Data processing agreement (AVV)
Version: 15 September 2026Translation — the German version is legally binding.
Agreement on the processing of personal data on behalf of a controller under Art. 28(3) GDPR between the customer purchasing NymTime for its business (hereinafter "controller") and LazyHead e.U., owner Andrii Snikhovskyi, Morizgasse 2/2/14, 1060 Vienna (hereinafter "processor"). It is accepted at purchase on nymtime.com/kaufen together with the terms of service and forms part of the service contract.
1. Subject matter and duration
(1) The processor provides the controller with the NymTime software as a service: rota planning, time tracking with the employee's smartphone at NFC stickers (alternatively QR code or geo-verified clock-in), presence at the location as intervals, recording of rest breaks according to the rule chosen by the controller, absences, availability entries, shift swaps, company announcements (notice board), a working-time account, hours reporting, export for payroll and optionally document storage including access for the employee concerned, payroll documents, revenue figures per location and internal labour cost. In doing so it processes personal data on behalf of the controller.
(2) The duration of this agreement follows the service contract (terms of service, nymtime.com/agb). It ends with the service contract; clause 10 continues to apply until all data has been returned or deleted.
(3) Processing takes place exclusively in data centres within the European Union (Annex 2).
2. Nature and purpose of processing, categories of data and data subjects
(1) The nature and purpose of the processing, the categories of personal data and the categories of data subjects are described in Annex 1. In summary: management of master data, rota, working time records under § 26 AZG, absences, presence intervals at the location, device data, employee messages and — where used by the controller — documents and labour cost figures, each for the purpose of workforce planning, fulfilment of statutory record-keeping duties under labour law and preparation of payroll.
(2) No GPS coordinates, routes or movement profiles are stored. Presence at the location is recorded only as the result "inside", "outside" or "location unavailable" with time and accuracy, only during a shift, and only for employees for whom the controller has filed a legal basis under § 96(1)(3) ArbVG or § 10 AVRAG.
(3) The absence reason "sick leave" is recorded without diagnosis and without details of the cause of illness. Beyond that, special categories of personal data under Art. 9 GDPR are the subject of the processing only where the controller uses the feature "sick note": the confirmation of the start and expected duration of incapacity for work is health data. The controller may file it only to the extent that it may request it under § 4 of the Austrian Continued Remuneration Act (EFZG), § 8(8) of the Salaried Employees Act (AngG) or § 17a(7) of the Vocational Training Act (BAG); the legal basis is Art. 9(2)(b) GDPR in conjunction with those provisions and Art. 88 GDPR. The processor limits access to these documents to the persons authorised for this by the controller and to the employee concerned and does not evaluate their content. The controller ensures that no diagnoses and no further health data are stored in free-text fields or other documents.
(4) In addition the processor processes on the controller's behalf: availability entries of employees (voluntary information for planning; neither stand-by nor on-call duty within the meaning of the AZG, no claim to pay), offers and acceptances in shift swaps (colleagues at the same location with the same role see the name, the role or department and the times of the shift concerned — no presence or performance data), the contact details an employee has released for colleagues (consent under Art. 6(1)(a) GDPR, default off, withdrawal at any time under Art. 7(3) GDPR taking immediate effect in the application), read receipts for company announcements (notice board), and the recorded rest breaks and short breaks together with the note "break not recorded". That note serves solely to correct the record under § 26 AZG and is neither a sanction nor a performance assessment; the correction is made by a person of the controller with a reason.
(5) Revenue figures per location that the controller enters or imports for key figures relate to the location and not to persons and are not personal data in themselves; they are evaluated only together with labour costs, which are accessible exclusively to the controller's management.
3. Instructions of the controller (Art. 28(3)(a))
(1) The processor processes personal data only on documented instructions from the controller unless required to do so by Union or Austrian law; in that case the processor informs the controller of that legal requirement before processing, unless that law prohibits such information.
(2) Instructions are given through the configuration in the Back Office — in particular locations and location area, roles and permissions, the break rule per location, the deadline for availability entries, whether shift swaps require approval, the visibility of documents to employees, retention periods, activation of the presence check per employee, enablement of support access (Settings → Subscription → Support access), export and deletion — and in writing to office@nymtime.com, for which an e-mail suffices (form agreed under § 886 ABGB). The controller determines which of its users are authorised to give instructions (role management).
