Data Processing Addendum
Last updated: 2026-09-29
This Data Processing Addendum ("DPA") forms part of the Terms of Service and applies whenever you (the employer or business) input the personal data of your employees or other individuals into TimePlate. It records that you are the data user (controller) and that SlashHub Limited processes that data only as your data processor, on your documented instructions, and never for its own purposes.
1. Parties, Roles & Scope
This DPA is between you ("Customer", "you") and SlashHub Limited ("SlashHub", "Processor", "we"), and forms part of, and is subject to, the SlashHub Terms of Service and any product-specific addendum (together, the "Agreement"). Capitalised terms not defined here have the meaning given in the Agreement.
The Customer is the data user (within the meaning of the Personal Data (Privacy) Ordinance (Cap. 486) ("PDPO")) — and, where the EU/UK GDPR applies, the controller — in respect of all personal data of its employees, applicants, contractors, and other individuals (together, "Data Subjects") that the Customer (or any person acting for it, including an employee with a TimePlate login) submits, uploads, generates, or stores in, or transmits through, TimePlate (the "Processed Data").
SlashHub is a data processor (and, where the EU/UK GDPR applies, a processor) that processes the Processed Data only on the Customer's documented instructions and only to provide and secure TimePlate. SlashHub does not determine the purposes or means of the processing, does not process the Processed Data for its own purposes, and is not a data user in respect of it. This DPA applies in addition to, and does not limit, the Allocation of responsibility in clause 28 of the Terms of Service.
2. Definitions
"Applicable Data Protection Law" means, as applicable, the PDPO (Cap. 486), the EU General Data Protection Regulation 2016/679, the UK GDPR and Data Protection Act 2018, and any other data-protection law that applies to the processing under this DPA. "Biometric Data" means personal data resulting from face, fingerprint, or similar processing that uniquely identifies an individual, including the face-descriptor and face-image data that TimePlate may store when the Customer enables face recognition. "Sub-processor" means any third party engaged by SlashHub to process the Processed Data. "Security Incident" means a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, the Processed Data.
The Customer's documented instructions include: (a) the configuration of TimePlate (including attendance methods, scheduling rules, payroll settings, and retention options) that the Customer selects; and (b) any lawful written instruction the Customer issues to SlashHub through the Services or by email to privacy@slashhub.hk or support@slashhub.hk.
3. Customer Responsibilities (Data User)
The Customer is solely responsible for the lawfulness of the Processed Data and of the processing. Without limiting that, the Customer shall: (a) comply with all Applicable Data Protection Law, including the six Data Protection Principles in the PDPO, in respect of the Processed Data; (b) give each Data Subject a Personal Information Collection Statement that is clear and lawful, stating the purposes of collection, the classes of transferees (including SlashHub and its Sub-processors), the consequences of failing to supply the data, and the Data Subject's rights of access and correction (DPP1); (c) ensure the Processed Data is adequate, relevant, and not excessive, and is collected for a lawful purpose directly related to its functions (DPP1); (d) obtain and maintain all consents, notices, permissions, and authorisations required for the processing, and ensure that the Customer has a lawful basis for any transfer of the Processed Data to SlashHub; and (e) ensure its employees' use of TimePlate complies with the Customer's internal policies and all applicable employment, tax, and social-security law.
Where the Customer enables location data (GPS), biometric attendance (face recognition or fingerprint), or any other sensitive feature, the Customer shall: (a) give the Data Subject the required Personal Information Collection Statement and obtain the Data Subject's EXPLICIT consent (and, where the PDPO or other law requires, written consent) before enabling the feature for that Data Subject; (b) make the feature genuinely optional and offer a reasonable alternative attendance method (for example QR, PIN, or kiosk without biometrics); (c) conduct any privacy impact assessment or necessity/proportionality assessment required by law; and (d) retain the evidence of consent for as long as the feature is enabled and thereafter as required by law.
