This Data Processing Agreement ("DPA") applies whenever an organization uses Tyma. It forms part of the [Terms](/terms) between Tyma and the organization, and it takes effect automatically when the organization is created, with no separate signature needed. If you need a countersigned copy for your records, email the address in section 9 and we will send one.
1. Who is who
The organization ("you") is the controller of the personal data its members put into Tyma as part of the organization: its members, teams, roles, closures, work asked through it and the organization's history.
Tyma ("we", "us") processes that data on your behalf, as your processor.
Each person's own account, personal calendar and personal tasks are not covered by this DPA. Tyma is the controller of those under the [Privacy Policy](/privacy), and the privacy wall between personal and organization data described there applies.
"Data Protection Law" means every law that applies to the processing, including the EU General Data Protection Regulation 2016/679 ("GDPR"), the GDPR as it forms part of UK law ("UK GDPR"), and the Nigeria Data Protection Act, 2023 ("NDPA").
2. What we process, and why
The details required by Article 28(3) of the GDPR are set out in Annex 1: what is processed, about whom, for what purpose and for how long.
We process the data only to provide Tyma to you and your members, as described in the Terms and as configured by your organization's admins. Those settings, the Terms and this DPA are your complete instructions. If we believe an instruction breaks Data Protection Law, we will tell you.
3. Our commitments
We will:
- process the data only on your documented instructions, unless a law requires otherwise, in which case we will tell you first where the law allows;
- ensure that everyone authorised to access the data is bound by confidentiality;
- apply the technical and organisational measures in Annex 2, and keep them at least as protective as they are today;
- help you, taking into account the nature of the processing, respond to requests from your members to exercise their rights. Each member can download their own data and delete their own account in Settings → Your data;
- help you with data protection impact assessments and prior consultations with a regulator, where they concern Tyma;
- notify you of a personal data breach affecting your data without undue delay, and within 48 hours of becoming aware of it, with what we know and what we are doing about it, so you can meet your own 72-hour deadline;
- at the end of the service, delete your organization's data within 30 days. Backups are overwritten within a further 30 days. Organization admins can export what they need before then; and
- make available the information needed to show we meet this DPA, and answer reasonable security questionnaires. Where that is not enough, you may audit us once a year on 30 days' written notice, at your cost, under a confidentiality agreement, and without access to other customers' data.
4. Sub-processors
You authorise us to use the sub-processors on our [sub-processor list](/subprocessors). We have a written contract with each that protects the data at least as well as this DPA does, and we remain responsible to you for them.
We will give at least 30 days' notice before adding or replacing a sub-processor, by updating the list and emailing the owners of every organization. If you object on reasonable data protection grounds, we will try to address it. If we cannot, you may stop using Tyma for your organization, and we will refund any part of a prepaid plan that you have not used.
5. Where the data is, and transfers
Tyma's application and database run in the European Union (Ireland). Some sub-processors operate in other countries, as shown on the sub-processor list.
Tyma is operated from Nigeria. To the extent that providing Tyma involves a transfer of personal data from the European Economic Area to a country without an adequacy decision, the Standard Contractual Clauses adopted by the European Commission in Decision (EU) 2021/914 apply and are incorporated into this DPA by reference, as follows:
- Module Two (controller to processor) applies, with you as the data exporter and Tyma as the data importer;
- the optional docking clause in Clause 7 applies;
- under Clause 9, option 2 (general written authorisation) applies, with the notice period in section 4 above;
- the optional wording in Clause 11 does not apply;
- under Clause 13, the supervisory authority is the one competent for you;
- under Clauses 17 and 18, the clauses are governed by the law of Ireland and disputes are resolved by the courts of Ireland; and
- Annexes I and II of the clauses are completed by Annexes 1 and 2 of this DPA, and Annex III by the sub-processor list.
For transfers from the United Kingdom, the International Data Transfer Addendum to those clauses, issued by the UK Information Commissioner (version B1.0), applies as well, completed with the same information. Either party may end the Addendum as it provides.
Onward transfers to our sub-processors rely on their own Standard Contractual Clauses, adequacy decisions or the EU–US Data Privacy Framework, as stated on the sub-processor list.
6. Your commitments
You will make sure you have a lawful basis for putting your members' data into Tyma, give your members any notice the law requires, and give us only lawful instructions.
7. Liability, and which document wins
Each party's liability under this DPA is subject to the limits in the Terms, except where Data Protection Law does not allow a limit.
If the Standard Contractual Clauses conflict with this DPA, the clauses win. If this DPA conflicts with the Terms, this DPA wins.
8. How long it lasts
This DPA lasts for as long as we process data for your organization, and section 3's commitments on deletion and confidentiality continue after that until the data is gone.
Annex 1. Description of the processing
Data exporter: the organization, through its owners and admins in Tyma. Contact details are those of its owners.
Data importer: Tyma, 7 Lord Emmanuel Avenue, Rumuomasi, Port Harcourt, Rivers State, Nigeria. Contact: the email in section 9.
People whose data is processed: the organization's members and invited people.
Kinds of personal data: names, usernames and email addresses; roles, teams and team leadership; membership start and end dates; invitations; working hours and how much time is open and taken (amounts only, never personal event details); work asked through the organization, with its titles, deadlines and estimates; organization events and meeting notes; office closures and holidays; and the organization's history of changes.
Sensitive data: none is intended. Do not put special category data into Tyma.
How often: continuously, for as long as the organization uses Tyma.
Nature and purpose: storing, organising, showing and sending this data to coordinate time and work among the organization's members — finding times, asking for work with its cost visible, reminders and notifications — and the AI features members choose to use.
How long: for as long as the organization exists in Tyma, then as section 3 says.
Annex 2. Security measures
- Where data lives: the application and database are hosted in the European Union (Ireland).
- Encryption: all traffic is encrypted in transit with TLS. Tokens for connected Google and Trello accounts, and private calendar links, are encrypted at rest with AES-256-GCM. Databases are encrypted at rest by our hosting provider.
- Passwords: hashed with Argon2; never stored in readable form.
- Sign-in protection: repeated failed sign-ins are rate-limited; sessions expire, and a password change ends every other session.
- Separation: every request is authorised against the organization and the person's role. Personal events and tasks are never shown to an organization; colleagues see time amounts only.
- Operator access: production data is reachable only by the operator. The internal tools need a separately configured account and a password re-entered every 30 minutes, and they show counts instead of personal content wherever possible.
- Accountability: changes to an organization's shared settings are recorded in a history its admins can read, and that history cannot be edited.
- Least data: usage is counted without cookies or third-party analytics, and logs are kept no longer than the retention periods in the Privacy Policy.
- Resilience: the database is backed up daily by our hosting provider, and backups are overwritten within 30 days.
- Incidents: suspected breaches are investigated and reported as section 3 requires.
9. Contact
Email: kaydeedevelopers@gmail.com
Address: 7 Lord Emmanuel Avenue, Rumuomasi, Port Harcourt, Rivers State, Nigeria