Legal
Data Processing Agreement
Last updated: 1 August 2026
1. What this is, and when it applies
This agreement covers what we do with personal data that you put into VibaCloud when you use it as a team. It forms part of our Terms of Service and applies automatically from the moment you create a team. There is nothing to sign, though we can provide a countersigned copy on request through our contact page.
It does not apply to people using VibaCloud on their own account for their own work. In that case we are the controller of their data and our Privacy Policy governs it.
2. Roles
When you create a team and invite people to it, you decide who is in it, which of your clients are shared with it, and what you do with the hours and figures you can then see. In data protection terms you are the controller of that data and we are your processor: we hold and process it to provide the service to you, and we do not use it for our own purposes.
Two things sit outside that. Each of your team members remains an individual user of VibaCloud in their own right, and for their own account, their own clients and any work they keep private, we are the controller and our Privacy Policy applies. Separately, we are the controller for our own operational data, such as billing records, support correspondence and security logs.
3. What we will and will not do
We will:
- process the data only to provide the service to you and only on your instructions, which for most purposes means the instructions you give through the product itself;
- tell you if we think an instruction you have given us would break data protection law;
- keep the data confidential, and make sure anyone who has access to it is under a duty of confidence;
- maintain the security measures described in Annex B;
- use sub-processors only as set out in section 5;
- help you respond if one of your people asks for a copy of their data, asks for it corrected, or exercises another right, as described in section 7;
- help you meet your own obligations around security, breach reporting and impact assessments, as described in sections 6 and 8;
- delete or return the data when you stop using the service, as described in section 9; and
- give you the information you reasonably need to satisfy yourself that we are doing all of this, as described in section 8.
We will not sell the data, use it to train models, use it for advertising, or use it to build any product other than the service we provide to you.
4. What you are responsible for
You are responsible for having a lawful basis for asking your staff or contractors to record their working time and for seeing the results, and for telling them that you can. Our Privacy Policy sets out precisely what a team administrator can and cannot see, and the invite page shows a summary of it before anyone accepts, but telling your own people is your job rather than ours.
You are also responsible for the accuracy of what you put in, for who you give administrator access to, and for removing people from the team when they leave your organisation.
5. Sub-processors
You authorise us to use the sub-processors listed in Annex C. Each of them is bound by written terms that are no less protective than this agreement, and we remain responsible to you for what they do.
If we want to add or replace a sub-processor that handles your data, we will give you reasonable advance notice. If you object on reasonable data protection grounds, tell us and we will either find an alternative or you may stop using the affected part of the service.
6. Security
We keep appropriate technical and organisational measures in place to protect the data, taking account of what the data is and what could go wrong. The measures we currently rely on are listed in Annex B. We may change them as the service develops, but not in a way that materially weakens protection.
7. Helping you with individuals' rights
Most of what your people might ask for, they can do themselves: every user can see their own timesheets, correct them while they are in draft, export them, and delete their own account. If you receive a request that you cannot satisfy from the product, contact us and we will help you within a reasonable period and at no charge for ordinary requests.
If one of your people contacts us directly about data that belongs to your team, we will not act on it ourselves. We will tell them to ask you, and let you know they got in touch.
8. Personal data breaches, audits and information
If we become aware of a breach affecting your data, we will tell you without undue delay. We will tell you what we know, what we are doing about it, and what we suggest you do, and we will keep you updated as we learn more. You need to know quickly, because your own deadline to report to the Information Commissioner's Office runs from the point you become aware. Reporting a breach to the Information Commissioner's Office or to the people affected is your decision as controller, and we will give you what you need to make it.
If you need to satisfy yourself that we are meeting this agreement, ask us and we will answer your questions and provide what documentation we have. We are a very small company and do not hold formal certifications such as ISO 27001 or a SOC 2 report, so we would rather tell you that plainly than imply otherwise. If you need an on-site audit, we will discuss a reasonable way to arrange one.
9. Deletion and return
You can export your team's approved time at any time from the team screens, in a spreadsheet, so you are never dependent on us to get your records out.
When you stop using the service, we will delete the data we hold as your processor without undue delay, unless the law requires us to keep something. Copies held in routine backups are removed as those backups age out. Note that deleting a team does not delete your members' individual accounts or their own timesheets, which belong to them rather than to you.
