Skip to main content
Security, compliance and hosting

Our commitments to hosting, data protection and data portability.

Tempolia describes the mechanisms actually implemented: data location, backups, account separation, personal data protection, permissions, exports and traceability.

Tempolia team working on security and operations
Verifiable commitments

What Tempolia implements to protect and return data.

These details can be included in an IT questionnaire, vendor assessment or contract review.

Hosting in France

Production environments are hosted in France.

Dedicated database per account

Every Tempolia account uses its own database, separating each organisation's data.

Off-site nightly backup

Data is backed up every night to another server in a different data centre.

Disk redundancy

Disks are mirrored so that an isolated hardware failure does not destroy data.

On-demand backup

The administrator can request an ad hoc backup before an important operation.

Data portability

Data remains the customer's property and can be retrieved through exports or APIs according to the subscribed scope.

Granular permissions and SSO

Access is defined by profile, menu, scope and data type. OAuth2 is available, and SAML is offered with Enterprise.

Traceability

Logins, sensitive actions, approvals, exports and maintenance operations are logged according to their nature.

Continuity and recovery

Back up, verify and restore through a controlled procedure.

The nightly backup is copied to another server. An ad hoc backup can also be triggered from the interface before a significant change.

Specific RPO, RTO or availability requirements can be discussed in detail with your Tempolia contact.

Daily backupCopy to another server with historical retention.
Ad hoc copyCan be triggered before an important operation.
Controlled restorationPermissions, reason, date and checks.
Access and confidentiality

Restrict each user to their scope.

Tempolia permissions combine menu access, read or edit level and data scope. They can differ by company, group, staff member, customer or engagement.

Sensitive values such as cost rates, selling prices or margin metrics can be hidden from selected profiles. Authorised managers retain control over configuration.

Custom profilesRead, create, edit and specific actions.
AuthenticationSecure access, OAuth2 and SAML SSO depending on the plan.Microsoft 365Gmail
LoggingLogins and sensitive operations retained for review.
Personal data protection

Tempolia acts as a processor under the GDPR.

When personal data is processed in Tempolia, including data relating to staff, time or invoicing; the customer remains the controller and Tempolia acts as a processor within the meaning of Regulation (EU) 2016/679.

These commitments are set out in detail in Article 13 of the Terms and Conditions.

GDPR banner with a padlock and the European Union stars

Documented instructions

Tempolia processes personal data only on the customer’s documented instructions, within the scope of the subscribed services.

Confidentiality

People authorised to process this data receive data protection awareness and are bound by confidentiality obligations.

Risk-appropriate security

Appropriate technical and organisational measures are implemented in accordance with Article 32 of the GDPR.

Data subject rights

Tempolia assists the customer in responding to requests for access, rectification, erasure, objection, restriction and portability.

Personal data breaches

Any personal data breach brought to Tempolia’s attention is reported to the customer as soon as possible, together with the relevant information available.

Subprocessors and contract end

Subprocessors are bound by the same data protection obligations. At the end of the contract, data is returned or deleted at the customer’s choice, subject to legal retention requirements.

Anti-money laundering

A customer record adaptable to your AML/CFT procedures.

Anti-money laundering and counter-terrorist financing obligations rely in particular on sufficient and up-to-date knowledge of the customer and, where applicable, its beneficial owners. Tempolia lets you organise this information according to your own internal procedures.

A fully adaptable customer record

The customer record can be adapted and freely reorganised. You choose the information displayed, its order and grouping to create a layout consistent with your business and control procedures.

Information supporting customer due diligence

Add the sections your organisation needs: customer identification, beneficial owners, nature of the business relationship, risk level, checks performed, review dates or any other information specific to your procedures.

Centralised customer knowledge

Relevant information is brought together in one record, making it easier to consult and update during periodic reviews.

Tempolia helps collect and organise information. Risk assessment, required due diligence and any reports to Tracfin remain the responsibility of the regulated professional.

View customer due diligence obligations on the Tracfin website ↗
Tax compliance

Traceability, integrity, retention and archiving.

French RepublicCompliant with Article 286 of the French Tax CodeIndividual statement issued for the customer and the version in use.

For features used to record payments, Tempolia meets the integrity, security, retention and archiving requirements set out in Article 286(I)(3 bis) of the French General Tax Code.

An individual publisher statement, issued for the customer and the version in use, is available in the customer area. It is one of the forms of evidence of compliance accepted by the French tax authorities.

At the same time, the product is working towards Category C NF525 certification.

Approved documentsIdentification, sequence, signature and integrity control.
DuplicatesTraceability of reissued documents and generated files.
JETLog of sensitive technical events and audit trail.
Tax archivesExtraction, sealing, retention and retrieval.
Data portability and integration

Retrieve data without depending on a single export.

Exports

Extract lists and reports

Views and reports can be exported according to the user's permissions and scope.

OpenAPI API

Access authorised objects

The documented API supports integration of customers, engagements, time, expenses, documents and other data according to the available scope.

Documents

Retrieve invoices and supporting documents

Associated documents can be included in the supported flows, particularly for accounting or archiving.

End of contract

Prepare data return

The format, schedule and expected data must be specified in the portability plan.

Frequently asked questions

Questions from IT teams, DPOs and auditors.

Where is the data hosted?

Production data is hosted in France, and every Tempolia account has its own database, separate from those of other organisations. A backup is created every night and copied to another server in a different data centre and city, with retained history available to support a controlled restoration.

Does the customer retain ownership of its data?

Yes. Data remains the customer’s property and can be returned through the available exports or API, according to the subscribed scope. The portability plan defines the required objects, documents, formats, timetable and checks in advance, so that data return does not depend on a single export.

What is Tempolia’s role under the GDPR?

The customer is the controller; Tempolia acts as processor for personal data handled in the software. Tempolia processes it on documented instructions, applies the security and confidentiality commitments set out in the contract, and assists the customer with data subject rights, personal data breaches, and return or deletion at the end of the contract.

Which users can use SSO?

OAuth2 is available as standard with every plan, for example to sign in an employee who is already authenticated with Google or Microsoft 365. SAML SSO is included in Enterprise; Tempolia profiles, scopes and permissions continue to determine what each user can view or change.

How does Tempolia restrict access to sensitive data?

Permissions combine menu access, the level of read or edit access and the data scope, by company, group, staff member, customer or engagement. Cost prices, selling prices and margin indicators can be hidden from selected profiles, while sensitive operations are logged according to their nature.

How is a backup restoration controlled?

Nightly backups are retained, and an on-demand copy can be created before an important operation. Restoration remains restricted to authorised profiles: its scope, date, operator, reason and required checks must be identified before the backup is loaded.

Ask the Tempolia team to review your requirements.

We answer your security, data portability and compliance questionnaire point by point.