Data processing agreement (AVV) — Version for Malta
Version: 30 September 2026Translation. Legally binding language version: German.
Agreement on the processing of personal data on behalf of a controller under Art. 28(3) GDPR between the customer purchasing NymTime for its business (hereinafter "controller") and LazyHead e.U., owner Andrii Snikhovskyi, Morizgasse 2/2/14, 1060 Vienna (hereinafter "processor"). It is accepted at purchase on nymtime.com/kaufen together with the terms of service and forms part of the service contract.
Part A — General provisions
Part A applies equally to all controllers in all Member States. Part B contains the special provisions for the state for which this version applies — in particular the legal bases in the employment context, the retention periods and the competent supervisory authority; for controllers established in that state and for locations in that state they take precedence over Part A. If the controller has locations in several states, the data of the employees of a location are governed by the special provisions of the version of the state in which the location lies. References to Part B mean Part B of the version applicable in each case.
1. Subject matter and duration
(1) The processor provides the controller with the NymTime software as a service: scheduling, time tracking with the employee's smartphone at NFC tags (alternatively geo-verified location clock-in without NFC), location check at the moment of clocking, recording of rest breaks according to the rule chosen by the controller, absences, availability entries, shift swaps, company announcements (notice board), a working-time account, hours reporting, export for payroll and optionally document storage including access for the employee concerned, payroll documents, revenue figures per location and internal labour cost. In doing so it processes personal data on behalf of the controller.
(2) The duration of this agreement follows the service contract (terms of service, nymtime.com/agb). It ends with the service contract; clause 10 continues to apply until all data has been returned or deleted.
(3) The controller's data is stored exclusively in data centres within the European Union. In transit it passes through Cloudflare's reverse proxy; e-mails and push notifications are sent via the services named in Annex 2. The transfers to third countries this involves and their basis (Art. 45 and Art. 46(2)(c) GDPR) are set out in Annex 2.
2. Nature and purpose of processing, categories of data and data subjects
(1) The nature and purpose of the processing, the categories of personal data and the categories of data subjects are described in Annex 1. In summary: management of master data, schedule, working time records under the law of the state of the location, absences, result of the location check at clocking, device data, employee messages and — where used by the controller — documents and labour cost figures, each for the purpose of workforce planning, fulfilment of statutory record-keeping duties under labour law and preparation of payroll.
(2) No GPS coordinates, routes or movement profiles are stored. The result of the location check is recorded only at the moment of a clock-in or clock-out during a shift, as "inside", "outside" or "location unavailable" with time and accuracy; there is no location tracking in the background. The check takes place only if the controller has completed, for the location and the employee concerned, the steps required by the law of the location's country and recorded them in the Back Office (Part B).
(3) The absence reason "sick leave" is recorded without diagnosis and without details of the cause of illness. Beyond that, special categories of personal data under Art. 9 GDPR are the subject of the processing only where the controller uses the feature "sick note": the confirmation of the start and expected duration of incapacity for work is health data. The controller may file it only to the extent that it may request it under the law of the state in which the employee is employed (Part B names the provisions); the legal basis is Art. 9(2)(b) GDPR in conjunction with those provisions and Art. 88 GDPR. The processor limits access to these documents to the persons authorised for this by the controller and to the employee concerned and does not evaluate their content. The controller ensures that no diagnoses and no further health data are stored in free-text fields or other documents.
(4) In addition the processor processes on the controller's behalf: availability entries of employees (voluntary information for planning; neither stand-by nor on-call duty within the meaning of working time law, no claim to pay), offers and acceptances in shift swaps (colleagues at the same location with the same role see the name, the role or department and the times of the shift concerned — no presence or performance data), the contact details an employee has released for colleagues (consent under Art. 6(1)(a) GDPR, default off, withdrawal at any time under Art. 7(3) GDPR taking immediate effect in the application), read receipts for company announcements (notice board), and the recorded rest breaks and short breaks together with the note "break not recorded". That note serves solely to correct the working time record and is neither a sanction nor a performance assessment; the correction is made by a person of the controller with a reason.