The Customer represents and warrants that: (a) it has the right to collect and disclose the Processed Data to SlashHub for the purposes of the Agreement; (b) its instructions to SlashHub are lawful; (c) it will not instruct SlashHub to process the Processed Data in a manner that would breach Applicable Data Protection Law; and (d) it will respond to Data Subject requests, complaints, and regulatory enquiries relating to the Processed Data in its capacity as data user. The Customer is responsible for all notices, consents, and authorisations relating to minors or any Data Subject lacking capacity.
4. SlashHub Responsibilities (Processor)
SlashHub shall: (a) process the Processed Data only on the Customer's documented instructions (and as necessary to provide TimePlate and comply with law), and only for the purposes set out in the Agreement; (b) not sell the Processed Data, not use it for its own marketing or profiling, and not use it to train any AI model of its own; (c) ensure that personnel authorised to process the Processed Data are bound by appropriate confidentiality obligations; (d) implement and maintain the technical and organisational security measures in clause 6 (DPP4); (e) assist the Customer, to the extent reasonable, in responding to Data Subject requests and in meeting the Customer's security, breach-notification, and impact-assessment obligations; and (f) notify the Customer promptly if, in SlashHub's opinion, an instruction would breach Applicable Data Protection Law.
SlashHub does not collect, use, or disclose the Processed Data for any purpose of its own. SlashHub may create and use anonymised and aggregated data that cannot reasonably be linked back to any individual (for example, platform-wide reliability metrics) to operate, secure, and improve the Services, and may use such anonymised data indefinitely. SlashHub may also process the Processed Data to comply with law, to respond to a lawful request from a public authority, and to enforce the Agreement.
SlashHub is not responsible for the accuracy, completeness, or lawfulness of the Processed Data (which the Customer supplies), for the Customer's configuration of TimePlate, or for any decision the Customer makes in reliance on an output of TimePlate.
5. Sub-processors
The Customer provides a general authorisation for SlashHub to engage Sub-processors to process the Processed Data. SlashHub maintains a current list of Sub-processors and the processing they carry out (for example hosting, storage, identity, payment, messaging, and AI-provider services) and makes it available on request and at a page we nominate. SlashHub will notify the Customer of any intended change to the Sub-processors as required by Applicable Data Protection Law (and, where the GDPR applies, at least the period required by Art. 28) so that the Customer may object; if the Customer objects on reasonable data-protection grounds and the parties cannot resolve it, the Customer may terminate the affected part of the Services.
Before any Sub-processor processes the Processed Data, SlashHub shall impose on it, by written contract, data-protection obligations that are no less protective than those in this DPA (including confidentiality, security, retention, and no-own-purpose/no-training terms). SlashHub remains liable to the Customer for the performance of its Sub-processors' data-protection obligations to the same extent SlashHub is liable for its own.
6. Security Measures (DPP4)
SlashHub shall implement and maintain appropriate technical and organisational measures to protect the Processed Data against unauthorised or accidental access, processing, erasure, loss, or use, having regard to the nature of the data and the harm that could result from a breach. These measures are expected to include, at a minimum: encryption of data in transit; encryption of data at rest; hashed credentials and tokens; least-privilege access control and role-based permissions; per-tenant logical segregation; logging and monitoring; secure software development practices; personnel confidentiality obligations; and an incident-response process.
SlashHub may update the security measures from time to time to reflect advances in technology and changes in risk, provided that the overall level of protection does not materially decrease during the term. SlashHub describes its current measures in general terms (without naming specific vendors) so that it can improve them without amending this DPA.
7. Employee & Biometric Data; Retention
TimePlate is used to record attendance and location, schedule shifts, and compute hours, overtime, leave, pay, MPF, and related figures for the Customer's employees. The Customer determines what data is collected, how long it is needed for its own employment, tax, and record-keeping purposes, and which features are enabled. SlashHub retains the Processed Data only for as long as necessary to provide TimePlate on the Customer's instructions and otherwise as required by law, and deletes or returns it in accordance with clause 12.
