CONTRACTUAL TERMS OF SECURITALY S.R.L.

Terms of Sale and Licence

Updated on 6 October 2026

These terms consist of the following parts:

  • Part A, General Terms of Sale, for all orders
  • Part B, TimeStudio On-Premise Licence Agreement, if the order includes TimeStudio On-Premise, its modules or a terminal with the licence included
  • Part C, TimeStudio Cloud Licence and Service Agreement, if the order includes TimeStudio Cloud
  • Part D, Data Processing Agreement (DPA), annexed to Parts B and C, for TimeStudio Cloud, the ADA module and remote-connection support
  • Part E, Expressly Approved Clauses

A. GENERAL TERMS OF SALE

These apply to all orders placed on the website www.iaccess.com.

A.1 Seller and scope

A.1.1 These terms govern the sale of the products and services offered on the website www.iaccess.com by SECURITALY S.r.l., Via dei Platani 3, 47042 Cesenatico (FC), Italy, VAT No. and Tax Code 03558340406, REA FC 305977, certified e-mail (PEC) securitaly@pec.it ("Securitaly"). The customer is the business, professional or consumer placing the order ("Customer").

A.1.2 If the order includes TimeStudio software or services, the following also apply: Part B for TimeStudio On-Premise, including when the licence is included in the supply of a terminal, Part C for TimeStudio Cloud and Part D for the processing of personal data carried out by Securitaly on behalf of the Customer. For TimeStudio software and services, Parts B, C and D prevail over this Part A.

A.1.3 If the Customer is a consumer within the meaning of the Italian Consumer Code (Legislative Decree 206/2005), the mandatory rules for consumer protection remain unaffected and prevail over these terms.

A.2 Order and conclusion of the contract

A.2.1 The Customer selects the products and adds them to the cart. Before submitting the order, the Customer can check its contents and correct any input errors. By ticking the first checkbox at checkout, the Customer accepts these terms, and by ticking the second, approves the clauses listed in Part E.

A.2.2 The contract is concluded upon receipt of payment, which is made in advance. Securitaly confirms receipt of the order by e-mail and summarises its contents. The contract is concluded in the Italian language and the order remains available for consultation in the Customer’s reserved area.

A.3 Prices and payment

A.3.1 Prices are those shown on the website at the time of the order. Before submission, the cart summary shows taxes, shipping costs and the total amount payable.

A.3.2 Payment is made using the methods available at checkout (bank transfer, credit card or PayPal). In the case of bank transfer, the order is processed once the funds have been credited.

A.4 Delivery and supply

A.4.1 Physical products are shipped by courier, with the times and costs indicated on the Shipping and Payment page and in the order summary. Delivery times are indicative. For consumers, delivery takes place in any case within 30 days of the conclusion of the contract, unless otherwise agreed (Art. 61 of the Consumer Code).

A.4.2 On delivery of shipped products, the Customer checks that the packaging is intact and notes any visible damage on the courier’s document. For consumers, the risk of loss of or damage to the products passes when the consumer, or a third party designated by the consumer other than the carrier, takes physical possession of the goods (Art. 63 of the Consumer Code). For business customers, delivery is deemed to have taken place when the products are handed over to the courier (Art. 1510(2) of the Italian Civil Code).

A.4.3 Software, licences, modules and digital services are not shipped. After receipt of payment, Securitaly sends the download link, activation codes or service access instructions to the e-mail address given in the order, without undue delay and without waiting for the shipment of other products in the same order. Supply is deemed performed when the link, codes or access are made available to the Customer (Art. 135-decies(1) and (2) of the Consumer Code). The Customer keeps the codes and credentials received safe and, if the e-mail is not received, reports this to info@iaccess.com.

A.4.4 Installation, configuration and training services are performed on the dates agreed with the Customer after the order. Assistance Packs may be used within the validity period stated on the product page.

A.5 Warranty and support

A.5.1 Securitaly’s commercial warranty, its extensions and the return and support procedures are described on the Warranty and Returns page.

A.5.2 For consumers, the statutory warranty of conformity provided for by Articles 128 et seq. of the Consumer Code remains unaffected for lack of conformity that becomes apparent within 2 years of delivery (Art. 133 of the Consumer Code). The warranty covers goods with digital elements, such as terminals with firmware or with a TimeStudio licence included, for which Securitaly informs the consumer of the updates needed to keep them in conformity and supplies them during the period provided for by Article 130(2) of the Consumer Code.

A.5.3 For software and digital services purchased by consumers, the warranty of conformity provided for by Articles 135-octies et seq. of the Consumer Code remains unaffected. For licences and modules supplied in a single act, Securitaly is liable for any lack of conformity that becomes apparent within 2 years of supply (Art. 135-quaterdecies(3)). For services and modules supplied on a continuous basis, such as TimeStudio Cloud, the ADA module and subscription modules, it is liable for any lack of conformity that becomes apparent during the period of supply (Art. 135-quaterdecies(5)). In both cases Securitaly informs the consumer of the updates needed to maintain conformity and supplies them (Art. 135-undecies(1)).

A.5.4 For business customers, the warranty against defects provided for by Articles 1490 et seq. of the Italian Civil Code applies to physical products. Defects must be reported within 8 days of discovery (Art. 1495 of the Civil Code). For TimeStudio software and services, the warranty is governed by Articles B.9 and C.13.

A.5.5 For installation, configuration, training and support services, the Customer reports any non-conformity to Securitaly, which remedies it by correcting or repeating the service. For consumers, the protections provided for by law remain unaffected.

A.6 Right of withdrawal

A.6.1 Consumers may withdraw from the contract within 14 days, in accordance with Articles 52 et seq. of the Consumer Code and in the manner indicated on the Right of Withdrawal page. For software and digital services, withdrawal follows the same rules, including the exceptions provided for by Article 59 of the Consumer Code, which apply only under the conditions set out therein. If the consumer asks for a service to begin during the withdrawal period and then withdraws, the consumer pays an amount proportionate to what has been supplied up to the communication of withdrawal (Art. 57(3) of the Consumer Code).

A.6.2 The right of withdrawal under A.6.1 does not apply to businesses and professionals, except as provided for in Parts B and C.

A.7 Liability

A.7.1 Towards business customers, except in cases of wilful misconduct or gross negligence and cases in which the law does not permit limitations, Securitaly’s liability for the products and services sold is limited to the price paid for the product or service that caused the damage, excluding indirect damage and loss of profit. For TimeStudio software and services, Parts B and C apply.

A.8 Personal data

A.8.1 Securitaly processes Customers’ data for the management of the order, delivery, invoicing and support as set out in the privacy notice published on the website. When it processes the data of the Customer’s staff on the Customer’s behalf through TimeStudio Cloud, the ADA module or remote support, Part D applies.

A.9 Communications and complaints

A.9.1 Requests and complaints are sent to info@iaccess.com or to +39 0547 1932159. Withdrawal, disputes and formal communications are sent by certified e-mail (PEC) to securitaly@pec.it or by any other means capable of proving dispatch and receipt.

A.10 Governing law and jurisdiction

A.10.1 The contract is governed by Italian law.

A.10.2 The Court of Forlì has exclusive jurisdiction over any dispute with business customers. If the Customer is a consumer, the court of the consumer’s place of residence or domicile has jurisdiction. The parties may attempt mediation under Legislative Decree 28/2010 before taking legal action.

A.11 Versions

A.11.1 These terms show their update date. The order is governed by the version published on the date of the order, which Securitaly keeps together with previous versions and makes available to the Customer on request.

B. TIMESTUDIO ON-PREMISE LICENCE AGREEMENT

This applies if the order includes TimeStudio On-Premise, its modules or a terminal with the licence included.