(5) Revenue figures per location that the controller enters or imports for key figures relate to the location and not to persons and are not personal data in themselves; they are evaluated only together with labour costs, which are accessible exclusively to the controller's management and to managers it authorises for them.
3. Instructions of the controller (Art. 28(3)(a))
(1) The processor processes personal data only on documented instructions from the controller unless required to do so by Union or Austrian law; in that case the processor informs the controller of that legal requirement before processing, unless that law prohibits such information.
(2) Instructions are given through the configuration in the Back Office — in particular locations and location area, roles and permissions, the break rule per location, the deadline for availability entries, whether shift swaps require approval, the visibility of documents to employees, retention periods, activation of the location check at clocking per location and employee according to the country steps recorded in the Back Office, enablement of support access (Settings → Subscription → Support access), export and deletion — and in writing to office@nymtime.com, for which an e-mail suffices (form agreed under § 886 ABGB). The controller determines which of its users are authorised to give instructions (role management).
(3) If the processor considers an instruction to be unlawful under data protection law, it informs the controller without delay and may suspend execution until the instruction is confirmed or changed.
4. Confidentiality (Art. 28(3)(b))
(1) The processor ensures that all persons authorised to process the data have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality, and that this obligation continues after the end of their activity.
(2) In normal operation the processor does not access the content of the customer account. Support access is only possible if the controller explicitly enables it in the Back Office — with scope, duration and revocation at any time. Every access is recorded with time, person and action in the controller's audit log.
5. Security of processing (Art. 28(3)(c), Art. 32)
(1) The processor implements the technical and organisational measures described in Annex 3 and maintains them for the entire duration of the contract. It reviews them regularly and adapts them to the state of the art.
(2) The processor may develop the measures further and replace them with equivalent ones provided the level of protection is not reduced. Material changes are documented in Annex 3 and shown to the controller in the Back Office.
6. Sub-processors (Art. 28(2) and (4), (3)(d))
(1) The controller gives general authorisation for the use of the sub-processors listed in Annex 2. A contract is in place with each sub-processor imposing on it the same data protection obligations as this agreement imposes on the processor.
(2) If the processor intends to engage or replace a sub-processor, it informs the controller at least 30 days in advance by e-mail and in the Back Office. The controller may object within this period on important data protection grounds; if no agreement is reached, either party may terminate the service contract to the end of the current month.
(3) Personal data is transferred to a third country outside the European Economic Area only if the requirements of Art. 44 to 49 GDPR are met (adequacy decision or standard contractual clauses under Art. 46(2)(c) GDPR). The processor is liable for sub-processors as for its own conduct.
7. Assistance with data subject rights (Art. 28(3)(e))
(1) The processor assists the controller by appropriate technical and organisational measures in responding within the statutory periods to requests by data subjects for access, rectification, erasure, restriction, data portability and objection (Art. 15 to 22 GDPR).
(2) The product provides for this: viewing and monthly export of the employee's own time records in the employee app (Art. 15 and 20 GDPR); export of all data of an employee from the Back Office; corrections with a log; archiving, anonymisation and deletion according to retention periods; in the employee app, the employee's request to delete their account, which is forwarded to the controller for a decision (working time records are kept for the statutory period under Part B).
(3) If a data subject addresses a request directly to the processor, the processor forwards it to the controller without delay and does not answer it itself unless instructed to do so by the controller.
8. Notification of personal data breaches (Art. 28(3)(f), Art. 33)
(1) The processor notifies the controller of any personal data breach without undue delay and at the latest 48 hours after becoming aware of it, by e-mail to the contact person's address. The notification contains the information under Art. 33(3) GDPR: nature of the breach, categories and approximate number of data subjects and records concerned, likely consequences, measures taken and proposed, and a contact point.
(2) The processor assists the controller with the notification to the supervisory authority within 72 hours (Art. 33) and with the communication to data subjects (Art. 34) and documents all breaches including their effects and the remedial action taken.
9. Data protection impact assessment and prior consultation (Art. 28(3)(f), Art. 35 and 36)
(1) Systematic recording of employee presence may require a data protection impact assessment under Art. 35(3)(a) GDPR. The processor provides the controller with a template data protection impact assessment for NymTime and the technical information on the product, and assists with any prior consultation of the supervisory authority (Art. 36).
