1Scope, structure and roles
- 1.1The parties. This Data Processing Agreement (the "DPA") is entered into between Kevin Alvarado, a natural person doing business as FTE Tracker ("FTE Tracker"), a sole proprietorship and not a corporation, limited liability company or other separate legal entity, and the customer organization identified in the Order (the "Customer").
- 1.2Incorporation. This DPA forms part of the Agreement between the parties, as defined in clause 1.4 of the Terms of Service (the "Terms"). Capitalised terms not defined here have the meaning given in the Terms. It applies whenever FTE Tracker Processes Customer Personal Data on the Customer's behalf.
- 1.3Roles. The Customer determines the purposes and means of the Processing of the personal data of its own employees, supervisors, project managers and administrators. Accordingly:
- (a)the Customer is the controller (and, under United States state privacy law, the business) in respect of Customer Personal Data; and
- (b)FTE Tracker is the processor (and, under United States state privacy law, the service provider), Processing Customer Personal Data only on the Customer's behalf and on its instructions.
- 1.4Where the Customer is itself a processor. If the Customer Processes any personal data on behalf of a third party, FTE Tracker acts as a subprocessor to the Customer, and the Customer warrants that it has the authority of that third party to appoint FTE Tracker on these terms and to give the instructions it gives.
- 1.5Where FTE Tracker is a controller. FTE Tracker acts as a controller, and this DPA does not apply, in respect of: the business contact details of the Customer's billing and administrative contacts; its own invoices, correspondence and support records; and the personal data of visitors to the public website and the Demo. That processing is described in the Privacy Policy.
- 1.6Precedence. In relation to the Processing of Customer Personal Data, this DPA prevails over the Terms and over any Order, unless the Order expressly amends this DPA and is signed by both parties.
- 1.7Applicability of laws. The provisions of this DPA that refer to a particular law apply only to the extent that law applies to the Processing in question. Nothing in this DPA extends the territorial or material scope of any law to Processing to which it would not otherwise apply.
- 1.8Execution. No signature is required: this DPA takes effect on the Effective Date as part of the Agreement. FTE Tracker will provide a countersigned copy on written request to legal@ftetracker.com.
2Defined terms
- Applicable Data Protection Law — all laws relating to the protection of personal data that apply to a party's Processing under the Agreement, which may include the California Consumer Privacy Act as amended by the California Privacy Rights Act ("CCPA"), comparable United States state privacy statutes, and, where they apply, the EU General Data Protection Regulation and the UK GDPR ("GDPR").
- Business, Service Provider, Sell, Share — as defined in the CCPA.
- Controller, Processor, Data Subject, Personal Data, Personal Data Breach, Processing, Supervisory Authority — as defined in the GDPR, and read as including the equivalent concepts in any other Applicable Data Protection Law.
- Customer Personal Data — the Personal Data contained within Customer Data that FTE Tracker Processes on the Customer's behalf under the Agreement, as described in Annex 1.
- PHI — protected health information as defined at 45 CFR 160.103.
- Security Measures — the technical and organisational measures set out in Annex 2.
- Subprocessor — a third party engaged by FTE Tracker to Process Customer Personal Data on its behalf, or that receives technical connection data when a page of the Service is loaded, as listed in Annex 3 and on the Subprocessors page.
3Subject matter, duration, nature and purpose
- 3.1Subject matter. The Processing of Customer Personal Data necessary to provide the Service under the Agreement.
- 3.2Duration. From the Effective Date until Customer Personal Data is deleted under clause 12 — that is, for the Term and then for the three‑year retention period in clause 12.3, unless the Customer requests earlier deletion.
- 3.3Nature and purpose. Hosting, storage, structured recording, retrieval, display, approval workflow, generation of certification records and reports, maintenance, security monitoring, backup where provided by a Subprocessor, support at the Customer's request, and deletion. FTE Tracker does not carry out automated decision‑making or profiling in relation to Data Subjects, does not carry out any analysis of Customer Personal Data for its own purposes, and does not monitor the content Users enter.
- 3.4Categories. The categories of Data Subject and of Customer Personal Data, and the frequency of Processing, are set out in Annex 1.
4Processing on documented instructions
- 4.1Instructions only. FTE Tracker will Process Customer Personal Data only on the Customer's documented instructions, including in relation to transfers, unless required to do otherwise by law to which it is subject.
- 4.2What counts as an instruction. The Customer's documented instructions consist of the Agreement, the configuration and settings its Administrators choose within the Service, the operations Users perform through the Service, and any further written instruction the Customer sends to privacy@ftetracker.com. Instructions outside the scope of the Service may be refused, or accepted subject to a separate written agreement and a reasonable charge.
- 4.3Restrictions FTE Tracker accepts. FTE Tracker will not:
- (a)Sell or Share Customer Personal Data, or disclose it for monetary or other valuable consideration;
- (b)retain, use or disclose Customer Personal Data for any purpose other than performing the Service and the other purposes stated in clause 3.3, or as otherwise permitted by Applicable Data Protection Law;
- (c)retain, use or disclose Customer Personal Data outside the direct business relationship between the parties;
- (d)combine Customer Personal Data with personal data received from or on behalf of any other person, or collected from its own interactions with any individual, except where permitted by Applicable Data Protection Law for a service provider;
- (e)use Customer Personal Data to train, fine‑tune, evaluate or develop any machine‑learning or artificial‑intelligence model; or
- (f)create de‑identified, aggregated, statistical or benchmark data sets from Customer Personal Data.
