks, and database-level access-control policies.
Teamspot monitors application dependencies and relevant infrastructure components for known vulnerabilities. Vulnerabilities are assessed based on severity, exploitability, potential impact, and exposure. Critical vulnerabilities are prioritized for remediation without undue delay.
6. Incident Response and Personal Data Breaches
Teamspot maintains an incident response process for identifying, investigating, escalating, mitigating, documenting, and resolving security incidents.
Where Teamspot becomes aware of a Personal Data Breach affecting Customer Personal Data, Teamspot shall notify the affected Customer without undue delay.
Where available and relevant, Teamspot's breach notification will include the nature of the breach, affected systems or services, categories of Personal Data affected, approximate number of affected data subjects where known, likely consequences, measures taken or proposed to address and mitigate the breach, and a contact point for follow-up.
Teamspot may provide additional information in phases where not all information is available at the time of the initial notification.
7. Confidentiality and Personnel Security
Persons authorized to process Customer Personal Data are subject to confidentiality obligations. Contractors or external service providers with access to Customer Personal Data are required to be subject to appropriate confidentiality and data protection obligations.
Teamspot personnel are instructed not to access Customer Personal Data unless necessary to provide, maintain, secure, troubleshoot, or support the Service, or where otherwise instructed by the Customer.
8. Optional Features, Data Minimisation, and Privacy by Design
Teamspot is designed to process the data necessary to provide workforce management functionality selected and configured by the Customer. Optional features, such as location-related functionality, calendar sync, messaging, payroll export, and document uploads, are used only where enabled or used by the Customer or its users.
Location-related functionality is optional and disabled by default. Where enabled by the Customer, Teamspot may process location data for clock-in and clock-out verification and related workforce management purposes. Teamspot does not perform continuous employee location tracking.
Teamspot supports direct and group messaging between identifiable users and may support document uploads. Uploaded documents are stored in private storage and access is restricted through authorization controls. Protected documents are accessed using short-lived signed URLs where applicable. Document access and downloads may be logged.
Customers should avoid uploading unnecessary or high-risk files and are responsible for ensuring that messages and uploaded documents do not contain unnecessary sensitive information.
Teamspot may provide warnings or guidance discouraging users from entering medical diagnoses or other unnecessary sensitive information.
9. Subprocessors, Vendor Security, Transfers, and External Assurance
Teamspot uses subprocessors to provide hosting, infrastructure, notification, email, payment, calendar-sync, analytics, monitoring, and related services. Teamspot assesses subprocessors that may process Customer Personal Data and enters into appropriate data protection terms with such subprocessors where required.
Teamspot maintains a subprocessor list in Annex 3 or otherwise makes it available to Customers. International transfers and subprocessor details are addressed in the DPA and Annex 3.
Teamspot itself does not currently hold ISO 27001 or SOC 2 certification. Teamspot relies in part on security controls and certifications of selected infrastructure providers. Security documentation may be made available to Customers upon reasonable request, subject to confidentiality, security, and commercial-sensitivity considerations.
Annex 3 — Subprocessors
1. General
Teamspot uses subprocessors to provide, host, secure, maintain, support, and improve the Service.
The Controller grants Teamspot general written authorization to engage subprocessors in accordance with the DPA. Teamspot remains responsible for the performance of its subprocessors to the extent required under the DPA and GDPR.
Teamspot maintains this list of subprocessors and will provide notice of intended additions or replacements in accordance with the DPA.
Where a subprocessor processes Personal Data outside the European Economic Area, Teamspot relies on appropriate transfer safeguards, such as an adequacy decision, Standard Contractual Clauses, and supplementary measures where required.
