18:30Legal
Data Processing Agreement
Effective: 1 September 2026
Last updated: 1 September 2026
1. Introduction
StaffVertex is operated by Alphinex Solutions (Private) Limited, a private limited company incorporated in Pakistan under company registration number 0315829, registered with the Securities and Exchange Commission of Pakistan (SECP), with its registered office at Ali Arcade, 6th Road, Rawalpindi, Punjab, Pakistan.
This Data Processing Agreement (the "DPA") sets out the terms on which we process personal data on behalf of your organization when your organization uses StaffVertex. It supplements our Terms of Service and Privacy Policy and forms part of the contract between us.
By continuing to use the service after this DPA's effective date, your organization accepts it. Where a signed counterpart is required (for example to satisfy an internal procurement or a regulator), you may request a counter-signed copy without changing the terms.
This DPA is written to meet Article 28 of Regulation (EU) 2016/679 (the "GDPR") and the UK GDPR, and to support customers who are subject to comparable rules elsewhere (including California, Brazil and the various US state laws that follow the same controller-processor model).
2. Definitions
The terms "controller", "processor", " personal data", "processing", "data subject" and "personal data breach" have the meanings given to them in the GDPR. In this document:
- "Customer", "you" and "your" mean the organization that has subscribed to StaffVertex.
- "We", "us" and "StaffVertex" mean Alphinex Solutions (Private) Limited.
- "Customer Personal Data" means any personal data we process on your behalf under the service, including data your members enter and data the desktop app captures on the devices your members use.
- "Applicable Data Protection Law" means every data protection law that applies to your use of the service, including the GDPR, the UK GDPR and any comparable law in a country from which you make the service available.
- "Sub-processor" means a third party that processes Customer Personal Data on our behalf.
3. Roles of the Parties
For Customer Personal Data, you are the controller and we are the processor. You decide the purposes and means of processing; we carry it out on your instructions.
Where your members enter personal data about their own colleagues, clients or third parties, you remain the controller for that data as well, and are responsible for having a lawful basis for it and for telling those people what is happening.
For our own website visitors, our marketing to you, our billing relationship with you and our internal security and abuse monitoring, we act as an independent controller. Those activities are governed by our Privacy Policy and not by this DPA.
4. Subject Matter and Duration
Subject matter. The processing of Customer Personal Data that is necessary for us to provide the StaffVertex service to you, including hosting the workspace, running the desktop tracker, storing screenshots and activity records, producing time and payroll reports, sending transactional email and delivering support.
Duration. This DPA takes effect on the earlier of (a) the date you first accept our Terms of Service and (b) the date this document was made effective, and continues for as long as we process Customer Personal Data on your behalf. Clauses on confidentiality, deletion, audit and liability survive termination.
5. Nature and Purpose of Processing
We process Customer Personal Data in order to:
- host your workspace, its documents and its history;
- record the time, activity, screenshots, application and website usage that the tracker captures when your administrators enable those features;
- calculate timesheets, attendance, leave, payroll and invoices from the recorded data;
- send transactional messages to your members;
- handle support requests from your members and administrators;
- protect the service β detect abuse, prevent fraud, apply rate limits, keep audit logs and comply with law;
- maintain backups so we can restore your data after a failure.
We do not use Customer Personal Data for our own marketing, we do not sell it, we do not share it with advertisers, and we do not use it to train machine-learning models.
6. Categories of Data and Data Subjects
Data subjects whose personal data we process on your behalf typically include: your employees, contractors, interns and other members of your workspace; your clients and their representatives, where you record work performed for them; and other individuals whose details your members enter (for example, an emergency contact).
Categories of Customer Personal Data typically include:
- identifiers: full name, email address, phone number, profile photo;
- account information: hashed password, sign-in history, session tokens;
- organizational information: job title, employment type, hire date, department, manager, project membership;
- contact and address information a member chooses to add, including home address, date of birth, emergency contact and bank account details entered for payroll;
- time-tracking data: clock-in and clock-out events, timesheet entries, project and task assignments, leave and holiday records;
- monitoring data captured by the desktop app when enabled: screenshots, activity levels, application and window titles in use, websites visited in a browser and idle time;
- finance data: pay rates, hours priced against them, payslips, billable and payable invoices;
- support content: messages your members send us through email or the chat window;
- device telemetry the desktop tracker needs to run: operating system, app version, machine identifiers, sync errors.
The exact scope depends on which features you enable. Nothing in this list obliges us to collect a category that the product does not; nothing prevents you from choosing not to enable a feature that would collect one.
7. Controller Instructions
We will process Customer Personal Data only on your documented instructions, including as set out in this DPA and in the Terms of Service, unless a law we are subject to requires otherwise. In that case we will (unless the law forbids it) tell you before we act.
Your instructions include configuring the service through its own controls: switching monitoring features on or off, setting retention periods, choosing who has which role, and asking us through support@staffvertex.com for anything the product does not do by itself. Instructions outside the scope of the service, or in breach of Applicable Data Protection Law, may be declined; we will tell you why.