(3) If the processor considers an instruction to be unlawful under data protection law, it informs the controller without delay and may suspend execution until the instruction is confirmed or changed.
4. Confidentiality (Art. 28(3)(b))
(1) The processor ensures that all persons authorised to process the data have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality, and that this obligation continues after the end of their activity.
(2) In normal operation the processor does not access the content of the customer account. Support access is only possible if the controller explicitly enables it in the Back Office — with scope, duration and revocation at any time. Every access is recorded with time, person and action in the controller's audit log.
5. Security of processing (Art. 28(3)(c), Art. 32)
(1) The processor implements the technical and organisational measures described in Annex 3 and maintains them for the entire duration of the contract. It reviews them regularly and adapts them to the state of the art.
(2) The processor may develop the measures further and replace them with equivalent ones provided the level of protection is not reduced. Material changes are documented in Annex 3 and shown to the controller in the Back Office.
6. Sub-processors (Art. 28(2) and (4), (3)(d))
(1) The controller gives general authorisation for the use of the sub-processors listed in Annex 2. A contract is in place with each sub-processor imposing on it the same data protection obligations as this agreement imposes on the processor.
(2) If the processor intends to engage or replace a sub-processor, it informs the controller at least 30 days in advance by e-mail and in the Back Office. The controller may object within this period on important data protection grounds; if no agreement is reached, either party may terminate the service contract to the end of the current month.
(3) Personal data is transferred to a third country outside the European Economic Area only if the requirements of Art. 44 to 49 GDPR are met (adequacy decision or standard contractual clauses under Art. 46(2)(c) GDPR). The processor is liable for sub-processors as for its own conduct.
7. Assistance with data subject rights (Art. 28(3)(e))
(1) The processor assists the controller by appropriate technical and organisational measures in responding within the statutory periods to requests by data subjects for access, rectification, erasure, restriction, data portability and objection (Art. 15 to 22 GDPR).
(2) The product provides for this: viewing and monthly export of the employee's own time records in the employee app (§ 26(8) AZG, Art. 15 and 20 GDPR); export of all data of an employee from the Back Office; corrections with a log; archiving, anonymisation and deletion according to retention periods.
(3) If a data subject addresses a request directly to the processor, the processor forwards it to the controller without delay and does not answer it itself unless instructed to do so by the controller.
8. Notification of personal data breaches (Art. 28(3)(f), Art. 33)
(1) The processor notifies the controller of any personal data breach without undue delay and at the latest 48 hours after becoming aware of it, by e-mail to the contact person's address. The notification contains the information under Art. 33(3) GDPR: nature of the breach, categories and approximate number of data subjects and records concerned, likely consequences, measures taken and proposed, and a contact point.
(2) The processor assists the controller with the notification to the supervisory authority within 72 hours (Art. 33) and with the communication to data subjects (Art. 34) and documents all breaches including their effects and the remedial action taken.
9. Data protection impact assessment and prior consultation (Art. 28(3)(f), Art. 35 and 36)
(1) Systematic recording of employee presence may require a data protection impact assessment under Art. 35(3)(a) GDPR. The processor provides the controller with a template data protection impact assessment for NymTime and the technical information on the product, and assists with any prior consultation of the supervisory authority (Art. 36).
(2) Carrying out the data protection impact assessment for its own deployment and concluding a works agreement (§ 96(1)(3) ArbVG) or obtaining consent (§ 10 AVRAG) are the controller's responsibility.
10. Deletion and return after the end of the contract (Art. 28(3)(g))
(1) After termination of the service contract the controller may export its data completely from the Back Office for 30 days (Excel, CSV, documents in their original format). After this period the processor deletes all personal data of the controller unless Union or Austrian law obliges the processor itself to store it; in that case processing is restricted to storage. The controller's own retention duties (in particular § 26 AZG, § 132 BAO) remain its own responsibility (§ 14(3) of the terms of service); it fulfils them by exporting in good time.
