Data Processing Agreement

Effective from 2026-09-12

This Data Processing Agreement (DPA) forms part of the Tivero Terms of Service. It governs how the Provider processes personal data on the Customer’s behalf, as required by Article 28 of the General Data Protection Regulation (GDPR).

1. Parties and roles

The Customer — the business that accepted the Terms of Service — is the controller of personal data it enters into its workspace (Customer Personal Data).

The Provider, Convertin OÜ, a company registered in Estonia — register: Estonian Commercial Register (Äriregister), registry code 14814025, VAT number EE102244560, registered address Harju maakond, Tallinn, Kesklinna linnaosa, Tornimäe tn 3 // 5 // 7, 10145, Estonia, is the processor of Customer Personal Data.

For account, billing and website data the Provider acts as an independent controller, as described in the Privacy Policy. This DPA does not apply to that processing.

2. Documented instructions

The Provider processes Customer Personal Data only on the Customer’s documented instructions. The Terms of Service, this DPA, and the Customer’s configuration and use of the service constitute those instructions.

The Provider informs the Customer if, in its opinion, an instruction infringes data protection law, and is not obliged to carry out such an instruction.

Where Union or Member State law requires processing beyond the instructions, the Provider informs the Customer before processing unless that law prohibits it.

3. Details of processing

The subject matter, duration, nature and purpose of processing, and the categories of data and data subjects, are set out in Annex 1.

4. Confidentiality

The Provider ensures that persons authorised to process Customer Personal Data are bound by confidentiality, whether contractual or statutory.

5. Security

The Provider implements the technical and organisational measures described in Annex 2, taking into account the state of the art, the costs of implementation, and the nature, scope, context and purposes of processing and the risks to data subjects (GDPR Art. 32).

The Provider may change those measures provided the overall level of protection is not reduced.

6. Subprocessors

The Customer grants the Provider general written authorisation to engage subprocessors necessary to provide the service. The current list of subprocessors that process Customer Personal Data is section 1 of the list published at /subprocessors. Providers listed there only for the Provider’s own processing as a controller are not subprocessors under this DPA, and the notice and objection process below does not apply to them.

The Provider informs the Customer of any intended addition or replacement of a subprocessor that processes Customer Personal Data by updating section 1 of that list and by email to the workspace owner, at least 14 days before the change takes effect, save where an urgent change is required to maintain the security or continuity of the service, in which case the Provider informs the Customer as soon as possible.

The Customer may object on reasonable data-protection grounds within that period. If the parties cannot agree a solution, the Customer may terminate the affected service before the new subprocessor begins processing, without a termination fee.

The Provider imposes on each subprocessor data protection obligations equivalent to those in this DPA and remains responsible to the Customer for the subprocessor’s performance (GDPR Art. 28(4)).

7. International transfers

The primary application database, backups and object storage holding Customer Personal Data are hosted by Microsoft Azure in the European Union, in the Poland Central region.

Certain subprocessors listed at /subprocessors — in particular for authentication and email delivery — process limited Customer Personal Data outside the European Economic Area. Not every copy and not every processing operation therefore takes place in the European Union.

Where a subprocessor processes Customer Personal Data outside the European Economic Area, the transfer relies on a mechanism under Chapter V GDPR, in particular the European Commission’s standard contractual clauses or an adequacy decision.

8. Assistance with data subject requests

Taking into account the nature of processing, the Provider assists the Customer by appropriate technical and organisational measures in responding to requests from data subjects exercising their rights.

The service provides the Customer with data export and deletion of accounts and workspaces. If a data subject contacts the Provider directly about Customer Personal Data, the Provider forwards the request to the Customer without undue delay and does not respond on the merits unless instructed.

9. Personal data breaches

The Provider notifies the Customer without undue delay after becoming aware of a personal data breach affecting Customer Personal Data.

The notification includes, as far as then known: the nature of the breach, the categories and approximate number of data subjects and records concerned, the likely consequences, and the measures taken or proposed. Information may be provided in phases.