- 4.4Unlawful instructions. If FTE Tracker considers that an instruction infringes Applicable Data Protection Law, it will inform the Customer without undue delay and may suspend performance of that instruction until it is confirmed, withdrawn or amended. FTE Tracker is not obliged to give legal advice and does not do so.
- 4.5Processing required by law. Where FTE Tracker is required by law to Process Customer Personal Data other than on the Customer's instructions, it will inform the Customer of that requirement before Processing, unless the law prohibits it from doing so on important grounds of public interest.
- 4.6Government and third‑party demands. If FTE Tracker receives a binding demand from a public authority or a third party for Customer Personal Data, it will, unless legally prohibited, notify the Customer without undue delay, provide the Customer a reasonable opportunity to challenge the demand, disclose only the minimum required, and where possible redirect the requester to the Customer.
- 4.7The Customer's own obligations. The Customer is responsible for: establishing a lawful basis for the Processing; giving its workforce whatever privacy notices its law requires; the accuracy and relevance of the Personal Data it enters; configuring roles, approvers and access appropriately; deactivating Users who leave; the lawfulness of its instructions; and not entering the data excluded by clause 5.
5Excluded data: PHI and special categories
No PHI, and no Business Associate Agreement
The Service is not designed to receive protected health information. The Customer must not enter PHI into any field of the Service, including free‑text description and note fields on time entries, supervisor review notes, rework and send‑back reasons, leave descriptions, user and fund names, file names, and any document a User uploads.
FTE Tracker does not act as a business associate within the meaning of 45 CFR 160.103, does not perform any function or activity involving PHI on behalf of a covered entity or another business associate, and does not execute Business Associate Agreements. Neither this DPA nor any other part of the Agreement is or creates a Business Associate Agreement, and nothing in either may be construed as one.
- 5.1The Customer's undertaking. The Customer acknowledges that many of its Users may work for or with a HIPAA covered entity, and undertakes to instruct its Users, before giving them access, that clinical information, patient or client information and any other PHI must never be entered into the Service.
- 5.2Special categories. The Customer must not enter special categories of personal data, as defined in Article 9 of the GDPR, or sensitive personal information as defined in the CCPA, into free‑text fields of the Service.
- 5.3Leave records — a point for the Customer's own assessment. The Service records the leave types that the Customer's own Administrators create, and a leave entry therefore records that a named individual was absent on a stated date under a leave type the Customer has named. Where the Customer names a leave type in a way that indicates a reason for absence, the resulting record may carry an inference about that individual. The Customer, as controller, decides which leave types exist and how they are named, and should take this into account in its own privacy notices and assessments. FTE Tracker neither requires nor recommends any particular leave type.
- 5.4No monitoring. FTE Tracker does not review, scan or monitor the content of Customer Personal Data and has no practical means of detecting excluded data. It relies on the Customer's compliance with this clause 5.
- 5.5If excluded data is entered anyway. If FTE Tracker becomes aware that excluded data has been entered, it may notify an Administrator, require the Customer to remove it, remove it itself where the application permits, or suspend access under clause 6.6 of the Terms. Entering PHI is a material breach of the Agreement, and clause 13.2 of the Terms applies to it.
6Confidentiality of personnel and access
- 6.1Who "personnel" means here. FTE Tracker is a sole proprietorship. Its personnel are Kevin Alvarado and any individual contractor he engages. There are no employees.
- 6.2Commitment to confidentiality. Kevin Alvarado is bound by the confidentiality obligations in clause 14 of the Terms and by this DPA. Any individual contractor engaged by FTE Tracker who may access Customer Personal Data is engaged only under a written agreement imposing confidentiality obligations at least as protective as those in clause 14 of the Terms, and those obligations survive the end of the engagement.
- 6.3Access is limited by purpose, and stated plainly. FTE Tracker holds administrative credentials for the hosting and authentication Subprocessor and is therefore technically able to access Customer Personal Data. It exercises that access only to: provision or reconfigure the Customer's organization; investigate or resolve a fault, security issue or availability issue; carry out a task the Customer has asked it to carry out; export or delete data under clause 12; or comply with law. It does not access Customer Personal Data for any other purpose.
- 6.4Support access. Where support requires FTE Tracker to look at a Customer's records, it will ask an Administrator first, unless the access is necessary to address an active security or availability incident.
7Security of processing
- 7.1The measures. FTE Tracker implements and maintains the Security Measures set out in Annex 2, taking into account the state of the art, the cost of implementation, and the nature, scope, context and purposes of the Processing, as well as the risk to Data Subjects. Annex 2 describes the measures that are actually implemented; it does not describe measures that are planned or aspirational, and it states expressly what is not implemented.
- 7.2Changes to the measures. FTE Tracker may update the Security Measures, provided that the level of protection is not materially reduced. Material changes are published with the updated version of this DPA.
- 7.3No certification. FTE Tracker holds no SOC 2 report, no ISO 27001 certificate, no HITRUST certification, no HIPAA attestation and no other third‑party security or compliance certification, and does not claim one. A Customer whose procurement process requires a vendor to hold such a certification should take that into account before contracting.
