Your time data, treated like it matters
A time record is only worth keeping if it's safe. Tidpunkt is built in Latvia and hosted in the EU, with encryption, least-privilege access, and honest practices around your data — not a wall of badges.
Encrypted in transit and at rest
Traffic is served over TLS 1.2+, and stored data is encrypted at rest with industry-standard AES-256. Passwords are hashed, never stored in the clear.
EU data residency
Your data is hosted in the European Union with reputable infrastructure providers, kept within the EU except where you explicitly ask otherwise.
Least-privilege access
Access to production is limited to the people who need it, protected by strong authentication, and logged. We work to the principle of least privilege by default.
Backups and recovery
We take regular, encrypted backups and test our ability to restore them, so an incident means an inconvenience — not a lost quarter of your records.
Monitoring and response
The service is continuously monitored for availability and anomalies, with alerting and a defined process for responding to incidents.
Responsible disclosure
Found something? We welcome reports from security researchers and will work with you in good faith. Email security@tidpunkt.com to get in touch.
Compliance & your rights
The commitments that sit alongside the technical ones.
GDPR
Tidpunkt is designed around the GDPR. We collect the minimum we need, tell you plainly what we do with it, and make it easy to access, export, or erase — see our Privacy Policy for the detail.
Data Processing Agreement
Business customers can request a DPA covering how we process personal data on your behalf, including our sub-processors and the safeguards used for any transfers outside the EU.
Your data, always exportable
No lock-in is part of our security stance too: you can export every entry, report, and invoice at any time, so your continuity never depends on ours.