(2) Carrying out the data protection impact assessment for its own deployment, assessing whether the law of the respective country requires a collective or works agreement, consultation, information or consent for the location check, and concluding or obtaining it are the controller's responsibility. The processor provides country checklists and templates for this; they do not replace legal advice.
10. Deletion and return after the end of the contract (Art. 28(3)(g))
(1) After termination of the service contract the controller may export its data completely from the Back Office for 30 days (Excel, CSV, documents in their original format). After this period the processor deletes all personal data of the controller unless Union or Austrian law obliges the processor itself to store it; in that case processing is restricted to storage. The controller's own retention duties (under the law of the state of the location, Part B) remain its own responsibility (§ 14(3) of the terms of service); it fulfils them by exporting in good time.
(2) Deletion is confirmed to the controller in writing on request. Backups are overwritten no later than 35 days after deletion of the primary data.
(3) During the contract the controller may archive, anonymise or delete individual employees and set the retention periods per data type itself within the statutory minimums. A daily job applies the periods and logs the number and data type of deleted records.
11. Evidence and audits (Art. 28(3)(h))
(1) The processor makes available to the controller all information necessary to demonstrate compliance with the obligations laid down in Art. 28 GDPR, in particular this agreement, its annexes, the record under Art. 30(2) GDPR and reports on the review of the technical and organisational measures.
(2) The controller or an auditor mandated by it and bound to confidentiality may verify compliance with this agreement after reasonable notice of at least 14 days during usual business hours, at most once per calendar year, unless a personal data breach or an order of the supervisory authority requires a further audit. The processor contributes to audits.
(3) The processor immediately informs the controller if, in its opinion, an instruction infringes the GDPR or other Union or Austrian data protection provisions.
12. Liability and final provisions
(1) The liability of the parties is governed by Art. 82 GDPR and otherwise by § 15 of the terms of service. As between the parties, each party is liable for breaches of the obligations incumbent on it under this agreement and the GDPR.
(2) Austrian law applies, excluding its conflict-of-law rules. As the exclusive place of jurisdiction the parties agree, under § 104 of the Austrian Jurisdiction Act (JN) — and, for controllers domiciled in another member state, additionally under Art. 25 of Regulation (EU) No 1215/2012 (Brussels Ia) — on the court with subject-matter jurisdiction for Vienna, Inner City. Amendments and additions to this agreement must be made in writing; for this the parties agree on a relaxed form under § 886 ABGB, an e-mail to the address on file suffices. This also applies to the waiver of this requirement.
(3) The electronic acceptance of this agreement at purchase or, if the processor set up the customer account on request, at the management's first login to the Back Office — with time, version, checksum (SHA-256) of the accepted document text, IP address and user — is recorded in the customer account and constitutes conclusion in electronic form within the meaning of Art. 28(9) GDPR. In case of conflict between this agreement and the terms of service, this agreement prevails in data protection matters.
Annex 1 — Subject of processing: data categories, data subjects, purposes
Categories of personal data (per category: data — purpose — legal basis of the controller):
- Master data: name, e-mail address, telephone number, position, role, location assignment, personnel number, type of employment, start and end date — administration, schedule, billing — Art. 6(1)(b) and (c) GDPR.
- Contract data (agreement): contractual working time (hours per week, month or year), employment category (full-time, part-time, minor under 18, apprenticeship, seasonal, other), averaging period, applicable collective agreement, vacation entitlement in days, each with its effective date and version history — schedule, time account, vacation balance, check of working-time limits — Art. 6(1)(b) and (c) GDPR.
- Schedule: planned shifts, roles, minimum staffing, open shifts, publication and acknowledgement timestamps (who published the schedule and when, when the employee saw and confirmed it), changes after publication with their reason — workforce planning, proof of timely notice — Art. 6(1)(b) and (c) GDPR.
