TERMS OF SERVICE
Supplier: HORARA CONTROL S.L.U. (hereinafter, "Horara")
Address: C/ Isabel la Católica nº 57, 47400 Medina del Campo (Valladolid), Spain
CIF: B22542260
Contact: admin@horara.es
Entry into force / last update: 13/09/2025
These Terms of Service ("TOS") regulate access and use of the time control and day registration platform (the “Service”). By creating an account or using the Service, the Customer agrees to these TOS. If the contracting party is a consumer, mandatory consumer regulations will apply; in any case, the Service is aimed at B2B (companies and professionals).
1. Definitions
- Customer: the company or professional that contracts the Service.
- Administrator Users: persons authorized by the Customer to configure the Service and manage billing and licenses.
- Employees/Workers: people whose workday data is processed on behalf of the Client.
- License: unit of use per employee and month.
- Subscription: Monthly recurring contracting based on the number of licenses.
- Client Data: account data, billing, support and communication of the Client.
- Employee Data: data that the Client instructs us to process (e.g. basic identity, clock-ins, workday, specific geolocation).
2. Purpose and scope
Horara provides a software as a service (SaaS) day registration and digital time tracking. The Client is responsible for configuring the Service according to its internal needs and legal employment obligations.
3. Account creation and electronic contracting
3.1 Registration and acceptance. Registration requires acceptance of these TOS (clickwrap). We retain the accepted timestamp, IP and version.
3.2 Identification and correction of errors. Before payment, the contract data is shown and the Client can correct errors. After contracting, the Client can download/view the current TOS.
3.3 Archive. We keep a trace of the contract and applicable versions. The Client may request a copy of the current conditions.
4. Pricing, billing and payments (Stripe)
4.1 Model. License by employee/month. Prices may or may not include taxes; it will be indicated if they carry IVA.
4.2 Payment processing. Payments are made through Stripe (Checkout and/or Customer Portal). We do not store full card details. Stripe may apply anti-fraud measures and technical cookies on its domains.
4.3 Subscription and renewals. The subscription is monthly and it renews automatically as long as it is not cancelled. The license changes are applied to the active subscription. A number lower than the currently licensed employees cannot be set.
4.4 Prorations and taxes. The additions/removals during the period can prorate. If enabled, automatic tax will be applied according to the Client's configuration.
4.5 Invoices and portal. Invoices are available at Customer Portal of Stripe and/or in the Service area.
4.6 Defaults. In case of non-payment, return or chargeback, we may temporarily suspend access until it is regularized, without prejudice to the accrued billing.
4.7 Price changes. We may modify prices with 30 days notice. If the Client does not accept, they may cancel before the next renewal.
5. Use of the Service and obligations of the Client
5.1 Labor compliance. The Client is responsible for legal compliance of the working day record (information to employees, conservation, access, etc.).
5.2 Acceptable use. The following are prohibited: unlawful use; violation of third-party rights; introduce malware; bypass access controls; overload or test security without authorization; resell the Service without permission.
5.3 Credentials. The Client will safeguard their credentials and restrict access in accordance with the principle of least privileges.
6. Specific functions
6.1 Geolocation (optional). Geolocation is recorded only when clocking in and is configurable by the Client. We do not carry out continuous monitoring. The Client must inform its employees and assess proportionality and the retention period.
6.2 Biometrics (disabled by default). We do not use biometrics by default. If the Client requests its activation, they must justify legal basis and, where appropriate, carry out a DPIA. Horara may deny or impose enhanced conditions.
7. Data ownership and reversibility
7.1 Property. The Client remains the owner of their data.
7.2 Export. During the relationship and 30 days upon termination, Customer may export data in standard format. Afterwards, we will proceed to deletion or anonymization, except where legal retention obligations apply.
8. Security and continuity
We apply technical and organizational measures according to the risk (TLS, access control, event registration, backups). Availability, support and backup levels are detailed in the Annex II (SLA).
9. Intellectual property and licenses
The Service, its code and contents are the property of Horara or its licensors. We grant the Client a non-exclusive, non-transferable and limited license to internal use during the subscription, by the number of licenses contracted. Reverse engineering is prohibited except where legally permitted.
10. Third parties and subprocessors
The Service may integrate with third parties (e.g. Stripe). We are not responsible for external services. The generally authorized processing subprocessors and their purpose/location appear in /subencargados; we will notify changes with reasonable advance notice (see Annex I - DPA).
11. Guarantees, responsibility and force majeure
The Service is provided “as is”, with the support and levels of the SLA. To the maximum extent permitted by law, our total liability for direct damages arising from the Service during a 12 month period is limited to the amounts actually paid by the Client in that period. We will not be responsible for lost profits, loss of business, or indirect damages. Neither party is responsible for Force Majeure.
12. Changes to the Service or TOS
We may introduce improvements or changes that do not substantially reduce functionality. Any substantive changes to these TOS will be notified with 30 days in advance. If the Client does not accept, they may cancel before the next renewal.
