Skip to main content
Effective Date: May 1, 2026  |  Last Updated: May 8, 2026

Data Processing Agreement

This Data Processing Agreement (“DPA”) supplements the Hourglass Terms and Conditions and governs the processing of Customer Data by Hourglass SaaS, operated by Spa City Digital LLC d/b/a Hourglass SaaS (“Hourglass,” “Processor”), on behalf of the Customer (“Customer,” “Controller”). This DPA is incorporated by reference into the Terms and Conditions and is binding upon Customer’s acceptance of the Terms.

1. Definitions

  • “Applicable Data Protection Laws” means all U.S. federal and state privacy and data protection laws applicable to the processing of Customer Data, including the California Consumer Privacy Act (CCPA), as amended.
  • “Customer Data” means any data, including personal information, that Customer or Customer’s authorized users submit to or process through the Service.
  • “Data Subject” means an identified or identifiable natural person whose personal information is contained in Customer Data.
  • “Personal Information” means information that identifies, relates to, describes, or could reasonably be linked to a particular individual or household, as defined under Applicable Data Protection Laws.
  • “Processing” means any operation performed on Customer Data, including collection, storage, use, disclosure, or deletion.
  • “Sub-processor” means any third party engaged by Hourglass to process Customer Data on Hourglass’s behalf.

Capitalized terms not defined here have the meanings given in the Terms and Conditions.

2. Scope and Roles

Customer is the controller of Customer Data. Hourglass is the processor and processes Customer Data only on Customer’s documented instructions, as set forth in this DPA, the Terms and Conditions, and the Service’s standard functionality.

This DPA applies to Hourglass’s processing of Customer Data in connection with the Service.

3. Customer Instructions

Customer instructs Hourglass to process Customer Data:

  • To provide, maintain, and improve the Service
  • To comply with Customer’s reasonable written instructions
  • To comply with Applicable Data Protection Laws and other legal obligations

If Hourglass believes an instruction violates Applicable Data Protection Laws, Hourglass will notify Customer and may suspend processing until the issue is resolved.

4. Confidentiality

Hourglass will ensure that personnel authorized to process Customer Data are bound by confidentiality obligations, whether by contract or statute, and have received appropriate training on data protection.

5. Security Measures

Hourglass implements and maintains appropriate technical and organizational measures designed to protect Customer Data against unauthorized or unlawful processing, accidental loss, destruction, or damage. These measures include those described in Schedule B (Security Measures).

Hourglass reviews and updates these measures periodically and will not materially decrease the overall security of the Service during the term.

6. Sub-processors

6.1 General Authorization

Customer authorizes Hourglass to engage Sub-processors to process Customer Data, subject to the requirements of this Section 6.

6.2 Current Sub-processors

A current list of Sub-processors is set forth in Schedule C and includes, at the date of this DPA, our hosting and infrastructure provider, payment processor, and email delivery provider. The full current list is available on request.

6.3 Notification of New Sub-processors

Hourglass will provide Customer with at least 30 days’ notice of any new Sub-processor before authorizing them to process Customer Data. Notice may be provided by email or through the Service.

6.4 Customer Objection

Customer may object to a new Sub-processor on reasonable data protection grounds within the notice period. Hourglass will work in good faith to address objections. If a resolution cannot be reached, Customer may terminate the affected Service with a pro-rata refund of prepaid fees for the unused portion of the term.

6.5 Sub-processor Obligations

Hourglass will impose data protection obligations on each Sub-processor that are no less protective than those in this DPA. Hourglass remains liable for the acts and omissions of its Sub-processors as if they were Hourglass’s own.

7. Data Subject Rights

To the extent Customer cannot fulfill a Data Subject’s rights request through the Service’s self-service tools, Hourglass will provide reasonable assistance to enable Customer to respond to:

  • Requests to access, correct, delete, or port Personal Information
  • Requests to restrict or object to processing
  • Other rights granted under Applicable Data Protection Laws

If Hourglass receives a request from a Data Subject directly, Hourglass will promptly forward the request to Customer and not respond to the Data Subject directly except as required by law or to confirm receipt.