B.1 Parties, sales channels and contractual documents

B.1.1 The licensor is SECURITALY S.r.l., Via dei Platani 3, 47042 Cesenatico (FC), Italy, VAT No. and Tax Code 03558340406, REA FC 305977 ("Securitaly"). The licensee is the business or professional identified in the order ("Customer"). The software is intended for businesses and professionals and is marketed in Italy. Orders from other countries are accepted only subject to Securitaly’s written confirmation, which states the applicable tax regime and conditions in the order confirmation. Where the Customer is a consumer within the meaning of the Consumer Code, the mandatory rules for consumer protection apply and prevail over any clauses of this Agreement that are incompatible with them.

B.1.2 Purchases may be made through the checkout of the iAccess e-commerce site (www.iaccess.com), through a commercial offer from Securitaly followed by an order confirmation, or through an authorised reseller or distributor. In the case of purchase through a reseller or distributor, the commercial relationship (price, payment, installation) is governed between the Customer and the reseller, while this Agreement governs in all cases the Customer’s use of the software. The reseller may not grant rights to the software beyond those provided for herein.

B.1.3 The contract consists of this Agreement, the order or order confirmation stating the product, modules, quantities and prices, the technical documentation published on the iAccess website referred to in the order and, for the ADA module and remote-connection support, the data processing agreement under Article 28 of the GDPR ("DPA"), which forms an annex to this Agreement and is accepted together with it. In the event of conflict, the order prevails for the specific commercial conditions and this Agreement prevails for the general licence conditions. Terminals, badges and other goods are subject to Part A.

B.1.4 Before submitting the order, the Customer can consult and save this Agreement, which is made available at checkout, attached to the offer and sent with the e-mail containing the activation codes. Where Articles 1341 and 1342 of the Italian Civil Code apply, the clauses listed in Article B.16 are approved separately.

B.2 Software and right of use

B.2.1 TimeStudio On-Premise is attendance management software installed on the Customer’s systems, with a centralised MySQL database to which multiple workstations may connect within the limits of Article B.2.3. Within the same database the Customer may configure multiple companies in accordance with Article B.2.3. Securitaly, the owner of the software, grants the Customer a non-exclusive, non-transferable licence for the activities permitted by this Agreement. The code, documentation, trademarks and other rights in the software remain with Securitaly and the respective owners.

B.2.2 The base version is granted without time limit, save for termination for breach, both when purchased separately at list price and when included in the supply of an eligible iAccess terminal. The price or inclusion is stated in the order. The base version allows the management of up to ten employees in total, adding together those of all the companies configured in the licence. Extending the number of employees requires the modules or additional licences indicated in the technical documentation and in the order.

B.2.3 The base version licence includes use of the software on one workstation. Each additional workstation connected to the same centralised MySQL database requires the Time Studio 1P annual licence, which extends the privileges and functions of the main licence to that workstation. Within the same database the Customer may configure multiple companies and register their employees, subject to the overall limit of the version purchased. The Customer warrants that it is authorised to manage the data of the configured companies and may keep a backup copy within the limits of the law. The number of iAccess terminals that can be connected is not limited by the licence.

B.2.4 The trial version, downloadable from the service.iaccess.com portal, lasts thirty days and includes all functions. On expiry, a valid licence is required to continue use. Modules may be tried for the period indicated on the relevant product page. Data stored in the Customer’s environment during the trial remain under the Customer’s control.

B.3 Requirements and installation

B.3.1 The software is compatible with personal computers running Microsoft Windows 11 or later and requires a MySQL database. The Customer provides suitable devices, operating system, network, database, power supply and backups and is responsible for their security, except for installation services expressly purchased.

B.3.2 Synchronisation with iAccess terminals, data transfer and module functions depend on the compatible devices and versions indicated in the product documentation. Services relating to third-party terminals, connectors or systems apply only if stated in the order.

B.4 Add-on modules, duration and renewal

B.4.1 The PRO, EXPORT, SYNC, ADA, A500 and 1P modules and the other modules indicated in the order are granted for the duration and within the functional limits specified on the relevant product page. Modules indicated as "annual licence" last twelve months from activation, unless a different date is stated in the order, and modules indicated as "monthly fee" last one month and are renewed in the same way. The PRO module enables attendance reports for up to one hundred users and the A500 module extends reports to five hundred additional users.

B.4.2 Renewal of time-limited modules is not automatic. One month before expiry, Securitaly gives notice by e-mail to the address associated with the licence and by a message in the software. The Customer may renew with a new order through the e-commerce site, through Securitaly (offer and order confirmation) or directly from the software, while customers served by a reseller renew through the reseller, which purchases the licences from Securitaly in its reserved portal. On expiry, failing renewal, only the functions of the expired module cease and the base version licence already acquired remains usable. The data remain in the Customer’s database.

B.4.3 The ADA module and its extensions A30, A100 and M300 involve an online service provided by Securitaly (clocking in from a mobile device with location detection, publication of payslips and documents to employees, expense reports, automatic recognition of uploaded payslips), in which Securitaly stores and processes staff data on behalf of the Customer. The service is provided on virtual machines located in the European Union, at the infrastructure provider indicated in the DPA, using only the sub-processors listed in the DPA. Clock-ins and location data (latitude, longitude and accuracy) are deleted from the online service when they are downloaded into the Customer’s software and in any case after ninety days. For these modules, the specific conditions published on the module page and the DPA apply. On expiry of the module, the documents and other data stored in the online service remain retrievable by the Customer for sixty days, after which Securitaly deletes them within thirty days and erases the backups containing them within the following three years, through the ordinary rotation of backups. The SYNC module runs as a Windows service on the Customer’s systems and connects to Securitaly’s online services solely for licence verification.

B.5 Price, payment and delivery

B.5.1 Prices, promotions, taxes and additional costs are those summarised at checkout, in the offer or in the order confirmation. Payment is made in advance by bank transfer, credit card or PayPal according to the methods available at checkout or indicated in the offer. After receipt of payment, Securitaly’s order office sends the download link, activation codes and this Agreement by e-mail. In the case of purchase through a reseller, the codes are delivered by the reseller.

B.5.2 Support, customisation, installation, configuration, training, migration and hardware are due only if purchased separately and are indicated in the offer as additional services. Time-limited modules are invoiced for the period purchased. A change to the price list, communicated to resellers and distributors with its effective date, applies to subsequent orders and renewals and does not alter the price already paid.

B.6 Updates and support

B.6.1 Updates to the licensed version are automatic, free of charge and without time limit. The software connects to Securitaly’s online services to check for and download releases issued after testing. At each login the user sees the notes for the available releases. The connection sends Securitaly the technical data needed to identify the licence and the installed version, together with aggregated usage statistics associated with the Customer’s identification code. The statistics report the total number of clock-ins, employees, departments, profiles, devices, areas, schedules and absence reasons present in the database, the size of the related tables and the date of the last update. They do not include names, individual clock-ins or any other data relating to identified persons. The Customer keeps its environment compatible, installs the security updates for its own system and checks the effects of updates on any of its own integrations and customisations.

B.6.2 Support is not included in the licence or in the modules. Software defects may be reported to support@securitaly.com. Specialist support is provided through a paid Assistance Pack. Telephone support is reserved for resellers with a code and for customers holding a valid Assistance Pack and is provided at +39 0547 1932159 on Monday, Wednesday and Friday from 9:00 to 12:00 and from 14:30 to 17:30 and on Tuesday and Thursday from 9:00 to 12:00 (Italian time). Assistance Packs are sold in bundles of one, three and ten hours, valid for twelve months from purchase. Time is counted in indivisible fifteen-minute units, charged at the start of each unit, with a minimum of fifteen minutes per intervention. Remote-connection support is provided only to Assistance Pack holders, using the Supremo tool, by appointment. Support covers the installation, configuration and use of the software and terminals and does not include the security, maintenance or network configuration of the Customer’s systems.

B.7 Permitted use and restrictions

B.7.1 The Customer may allow its authorised employees and collaborators to use the software to manage attendance for the companies configured under Article B.2.3, within the limits of the licence. It may not sublicense, resell, rent, make it available to third parties as a stand-alone service, modify it or remove proprietary notices.

