Data Processing Addendum

Version 1.0 · Effective September 1, 2026

This Addendum governs how Temporal Logic LLC d/b/a Temporal Logik handles the personal information a customer puts into 9forty5 about its own workforce. The Privacy Policy describes what we do; this Addendum is the contractual commitment a customer can hold us to, and it carries the specific terms US state privacy law requires between a business and its service provider. It is written for United States customers. Nothing here is a transfer mechanism for the EEA or the UK.

1. Scope, roles, and how this fits the Terms

This Data Processing Addendum (the "Addendum") supplements the 9forty5 Terms of Service between Temporal Logic LLC d/b/a Temporal Logik ("Temporal Logik", "we") and the customer that accepted them ("Customer", "you"). It applies to Personal Information that we process on your behalf through the Service.

For that information you are the Business (or Controller) and we are the Service Provider (or Processor). You decide what is collected, who may see it, and how long it is kept. We act only on your instructions. Your instructions are your configuration of the Service, your use of its features, and this Addendum; anything further must be agreed in writing.

Where this Addendum and the Terms conflict on the handling of Personal Information, this Addendum controls. In all other respects the Terms govern, including their limitations of liability, which apply to this Addendum as if set out here.

2. Definitions
  • Personal Information: information relating to an identified or identifiable individual that we process on your behalf through the Service. It does not include our own account and billing records, which we hold in our own right and which the Privacy Policy covers.
  • Business, Service Provider, sell, share, and commercial purpose carry the meanings given to them by the California Consumer Privacy Act as amended (the "CCPA").
  • Business Purpose: providing, securing, supporting, and maintaining the Service for you, as described in Annex A.
  • Security Incident: a breach of security leading to the accidental or unlawful destruction, loss, alteration, or unauthorized disclosure of, or access to, Personal Information in our possession.
3. Our obligations as Service Provider

These are the commitments that make us a Service Provider rather than a third party:

  • We process Personal Information only for the Business Purpose set out in Annex A, and only on your documented instructions.
  • We do not sell or share Personal Information, as the CCPA defines those terms, and we receive no consideration for it.
  • We do not retain, use, or disclose Personal Information for any purpose other than performing the Service for you, or outside our direct business relationship with you, except where law requires it.
  • We do not combine Personal Information received from you with personal information received from or on behalf of anyone else, or collected from our own interactions with individuals, except as the CCPA expressly permits a service provider to do.
  • We do not use Personal Information to train machine learning models, and our AI subprocessor does not train on data submitted through its API. Section 7 of the Privacy Policy states precisely which categories reach that subprocessor and which are excluded by design.
  • We provide at least the level of privacy protection the CCPA requires of a service provider, and we will comply with our own applicable obligations under it.
  • We will tell you promptly if we determine we can no longer meet these obligations, and will stop processing or take other reasonable steps to remediate on your instruction.
  • You may take reasonable and appropriate steps to stop and remediate any unauthorized use of Personal Information, and we will cooperate with them.
4. Confidentiality and personnel

We keep Personal Information confidential. Access is limited to personnel who need it to deliver, support, or secure the Service, who are bound by confidentiality obligations, and who are told what these obligations require of them.

5. Security

We maintain technical and organizational measures appropriate to the risk, described in Annex C and in section 8 of the Privacy Policy. Those measures may change as the Service evolves, but we will not materially reduce the overall level of protection during your subscription. You are responsible for the parts of security you control: who you invite, what role you give them, deactivating people who leave, and the strength and secrecy of your own credentials.

6. Subprocessors

You authorize us to engage the subprocessors listed in Annex B. Each is bound by written terms no less protective than this Addendum, and we remain responsible to you for their performance.

We will give you at least 30 days' notice before adding or replacing a subprocessor that processes Personal Information, by email to the account address or by notice in the Service. If you reasonably object on data protection grounds within that period, tell us at legal@temporallogik.com and we will work with you in good faith on an alternative. If none is reasonably available, you may terminate the affected part of the Service without penalty, and we will refund any prepaid fees covering the terminated period.