8. Personal Data Breach Notification

Hourglass will notify Customer without undue delay, and in any event within 72 hours, after becoming aware of a Personal Data breach affecting Customer Data. The notification will include, to the extent known:

  • A description of the nature of the breach
  • The categories and approximate volume of Personal Information affected
  • The likely consequences
  • The measures taken or proposed to address the breach and mitigate harm
  • Contact information for follow-up

Hourglass will cooperate with Customer in investigating and remediating any breach. Customer is responsible for notifying affected individuals and regulators as required by Applicable Data Protection Laws.

9. Audits

Customer may, no more than once per year and on at least 30 days’ written notice, request information reasonably necessary to verify Hourglass’s compliance with this DPA. Hourglass will respond to reasonable audit requests by providing:

  • Summaries of independent security audits or certifications (if any)
  • Written responses to specific compliance questions
  • Documentation of Hourglass’s security and privacy practices

On-site audits are not permitted unless required by Applicable Data Protection Laws and conducted at Customer’s expense, during business hours, with reasonable notice, and subject to confidentiality obligations.

10. Return or Deletion of Customer Data

Upon termination of the Service or at Customer’s written request:

  • Hourglass will make Customer Data available for export for 30 days following termination
  • After the export period, Hourglass will delete Customer Data from active production systems within 30 days
  • Backup copies will be deleted in accordance with Hourglass’s standard backup retention schedule, but Hourglass will not access or use such backups except for legal compliance or disaster recovery
  • Hourglass may retain Customer Data as required by law, with continued application of this DPA’s protections to such retained data

11. International Transfers

Customer Data is processed and stored in the United States.

12. Liability

Each party’s liability under this DPA is subject to the limitations and exclusions of liability set forth in the Terms and Conditions.

13. Term and Termination

This DPA takes effect when Customer accepts the Terms and Conditions and remains in force for as long as Hourglass processes Customer Data on Customer’s behalf. Sections that by their nature should survive termination (including confidentiality, deletion, and liability) will survive.

14. Conflict

If there is a conflict between this DPA and the Terms and Conditions regarding the processing of Customer Data, this DPA controls.

15. Governing Law

This DPA is governed by the laws of the State of New York, consistent with the Terms and Conditions, except where Applicable Data Protection Laws require otherwise.


Schedule A — Details of Processing

Subject matter and duration of processing: As set forth in the Terms and Conditions, for the duration of Customer’s subscription and as required afterward to fulfill obligations under this DPA.

Nature and purpose of processing: Provision of the Hourglass operations platform, including time tracking, billing, reporting, client-portal access, and related features.

Categories of Data Subjects:

  • Customer’s employees, contractors, and authorized users
  • Customer’s clients (where Customer enters client information)
  • Customer’s clients’ representatives (where granted client-portal access)

Categories of Personal Information:

  • Identification data (name, email, role)
  • Business contact information
  • Time entries, project records, billing information, and related operational data submitted by Customer
  • Authentication and access logs

Special categories of data: None intended. Customer agrees not to submit special category personal information (e.g., health, biometric, government ID, or financial account numbers beyond what is required for invoicing) to the Service.

Schedule B — Security Measures

Hourglass implements security measures including:

  • Encryption in transit: TLS encryption for data transmitted to and from the Service.
  • Encryption at rest: managed database storage with provider-level encryption at rest.
  • Backups: automated backups via managed database provider with point-in-time recovery, as standard with the database service.
  • Access controls: role-based access within the Service, with administrative access restricted to authorized personnel.
  • Authentication: password-based authentication with industry-standard password storage and the option for users to enable additional authentication methods as supported by the Service.
  • Patching and updates: regular application of security updates to infrastructure and application dependencies.
  • Personnel: confidentiality obligations for personnel with access to Customer Data.
  • Vendor management: contractual data protection obligations on sub-processors handling Customer Data.

Schedule C — Sub-processors

Sub-processor Service Location
DigitalOcean, LLC Application and database hosting United States

This list will be kept current. Customer will receive notice of new Sub-processors as described in Section 6.

Spa City Digital LLC d/b/a Hourglass SaaS
63 Putnam St, Suite 202, Saratoga Springs, NY 12866
michael@hourglasssaas.com