Data Processing Agreement
Last updated 17 September 2026
This Data Processing Agreement (DPA) forms part of the contract between your organisation (the controller) and Fortis Time Management (the processor), and reflects Article 28 UK GDPR.
1. Parties and scope
Fortis Time Management is operated by Fortis Tech Limited (company number 07298301), registered office 18 Callywith Gate, Launceston Road, Bodmin, England, PL31 2RQ ("Fortis Time Management", "we", "us"). Our ICO registration number is [TBC].
If you have any question about this document, email us at support@fortistime.co.uk.
For the personal data your organisation submits to or through Fortis Time Management, your organisation is the "Controller" and Fortis Time Management is the "Processor". This DPA applies whenever Fortis Time Management processes personal data on your behalf under the Terms of Service.
2. Definitions
"UK GDPR", "Data Protection Act 2018", "Personal Data", "Processing", "Controller", "Processor" and "Data Subject" have the meanings given in the UK GDPR. "Sub-processor" means another processor engaged by Fortis Time Management to process personal data on the Controller's behalf.
3. Subject matter, duration, nature and purpose of processing
- Subject matter: provision of the Fortis Time Management time-tracking, budgeting, profitability and invoicing software-as-a-service.
- Duration: for as long as the Controller's subscription is active, plus the retention period described in clause 12.
- Nature of processing: hosting, storage, retrieval, organisation, transmission and deletion of the data described in clause 4, carried out by automated cloud software.
- Purpose: to let the Controller track staff time, manage clients and projects, calculate profitability, generate invoices, optionally sync with Xero, and receive support (including, once launched, AI-assisted help chat).
4. Categories of data subjects and personal data
Data subjects
- The Controller's employees, workers and contractors who use Fortis Time Management ("Users").
- The Controller's own clients and contacts, to the extent the Controller enters their details (name, company, billing address, contact email) into Fortis Time Management.
Categories of personal data
- User identity and contact data: name, work email address, role.
- Authentication data: password hash, and TOTP two-factor status where enabled.
- Time and work data: time entries, tasks, notes, charge-out and cost rates.
- Client and billing data: client/contact names, addresses, invoice line items and amounts.
- Integration data: where connected, Xero contact and invoice references (not Xero login credentials — those stay with Xero's own OAuth flow, and Fortis Time Management stores only the resulting access/refresh tokens needed to call the Xero API on the Controller's behalf).
- Support data: content of support emails and, once launched, AI help chat messages.
5. Processor obligations
Fortis Time Management shall:
- Process personal data only on the Controller's documented instructions, including as set out in the Terms of Service and this DPA, unless required to do otherwise by law (in which case Fortis Time Management will inform the Controller before processing, unless prohibited from doing so).
- Ensure that people authorised to process the data are subject to confidentiality obligations.
- Implement appropriate technical and organisational security measures (clause 8).
- Engage sub-processors only as permitted by clause 7.
- Assist the Controller, at the Controller's request, in responding to data subject rights requests and in meeting its obligations around security, breach notification and data protection impact assessments, taking into account the nature of processing and information available to Fortis Time Management.
- Delete or return personal data at the end of the relationship in accordance with clause 12.
- Make available the information reasonably necessary to demonstrate compliance with this clause and allow for audits in accordance with clause 13.
6. Sub-processors
The Controller authorises Fortis Time Management to engage the following sub-processors:
- Supabase — Database, authentication and file storage that holds your workspace data. Location: London, UK (eu-west-2 region).
- Vercel — Hosts the Fortis Time Management website and application and serves it via a content delivery network. Location: Primarily United States, served through a global edge network; transfers are safeguarded under the UK International Data Transfer Addendum and the EU Standard Contractual Clauses.
- Stripe — Processes subscription payments. Card and bank details go straight to Stripe — Fortis Time Management never receives or stores them. Location: United States / Ireland, under Stripe's own data processing terms.
- Anthropic — Processes the messages you send to the in-app AI help chat in order to generate a reply. Under Anthropic's commercial API terms, content submitted through the API is not used to train Anthropic's models. Location: United States.
- Xero — Only used if you choose to connect your organisation's Xero account: receives the contacts and invoices you push, or supplies the contacts you import. Location: Primarily UK / global, under Xero's own privacy policy — Xero is your data controller for that connection.
- Email support provider — Sends and receives support emails when you contact us. Location: [TBC].
Fortis Time Management will give the Controller at least 30 days' prior notice (by email to workspace admins, or by posting to this page) before appointing a new sub-processor that will process the Controller's personal data. If the Controller reasonably objects to a new sub-processor on data protection grounds within that window, the parties will discuss in good faith; if the objection cannot be resolved, the Controller may terminate the affected service.
7. Security measures
- Encryption in transit (TLS) for all traffic to and from Fortis Time Management.
- Encryption at rest, provided by our database host, Supabase.
- PostgreSQL Row Level Security enforcing workspace-level data isolation at the database layer.
- Optional time-based one-time-passcode (TOTP) multi-factor authentication available to every user.
- Role-based access control within each workspace, and least-privilege access to production systems for Fortis Time Management staff.
- Automated daily backups, with a nightly off-site copy, to support recovery.
- Ongoing monitoring and a process for logging and responding to security incidents.
8. Personal data breach notification
Fortis Time Management will notify the Controller without undue delay, and in any event within 48 hours of becoming aware of a personal data breach affecting the Controller's data, with the information reasonably available at the time to help the Controller meet its own Article 33/34 obligations, and will keep the Controller updated as the investigation progresses.
9. International transfers
Core workspace data is hosted in the UK (Supabase, London). Where a sub-processor listed in clause 6 processes personal data outside the UK — currently Vercel, Stripe and Anthropic, each based primarily in the United States — the transfer is protected by the UK International Data Transfer Addendum to the EU Standard Contractual Clauses, or an equivalent recognised transfer mechanism, incorporated into Fortis Time Management's agreement with that sub-processor.
10. Assistance with data subject requests
Where Fortis Time Management receives a request from a data subject relating to data the Controller controls, Fortis Time Management will promptly forward it to the Controller and will not respond to it directly except to confirm receipt, unless instructed otherwise by the Controller.
11. Deletion and return of data
On termination of the Controller's subscription, Fortis Time Management will make the Controller's data available for export for 30 days, after which Fortis Time Management will delete or anonymise the remaining personal data, except to the extent Fortis Time Management is required by law to retain it (for example, financial records relating to invoicing).
12. Audit
On reasonable written notice, and no more than once in any 12-month period (except where required by a supervisory authority or following a security incident), Fortis Time Management will provide the Controller with the information reasonably necessary to demonstrate compliance with this DPA, which may be satisfied by providing a summary of relevant third-party audits or certifications held by Fortis Time Management's infrastructure providers, or by a mutually agreed audit of Fortis Time Management's own practices.
13. Liability
Each party's liability under this DPA is subject to the liability provisions set out in the Terms of Service.
14. Contact
Data protection queries relating to this DPA: support@fortistime.co.uk.