- 7.4The Customer's share of security. The Customer is responsible for its own security decisions, including who it authorises, what role it gives them, how promptly it deactivates leavers, and the security of the devices and browsers its Users use. In particular, the Customer acknowledges paragraph C of Annex 2: role‑based visibility between colleagues within one organization is an interface control and not a boundary enforced by the database.
- 7.5Signed certification files. A signed certification PDF uploaded by a supervisor is stored in a local database inside the browser used to upload it, and not on any server operated by or for FTE Tracker. It is therefore outside the Security Measures, is not backed up, cannot be produced by FTE Tracker, and cannot be deleted by FTE Tracker. The Customer is responsible for the security and retention of those files and for erasing them from its own devices when it needs to.
8Subprocessors
- 8.1General authorisation. The Customer gives FTE Tracker general authorisation to engage the Subprocessors listed in Annex 3 and published on the Subprocessors page, and to engage further Subprocessors subject to the notice and objection procedure in clauses 8.4 and 8.5.
- 8.2Two kinds of Subprocessor. Annex 3 distinguishes between Subprocessors that store and Process Customer Personal Data on FTE Tracker's behalf, and providers that receive only technical connection data — an IP address, a browser user‑agent string and a referring page address — when a page of the Service loads in a User's browser. The second kind receives no Customer Data.
- 8.3Terms imposed on Subprocessors. A Subprocessor in Part 1 of Annex 3 — one that Processes Customer Personal Data — is engaged under written data protection terms imposing obligations that offer a level of protection materially equivalent to those in this DPA. Where that Subprocessor contracts on its own published standard terms rather than on a negotiated agreement, FTE Tracker relies on those published data processing terms and will identify them to the Customer on request. FTE Tracker remains fully liable to the Customer for a Part 1 Subprocessor's performance of those obligations to the same extent as for its own performance.The position is different for Part 2. A provider in Part 2 of Annex 3 receives only technical connection data and no Customer Data, and is used on that provider's own published terms rather than under terms negotiated by FTE Tracker. In the case of the two globally distributed delivery networks there is no agreement specific to FTE Tracker at all: they are public services that any page may request a file from, they receive no instruction from FTE Tracker, and each determines its own purposes for the connection data it receives, as a controller in its own right. FTE Tracker does not represent that it has imposed data protection obligations on them. A Customer that objects to either of them should raise it before contracting under clause 8.5, because the answer is to remove the dependency rather than to contract around it.
- 8.4Notice of a new Subprocessor. Before a new Subprocessor begins Processing Customer Personal Data, FTE Tracker will update the Subprocessors page and give the Customer at least thirty (30) days' written notice by email to the Administrators and billing contact on record. Any Customer may also ask to be added to the notification list for that page by writing to privacy@ftetracker.com.
- 8.5Objection. The Customer may object to a new Subprocessor on reasonable data protection grounds by written notice within thirty (30) days of the notice under clause 8.4. The parties will discuss the objection in good faith. If FTE Tracker cannot provide the Service without the proposed Subprocessor and the objection is not withdrawn, either party may terminate the Agreement on written notice, and FTE Tracker will refund the portion of prepaid Fees relating to the period after termination. That is the Customer's sole remedy for such an objection.
- 8.6Replacement in an emergency. If a Subprocessor ceases to be available, or must be replaced urgently for security or continuity reasons, FTE Tracker may engage a replacement immediately and will give notice as soon as reasonably practicable, after which clause 8.5 applies.
- 8.7Sub‑subprocessors. Subprocessors engage their own subprocessors — for example, the cloud infrastructure on which a hosting provider runs. Those are published by the Subprocessor concerned; FTE Tracker will identify where to find that list on request.
9Assistance with data subject requests
- 9.1Self‑service first. The Service is built so that the Customer can respond to most requests itself. An Administrator can view and correct a User's record, view and correct time entries subject to the locking rules in clause 3.3 of the Terms, export records, deactivate a User, and delete a User.
- 9.2What deletion within the Service does, and does not, do. This is stated precisely because it affects what the Customer can promise a Data Subject. Deleting a User through the Service removes that User's record, their time entries and their notifications from the organization's data. It does not remove:
- (a)entries in the event log that reference that individual — for example, that they approved a colleague's entry, or that an Administrator changed their role — because the event log is the record of who did what and is not editable;
- (b)the identification of that individual within a certification package that has already been generated or certified, which is a fixed audit record; or
- (c)the corresponding sign‑in account held by the authentication Subprocessor. FTE Tracker will delete that sign‑in account, including any authenticator enrolment attached to it, on written request from an Administrator.
- 9.3Assistance beyond the Service. Where the Customer cannot fulfil a request through the Service, FTE Tracker will provide reasonable assistance, taking into account the nature of the Processing, within ten (10) business days of a written request from an Administrator. Where a request requires substantial work beyond reasonable assistance, FTE Tracker will say so, and may charge at a rate agreed in advance in writing.
- 9.4Requests made directly to FTE Tracker. If a Data Subject contacts FTE Tracker directly, FTE Tracker will not respond substantively other than to acknowledge the request and direct the individual to their employer, and will forward the request to the Customer's Administrators without undue delay and in any event within five (5) business days.
