Data Processing Agreement
Symplio Time & Attendance Platform — Version 1.1 — 29 June 2026
Parties
Processor: Symplio, established in Portugal, with tax and VAT number (NIPC): PT519140672 — support@symplio.eu
Controller: The Customer subscribing to and using the Symplio platform.
1. Purpose
This DPA defines the terms under which Symplio processes personal data on behalf of the Customer in connection with the Symplio time & attendance platform — a cloud-based workforce management solution covering time registration, attendance, working schedules, leave administration and workforce records. The Customer determines the purposes and means of processing (controller); Symplio processes only on its behalf (processor).
2. Processing Instructions
Symplio processes personal data only:
- to provide the Symplio services as described in the Terms & Conditions;
- according to documented instructions from the Customer;
- as necessary to maintain, secure and improve the platform.
Symplio does not sell, rent or use customer personal data for independent commercial purposes. If Symplio is required by applicable law to process personal data beyond the Customer's instructions, it will notify the Customer before doing so unless prohibited by law.
3. Sub-processors
Symplio uses third-party technology providers that may process personal data on its behalf. The current list is available at symplio.eu/subprocessors.
When Symplio intends to add or replace a sub-processor, it will notify the Customer at least 14 days in advance by updating the sub-processors page and notifying subscribed customers by email. The Customer may object to a new sub-processor within 14 days of notification by emailing support@symplio.eu with the reason for objection. If Symplio cannot reasonably accommodate the objection and proceeds with the sub-processor change, the Customer is entitled to terminate the subscription without penalty within 30 days of Symplio's final decision.
4. Categories of Data Subjects
- Employees
- Contractors
- Temporary workers
- Administrators
- Other authorised platform users
5. Categories of Personal Data
Identity information
- Name, email address, username, employee identifier.
Employment information
- Working hours, start and end times, breaks, attendance records, leave balances, absence records (including sick leave), work schedules, contract-based working information.
Technical information
- Login records, IP addresses, device information, security logs.
Note on special categories (Article 9 GDPR)
The Symplio platform is not designed to process special categories of personal data. However, absence records entered by the Customer may incidentally include health-related information (e.g. sick leave codes). The Customer, as controller, is solely responsible for ensuring a valid legal basis under Article 9(2) GDPR exists for any such data entered into the platform, and for informing employees accordingly. Symplio processes such data solely on the Customer's documented instructions.
6. Hosting and Storage Location
Customer data is stored primarily in the European Union (Frankfurt, EU-Central region) via Symplio's infrastructure provider Supabase. Symplio applies measures to ensure separation of customer environments, controlled access, secure authentication and protection against unauthorised access. See the sub-processors page for full details of infrastructure providers and data locations.
7. Security Measures
- Encryption of data in transit (TLS 1.2+) and at rest at the infrastructure level.
- Secure authentication, including password reset and email confirmation flows.
- Role-based access control (admin, manager, employee) with database-enforced row-level security.
- Tenant/customer data separation enforced per row at the database layer.
- Backup procedures and access monitoring through the audit log.
- Access to customer personal data is limited to authorised personnel on a need-to-know basis.
- Regular review and testing of security measures.
8. Audit Rights
Audit requests will normally be satisfied through the provision of documentation, security questionnaires, certifications, and available third-party audit reports.
Only where such information is insufficient to verify compliance may the Customer request an audit, provided that:
- (a) the Customer gives at least 30 days' prior written notice;
- (b) audits are conducted during normal business hours;
- (c) audits occur no more than once in any 12-month period, unless required following a personal data breach, security incident, or regulatory request;
- (d) the Customer and any appointed auditor are subject to appropriate confidentiality obligations;
- (e) the audit does not unreasonably interfere with Symplio's business operations, security measures, or service availability;
- (f) the audit does not provide access to personal data or confidential information relating to other customers;
- (g) the scope of the audit is limited to systems, records, policies, and processes relevant to the Services and Symplio's obligations under this DPA.
The Customer shall bear its own audit costs unless the audit identifies a material non-compliance by Symplio with this DPA or applicable data protection law.
9. Customer Responsibilities
- Having a lawful basis for processing employee personal data.
- Informing employees about the use of Symplio and the processing of their data.
- Configuring access rights correctly within the platform.
- Ensuring entered data is accurate and limited to what is necessary.
- Complying with applicable employment legislation.
- Ensuring a valid Article 9(2) GDPR basis if special categories of data are entered.
10. Data Subject Rights
Symplio reasonably assists Customers with employee requests regarding access, correction, deletion, restriction and portability. Requests should normally be handled by the Customer as data controller through the admin panel. Where direct technical assistance is required from Symplio, the Customer should submit a request to support@symplio.eu.
11. Data Breaches
If Symplio becomes aware of a personal data breach affecting customer data, it will:
- notify the Customer without undue delay and in any event within 24 hours of becoming aware of the breach;
- investigate the breach and take reasonable corrective actions;
- provide the Customer with sufficient information to enable it to meet its own 72-hour notification obligation to the competent supervisory authority under Article 33 GDPR, including the nature of the breach, categories and approximate number of data subjects affected, categories and approximate number of records affected, likely consequences, and measures taken.
12. Retention and Deletion
The Customer is responsible for determining the applicable retention periods for Customer Personal Data in accordance with applicable law. Symplio shall retain Customer Personal Data only for the duration instructed by the Customer, unless a longer retention period is required by law. Upon termination of the Services, Customer Personal Data shall be deleted or anonymised within 30 days, unless otherwise instructed by the Customer or required by applicable law.
13. Sub-processor Management
Symplio remains responsible for ensuring that sub-processors provide appropriate data protection measures equivalent to those in this DPA, and may update the list of sub-processors when necessary to operate the platform, subject to the notification procedure in Article 3.
14. International Transfers
Symplio primarily stores Customer Personal Data within the European Economic Area (EEA).
Where personal data is transferred to, accessed from, or otherwise processed outside the EEA, Symplio shall ensure that appropriate safeguards are implemented in accordance with Chapter V GDPR, including:
- adequacy decisions adopted by the European Commission;
- Standard Contractual Clauses (SCCs);
- the EU-U.S. Data Privacy Framework, where applicable; or
- other lawful transfer mechanisms recognised under applicable data protection law.
Certain approved sub-processors may process, store or access personal data outside the EEA in connection with the provision of infrastructure, hosting, security, communication, content delivery, support or payment services.
Details of sub-processors, processing locations and applicable transfer safeguards are maintained on the Sub-processors Page and may be updated from time to time.
15. Confidentiality
Persons authorised by Symplio to access customer personal data are bound by contractual confidentiality obligations and have received appropriate data protection training.
16. Term
This DPA remains valid as long as Symplio processes personal data on behalf of the Customer. It is accepted at account creation and applies from the date of account activation.
17. Contact and DPO
Privacy contact: support@symplio.eu