Your responsibility. You confirm that (a) your instructions have a lawful basis; (b) you have told your members what StaffVertex is used for, in the form your local law requires, before recording their activity; (c) where the law requires consent for monitoring, you have obtained and kept a record of it; and (d) any personal data you put into the service about anyone else is data you were entitled to enter.
8. Confidentiality
We ensure that every person authorized to process Customer Personal Data β our employees, contractors and anyone else with access β is bound by a written obligation of confidentiality, trained in what that obligation means, and has access limited to what their job actually needs. Confidentiality obligations survive the end of any individual's engagement with us.
We keep an internal log of who has stood-up access to production systems and when. Access is granted on request, revoked on departure, and reviewed periodically.
9. Security Measures
We maintain appropriate technical and organizational measures to protect Customer Personal Data against accidental or unlawful destruction, loss, alteration, unauthorized disclosure or access. These measures are described in more detail on our Security page and include, at a minimum:
- Encryption in transit. HTTPS with modern TLS for every request to the web application, the desktop tracker sync and the API.
- Encryption at rest. Provider-side encryption on the primary database and on object storage. Secrets that must be read back are additionally sealed with authenticated encryption before they reach the database.
- Access control. Role-based access to the product and least-privilege access to production systems. Passwords are stored only as one-way hashes.
- Network protection. Traffic passes through a network layer that performs DDoS mitigation and abuse filtering before it reaches the application.
- Backups and restore. Regular database backups written to redundant object storage on a documented retention schedule, with a tested restore procedure.
- Change management. Code changes are peer reviewed and deployed through an audited pipeline.
- Monitoring. Application and access logs are retained for a period sufficient to investigate incidents, and alerting is in place for the incidents we expect to see.
- Incident response. A written procedure that triggers on suspicion of a personal data breach, escalates to the people who can contain it, and produces the notification described in Β§13.
Security measures develop over time. We may substitute a control with an equivalent or stronger one; we will not weaken the overall level of protection.
10. Sub-processors
You give us general authorization to appoint sub-processors to help us provide the service. Each sub-processor is bound by terms that are, in substance, no less protective of Customer Personal Data than this DPA.
Current sub-processors, confirmed live in production at the effective date of this DPA:
| Provider | Purpose | Location |
|---|---|---|
| Stripe | Payment, subscription and invoice processing | United States |
| MongoDB Atlas | Our primary database, where your account and workspace data lives | United States (Northern Virginia) |
| Cloudflare R2 | Storage for screenshots and uploaded files, and network protection | United States |
| Vercel | Hosting for the web application, and request logs | United States |
| Resend | Sending our emails (account, billing and product messages) | United States |
| tawk.to | The live chat window on our public website and help center | United States |
| Google reCAPTCHA | Blocking automated abuse of our sign-up and contact forms | Global |
Changes. Before we add or replace a sub-processor that handles Customer Personal Data, we will update this list. Where Applicable Data Protection Law requires it, we will also notify customers who have asked us for advance notice at privacy@staffvertex.com.
Objection. You may object to a new sub-processor on reasonable data-protection grounds within 30 days of the notice. If the objection cannot be resolved, you may terminate the affected part of the service and receive a pro-rata refund of pre-paid fees for the unused period.
11. International Transfers
StaffVertex is operated from Pakistan, and most of our sub-processors are located in the United States, as set out in the table above. When Customer Personal Data leaves the European Economic Area, the United Kingdom or another jurisdiction whose law restricts international transfer, we rely on a lawful transfer mechanism recognized by that law β including the Standard Contractual Clauses adopted by the European Commission and the UK International Data Transfer Addendum, as applicable.
If you require a signed set of Standard Contractual Clauses alongside this DPA, request them from privacy@staffvertex.com or on the request page. Where a transfer would place Customer Personal Data at substantial risk that a lawful mechanism cannot mitigate, we will tell you before making it.
12. Assistance to the Controller
Taking into account the nature of the processing and the information available to us, we will assist you, at your cost where the assistance is substantial, to meet your obligations under Applicable Data Protection Law. Specifically:
- Data subject rights. The product lets your administrators view, correct and delete most Customer Personal Data directly. Where a request cannot be handled from the product β for example, a request to export everything the service holds about one individual, or a restriction request that cuts across features β email privacy@staffvertex.com and we will help. Requests should reach us via you, since we cannot verify whether a person we do not have a direct relationship with is who they say they are; if a data subject contacts us directly we will point them back to you unless the law requires us to act.
- Data protection impact assessments. On reasonable notice, we will provide the information about the service we have that you need to complete a DPIA β a description of the processing, the categories of data, the retention schedule, the sub-processor list, and a summary of our security measures. Much of this is already on this page and in the Privacy Policy.