- 9.5Complaints and regulators. FTE Tracker will forward to the Customer, within the same period, any complaint or communication it receives from a Supervisory Authority or other regulator relating to Customer Personal Data, unless it is prohibited from doing so.
10Assistance with security, assessments and consultation
- 10.1General assistance. Taking into account the nature of the Processing and the information available to it, FTE Tracker will provide the Customer with reasonable assistance in meeting the Customer's own obligations relating to the security of Processing, notification of Personal Data Breaches to regulators and Data Subjects, data protection impact assessments and prior consultation with a Supervisory Authority.
- 10.2Impact assessments. That assistance consists principally of this DPA and its Annexes, the Privacy Policy, the Subprocessors page, and written answers to reasonable questions about the Processing.
- 10.3Security questionnaires. FTE Tracker will complete one reasonable security or vendor‑risk questionnaire per Customer in any twelve‑month period at no charge, and will respond within twenty (20) business days. Additional or unusually long questionnaires may be subject to a reasonable fee agreed in advance.
11Personal Data Breach
- 11.1Notification within 72 hours. FTE Tracker will notify the Customer of a Personal Data Breach affecting that Customer's Customer Personal Data without undue delay and in any event within seventy‑two (72) hours of becoming aware of it. Notice is given by email to the Administrators and the billing contact on record.
- 11.2What the notice will contain. So far as the information is available at the time, the notice will state:
- (a)the nature of the Personal Data Breach, including where possible the categories and approximate number of Data Subjects and of records concerned;
- (b)when it occurred or is believed to have occurred, when and how FTE Tracker became aware of it, and whether it is ongoing;
- (c)the likely consequences of the Personal Data Breach;
- (d)the measures taken or proposed to address it, including measures to mitigate its possible adverse effects;
- (e)whether the Personal Data Breach originated with FTE Tracker or with a Subprocessor and, if a Subprocessor, what that Subprocessor has reported; and
- (f)the contact point for further information, which is privacy@ftetracker.com.
- 11.3Information in phases. Where all the information in clause 11.2 is not available within seventy‑two hours, FTE Tracker will send the initial notice within that period with what it has, say what is still unknown, and provide the remaining information in phases without further undue delay as it is established.
- 11.4Investigation and records. FTE Tracker will investigate the Personal Data Breach, take reasonable steps to contain and remediate it, and document the facts, its effects and the remedial action taken. It will make that record available to the Customer on request.
- 11.5Who notifies whom. As controller, the Customer is responsible for deciding whether and how to notify a Supervisory Authority, a funder, an insurer or affected Data Subjects, and for making any such notification. FTE Tracker will not notify a Supervisory Authority or a Data Subject on the Customer's behalf unless the Customer instructs it in writing to do so or the law requires it, and will give the Customer reasonable assistance with the Customer's own notifications.
- 11.6Not an admission. Notification under this clause is not an acknowledgement of fault or liability by FTE Tracker.
- 11.7The Customer's part. The Customer will keep its Administrator and billing contact addresses current so that notice can be given, and will notify FTE Tracker without undue delay at security@ftetracker.com if it becomes aware of a compromise of any User credential or authenticator, or of any unauthorised access to its organization's data.
12Return and deletion
- 12.1During the Term. The Customer may export its records at any time using the export functions of the Service.
- 12.2On termination. For thirty (30) days after the effective date of termination or expiry, FTE Tracker will, on written request from an Administrator, either make the Service available for the sole purpose of export or provide a copy of the Customer Data in a structured, machine‑readable file, at its option, as provided in clause 9.8 of the Terms. FTE Tracker cannot return signed certification PDFs, because it does not hold them (clause 7.5).
- 12.3Three years, then deletion. FTE Tracker retains Customer Personal Data for three (3) years following the effective date of termination or expiry, and then deletes it. That period is set deliberately to match the federal record retention period at 2 CFR 200.334 to which many Customers are themselves subject, so that a Customer's records remain recoverable for as long as its own retention obligation is likely to run.
- 12.4Earlier deletion. The Customer may at any time instruct FTE Tracker in writing, through an Administrator, to delete its Customer Personal Data earlier. FTE Tracker will delete it within thirty (30) days of the instruction and confirm the deletion in writing. Deletion is irreversible; the Customer should export first.
- 12.5Retention is not the Customer's compliance. Retention by FTE Tracker is not a substitute for the Customer's own record retention. The Customer, not FTE Tracker, is the custodian of its records for audit purposes and remains responsible for retaining them for as long as its awards, its funders and its own law require.
- 12.6Exceptions. FTE Tracker may retain Customer Personal Data beyond these periods where required by law, or where necessary to establish, exercise or defend a legal claim, in which case it will retain only what is necessary, will not Process it for any other purpose, and will continue to protect it under this DPA until deletion is possible. Deletion applies to the live environment; any residual copies in a Subprocessor's routine backups are overwritten or expire in the ordinary course of that Subprocessor's operation.
13Audit and information rights
This clause is written to describe what a one‑person business can genuinely deliver, rather than to promise an audit programme that could not be honoured.
