← Back to home
Effective from: 29 September 2026 · Version 1.1

This is a translation of the Czech original, provided for convenience. In case of any discrepancy, the Czech version prevails.

Privacy Policy

This policy explains how “HRko” (hereinafter “we”) processes the personal data of visitors to the website hrko.eu, users of the application app.hrko.eu and users of the HRko mobile application for Android and iPhone. The same applies to HRko instances operated for a specific client at its own address (e.g. hrko.uhcar.cz) and to their mobile applications (e.g. “HRko UH CAR”). Processing is carried out in accordance with Regulation (EU) 2016/679 (GDPR) and Czech Act No. 110/2019 Coll., on personal data processing.

Contents

  1. Controller vs. processor
  2. What data we process (including the mobile application)
  3. Purposes and legal bases
  4. Recipients of data
  5. International transfers
  6. Retention period
  7. Your rights
  8. Contact and complaints

1. Controller vs. processor

HRko acts in two different roles, depending on whose data it processes:

2. What data we process

2.1 Website visitors

2.2 Application users

2.3 Employees of our clients

In the role of processor, we store the data that clients themselves upload to the application. These typically include:

The specific scope and retention period are set out in the DPA with the given client.

2.4 Mobile application

The HRko mobile application (on Android from Google Play; on iPhone as a web application added to the home screen) displays the same data as the web application — shifts, leave, attendance, messages and notifications. In addition, it processes:

The application contains no advertising or analytics and tracking tools, and does not access location, contacts, photos or any other data on the phone. It requests only permission to display notifications and (if the user so chooses) to unlock using a fingerprint. The sign-in session is held only in the application's memory; only the device registration data remain in the phone's secure storage, and these are deleted by signing out or uninstalling the application.

3. Purposes and legal bases of processing

PurposeLegal basisRetention period
Provision of the HRko service (account operation, authentication)Performance of a contract (Art. 6(1)(b) GDPR)For the duration of the contract + 30 days
Invoicing and accountingLegal obligation (Czech Accounting Act)10 years from the end of the accounting period
Marketing communications (newsletter)Consent (Art. 6(1)(a))Until consent is withdrawn
Mobile application — management of signed-in devices and delivery of notificationsPerformance of a contract (Art. 6(1)(b)) and legitimate interest (security)Until the device is signed out, at most 90 days from last use
Security and audit logLegitimate interest (Art. 6(1)(f))2 years
Web server logsLegitimate interest (security)90 days
Cookies — necessaryLegitimate interestSession / max. 12 months
Cookies — analytics and marketingConsent (via the cookie banner)Until withdrawn

4. Recipients of data

We share data only with carefully selected sub-processors who are contractually bound to comply with the GDPR. The current list is public on the Subprocessors page. The main sub-processors are:

We do not disclose data to public authorities beyond what is required by law.

5. International data transfers

All production data are stored exclusively in the EU (Germany, Oracle Frankfurt data centre); instances operated for a client on its own server are stored where the client determines. Application data are not stored outside the EU.

An exception is the delivery of push notifications to the mobile application for Android via the Firebase Cloud Messaging service: the device token and the notification content may be processed by Google also outside the EU (in particular in the USA). The transfer is secured by the European Commission's standard contractual clauses and by the certification of Google LLC under the EU-US Data Privacy Framework. The notification carries only a short text; for sensitive types of notification only a generic wording. Notifications delivered via Web Push (iPhone, browser) are end-to-end encrypted.

6. Retention period

We retain data only for as long as strictly necessary. The specific periods are set out in the table above. After the period expires, we irreversibly delete or anonymise the data.

Account termination: After the contract is terminated, you have 30 days to export your data (CSV/JSON). After this period, we delete the data and all active backups. Backup snapshots are rotated in a 7-day retention cycle and are deleted gradually.

7. Your rights

Under the GDPR, you have the right:

Send your request to privacy@hrko.eu. We will handle it within 30 days at the latest (in exceptional cases within 90 days at most, with notice of the extension).

Important: if you are an employee of a company that uses HRko, address your request directly to your employer (the data controller). We only carry out actions on the basis of its instructions.

8. Contact and complaints

Contact for questions on personal data protection: privacy@hrko.eu

Identification details of the controller: see the Operator page

Supervisory authority: Czech Office for Personal Data Protection (ÚOOÚ), Pplk. Sochora 27, 170 00 Praha 7, uoou.cz


We may update this policy from time to time. The current version can always be found on this page. We will notify you of material changes in advance by e-mail.