Data processing agreement
Last updated: 9 October 2026. When you keep other people’s working hours in Clockhund, for example your employees’, you are the controller of that data and we process it for you. This agreement sets out how, as Article 28 of the GDPR requires. It is part of our terms and applies automatically, with no signature needed.
1. The parties
Controller: you, the holder of the Clockhund account (“you”). Processor: Dibsido.com s.r.o., Hlinky 995/70, Staré Brno, 603 00 Brno, Czech Republic, company ID 04779568 (“we”).
2. What we process
| Subject and purpose | Storing working hours and calculating totals, breaks, overtime, balances and pay, and creating timesheets and payroll files, as the Clockhund service does. |
|---|---|
| Nature of processing | Storage, retrieval, calculation, display, export and deletion. |
| Data subjects | The people whose hours you keep, usually your employees, workers or contractors. |
| Personal data | Names you enter, working days (start, end, breaks or hours), notes, hourly rates, contract hours and the resulting totals. If you choose “Read with AI”, the text or photo you send for reading. |
| Special categories | None are required. Please don’t enter health or other special category data in names or notes. |
| Duration | As long as your account exists, then as described in section 8. |
3. Your instructions
We process the data only to provide Clockhund to you and on your documented instructions, which are these terms, this agreement and what you do in the app. If an instruction appears to us to break data protection law, we tell you. We process the data otherwise only where EU or Czech law requires it, and then tell you first unless that law forbids it.
4. Confidentiality and security
- Everyone with access to the data at Dibsido.com s.r.o. is bound by confidentiality.
- We take appropriate technical and organisational measures (Art. 32 GDPR), including: encryption in transit (HTTPS) and at rest at our database provider; login links and sessions stored only as one-way hashes; access to production systems limited to people who need it; backups at our database provider; and an information security management system certified to ISO/IEC 27001.
5. Sub-processors
You give general authorisation for us to use these sub-processors:
| Sub-processor | What for | Location |
|---|---|---|
| Vercel Inc. | Hosting the website and the app | USA |
| Neon Inc. | Database hosting for accounts and saved hours | USA |
| Resend | Sending login links and service emails (your email address only, not the hours) | USA |
| Anthropic PBC | Reading imported text and photos, only when you choose “Read with AI”; not stored and not used for training | USA |
Each sub-processor is bound by a written agreement with data protection obligations equivalent to these. We announce a new or replaced sub-processor on this page and by email to account holders at least 30 days in advance; you can object, and if we can’t resolve the objection you can end the subscription and get a refund of the unused period. We remain responsible for our sub-processors.
6. Transfers outside the EEA
Where a sub-processor processes data outside the European Economic Area, the transfer relies on the EU-U.S. Data Privacy Framework where the provider is certified, or on the European Commission’s Standard Contractual Clauses.
7. Helping you
- Requests from the people: you can view, correct, export (PDF, CSV) and delete their hours in the app. If one of them contacts us directly, we forward the request to you and don’t answer it ourselves.
- Breaches: we tell you without undue delay, and in any case within 48 hours, after becoming aware of a personal data breach affecting your data, with the information we have, so you can meet your own duties.
- Assessments: we give you reasonable help with data protection impact assessments and consultations with authorities, as far as they concern Clockhund.
8. At the end
You can download the data at any time as PDF and CSV. When you ask us to delete your account, we delete the people and hours in it within 30 days, and from backups within a further 30 days as they expire, unless the law requires us to keep them.
9. Audits
We make available the information needed to show that we meet these obligations, starting with our ISO/IEC 27001 certificate. If that is not enough, you or an auditor you appoint and who is bound by confidentiality may audit us, with reasonable notice, during working hours and at most once a year unless a breach or an authority requires more.
10. Other terms
The liability provisions of our terms apply. If this agreement and the terms conflict on data protection, this agreement prevails. It is governed by Czech law. Questions: hello@clockhund.com.