Attenova Attenova

Data processing agreement

Version 1.0 · last updated 30 August 2026

This data processing agreement ("DPA") forms part of the terms of service and applies automatically between the organisation using Attenova (the "Controller") and ATTENOVA (the "Processor"; company details will be added after registration), insofar as Attenova processes personal data on behalf of the organisation.

1. Subject and duration

Attenova processes, on behalf of the organisation, personal data of its employees and members, exclusively to provide the service (scheduling, leave management, time tracking, notifications and reporting). The DPA applies as long as the organisation uses the service.

2. Nature of the data and data subjects

Data subjects: employees and members of the organisation. Data: identification data (name, email address), scheduling and attendance data (shifts, leave and absences, clocked times, any geofence check at the moment of clocking), role and team assignments and notification preferences. No special categories of data, although absence codes may indirectly reveal health-related information (e.g. "sick"); the organisation itself determines which codes it uses.

3. Attenova's obligations

  • Processes the data exclusively on the organisation's instructions (as given via the settings and the use of the platform) and never for its own purposes.
  • Processes and hosts all data within the European Union.
  • Takes appropriate technical and organisational measures (encrypted connections, hashed passwords, role-based access, correction trails on time records, encrypted backups).
  • Guarantees confidentiality of everyone who has access to the data on behalf of Attenova.
  • Reports a personal data breach affecting the organisation without undue delay after Attenova becomes aware of it, with the information the organisation reasonably needs for its own notification obligation.
  • Reasonably assists the organisation with requests from data subjects (access, rectification, erasure) and with its obligations regarding security, breach notifications and data protection impact assessments.
  • Informs the organisation immediately if, in Attenova's opinion, an instruction conflicts with data protection legislation.

4. Sub-processors

The organisation gives general authorisation for these sub-processors: Brevo (email delivery, EU), Stripe (payment processing), Backblaze (encrypted backups, EU region) and Google (only the sign-in feature, if a user chooses it). Attenova imposes on each sub-processor, by contract, the same data protection obligations as in this DPA. We announce changes to this list in advance; in case of objection the organisation can terminate the agreement and export its data.

5. Audit

On request, Attenova makes reasonable information available to demonstrate compliance with this DPA. An on-site audit is possible at most once a year, by appointment, at the organisation's expense, and without access to other customers' data.

6. Termination

Upon termination, the organisation can export its data. On request, Attenova permanently deletes all of the organisation's personal data within a reasonable period after termination, subject to statutory retention obligations; backups then rotate out automatically.

← Back to the home page