This is a translation of the Czech original, provided for convenience. In case of any discrepancy, the Czech version prevails.
Privacy Policy
This policy explains how “HRko” (hereinafter “we”) processes the personal data of visitors to the website hrko.eu, users of the application app.hrko.eu and users of the HRko mobile application for Android and iPhone. The same applies to HRko instances operated for a specific client at its own address (e.g. hrko.uhcar.cz) and to their mobile applications (e.g. “HRko UH CAR”). Processing is carried out in accordance with Regulation (EU) 2016/679 (GDPR) and Czech Act No. 110/2019 Coll., on personal data processing.
Contents
1. Controller vs. processor
HRko acts in two different roles, depending on whose data it processes:
- Controller — for the data of website visitors, applicants for our services and the user accounts of administrators. We ourselves determine why and how the data are processed.
- Processor — for the employee data and HR data uploaded to the application by our clients (customer companies). In this case the controller is the given client, and we process the data on its instructions on the basis of a Data Processing Agreement (DPA).
2. What data we process
2.1 Website visitors
- IP address, user agent, time of visit — from web logs
- Cookies (see the Cookie policy)
- Data you enter yourself into the contact form or an enquiry (name, e-mail, telephone, company name, company ID number (IČO))
2.2 Application users
- Account identification data — e-mail, name, display name
- Authentication data — password hash (BCrypt), TOTP secret for MFA, refresh tokens
- Activity logs — login/logout, IP address, operations performed (audit log)
- Contact details, if you fill them in yourself (telephone, alternative e-mail)
2.3 Employees of our clients
In the role of processor, we store the data that clients themselves upload to the application. These typically include:
- Identification data — first name, surname, date of birth, national identification number (rodné číslo)
- Contact details — address, telephone, e-mail
- Employment data — position, salary, contracts, shift schedule, attendance, leave
- Documents — employment contracts, medical certificates, certifications (uploaded by the client)
The specific scope and retention period are set out in the DPA with the given client.
2.4 Mobile application
The HRko mobile application (on Android from Google Play; on iPhone as a web application added to the home screen) displays the same data as the web application — shifts, leave, attendance, messages and notifications. In addition, it processes:
- Device data — internal installation identifier, platform (Android / web), phone model name, application version, time of registration and of last unlock. They serve to manage signed-in devices; the user can see them in their profile and can sign any of them out at any time.
- Push notification token — on Android the Firebase Cloud Messaging token, on iPhone and in the browser the Web Push subscription address. Without them, a notification of a new message or of a request awaiting approval cannot be delivered.
- Notification content — the heading and short text of the notification (e.g. “New message” and its beginning, a leave request). For sensitive types of notification only a generic text is sent and the content is displayed only after the application is opened.
- Access security — we store the PIN only as a one-way fingerprint (hash). The fingerprint is verified exclusively by the phone; it does not reach the application or us, and only a public key for verifying the signature is stored on the server.
The application contains no advertising or analytics and tracking tools, and does not access location, contacts, photos or any other data on the phone. It requests only permission to display notifications and (if the user so chooses) to unlock using a fingerprint. The sign-in session is held only in the application's memory; only the device registration data remain in the phone's secure storage, and these are deleted by signing out or uninstalling the application.
3. Purposes and legal bases of processing
| Purpose | Legal basis | Retention period |
|---|---|---|
| Provision of the HRko service (account operation, authentication) | Performance of a contract (Art. 6(1)(b) GDPR) | For the duration of the contract + 30 days |
| Invoicing and accounting | Legal obligation (Czech Accounting Act) | 10 years from the end of the accounting period |
| Marketing communications (newsletter) | Consent (Art. 6(1)(a)) | Until consent is withdrawn |
| Mobile application — management of signed-in devices and delivery of notifications | Performance of a contract (Art. 6(1)(b)) and legitimate interest (security) | Until the device is signed out, at most 90 days from last use |
| Security and audit log | Legitimate interest (Art. 6(1)(f)) | 2 years |
| Web server logs | Legitimate interest (security) | 90 days |
| Cookies — necessary | Legitimate interest | Session / max. 12 months |
| Cookies — analytics and marketing | Consent (via the cookie banner) | Until withdrawn |
4. Recipients of data
We share data only with carefully selected sub-processors who are contractually bound to comply with the GDPR. The current list is public on the Subprocessors page. The main sub-processors are:
- Oracle Cloud Infrastructure (Oracle Czech, s.r.o.) — application hosting, region eu-frankfurt-1 (Germany)
- Let's Encrypt — TLS certificates
- Google Ireland Limited — Google Analytics 4, measurement of traffic to the hrko.eu website; only with the visitor's consent and only on the website, not in the application
- Google Ireland Limited — Firebase Cloud Messaging, delivery of push notifications to the mobile application for Android (device token and notification content)
- Web Push service providers (Apple, Google, Mozilla — depending on the user's browser) — delivery of notifications to iPhone and to the browser; the notification content is end-to-end encrypted and the service cannot read it
We do not disclose data to public authorities beyond what is required by law.
5. International data transfers
All production data are stored exclusively in the EU (Germany, Oracle Frankfurt data centre); instances operated for a client on its own server are stored where the client determines. Application data are not stored outside the EU.
An exception is the delivery of push notifications to the mobile application for Android via the Firebase Cloud Messaging service: the device token and the notification content may be processed by Google also outside the EU (in particular in the USA). The transfer is secured by the European Commission's standard contractual clauses and by the certification of Google LLC under the EU-US Data Privacy Framework. The notification carries only a short text; for sensitive types of notification only a generic wording. Notifications delivered via Web Push (iPhone, browser) are end-to-end encrypted.
6. Retention period
We retain data only for as long as strictly necessary. The specific periods are set out in the table above. After the period expires, we irreversibly delete or anonymise the data.
7. Your rights
Under the GDPR, you have the right:
- Of access — to a copy of the data we hold about you
- To rectification — if the data are inaccurate
- To erasure (“to be forgotten”)
- To restriction of processing
- To data portability — export in a machine-readable format (CSV/JSON)
- To object to processing based on legitimate interest
- To withdraw consent — at any time and without giving a reason
- To lodge a complaint with the Czech Office for Personal Data Protection (ÚOOÚ)
Send your request to privacy@hrko.eu. We will handle it within 30 days at the latest (in exceptional cases within 90 days at most, with notice of the extension).
Important: if you are an employee of a company that uses HRko, address your request directly to your employer (the data controller). We only carry out actions on the basis of its instructions.
8. Contact and complaints
Contact for questions on personal data protection: privacy@hrko.eu
Identification details of the controller: see the Operator page
Supervisory authority: Czech Office for Personal Data Protection (ÚOOÚ), Pplk. Sochora 27, 170 00 Praha 7, uoou.cz
We may update this policy from time to time. The current version can always be found on this page. We will notify you of material changes in advance by e-mail.