e-HR

GDPR Compliance

Last Updated: 28.07.2026

This page centralizes how e-HR applies Regulation (EU) 2016/679 (GDPR) and Romanian data protection legislation in operating the platform. We recommend reading it together with the Terms and Conditions and the Privacy Policy, which form an integral part of our compliance commitment.

1. Introduction

e-HR ("we", "the Provider") operates a multi-tenant SaaS platform for HR management, time tracking, leave, and payroll, aimed at companies in Romania and the European Union. We are committed to complying with the General Data Protection Regulation (Regulation (EU) 2016/679, "GDPR"), Romanian Law No. 190/2018 on measures implementing the GDPR, and other applicable Romanian and European personal data protection legislation. This page describes, in a centralized manner, our compliance measures, the roles of the parties involved, and the safeguards applied within the Platform.

2. Data Controller and Data Processor

For account, billing, and usage data of the Client Company's representatives and Users (name, email, billing data, access logs), e-HR acts as data controller, independently determining the purposes and means of processing.

For Employee Data entered, uploaded, or generated by a Client Company in the Platform (for example identification, attendance, leave, payroll, or document data), the Client Company is the data controller, and e-HR acts solely as data processor, processing such data based on the Company's documented instructions, in accordance with the Terms and Conditions, Article 28 GDPR, and, where applicable, a separately executed Data Processing Agreement (DPA).

If you are an employee of a Client Company, your employer is the data controller responsible for the processing carried out through the Platform; e-HR supports the Client Company in addressing your requests, in accordance with its contractual obligations.

3. Categories of Personal Data Processed

Account, Billing, and Usage Data

  • Name, job title, email address, phone number
  • Company name, tax identification number, registered address, billing data
  • Authentication data: encrypted password, kiosk PIN codes
  • IP address, access and system logs, device and browser type

Employee Data (processed by e-HR as processor)

  • Identification data: name, national ID number (CNP), identity document details, address, contact details
  • Employment contract details, job title, department, and organizational structure
  • Attendance and time-tracking data, including records made via the kiosk terminal with PIN code and IP address
  • Leave data (annual, medical, and other leave types) and related requests
  • Payroll data: salary calculation elements, contributions, deductions, payslips
  • HR documents: contracts, addenda, certificates, medical leave certificates

Special Categories of Data and National Identifiers

  • National ID number (CNP) — a national identifier subject to additional safeguards under Law No. 190/2018
  • Health data contained in medical leave certificates, processed by the Client Company for payroll and legal reporting purposes, and by e-HR strictly as processor

5. GDPR Principles Applied

Lawfulness, fairness, and transparency — we process data only on a valid legal basis and inform data subjects about how it is processed.

Purpose limitation — we collect data only for specific, explicit, and legitimate purposes, described on this page and in the Privacy Policy.

Data minimization — we collect and process only the data strictly necessary for the stated purposes, avoiding unjustified additional fields or collection.

Accuracy — we take reasonable steps to ensure inaccurate data is erased or rectified without delay, including through the editing features available to Client Companies.

Storage limitation — we retain data in a form that allows identification of individuals only for the period necessary for the processing purposes or required by law, as described in Section 11.

Integrity and confidentiality — we apply appropriate technical and organizational measures against unauthorized processing, loss, or accidental destruction, detailed in Section 12.

Accountability — we can demonstrate compliance with the above principles through internal policies, records of processing activities, and documentation of relevant decisions.

6. Processing of Special Categories of Data

Medical leave certificates uploaded to the Platform contain health data, a special category of data under Article 9 GDPR. This data is entered and processed by the Client Company, as controller, under Article 9(2)(b) GDPR (carrying out obligations and exercising specific rights in the field of employment and social security law), for calculating leave indemnities and reporting to health insurance authorities. e-HR processes this data solely as processor, with role-based restricted access and no use for other purposes.

The national ID number (CNP) is processed subject to the additional safeguards required by Law No. 190/2018, solely for purposes related to uniquely identifying the employee for payroll, tax reporting, and labor registry purposes, with role-based restricted access and no use for public display or other incompatible purposes.

The Client Company is responsible for having an appropriate legal basis for entering special categories of data into the Platform and for properly informing its employees.

7. Rights of Data Subjects

Under Chapter III of the GDPR, you have the following rights regarding your personal data:

Right of Access (Art. 15)

The right to obtain confirmation that we process your data and a copy of it, together with information about the purposes, categories of data, recipients, and retention period.