(2) Deletion is confirmed to the controller in writing on request. Backups are overwritten no later than 35 days after deletion of the primary data.
(3) During the contract the controller may archive, anonymise or delete individual employees and set the retention periods per data type itself within the statutory minimums. A daily job applies the periods and logs the number and data type of deleted records.
11. Evidence and audits (Art. 28(3)(h))
(1) The processor makes available to the controller all information necessary to demonstrate compliance with the obligations laid down in Art. 28 GDPR, in particular this agreement, its annexes, the record under Art. 30(2) GDPR and reports on the review of the technical and organisational measures.
(2) The controller or an auditor mandated by it and bound to confidentiality may verify compliance with this agreement after reasonable notice of at least 14 days during usual business hours, at most once per calendar year, unless a personal data breach or an order of the supervisory authority requires a further audit. The processor contributes to audits.
(3) The processor immediately informs the controller if, in its opinion, an instruction infringes the GDPR or other Union or Austrian data protection provisions.
12. Liability and final provisions
(1) The liability of the parties is governed by Art. 82 GDPR and otherwise by § 15 of the terms of service. As between the parties, each party is liable for breaches of the obligations incumbent on it under this agreement and the GDPR.
(2) Austrian law applies, excluding its conflict-of-law rules. As the exclusive place of jurisdiction the parties agree, under § 104 of the Austrian Jurisdiction Act (JN) — and, for controllers domiciled in another member state, additionally under Art. 25 of Regulation (EU) No 1215/2012 (Brussels Ia) — on the court with subject-matter jurisdiction for Vienna, Inner City. Amendments and additions to this agreement must be made in writing; for this the parties agree on a relaxed form under § 886 ABGB, an e-mail to the address on file suffices. This also applies to the waiver of this requirement.
(3) The electronic acceptance of this agreement at purchase — with time, version, checksum of the document, IP address and user — is recorded in the customer account and constitutes conclusion in electronic form within the meaning of Art. 28(9) GDPR. In case of conflict between this agreement and the terms of service, this agreement prevails in data protection matters.
Annex 1 — Subject of processing: data categories, data subjects, purposes
Categories of personal data (per category: data — purpose — legal basis of the controller):
- Master data: name, e-mail address, telephone number, position, role, location assignment, personnel number, type of employment, start and end date, weekly hours — administration, rota, billing — Art. 6(1)(b) and (c) GDPR.
- Rota: planned shifts, roles, minimum staffing, open shifts — workforce planning — Art. 6(1)(b) GDPR.
- Availability: entry per day or half-day ("available", "would rather not", "not available"), time of entry — voluntary information for planning, neither stand-by nor on-call duty within the meaning of the AZG — Art. 6(1)(b) GDPR.
- Shift swaps: offer, responses from colleagues at the same location with the same role (visible to them: name, role or department, times of the shift), decision of the manager, result of the working-time limit check — workforce planning — Art. 6(1)(b) GDPR.
- Contact release (Contacts): flag whether the employee has made their phone number and e-mail address visible to colleagues at the same location, with the time it was given and of any withdrawal — reachability within the team — consent under Art. 6(1)(a) GDPR, default off, withdrawal at any time under Art. 7(3) GDPR.
- Company announcements (notice board): text, audience, validity, read receipt per employee with time — evidence that company information was acknowledged — Art. 6(1)(b) and (f) GDPR; not performance monitoring.
- Working time records: actual start and end, rest breaks (§ 11 AZG, unpaid) and short breaks together with the flag "break not recorded", clock-in method (NFC, QR, geo-verified), working-time account balance within the averaging period, corrections with reason and editor — § 26 AZG — Art. 6(1)(c) GDPR.
- Absences: type (holiday, sick leave, time off in lieu, care leave, public holiday, special leave, training, unpaid), period, status, editor; sick leave without diagnosis — rota, continued remuneration — Art. 6(1)(b) and (c) GDPR.
- Presence at the location: intervals "inside", "outside", "location unavailable" with time and accuracy in metres; no coordinates, no routes — evidence of presence during the shift — § 96(1)(3) ArbVG (works agreement) or § 10 AVRAG (consent), Art. 88 GDPR.