B.7.2 The mandatory rights granted by law regarding interoperability, backup copies and analysis of the program (Articles 64-ter and 64-quater of Italian Law 633/1941) remain unaffected. Use to manage the companies configured under Article B.2.3 is permitted within the limits of the licence and does not grant those companies an independent right to use the software.

B.7.3 The Customer keeps the activation codes and credentials safe and promptly informs Securitaly of any unauthorised use of the licences or of any connected online services.

B.8 Customer data and personal data protection

B.8.1 The data entered into the software and the local database remain at the disposal of the Customer, which determines their use, access, retention periods and backups and which is the controller of its employees’ data. The licence does not give Securitaly any right to use the data of the Customer’s staff for its own purposes.

B.8.2 Remote-connection support is started at the Customer’s request, takes place for the duration of the session via Supremo and may involve viewing personal data processed by the Customer. Any files acquired for analysis are deleted when the intervention is closed and in any case within thirty days of their acquisition. Securitaly acts within the limits of the Customer’s instructions, with authorised personnel bound by confidentiality. When the intervention involves processing personal data on behalf of the Customer, the DPA applies.

B.8.3 Securitaly is an independent controller of the data of the Customer’s contact persons processed for ordering, invoicing, licence activation, expiry notices and management of the relationship, as set out in its privacy notice published at www.securitaly.com. The Customer remains responsible for the lawfulness of the processing carried out with the software, including functions linked to terminals with biometric recognition, for which it assesses the applicability of Article 9 of the GDPR and of the guidance of the Italian Data Protection Authority (Garante). The templates and other data generated by the terminals for recognition constitute biometric data within the meaning of Article 4(14) of the GDPR. The decision to use biometric recognition, the choice of terminals and data storage methods and the related obligations are the responsibility of the Customer as controller. Securitaly makes available, on request, the manufacturers’ technical documentation in its possession.

B.9 Warranty and reporting of defects

B.9.1 Securitaly warrants the substantial conformity of the software with the functions described in the documentation applicable to the version purchased. The Customer reports reproducible defects with the information necessary for verification. Securitaly may correct them by means of an update, a workaround or replacement of the defective component within a reasonable time.

B.9.2 The warranty does not cover malfunctions caused solely by unauthorised modifications, use outside the stated requirements, failures of the Customer’s environment or third-party products not indicated as compatible. The software supports the Customer’s activities and does not replace the Customer’s own checks in matters of personnel management and legal obligations.

B.10 Liability

B.10.1 In no event shall Securitaly or its suppliers be liable for damages (including, without limitation, damages for loss of profits, business interruption, loss of stored information or other economic loss) arising from the use of the software or from hacker attacks, even if Securitaly has been advised of the possibility of such damages, save as mandatorily provided by law. In any case, Securitaly’s liability under this Agreement shall be limited to an amount corresponding to that actually paid for the software, which the parties pre-determine as a penalty clause.

B.10.2 In any case, Securitaly is not liable for any direct or indirect damage, incidental damage, or loss of profits or losses suffered by the Customer and/or third parties arising from original or subsequent defects in the updates of any version and type and/or in any case suffered through the use or non-use thereof. The Customer is required to verify the correctness of the data processed by the updates and in any case may not claim sums greater than the amount paid to Securitaly in the last year. The Customer may not hold Securitaly liable in any way, even if the service for downloading updates via the Internet fails for any reason (by way of example only and without limitation: network congestion, provider blackout, insufficient bandwidth on the Customer’s side).

B.11 Suspension and termination

B.11.1 The expiry of time-limited modules has the effects indicated in Article B.4 and does not extinguish the base licence already acquired. In the event of breach of the obligations under Articles B.2.3 (licence limits) and B.7.1 (permitted use and restrictions), Securitaly may require the conduct to cease and grant a reasonable period, of not less than fifteen days, to remedy it, except where no remedy is possible. If the breach persists, the contract relating to the licence concerned is terminated by operation of law pursuant to Article 1456 of the Italian Civil Code when Securitaly declares in writing to the Customer that it intends to invoke this clause.

B.11.2 Since licences, modules and services are paid in advance and activated after payment, there is no suspension for non-payment. Modules and services not renewed cease on expiry in accordance with Article B.4. A connected online service may be suspended, with notice to the Customer, in the event of an urgent security risk. Suspension does not affect the data that remain in the Customer’s local environment.

B.12 Amendments to the Agreement

B.12.1 New versions of this Agreement apply to orders placed after their publication and to renewals accepted by the Customer. They do not retroactively modify the perpetual right of use already acquired, unless expressly agreed or required by law. Each version shows its effective date.

B.13 Confidentiality

B.13.1 Each party uses the confidential information received from the other solely to perform the contract and protects it with appropriate care. Information that is already public, lawfully known or required to be disclosed by law is excluded. In the latter case, the party concerned informs the other where permitted. The obligation lasts for the entire duration of the relationship and for the following three years.

B.14 Force majeure

B.14.1 A party prevented by an extraordinary, unforeseeable event beyond its reasonable control informs the other without undue delay, limits the effects as far as possible and resumes performance as soon as possible. If the impediment lasts more than sixty days, either party may withdraw from the affected services by written notice, without penalty.

B.15 Communications, governing law and disputes

B.15.1 Operational communications are sent to the contact details given in the order or in the Customer’s account and, for Securitaly, to info@iaccess.com or to +39 0547 1932159. Withdrawal, disputes and termination are communicated by certified e-mail (PEC) to securitaly@pec.it or by any other means capable of proving dispatch and receipt.

B.15.2 The Agreement is governed by Italian law. The Court of Forlì has exclusive jurisdiction over any dispute between professionals. If the Customer is a consumer, the court of the consumer’s place of residence or domicile has jurisdiction. The parties may attempt mediation under Legislative Decree 28/2010 before taking legal action.

B.16 Specific approval

B.16.1 Pursuant to Articles 1341 and 1342 of the Italian Civil Code, the Customer specifically approves, by means of the dedicated checkbox at checkout, separate from the one for acceptance of the terms, or by means of the order confirmation, clauses B.2.3 (licence limits), B.4.2 (renewal and cessation of modules), B.5.1 (advance payment), B.7.1 (permitted use and restrictions), B.9.2 (warranty exclusions), B.10.1 and B.10.2 (exclusion and limitation of liability), B.11.1 and B.11.2 (termination and suspension), B.12.1 (amendments to the Agreement) and B.15.2 (competent court).

C. TIMESTUDIO CLOUD LICENCE AND SERVICE AGREEMENT

This applies if the order includes TimeStudio Cloud.

This Agreement governs access to and use of the TimeStudio Cloud service purchased through the iAccess e-commerce site, through an offer from Securitaly or through a reseller. The plan sheet published on the website, the service levels in Article C.6 and the data processing agreement complete the terms of supply.

C.1 Parties, scope and documents

C.1.1 The provider is SECURITALY S.r.l., Via dei Platani 3, 47042 Cesenatico (FC), Italy, VAT No. and Tax Code 03558340406, REA FC 305977 ("Securitaly"). The customer is the business or professional identified in the order ("Customer"). The service is intended for businesses and professionals and is marketed in Italy. Orders from other countries are accepted only subject to Securitaly’s written confirmation, which states the applicable tax regime and conditions in the order confirmation. Where the Customer is a consumer within the meaning of the Italian Consumer Code, the mandatory rules for consumer protection apply. The Customer may purchase directly from the e-commerce site www.iaccess.com at list price, through a commercial offer from Securitaly followed by an order confirmation, or through an authorised reseller that purchases the service from Securitaly. In the latter case, the commercial relationship is governed between the Customer and the reseller, while the service is provided by Securitaly under the terms of this Agreement.

C.1.2 The relationship comprises this Agreement, the order or order confirmation stating the plan, quantities, modules and price, the plan sheet published on the iAccess website and in the www.timestudio.cloud configurator on the date of the order, and the data processing agreement under Article 28 of the GDPR with its annexes ("DPA"), which forms an annex to this Agreement and is accepted together with it. The order prevails for the specific commercial conditions. The DPA prevails for the processing of personal data.

