This data processing agreement ("DPA") forms part of the terms of service and applies automatically between the organisation using Attenova (the "Controller") and ATTENOVA (the "Processor"; company details will be added after registration), insofar as Attenova processes personal data on behalf of the organisation.
Attenova processes, on behalf of the organisation, personal data of its employees and members, exclusively to provide the service (scheduling, leave management, time tracking, notifications and reporting). The DPA applies as long as the organisation uses the service.
Data subjects: employees and members of the organisation. Data: identification data (name, email address), scheduling and attendance data (shifts, leave and absences, clocked times, any geofence check at the moment of clocking), role and team assignments and notification preferences. No special categories of data, although absence codes may indirectly reveal health-related information (e.g. "sick"); the organisation itself determines which codes it uses.
The organisation gives general authorisation for these sub-processors: Brevo (email delivery, EU), Stripe (payment processing), Backblaze (encrypted backups, EU region) and Google (only the sign-in feature, if a user chooses it). Attenova imposes on each sub-processor, by contract, the same data protection obligations as in this DPA. We announce changes to this list in advance; in case of objection the organisation can terminate the agreement and export its data.
On request, Attenova makes reasonable information available to demonstrate compliance with this DPA. An on-site audit is possible at most once a year, by appointment, at the organisation's expense, and without access to other customers' data.
Upon termination, the organisation can export its data. On request, Attenova permanently deletes all of the organisation's personal data within a reasonable period after termination, subject to statutory retention obligations; backups then rotate out automatically.