How we protect customer data
Availability and leave records are personal data. This page describes what we have built, what we have not, and where the boundaries are.
Where your data lives
The first question a technical buyer asks is where the records sit and who else is holding them. These are the answers, including the part that does not fit the simple version.
Data residency
You choose the United States or the European Union when you create a workspace. Availability, leave, and audit records stay in that region. The choice is permanent, so make it before you invite anyone.
Sign-in data
Our identity provider runs in a single United States region for every customer, including EU workspaces. It holds account identifiers and email addresses. It holds no availability, leave, or audit records. A small set of routing identifiers is also processed in the United States.
Privacy Policy →Encryption
TLS 1.2 or higher in transit. AES-256 at rest, using AWS managed keys. We do not offer customer-managed keys. The application is hosted on AWS.
Workspace isolation
Temprix is multi-tenant. Every request resolves to exactly one workspace at the API, and that scope is enforced server-side on every read and write. It is not a filter applied in the browser.
Deletion
Deleting a workspace opens a 30 day window in which it can be restored. After that it is removed from live systems, audit history included. Residual copies can remain in encrypted backups for up to 35 more days, then they expire.
Export
Members, events, and reports export to CSV from inside the app, scoped to whatever you have filtered. That is a workspace export. A member asking for their own data goes to their employer, not to this button.
Who can see what
How people and machines sign in, what roles actually enforce on each plan, and what our side can reach.
Sign-in
Email and password, or Google sign-in. Multi-factor authentication is not available on email-and-password sign-in. Google sign-in uses whatever MFA you have set on the Google account. Access tokens are short-lived and refreshed in the background. Signing out ends the session.
Roles
Every workspace has an owner. Members are admin or standard. Role enforcement applies on paid plans; on Free, every member has admin access. Business adds team-level admins.
API keys
Tokens are scoped to a single workspace, shown once at creation, and stored only as a hash. Any key can be revoked immediately, and a member's keys are revoked automatically when that member is deactivated.
SAML SSO
Not a self-serve switch. We build it against your identity provider on request, as part of an Enterprise agreement. Ask before you buy, not after.
Contact sales →Our access
Production workspace data is not used for development, testing, or day-to-day work on the product. Support and incident access is requested case by case, time-bounded, and logged.
What we sign
Contracts, roles under GDPR, and the third parties involved. Including the certifications and tests we do not have.
GDPR roles
Temprix is registered in the Netherlands, KvK 42087766. For workspace data, including member records and audit history, you are the controller and we are the processor. For your account and billing data, we are the controller.
Privacy Policy →Data Processing Agreement
One DPA covers every plan, Free included. Nothing to negotiate, nothing to request, no minimum contract value.
Read the DPA →Sub-processors
AWS, Sentry, PostHog, Slack, and Google. Each is named in Annex II of the DPA, with what it does and where it runs. Stripe processes billing as a separate controller, not as a sub-processor of workspace data.
See the list →Health-related data
Depending on how a workspace is configured, an absence category can reveal information about health, a special category under Article 9. Nothing in Temprix requires a reason to be recorded, and category names are yours to choose.
Certifications
We do not hold SOC 2 or ISO 27001, and we have not commissioned a third-party penetration test. We do not claim equivalence. If that changes, it will say so here.
When something goes wrong
What gets recorded, when you hear from us, and how to reach us if you find something we missed.
Audit log
Every create, update, and delete is recorded with who, what, and when. Entries cannot be edited or deleted through the product, including by workspace admins. Six months of history on Free, no fixed limit on paid plans.
Breach notification
If a personal data breach affects your workspace data, we notify the workspace owner within 48 hours of becoming aware of it. That commitment lives in the DPA, not only on this page.
See the DPA →Vulnerability disclosure
No bug bounty, and we will not pretend otherwise. Send it to security@temprix.app and we will acknowledge receipt, investigate, and agree disclosure timing with you.
security@temprix.app →Reviewing Temprix for your organization?
If something you need is not on this page, ask. A security questionnaire, a specific clause in the DPA, or a question about how a control actually works: those go to a person, not a form.