7. Individual rights requests

The Service gives you direct access to the records it holds, so in most cases you can answer a request from one of your workers yourself. Where you cannot, we will provide reasonable assistance to help you respond within the time the law allows. If we receive such a request directly, we will not respond to it substantively. We will tell the individual to contact their employer, and forward the request to you unless the law prevents it.

8. Security Incidents

We will notify you of a Security Incident affecting your Personal Information without undue delay after we become aware of it, and in any event within the time applicable law requires. The notice will describe what we know, the categories and approximate volume of information involved, the likely consequences, and the steps we are taking. We will provide reasonable cooperation and further information as the investigation develops. An initial notice is not an admission of fault.

9. Deletion and return

On termination, Personal Information remains available for export for 30 days, after which we may delete it. We will delete or return it sooner on your written instruction, except to the extent law requires us to keep it, in which case we will keep it only for that purpose and continue to protect it under this Addendum. Note that deactivating a worker inside the Service preserves their history by design, so it is not a deletion instruction; tell us at legal@temporallogik.com if you need actual deletion.

10. Demonstrating compliance

On reasonable written request, and no more than once in any twelve month period unless a Security Incident or a regulator requires otherwise, we will provide the information reasonably necessary to show we are meeting this Addendum, ordinarily by answering a written security questionnaire. This does not extend to access to our premises, our systems, or any data belonging to another customer.

11. Employee information

Most of what the Service holds is information about your workers, which the CCPA has covered in full since 2023. You are responsible for giving your workers any notice the law requires, including notice at or before collection describing the categories collected and why, and for obtaining any consent required before enabling optional features such as punch location capture.

12. Term, changes, and contact

This Addendum takes effect when you accept the Terms and continues for as long as we process Personal Information for you. We may update it, and will give notice of material changes the same way the Terms require, updating the version and effective date shown on this page. We will not make a change that materially reduces the protections that applied to information already collected without your consent.

Notices under this Addendum, including subprocessor objections and deletion instructions: Temporal Logic LLC d/b/a Temporal Logik, legal@temporallogik.com.

Annex A: details of processing
  • Subject matter and nature: hosting and processing workforce time and attendance records so the Service can record punches, calculate time cards and overtime, manage schedules and leave, and produce payroll exports.
  • Business Purpose: providing, securing, supporting, maintaining, and improving the Service for you; billing; and complying with law.
  • Duration: for as long as your account is active, plus the 30 day export window in section 9.
  • Categories of individuals: your employees, managers, and administrators.
  • Categories of Personal Information: identifiers and contact details (name, work email, phone numbers, mailing address); employment records (hire date, site, department, role, external payroll identifier, wage or salary rates); time and attendance records (punches, time cards, hour classifications, leave, schedules, approvals); punch location (latitude, longitude, accuracy, geofence flag) where you enable it; authentication data (password hashes, passkey public keys); and activity log records.
  • Sensitive Personal Information: Social Security number, where you choose to enter it. It is encrypted at rest, masked in payroll exports, and never sent to our AI subprocessor. We use it only to produce payroll output for you, which the CCPA permits without triggering a right to limit.
Annex B: subprocessors
  • Amazon Web Services: hosting, database, and file storage. United States.
  • Amazon Simple Email Service: transactional email delivery. United States.
  • Stripe: payment processing. Receives billing details directly; does not receive workforce records. United States.
  • Anthropic: the large language model behind the AI-assisted features. Receives only the categories listed in section 7 of the Privacy Policy, and never Social Security numbers, payroll registers, timecard detail, worker contact information, or the punch audit trail. United States.
Annex C: security measures
  • Encryption in transit over HTTPS, with plain HTTP redirected rather than answered.
  • Social Security numbers encrypted at rest with AES-256-GCM, a fresh nonce per record, under a key held outside both the application source and the database.
  • Passwords stored only as bcrypt hashes, never reversibly encrypted.
  • Signed, expiring session tokens, with a revocation mechanism that invalidates a user's outstanding sessions.
  • Role-based access control, so workers see their own records and managers see only the sites assigned to them.
  • Social Security numbers masked in payroll exports.
  • A database not reachable from the public internet; only the application edge is exposed.
  • An activity log recording actions taken in the Service, for audit and investigation.

© 2026 Temporal Logik LLC. All rights reserved.