Data Processing Agreement

Last Revised: July 23, 2026

Overview

Timeglass, Inc. ("Timeglass") has entered into Data Processing Agreements (DPAs) with all third-party service providers and data processors that handle personal data on behalf of our customers. These agreements comply with GDPR Article 28 and establish the roles, responsibilities, and obligations of both controllers and processors.

Our Data Processors

Timeglass uses the following data processors to provide our services:

  • Customer.io: Email marketing and customer engagement platform
  • Google Analytics: Website analytics and usage tracking
  • Google Ads: Website ad conversion measurement and campaign attribution
  • Microsoft Clarity: Session recording and user behavior analysis
  • PostHog: Product analytics and session recording
  • Meta Pixel: Website ad conversion measurement and campaign attribution
  • LinkedIn Insight Tag: Website ad conversion measurement and campaign attribution
  • Reddit Pixel: Website ad conversion measurement and campaign attribution
  • beehiiv Ad Network Pixel: Newsletter ad conversion measurement and campaign attribution
  • HubSpot: Internal CRM for sales and customer management
  • Clerk: Authentication and user identity management
  • Supabase: Database and backend infrastructure
  • Morph (AutoInfra, Inc.): AI inference hosting via OpenRouter using an OpenRouter-verified zero-data-retention endpoint
  • RB2B: B2B visitor identification and lead generation
  • Apollo: Sales intelligence and prospecting data

DPA Execution

For processors that provide formal Data Processing Agreements, Timeglass has executed signed DPAs or incorporated their standard DPAs into our Data Processing Agreements. These agreements include:

  • Subject matter and duration of processing
  • Nature and purpose of processing
  • Types of personal data and categories of data subjects
  • Data subject rights and controller obligations
  • Sub-processor authorization and management
  • International data transfer mechanisms (Standard Contractual Clauses where applicable)
  • Security and confidentiality obligations
  • Audit and compliance procedures

Processor Responsibilities

All of our data processors are obligated to:

  • Process personal data only on documented instructions from Timeglass
  • Ensure that persons authorized to process personal data have committed to confidentiality or are under an appropriate legal obligation
  • Implement and maintain appropriate technical and organizational security measures
  • Obtain prior written authorization before engaging sub-processors
  • Assist Timeglass in responding to data subject requests and exercising their rights under GDPR
  • Assist Timeglass in ensuring compliance with GDPR obligations
  • Delete or return all personal data after termination of services
  • Make available all information necessary to demonstrate compliance and allow for audits

Data Subject Rights

Under GDPR and other applicable privacy laws, you have the right to:

  • Request access to your personal data
  • Request correction of inaccurate data
  • Request erasure of your data (right to be forgotten)
  • Request restriction of processing
  • Receive your data in a portable format
  • Object to processing
  • Lodge a complaint with a supervisory authority

For questions about Data Processing Agreements or to exercise your rights, please contact us at privacy@timeglass.ai.

Contact & Support

If you have questions about our data processing practices or our processors, please reach out to our Privacy Team at privacy@timeglass.ai.