Your workspaces contain data about people: clients, employees, service providers, prospects. This article brings together what that means day to day, and who to reach when something goes wrong.
Keeping a register of your processing activities
The register lists, for each processing of personal data, its purpose, the categories of data concerned, the recipients, the retention period and the security measures in place.
In the context of TimeTonic, a processing activity generally corresponds to a workspace, or to a set of tables sharing the same purpose.
Remember to record your outgoing flows as well: every automation, every dashboard, every synchronisation that sends data to a third-party tool is a recipient to be declared.
Go further
GDPR register template
A ready-to-use workspace template for keeping your register.
See the article →
Privacy by design and by default, in practice
The principle fits in one sentence: collect and expose only what is strictly necessary, right from the design stage. Here is what that looks like in a workspace.
| The principle |
What you do in TimeTonic |
| Minimisation |
An external form only asks for the essential fields. An export view only contains the columns useful to its destination. |
| Access limitation |
Each role only reaches its own views. Sensitive columns are restricted, encrypted or masked. |
| Security by default |
Authentication required ticked on shares, 2FA enabled on accounts, API keys limited to the rights that are needed. |
| Storage limitation |
A retention period defined per table, and effective clean-up of the rows that have gone past it. |
Personal data is not only in the columns that carry a person's name. IP addresses, URLs, change histories, comments and SmartText contain it too: see
Personal data and technical data.
Answering a request from a data subject
A person can ask you to access their data, to rectify it, to erase it, or to object to its processing. The reflex is the same in every case.
1
Record the request
Date, requester, nature of the request, data concerned, action taken. It is the trace that proves you handled the request.
2
Search everywhere, not only in the obvious table
The person's data may also be in comments, attachments, histories and linked tables.
3
Do not forget the copies that went elsewhere
If an automation or an export has sent this data to a third-party tool, the request covers those copies as well. Your register tells you where they are.
TimeTonic's data protection officer
dpo@timetonic.com: for any question about the processing of your data by TimeTonic, and immediately if you suspect a leak.
The supervisory authority, in the event of a confirmed breach
The data controller has 72 hours to notify a personal data breach to the competent supervisory authority. In France, this is done through the notification service on cnil.fr. The deadline starts from the moment you become aware of it.
Do not assess the seriousness on your own. A doubt about a leak is to be reported, not weighed up in your corner. The 72-hour deadline is short, and it starts running as soon as you become aware of the facts.
Go further
GDPR
TimeTonic's commitment on data protection.
Read more →
Go further
Privacy policy
TimeTonic's reference document.
Read more →
Go further
Revoke an access
What to do in case of compromise.
Read more →