Privacy Policy
Last updated: 7 September 2026
This Privacy Policy governs the processing of personal data collected through the StaffControl platform (hereinafter, the “Platform”), accessible at www.staffcontrol.app, both in its web version and in its progressive web app (PWA).
This policy has been drafted in accordance with Regulation (EU) 2016/679 (General Data Protection Regulation, GDPR), Ley Orgánica 3/2018, of 5 December, on the Protection of Personal Data and guarantee of digital rights (LOPDGDD), and Ley 34/2002, of 11 July, on Information Society Services and Electronic Commerce (LSSI-CE).
1. Identity of the Data Controller
- Owner: StaffControl (hereinafter, the “Controller”)
- Tax ID (NIF/CIF): [Pendiente de cumplimentar]
- Registered office: [Pendiente de cumplimentar], Spain
- Email: hola@staffcontrol.app
- Website: www.staffcontrol.app
2. Personal Data We Collect
StaffControl is a team and shift management platform for the hospitality and franchise sector. Depending on your role (administrator, manager or employee), we may process the following categories of personal data:
2.1. Identification and contact data
- First name and surnames (first and second surname)
- Nickname or short name (optional)
- Identification number (DNI/NIE/Passport)
- Email address
- Phone number (optional)
- Profile photo or avatar (optional, uploaded by the user themselves)
2.2. Employment and contractual data
- Contract type (permanent, temporary, work placement, intern, permanent-seasonal, administrator)
- Working-time type (full-time or part-time)
- Weekly contract hours
- Contract start and end dates
- Assigned roles and job positions
- Assigned workplace (store) and contracting legal entity
- Access level within the platform
- Working days of the contract
- Reason for termination or deactivation (in the event of separation)
2.3. Additional private employee data
In order to complete the employee's onboarding and their communication to the business's labor advisory firm, the Platform may process the following data, which is normally entered by the employee themselves during their onboarding process or, failing that, by an administrator:
- Social Security affiliation number (NAF)
- Date of birth
- Full postal address (street, postal code, municipality and province)
- Bank account IBAN for payroll payment
This data has restricted access: only the employee themselves and the administrators of their organization can view it. In the interface it is masked by default, and the affiliation number and date of birth, once recorded, can only be corrected by an administrator.
2.4. Working time and time-clock data
- Clock-in and clock-out records (digital time clock)
- Start and end records of breaks/rest periods
- Planned shifts (weekly schedules)
- Hours worked, planned and differences
- Requests and records of vacations, absences and leaves
- Availability and unavailability by time slot
- Shift swaps between employees
2.5. Geolocation data
When the business administrator enables geolocation verification for clocking, the Platform will request permission from the employee's browser to access their GPS coordinates at the exact moment of clocking in. This data is used exclusively to verify that the employee is within the radius configured for their workplace. The coordinates are recorded alongside the clock entry and are not used for continuous or real-time tracking.
2.6. Financial and billing data
- Employee's hourly labor cost (visible only to administrators)
- Tip amounts allocated to each employee in the pool distribution, when the business uses this feature
- Client's subscription billing data
- Invoice history and subscription status
Note: StaffControl does not store payment card data. When subscription collection is carried out through Stripe, Inc., a payment processor certified to the PCI-DSS Level 1 standard, it is Stripe that processes the payment method. The employee's IBAN indicated in section 2.3 is indeed stored on the Platform, with restricted access, for its communication to the labor advisory firm for the purpose of payroll payment.
2.7. Employee documents and contract signing
- Employment contracts
- Monthly payslips
- Copies of DNI/NIE
- Certificates and onboarding documentation
- Other labor documents uploaded by the administrator
When the business uses the electronic contract signing feature, the following data is additionally processed as evidence of the signing process: the handwritten signature traced by the employee on screen (which is embedded in the PDF document), the date and time of the signature, the IP address and user agent (browser) from which it was signed, and the cryptographic hashes of the original document and the signed document. This evidence is kept alongside the contract for the sole purpose of proving the integrity of the document and the authorship of the signature.