C.1.3 The service does not require any software components installed at the Customer’s premises: access is via browser from desktop and mobile devices. The iAccess terminals compatible with TimeStudio Cloud are the ScanFACE XP and TIME-MINI models. Terminals, their installation and the licence for any installed TimeStudio On-Premise version are governed by Parts A and B. The software for generating payroll export files is available only in the On-Premise version.

C.2 Service and plan purchased

C.2.1 Securitaly provides the Customer with browser access to the TimeStudio Cloud plan indicated in the order. There are three plans, all based on thirty included employees: Starter (online clock-in, basic reports, general communications, public noticeboard, bulk upload of payslips); Advanced (in addition: advanced reports, schedule management, holiday and leave requests, control dashboard); Enterprise (in addition: employee document file and expense reports). The detailed functions of each plan are those shown in the configurator on the date of the order.

C.2.2 "Employees" means the persons whose attendance and data are managed in the service. "Admin users" means profiles with an administrative role for the Customer. The Customer may configure multiple companies within the same plan: the limit of thirty included employees is an overall limit for all configured companies, not per company. The number of employees may be increased with the C10 (ten additional employees) and C100 (one hundred additional employees) modules. The Quick User module adds a profile with an administrator role. Modules have the same duration as the plan and are purchased in the same way.

C.2.3 The Customer uses the service to manage attendance, communications and the other personnel processes provided for by the plan. The Customer remains responsible for its Internet connection, compatible devices, the correctness of the data, settings, internal authorisations and the checks required by employment law. Application programming interfaces (APIs) for integration with third-party systems are not currently available. Customisations are included only if described in the order and Securitaly does not guarantee compatibility with third-party systems not expressly indicated.

C.3 Order, activation and trial

C.3.1 Purchases are made through the checkout of the iAccess e-commerce site, where the Customer selects the plan, modules and quantities, reviews the contractual documents and submits the order, or through an offer and order confirmation. The contract is concluded upon receipt of advance payment. Securitaly’s order office then sends the activation codes, this Agreement and the DPA by e-mail, and access runs from activation, which is immediate after payment. Securitaly keeps the version, date and proof of acceptance of the contractual documents.

C.3.2 The Customer appoints an administrator and keeps its contact details for invoicing, operational communications and incidents up to date. Credentials are personal and must be protected.

C.3.3 The Customer may request a demo of the service. The free trial, where offered on the website, lasts thirty days with no commitment, with the functions and limits shown before activation. Conversion to a paid plan requires an express order. Data entered during the trial are deleted thirty days after it expires, unless converted to the paid plan.

C.4 Duration, renewal and price

C.4.1 The plan has an annual term and runs from the activation date or from any other date stated in the order. On the date of the order, the published price list provides, for thirty employees, the Starter plan at EUR 300.00, the Advanced plan at EUR 500.00 and the Enterprise plan at EUR 700.00 per year, and the C10 module at EUR 50.00, C100 at EUR 200.00 and Quick User at EUR 50.00 per year, plus VAT. The applicable price is in all cases the one summarised in the order.

C.4.2 Renewal is not automatic. One month before expiry, Securitaly gives notice by e-mail to the address associated with the plan. The Customer renews with a new order and the related payment, through the e-commerce site, through Securitaly or through its reseller. Failing renewal, the service is suspended on expiry and the data remain retrievable in accordance with Article C.10. The fee paid is non-refundable in the event of non-use or early withdrawal by the Customer, except in the cases provided for by law or by this Agreement.

C.4.3 Payment is made in advance by bank transfer, credit card or PayPal according to the methods of the checkout or the offer. The electronic invoice is issued after payment. During the year the Customer may increase the number of employees by purchasing the C10 and C100 modules and may upgrade to a higher plan by paying the difference for the remaining period. Downgrading to a lower plan is possible only at the annual expiry. Configuration, training, migration, customisation, hardware and specialist support require a separate order. Price list changes are communicated with their effective date and apply to subsequent renewals.

C.5 Users and permitted use

C.5.1 The Customer may enable its employees and collaborators, as well as its payroll consultant and the companies of its group, provided that they act on its behalf and within the limits of the plan. The Customer manages roles, checks authorisations and promptly revokes access that is no longer needed. Resellers do not access the Customer’s data, unless instructed in writing by the Customer.

C.5.2 It is prohibited to share individual credentials, exceed the technical limits purchased, compromise the security of the service, resell it or use it for unlawful purposes. The Customer is responsible for the activities carried out through the accounts it has enabled, except for acts attributable to Securitaly.

C.6 Support, maintenance and service levels

C.6.1 The fee includes the correction of service defects, platform maintenance and updates. The Customer reports defects and incidents by opening a ticket at support@securitaly.com. Specialist support is provided through a paid Assistance Pack. Telephone support is reserved for resellers with a code and for customers with a valid Assistance Pack, at +39 0547 1932159, on Monday, Wednesday and Friday from 9:00 to 12:00 and from 14:30 to 17:30 and on Tuesday and Thursday from 9:00 to 12:00 (Italian time). Assistance Packs are sold in bundles of one, three and ten hours, valid for twelve months, and time is counted in indivisible fifteen-minute units, charged at the start of each unit, with a minimum of fifteen minutes per intervention. Remote-connection support to the Customer’s workstation is provided only to Assistance Pack holders, using the Supremo tool, by appointment.

C.6.2 Securitaly carries out maintenance, updates and security work with reasonable attention to service continuity. Scheduled maintenance is normally carried out outside the hours of 8:00–20:00 on working days, with at least forty-eight hours’ notice by means of a notice in the service or an e-mail to the administrator. Urgent security work may be carried out without notice. New functions are released progressively and announced in the release notes displayed in the service.

C.6.3 Securitaly undertakes to provide service availability of 99.5 per cent on a monthly basis, measured on the accessibility of the application from Securitaly’s point of entry and excluding scheduled maintenance, force majeure and causes attributable to the Customer or its connection. In the event of an interruption, the recovery time objective is eight working hours and the maximum data loss is twenty-four hours, corresponding to the daily backup frequency. Failure to meet the service levels does not give rise to any credits or refunds of the fee, without prejudice to Securitaly’s liability within the limits of Article C.13 and the right of termination provided for by Article C.11.3.

C.7 Security and shared responsibilities

C.7.1 Securitaly provides the service within its Information Security Management System compliant with ISO/IEC 27001:2022, integrated with the controls of ISO/IEC 27017:2015 and ISO/IEC 27018:2025 for cloud services and personal data protection. Information on the certification status of the System is available at the Customer’s request. The measures include: encryption of communications with TLS 1.2 or higher; database encryption with AES-256; encrypted daily backups, performed by Securitaly and stored in Italy at one of its own premises, with an encrypted replica, encrypted before transfer, on a cloud storage service in the European Union; encrypted daily replication of the production virtual machines to a second data centre of the infrastructure provider; access control for personnel with activity logging; vulnerability management with component scanning and security updates; incident management and business continuity procedures. The Customer protects the devices, credentials, connections, users and data under its control, manages the roles and authorisations of its users and periodically exports its data.

C.7.2 Each party notifies the other without undue delay of security events requiring its cooperation, at the contact details in Article C.15 and, for Securitaly, at support@securitaly.com. In the case of breaches of personal data processed on behalf of the Customer, Securitaly informs the Customer without undue delay and in any case within forty-eight hours of becoming aware of it, with the information provided for in the DPA, and cooperates with the notifications for which the Customer is responsible.

C.8 Personal data and DPA

C.8.1 The Customer determines the purposes and essential means of processing the data of its staff uploaded to the service and is the controller of such data. Securitaly processes them on behalf of the Customer as processor, in accordance with the DPA and documented instructions. For orders, invoicing, activation and management of its own business relationships, Securitaly is an independent controller in accordance with its privacy notice published at www.securitaly.com.

