GentleTime

FunktionenRoadmapPreiseÜber uns
AnmeldenJetzt starten

Data processing agreement

Version 2026-09-29
This is a translation; if the versions differ, the Dutch text prevails. This agreement is available in Dutch and English.

1. Parties and scope

This data processing agreement is concluded between the organisation that uses GentleTime (the controller, "the organisation") and RG-IT B.V. (the processor, "GentleTime"):

RG-IT B.V.
Vlotstraat 20, 6417 CB Heerlen, the Netherlands
Chamber of Commerce (KvK): 51460602
VAT number: NL850028954B01
Email: hello@gentletime.app

It is part of the terms of service and applies from the moment an organisation account is created, for as long as GentleTime processes personal data for the organisation. Where they conflict on personal data, this agreement prevails. Families (consumers) are not covered; the privacy policy applies to them.

2. Subject, nature and purpose

GentleTime processes personal data solely to provide the GentleTime service as described in the terms of service: creating, showing and keeping day plans with pictograms on screen, phone and watch, and, if the organisation switches it on, showing heart-rate data from a paired watch and offering optional AI features.

  • Data subjects: the organisation's clients (often minors or people with a disability), and staff, volunteers and relatives with an account.
  • Types of data: clients' name and, where entered, date of birth, notes, language and settings; day plans; details of paired watches; account details (name, email address or username, role); technical data (IP address, logs).
  • Special categories: health data (heart rate, heart-rate variability, movement and derived indications), only if the organisation switches readings on for a client.
  • Duration: as long as the organisation uses GentleTime, plus the deletion period in section 10.

3. Responsibilities of the organisation

The organisation determines the purpose and means of the processing and warrants that it is lawful: that there is a valid legal basis (for health data an exception from Art. 9(2) GDPR, such as explicit consent or the provision of care), that data subjects have been informed, and that only staff who need it get access. The organisation records the consent for heart-rate readings in the app before a watch sends readings, and is responsible for its accuracy.

4. Obligations of GentleTime

  • GentleTime processes the data only on documented instructions from the organisation. The organisation's use of GentleTime (the settings it chooses and the data it enters) and this agreement constitute those instructions. If GentleTime considers an instruction to infringe the GDPR, it says so.
  • GentleTime does not use the data for its own purposes, does not sell it, and does not use it for advertising or to train AI models.
  • Everyone at GentleTime with access to the data is bound by confidentiality.
  • If GentleTime is legally required to disclose data to a public authority, it informs the organisation beforehand, unless the law prohibits this.

5. Security

GentleTime takes appropriate technical and organisational measures (Art. 32 GDPR), including:

  • encrypted connections (TLS) and encrypted storage of the database and files;
  • hosting in the EU (the Netherlands and Belgium);
  • strict separation per organisation: each organisation only sees its own data, enforced in the API;
  • roles within an organisation (owner, caregiver, viewer, client), and client logins that only see their own day;
  • passwords only as a bcrypt hash, refusal of passwords from known data breaches, a limit on sign-in attempts, and short-lived sessions that are re-checked regularly;
  • system keys and passwords in a secure secret store; administrative access only for those who need it;
  • automatic deletion of heart-rate readings after 14 days and of AI insights after 90 days;
  • logs of requests and errors, kept for 30 days.

GentleTime may improve these measures, as long as the level of security does not decrease.

6. Sub-processors

The organisation gives general authorisation for engaging sub-processors. GentleTime imposes the same obligations on them as in this agreement and remains responsible for them towards the organisation. Currently:

  • Google Cloud (Google Cloud EMEA Ltd., Ireland) — hosting, secret store, logs, pictogram storage; the Netherlands.
  • MongoDB Atlas (MongoDB Ltd., Ireland) — database; Belgium.
  • Resend (Resend Inc., US) — account emails (such as confirmation and password emails); sent from Ireland.
  • Stripe (Stripe Payments Europe Ltd., Ireland) — payments and invoices; no client or health data.
  • Anthropic (Anthropic PBC, US) — only if the organisation uses AI features: answers to the routine assistant (with age and language, without a name) and summaries without a name or ID for AI insights. An organisation can switch all AI features off at once.

Transfers outside the EEA take place under the EU-US Data Privacy Framework or the European Commission's standard contractual clauses. GentleTime announces a new or replaced sub-processor by email at least 30 days in advance; within that period the organisation may object on reasonable grounds and, if the parties cannot resolve it, terminate the agreement.

7. Personal data breaches

If GentleTime discovers a personal data breach affecting the organisation's data, it notifies the owner of the organisation account without undue delay, and in any event within 48 hours of becoming aware of it. It provides the information the organisation needs to report the breach, where required, to the supervisory authority and to data subjects, and takes immediate measures to limit its consequences. Reporting to the authority and data subjects is up to the organisation.

8. Data subject rights and assistance

The organisation can handle many data subject requests itself in the app: viewing and correcting data, deleting readings, withdrawing consent and deleting clients. If GentleTime receives a request directly from a data subject, it forwards it to the organisation. Beyond that, GentleTime assists the organisation, as far as reasonable, with data subject requests, a data protection impact assessment (DPIA) and a prior consultation.

9. Audits

On request, GentleTime gives the organisation all information needed to demonstrate compliance with this agreement. The organisation may have an audit carried out by an independent expert bound by confidentiality at most once a year, and additionally after a data breach, with at least 30 days' notice and without disrupting the service. The organisation bears the cost of an audit, unless it shows that GentleTime materially fails to comply with this agreement. Requests: privacy@gentletime.app.

10. Ending

When the use of GentleTime ends, the organisation can first view and take over its data itself. GentleTime then deletes all personal data of the organisation within 30 days, or immediately if the organisation deletes itself in Settings, unless the law requires retention. Any backups are overwritten within 30 days after that. Obligations that by their nature continue (such as confidentiality) remain in force.

11. Liability and law

Liability is governed by the terms of service, except where the GDPR mandatorily provides otherwise. This agreement is governed by Dutch law; disputes are submitted to the District Court of Limburg (Rechtbank Limburg, location Maastricht).