2.8. Job candidate data
When the business publishes job offers through the Platform, the data that the candidate voluntarily provides in the public application form is processed:
- First name, surnames, email and phone
- Attached résumé and cover letter or introductory comments
- Answers to the screening questions defined by the business
- Descriptive summary of the résumé generated by artificial intelligence to ease its reading (see section 3), without any scoring or ranking
- Selection process stage, interview notes and application status
2.9. Third-party data entered by the client
The business using the Platform may enter third-party contact data necessary for its operations. With regard to this data, the business acts as data controller and guarantees that it is legitimately entitled to its use:
- Business end customers: contact name and phone associated with reservations and orders
- Labor advisory firms: contact person's name, company, email and phone
- Maintenance technicians and providers: name, company, email and phone, for incident notifications
2.10. Communications data
- Internal notifications (announcements, assigned tasks)
- Browser push notification subscriptions
- Contact form messages (name, email, message)
2.11. Technical and browsing data
- IP address
- Browser type and operating system
- Session and authentication cookies (see section 9)
- Usage log of the artificial intelligence features: feature used, model, token volume and estimated cost — without storing the content of the requests or the responses
3. Purposes of the Processing
| Purpose | Legal basis (GDPR art.) |
|---|---|
| Management of the employment relationship: shifts, time clock, vacations, absences, tasks, onboarding and documents | Art. 6(1)(b) — Performance of a contract |
| Compliance with the mandatory working-time record (art. 34.9 of the Estatuto de los Trabajadores) | Art. 6(1)(c) — Legal obligation |
| Geolocation verification of the clock entry | Art. 6(1)(f) — Legitimate interest of the employer, subject to prior notice to the employee |
| Communication of the employee's onboarding (identification, affiliation, banking and contractual data) to the labor advisory firm designated by the business, for the formalization of the contract and payroll management, subject to the approval of an authorized manager | Art. 6(1)(b) — Performance of the employment contract and art. 6(1)(c) — labor and Social Security obligations |
| Electronic signing of employment contracts and retention of the signature evidence (traced signature, IP, user agent, timestamps and cryptographic hashes of the document) | Art. 6(1)(b) — Performance of a contract and art. 6(1)(f) — legitimate interest in proving the integrity and authorship of the signature |
| Management of the user account and authentication | Art. 6(1)(b) — Performance of a contract |
| Management of subscription billing and collection | Art. 6(1)(b) — Performance of a contract |
| Sending of operational notifications (shifts, tasks, incidents) | Art. 6(1)(b) — Performance of a contract |
| Notification of maintenance incidents to the technicians designated by the business, subject to a manager's approval | Art. 6(1)(b) — Performance of a contract |
| Analysis of the business's labor profitability and distribution of tips among the team | Art. 6(1)(f) — Legitimate interest of the controller / performance of the employment contract |
| Automated extraction of data from labor documents (payslips) using artificial intelligence systems, with human review and confirmation prior to recording | Art. 6(1)(b) — Performance of a contract |
| Artificial intelligence assistance features described in section 7 (administrator query assistant, text drafts, suggested incident classification, product matching, report summaries), always assistive in nature and with human review | Art. 6(1)(b) — Performance of a contract and art. 6(1)(f) — legitimate interest |
| Management of personnel selection processes (applications received through the job pages), including the generation by artificial intelligence of a descriptive summary of the résumé to ease its reading — without any scoring, ranking or automated decision | Art. 6(1)(a) — Candidate's consent and art. 6(1)(b) — pre-contractual measures |
| Management of reservations and orders from the business's end customers | Art. 6(1)(b) — Performance of a contract (on behalf of the controlling business) |
| Handling of contact and support requests | Art. 6(1)(b) — Pre-contractual or contractual measures |
| Management of the business's production, orders and purchasing | Art. 6(1)(b) — Performance of a contract |
| Logging of the consumption of the artificial intelligence features (usage metrics, without content) for cost control and abuse prevention | Art. 6(1)(f) — Legitimate interest of the controller |
| Retention of data after the end of the employment relationship for compliance with legal and tax obligations | Art. 6(1)(c) — Legal obligation |
4. Data Recipients