Right to Rectification (Art. 16)

The right to request correction of inaccurate data or completion of incomplete data.

Right to Erasure (Art. 17)

The right to request deletion of your data, for example when it is no longer necessary for the purposes for which it was collected or you withdraw consent, subject to applicable legal retention obligations.

Right to Restriction of Processing (Art. 18)

The right to request that we limit the processing of your data in certain situations, for example while the accuracy of the data is being verified.

Right to Data Portability (Art. 20)

The right to receive the data you provided in a structured, commonly used, machine-readable format, and to transmit it to another controller.

Right to Object (Art. 21)

The right to object to processing based on e-HR's legitimate interest, as well as to processing for direct marketing purposes, at any time.

Right to Withdraw Consent (Art. 7)

Where processing is based on consent, you have the right to withdraw it at any time, without affecting the lawfulness of processing carried out before the withdrawal.

Right Not to Be Subject to Automated Decision-Making (Art. 22)

e-HR does not use automated decision-making processes or profiling that produce legal effects concerning you or similarly significantly affect you, without human intervention.

Right to Lodge a Complaint

The right to lodge a complaint with the National Supervisory Authority for Personal Data Processing (ANSPDCP) or with the competent courts, as described in Section 20.

8. How to Exercise Your Rights

You may exercise your rights by sending a request to [email protected], clearly indicating the right you wish to exercise.

We will respond to your request within one month of receipt, a period that may be extended by up to two further months taking into account the complexity and number of requests, in which case you will be informed of the extension within one month of receiving the request.

To prevent disclosure of data to unauthorized persons, we may request reasonable additional information to verify the requester's identity before responding.

If you are an employee of a Client Company and your request concerns Employee Data, we may direct you to your employer, as the responsible data controller, while supporting them in addressing your request in accordance with our contractual obligations.

Exercising your rights is generally free of charge; we may charge a reasonable fee or refuse to act on a request that is manifestly unfounded or excessive, in particular because of its repetitive character.

9. Data Recipients and Sub-processors

We work with the following categories of sub-processors/recipients, contractually bound to security and confidentiality safeguards:

  • Stripe — payment processing and subscription billing;
  • Cloud infrastructure providers (for example Amazon Web Services/S3) — hosting and storage of data and documents;
  • Email and notification service providers — transactional communications;
  • Platform monitoring, maintenance, and technical support providers.

With each sub-processor that processes Employee Data, e-HR enters into data processing agreements compliant with Article 28 GDPR, imposing confidentiality, security, and incident notification obligations similar to those undertaken by e-HR.

e-HR does not sell or rent personal data to third parties for their own marketing purposes.

The updated list of sub-processors is available upon request at [email protected].

10. International Data Transfers

Some of our sub-processors may process data outside the European Economic Area (EEA), including in countries for which the European Commission has not issued an adequacy decision. In such cases, we ensure the transfer relies on appropriate safeguards recognized by the GDPR (Articles 44-49), such as Standard Contractual Clauses approved by the European Commission, applicable adequacy decisions, or other equivalent legal mechanisms. You may request further information about the safeguards applied to a specific transfer at [email protected].

11. Data Retention Periods

We retain personal data for as long as necessary to fulfill the purposes described on this page, generally for the duration of the Client Company's account and active Subscription.

Certain categories of data are subject to minimum retention periods required by Romanian law, regardless of account status, including:

  • Accounting records and payslips — under Accounting Law No. 82/1991 and the Fiscal Code;
  • The general employee registry (REVISAL) and related employment documents — under the Labor Code and Government Decision No. 905/2017;
  • Documents related to medical leave and related indemnities — under health and social security legislation;
  • Data necessary to defend legal rights, for the duration of applicable limitation periods.

After account termination, the Client Company has a reasonable period (typically 30 days, per the Terms and Conditions) to export its data. Afterwards, data not subject to a legal retention obligation is deleted or irreversibly anonymized, in accordance with our internal retention policy.

