CHAIDLA OÜ · Staatus
Data processing terms
Last updated: 29 September 2026
How CHAIDLA OÜ processes personal data on behalf of business customers, following Article 28 of the GDPR.
Roles
Your business is the controller of the personal data it enters into its workspace, such as employee records, schedules and attendance. CHAIDLA OÜ is the processor of that data and processes it only to provide the service to your business. For account, billing and website data that we use for our own purposes, CHAIDLA OÜ is the controller, as described in the privacy policy.
Subject matter, duration and purpose
We process workspace data to provide scheduling, attendance, notifications, calendar synchronization and support, and to keep the service secure and backed up. Processing lasts as long as your business uses the service and ends as described under Deletion and return.
Personal data and data subjects
Data subjects are your employees, managers, owners and other people you invite. Personal data can include names, email addresses and phone numbers, roles, locations, availability, leave, working-hour limits, shifts, recorded working time and corrections, notification preferences and identifiers of linked integrations. For minors, it can include the date of birth and school status needed for working-time rules.
Your instructions
We process workspace data only on your documented instructions: these terms, your workspace settings and the actions of your authorized users. This includes transfers outside the European Economic Area. If the law requires other processing, we tell you first unless the law prohibits it. We tell you if we believe an instruction infringes data protection law.
Confidentiality
People authorized to process workspace data are bound by confidentiality and access it only when needed to provide, support or secure the service.
Security
We apply technical and organizational measures appropriate to the risk, including tenant isolation enforced in the database, role-based access, hashed passwords, encrypted connections, encrypted Google connection credentials and encrypted daily backups stored on a separate host.
Sub-processors
You give general authorization for us to engage the providers listed on the sub-processors page. Each is bound by data protection obligations equivalent to these terms, and we remain responsible for their performance. We announce a new or replacement sub-processor before it starts processing workspace data. You may object on reasonable data protection grounds; if we cannot resolve the objection, you may end the affected subscription.
Helping you meet your obligations
Taking into account the nature of the processing, we help you respond to requests from data subjects, including through the export and erasure functions in the service. We also assist with security, breach notification, data protection impact assessments and prior consultation with a supervisory authority.
Personal data breaches
We notify you without undue delay after becoming aware of a personal data breach affecting your workspace data, with the information available to help you meet your own notification duties.
Deletion and return
When your service ends, you can ask us to export your workspace records. We then delete or anonymize workspace personal data unless the law requires us to keep it. Backup copies expire through backup rotation.
Audits and information
We make available the information needed to demonstrate compliance with these obligations and allow for and contribute to reasonable audits, including inspections by you or an auditor you appoint, with reasonable notice and under confidentiality.
International transfers
Where a sub-processor processes workspace data outside the European Economic Area, the transfer relies on an adequacy decision or appropriate safeguards, such as standard contractual clauses.
About this page
This page summarizes the terms on which we process personal data for business customers. If your business needs a signed data processing agreement, contact us.