Personal data may be communicated to the following data processors, with whom the corresponding data processing agreements (DPAs) have been signed in accordance with article 28 of the GDPR:
| Processor | Function | Location | Safeguards |
|---|---|---|---|
| Supabase, Inc. | Database hosting, authentication and file storage | EU region (eu-central-1, Germany) / United States (HQ) | DPA with Standard Contractual Clauses (SCCs) and EU-US Data Privacy Framework |
| Stripe, Inc. | Payment processing and subscription billing | United States / EU | DPA, PCI-DSS certification, EU-US Data Privacy Framework and SCCs |
| Resend, Inc. | Sending of transactional emails (invitations, notifications, onboarding communications to the labor advisory firm and technician notifications) | United States | DPA with Standard Contractual Clauses (SCCs) |
| Anthropic, PBC | Natural language processing (AI) for the features described in section 7: payslip and document expiry data extraction, résumé summaries, administrator and staff query assistants, text drafts and messages to candidates, incident classification and fault descriptions from photos, product matching, report summaries, the weekly summary and bookings from a message | United States | DPA with Standard Contractual Clauses (SCCs); the data sent is not used to train models; operational logs deleted within a maximum of 7 days |
In addition, on the express instruction of the business using the Platform, certain data may be communicated to recipients designated by the business itself:
- Labor advisory firms: on the occasion of a new employee's onboarding, the business may order the sending by email to its labor advisory firm of the data necessary to formalize the contract and manage payroll (identification, affiliation number, date of birth, address, IBAN, contractual conditions and workplace). Sending always requires the prior approval of an authorized manager of the business.
- Maintenance technicians: notification of incidents with the incident and workplace data, subject to a manager's approval. When the notification is made via WhatsApp, the Platform merely opens the user's own WhatsApp application with the message prepared; StaffControl does not send data to WhatsApp, nor does WhatsApp act as a data processor.
No other transfers of data to third parties will be made except for legal obligation. The listed data processors only access the data strictly necessary for the provision of their services and do not use it for their own purposes. StaffControl's authorized personnel only access client data when necessary for technical support, with such access being subject to audit.
5. International Data Transfers
Some of the providers indicated in the previous section are based in the United States. These international transfers are covered by:
- The EU-US Data Privacy Framework, in accordance with the European Commission's Adequacy Decision of 10 July 2023.
- Standard Contractual Clauses (SCCs) approved by the European Commission, incorporated into the data processing agreements (DPAs) with each provider.
The project's main database is hosted in AWS's eu-central-1 region (Frankfurt, Germany), within the European Economic Area.
6. Data Retention Periods
| Data category | Retention period |
|---|---|
| Working-time records (clock entries) | 4 years (art. 34.9 ET and Labor Inspectorate obligations) |
| Contractual and employment data | Duration of the employment relationship + 4 years for the limitation period of labor claims |
| Documents (payslips, contracts) | Duration of the employment relationship + retention period configured by the administrator |
| Electronically signed contracts and their signature evidence | Duration of the employment relationship + limitation periods of legal claims |
| Billing data | 5 years (fiscal and tax obligations) |
| Geolocation data | Same period as the working-time records (4 years) |
| Job applications | Duration of the selection process + retention period configured by the business, after which the data is automatically purged |
| Reservations and orders from end customers | As long as necessary for the business's operations and, in any case, while the business's account remains active |
| Usage log of the AI features (metrics, without content) | While the business's account remains active |
| Contact form data | 12 months from the query or until it is resolved |
| Read notifications | 30 days after being read (automatic purge) |
| User account after deactivation | Configured retention period (retention_expires_at), after which it is anonymized |
7. Artificial Intelligence Features and Data Subject Rights
The Platform incorporates assistance features based on third-party artificial intelligence models (currently, Anthropic, PBC). All of them are assistive in nature: they propose a result that a person reviews, edits and confirms, and they can be enabled or disabled by module for each business. They are the following:
- Payslip data extraction: the document is sent to the AI provider to extract the employer cost and other amounts, which the administrator reviews before recording.
