This is a translation of the Czech original, provided for convenience. In case of any discrepancy, the Czech version prevails.
Data Processing Agreement (DPA)
This agreement (the “DPA”) governs the processing of personal data that the Client (controller) uploads to the HRko service, the provider of which is the operator of the HRko service, whose identification details are stated on the Operator page (processor). The DPA forms an integral part of the Terms and conditions and is concluded pursuant to Article 28 GDPR.
1. Subject matter of processing
The processor processes personal data solely for the purpose of performing the service — operating an HR system in which the controller records its employees, candidates and other persons.
2. Duration of processing
For the duration of the main agreement + a 30-day grace period for data export + backup retention (max. 7 days).
3. Nature and purpose of processing
- Storing and searching employee data
- Shift planning, tracking of attendance and absences
- Workflow processes (onboarding, approval of leave)
- Generating documents and contracts from templates
- Reports and statistics
4. Categories of personal data
- Identification — first name, surname, date of birth, national identification number (rodné číslo)
- Contact — address, telephone, e-mail
- Employment — position, salary, evaluation, schedule
- Sensitive (only if uploaded by the controller) — health restrictions, ZTP/P (severe disability status), medical assessments
- Documents uploaded by the controller
5. Data subjects
- The controller's employees
- Candidates
- Contractors under DPP/DPČ (work-performance agreements)
- Other persons recorded by the controller (family members for tax relief purposes, etc.)
6. Obligations of the processor
- Processes data only on the basis of documented instructions from the controller
- Maintains confidentiality — personnel are contractually bound
- Implements appropriate technical and organisational measures (see Security)
- Does not engage other processors without the controller's prior authorisation (see the list of sub-processors); informs of changes at least 30 days in advance
- Assists the controller in fulfilling its obligations (access, rectification, erasure, portability) by means of the agreed tools of the application
- Reports personal data breaches without undue delay, at the latest within 48 hours of becoming aware of them
- Upon termination of processing, deletes or returns the data as instructed by the controller
7. Sub-processors
The processor uses other processors (sub-processors) listed publicly on the page /en/subprocessors. The controller gives general authorisation for their use; the processor will notify changes by e-mail at least 30 days in advance. If the controller does not agree with a new sub-processor, it has the right to terminate the agreement.
8. Security measures (Article 32 GDPR)
- Encryption of data in transit (TLS 1.2+)
- Password hashing (BCrypt)
- MFA support (TOTP)
- Multi-tenant isolation — strict separation of data between clients
- Audit log of all mutations
- Daily backups with weekly retention
- Restore test verified and documented
- Regular updates of runtime + dependencies
Detailed description: /en/security.
9. International transfers
Data is stored exclusively in the EU (Oracle Cloud Frankfurt). Should a transfer outside the EU occur in the future, we will notify the controller in advance and ensure an appropriate legal basis (standard contractual clauses, adequacy decision).
10. Audit and accountability
The controller has the right to audit compliance with the DPA in writing — by sending a security questionnaire (e.g. SIG, VSA or its own template) to privacy@hrko.eu. The processor will usually return the completed questionnaire within 5 business days. For enterprise clients with their own information security team, the processor may provide logs of administrative actions, a list of sub-processors and other supporting documentation.
11. Liability
The parties are liable for damage caused by a breach of this DPA. The limit of liability is identical to the limit in the Terms and conditions, unless the parties agree otherwise.
12. Effectiveness and changes
The DPA becomes effective upon conclusion of the main agreement and remains in force for its duration. The current version can always be found on this page. We announce material changes 30 days in advance.
If you need to sign this DPA in written form (for your compliance), send a request to privacy@hrko.eu. We will issue a PDF for signature.