C.8.2 The data are stored in Italy, in the virtual infrastructure of the provider Zinca S.r.l., based in Cesena, hosted in a data centre in Milan. Zinca replicates the virtual machines every day to a second data centre in Bologna. Backups are performed by Securitaly and stored at its premises in Cesenatico, with a replica on Synology C2 in the Frankfurt (Germany) data centre, encrypted before transfer with a key held by Securitaly. Application protection and name resolution are entrusted to Cloudflare, which acts as a sub-processor under its own data processing agreement, including the European Commission’s standard contractual clauses for transfers to third countries. The list of sub-processors, with their location and role, is set out in the DPA and is updated with prior notice to the Customer, who may object on legitimate grounds. Access to the data by Securitaly personnel takes place from Italy, is limited to persons authorised for support, development and system administration, and is logged.

C.8.3 Depending on the plan, the service processes employee master data, clock-ins, schedules and shifts, absence reasons, holiday and leave requests, communications, documents and payslips uploaded by the Customer, the expiry dates of documents in the employee file, and expense reports. Absence reasons and the document file may include sick leave and occupational health surveillance deadlines, which constitute data concerning health within the meaning of Article 9 of the GDPR, processed on behalf of the Customer in the context of managing the employment relationship. For absences, the service records the start and end date and, at the discretion of the Customer’s administrator, the PUC code of the medical certificate, a description and attachments. The Customer verifies the lawfulness of the functions activated. When the Customer connects terminals with biometric recognition to the service, the decision to use such functions, the assessment of their lawfulness under Article 9 of the GDPR and the guidance of the Italian Data Protection Authority (Garante) and the obligations towards employees are the responsibility of the Customer as controller. Any biometric data processed by means of such terminals are processed on behalf of the Customer and in accordance with its instructions. Securitaly does not use the Customer’s data for its own purposes, for identifiable statistics or to train models, and informs the Customer of requests for access to its data received from authorities, unless prohibited by law.

C.9 Rights in the software and customisations

C.9.1 For the duration of the contract, Securitaly grants the Customer a non-exclusive, non-transferable right to access and use the service for its own internal activities. Software, documentation and trademarks remain with Securitaly and the respective owners. The Customer’s data remain at its disposal.

C.9.2 The rights in commissioned customisations are set out in the relevant order. In the absence of a specific agreement, the Customer receives the right to use them together with the service for the duration purchased, without assignment of the source code, and Securitaly remains free to reuse them.

C.10 Export, switching to another service and deletion

C.10.1 During the relationship the Customer may export reports in the Excel and PDF formats provided by the plan. On termination, and upon written request, Securitaly provides within thirty days a complete export of the Customer’s data in a structured, commonly used and machine-readable format (CSV or Excel for data, PDF for documents), with integrity verification, at no additional cost for one export. Further exports or migration assistance are invoiced according to the offer. For switching to another provider, until 12 January 2027 switching charges do not exceed the costs directly linked to the switching and from that date no charges are applied (Article 29 of Regulation (EU) 2023/2854).

C.10.2 The Customer may withdraw at any time with notice of no more than two months. Where the provisions of Regulation (EU) 2023/2854 on switching between data processing services apply, the transition is completed within thirty calendar days of the end of the notice period, extendable in the cases provided for by the Regulation, and the Customer has a data retrieval period of sixty calendar days from termination, during which read-only access and export remain available. For the purposes of Article 28 of Regulation (EU) 2023/2854, the service infrastructure and the related jurisdiction are indicated in Article C.8.2 and the measures taken to prevent international governmental access to data held in the Union in conflict with Union or national law are described in Articles C.7.1 and C.8.3. This information is published and updated on the Terms of Sale and Licence page of the website www.iaccess.com.

C.10.3 At the end of the retrieval period, Securitaly deletes the Customer’s data from the production systems within thirty days. Backup and replica copies containing them remain encrypted, are no longer used to process the Customer’s data and are erased through the ordinary rotation of copies within three years of deletion from the production systems. If, during this interval, the restoration of a system brings the Customer’s data back online, Securitaly deletes them again without delay. These operations follow the DPA and Securitaly’s deletion and return procedure, and upon request Securitaly issues a certificate of deletion within five working days.

C.11 Suspension and termination

C.11.1 Securitaly may suspend the service proportionately where necessary to contain a concrete security risk, unlawful use or a serious breach, informing the Customer before taking action where possible and restoring access when the cause ceases.

C.11.2 Since the fee is paid in advance, there is no suspension for non-payment during the year. On expiry without renewal, the service is suspended and the Customer retains the right to retrieve the data within the terms of Article C.10. Renewal within the retrieval period reactivates the service with the existing data.

C.11.3 Either party may terminate the contract for serious breach by the other after a written notice of breach and a remedy period of not less than fifteen days, where a remedy is possible. In the event of termination for breach by Securitaly, the Customer is entitled to a refund of the fee for the unused period. The clauses on data, confidentiality and liability continue to apply.

C.12 Changes to the service and to the contract

C.12.1 Technical and security updates are carried out during the relationship without the need for consent. Changes that substantially reduce purchased functions are notified at least sixty days in advance, except for urgent interventions. If the Customer does not accept them, it may withdraw before they take effect, with a refund of the fee for the unused period.

C.12.2 Changes to the price and the general terms take effect from the next renewal, subject to notice to the Customer at least thirty days before expiry. A Customer who does not wish to accept them does not renew the service.

C.13 Warranties and liability

C.13.1 Securitaly provides the service with professional diligence and in accordance with the agreed characteristics. The Customer reports defects with sufficient information for verification and cooperates in their resolution. Problems caused solely by systems or conduct under the Customer’s control are not attributable to Securitaly.

C.13.2 In no event shall Securitaly or its suppliers be liable for damages (including, without limitation, damages for loss of profits, business interruption, loss of stored information or other economic loss) arising from the use of the service or from hacker attacks, even if Securitaly has been advised of the possibility of such damages, save as mandatorily provided by law. In any case, Securitaly’s liability under this Agreement shall be limited to an amount corresponding to that actually paid for the service in the last year, which the parties pre-determine as a penalty clause.

C.14 Confidentiality and force majeure

C.14.1 Each party uses the other’s confidential information solely to perform the relationship and protects it with appropriate care, except for information that is public, already lawfully known or required to be disclosed by law. The obligation lasts for the entire duration of the relationship and for the following three years. Obligations concerning personal data are specified in the DPA.

C.14.2 A party prevented by an extraordinary, unforeseeable event beyond its reasonable control informs the other without undue delay, limits the effects and resumes performance as soon as possible. If the impediment lasts more than sixty days, either party may withdraw by written notice and the Customer is entitled to a refund of the fee for the unused period.

C.15 Communications, governing law and jurisdiction

C.15.1 Operational communications are sent to the contact details in the order or account and, for Securitaly, to info@iaccess.com or to +39 0547 1932159. Security reports are sent to support@securitaly.com and personal data matters to privacy@securitaly.com. Withdrawal, termination and disputes are communicated by certified e-mail (PEC) to securitaly@pec.it or by any other means capable of proving dispatch and receipt.

C.15.2 The contract is governed by Italian law. The Court of Forlì has exclusive jurisdiction over any dispute between professionals. If the Customer is a consumer, the court of the consumer’s place of residence or domicile has jurisdiction. The parties may attempt mediation under Legislative Decree 28/2010 before taking legal action.

C.16 Specific acceptance in the e-commerce site

C.16.1 Before submitting the order, the Customer can consult and save this Agreement, the order, the plan sheet and the DPA. Pursuant to Articles 1341 and 1342 of the Italian Civil Code, the Customer specifically approves, by means of the dedicated checkbox at checkout, separate from the one for acceptance of the terms, or by means of the order confirmation, clauses C.4.2 (renewal, suspension on expiry and non-refundability), C.4.3 (advance payment and change of plan), C.5.2 (permitted use), C.6.3 (service levels and exclusion of credits and refunds), C.10.2 and C.10.3 (withdrawal, retrieval and deletion of data), C.11.1, C.11.2 and C.11.3 (suspension and termination), C.12.1 and C.12.2 (changes), C.13.2 (exclusion and limitation of liability) and C.15.2 (competent court). Securitaly keeps the version, date and proof of acceptance.