- 13.1Information FTE Tracker makes available. FTE Tracker will make available to the Customer the information necessary to demonstrate compliance with this DPA, in the following ways:
- (a)this DPA and its Annexes, which describe the Processing, the Security Measures actually implemented, and what is not implemented;
- (b)the published Subprocessors page and the Privacy Policy;
- (c)written answers to reasonable questions about the Processing, within twenty (20) business days of a written request;
- (d)one completed security or vendor‑risk questionnaire in any twelve‑month period, at no charge, under clause 10.3; and
- (e)identification of the compliance documentation that its Subprocessors publish, together with copies of any such documentation that FTE Tracker holds and is permitted to share.
- 13.2Audit. Where the information in clause 13.1 is not sufficient for the Customer to meet an obligation under Applicable Data Protection Law, the Customer may, no more than once in any twelve‑month period and on at least thirty (30) days' written notice, carry out an audit limited to (a) a remote interview with Kevin Alvarado of up to four hours, and (b) inspection of documentation relevant to the Processing under the Agreement. An audit may also be carried out where a Personal Data Breach affecting the Customer has occurred, or where Applicable Data Protection Law or a Supervisory Authority requires it, without regard to the annual limit.
- 13.3What FTE Tracker cannot offer. FTE Tracker is a sole proprietorship. It operates no premises of its own to which access could be given, holds no data centre, and has no right to admit a Customer or a Customer's auditor to a Subprocessor's facilities or systems. It therefore does not offer on‑site audits, physical inspection of infrastructure, access to Subprocessor systems, or penetration testing of Subprocessor infrastructure, and no provision of this DPA should be read as offering any of them.
- 13.4Conduct and cost. An audit must be conducted during business hours, with minimum disruption, by the Customer or by an independent auditor that is not a competitor of FTE Tracker and that is bound by written confidentiality obligations. The Customer bears its own costs. FTE Tracker may charge a reasonable fee, agreed in advance, for time spent supporting audits in excess of eight hours in any twelve‑month period.
- 13.5Confidentiality of findings. Information obtained in an audit is FTE Tracker's Confidential Information and may be used only to verify compliance with this DPA and to meet the Customer's own regulatory obligations.
- 13.6Regulators. FTE Tracker will cooperate with a Supervisory Authority exercising audit or investigatory powers to the extent required by law.
14Location of processing and international transfers
This clause states the position as it actually is, including where it is a matter of a Subprocessor's configuration rather than of FTE Tracker's own code.
- 14.1Where FTE Tracker is. FTE Tracker operates from the Commonwealth of Puerto Rico, an unincorporated territory of the United States. The Service is offered to organizations in the United States and its territories.
- 14.2Where stored data sits. Customer Personal Data stored by the Service is held by the hosting, database and authentication Subprocessor identified in Annex 3. The region in which that Subprocessor holds the data is a configuration of that Subprocessor's platform. FTE Tracker will confirm the current region in writing on request before the Customer contracts, and will notify Customers in writing if it changes materially. FTE Tracker does not publish a region claim in this document that it cannot evidence at the time a Customer asks.
- 14.3Content delivery and typefaces. When a page of the Service, the public website or the Demo loads, the User's browser requests a script library and typeface files from globally distributed networks operated by the third parties named in Annex 3. Those requests carry the User's IP address, browser user‑agent string and the address of the referring page. They do not carry Customer Data. Because those networks are globally distributed, such a request may be served from infrastructure outside the United States, and the recipient may be a controller in its own right for that limited technical data.
- 14.4No transfer mechanism is currently in place. FTE Tracker has not entered into the European Commission's Standard Contractual Clauses, the UK International Data Transfer Addendum or any other cross‑border transfer mechanism, and is not certified under the EU‑US Data Privacy Framework. A Customer whose Processing is subject to the GDPR or UK GDPR, or that has Users in the EEA, the United Kingdom or Switzerland, should raise that with FTE Tracker at legal@ftetracker.com before contracting so that the position can be addressed in the Order. FTE Tracker has not appointed a representative under Article 27 of the GDPR and is not required to do so on the basis of the Processing described in this DPA.
- 14.5No data protection officer. FTE Tracker has not appointed a data protection officer. Data protection correspondence goes to privacy@ftetracker.com, which reaches Kevin Alvarado directly.
15California-specific terms
- 15.1Roles. Where the CCPA applies, the Customer is the business and FTE Tracker is a service provider. Customer Personal Data is disclosed to FTE Tracker only for the limited and specified business purpose of providing the Service under the Agreement.
- 15.2Certification. FTE Tracker understands the restrictions set out in clause 4.3 and in the CCPA as they apply to a service provider, and will comply with them. FTE Tracker does not Sell or Share Customer Personal Data, and receives no consideration for it other than the Fees for the Service.
- 15.3Customer's oversight rights. The Customer may take reasonable and appropriate steps to confirm that FTE Tracker uses Customer Personal Data in a manner consistent with the Customer's obligations under the CCPA, using the mechanisms in clause 13, and may take reasonable and appropriate steps to stop and remediate any unauthorised use of Customer Personal Data.
- 15.4Notification of inability to comply. FTE Tracker will notify the Customer in writing without undue delay if it determines that it can no longer meet its obligations as a service provider under the CCPA.
- 15.5Deidentified data. FTE Tracker does not create deidentified data from Customer Personal Data (clause 4.3(f)), so no obligation relating to deidentified data arises.