- Availability: entry per day or half-day ("available", "would rather not", "not available"), time of entry — voluntary information for planning, neither stand-by nor on-call duty within the meaning of working time law — Art. 6(1)(b) GDPR.
- Shift swaps: offer, responses from colleagues at the same location with the same role (visible to them: name, role or department, times of the shift), decision of the manager, result of the working-time limit check — workforce planning — Art. 6(1)(b) GDPR.
- Contact release (Contacts): flag whether the employee has made their phone number and e-mail address visible to colleagues at the same location, with the time it was given and of any withdrawal — reachability within the team — consent under Art. 6(1)(a) GDPR, default off, withdrawal at any time under Art. 7(3) GDPR.
- Company announcements (notice board): text, audience, validity, read receipt per employee with time — evidence that company information was acknowledged — Art. 6(1)(b) and (f) GDPR; not performance monitoring.
- Working time records: actual start and end, rest breaks (unpaid; planned break blocks per shift, paid or unpaid, and a break confirmed by the location manager with the editor) and short breaks together with the flag "break not recorded", clock-in method (NFC or location clock-in without NFC), deviation log for contractual working time (days confirmed "as planned", actual times of a deviation, the employee's report and the manager's confirmation), working-time account per settlement period (contract hours, credited hours, balance, carry-over and period closing), corrections with reason and editor — record-keeping duty under the law of the state of the location (Part B) — Art. 6(1)(c) GDPR.
- Absences: type (holiday, sick leave, time off in lieu, care leave, public holiday, special leave, training, unpaid), period, status, editor; sick leave without diagnosis — schedule, continued remuneration — Art. 6(1)(b) and (c) GDPR.
- Location check at clocking: result "inside", "outside" or "location unavailable" with time and accuracy in metres; no coordinates, no routes — plausibility of the clock-in or clock-out — under the law of the location's country (Part B); Art. 88 GDPR.
- Set-up evidence (compliance): the controller's answers on country, company size and employee representation, uploaded agreements and minutes, date of the data protection impact assessment, acknowledgements and consents per employee with time and document version, withdrawals — proof that the steps required by national law were taken before the function is enabled — Art. 6(1)(c) and (f) GDPR, for consents Art. 7 GDPR.
- Device data: device identifier, public key, model and operating system version, push token for notifications, status (active, replaced, blocked), time of registration — one device per person, anti-forgery — Art. 6(1)(f) GDPR.
- Employee messages: "running late", "not today", free text to the business — organisation of the shift — Art. 6(1)(b) GDPR.
- Documents (optional): social insurance registration, written information on the essential terms of employment, employment contract, certificates with any expiry date, documents requested by the business and uploaded by the employee, payslips and annual payslips including automatically suggested fields with review flag, each with the flag whether the document is visible to the employee concerned in the app — personnel file, preparation of payroll — Art. 6(1)(c) GDPR in conjunction with the law of the state of the location (Part B); these documents may contain national identification numbers (for example the social security number), which the controller files only within the law of its state. Payroll documents can be seen only by management, persons expressly authorised by the controller and the employee concerned; every access is logged. Retention: payroll documents follow the data type "payroll documents" (period and start of the period as stated in Part B), the other documents the data type "employee documents".
- Sick note (optional): start and expected duration of the incapacity for work without diagnosis — evidence of sick leave and continued remuneration — health data, Art. 9(2)(b) GDPR in conjunction with the provision of the state in which the employee is employed under which the employer may request the note (Part B). Where incapacity for work is reported electronically via a social security institution, the controller files only the information it is entitled to, without diagnosis; where a note contains a diagnosis code, it makes the code illegible before uploading. Access only for management, persons expressly authorised by the controller and the employee concerned; every access is logged. Retention follows the data type "employee documents".
- Labour cost (optional, visible to management and to managers it authorises („Personalkosten“)): gross pay with history (amount, unit, salaries per year, weekly hours, type of employment, employer cost rate), supplements, advances, adjustments with history — internal calculation — Art. 6(1)(f) GDPR.
- Revenue figures per location (optional): daily revenue and target value — key figure labour cost ratio — not personal data; evaluated only together with labour costs.