D. DATA PROCESSING AGREEMENT (DPA)

Deed appointing the data processor pursuant to Art. 28 of Regulation (EU) 2016/679. It is annexed to Parts B and C and applies to TimeStudio Cloud, the ADA module and remote-connection support.

BETWEEN

the Customer identified in the order or order confirmation for the Service, represented by its legal representative pro tempore (hereinafter also the "Customer" or the "Controller")

AND

SECURITALY S.r.l., with registered office at Via dei Platani 3, 47042 Cesenatico (FC), Italy, VAT No. and Tax Code 03558340406, represented by its legal representative pro tempore (hereinafter also "Securitaly" or the "Processor")

Hereinafter the Controller and the Processor may also be referred to jointly as the Parties or individually as a Party.

WHEREAS:

  • on the basis of the references and expertise claimed by the Processor in terms of ownership, human resources, equipment and experience in the field of data Processing in general and in the management of situations similar to that of the Processing, the Controller has carried out a positive assessment of the Processor’s suitability and qualification to meet, including in terms of the security of the Processing, the necessary requirements of experience, capacity and reliability laid down by the applicable personal data protection legislation, in order to ensure the guarantees required by law for the Processing of data as Processor on behalf of the Controller under the applicable personal data protection legislation in relation to the Processing of Personal Data necessary for the performance of the Contract;
  • the Processor provides the Services within an Information Security Management System compliant with ISO/IEC 27001:2022, integrated with the controls of ISO/IEC 27017:2015 and ISO/IEC 27018:2025 for cloud services and personal data protection;
  • under the Contract between the Controller and the Processor, the Controller relies on the support of the Processor, as identified above, which provides it with the following services:
  • internet access to the TimeStudio Cloud service for attendance and personnel management, according to the plan purchased ("TimeStudio Cloud");
  • online services of the ADA module and its extensions, connected to the TimeStudio On-Premise software: clocking in from a mobile device with location detection, publication of payslips and documents to employees, expense reports and automatic recognition of uploaded payslips ("ADA");
  • remote-connection support on the Controller’s TimeStudio On-Premise installations, when the intervention involves access to Personal Data ("Remote Support");
  • the performance of these services involves the processing of personal data, as defined in Art. 4 of the GDPR;
  • the applicable personal data protection legislation imposes a series of obligations and constraints on the processing of personal data by the Controller that affect the Processing in question. The Processor may access the Personal Data, albeit solely for contractual purposes and for the benefit of the Controller and in strict compliance with the regulations in force (including the applicable personal data protection legislation);
  • by means of this Deed, the Controller therefore intends to appoint Securitaly as Processor, giving it detailed instructions, in order to comply with the applicable legal provisions and establish appropriate security measures for the lawful Processing of Personal Data.

Now, therefore, the Parties, represented as above, agree and stipulate as follows.

D.1 Recitals and annexes

The recitals and annexes form an integral and substantial part of this Deed.

D.2 Definitions

Unless otherwise defined in this Deed, all capitalised terms used have the meaning given to them in the Contract. With regard to Personal Data Protection, in the event of conflict or terminological inconsistency between this Deed and the Contract, the provisions of this Deed and of Art. 4 of the GDPR prevail:

  • "Deed": this deed appointing the data processor pursuant to Art. 28 of the GDPR, also referred to in the Contract as the "DPA" or as the data processing agreement;
  • "Contract": the TimeStudio Cloud Licence and Service Agreement (Part C) or the TimeStudio On-Premise Licence Agreement (Part B) concluded between the Parties, with the related order or order confirmation;
  • "Law": Regulation (EU) 2016/679 (GDPR);
  • "Data Processor or Processor": the natural or legal person, public authority, agency or other body which processes personal data on behalf of the controller;
  • "Service/Services": TimeStudio Cloud, ADA and Remote Support, as described in the recitals, to the extent purchased or requested by the Controller under the Contract;
  • "Sub-Processor": a body engaged by the Processor to assist it in (or to directly undertake any) processing of Personal Data in compliance with the obligations of the Processor and of this Deed, identifiable in the list of Sub-Processors, which has been authorised by the Controller pursuant to Art. D.6 of this Deed;
  • "Data Controller or Controller": the natural or legal person, public authority, service operator or other body which, alone or jointly with others, determines the purposes and means of the processing of personal data and the tools used, including the security profile;

D.3 Privacy roles

By means of this Deed, the Controller appoints Securitaly, with effect from the date of acceptance, as Processor of the personal data processing carried out under the Contract and necessary for the performance of all obligations connected with the related activities, in compliance also with the provisions of the following articles and in particular Art. D.4.

This deed of appointment is conditional, as to subject matter and duration, on the relationship in progress between the Controller and the Processor and is deemed revoked by operation of law on expiry of the relationship or in the event of its termination for any reason. The obligations of return and deletion provided for in Art. D.12 remain in force after cessation.

The Deed applies only to the Services purchased or requested by the Controller. Data managed with the TimeStudio On-Premise software installed on the Controller’s systems remain at its exclusive disposal and the Processor does not process them outside ADA and Remote Support.

The Parties therefore agree that:

  • the Controller acts as controller of the processing carried out by the Processor in providing the Service;
  • the Processor, in providing the Service, acts as processor of the Personal Data;
  • this Deed governs the relationship between the Parties with regard to their respective tasks and obligations relating to the Processing of Personal Data carried out by the Processor in providing the Service.

D.4 Obligations of the processor

The Controller determines the purposes of the Processing of Personal Data in the provision of the Service, which consist of attendance management and the administration of the Controller’s personnel, including the recording of clock-ins, the management of schedules, shifts, absences, holidays and leave, communications to employees, the provision of payslips and documents and the management of expense reports.

The Processor does not process the Personal Data for its own purposes and does not use them for statistics relating to identifiable persons, for marketing or advertising activities or to train models.

The Processor is authorised to organise any Personal Data Processing operation, with or without the aid of electronic or otherwise automated tools, in full compliance with the rules laid down by the Law and with the operating instructions given by the Controller.

With regard to the provision of the Service, the Processor undertakes to comply with the following obligations, including those set out in Annex 1, which form an integral part of this Deed:

  • the Processor shall process the Personal Data only to the extent strictly necessary for the provision of the Service, subject to the documented instructions given by the Controller through this Deed, the Contract and the configurations the Controller sets in the Service, including with regard to transfers of Personal Data to a third country or an international organisation, unless required to do so by Union or Member State law to which the Processor is subject. In such a case, the Processor informs the Controller of that legal requirement before processing, unless that law prohibits such information on important grounds of public interest (Art. 28(3)(a) of the Law);
  • the Processor ensures that persons authorised to process the Personal Data have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality (Art. 28(3)(b) of the Law);
  • the Processor immediately informs the Controller if, in its opinion, an instruction infringes the Law or other Union or Member State data protection provisions (Art. 28(3), second subparagraph, of the Law);
  • the Processor informs the Controller, without undue delay, of any contact or communication received from a Supervisory Authority in relation to the Processing of Personal Data and of any request for access to Personal Data received from a judicial or administrative authority, unless prohibited by law;
  • the Processor adopts appropriate technical and organisational measures pursuant to Art. 32 of the Law to protect the Personal Data. As at the date of this Deed, the measures include encryption of communications with TLS 1.2 or higher, database encryption with AES-256, encrypted daily backups stored in Italy at one of the Processor’s premises and replicated, encrypted before transfer, on a cloud storage service in the European Union, encrypted daily replication of the production virtual machines to a second data centre, access control for personnel with activity logging, vulnerability management, and incident management and business continuity procedures. The Processor may update the measures over time, provided that the level of security is not reduced (Art. 28(3)(c) of the Law);
  • the Personal Data are stored in Italy, in the infrastructure of the Sub-Processor Zinca S.r.l. and at the Processor’s premises. The encrypted replica of the backups is stored in Germany at the Sub-Processor indicated in Annex 1. The Processor’s personnel access the Personal Data from Italy. The Processor does not transfer the Personal Data to third countries or international organisations, except for the activities of the Sub-Processors indicated in Annex 1 and under the conditions of Chapter V of the Law. Any other transfer requires the prior written authorisation of the Controller;
  • the Processor therefore provides adequate guarantees, by virtue of its training and experience, of full compliance with the provisions in force on the processing of personal data, including the security of processing.