10. Impact assessments and prior consultation

Taking into account the nature of processing and the information available to it, the Provider assists the Customer with data protection impact assessments and prior consultation with a supervisory authority (GDPR Art. 35–36).

11. Audits and information

The Provider makes available to the Customer the information necessary to demonstrate compliance with Article 28 GDPR.

The Customer may audit that compliance, including by inspection, on reasonable prior notice, subject to confidentiality and to avoiding disruption to the service and other customers. An audit is normally limited to once in any 12-month period, unless a supervisory authority requires otherwise or a personal data breach justifies it. Each party bears its own costs.

12. Return and deletion

During the agreement the Customer can export Customer Personal Data using the service’s export functions, described at /legal/data-portability.

After the agreement ends, the workspace remains available in read-only mode for export until the Customer requests deletion. Deletion is staged: a request, a 30-day grace period during which access is cut off and the deletion can still be cancelled, and then permanent deletion from active systems.

Database backups expire automatically after 14 days; residual copies within that window are protected and are not restored to production except to recover the service.

Where the Customer switches provider under the Terms of Service, the transitional, retrieval and erasure periods set out there apply instead.

The Provider may retain data where Union or Member State law requires it.

13. Customer obligations

The Customer is responsible for the lawfulness of the processing it instructs, including having a legal basis and informing data subjects.

The Customer does not use the service to store medical documentation or descriptions of a person’s health; the service records the fact of a health-related absence as a distinct type whose details are not shown to the whole team and are not named in outbound notifications.

14. Liability and order of precedence

Liability between the parties under this DPA is governed by the limitation of liability section of the Terms of Service, to the extent permitted by mandatory law. That section does not limit either party’s liability towards data subjects or supervisory authorities where that liability arises under mandatory law.

In the event of a conflict concerning the processing of Customer Personal Data, this DPA prevails over the Terms of Service.

15. Term and governing law

This DPA applies for as long as the Provider processes Customer Personal Data. It is governed by the law that governs the Terms of Service, and disputes under it are settled by the court named there.

This DPA is published in English and in Polish. If the versions differ, the English version prevails, subject to mandatory law.

Contact for matters concerning this DPA: hello@tivero.app.

16. Annex 1 — Details of processing

ItemDescription
Subject matterProvision of the Tivero service for managing absences, balances and approvals
DurationThe term of the agreement, plus the return and deletion period described above
NatureStorage, organisation, retrieval, display, calculation, export and deletion
PurposeEnabling the Customer to manage its team’s absences, balances, approvals and related reporting
Data subjectsThe Customer’s employees, contractors and other users it invites
Categories of dataName, work email, team and role, employment form, absence requests with dates and types, balances, approval decisions and comments, audit records of administrative actions
Special categoriesThe fact of a health-related absence, where the Customer records one; no medical documentation or diagnosis is intended to be processed

17. Annex 2 — Technical and organisational measures

The measures below are those implemented in the production environment at the date of this DPA.

  • Primary database, backups and object storage in the European Union (Microsoft Azure, Poland Central).
  • The production database is not reachable from the public internet; encryption at rest is enabled.
  • Transport encryption: HTTPS enforced, minimum TLS 1.2; unencrypted FTP disabled.
  • Object storage with public access disabled and shared-key access disabled; access by managed identity only.
  • Production secrets held in a key vault with role-based access control and purge protection; grants scoped to individual secrets where supported.
  • Tenant isolation: every data operation is scoped to the workspace, enforced in the data-access layer and checked by an automated guard in the build.
  • Server-side authorisation on every action, based on roles and capabilities.
  • Access requires both a live membership and an active employee profile; revoking either removes access.
  • Audit log of administrative actions, without sensitive content.
  • Health-related absence types are redacted in every view that is not entitled to their details, and in all outbound notifications.
  • Database backups retained for 14 days.
  • Operational logs retained for 30 days in Azure Log Analytics.
  • Production releases only from a commit on the main branch with passing continuous integration, through a controlled release pipeline.
  • Separate isolated tenants for the public demo, which runs on synthetic data and is deleted automatically.