- Logs: audit log (who, what, when, before/after), notifications — accountability, security — Art. 5(2) and Art. 32 GDPR.
- Categories of data subjects: employees, freelance contractors, temporary agency workers, interns and apprentices of the controller. Back Office users (management, managers, tax adviser) and the controller's contact person are not covered by this agreement; for their data the processor is itself the controller (privacy policy, sections 6 and 7).
- Purposes: workforce planning; fulfilment of the duty to record working time, including rest breaks, under the law of the state of the location; plausibility of the clock-in or clock-out; management of absences; organisation of availability, shift swaps and company announcements; filing and provision of personnel documents; preparation of payroll; security and traceability of the system.
- Retention (adjustable by the controller within the statutory minimums): the default and minimum values for working time records, audit log, employee documents (data type "employee_documents", including uploaded evidence and sick notes), payroll documents, labour cost and archived employee profiles (then anonymisation) are stated in Part B under the law of the state of the location; raw presence events 3 months, shorter where the law of the state requires it (Part B); messages 12 months; notifications 6 months. Availability entries, swap records and read receipts are deleted together with the corresponding schedule or announcement, at the latest after 12 months.
Annex 2 — Authorised sub-processors
As of 28 September 2026. The processor uses the following sub-processors; the current list can be viewed in the Back Office under Settings → Subscription.
- Hosting of the service (servers, database, file storage, backups): Hetzner Online GmbH, Industriestraße 25, 91710 Gunzenhausen, Germany — Falkenstein data centre (Germany, region fsn1), object storage in the same region. Guarantee: data processing agreement under Art. 28 GDPR; no processing outside the EU.
- Hosting and delivery of the website nymtime.com and forwarding of all traffic to api.nymtime.com, app.nymtime.com and admin.nymtime.com (reverse proxy, transport encryption, protection against overload attacks): Cloudflare (Cloudflare Germany GmbH, Rosental 7, 80331 Munich / Cloudflare, Inc., San Francisco, USA). The TLS connection ends at Cloudflare; Cloudflare therefore technically processes all transmitted data, including employee data, while in transit, but stores no content of the service — only static files are cached, plus connection logs to fend off attacks. Guarantee: data processing agreement under Art. 28 GDPR; transfer to the USA on the basis of the certification under the EU-US Data Privacy Framework (Art. 45 GDPR) and the standard contractual clauses (Art. 46(2)(c) GDPR).
- E-mail delivery (login and invitation links, activation codes of the employee app, notifications, contract and payment messages, invoices): Resend, Inc., San Francisco, USA — sent via Amazon Simple Email Service in the region eu-west-1 (Ireland). Data processed: recipient address, subject, content and delivery status of the message. Guarantee: Data Processing Addendum of 28 September 2026 (Art. 28 GDPR); transfer to the USA on the basis of the EU-US Data Privacy Framework (Art. 45 GDPR) and the standard contractual clauses (Art. 46(2)(c) GDPR).
- Push notifications to the employee app: Expo (650 Industries, Inc., USA), delivery to the devices via the Apple Push Notification service (Apple Inc.) or Firebase Cloud Messaging (Google). Data processed: the device's push token, identifier and type of the notification, a general text without personal content. Guarantee: data processing agreement under Art. 28 GDPR; transfer to the USA on the basis of the EU-US Data Privacy Framework (Art. 45 GDPR) and the standard contractual clauses (Art. 46(2)(c) GDPR).
- Automatic field recognition in documents (only if the controller activates this feature): provider with processing in the EU, no use of the data for training purposes — will be added here before the feature is activated; until then the feature is disabled.
- Address search in the Back Office (suggestions while a location address is entered): Komoot GmbH, Hauptstraße 35, 12159 Berlin, Germany (Photon service, servers in the EU; data source OpenStreetMap, ODbL 1.0). Only the typed address text is transmitted; the request is made by our server, not by the browser. No employee data is transmitted. Fallback in case of an outage: Nominatim of the OpenStreetMap Foundation, St John’s Innovation Centre, Cowley Road, Cambridge CB4 0WS, United Kingdom — a data processing agreement cannot be concluded with the foundation; the service receives only the address text and is queried only as a fallback.
