HRDesk

GDPR

Privacy and Data Protection

This page describes how HRDesk approaches personal data, security and the rights of people whose data may be processed in the platform.

Who Processes Data

HRDesk provides software tools for employers and their authorized users. Depending on the specific customer and agreement, HRDesk may act as a controller or processor of personal data.

What Data Is Processed

The platform may process data about user accounts, roles, access rights, employees, schedules, absences, working time, locations, system activity and technical security data.

Why Data Is Processed

Data is used to provide the service, manage schedules and absences, control access, secure accounts, support operations, maintain audit records and meet contractual or legal obligations.

Legal Bases

Processing may be based on contract, legal obligation, legitimate interests for security and support, or consent where optional functions require it.

Retention

Data is retained for as long as necessary to provide the service, meet contractual and legal obligations, protect against disputes and maintain an audit trail.

Data Subject Rights

Individuals may request access, rectification, erasure, restriction, portability, objection to processing and withdrawal of consent where processing is based on consent.

Recipients and Providers

Data may be accessible to authorized users, infrastructure providers, email services, support providers and other subprocessors where required for platform operation.

Security

HRDesk uses access control, secure session cookies, two-factor authentication for administrators, password hashing and audit records for important actions.

For personal data requests, use the official contact of the service administrator or the company that provided your HRDesk access. This text is informational and should be aligned with the specific agreement, controller and subprocessors before public legal use.