Where the Customer enables face recognition, the face descriptor is used only to verify or identify the Data Subject for attendance. The Customer shall treat biometric data as sensitive and obtain explicit consent as required by clause 3. SlashHub stores biometric data as a processor and, where the Customer enables it, may create a limited number of additional reference captures (a "self-evolving gallery") to improve recognition reliability under changing lighting; the Customer may disable this, reset the gallery, or request deletion at any time.
8. Data Subject Requests from Employees
Data Subjects are the Customer's employees and contractors. The Customer, as data user, is responsible for receiving and responding to their Data Access Requests, correction requests, and other rights requests under the PDPO (and, where applicable, the GDPR). SlashHub will provide the Customer with the functionality (and, on reasonable request, assistance) needed for the Customer to locate, export, correct, or delete the relevant Processed Data so the Customer can meet its obligations within the statutory time limits.
If SlashHub receives a request directly from a Data Subject, it will, unless legally required to act otherwise, direct the request to the Customer and not respond to it substantively, and will notify the Customer without undue delay. The Customer shall not instruct SlashHub to provide false or misleading information in response to a data-subject request.
9. Cross-Border Transfers
The Customer acknowledges that SlashHub and its Sub-processors may process and store the Processed Data in Hong Kong and in other jurisdictions where they or their service providers operate, including jurisdictions that may not have data-protection laws identical to the PDPO. Section 33 of the PDPO (restrictions on transferring personal data outside Hong Kong) is not currently in operation, but the Customer remains responsible under DPP3 for ensuring that any transfer is for a purpose same as or directly related to the original purpose of collection, or is otherwise lawful.
To the extent the GDPR/UK GDPR applies, SlashHub will implement an appropriate transfer mechanism (such as the EU Standard Contractual Clauses and the UK International Data Transfer Addendum) for transfers of Processed Data out of the EEA/UK, and will process the Processed Data in accordance with clause 4. SlashHub will, on request, make the appropriate transfer documentation available to the Customer.
10. Personal Data Breach
SlashHub shall notify the Customer without undue delay after becoming aware of a Security Incident affecting the Processed Data and shall provide the information the Customer reasonably needs to meet its own notification obligations (for example, to the PCPD, to a supervisory authority, or to Data Subjects). SlashHub's notification is not, and shall not be construed as, an acknowledgement of fault or liability.
SlashHub shall take reasonable steps to mitigate the Security Incident and to remedy its cause. The Customer, as data user, is responsible for deciding whether, and how, to notify Data Subjects and regulators and for the content of any such notification, and shall not do so in a way that misstates SlashHub's role or that names SlashHub other than as the Customer's processor where that is accurate.
11. Audit & Compliance
SlashHub shall make available to the Customer information reasonably necessary to demonstrate compliance with this DPA, and shall allow for and contribute to audits, including inspections, by the Customer (or an auditor it mandates) that is not a competitor of SlashHub, subject to: (a) reasonable prior written notice; (b) the auditor entering a confidentiality agreement with SlashHub on terms acceptable to SlashHub; (c) the audit being conducted during business hours and in a manner that does not disrupt the Services or breach other customers' confidentiality; and (d) the Customer bearing its own costs and any reasonable costs SlashHub incurs.
Where SlashHub holds a current independent security certification or audit report, the Customer may rely on it as evidence of the relevant controls instead of conducting its own inspection.
12. Return & Deletion of Personal Data
On termination or expiry of the Agreement, on the Customer's written request, SlashHub shall delete or return the Processed Data in SlashHub's possession or control, at the Customer's choice, except to the extent SlashHub is required by law to retain it (for example, under Hong Kong tax and record-keeping law) or needs it to establish, exercise, or defend legal claims. SlashHub may retain the Processed Data for the retention period described in the Privacy Policy and this DPA, after which it will be deleted or anonymised. Backup copies are overwritten or destroyed in the ordinary course.