The appointed Processor has the power to do everything necessary to comply with the legal provisions in force on the processing of personal data in the activities carried out within the scope of its operations. In particular, it shall:

  • without prejudice to the provisions already made by the Controller, appoint and identify the persons authorised to process data, also by reference, with regard to the assignment of one or more persons to activities involving the processing of Personal Data within its remit;
  • comply, and ensure that the persons authorised to process Personal Data within its remit comply, with the security measures already implemented or to be adopted in the future under the applicable personal data protection legislation;
  • assist the Controller, where necessary, in the data protection impact assessment (DPIA) process under Art. 35 of the Law, and in any prior consultation with the Supervisory Authority under Art. 36 of the Law, where the data protection impact assessment indicates that the Processing would result in a high risk in the absence of measures taken by the Controller to mitigate the risk;
  • delete or return all Personal Data at the end of the Processing and delete existing copies, in the manner and within the time limits of Art. D.12, unless Union or Member State law requires their storage (Art. 28(3)(g) of the Law);
  • cooperate with the Controller in order to fulfil the Controller’s obligation to respond to requests for the exercise of the data subject’s rights under the Law and provide all the support necessary to enable the Controller to respond within one month of the request, extendable by two months in particularly complex cases, pursuant to Art. 12(3) of the Law;
  • promptly inform the Controller of any new processing and of any matter relevant to personal data protection legislation, including any complaints made by data subjects and any requests submitted to the Italian Data Protection Authority (Garante);
  • within the scope of the responsibilities thus entrusted to it and in compliance with the related instructions, the Processor shall be required to keep, constantly updated and available to the Controller at all times, a record of all categories of processing activities carried out on behalf of the Controller, pursuant to Art. 30(2) of the Law, in writing, including in electronic form. The Processor shall also have the exclusive obligation to prepare and carry out periodic internal audits of the work of its Sub-Processors and authorised persons;
  • in carrying out the necessary Processing operations and in ceasing such Processing, the Processor shall comply with the regulations applicable from time to time and with the instructions given by the Controller. The Processor also undertakes to maintain and apply appropriate security measures under the applicable personal data protection legislation;
  • the Processor shall be responsible for providing in writing to the persons authorised to process data who operate under its direct authority the necessary instructions and binding provisions for processing regarding compliance with the provisions in force, providing a copy thereof to the Controller where requested.

Each Party is liable for damage caused by the Processing in accordance with Art. 82 of the Law. As between the Parties, liability for non-compliance with this Deed is governed by the liability clauses of the Contract, which also apply to this Deed. The rights of Data Subjects remain unaffected.

Failure by the Processor to comply with the provisions of this article and of the Annex referred to constitutes a breach of the Contract. Where the breach is serious, the Controller may terminate the Contract and this Deed in accordance with the termination clauses of the Contract.

The Processor, pursuant to Art. 28(4) of the Law, acknowledges that, where its sub-processor fails to fulfil its obligations relating to the appointment received, it remains fully liable to the Controller for the performance of the Sub-Processor’s obligations.

D.5 Obligations of the controller

The Controller is aware and accepts that, in order to enable the Processor to provide the Service, it will provide the Processor with Personal Data of which it is the Controller.

The Controller warrants and guarantees that there is an appropriate legal basis for the Processing and for the transmission to the Processor of the Personal Data of which it is Controller, in relation to the provision of the Service.

The Controller remains responsible for the lawfulness of the processing carried out with the Service. It decides which functions to activate, including location detection in mobile clock-ins and the connection of terminals with biometric recognition, assesses their legal basis under Arts. 6 and 9 of the Law and the guidance of the Italian Data Protection Authority (Garante per la protezione dei dati personali), informs Data Subjects and fulfils the obligations laid down by employment legislation.

The Controller manages its users, roles and access authorisations for the Service, protects the credentials and devices under its control and enters into the Service only Personal Data relevant to the purposes indicated in Art. D.4.

D.6 Authorisation for processing by sub-processors

The Controller acknowledges, accepts and agrees that, solely for the provision of the Service and in compliance with this Deed, the Controller’s Personal Data may be processed by the Processor or by its Sub-Processors as described in the List of Sub-Processors in Annex 1 to this Deed.

By means of this Deed, the Controller grants the Processor a general written authorisation to engage the Sub-Processors indicated in Annex 1 and to replace them or add others in accordance with this article (Art. 28(2) of the Law). Sub-Processors are required to comply with the obligations set out in this Deed.

The Processor is authorised to use Sub-Processors provided that it:

  • informs the Controller in advance of the identity of the Sub-Processors as described in the relevant list and notifies it of any update to that list at least 30 days in advance, in order to allow the Controller to object to the engagement of such Sub-Processors;
  • enters into agreements with the Sub-Processors containing the same obligations as those set out in this Deed with regard to the Processing of Personal Data;
  • exercises adequate checks when selecting Sub-Processors and remains liable for the fulfilment of the obligations contained in this Deed by the Sub-Processors involved;
  • at the Controller’s request, provides the Controller with adequate information on the actions and measures that the Processor and its Sub-Processors have taken to ensure compliance with the provisions of this Deed.

The Controller may object on legitimate grounds within 10 days of receipt of the notice. In that case the Parties seek a solution in good faith and, failing that, the Controller may withdraw from the Service concerned before the change takes effect, with a refund of the fee for the unused period.

D.7 Data subjects

The Personal Data processed relate to the following categories of Data Subjects:

  • employees and collaborators of the Controller and of the companies the Controller manages with the Service
  • users and administrators designated by the Controller to use the Service

D.8 Processing operations

The Personal Data processed will be subject to the following Processing activities:

  • Collection
  • Recording
  • Use
  • Processing
  • Alteration
  • Selection
  • Retrieval
  • Comparison
  • Restriction
  • Storage
  • Erasure
  • Consultation
  • Disclosure

The personal data processed are as follows:

  • Identification and contact data (employee master data, tax code, contact details, user credentials and profiles)
  • Data relating to the employment relationship (clock-ins, schedules and shifts, absence reasons, holiday and leave requests, communications, expense reports with their attachments)
  • Documents and payslips uploaded by the Controller, with the pay data and any bank details contained therein
  • Location data of clock-ins made from mobile devices (latitude, longitude and accuracy), when the function is activated by the Controller
  • Special categories of data (Art. 9 GDPR), limited to data concerning health contained in sick-leave absence reasons, with the certificate code, description and any attachments entered by the Controller, and in occupational health surveillance deadlines
  • Biometric data (Art. 9 GDPR) that may be processed by means of terminals with biometric recognition connected by the Controller
  • Data relating to criminal convictions and offences (Art. 10 GDPR) are not within the scope of the Service

In Remote Support the Processor may view and, only if necessary for analysis, acquire the data present in the Controller’s installation, belonging to the categories indicated above.

The Processing is carried out with IT tools and lasts for the period in which the Services are provided and for the retrieval and deletion periods indicated in Art. D.12.

The Parties undertake to cooperate in good faith to ensure compliance with the provisions of this Deed, including, but not limited to, the duty to ensure the correct and timely exercise of the Data Subject’s rights and to manage security incidents/Personal Data Breaches in order to mitigate their possible adverse effects.

In compliance with this Deed, the Parties cooperate in good faith to make available to each other and to the Supervisory Authority the information necessary to demonstrate compliance with the applicable personal data protection legislation.

The Processor makes available to the Controller all information necessary to demonstrate compliance with the obligations laid down in Art. 28 of the Law and allows for and contributes to audits, including inspections, conducted by the Controller or another auditor mandated by the Controller, with reasonable notice (Art. 28(3)(h) of the Law).

