Skip to main content

Data Processing Addendum

How PositionMySite processes personal data on behalf of TimeOff Manager customers.

Last updated: August 22, 2026

1. Roles

This Data Processing Addendum (“DPA”) forms part of the agreement between the customer organization (“Controller” or “Customer”) and PositionMySite (“Processor”) for use of TimeOff Manager.

  • Controller: The employer or organization that provisions accounts, configures features, and determines how workforce data is used.
  • Processor: PositionMySite, which hosts and operates TimeOff Manager and processes personal data only on documented instructions from the Controller.

2. Subject matter and duration

Processor provides cloud workforce management services (leave, scheduling, time tracking, mileage, payroll-related exports, and related features) for the duration of the Customer’s subscription or other service term, and as needed to wind down or delete data in accordance with this DPA and the Customer’s instructions.

3. Categories of data subjects and personal data

Depending on features enabled by the Controller, Processor may process:

  • Data subjects: employees, contractors, managers, HR administrators, and other users the Controller authorizes.
  • Account and profile data: names, email addresses, roles, employee identifiers, and profile information.
  • Leave and scheduling data: PTO balances, leave requests, approvals, schedules, and public-holiday assignments.
  • Time and attendance data: clock-in/out timestamps, break records, work activity selections, and optional GPS coordinates or geofence validation results when enabled.
  • Photo verification data: selfie images captured at clock events when the Controller enables photo verification.
  • Payroll-related exports: hours, overtime, mileage reimbursements, and related reporting data the Controller generates or exports.
  • Mileage data: trip routes, distances, and related metadata when mileage tracking is enabled.

4. Processor obligations

  • Process personal data only on documented instructions from the Controller, including configuration of product features and account settings.
  • Ensure personnel authorized to process personal data are bound by confidentiality obligations.
  • Implement appropriate technical and organizational measures described in our Security page.
  • Use subprocessors listed on our Subprocessors page and notify Customers of material changes as described there.
  • Assist the Controller, where reasonably possible, with data subject requests that the Controller cannot fulfill through self-service export or deletion tools.
  • Notify the Controller without undue delay after becoming aware of a personal data breach affecting Customer data, to the extent permitted by law.

5. Controller responsibilities

  • Establish a lawful basis and provide any required notices to employees and other data subjects.
  • Configure features (including GPS, geofencing, and photo verification) in line with applicable law and internal policy.
  • Respond to data subject requests from their workforce, using export and account tools where available.
  • Ensure instructions to Processor comply with applicable privacy and employment laws.

6. Export and deletion

Controllers can export workforce data through in-product reporting and export features where available. Controllers may request deletion of their organization’s data by contacting security@timeoffmanager.us. Processor will delete or return personal data at the end of the service term, subject to legal retention requirements and backup cycles.

7. International transfers

Customer data is processed primarily in Canada (application origin). Where subprocessors process data in other regions, Processor uses appropriate safeguards required by applicable law.

8. Governing law

This DPA is governed by the laws of the State of Delaware, United States, without regard to conflict-of-law principles, except where mandatory local law requires otherwise.