Terms & Data Processing
Last updated: June 2026 · Version 1.0
Part 1 — General Terms & Conditions
1. Scope
These terms govern the provision of the iXTime software as Software-as-a-Service by innoX-IT GmbH (“Provider”) to businesses (“Customer”). Consumer transactions are excluded.
2. Service
The Provider makes iXTime available over the internet for time tracking, project and reporting management. The feature scope follows the current product description. The Provider targets high availability based on the Microsoft Azure infrastructure; no specific availability percentage is guaranteed. Maintenance windows are announced.
3. Trial & conclusion
Use starts with a free 21-day trial. After that, use requires a paid plan. The contract is concluded upon selecting a plan and accepting these terms.
4. Prices & payment
The prices stated at booking apply per workspace and size tier, net plus VAT. Billing is monthly in advance via Stripe.
5. Customer obligations
The Customer keeps credentials confidential, uses the software lawfully and ensures the necessary legal bases for processing employee data (e.g. informing data subjects, works agreements where applicable).
6. Availability & liability
The Provider is liable under statutory provisions; for slight negligence only for breach of essential obligations, limited to foreseeable damage typical of the contract. Liability for slight negligence is capped at the fees paid in the twelve months preceding the damaging event. Mandatory statutory liability — in particular under product liability law and Art. 82 GDPR — remains unaffected.
7. Term & termination
The contract runs indefinitely and may be terminated at the end of the respective billing period. Data is deleted or returned after termination per Part 2.
8. Final provisions
Austrian law applies, excluding the UN Convention on Contracts for the International Sale of Goods. Place of jurisdiction is Wels, where legally permissible.
Part 2 — Data Processing Agreement (DPA)
This data processing agreement becomes part of the agreement between Provider and Customer upon contract conclusion and sets out the Provider’s obligations under Art. 28 GDPR for processing personal data on the Customer’s behalf.
1. Subject
Where the Provider processes personal data on the Customer’s behalf within iXTime, this DPA under Art. 28 GDPR applies. The Customer is controller, the Provider is processor.
2. Nature, purpose & data subjects
The subject is processing of time, project and employee data for time tracking and reporting. Data subjects are notably the Customer’s employees and contacts. Categories: master data, contact data, working-time and activity data.
3. Instructions
The Provider processes data only on the Customer’s documented instructions unless required otherwise by law.
4. Confidentiality & security (TOMs)
The Provider binds personnel to confidentiality and maintains appropriate technical and organisational measures (encryption in transit via TLS and of stored data at rest, access control, tenant separation, backups, logging).
5. Sub-processors
The Customer consents to the following sub-processors. The Provider informs of intended changes in good time so the Customer can object:
| Sub-processor | Purpose | Region |
|---|---|---|
| Microsoft Azure | Hosting, database, authentication (Entra External ID) | EU — West Europe |
| Stripe | Payment processing | EU / USA (SCCs) |
| Microsoft Azure Communication Services | Transactional & invitation emails | EU — Germany |
| Cloudflare, Inc. | CDN/reverse proxy, DNS, bot protection (Turnstile), email forwarding (info@) | USA (DPF/SCCs) |
6. Assistance & data-subject rights
The Provider reasonably assists the Customer in fulfilling data-subject rights and in breach notifications and data protection impact assessments.
7. Deletion & return
After termination, data processed on behalf is deleted or returned at the Customer’s choice, unless a statutory retention obligation applies.
8. Evidence & audits
The Provider provides the information necessary to demonstrate compliance and allows for reasonable audits.