- Consultation with regulators. Where you are required to consult a supervisory authority in advance of a particular use of the service, we will co-operate with that consultation to a reasonable extent.
13. Personal Data Breach
If we become aware of a personal data breach affecting Customer Personal Data, we will notify you without undue delay, and in any event within 72 hours of becoming aware, at the administrator email address on your account (with a copy to your billing email if it differs). The notice will describe:
- the nature of the breach, including where possible the categories and approximate number of data subjects and records affected;
- the name and contact of a person from whom more information can be obtained;
- the likely consequences of the breach;
- the measures we have taken or propose to take to address it and mitigate its effects.
You are responsible for notifying supervisory authorities and, where required, data subjects. We will co-operate reasonably with those notifications. We will not contact your data subjects directly about an incident without asking you first, unless the law requires us to.
14. Return and Deletion
While the service is live for you, our retention of Customer Personal Data is set out in our Privacy Policy β reproduced below so that both documents cannot drift:
- Your account and workspace dataKept for as long as your organization's account is open.
- Screenshots and activity recordsKept for the retention period that applies to your organization, then deleted automatically by a daily job. Your plan sets the longest period, and your organization's administrators can choose a shorter one in Settings. Once the period has passed, the screenshot image and the minute-by-minute activity, app and website detail are permanently erased; your time entries, hours and activity totals are kept. If no period applies, they are kept until your organization deletes them or closes the account.
- Desktop app clock records (computer start-up times and clock offsets)Kept for as long as your organization's account is open, including after you leave the organization or delete your own account. They are not deleted automatically on a timer, and are erased when the organization's account is closed. Clock warnings attached to a time entry are also erased when that entry is permanently deleted.
- Members and projects you deleteHidden from the app straight away, and permanently erased once the retention period set for your organization has passed.
- Closed accountsRemoved from the app immediately, and permanently erased (including stored screenshots) within 30 days.
- Database backupsKept for up to 30 days on a rolling basis, so deleted data disappears from backups within 30 days of being erased.
- Billing and financial recordsKept for 6 years, because tax and accounting rules require it. This applies even after an account is closed.
End of the contract. When your subscription ends, or on your written request at any time, we will at your choice return Customer Personal Data to you (in the form the service supports at the time) or delete it. In either case, deletion is completed within 30 days of the account being closed, except that:
- Backups follow their own retention cycle. A copy of your data may sit in a backup for as long as our backup retention lasts; it is not accessed to serve requests and is over-written on schedule.
- Records we are required by law to keep β for example billing records kept to satisfy tax or accounting law β are retained for the period the law requires and processed only for that purpose.
15. Audit Rights
You have the right to satisfy yourself that we are complying with this DPA. In practice, that right is exercised in the ways least disruptive to the service:
- Documentation first. We will make available the records we already keep β this document, the Privacy Policy, the Security page, the sub-processor list, and any external attestations we hold at the time β on written request. For most audits, that is enough.
- Written questions. Where documentation is not enough, we will answer reasonable written questions from you or your appointed auditor about our processing. We are not required to answer questions that would compromise the security of other customers, disclose information that is not ours to disclose, or reveal commercially sensitive detail beyond what the answer needs.
- On-site audits. Where Applicable Data Protection Law requires an on-site audit that documentation and questions cannot satisfy, we will co-operate in good faith to plan one that (a) is conducted by a mutually acceptable independent auditor bound by confidentiality, (b) takes place during business hours, (c) does not endanger the security or availability of the service or the privacy of other customers, and (d) happens at most once every twelve months except where a regulator or a personal data breach requires otherwise. You are responsible for the auditor's cost; we bear our own.
16. Liability and Priority
Each party's liability under this DPA is subject to the limitations and exclusions of liability set out in the Terms of Service, to the extent permitted by law. Nothing in this DPA excludes or limits liability that cannot be excluded or limited under Applicable Data Protection Law.
If there is a conflict between this DPA and the Terms of Service, this DPA prevails on any question about our processing of Customer Personal Data. On every other question the Terms of Service prevail.
17. Requesting a Signed Copy
This DPA takes effect without a signature: it is part of the terms you accept when you use the service. Where a signed counterpart is required for internal procurement, a regulator or a partner audit, we will counter-sign a copy on request. It reproduces exactly what is on this page β the wording is not negotiated per customer, so we cannot make bespoke edits to it, but a signed identical copy is available.
Submit the request from the DPA request page, or email legal@staffvertex.com. We aim to return a signed counterpart within five business days.
18. Changes to this DPA
We may update this DPA to reflect a change in law, a new sub-processor, a change to our security measures, or to correct a mistake. The Last updated and Effective dates at the top of the page will record the change. Material changes are announced by email to administrator addresses on active accounts at least 30 days before they take effect, so that a customer who wishes to object under Β§10 has time to do so.
19. Contact
For anything about this DPA, or to request a signed copy, write to legal@staffvertex.com. Data subject requests and general privacy questions go to privacy@staffvertex.com.