Skip to content

Data processing agreement

Last updated 27 September 2026

1. Scope and roles

This Data Processing Agreement ("DPA") forms part of the Terms of service between the customer ("Controller") and WeCode A/S ("Processor"). It applies to personal data the Controller puts into Hourtick workspaces.

2. Details of processing

  • Subject matter: providing time tracking, tasks, team chat, AI agent sessions, timesheets, approvals, reporting, API and MCP access.
  • Duration: for the term of the agreement and until deletion under section 9.
  • Nature and purpose: storage, retrieval, computation of reports, display and transmission as instructed through the service.
  • Data subjects: the Controller's staff, contractors and other invited users.
  • Personal data: names, email addresses, roles, time zones, time entries and notes, approval and invoicing status, tasks, comments, chat messages and shared files, presence (last seen and, if shared, the running timer), AI agent activity, and any personal data users write in these.
  • Special categories: not intended. The Controller should not enter special-category data in notes, tasks or chat.

3. Processor obligations

  • Process personal data only on the Controller's documented instructions, including these terms and the Controller's use of the service.
  • Ensure people authorised to process the data are bound by confidentiality.
  • Implement the technical and organisational measures on the Security page (Art. 32).
  • Assist the Controller with data subject requests, security, breach notification, impact assessments and prior consultations, taking into account the nature of processing.
  • Make available the information needed to demonstrate compliance and allow for reasonable audits, normally through documentation and written answers.

4. Sub-processors

The Controller gives general authorisation to the sub-processors listed on our Subprocessors page. We'll give at least 30 days' notice of new sub-processors by updating that page and emailing workspace owners; the Controller may object on reasonable grounds and, if we can't address the objection, terminate. We impose data protection obligations on sub-processors equivalent to this DPA.

5. International transfers

Where personal data is transferred outside the EU/EEA, we ensure a valid transfer mechanism, such as an adequacy decision or the Standard Contractual Clauses.

6. Personal data breaches

We notify the Controller without undue delay, and aim to do so within 48 hours, after becoming aware of a personal data breach affecting the Controller's data, with the information available at the time.

7. Deletion and return

The Controller can export data at any time. After the agreement ends, we delete the Controller's personal data within 30 days, unless the law requires us to keep it.

8. Liability and precedence

Liability under this DPA follows the Terms of service. If this DPA conflicts with the Terms on data protection, this DPA prevails.

Send us a message. The topic is already chosen, change it if you like.

We only use your details to answer you. See our privacy policy.