10. International transfers
We will not transfer your data outside the UK, and will not permit a sub-processor to, except where an appropriate safeguard recognised by UK data protection law is in place. If you need the detail of where a particular sub-processor processes data, ask us and we will tell you.
11. General
Where this agreement and our Terms of Service conflict on the handling of personal data, this agreement wins. Everything else in the Terms, including the limits on liability and the governing law, applies here too. If we change this agreement we will revise the date at the top, and we will tell you in advance of any change that materially affects your rights.
Annex A: details of the processing
Subject matter: providing the VibaCloud timesheet service to your team.
Duration: for as long as your team exists, plus the deletion period in section 9.
Nature and purpose: recording and reviewing time worked. In practice: importing calendar events at a user's request, turning them into draft timesheet entries, letting users tag them to your shared clients and projects, letting administrators review, approve or send back submitted weeks, and producing totals, reports and spreadsheet exports from approved and submitted work.
Categories of data subject: your team members, meaning the staff or contractors you invite; and, where a member records work against a client of yours and raises or is included in an invoice, the contact people at that client.
Types of personal data:
- About your team members: name, email address, the identifier from their Microsoft or Google account where they sign in that way, and their time records, meaning dates, hours, descriptions of work, the client and project each entry is tagged to, hourly rates, values, and when they submitted each week.
- Calendar content: the titles, dates, times, durations and category colours of events a member chooses to import. Members choose what to import, and imported events remain personal to them until they tag the resulting entry to one of your shared clients.
- About your clients: business name, billing contact email address, and the contents of invoices raised for the work, including line items and amounts.
Special category data: none is requested or required. Be aware that a free-text description on a timesheet entry, or the title of an imported calendar event, could contain anything a member types or has in their diary. We do not inspect that content, and you should tell your people not to put sensitive personal information in it.
Annex B: security measures
These are the measures actually in place, described honestly rather than aspirationally.
- In transit: all traffic uses HTTPS, enforced with HSTS so browsers refuse an insecure connection.
- Authentication: most users sign in with Microsoft or Google, in which case we never see or hold a password. Where an email and password login is used, the password is stored only as a salted hash using the standard ASP.NET Core Identity hasher. Password reset links are stored only as a hash, are single use, and expire after an hour.
- Provider tokens: the access and refresh tokens that let us read a calendar are held server-side and are never exposed to the browser. Calendar access is read-only: we cannot create, change or delete anything in a user's calendar, and cannot read or send their email.
- Separation between accounts and teams: every database query is scoped to the requesting user, and team visibility is enforced centrally in the application rather than page by page. Work on clients you have not shared with the team is excluded from every team view, export and total, including from the aggregate figures, and work submitted before a member joined your team is excluded as well.
- Uploaded images: business logos and profile photos are served without requiring a sign-in, so their filenames include a random component that makes them impractical to guess. Do not upload anything to those fields that would be sensitive if someone had the link.
- Access by us: production access is limited to the people who run the service, and is used only to deal with a support request, investigate an incident, or where the law requires it.
- Monitoring: application errors are logged and alert us by email so problems are noticed rather than sitting unseen.
- Payment data: we do not hold card details. There is currently no payment processing in the product at all.
If you need detail we have not covered here, such as how storage is encrypted, how backups are taken and retained, or what happens if the service becomes unavailable, ask us and we will tell you what we do rather than guess in a document.
Annex C: sub-processors
- Hosting and database provider: stores and runs the application and its database. We will name it on request.
- Mailjet (Sinch): delivers email we send on your behalf, including team invites, notifications about timesheets being submitted, approved or sent back, and invoices and payment reminders to your clients. Handles recipient addresses and message contents, including the invoice PDF where one is attached.
- Cloudflare: provides the Turnstile check that protects the create-account and password reset forms from automated abuse. Receives the IP address and basic browser information of the person filling in the form.
- Microsoft and Google: provide sign-in and the calendar data a member chooses to import. Where your members use their work accounts, your own agreements with Microsoft or Google also apply to that data.
Contact
Questions about this agreement, or a request for a countersigned copy, can go through our contact page.
