Draft: This is a working version of the data processing agreement. The final, signed version is part of the subscription and must be reviewed legally. Fields between [square brackets] are still to be filled in.
1. Parties and roles
This agreement applies between the customer (the employer, as controller) and Klox, [bedrijfsnaam BV] with company number [KBO-nummer] (as processor). The customer determines the purpose and means of the processing; Klox processes the personal data solely on the customer's instructions.
2. Subject matter, duration, nature and purpose
Klox processes personal data in order to provide time registration: recording clock-ins and clock-outs, building the daily register, tracing corrections, and exporting the inspection file. The processing lasts for the duration of the agreement, plus the statutory retention period.
3. Categories of data subjects and data
Data subjects: the employees and any other staff of the customer who use the service. Data: identification data (name, personnel number, work location), clock-in and clock-out times, corrections with reason and author, and NFC badge data where applicable. No special categories of personal data are processed.
4. Instructions and confidentiality
Klox only processes the data on documented instructions from the customer, unless otherwise required by law. Everyone at Klox with access to the data is bound by confidentiality.
5. Security measures
Klox takes appropriate technical and organisational measures (Article 32 GDPR), including:
- encryption of data in transit;
- strict access control and separation of roles;
- tenant isolation at database level (Row-Level Security) as a safety net;
- append-only storage of raw records, so they cannot be silently overwritten;
- an audit trail that records who did what and when;
- hosting within the European Union.
6. Sub-processors
Klox only engages sub-processors that are necessary to deliver the service, and imposes the same obligations on them. The customer gives general authorisation and is informed of changes, so that they can object. Current sub-processors:
- [hostingprovider] (EU) for hosting the application and the database;
- [email provider] (EU) for sending transactional email, such as invitations and notifications;
- [network/security provider] for the security and availability of the website; it processes network traffic only and does not retain personal data;
- [payment provider] (EU) for processing payments, where applicable.
7. Assistance and data breaches
Klox reasonably assists the customer in responding to requests from data subjects and with its own obligations regarding security and impact assessments. In the event of a personal data breach, Klox informs the customer without undue delay, providing the information the customer needs to comply with its notification obligation.
8. Data location and international transfers
All data is stored and processed within the European Economic Area, specifically in a data centre in Germany. The only exception is the provider that secures and accelerates the website's network traffic: it has servers outside the EEA, but does not retain the personal data. No further transfer outside the EEA takes place.
9. Retention, return and audits
Registrations are kept for at least 5 years and remain exportable for the employee and the inspectorate. At the end of the agreement Klox returns the data or deletes it, at the customer's choice and subject to statutory retention obligations. After the retention period, personal data is anonymised rather than erased, so that the registrations retain their legal evidentiary value without still being traceable to a person.privacy@klox.be.