12. Technical and Organizational Security Measures

Technical Measures

  • Encryption of data in transit (TLS/HTTPS) and, where applicable, at rest
  • Role-based access control and the principle of least privilege
  • Logical isolation of each Client Company's data (multi-tenant architecture)
  • Periodic backups and disaster recovery procedures
  • Continuous monitoring of activity and security incidents
  • Hosting through recognized cloud infrastructure providers with their own security certifications

Organizational Measures

  • Internal data protection and security policies and procedures
  • Access to Employee Data limited on a need-to-know and role basis
  • Confidentiality agreements with staff and sub-processors
  • Periodic risk assessments and, where applicable, data protection impact assessments
  • Documented security incident response procedures

No method of transmission over the internet or electronic storage is 100% secure. While we apply reasonable security measures, we cannot guarantee absolute security of the data, and we recommend that Client Companies and Users follow good security practices (strong passwords, confidentiality of kiosk PIN codes).

13. Data Protection Impact Assessment (DPIA)

In accordance with Article 35 GDPR, we periodically assess whether the processing activities carried out through the Platform (including large-scale processing of special categories of data, such as medical leave certificates) pose a high risk to the rights and freedoms of data subjects and, where necessary, carry out a data protection impact assessment (DPIA) before introducing new features with a significant impact on privacy.

14. Data Security Breach Management

We maintain an internal procedure for identifying, assessing, and documenting security incidents affecting personal data, including a breach register in accordance with Article 33(5) GDPR.

In the event of a personal data breach that poses a risk to the rights and freedoms of individuals, we notify the National Supervisory Authority for Personal Data Processing (ANSPDCP) within 72 hours of becoming aware of the incident, in accordance with Article 33 GDPR.

If the breach poses a high risk to the rights and freedoms of data subjects, we notify affected individuals without undue delay or, in the case of Employee Data, support the Client Company in fulfilling this obligation, in accordance with Article 34 GDPR.

If a security breach affects Employee Data processed as processor, we notify the Client Company without undue delay, so that it can fulfill its own notification obligations.

15. Data Protection Officer / Contact Point

We periodically assess, in accordance with Article 37 GDPR, whether our processing activities require the mandatory designation of a Data Protection Officer (DPO), taking into account the nature, scope, and purposes of processing, including large-scale processing of special categories of data.

Regardless of the outcome of this assessment, we provide a dedicated contact point for any question about personal data processing or to exercise your GDPR rights, available at: [email protected].

16. Data Processing Agreement (DPA) for Client Companies

As data controllers for Employee Data, Client Companies may request a Data Processing Agreement (DPA) under Article 28 GDPR, detailing the subject matter and duration of processing, its nature and purpose, the types of data and categories of data subjects, the controller's obligations and rights, as well as safeguards regarding sub-processing, security measures, support for exercising data subjects' rights, security breach notification, and deletion or return of data upon termination of the agreement. Requests can be sent to [email protected].

17. Automated Decision-Making and Profiling

e-HR does not use automated decision-making processes, including profiling, that produce legal effects concerning data subjects or similarly significantly affect them, without human intervention. The payroll, attendance, and leave calculations performed by the Platform are decision-support tools made available to the Client Company, which remains responsible for final decisions regarding its employees.

18. Cookies and Tracking Technologies

We use strictly necessary, performance, and functional cookies to operate the Platform and the public website, in accordance with preferences expressed through the consent banner. Full details about the categories of cookies used, their purposes, and how to manage your preferences are available in Section 13 of the Privacy Policy.

19. Children's Privacy

The Platform is intended exclusively for use by persons with full legal capacity, in the context of employment relationships or company administration, and is not intended for persons under 18 years of age. We do not knowingly collect personal data directly from children. If you believe we may have inadvertently collected data about a child, please contact us at [email protected] so we can take appropriate action.

20. National Supervisory Authority (ANSPDCP)

The authority competent to oversee compliance with personal data protection legislation in Romania is the National Supervisory Authority for Personal Data Processing (ANSPDCP), located at Bd. G-ral. Gheorghe Magheru no. 28-30, Sector 1, Bucharest, Romania (anspdcp.ro). You have the right to lodge a complaint with the ANSPDCP or with the supervisory authority of the EU member state where you have your habitual residence, place of work, or where the alleged infringement occurred, without prejudice to your right to bring proceedings before a competent court.

21. Updates to This Page

We reserve the right to periodically update this GDPR compliance page to reflect changes in our data processing practices, technical infrastructure, or applicable legislation. Material changes will be communicated by email or through a visible notice on the Platform at least 15 days before taking effect. The date of the last update is shown at the top of this page.

22. Contact

For questions, requests, or complaints regarding GDPR compliance, or to exercise the rights described in Section 7, you may contact us at any time at: [email protected].

Questions about GDPR Compliance?

Our team is here to help. Contact us at [email protected]

Contact us