Until deletion, SlashHub shall continue to protect the Processed Data in accordance with this DPA. The Customer acknowledges that it should export and retain its own copy of any data it is required to keep (for example for the Inland Revenue Ordinance (Cap. 112), the Employment Ordinance (Cap. 57), or MPF purposes) before termination.
13. Liability, Indemnity & Order of Precedence
Each party's liability under this DPA is subject to the exclusions, limitations, and liability cap in the Terms of Service (including clause 19 and clause 20), and nothing in this DPA increases or extends SlashHub's liability beyond that cap or those exclusions. To the maximum extent permitted by law, the Customer shall indemnify SlashHub against all claims, fines, penalties, losses, and costs arising from: (a) the Customer's failure to give the required Personal Information Collection Statement or to obtain the required consent (including explicit consent for biometric or location data); (b) the Customer's unlawful or inaccurate instructions; (c) the Customer's breach of this DPA or Applicable Data Protection Law; and (d) any claim by a Data Subject, works council, union, or regulator relating to the Customer's processing of the Processed Data.
Nothing in this DPA excludes or limits any liability that cannot lawfully be excluded or limited under Hong Kong law, including under the Control of Exemption Clauses Ordinance (Cap. 71) (for example, liability for death or personal injury caused by negligence). Where a conflict exists between this DPA and the Terms of Service on a data-protection matter, this DPA prevails; on all other matters, the Terms of Service prevail.
14. Governing Law & Contact
This DPA is governed by the laws of the Hong Kong Special Administrative Region of the People's Republic of China and is subject to the dispute-resolution clause (HKIAC arbitration, seat in Hong Kong) in the Terms of Service.
Data-protection enquiries and notices: privacy@slashhub.hk.
Data Protection Officer: SlashHub Data Protection Officer, dpo@slashhub.hk.
Product-Specific Addendum — timeplate
The following additional terms apply specifically to timeplate and supplement the main document above.
T-1. TimePlate-Specific Terms (Workforce Management for All Companies)
TimePlate is a workforce-management, attendance, payroll, and shift-scheduling platform designed for companies of all sizes and industries — including but not limited to retail, hospitality, restaurants, healthcare, manufacturing, professional services, construction, logistics, education, and the public sector. By using TimePlate, you agree to the additional terms in this Addendum.
**Industry Modes.** TimePlate provides industry-specific templates and rule packs to accommodate different workforce needs: (a) **Hospitality / Restaurants** — tip-out rules, Average Daily Wage (ADW), split-shifts, statutory-holiday pay under the Hong Kong Employment Ordinance (Cap. 57); (b) **Retail** — multi-site scheduling, seasonal rotas, commission tracking; (c) **Healthcare** — shift handovers, on-call rotas, professional-registration expiry tracking; (d) **Manufacturing** — production-line rosters, overtime caps, fatigue-management rules; (e) **Construction** — site-based attendance, weather-day rules, CIS (Construction Industry Scheme) compliance; (f) **Professional Services** — billable-hour tracking, project allocation, leave-management; (g) **Education** — academic-year calendars, term-time scheduling, substitute-teacher pools; (h) **Logistics & Warehousing** — shift bidding, fatigue rules, vehicle-assignment logs; (i) **General Office** — flexible working, remote/hybrid scheduling, core-hours compliance. You select an industry mode at sign-up and may switch modes at any time; switching does not erase your existing data but may require you to re-verify industry-specific settings.
**Third-Party Integrations.** TimePlate may integrate or interoperate with third-party systems and services (for example point-of-sale, accounting, messaging, or identity services). Third-party services are provided and operated by their respective owners under their own terms and privacy policies. SlashHub is not a party to any third-party transaction and is not responsible for any third-party service, including its availability, accuracy, security, content, acts, or omissions, or for any payment dispute, refund, chargeback, outage, or data loss arising from it. We do not name our integration partners here so that we may add, change, or remove integrations without amending this Addendum.