The Processor normally fulfils audit requests by making available documentation on the measures adopted, including any certifications of its management system. On-site inspections are agreed with at least 30 days’ notice, take place during working hours, not more than once a year except in the event of a Personal Data Breach or a request from a Supervisory Authority, and in a manner that protects the confidentiality of other customers’ data.

The Processor undertakes to process personal data in accordance with appropriate technical and organisational measures pursuant to Art. 32 of the Law.

The Processor undertakes to ensure that such security measures are also complied with by authorised sub-processors, under its direct responsibility.

D.9 Rights of the data subject

Taking into account the nature of the Processing, the Processor assists the Controller by appropriate technical and organisational measures to ensure the fulfilment of the Controller’s obligations to respond to requests for the exercise of the Data Subject’s rights.

The Processor shall provide the Controller with adequate cooperation and assistance, and shall provide all information that may be deemed necessary to respond to the Data Subject or otherwise to enable the Controller to demonstrate compliance with its duties and obligations regarding the rights of the Data Subject under the Law and, more generally, the applicable personal data protection legislation.

The Processor forwards to the Controller, without undue delay, any requests received directly from Data Subjects and does not respond to them itself, unless otherwise instructed by the Controller.

D.10 Personal data breach

If the Processor becomes aware of a Personal Data Breach, it shall:

  • take appropriate measures to contain and mitigate such Personal Data Breach, including notifying the Controller as soon as possible and in any case no later than 48 hours after becoming aware of the Personal Data Breach, in order to enable the Controller to promptly implement the necessary countermeasures;
  • cooperate with the Controller in investigating the nature, the categories and approximate number of Data Subjects concerned, the categories and approximate number of Personal Data records concerned and the likely consequences of such breach, in a manner commensurate with its seriousness and its overall impact on the Controller, and therefore on the Data Subject and on the provision of the Service(s) under this Deed;
  • prepare a written report to be sent to the Controller and/or the Controller’s DPO containing a detailed description and as much information as possible about the incident that caused the data breach;

Communications are sent to the contact details indicated by the Controller in the order or in its account.

Where the Applicable Personal Data Protection Laws require notification of the Personal Data Breach to the competent Supervisory Authorities and to the Data Subjects, and where it concerns the Controller’s Personal Data, the Processor shall defer to and take instructions from the Controller, which alone shall have the right to determine the measures to be taken to comply with the Law or to remedy any risk, including but not limited to:

  • determining whether notice is to be given to any individual, regulatory authority, judicial authority, or others as required by Law, or as required at the Controller’s discretion; and
  • determining the content of such notice, whether any type of remedy may be offered to the Data Subject affected by the breach, and the nature and extent of such remedy.

D.11 Resilience

The Processor adopts and updates, in accordance with the standards of professional diligence, appropriate protocols and methodologies to ensure an adequate level of resilience. For TimeStudio Cloud the recovery objectives are those indicated in the Contract.

D.12 Return, deletion and retention

On cessation of TimeStudio Cloud, the Controller has a retrieval period of 60 calendar days, during which read-only access and export remain available. Upon written request, the Processor provides within 30 days a complete export of the Personal Data in a structured, commonly used and machine-readable format. At the end of the retrieval period, the Processor deletes the Personal Data from the production systems within 30 days.

On expiry of the ADA module, the documents and other data stored in the online service remain retrievable by the Controller for 60 days, after which the Processor deletes them within 30 days. During the relationship, clock-ins and location data are deleted from the online service when they are downloaded into the Controller’s software and in any case after 90 days.

In Remote Support, any files acquired for analysis are deleted when the intervention is closed and in any case within 30 days of their acquisition.

Backup and replica copies containing the Personal Data remain encrypted, are no longer used to process the Controller’s Personal Data and are erased through the ordinary rotation of copies within 3 years of deletion from the production systems. If, during this interval, the restoration of a system brings the Controller’s Personal Data back online, the Processor deletes them again without delay.

The Processor may retain the Controller’s Personal Data beyond the stated periods only if and for as long as required by Union or Member State law, ensuring their confidentiality and processing them for that purpose only (Art. 28(3)(g) of the Law).

Upon written request from the Controller, the Processor issues within 5 working days a certificate attesting the deletion.

D.13 Final clauses

Amendments to this Deed are made in writing. New versions of the Deed prepared by the Processor apply from the next renewal, in the manner and with the notice provided for in the Contract for changes to the general terms, and do not reduce the guarantees required by Art. 28 of the Law. Updates to Annex 1 follow Art. D.6.

The invalidity, even partial, of one or more clauses of this Deed does not affect the validity of the remaining clauses.

By means of this Deed, the Parties expressly intend to revoke and replace any other contract or agreement existing between them relating to the processing of personal data in connection with the Services.

For matters not expressly provided for in this agreement, reference is made to the personal data protection legislation in force and to the Contract signed between the Parties.

Communications relating to this Deed are sent by the Controller to privacy@securitaly.com and, where proof of receipt is required, to the certified e-mail (PEC) address securitaly@pec.it.

This Deed forms an annex to the Contract and the Controller accepts it by accepting the Contract, at the e-commerce checkout or by means of the order confirmation. The Processor keeps the version, date and proof of acceptance. When the Contract is concluded by offer and order confirmation, the Parties may also sign the Deed.

D. Annex 1, Sub-Processors

Securitaly, acting as Processor, declares that it uses the Sub-Processors indicated in the following table and, should it subsequently use others, undertakes to inform the Controller in accordance with Art. D.6.

The following table identifies the Sub-Processors engaged by the Processor in the relevant country.

Sub-processors

Country/countries in which Personal Data are processed and purposes

Contact details of the Data Protection Officer or of the person responsible for privacy matters

Zinca S.r.l., Piazza Caduti del Lavoro 200, 47522 Cesena (FC)

Italy.

dpo@zinca.com

Cloudflare Germany GmbH, a company of the Cloudflare, Inc. group

European Union and, for the operation of the global network, third countries, with the European Commission’s standard contractual clauses (Chapter V of the GDPR). Application protection and name resolution

dpo@cloudflare.com

Synology C2, cloud storage service of the Synology group

Germany, Frankfurt data centre. Storage of the replica of the backups, encrypted before transfer with a key held by the Processor and not accessible to the Sub-Processor

Synology GmbH, Data Protection, Grafenberger Allee 295, 40237 Düsseldorf (Germany)

The list of further processors used by Zinca S.r.l., established in Italy, is available at the Controller’s request.

In the event of changes to the above list, the Controller will be informed by means of a new Annex 1 so that it may object to the engagement of new Sub-processors, with the notice provided for in Art. D.6.

The new Annex 1 will be deemed tacitly accepted by the Controller if it does not object within 10 days of receipt of the new Annex 1.

E. EXPRESSLY APPROVED CLAUSES

By ticking the second checkbox at checkout, the Customer expressly approves, pursuant to Articles 1341 and 1342 of the Italian Civil Code, the following clauses:

  • Part A, for all orders: A.7.1 (limitation of liability) and A.10.2 (competent court).
  • Part B, if the order includes TimeStudio On-Premise or a terminal with the licence included: B.2.3 (licence limits), B.4.2 (renewal and cessation of modules), B.5.1 (advance payment), B.7.1 (permitted use and restrictions), B.9.2 (warranty exclusions), B.10.1 and B.10.2 (exclusion and limitation of liability), B.11.1 and B.11.2 (termination and suspension), B.12.1 (amendments to the Agreement) and B.15.2 (competent court).
  • Part C, if the order includes TimeStudio Cloud: C.4.2 (renewal, suspension on expiry and non-refundability), C.4.3 (advance payment and change of plan), C.5.2 (permitted use), C.6.3 (service levels and exclusion of credits and refunds), C.10.2 and C.10.3 (withdrawal, retrieval and deletion of data), C.11.1, C.11.2 and C.11.3 (suspension and termination), C.12.1 and C.12.2 (changes), C.13.2 (exclusion and limitation of liability) and C.15.2 (competent court).