- Device data: device identifier, public key, model and operating system version, status (active, replaced, blocked), time of registration — one device per person, anti-forgery — Art. 6(1)(f) GDPR.
- Employee messages: "running late", "not today", free text to the business — organisation of the shift — Art. 6(1)(b) GDPR.
- Documents (optional): social insurance registration (§ 33 ASVG), written statement of terms (Dienstzettel, § 2 AVRAG), employment contract, certificates with any expiry date, documents requested by the business and uploaded by the employee, payslips and annual payslips (L16) including automatically suggested fields with review flag, each with the flag whether the document is visible to the employee concerned in the app — personnel file, preparation of payroll — Art. 6(1)(c) GDPR, § 132 BAO, ASVG. Retention follows the data type "employee documents".
- Sick note (optional): start and expected duration of the incapacity for work without diagnosis — evidence of sick leave and continued remuneration — health data, Art. 9(2)(b) GDPR in conjunction with § 4 EFZG, § 8(8) AngG or § 17a(7) BAG; access only for the persons authorised by the controller and for the employee concerned. Retention follows the data type "employee documents".
- Labour cost (optional, visible to management only): hourly rate, supplements, advances, adjustments with history — internal calculation — Art. 6(1)(f) GDPR.
- Revenue figures per location (optional): daily revenue and target value — key figure labour cost ratio — not personal data; evaluated only together with labour costs.
- Logs: audit log (who, what, when, before/after), notifications — accountability, security — Art. 5(2) and Art. 32 GDPR.
- Categories of data subjects: employees, freelance contractors, temporary agency workers, interns and apprentices of the controller. Back Office users (management, managers, tax adviser) and the controller's contact person are not covered by this agreement; for their data the processor is itself the controller (privacy policy, sections 6 and 7).
- Purposes: workforce planning; fulfilment of the record-keeping duty under § 26 AZG including rest breaks under § 11 AZG; evidence of presence during the shift; management of absences; organisation of availability, shift swaps and company announcements; filing and provision of personnel documents; preparation of payroll; security and traceability of the system.
- Retention (Austrian defaults, adjustable by the controller within the minimums): working time records 84 months (minimum 12 months, § 26 AZG; § 132 BAO); raw presence events 3 months; messages 12 months; audit log 84 months (minimum 12 months); employee documents (data type "employee_documents", including uploaded evidence and sick notes) 84 months; payroll documents 84 months (minimum 84 months, § 132 BAO); labour cost 84 months; notifications 6 months; archived employee profiles 84 months, then anonymisation. Availability entries, swap records and read receipts are deleted together with the corresponding rota or announcement, at the latest after 12 months.
Annex 2 — Authorised sub-processors
As of 15 September 2026. The processor uses the following sub-processors; the current list can be viewed in the Back Office under Settings → Subscription.
- Hosting (servers, database, file storage, backups): data centre in the EU — the provider will be added here with company, seat and data centre location before the production system goes live. Safeguard: data processing agreement under Art. 28 GDPR; no processing outside the EU.
- E-mail delivery (invitations, notifications, invoices): provider with processing in the EU — the provider will be added here with company, seat and region before the production system goes live. Safeguard: data processing agreement under Art. 28 GDPR.
- Automatic field recognition in documents (only if the controller activates this feature): provider with processing in the EU, no use of the data for training purposes — will be added here before the feature is activated; until then the feature is disabled.
- Address search in the Back Office (suggestions while a location address is entered): Komoot GmbH, Hauptstraße 35, 12159 Berlin, Germany (Photon service, servers in the EU; data source OpenStreetMap, ODbL 1.0). Only the typed address text is transmitted; the request is made by our server, not by the browser. No employee data is transmitted. Fallback in case of an outage: Nominatim of the OpenStreetMap Foundation, St John’s Innovation Centre, Cowley Road, Cambridge CB4 0WS, United Kingdom — a data processing agreement cannot be concluded with the foundation; the service receives only the address text and is queried only as a fallback.
