Skip to content

Effective: 25 September 2026

Polska wersja

Data Processing Agreement

This agreement (“DPA”) meets Article 28 of the General Data Protection Regulation (EU) 2016/679 (“GDPR”). It governs how Binary Brain Technologies sp. z o.o. processes personal data contained in a WorkLog Workspace on behalf of the Workspace Owner. It forms part of the Terms of Service.

1.Parties and acceptance

  • Controller: the Owner of a Workspace — the User who created it or to whom ownership was transferred — or the organisation on whose behalf that User acts (“the Owner”).
  • Processor: the provider of WorkLog:
Company
Binary Brain Technologies sp. z o.o.
Legal form
limited liability company (spółka z ograniczoną odpowiedzialnością)
Registered office
Abramowice Prywatne, Poland
Registry court
Sąd Rejonowy Lublin-Wschód w Lublinie z siedzibą w Świdniku, VI Wydział Gospodarczy Krajowego Rejestru Sądowego
KRS
0001207918
NIP
7133142056
Share capital
PLN 5,000.00

The DPA is concluded electronically and takes effect when a Workspace is created or ownership of it is transferred, and applies for as long as WorkLog processes personal data in that Workspace. An Owner who needs a signed copy can ask at support@worklog.click; its content is this DPA. Where the Owner processes data only for purely personal or household purposes, the GDPR does not apply to that processing and this DPA applies only to the extent the law requires.

2.Subject and duration

The Owner entrusts us with processing the personal data described in section 3 for the purpose of providing WorkLog under the Terms of Service. The processing lasts for the term of the Terms of Service for that Workspace, and ends with deletion under section 11.

3.Nature, purpose and data

Nature of processingStorage, organisation, retrieval, display, calculation (totals, values, budgets), export, transmission to Workspace members, backup, and deletion, by automated means.
PurposeProviding WorkLog to the Owner and the Workspace’s members: recording and reporting work time, managing clients, projects and teams.
Categories of data subjectsWorkspace members and invited people; the Owner’s clients and their contact persons; any other persons the Owner or members mention in content.
Types of personal dataNames and email addresses; roles and membership; time entries (dates, times, durations, descriptions); rates and budgets; timesheet approvals; client contact details entered by the Owner; activity log entries.
Special categoriesNone are intended. The Owner must not store special categories of data (Article 9 GDPR) or data about criminal convictions in WorkLog.

4.Instructions

  • We process the data only on the Owner’s documented instructions, including with regard to transfers to third countries, unless EU or Polish law requires otherwise; in that case we inform the Owner before processing unless the law forbids it.
  • The Owner’s instructions are this DPA, the Terms of Service and the Owner’s (and authorised members’) use and configuration of WorkLog. Further instructions must be given in writing (email is enough) and be consistent with the Service.
  • We inform the Owner immediately if, in our opinion, an instruction infringes the GDPR or other data protection law.

5.Confidentiality

Only people who need access to operate and support WorkLog are authorised to process the data, and each of them is bound by confidentiality, which continues after their work for us ends. We do not access Workspace content except to provide, secure or support the Service, to comply with the law, or at the Owner’s request.

6.Security

We implement the technical and organisational measures required by Article 32 GDPR, taking into account the state of the art, the costs and the risks. The current measures are in the annex. We may update them, provided the overall level of protection does not decrease.

7.Sub-processors

The Owner gives general authorisation to use sub-processors. The current ones are:

Sub-processorServiceLocation of data
Neon, Inc.Database and authentication (Neon Postgres, Neon Auth)AWS eu-central-1, Frankfurt, Germany
Vercel, Inc.Application hosting and content deliveryFrankfurt (fra1); global delivery network
ResendDelivery of sign-in and notification emails (email addresses and email content only)May process in the United States
  • We impose on each sub-processor, by contract, data protection obligations that provide the same level of protection as this DPA, and we remain responsible to the Owner for their performance.
  • We announce an intended addition or replacement of a sub-processor at least 14 days in advance by updating this page and notifying Owners by email or in the app. The Owner may object for reasonable data-protection reasons within that period; if we cannot address the objection, the Owner may end the Terms of Service for the Workspace and export its data first.

