Data Processing Terms

Last updated: September 16, 2026

Overview

Daily TimeCards is a business-to-business production workflow service operated by ACE Films LLC. This page describes the general framework Daily TimeCards uses when processing customer production data to provide the Services.

These public Data Processing Terms are informational. They do not, by themselves, create a separately executed Data Processing Addendum or customer-specific data-processing agreement. Any such agreement must be separately reviewed and agreed in writing by authorized parties.

Roles and Data Relationship

Production companies and their authorized representatives control the Customer Production Data submitted, uploaded, configured, collected, or otherwise processed through their Daily TimeCards Projects.

ACE Films LLC, operating as Daily TimeCards, processes Customer Production Data as a service provider or processor to provide, secure, support, and maintain the Services and Customer-authorized integrations. ACE Films LLC separately controls platform operational information such as account, authentication, billing, support, security, audit, system, and communications records, as described in the Privacy Policy.

Processing Scope and Customer Production Data

Daily TimeCards may process Customer Production Data for authorized production workflows, including Project setup, crew and department administration, timecard collection and review, amendments, reporting, document handling, uploads, exports, notifications, post-shoot workflows, support, security, and Customer-authorized Google Workspace or external API connections.

Depending on how a Customer uses the Services, Customer Production Data may include Project settings, crew names and contact information, departments and positions, work dates, timecard times, meal-related information, notes, amendments, submissions, reports, uploaded production documents, document metadata, access information, and other production information the Customer chooses to process through Daily TimeCards.

Daily TimeCards processes Customer Production Data to provide the Services and related support. It does not use Customer Production Data for third-party advertising or unrelated marketing purposes.

Customer Instructions and Responsibilities

Daily TimeCards processes Customer Production Data according to the Customer's Project configuration, authorized workflows, enabled integrations, support requests, and other documented instructions consistent with the Services.

Customers and their Users are responsible for deciding what information is appropriate and necessary for their production workflow and for having the rights, permissions, consents, and other authority required to provide, access, upload, share, export, or transmit that information through Daily TimeCards.

Daily TimeCards is not designed to require passwords, authentication secrets, private keys, financial-account credentials, or full payment-card information as Customer Production Data, and Users should not upload those credential types into Project workflows.

Confidentiality, Security, and Access Controls

Daily TimeCards uses technical and organizational safeguards designed to protect Customer Production Data and limit access to authorized workflows. These safeguards may include authentication controls, role-based and Project-based permissions, server-side validation, controlled storage access, public-form protections, audit mechanisms, and administrative controls.

Access to Customer Production Data is limited according to Project roles, permissions, operational needs, and authorized support or maintenance functions. No electronic service can guarantee absolute security, and Daily TimeCards reviews its safeguards as the Services and risks evolve.

If Daily TimeCards confirms a security incident involving Customer Production Data, it will respond in accordance with applicable legal obligations and any separately agreed Customer-specific requirements.

Service Providers and Subprocessors

Daily TimeCards uses third-party providers to host, secure, authenticate, support, communicate, bill for, develop, deploy, and maintain the Services. Depending on the function involved, those providers may process limited Customer Production Data or platform operational data on behalf of Daily TimeCards.

Providers may include infrastructure and backend providers such as Supabase and Hostinger, authentication or integration providers such as Google and Apple where applicable, communications providers, payment-processing providers such as Stripe for applicable billing functions, and development or operational providers used to maintain the platform. Additional information is available in the Privacy Policy.

Customer-Directed Google and External API Connections

Customers or authorized project administrators may direct Daily TimeCards to create, synchronize, export, or transmit Project information to a Customer-controlled Google Workspace environment or another external application through an enabled API connection.

These transfers occur at the Customer's direction. Once information is delivered to a Customer-controlled or Customer-selected external service, the handling of that copy is governed by the Customer's relationship with that provider and the provider's own terms, privacy practices, and security controls. Deleting or changing information in Daily TimeCards does not automatically delete copies already created, synchronized, exported, downloaded, or transmitted elsewhere.

Retention, Deletion, and Post-Project Access

Daily TimeCards is a production workflow service and is not intended to be permanent archival storage. Customer access becomes limited after Full Wrap and may later end in accordance with Daily TimeCards retention and access practices or the applicable Customer arrangement. Customers are responsible for downloading or exporting records they need before access ends.

Production operational content, including timecards, uploaded documents, and similar Project records, may be retained for a limited post-project period and may later be deleted, de-identified, or otherwise removed when no longer needed. Core account, billing, administrative, audit, security, legal, and similar business records may be retained for longer periods where reasonably needed for operational or legal purposes.

Customer-Specific Agreements and Requests

Customers may contact Daily TimeCards regarding Project-specific privacy or data-processing questions, security reviews, vendor questionnaires, procurement requirements, or requests for a separately executed Data Processing Addendum, security addendum, or similar document.

A customer-specific data-processing agreement becomes binding only when separately agreed in writing by authorized parties. If an executed agreement conflicts with these public Data Processing Terms or the Terms of Use on a matter it specifically governs, the executed agreement controls that matter.

Related Policies and Contact

These Data Processing Terms should be read together with the Daily TimeCards Privacy Policy and Terms of Use.

For Project-specific data-processing, privacy, security-review, or procurement questions, use the Support page or contact support@dailytimecards.com.