Hosting in France
Production environments are hosted in France.
Tempolia describes the mechanisms actually implemented: data location, backups, account separation, personal data protection, permissions, exports and traceability.

These details can be included in an IT questionnaire, vendor assessment or contract review.
Production environments are hosted in France.
Every Tempolia account uses its own database, separating each organisation's data.
Data is backed up every night to another server in a different data centre.
Disks are mirrored so that an isolated hardware failure does not destroy data.
The administrator can request an ad hoc backup before an important operation.
Data remains the customer's property and can be retrieved through exports or APIs according to the subscribed scope.
Access is defined by profile, menu, scope and data type. OAuth2 is available, and SAML is offered with Enterprise.
Logins, sensitive actions, approvals, exports and maintenance operations are logged according to their nature.
The nightly backup is copied to another server. An ad hoc backup can also be triggered from the interface before a significant change.
Specific RPO, RTO or availability requirements can be discussed in detail with your Tempolia contact.
Tempolia permissions combine menu access, read or edit level and data scope. They can differ by company, group, staff member, customer or engagement.
Sensitive values such as cost rates, selling prices or margin metrics can be hidden from selected profiles. Authorised managers retain control over configuration.

When personal data is processed in Tempolia, including data relating to staff, time or invoicing; the customer remains the controller and Tempolia acts as a processor within the meaning of Regulation (EU) 2016/679.
These commitments are set out in detail in Article 13 of the Terms and Conditions.

Tempolia processes personal data only on the customer’s documented instructions, within the scope of the subscribed services.
People authorised to process this data receive data protection awareness and are bound by confidentiality obligations.
Appropriate technical and organisational measures are implemented in accordance with Article 32 of the GDPR.
Tempolia assists the customer in responding to requests for access, rectification, erasure, objection, restriction and portability.
Any personal data breach brought to Tempolia’s attention is reported to the customer as soon as possible, together with the relevant information available.
Subprocessors are bound by the same data protection obligations. At the end of the contract, data is returned or deleted at the customer’s choice, subject to legal retention requirements.
Anti-money laundering and counter-terrorist financing obligations rely in particular on sufficient and up-to-date knowledge of the customer and, where applicable, its beneficial owners. Tempolia lets you organise this information according to your own internal procedures.
The customer record can be adapted and freely reorganised. You choose the information displayed, its order and grouping to create a layout consistent with your business and control procedures.
Add the sections your organisation needs: customer identification, beneficial owners, nature of the business relationship, risk level, checks performed, review dates or any other information specific to your procedures.
Relevant information is brought together in one record, making it easier to consult and update during periodic reviews.
Tempolia helps collect and organise information. Risk assessment, required due diligence and any reports to Tracfin remain the responsibility of the regulated professional.

Compliant with Article 286 of the French Tax CodeIndividual statement issued for the customer and the version in use.For features used to record payments, Tempolia meets the integrity, security, retention and archiving requirements set out in Article 286(I)(3 bis) of the French General Tax Code.
An individual publisher statement, issued for the customer and the version in use, is available in the customer area. It is one of the forms of evidence of compliance accepted by the French tax authorities.
At the same time, the product is working towards Category C NF525 certification.
Views and reports can be exported according to the user's permissions and scope.
The documented API supports integration of customers, engagements, time, expenses, documents and other data according to the available scope.
Associated documents can be included in the supported flows, particularly for accounting or archiving.
The format, schedule and expected data must be specified in the portability plan.
Production data is hosted in France, and every Tempolia account has its own database, separate from those of other organisations. A backup is created every night and copied to another server in a different data centre and city, with retained history available to support a controlled restoration.
Yes. Data remains the customer’s property and can be returned through the available exports or API, according to the subscribed scope. The portability plan defines the required objects, documents, formats, timetable and checks in advance, so that data return does not depend on a single export.
The customer is the controller; Tempolia acts as processor for personal data handled in the software. Tempolia processes it on documented instructions, applies the security and confidentiality commitments set out in the contract, and assists the customer with data subject rights, personal data breaches, and return or deletion at the end of the contract.
OAuth2 is available as standard with every plan, for example to sign in an employee who is already authenticated with Google or Microsoft 365. SAML SSO is included in Enterprise; Tempolia profiles, scopes and permissions continue to determine what each user can view or change.
Permissions combine menu access, the level of read or edit access and the data scope, by company, group, staff member, customer or engagement. Cost prices, selling prices and margin indicators can be hidden from selected profiles, while sensitive operations are logged according to their nature.
Nightly backups are retained, and an on-demand copy can be created before an important operation. Restoration remains restricted to authorised profiles: its scope, date, operator, reason and required checks must be identified before the backup is loaded.
We answer your security, data portability and compliance questionnaire point by point.