8.International transfers

Data is stored in the European Economic Area. Where a sub-processor processes data outside the EEA, the transfer relies on an adequacy decision (including the EU–U.S. Data Privacy Framework where the recipient is certified) or on the Standard Contractual Clauses (Commission Decision (EU) 2021/914), with supplementary measures where needed.

9.Assistance to the Owner

  • Taking into account the nature of the processing, we help the Owner respond to data subjects exercising their rights under Chapter III GDPR. WorkLog provides tools for this: editing and deleting entries, removing members, and CSV and JSON exports. If a data subject writes to us about Workspace data, we pass the request to the Owner without undue delay and do not answer it ourselves unless the Owner instructs us to.
  • We help the Owner meet its obligations under Articles 32–36 GDPR (security, breach notification, data protection impact assessments and prior consultation), taking into account the information available to us.

10.Personal data breaches

We notify the Owner of a personal data breach affecting the Workspace without undue delay, and in any case within 48 hours of becoming aware of it, by email to the Owner’s account address. The notice describes, as far as then known, the nature of the breach, the categories and approximate number of data subjects and records concerned, the likely consequences, and the measures taken or proposed. We supplement it as more information becomes available and take reasonable steps to contain the breach.

11.Deletion and return

The Owner can export the Workspace data at any time. When the Owner deletes the Workspace, or the Terms of Service end for it, we delete the personal data in it, unless EU or Polish law requires us to keep it. Deleted data leaves our database backups within 30 days. On request we confirm the deletion.

12.Information and audits

We make available to the Owner the information necessary to demonstrate compliance with Article 28 GDPR, and allow for and contribute to audits, including inspections, by the Owner or an auditor it mandates. An audit is requested at least 30 days in advance, is limited to what is needed, takes place during business hours without disrupting the Service or other customers’ data, is subject to confidentiality, and is at the Owner’s cost; normally it is carried out first by written questions and our documentation. These limits do not restrict audits by a supervisory authority.

13.The Owner’s obligations

  • The Owner is responsible for having a legal basis for the processing, for informing the data subjects (for example employees and contractors whose time is recorded), and for the lawfulness of its instructions.
  • The Owner controls who is a member of the Workspace and with which role, and is responsible for members’ access.
  • The Owner informs us without delay of any error or irregularity it finds in the processing.

14.Liability and order of precedence

Each party is liable for its breaches of this DPA and of the GDPR in accordance with Article 82 GDPR and the Terms of Service. On matters of personal data protection, this DPA prevails over the Terms of Service. This DPA is governed by Polish law and is available in English and Polish; if the versions differ, the Polish version prevails.

15.Annex: security measures

  • Encryption in transit: HTTPS with HSTS for all traffic; TLS between the application and the database.
  • Encryption at rest: provided by the database provider for all stored data and backups.
  • Tenant isolation: row-level security in the database; each request runs as a restricted database role limited to the signed-in person’s Workspaces, in addition to server-side permission checks.
  • Least privilege: separate database roles for the application and for administration; the application role cannot change the schema or bypass row-level security.
  • Authentication: managed sign-in with Google, GitHub or a verified email address; passwords stored as one-way hashes by the authentication provider; email codes and invitation tokens stored only as hashes and valid for a limited time; the ability to end all other sessions.
  • Roles and permissions: four Workspace roles; money data shown only to roles entitled to it; sensitive changes recorded in an activity log.
  • Application security: content security policy and other security headers; protection against cross-site request forgery; input validation; formula-injection protection in CSV exports.
  • Environments: production data is not used in development or testing environments.
  • Resilience: managed database with point-in-time recovery; the ability to restore from backups.
  • Logging: application logs exclude entry descriptions and email codes.
  • Organisation: access limited to authorised personnel bound by confidentiality; incident response and breach notification under section 10; regular updates of dependencies.