**Outputs Are Estimates; You Must Verify.** Attendance records, worked-hours and overtime figures, leave balances, payroll and MPF computations, statutory-holiday and rest-day treatments, tax figures, reports, exports, schedules, and any other output of TimePlate are ESTIMATES and tools provided for your own review. They are not professional advice and are not a substitute for the judgement of a qualified accountant, payroll professional, or lawyer. You are solely responsible for reviewing, verifying, and approving every output before you use it, rely on it, publish it to your employees, or file it with any authority. SlashHub is not liable for any underpayment, overpayment, statutory penalty, surcharge, fine, interest, assessment, or employee claim arising from your reliance on any output.
**No Employment or Similar Decisions.** TimePlate does not make, and must not be used to make, employment or other decisions about individuals without human review. You must not use TimePlate to automatically terminate, discipline, demote, or otherwise materially affect an employee without a human decision-maker reviewing the underlying information. You are responsible for any decision you make in reliance on TimePlate data or AI suggestions.
**Your Records & Backups.** You are responsible for keeping your own records and backups of the data you need to retain (for example, records required by the Inland Revenue Ordinance (Cap. 112), the Employment Ordinance (Cap. 57), or MPF purposes), including by exporting data from TimePlate periodically. SlashHub is not liable for any loss of data that you have not independently backed up or exported.
**Employee Data — You Are the Data User.** You are the data user (Personal Data (Privacy) Ordinance (Cap. 486)) and, where applicable, the controller, of your employees' personal data (name, contact details, ID and bank details, schedule, hours worked, pay rate, attendance and location records, performance notes, training records, and, if you enable it, biometric data). SlashHub processes that data only as your data processor, on your instructions, and never for its own purposes. You represent and warrant that you have provided each employee with a Personal Information Collection Statement, obtained all necessary consents (including explicit consent for biometric and location data), and that your instructions to us are lawful. Our processing of employee data is governed by our Data Processing Addendum (available at /dpa), which forms part of these Terms.
**Payroll, MPF & Tax Computation.** Payroll, MPF, statutory-holiday and rest-day, overtime, leave, and tax figures are computed from the data you provide and the rules you configure. TimePlate performs COMPUTATION AND EXPORT ONLY: it does not move money, pay wages, remit MPF, or file returns, and is not a payroll bureau, employment agency, or tax adviser. You remain solely responsible, as the employer, for all statutory and contractual obligations (including under the Employment Ordinance (Cap. 57), the Mandatory Provident Fund Schemes Ordinance (Cap. 485), and the Inland Revenue Ordinance (Cap. 112)) and for the accuracy and timeliness of every payment, contribution, and filing. SlashHub is not liable for any miscalculation, under- or over-payment, MPF surcharge, tax assessment, penalty, or employee claim arising from inaccurate input data, your configuration, your failure to verify an output, or any change in law.
**Multi-Site & Multi-Country.** TimePlate supports scheduling and payroll for companies operating in multiple sites, regions, or countries. Each site may have its own timezone, currency, and labour-law configuration. You are responsible for configuring each site correctly and for complying with the local employment, tax, and data-protection laws of each jurisdiction in which you operate.
**Attendance, Location & Biometrics.** TimePlate may record clock-in/clock-out times and, if you enable them, GPS location, IP address, device signals, and biometric data (face or fingerprint). Biometric and location features are OPTIONAL and OFF unless you enable them. Before enabling any such feature you must give the affected employee the required Personal Information Collection Statement and obtain their EXPLICIT consent, must offer a reasonable non-biometric alternative, and must retain evidence of consent. You are responsible for resolving any attendance dispute, and SlashHub is not liable for any dispute over whether an employee was present or worked particular hours. You may disable these features at any time.
**AI Scheduling & Forecasting.** SlashAI may assist with shift scheduling, demand forecasting, and labour-cost optimisation. All AI suggestions are drafts; you must review and approve before publishing to your employees. SlashHub is not liable for misallocations arising from inaccurate historical data or from your failure to incorporate local labour laws into the constraints.