- Descriptive résumé summary: in selection processes, to ease reading of the CV; without scoring, ranking or automatic rejection of candidates.
- Administrator query assistant: allows the administrator to ask in natural language about their own business's data (shifts, clock entries, costs, sales, absences, incidents, tasks or reservations, depending on the active modules). The queried data is sent one-time to the AI provider to produce the answer. The assistant is read-only and cannot modify information.
- Actions proposed by the assistant: at the administrator's request, the assistant can propose logging an absence, an incident, a task or a shift, and moving a shift. The proposal is shown on screen with all its details and has no effect until a person expressly confirms it; it can be edited or discarded.
- Assistant for staff: if the employer enables it, each person can ask in plain language about their own data (their shifts, their time off, their overtime, their tasks and the list of their documents). It is technically limited to the data of the person asking: it cannot be used to look up a colleague's. For documents, only the name and dates are read, never their content.
- Plain-language requests: employees can request time off or report an incident describing it in their own words. The request is shown filled in for confirmation and follows the usual approval route: an absence remains pending approval by their manager.
- Suggested incident classification: proposes a category and priority based on the description; the user can change them.
- Fault descriptions from a photo: turns a photo of a fault into written text, editable before it is logged. It is expressly instructed not to describe any people who may appear in the image.
- Text drafts: drafting of the technician notification for an incident and of the job offer description; always editable before sending or publishing.
- Draft messages to candidates: writes the interview invitation, the request for details or the rejection notice. The model is given only the first name, the role and the instructions of the person writing; never the CV or its summary. It does not rate the candidate: the decision is prior and human.
- Product matching: suggests the correspondence between POS product names and the internal catalog during the import of sales; the user confirms each match. It does not process personal data.
- Bookings from a message: the text a customer of the business sends with an order (a WhatsApp, an email) is passed to the provider to transcribe it into a booking with name, phone, date and products, which the user reviews before saving. It is the only case where contact details of a customer of the business are sent; they are transmitted only for that one-off transcription and are not kept until the person confirms the booking.
- Production queries: the administrator's assistant can look up quantities produced and waste per product. No personal data is processed.
- Executive profitability summary: drafts a summary of the period based exclusively on aggregate figures, without employee names or data.
- Weekly summary: writes the weekly alert that managers receive. The facts it summarises (how many absences are pending, how much overtime, and so on) are calculated by the Platform without AI; only aggregate counts are sent to the provider, with no names or identifiers.
- Document expiry: when a document is uploaded, it suggests its type and expiry date to fill in the form, which the user reviews. Expiry reminders are sent regardless of this feature.
For each use, only metrics are recorded (feature, model, token volume and estimated cost), never the content of the requests or the responses. The data sent to the AI provider is not used to train models.
In accordance with the GDPR and the LOPDGDD, any person whose data is processed by StaffControl may exercise the following rights:
- Right of access (art. 15 GDPR): to obtain confirmation of whether their data is being processed and to access it.
- Right to rectification (art. 16 GDPR): to request the correction of inaccurate or incomplete data.
- Right to erasure (art. 17 GDPR): to request the deletion of their data when it is no longer necessary for the purposes for which it was collected, without prejudice to the duty of retention by legal obligation.
- Right to restriction of processing (art. 18 GDPR): to request the suspension of processing in certain circumstances.
- Right to portability (art. 20 GDPR): to receive the data in a structured, commonly used and machine-readable format.
- Right to object (art. 21 GDPR): to object to processing based on legitimate interest.