For completeness — independent controllers, not sub-processors: European Commission, Rue de la Loi 200, 1049 Brussels, Belgium (confirmation of the controller’s VAT identification number in the VAT Information Exchange System VIES; only the country code and the VAT ID are transmitted, legal basis Art. 6(1)(c) GDPR in conjunction with § 11(1a) UStG 1994; no employee data), Stripe Payments Europe, Ltd., 1 Grand Canal Street Lower, Grand Canal Dock, Dublin 2, Ireland (payment processing, invoicing and subscription management for the controller as a customer; transfers to Stripe, Inc. (USA) under the EU-US Data Privacy Framework and standard contractual clauses) and Österreichische Post AG, Rochusplatz 1, 1030 Vienna, or a courier service (delivery of the NFC stickers to the business or delivery address; receives shipping data only: company, contact person, address, telephone number where applicable). None of these recipients processes data of the controller's employees.
Annex 3 — Technical and organisational measures (Art. 32 GDPR)
The processor implements in particular the following measures:
- Physical and system access control: operation exclusively in data centres in the EU; physical access control and ISO 27001 certification are requirements placed on the hosting provider, which will be named here before go-live; administrative access only via personal accounts with SSH keys, two-factor authentication for the management console likewise a requirement placed on the hosting provider; no shared accounts.
- Access control in the product: role- and permission-based authorisation (management, manager, employee, further roles with individual permissions), managers restricted to assigned locations; payroll and labour cost data for management only; sick notes only for the persons authorised for this and for the employee concerned; sign-in to the Back Office via personal accounts with the e-mail address as the user name and a password stored exclusively as a hash with a random salt (scrypt) — password set through a one-time link (valid 24 hours), reset through a one-time link (valid 1 hour), confirmation of a new e-mail address by a code sent to the new address, lockout for 15 minutes after 10 failed attempts, termination of all existing sessions on every password change, session cookie expiring after 14 days, optional two-factor authentication (TOTP app, enabled organisation-wide by the controller, recovery codes stored only as hashes, TOTP secret stored encrypted); activation of the employee app by a one-time code sent to the registered e-mail address (limited validity, at most 5 attempts, requests limited per address and IP address); accesses are logged.
- Device binding: exactly one active device per employee; cryptographic key pair in the device's secure storage; every clock-in is signed by the device; a new device is bound only after confirming an e-mail code and proving presence at the location (NFC sticker or location check) — the previous device is locked automatically, the business is notified and the change is logged; the business can lock a device at any time.
- NFC stickers: NTAG 424 DNA with a dynamic, cryptographically verified message (Secure Unique NFC) and counter check against copying and replay; QR codes with a location-bound code and check of the location zone.
- Data minimisation: no storage of coordinates, routes or photos; presence only as intervals; check only during the shift; presence check per employee only after a legal basis has been filed; raw events are condensed after 3 months.
- Encryption: transmission exclusively over TLS 1.2 or higher; the database resides on a LUKS-encrypted volume (dm-crypt, AES-XTS) at the hosting provider, documents and backups are stored server-side encrypted in object storage (encryption at rest); keys and credentials outside the source code; passwords and login codes stored only as hashes with a random salt.
- Integrity and traceability: immutable audit log (append allowed, modification and deletion prevented by a database rule) for all security-relevant actions; soft delete only, with timestamp; corrections of working time with reason, editor and previous value.
- Availability: daily backups with 35 days' retention on encrypted storage media, restore tests as a requirement placed on the hosting provider, which will be named here before go-live, monitoring with alerting, caching of clock-ins on the device when the connection is lost.
- Separation: logical separation of customer data by organisation key in every query; separate environments for development, testing and production; no production data in test or development environments.
- Retention and deletion: configurable periods per data type with enforced statutory minimums; daily automated deletion and anonymisation job with a log; return and deletion under clause 10.
- Support access: no access by the processor to customer data in normal operation; access only after enablement by the controller with scope, duration and revocation at any time; every access logged.
- Organisation: confidentiality obligations for all persons involved; documented process for data breaches with notification within 48 hours; record of processing activities under Art. 30(2) GDPR; annual review of these measures; security updates within a reasonable period; the principles of data protection by design and by default (Art. 25 GDPR) in the development process.