Data Processing Agreement

Symplio Time & Attendance Platform — Version 1.1 — 29 June 2026

This DPA forms part of the agreement between Symplio and the Customer and is accepted at account creation. It governs the processing of personal data by Symplio on behalf of the Customer in accordance with the GDPR (Regulation (EU) 2016/679).

Parties

Processor: Symplio, established in Portugal, with tax and VAT number (NIPC): PT519140672 — support@symplio.eu
Controller: The Customer subscribing to and using the Symplio platform.

1. Purpose

This DPA defines the terms under which Symplio processes personal data on behalf of the Customer in connection with the Symplio time & attendance platform — a cloud-based workforce management solution covering time registration, attendance, working schedules, leave administration and workforce records. The Customer determines the purposes and means of processing (controller); Symplio processes only on its behalf (processor).

2. Processing Instructions

Symplio processes personal data only:

Symplio does not sell, rent or use customer personal data for independent commercial purposes. If Symplio is required by applicable law to process personal data beyond the Customer's instructions, it will notify the Customer before doing so unless prohibited by law.

3. Sub-processors

Symplio uses third-party technology providers that may process personal data on its behalf. The current list is available at symplio.eu/subprocessors.

When Symplio intends to add or replace a sub-processor, it will notify the Customer at least 14 days in advance by updating the sub-processors page and notifying subscribed customers by email. The Customer may object to a new sub-processor within 14 days of notification by emailing support@symplio.eu with the reason for objection. If Symplio cannot reasonably accommodate the objection and proceeds with the sub-processor change, the Customer is entitled to terminate the subscription without penalty within 30 days of Symplio's final decision.

4. Categories of Data Subjects

5. Categories of Personal Data

Identity information

Employment information

Technical information

Note on special categories (Article 9 GDPR)

The Symplio platform is not designed to process special categories of personal data. However, absence records entered by the Customer may incidentally include health-related information (e.g. sick leave codes). The Customer, as controller, is solely responsible for ensuring a valid legal basis under Article 9(2) GDPR exists for any such data entered into the platform, and for informing employees accordingly. Symplio processes such data solely on the Customer's documented instructions.

6. Hosting and Storage Location

Customer data is stored primarily in the European Union (Frankfurt, EU-Central region) via Symplio's infrastructure provider Supabase. Symplio applies measures to ensure separation of customer environments, controlled access, secure authentication and protection against unauthorised access. See the sub-processors page for full details of infrastructure providers and data locations.

7. Security Measures

8. Audit Rights

Audit requests will normally be satisfied through the provision of documentation, security questionnaires, certifications, and available third-party audit reports.

Only where such information is insufficient to verify compliance may the Customer request an audit, provided that:

The Customer shall bear its own audit costs unless the audit identifies a material non-compliance by Symplio with this DPA or applicable data protection law.

9. Customer Responsibilities

10. Data Subject Rights

Symplio reasonably assists Customers with employee requests regarding access, correction, deletion, restriction and portability. Requests should normally be handled by the Customer as data controller through the admin panel. Where direct technical assistance is required from Symplio, the Customer should submit a request to support@symplio.eu.

11. Data Breaches

If Symplio becomes aware of a personal data breach affecting customer data, it will:

12. Retention and Deletion

The Customer is responsible for determining the applicable retention periods for Customer Personal Data in accordance with applicable law. Symplio shall retain Customer Personal Data only for the duration instructed by the Customer, unless a longer retention period is required by law. Upon termination of the Services, Customer Personal Data shall be deleted or anonymised within 30 days, unless otherwise instructed by the Customer or required by applicable law.

13. Sub-processor Management

Symplio remains responsible for ensuring that sub-processors provide appropriate data protection measures equivalent to those in this DPA, and may update the list of sub-processors when necessary to operate the platform, subject to the notification procedure in Article 3.

14. International Transfers

Symplio primarily stores Customer Personal Data within the European Economic Area (EEA).

Where personal data is transferred to, accessed from, or otherwise processed outside the EEA, Symplio shall ensure that appropriate safeguards are implemented in accordance with Chapter V GDPR, including:

Certain approved sub-processors may process, store or access personal data outside the EEA in connection with the provision of infrastructure, hosting, security, communication, content delivery, support or payment services.

Details of sub-processors, processing locations and applicable transfer safeguards are maintained on the Sub-processors Page and may be updated from time to time.

15. Confidentiality

Persons authorised by Symplio to access customer personal data are bound by contractual confidentiality obligations and have received appropriate data protection training.

16. Term

This DPA remains valid as long as Symplio processes personal data on behalf of the Customer. It is accepted at account creation and applies from the date of account activation.

17. Contact and DPO

Privacy contact: support@symplio.eu