- Right not to be subject to automated decisions (art. 22 GDPR): the Platform does not make decisions based solely on automated processing that produces legal effects, nor does it carry out profiling. In the AI features described in this section, the result is always a proposal reviewed by a person, who is the one who makes any decision; in no case does the AI score, rank or reject candidates or employees.
To exercise any of these rights, you can contact hola@staffcontrol.app, indicating in the subject line “Exercise of GDPR rights” and enclosing a copy of your identity document. We will respond within a maximum period of one month from receipt of the request.
Likewise, if you consider that the processing of your data does not comply with the regulations, you have the right to file a complaint with the Spanish Data Protection Agency (AEPD), www.aepd.es, C/ Jorge Juan 6, 28001 Madrid.
8. Security Measures
StaffControl applies appropriate technical and organizational measures to guarantee a level of security appropriate to the risk, in accordance with article 32 of the GDPR. Among others:
- Encryption of data in transit (HTTPS/TLS) and at rest
- Secure authentication using JWT tokens and HttpOnly cookies
- Role-based access control policies (Row-Level Security in the database)
- Per-client isolation (tenant isolation): each organization only accesses its own data
- Restricted access to the employee's private data (section 2.3), with masking in the interface and a modification lock on the affiliation number and date of birth once recorded, except by an administrator
- Integrity verification of signed contracts using cryptographic hashes
- Prior approval by an authorized manager for the sending of data to labor advisory firms and technicians
- Automated database backups
- Monitoring and auditing of administrative access
- Payment processing delegated to PCI-DSS certified providers
9. Cookie Policy
StaffControl uses exclusively technical and strictly necessary cookies for the correct functioning of the Platform. These cookies do not require the user's prior consent under current regulations.
| Cookie | Purpose | Duration | Type |
|---|---|---|---|
| sb-*-auth-token | Authentication and maintenance of the user's session (Supabase Auth) | Session / 7 days | Technical, strictly necessary |
Additionally, the Platform uses the browser's local storage (localStorage and sessionStorage) for exclusively technical purposes, such as remembering interface preferences. The Platform does not use analytics, advertising or third-party tracking cookies. Tools such as Google Analytics, Facebook Pixel or similar services are not used. Therefore, a cookie consent banner is not necessary.
10. Processing of Minors' Data
StaffControl is intended exclusively for the labor management of workers. Data of minors under 16 years of age is not knowingly collected. If the processing of a minor's data were detected, it would be deleted immediately.
11. Client Responsibility (User Company)
The company or organization that contracts StaffControl to manage its employees acts as Data Controller with regard to the data of its employees, candidates, end customers and contacts, with StaffControl being the Data Processor in accordance with article 28 of the GDPR.
The client company is responsible for:
- Informing its employees about the use of StaffControl and the processing of their data, including the communication of their onboarding data to the labor advisory firm
- Obtaining the necessary consent where applicable (for example, for geolocation)
- Guaranteeing the accuracy of the data entered
- Guaranteeing the lawfulness of the processing of third-party data it enters into the Platform (end customers for reservations and orders, labor advisory firms and technicians)
- Verifying that its labor advisory firm and other designated recipients offer adequate data protection safeguards
- Respecting the retention periods and the exercise of rights of its employees and candidates
12. Modifications to this Policy
StaffControl reserves the right to modify this Privacy Policy to adapt it to legislative or case-law developments. Substantial changes will be communicated to users through the Platform. The current version will always be available at www.staffcontrol.app/privacy.
13. Applicable Law
This Privacy Policy is governed by Spanish and European law, in particular:
- Regulation (EU) 2016/679 (GDPR)
- Ley Orgánica 3/2018, of 5 December (LOPDGDD)
- Ley 34/2002, of 11 July (LSSI-CE)
- Real Decreto-ley 8/2019 (working-time records)
- Real Decreto Legislativo 2/2015 (Estatuto de los Trabajadores)
- Regulation (EU) 910/2014 (eIDAS) and Ley 6/2020, of 11 November, on electronic signature
- Regulation (EU) 2024/1689 (Artificial Intelligence Act)