- 15.6Other states. Where a comparable statute of another United States state applies, this clause is read as imposing the equivalent obligations of that statute on FTE Tracker as a processor or service provider.
16Liability, changes and governing law
- 16.1Liability. Each party's liability arising out of or relating to this DPA is subject to the exclusions and the cap in clause 12 of the Terms. The Terms and this DPA together form a single agreement and there is a single aggregate cap across both. Nothing in this clause limits a Data Subject's rights under Applicable Data Protection Law, or either party's liability to a Supervisory Authority.
- 16.2Changes to this DPA. FTE Tracker may amend this DPA in accordance with clause 17 of the Terms, including where an amendment is required by a change in Applicable Data Protection Law. Amendments that materially reduce the Customer's protections are notified at least thirty (30) days in advance.
- 16.3Governing law and venue. This DPA is governed by the laws of the Commonwealth of Puerto Rico and the federal law of the United States, and the courts located in the Commonwealth of Puerto Rico have exclusive jurisdiction, as provided in clause 20 of the Terms, save where Applicable Data Protection Law mandates a different governing law or forum for a particular claim.
- 16.4Severability and survival. If any provision of this DPA is held unenforceable, the remainder continues in effect. Clauses 5, 6, 11.4, 12, 13 and 16 survive termination of the Agreement for as long as FTE Tracker holds Customer Personal Data.
- 16.5Contact. All notices, instructions and requests under this DPA go to privacy@ftetracker.com.
Annex 1Details of processing
| Controller / business | The Customer organization identified in the Order. |
|---|---|
| Processor / service provider | Kevin Alvarado, doing business as FTE Tracker. |
| Subject matter | Provision of the FTE Tracker hosted web application for recording, approving and certifying employee time and effort against funding sources. |
| Duration | The Term, and then three years after termination or expiry, unless the Customer instructs earlier deletion (clause 12). |
| Nature of processing | Collection, recording, organisation, structuring, storage, retrieval, display, consultation, use for the approval and certification workflow, generation of reports and certification records, erasure and destruction. |
| Purpose | To enable the Customer to record how its workforce's time is spent, to obtain supervisory approval of those records, to produce quarterly Time & Effort certification packages, and to compare posted against target allocation by fund. |
| Frequency | Continuous for the duration of the Term. |
| Automated decision-making | None. No profiling, scoring or automated decision producing legal or similarly significant effects is carried out. |
1. Categories of Data Subject
- (a)Employees of the Customer whose time is recorded in the Service.
- (b)Supervisors and project or programme managers who review, approve and certify.
- (c)Administrators who configure the organization and manage Users.
- (d)Former workers of the Customer whose historical records remain in the organization's data.
- (e)Any other individual a User names in a free‑text field, which the Customer is required by clause 6.4 of the Terms to instruct its Users not to do.
2. Categories of Customer Personal Data
- (a)Identity and contact. First name, last name and work email address.
- (b)Employment and organisational. Role in the Service (employee, supervisor, administrator, project manager), reporting line recorded as the supervisor's email address, contracted weekly hours, active or inactive status, service group membership, and fund allocation percentages together with the dated history of changes to them and who made each change.
- (c)Photograph. An optional photograph of the individual, uploaded by an Administrator and stored as an embedded image on the user record. Whether photographs are used at all is the Customer's choice.
- (d)Time and effort records. Work date, minutes worked, the fund, service group and activity charged, the allocation split in force on that date, the leave type where the entry is leave, the status of the entry, and an optional free‑text note typed by the individual.
- (e)Approval and correction records. The identity of the reviewer, the decision, the exact time of the decision and any review note the reviewer wrote about the individual's hours; where an approved entry is reopened, the reason, the identity of the person who reopened it and the time; and where an Administrator records or edits an entry on another person's behalf, the identity of that Administrator and of the person on whose behalf they acted.
- (f)Certification records. The quarter, the certifying supervisor, the employees covered, the attestation text the certifying supervisor agreed to, the identity of the person who uploaded each signed file and when, the record of every send‑back, and the times of generation, submission and approval.
- (g)Event log. For each recorded change: the email address of the signed‑in person, the email address of the account acted on behalf of where applicable, the action, the record affected, the time with time‑zone offset, and snapshots of the values before and after. The log retains the most recent 5,000 records for the organization.
- (h)Authentication data held by the authentication Subprocessor. Email address, the password credential managed by that Subprocessor, the authenticator (TOTP) enrolment and its timestamps, and session tokens. FTE Tracker does not have access to a User's chosen password.
- (i)Data written to the User's own browser. Theme and view preferences, the signed‑in session issued by the authentication Subprocessor, and any signed certification PDF the User has uploaded, which is stored in that browser's local database and nowhere else (clause 7.5).
- (j)Technical connection data received by third parties. When a page loads, the IP address, browser user‑agent string and referring page address are received by the content delivery and typeface providers in Annex 3.
3. Special categories of personal data
None is intended, none is requested by any field of the Service, and the Customer is prohibited from entering any by clause 5. The Customer should read clause 5.3 on how it names leave types before deciding that no such data exists in its own configuration.
