Personal Data Processing Policy
This document explains on what basis personal data is processed in the QR Gate system and how it is protected. It applies together with the Privacy Policy.
1. Roles of the parties
- The company (the user) acts as the owner of the data in respect of its employees' data: it determines what data is collected and for what purpose it is used.
- Proveb MMC processes that data on the company's instructions, within the framework of providing the service.
2. Legal basis for processing
Employee data may be entered into the System only where there is a lawful basis:
- obligations arising from the employment relationship (employment contract, recording of working time);
- the employer's statutory record-keeping and reporting obligations;
- where necessary - the consent of the data subject.
It is the employer's obligation to inform employees in advance of the purpose for which their data is collected.
3. Categories of data processed
- Personal identification: first name, last name, patronymic, position, personnel number, contact details.
- Attendance: check-in and check-out times, work schedule, lateness and early-leave indicators, leave and time-off records.
- Location: coordinates determined at the moment of a QR scan - solely to verify whether the employee is within the radius of the assigned access point. No continuous tracking is carried out.
- Device and network: device identifier, IP address, application / browser details - for prevention of fraudulent records and for security.
- System logs: operation and access records - for dispute investigation and audit.
4. Principles of processing
- only the minimum volume of data necessary for the stated purpose is collected;
- data is not used beyond the stated purpose;
- access rights are restricted on a role basis - each user sees only the data within their own authority;
- data is backed up regularly and transmitted over an encrypted channel.
5. Retention and erasure
Data is retained for the duration of the employment relationship and for the record-keeping period established by law. Once that period expires, or upon a substantiated request from the company, data is deleted or anonymised. Where an erasure request conflicts with a retention obligation established by law, that obligation prevails.
6. Rights of the data subject
An employee has the right to obtain information about their own data, to request correction of inaccurate data and, in the cases provided for by law, to request its erasure. Requests should be addressed first of all to the employer (the company); where technical support is required, they may be sent to [email protected].
7. Liability
Liability for entering third-party data into the System without a lawful basis lies with the company that entered that data. Where such cases are identified, the account may be blocked.