13. Termination
Either party may terminate for material breach not corrected within 30 days from notification. The Client may cancel at any time with effect at the end of the current period. Termination does not release accrued payment obligations.
14. Applicable law and jurisdiction
These TOS are governed by Spanish law. For B2B, the parties submit to the courts and tribunals of Medina del Campo (Valladolid). If the contracting party is a consumer, its imperative jurisdiction will prevail.
15. Contact
For any contractual or support issue: admin@horara.es.
ANNEX I – DATA PROCESSOR AGREEMENT (DPA) (Art. 28 RGPD)
1. Purpose and duration
Horara will act as processor for processing regarding the Employee Data that the Client (as controller) entrusts to it when using the workday recording service. This Annex will remain in force for the same duration as the contractual relationship.
2. Nature and purpose
Provision of the clocking and registration service: registration of employees, clocking in, management of shifts, (optional) specific geolocation when clocking in, generation of reports and associated evidence.
3. Types of data and categories of data subjects
- Data subjects: employees and, where applicable, external personnel that the Client manages in the Service.
- Data: basic identifiers (name, internal email/ID), day data (dates/times for entry/exit/breaks), technical metadata (IP, user agent, device), specific geolocation when clocking in if activated, and associated evidence (e.g. notes/observations). No special categories are covered unless configured and justified by the Customer in accordance with the law (e.g. biometrics, disabled by default).
4. Documented instructions
Horara will process the data only following the documented instructions of the Client and for the purposes described. If any instruction violates the regulations, Horara will notify you when it is reasonable to know.
5. Confidentiality
Horara personnel are subject to duty of confidentiality and commitment to secrecy.
6. Security (art. 32 RGPD)
Horara will apply appropriate technical and organizational measures based on the risk, including: encrypted transmission (TLS), access control, event logging, environment segmentation, backup and periodic testing. The operational details can be consulted in the technical documentation of the Service.
7. Subprocessors
The Client grants general authorization for sub-processors, published and updated in /subencargados (supplier/purpose/location). Horara will notify with reasonable notice any changes, allowing the Client to object for well-founded reasons. If the objection cannot be resolved, the Client may resolve the affected processing without penalty.
8. Assistance to the controller
Horara will assist the Client, as far as possible, to respond to requests for rights (access, rectification, deletion, opposition, limitation, portability) related to Employee Data, and to comply with obligations regarding security, breach notification, impact evaluations and prior consultations.
9. Breach Notification
Horara will notify the Client without undue delay any security breach affecting Employee Data of which it becomes aware, providing available information to facilitate, where appropriate, notification to authorities/affected parties.
10. International transfers
If any operation involves transfers outside the EEA, Horara will guarantee an adequate level of protection under the RGPD (e.g. Standard Contractual Clauses and complementary measures), informing the Client of the applicable mechanism.
11. Deletion or return
Upon termination of the Service, and at the Customer's option, Horara will return or will delete Employee Data and its copies, unless retention is required by law. For 30 days after termination, the Client may request export.
12. Records and audits
Horara will keep records of the processing activities carried out as processor and will provide reasonable information to demonstrate compliance. With prior notice and with confidentiality limits, the Client may perform reasonable audits (once a year unless justified cause), without interfering with normal operation.
13. Responsibility
Each party will be responsible under the terms of the RGPD for its own obligations as controller or processor.
ANNEX II – SERVICE LEVEL AGREEMENT (SLA)
1. Scope
This SLA defines levels of availability, support and backups of the Service. It does not include credits for unavailability.
2. Availability
Objective of monthly availability ≥ 99.5%. The calculation excludes planned maintenance windows and causes of exclusion (point 6).
3. Planned maintenance
We will announce scheduled interventions 48 hours in advance, preferably in the 00:00–06:00 CET.
4. Support
- Channel: email admin@horara.es.
- Schedule: working days 09:00–19:00 CET.
- Initial response SLA:
- Incident Critical (total drop): ≤ 2 natural hours.
- Incident High (degraded key function): ≤ 4 working hours.
- Incident Medium/Low: ≤ 8 working hours.
5. Backups and continuity
Daily backups with retention 7 days. Goals: RPO ≤ 24h and RTO ≤ 12h.
6. Measurement and exclusions
Unavailability is measured by continuous 5xx errors ≥ 5 minutes from server monitoring. Excluded: (i) force majeure; (ii) incidents on the Client's/ISP/DNS network; (iii) external/third-party services (e.g. Stripe, email providers/SMS); (iv) unsupported browsers or outdated devices; (v) DDoS attacks or other external malicious acts; (vi) planned maintenance; (vii) Customer misconfiguration.
7. SLA changes
We may adjust this SLA to improve the quality of the service. Substantive changes will be notified with 30 days in advance.
ACCEPTANCE
By registering and using the Service, the Client declares that they have read and accepted these TOS, including the Annex I (DPA) and the Annex II (SLA).