2. Subprocessor List
| Subprocessor | Purpose | Personal Data Processed | Location / Region | Transfer Mechanism | Use |
|---|---|---|---|---|---|
| Supabase | Backend infrastructure, managed database, authentication, storage, and related platform services | Account data, authentication data, employee/workforce data, scheduling data, time-tracking data, absence data, communication data, technical data, uploaded documents, logs, and other Customer Personal Data processed through the Service | Hosted in EU region selected by Teamspot; corporate entity may be outside the EEA | EU hosting; Standard Contractual Clauses where applicable | Core service |
| Clever Cloud | Application deployment and hosting | Technical data, application traffic, service metadata, and limited Customer Personal Data necessary to operate the application | EEA | EEA processing | Core service |
| Apple Push Notification Service | Push notifications to iOS devices | Device tokens, notification payloads, technical delivery metadata | May include processing outside the EEA | Standard Contractual Clauses or other appropriate transfer mechanism where applicable | Optional / notification feature |
| Resend | Transactional email delivery | Name, email address, email content, account/service notification data, technical delivery metadata | United States or other locations used by provider | Standard Contractual Clauses where applicable | Core/notification service |
| Mollie | Payment processing and billing | Billing contact details, payment metadata, invoice/payment status, subscription-related data | EEA | EEA processing | Billing |
| Google Calendar / Google APIs | Optional calendar synchronization | Calendar-sync mappings, user identifiers, event/schedule data selected for synchronization, technical metadata | May include processing outside the EEA | Standard Contractual Clauses or other appropriate transfer mechanism where applicable | Optional, user-enabled |
| Microsoft Outlook / Microsoft APIs | Optional calendar synchronization | Calendar-sync mappings, user identifiers, event/schedule data selected for synchronization, technical metadata | May include processing outside the EEA | Standard Contractual Clauses or other appropriate transfer mechanism where applicable | Optional, user-enabled |
| Apple Calendar / Apple APIs | Optional calendar synchronization | Calendar-sync mappings, user identifiers, event/schedule data selected for synchronization, technical metadata | May include processing outside the EEA | Standard Contractual Clauses or other appropriate transfer mechanism where applicable | Optional, user-enabled |
| Mistral | Analytics/report-specification generation | Limited analytics or report configuration data; raw personally identifiable Customer Personal Data is not intentionally sent | European Union where available; provider locations may vary | EEA processing and/or Standard Contractual Clauses where applicable | Optional/reporting feature |
3. Optional and Feature-Dependent Subprocessors
Certain subprocessors are used only where the Customer or its users enable or use the relevant functionality.
This includes, for example:
- push notifications;
- calendar synchronization;
- report-generation or analytics features;
- payment or billing processing;
- optional integrations.
If a feature is not enabled or used, the related optional subprocessor may not receive Customer Personal Data.
4. Subprocessor Changes
Teamspot may add or replace subprocessors where necessary to provide, secure, support, or improve the Service.
Teamspot will provide at least 30 days' prior notice of any intended addition or replacement of a subprocessor, unless a shorter period is required due to urgent security, continuity, or legal reasons.
The Controller may object to a new or replacement subprocessor on reasonable data protection grounds within the notice period. If the parties cannot resolve the objection, the Controller may terminate the affected Service to the extent provided in the Agreement.
5. Subprocessor Obligations
Teamspot shall ensure that subprocessors processing Customer Personal Data are subject to contractual data protection obligations that are substantially equivalent to those set out in the DPA, including obligations relating to:
- confidentiality;
- security of processing;
- processing only for authorized purposes;
- assistance with data subject requests and security incidents where applicable;
- return or deletion of Personal Data where applicable;
- restrictions on further subprocessors;
- international transfer safeguards where required.
6. International Transfers
Where a subprocessor processes Customer Personal Data outside the EEA, Teamspot shall ensure that an appropriate transfer mechanism is in place, such as:
- an adequacy decision;
- the European Commission's Standard Contractual Clauses;
- supplementary measures where required;
- another lawful transfer mechanism under GDPR.
7. Notes on Data Minimisation
Teamspot configures subprocessors to process only the Personal Data reasonably necessary for the relevant service.
Where technically and commercially feasible, Teamspot limits the Personal Data shared with optional subprocessors. For example, report-generation or analytics providers are not intended to receive raw personally identifiable Customer Personal Data, and calendar providers receive data only where calendar synchronization is enabled by the user or Customer.