Data Processing Addendum – Offdays
Version 1.0, effective from 7 October 2026 This Data Processing Addendum (DPA) under Article 28 GDPR is part of the Terms of Service. Nothing needs to be signed or sent. If the Czech and English versions differ, the Czech version prevails.1. Parties and subject matter
The processor is Ing. Jiří Psota, Company ID (IČO) 76072266, registered at Zborovská 1200/6, 150 00 Prague 5 – Smíchov, Czech Republic (the “processor”). The controller is the organization that uses Offdays under the Terms of Service (the “customer”).
This addendum governs the processing of personal data the customer enters into the service, under Article 28 of Regulation (EU) 2016/679 (GDPR). It is an integral part of the Terms of Service and the customer accepts it by accepting them; no signature is required. On data protection matters it takes precedence over the Terms of Service.
2. Scope
The subject matter, nature and purpose of the processing and the categories of data and data subjects are set out in Annex 1. Processing lasts for as long as the service is used.
3. Instructions
The processor processes personal data only on the customer's instructions. These are the Terms of Service, this addendum and the way the customer configures and uses the service. Otherwise only where EU or Czech law requires it. If the processor considers an instruction unlawful, it says so.
4. Confidentiality
Everyone with access to the personal data is bound by confidentiality.
5. Security
The processor protects the data with the measures under Article 32 GDPR described in Annex 2. It may change them as long as the level of protection does not decrease.
6. Sub-processors
The customer agrees to the sub-processors listed at www.offdays.cz/subprocessors. The processor publishes any addition or replacement of a sub-processor on that page in advance. The customer may object to a change; if the parties cannot resolve the objection, the customer may terminate the service. Sub-processors are bound by data protection obligations to the same extent.
7. Transfers outside the EEA
Personal data is stored in the EU (Google Cloud, region europe-west1, Belgium). It is transferred outside the EEA only to the extent stated in the sub-processor list and only with a safeguard under Chapter V GDPR.
8. Assistance
The customer handles data subject requests primarily on its own with the features of the service (editing and deactivating users, editing and cancelling absences, XLSX export). The processor reasonably helps with what the service cannot do on its own and with the obligations under Articles 32 to 36 GDPR. It informs the customer of a personal data breach without undue delay.
9. Termination
Until the service ends, the customer can export its data. After the service ends, the processor deletes the personal data unless the law requires it to be kept. Backups rotate it out in the normal course.
10. Information and audits
On request, the processor provides the information needed to demonstrate compliance with this addendum and allows audits by prior agreement and at the customer's cost. For sub-processors, their public certifications and reports replace an audit.
11. Final provisions
Liability is governed by the Terms of Service. This addendum is governed by Czech law. The processor publishes changes to this addendum on this page. If the Czech and English versions differ, the Czech version prevails.
Contact: hello@offdays.cz.
Annex 1 – Description of the processing
Purpose and nature
Recording vacation and other absences of the customer's employees and contractors, approving them, tracking entitlements and balances, writing approved absences into the customer's shared Google Calendar, and sending approval notifications by email. Processing includes storing, displaying, editing, making data available to the customer's users, writing calendar events, sending emails and deletion.
Data subjects
- The customer's employees and contractors who use the service or are recorded in it.
- Their managers (approvers) and the customer's administrators of the service.
Categories of personal data
- Identity and contact: name, work email, Google account profile photo, app language, country (for public holidays), type of engagement (employee or contractor).
- Organization: manager, administrator role, active or deactivated account, account creation date and last sign-in.
- Absences: dates including half days, number of days, absence type (vacation or sick day), approval status, request note, requested changes and cancellations.
- Entitlements: annual vacation entitlement, carry-over from last year, manually entered usage, annual sick day limit.
- Technical data: Google account identifier and Google access tokens (OAuth) that the service uses, with the user's consent, to read the customer's Google Workspace directory.
- Google Workspace directory data (if an administrator imports it): name, email and photo of colleagues who have not signed in yet.
Special categories of data
The service does not record health data: no diagnoses, no sick leave certified by a doctor (in Czech law “pracovní neschopnost”) and no doctor's visits. A sick day is a company benefit day off without a doctor's note. For a sick day only the dates and number of days are stored, without a reason. The request note is free text; the customer instructs its users not to put health or other sensitive data in it.
Who can see the data at the customer
- All of the customer's users see colleagues' approved absences in the team calendar: name, photo, dates, absence type (vacation or sick day) and note. They also see the list of colleagues with their email addresses.
- Managers also see requests awaiting approval, absence history and balances of their direct reports.
- Administrators see and manage data of all the customer's users and can download the annual absence overview as XLSX.
- The customer's shared Google Calendar (if an administrator sets one up): the service writes events with the name and number of days, and “Sick Day” for sick days. The note is not written to the calendar. Who can see the calendar is up to the customer in Google Workspace.
- Approval emails go to managers and requesters. They contain the name, absence type, dates and number of days, not the note.
Annex 2 – Technical and organizational measures
- EU hosting: the application (Google Cloud Run) and the database (Google Cloud SQL, PostgreSQL) run in region europe-west1 in Belgium. Data is encrypted in transit (HTTPS/TLS) and at rest (Google Cloud default encryption).
- Sign-in through the customer's Google Workspace: only Google Workspace work accounts can sign in; personal Gmail accounts are rejected. Offdays stores no passwords. Two-step verification and other sign-in rules follow the customer's Google Workspace settings.
- Customer separation: each customer has its own separate space based on its Google Workspace domain. Users only see data of their own organization.
- Role-based access: employees manage their own requests, managers approve and see details of their direct reports, administrators manage the whole organization (see Annex 1).
- Google Calendar: only the name, dates and number of days are written to the calendar, and “Sick Day” for sick days. Neither the note nor any other reason for the absence is written.
- Access keys for third-party services are kept in Google Secret Manager, not in the source code.
- Operator access: only the operator has access to the production environment and database, and accesses customer data only when needed for operations or support.
- Abuse protection: rate limits on sign-in and session refresh requests.
- Backups: the database is backed up automatically by Google Cloud SQL.
- Operational logs: technical records (e.g. errors, sent emails) are kept in Google Cloud Logging and deleted when its retention period ends.