For completeness — independent controllers, not sub-processors: European Commission, Rue de la Loi 200, 1049 Brussels, Belgium (confirmation of the controller’s VAT identification number in the VAT Information Exchange System VIES; only the country code and the VAT ID are transmitted, legal basis Art. 6(1)(c) GDPR in conjunction with § 11(1a) UStG 1994; no employee data), Stripe Payments Europe, Ltd., 1 Grand Canal Street Lower, Grand Canal Dock, Dublin 2, Ireland (payment processing, invoicing and subscription management for the controller as a customer; transfers to Stripe, Inc. (USA) under the EU-US Data Privacy Framework and standard contractual clauses) and Österreichische Post AG, Rochusplatz 1, 1030 Vienna, or a courier service (delivery of the NFC tags to the business or delivery address; receives shipping data only: company, contact person, address, telephone number where applicable). None of these recipients processes data of the controller's employees.
Annex 3 — Technical and organisational measures (Art. 32 GDPR)
The processor implements in particular the following measures:
- Physical and system access control: operation of the service exclusively in data centres in the EU; physical access control and ISO 27001 certification are requirements placed on the hosting provider of the service (Hetzner Online GmbH, Annex 2); administrative access only via personal accounts with SSH keys, two-factor authentication for the management console likewise a requirement placed on the hosting provider; no shared accounts.
- Access control in the product: role- and permission-based authorisation (management, manager, employee, further roles with individual permissions), managers restricted to assigned locations; labour cost data for management only; sick notes and payroll documents only for management, persons expressly authorised by the controller and the employee concerned, every access to them is logged; sign-in to the Back Office via personal accounts with the e-mail address as the user name and a password stored exclusively as a hash with a random salt (scrypt) — password set through a one-time link (valid 24 hours), reset through a one-time link (valid 1 hour), confirmation of a new e-mail address by a code sent to the new address, lockout for 15 minutes after 10 failed attempts, termination of all existing sessions on every password change, session cookie expiring after 14 days, optional two-factor authentication (TOTP app, enabled organisation-wide by the controller, recovery codes stored only as hashes, TOTP secret stored encrypted); activation of the employee app by a one-time code sent to the registered e-mail address (limited validity, at most 5 attempts, requests limited per address and IP address); accesses are logged.
- Device binding: exactly one active device per employee; cryptographic key pair in the device's secure storage; every clock-in is signed by the device; a new device is bound only after confirming an e-mail code and proving presence at the location (NFC tag or location check) — the previous device is locked automatically, the business is notified and the change is logged; the business can lock a device at any time.
- NFC tags: NXP NTAG 424 DNA, configured to produce a dynamic, cryptographically signed message per touch (Secure Unique NFC) with counter check — designed to prevent copying and replay; the chip key is disclosed neither to the phone nor to users; the QR code on the location sign only leads to the download page of the employee app and is not a clock-in method; location clock-in without NFC only inside the location area.
- Data minimisation: no storage of coordinates or routes; no photos when clocking — images only enter the system as documents uploaded by the employee themselves (for example a sick note); of the location only the result of the check at clocking ("inside", "outside", "location unavailable", time, accuracy); no location tracking in the background; check only during the shift and only once the steps under the law of the location's country have been recorded in the Back Office; raw events are deleted after 3 months, sooner where the law of the country requires it; push notifications without personal content.
- Encryption: transmission exclusively over TLS 1.2 or higher (up to Cloudflare's reverse proxy and from there encrypted again up to the servers of the service); the database resides on LUKS-encrypted volumes (dm-crypt, AES-XTS) at the hosting provider; the application encrypts documents with AES-256-GCM before storing them in object storage, the keys are held only on the application servers; pgBackRest encrypts database backups with AES-256 before storing them in object storage; keys and credentials outside the source code; passwords and login codes only as hashes with a random salt.
- Integrity and traceability: immutable audit log (append allowed, modification and deletion prevented by a database rule) for all security-relevant actions; soft delete only, with timestamp; corrections of working time with reason, editor and previous value.