Annex 2Technical and organisational measures
Every measure listed below is implemented in the Service today. Measures that are planned, partial or absent are not listed as implemented; paragraph H states what is not in place, and paragraph C states the limits of what the access controls do. A Customer may rely on this Annex as the description of FTE Tracker's security measures for the purposes of Article 32 of the GDPR and equivalent provisions.
A. Authentication and account provisioning
- A1Multi‑factor authentication is mandatory. Entry to the application requires a session that has completed both the password step and a six‑digit authenticator code. The assurance level is checked when a User signs in and again whenever a session resumes. There is no way to use the Service without it, for any Customer or any User.
- A2Passwords are held by the authentication Subprocessor. Sign‑in credentials are created and verified by the authentication Subprocessor. FTE Tracker does not have access to a User's chosen password. The password field is cleared from the page as soon as it is submitted, and a password change is verified on a separate non‑persisting client so that the multi‑factor session is not weakened. A minimum length of ten characters is enforced when a User changes their password in the application.
- A3Authenticator secrets. The authenticator secret is generated and held by the authentication Subprocessor. It exists in the browser only for as long as it takes to display the enrolment code and is not written to any persistent storage by the Service. The application cannot read an existing User's authenticator secret; it can only see that an enrolment exists and when it was made.
- A4Privileged account creation is server‑side. New sign‑in accounts are created by a server‑side function running with a privileged key that is never present in any browser. That function verifies the caller's session, requires a session that has completed the authenticator step, requires the caller to hold an administrator or project‑manager role, permits only a project manager to create administrator or project‑manager accounts, takes the organization from the caller's own record rather than from the request, and reverses the account creation if the associated record cannot be written.
- A5Session handling. Signing out from the sign‑in screen is scoped to the local device, so an incomplete authentication cannot end a User's sessions on other devices; a full sign‑out from within the application is global.
- A6Authenticator recovery. No recovery codes are issued. An authenticator enrolment can be removed only by FTE Tracker, manually, at the written request of an Administrator, as described in clause 5.4 of the Terms.
B. Separation between organizations
- B1Row‑level security in the database. Separation between Customer organizations is enforced by the database, and not only by the application interface. Row‑level security is enabled on the organization table, the user profile table and the table holding each organization's data. Every row is filtered by a policy that compares the row's organization identifier to a database function that resolves the caller's organization from the profile row keyed to the identifier in the caller's own session token. A table with row‑level security enabled and no matching policy is unreadable, so the default is denial. The mechanism depends on the organization identifier recorded on each User's profile row. FTE Tracker describes the mechanism it has implemented; it does not represent that mechanism, or any other measure in this Annex, to be free from defect, and clause 11.4 of the Terms applies.
- B2Multi‑factor requirement in the database policies. The database schema includes a further set of policies requiring a session that has completed the authenticator step before organization data may be read or written, so that a password‑only session cannot reach organization data even through a direct call to the platform interface. Whether those policies are in force in a given environment is a matter of that environment's configuration rather than of the application's own code. FTE Tracker will confirm the position for the Customer's environment in writing on request.
- B3Organizations cannot be created or altered by a client. There is no policy permitting any signed‑in client to create, modify or delete an organization record. Provisioning is carried out by FTE Tracker.
C. The limits of access control, stated plainly
- C1Role‑based visibility inside an organization is an interface control. The rule that an employee sees their own entries, a supervisor sees their direct reports and an administrator sees everyone is implemented in the application interface. It is not a boundary enforced by the database between colleagues in the same organization: a person holding valid credentials for that organization, who has completed the authenticator step, is technically capable of retrieving the organization's stored data outside the application interface. The Customer should authorise Users on that basis.
- C2Colleague directory data is visible to every member. Every User can read the name, work email address, role and photograph of every other member of the same organization. This is deliberate: the Service needs it for supervisor selection and the organizational tree.
- C3Directory data before the authenticator step. The name, work email address and role of an organization's members can be read by a session that has completed the password step but not yet the authenticator step, because the sign‑in screen needs that information to tell a User who to contact for help. Where the database policies described in B2 are in force, time and effort records, notes, approvals and the event log are not readable at that point.
- C4The event log is not independently sealed. See E3.
D. Encryption
- D1In transit. Every endpoint of the Service is reached over HTTPS. Transport security is terminated by the Subprocessors that operate those endpoints.
- D2At rest. Encryption at rest is provided by the hosting Subprocessor at platform level. FTE Tracker applies no application‑level or field‑level encryption of its own to Customer Personal Data, and does not represent that it does.
E. Recording of changes
- E1Append‑only event log. The application writes a log record for each recorded change, containing the acting account, the account acted on behalf of where applicable, the action, the record affected, the time with time‑zone offset, and the values before and after. No function of the Service edits or deletes a log record.
- E2The log is capped. The log retains the most recent 5,000 records for each organization. Older records are discarded, and the number discarded is retained as a count. The log should therefore not be relied on as a complete permanent history.
- E3The log is not tamper‑proof. The log is stored inside the organization's own data record. It follows from C1 that a person with valid credentials for the organization is technically capable of overwriting it outside the application interface. It is an accurate record of what the application did; it is not an independently sealed or write‑once archive, and FTE Tracker does not describe it as one.
- E4Acting on behalf of another User is recorded. Where an Administrator acts as another User, the log records both the real actor and the account acted upon. Changing a password is blocked while acting as another User.