**Workforce Data Sharing.** Aggregated, anonymised workforce metrics (e.g. industry-wide turnover rates, average overtime hours) may be used to improve TimePlate's scheduling recommendations. Personally identifiable employee data is never shared or sold.
T-2. TimePlate Subscriptions, Plans & Billing
TimePlate offers a free tier and paid subscription plans (currently Starter, Plus, and Pro, billed yearly or monthly), each with its own store and employee limits and price, as described on our pricing page and in the TimePlate Subscription Terms. Any plan described as "Enterprise" is not currently offered for self-serve purchase; where referenced, it is subject to a separate written agreement. The Free plan is limited (currently 1 store and 10 employees) and is intended for evaluation. Plan names, limits, features, and prices may change on the notice provided in the Subscription Terms.
Paid TimePlate plans are billed annually in advance, in Hong Kong Dollars, through our payment provider. Subscriptions renew automatically for successive 12-month terms unless you cancel before the renewal date. By purchasing a paid plan, you authorise us to charge the payment method on file at each renewal.
New paid plans may include a trial period. If no payment is received by the end of a trial, the plan automatically reverts to the Free plan and its limits. Similarly, if a renewal payment fails or is not received, the plan becomes past due and, after a short grace period, automatically reverts to the Free plan. These automatic changes may occur even if our renewal or warning notices did not reach you.
Plan fees are non-refundable except as required by applicable law; there are no partial or pro-rated refunds for cancellation, downgrade, or non-use. Upgrades take effect immediately (pro-rated), and downgrades take effect at the next renewal. Exceeding your plan limits may restrict or block functions until you upgrade. Add-ons (e.g. training sessions, advanced analytics, white-label branding) are billed separately and are available only on eligible plans.
The TimePlate Subscription Terms set out the full terms of purchase, billing, renewal, cancellation, refunds, promotional and loyalty pricing, and the conclusive nature of our system and payment records. The TimePlate Subscription Terms form part of the Terms of Service. Notices (including renewal notices, invoices, receipts, and expiry warnings) are deemed delivered when sent to the contact details on your account; non-receipt of a notice does not delay a renewal charge, prevent an automatic downgrade, or excuse payment.
T-3. TimePlate Partner Programme (Sales Partners / 合作者)
The TimePlate Partner Programme allows approved individuals and entities (internal or external "Partners") to earn commission by referring paying customers through a unique invite code. Participation is governed by the TimePlate Partner Programme Agreement (the "Partner Agreement"), which is available at /partner-terms and forms part of these Terms. By applying to, being accepted into, or participating in the Programme, you agree to the Partner Agreement.
Commission is a ONE-TIME percentage (15%–25%, rising automatically with your cumulative attributed first-year revenue) of the Net First-Year Fee actually received and retained by SlashHub. THERE IS NO BASE SALARY and no guaranteed income. Renewals, subsequent years, add-ons, free plans, and any amount not ultimately retained (including refunds and chargebacks) do not earn commission. Attribution is first-write-wins, must be linked at sign-up or before the customer's first payment, is unavailable after payment, and self-referral is prohibited. SlashHub may suspend or rotate invite codes, and its records are conclusive.
Partners participate solely as independent contractors; no employment, agency, partnership, or fiduciary relationship is created and Partners have no authority to bind SlashHub. Commission is provisional, and SlashHub may reverse or recover it (clawback) and set it off against amounts owed where a payment is refunded, charged back, or not retained, or where commission was earned through fraud, error, or breach. NO PAYOUT IS MADE until a TimePlate administrator confirms the final payable amount. SlashHub may suspend, terminate, or prospectively modify the Programme at any time. The Partner Agreement contains its own disclaimers, limitation of liability, indemnity, tax, confidentiality, and governing-law clauses, which apply to the Programme and prevail over these Terms for Programme matters.