GDPR Compliance

Last updated: September 2, 2026

KpiClock is committed to supporting our Customers' compliance with the EU General Data Protection Regulation (GDPR) and the UK GDPR. This page summarizes how we approach GDPR compliance.

1. Our Role

For personal data relating to a Customer's End Users (employees, contractors, or team members) processed through the Service — such as time tracking, attendance, activity, screenshot, and document-signing data — the Customer acts as the data Controller, and KpiClock acts as the data Processor, processing that data only on the Customer's documented instructions.

For personal data relating to the Customer's own account (such as billing and contact details), KpiClock acts as an independent Controller, as described in our Privacy Policy.

2. Data Processing Agreement

We offer a Data Processing Agreement (DPA) to all Customers, covering the obligations required under Article 28 of the GDPR, including confidentiality, security measures, sub-processor management, data subject request assistance, breach notification, and international transfer safeguards.

3. Legal Bases for Processing

Where KpiClock processes personal data as a Controller, we rely on legal bases including performance of a contract, legitimate interests, legal obligation, and consent where required. Where KpiClock processes End User data as a Processor, the applicable legal basis is determined by the Customer.

4. International Data Transfers

Where personal data is transferred outside the European Economic Area, the United Kingdom, or Switzerland, we put appropriate safeguards in place, such as Standard Contractual Clauses (SCCs), consistent with our Data Processing Agreement.

5. Data Subject Rights

Individuals have rights under the GDPR, including the right to access, rectify, erase, restrict, or port their personal data, and to object to certain processing. End Users should generally direct these requests to the employer/Customer that manages their workspace, as the Customer determines how that data is used; KpiClock provides reasonable assistance to Customers in responding to such requests, and can also be contacted directly at info@kpiclock.com.

6. Data Minimization and Retention

We collect only the categories of personal data reasonably necessary to provide the Service and retain it in line with the retention periods described in our Privacy Policy, after which it is deleted or anonymized, except where longer retention is required by law or requested by the Customer's plan.

7. Security Measures

Technical and organizational measures we maintain to protect personal data — including encryption, access controls, and 2FA — are described on our Security page.

8. EU Representative

[If applicable, insert the name and contact details of your EU/UK representative appointed under Article 27 GDPR / UK GDPR here.]

9. Contact Our Data Protection Team

For questions about our GDPR compliance or to exercise your data protection rights, contact us at info@kpiclock.com.