F. Integrity of the record
- F1Approved entries. An approved entry cannot be edited by the person who recorded it. It can be reopened only by an administrator or project manager, only with a written reason, and the reopening is attributed and logged.
- F2Certified quarters. Once a certification package for a quarter has been submitted or approved, entries within that quarter cannot be changed and no entry can be added to it.
- F3Allocation snapshots. Each entry stores the fund allocation split that was in force on the date of the work, so a later change to a person's allocation does not alter how past time was recorded.
G. Data minimisation and absence of tracking
- G1No analytics or tracking. The Service, the public website and the Demo contain no analytics, no tag manager, no tracking pixel, no advertising technology and no third‑party session recording.
- G2No cookies are set by the product. The Service does not set cookies. The signed‑in session is held in the browser's local storage by the authentication Subprocessor's client library.
- G3No device fingerprinting. The browser user‑agent string is read only to display a readable device label on the settings screen. It is not stored and not transmitted. No IP address or location is recorded by the application.
- G4The Demo processes nothing. The public Demo runs entirely in the visitor's browser, creates no account and no server record, and contains only fictional data. Its only outbound request is for typefaces (Annex 3).
H. Measures that are not implemented
Listed so that a Customer's assessment is based on the real position rather than on an inference from silence.
- H1No third‑party security certification or attestation of any kind is held (clause 7.3).
- H2No application‑level or field‑level encryption of Customer Personal Data (D2).
- H3No per‑User access boundary enforced at the database layer within an organization (C1).
- H4No content security policy, subresource integrity attribute or strict transport security header is set by the application's own code; transport and platform protections are those the Subprocessors provide.
- H5No rate limiting or brute‑force protection is implemented by FTE Tracker's own code; what applies is the authentication Subprocessor's own protection.
- H6No server‑side storage, backup or recovery of signed certification PDFs (clause 7.5).
- H7No independent penetration test has been commissioned.
- H8Backup and restoration of the database are those provided by the hosting Subprocessor's platform; FTE Tracker operates no backup process of its own and gives no recovery point or recovery time commitment (clause 10.6 of the Terms).
- H9One known defect, disclosed rather than glossed over. A code path inherited from the standalone version of the application, used when an Administrator resets another User's password, writes a value derived from a temporary password by PBKDF2‑HMAC‑SHA256 with 100,000 iterations and a random per‑user salt into the organization's data record. The value is not the password and is not used to authenticate anyone in the Service, but it is password‑derived material stored where it should not be, and it is being removed. It is stated here so that A2 is not read as an unqualified claim that no password‑derived material is ever written to a Customer's record. The same disclosure appears in clause 7.5 of the Privacy Policy.
Annex 3Approved subprocessors
The current list is also published, with any pending changes, on the Subprocessors page. Clauses 8.4 and 8.5 govern how a change is notified and how a Customer may object.
Part 1 — Subprocessors that process Customer Personal Data
| Subprocessor | Function | Data processed |
|---|---|---|
| Supabase | Database, authentication, multi‑factor enrolment and verification, and the server‑side function that creates new sign‑in accounts. | All Customer Data stored by the Service, including every category in Annex 1 paragraph 2(a) to (g); and the authentication data in Annex 1 paragraph 2(h). Region confirmed in writing on request (clause 14.2). Supabase's own infrastructure providers are its subprocessors and are published by it (clause 8.7). |
Part 2 — Providers that receive technical connection data only
| Provider | Function | Data received |
|---|---|---|
| jsDelivr | Public content delivery network that serves the authentication client library to the browser when the signed‑in application loads. Used by the Service only. | IP address, browser user‑agent string and referring page address of the User's browser. No Customer Data. |
| Google Fonts | Delivery of the typefaces used by the Service, the public website and the Demo. | IP address, browser user‑agent string and referring page address of the visitor's browser. No Customer Data. |
| Static hosting provider | Delivery of the files that make up the Service's interface, the public website and the Demo. It holds no Customer Data: the Service's records are held by the Part 1 Subprocessor. FTE Tracker names this provider in writing to any Customer or prospective Customer that asks at privacy@ftetracker.com, and names it here once it is fixed for the Customer's environment. | IP address and request details of the visitor's browser, as every web host necessarily processes in order to serve a file. No Customer Data. |
Notes on this list
- (a)No email provider is listed because the Service sends no email. The application generates no outbound message: new accounts are created without a confirmation email, and self‑service password reset by email is not enabled. Correspondence with FTE Tracker is ordinary email between the parties. If email delivery is added, the provider will be listed and notified under clause 8.4.
- (b)No analytics, advertising, monitoring or session‑recording provider is engaged, on any surface (Annex 2, G1).
- (c)No payment processor is engaged, because Fees are invoiced rather than collected in the Service (clause 8.1 of the Terms).
- (d)The Demo engages no Subprocessor other than the typeface provider, because it runs entirely in the visitor's browser.
- (e)The static hosting provider is named on request rather than in this table. FTE Tracker publishes only what it can evidence at the time it is asked. The host delivers files and holds no Customer Data; it is engaged on that provider's own published terms. A Customer that needs the provider named — for a security questionnaire or a grant condition — obtains it in writing under clause 14.2 and section 12 of the Subprocessors page, and a change of host is notified under clause 8.4.