- Server logs: the logs of the application servers (interface, web server) contain IP addresses but no content of documents or payroll data; they are rotated by size (at most five files of 10 MB each per service) and deleted after 30 days at the latest.
- Availability: two database servers with continuous replication; daily backups (weekly full, daily differential, plus continuous archiving of the transaction logs) with up to 35 days' retention, encrypted in the hosting provider's object storage in the EU; monthly automated restore test; monitoring with alerting; buffering of clock-ins on the device if the connection is lost.
- Separation: logical separation of customer data by organisation key in every query; separate environments for development, testing and production; no production data in test or development environments.
- Retention and deletion: configurable periods per data type with enforced statutory minimums; daily automated deletion and anonymisation job with a log; return and deletion under clause 10.
- Support access: no access by the processor to customer data in normal operation; access only after enablement by the controller with scope, duration and revocation at any time; every access logged.
- Organisation: confidentiality obligations for all persons involved; documented process for data breaches with notification within 48 hours; record of processing activities under Art. 30(2) GDPR; annual review of these measures; security updates within a reasonable period; the principles of data protection by design and by default (Art. 25 GDPR) in the development process.
Part B — Special provisions for Malta
The following provisions apply to controllers established in Malta and to the data of employees at locations in Malta. They take precedence over the provisions of Part A. The contract language is German; the English version is for information, in case of doubt the German version prevails.
B1. Legal bases in the employment context
(1) Processing in the employment context is governed by Art. 6 and Art. 88 GDPR and the Data Protection Act (Cap. 586). Employees must be informed before the processing begins; consent is generally not an appropriate legal basis in employment. In undertakings with at least 50 employees the controller checks information and consultation under S.L. 452.83 (clause 9 of Part A).
(2) The controller bases the location check at clocking (clause 2(2) and Annex 1 of Part A) on Art. 6(1)(f) GDPR with a written legitimate-interest assessment per location; a data protection impact assessment is mandatory, because the IDPC's list under Art. 35(4) GDPR names the processing of location data (item 1(c)). For clocking at the NFC tag a short data protection impact assessment is recommended (item 7, employees).
B2. Working time records
The working time records (clause 2(1) and Annex 1 of Part A) serve the records under the Organisation of Working Time Regulations (S.L. 452.87) and the payroll and overtime records; the legal basis is Art. 6(1)(c) GDPR to the extent Maltese law requires the records, otherwise Art. 6(1)(f) GDPR.
B3. Sick leave and documents
(1) The controller files a medical certificate (clause 2(3) and Annex 1 of Part A) only to the extent that it may request it under the applicable Wage Regulation Order, the collective agreement or the contract of employment; only the statement of unfitness for work and its expected duration is filed. The legal basis is Art. 9(2)(b) GDPR in conjunction with these provisions.
(2) The documents under Annex 1 of Part A include in Malta in particular the written information on the conditions of employment under the Employment and Industrial Relations Act (Cap. 452), the engagement notification to Jobsplus and payslips; the legal basis is Art. 6(1)(c) GDPR. The controller files the identity card number and the social security number only within these provisions.
B4. Retention
Default values for locations in Malta, changeable by the controller within the minimum values: working time records 84 months (minimum 24 months); raw attendance events 3 months (recommended: accuracy data of the location check at most 30 days); messages 12 months; audit log 84 months (minimum 24 months); employee documents (data type “employee_documents”, including uploaded evidence and medical certificates) 84 months; payroll documents 120 months (minimum 120 months); personnel costs 84 months; notifications 6 months; archived employee profiles 84 months, then anonymisation. The statutory retention duties remain the controller's own duty (clause 10(1) of Part A).
B5. Supervisory authority
The competent supervisory authority for the controller is the Information and Data Protection Commissioner (IDPC), Floor 2, Airways House, Triq Il-Kbira, Tas-Sliema SLM 1549, telephone +356 2328 7100, idpc.org.mt. The competent supervisory authority for the processor is the Austrian Data Protection Authority (Österreichische Datenschutzbehörde, DSB), Barichgasse 40–42, 1030 Vienna, www.dsb.gv.at.