Privacy Policy
Last Updated: 28.07.2026
This Privacy Policy explains how e-HR collects, uses, discloses, and protects personal data when you use the e-HR platform. We recommend reading it together with the Terms and Conditions and the GDPR Compliance page.
1. Introduction
e-HR ("we", "our", "Platform") respects your privacy and is committed to protecting your personal data. This Privacy Policy ("Policy") explains what data we collect, for what purpose and on what legal basis we process it, to whom we may disclose it, how long we keep it, and what rights you have, when you use our SaaS platform for HR management, time tracking, leave, and payroll available at e-hr.ro, including the web application, the kiosk time-tracking terminal, and the public blog and help center sections.
2. Data Controller
The data controller, within the meaning of Regulation (EU) 2016/679 ("GDPR"), for the data described in this Policy (account data, billing data, Platform usage data) is e-HR, located in Romania. For Employee Data uploaded to the Platform by a Client Company, that Company is the data controller, and e-HR acts as data processor, as described in Section 7 below. For any question about the processing of your data, you can contact us at: [email protected].
3. Scope
This Policy applies to personal data processed through the Platform, whether you are an account owner, administrator, manager, or employee of a Client Company, a visitor of our public website, blog, or help center, or a contact person in a sales or support process. This Policy does not apply to the data processing practices of other websites or services that the Platform may link to, which have their own privacy policies.
4. Data We Collect
Account and Billing Data
- Full name and job title
- Email address and phone number (optional)
- Company name, tax identification number, registered address
- Billing information and payment history (processed through Stripe)
- Authentication credentials (encrypted password, kiosk PIN codes)
Technical and Usage Data
- IP address, browser type and version, operating system, device type
- Pages visited, actions taken, access dates and times, system logs
- Cookies and similar technologies, as described in Section 13
- Approximate location (derived from IP address), for security purposes
Client Company Employee Data
- Identification data (name, national ID number, identity document, contact details) entered by the Company
- Employment contract details, job title, department, and organizational structure
- Attendance and time-tracking data, including records made via the kiosk terminal
- Leave data (annual, medical, and other leave types) and related requests
- Payroll data, including salary calculation elements and payslips
- Documents and files uploaded to the Platform (for example contracts, certificates, medical leave documents)
Communications Data
- Correspondence with our support, sales, or other e-HR teams
- Feedback, suggestions, or survey responses submitted voluntarily
5. How We Collect Data
Directly from you – when you create an account, fill in forms, upload documents, contact support, or use Platform features.
Automatically – through cookies, server logs, and similar technologies, when you access the Platform or our public website.
From your employer – if you are an employee of a Client Company, part of your data (for example identification, payroll, or attendance data) is entered into the Platform by the Company, acting as data controller, rather than by you directly.
From third parties – for example from our payment processor (Stripe), regarding the status of a transaction, or from publicly available sources, to the extent permitted by law.
6. Purpose of Processing and Legal Basis
We process your personal data for the following purposes, based on the legal grounds indicated:
- Creating and managing your account and providing the Service — based on performance of the contract (the Terms and Conditions) between you/your Company and e-HR;
- Processing payments, issuing invoices, and maintaining accounting records — based on performance of the contract and the legal (tax and accounting) obligations applicable to e-HR;
- Transactional communications (confirmations, system notifications, security updates) — based on performance of the contract and our legitimate interest in ensuring the Platform runs properly;
- Marketing communications (newsletters, information about new features) — based on your consent, which you may withdraw at any time;
- Improving the Platform, statistical analysis, and developing new features — based on our legitimate interest, applied so that it does not override your rights and freedoms;
- Ensuring Platform security, preventing fraud and misuse — based on the legitimate interest of e-HR and our Clients;
- Fulfilling legal obligations (for example responding to requests from authorities, tax obligations, GDPR reporting) — based on the legal obligation applicable to e-HR;
- Resolving disputes and defending e-HR's rights — based on the legitimate interest of e-HR.
7. e-HR's Role: Controller or Processor
For the account, billing, and usage data described in Section 4, relating to representatives and Users of the Client Company, e-HR acts as data controller, independently determining the purposes and means of processing, as described in this Policy.
For Employee Data entered by a Client Company into the Platform (for example identification, attendance, payroll, or leave data of its employees), e-HR acts solely as data processor, processing such data based on the documented instructions of that Company, in accordance with the Terms and Conditions and, where applicable, a separately executed Data Processing Agreement (DPA).
If you are an employee of a Client Company and have questions about how your data is used within the Platform, please contact your employer directly, as the data controller responsible for such processing; e-HR will support your employer in addressing such requests, in accordance with its contractual obligations.
9. International Data Transfers
Some of our service providers may process data outside the European Economic Area (EEA), including in countries for which the European Commission has not issued an adequacy decision. In such cases, we ensure the transfer relies on appropriate safeguards recognized by the GDPR, such as Standard Contractual Clauses approved by the European Commission, applicable adequacy decisions, or other equivalent legal mechanisms. You may request further information about the safeguards applied to a specific transfer at [email protected].
10. Data Retention
We retain your personal data for as long as necessary to fulfill the purposes described in this Policy, generally for the duration of your account and active Subscription.
Certain categories of data (for example accounting records, payslips) must be retained for minimum periods required by applicable Romanian law (tax, accounting, archiving, and labor law), even after account closure.
After account termination, the Client Company has a reasonable period (typically 30 days, per the Terms and Conditions) to export its data. Afterwards, data not subject to a legal retention obligation is deleted or irreversibly anonymized, in accordance with our internal retention policy.
11. Data Security
We implement appropriate technical and organizational measures to protect your data against unauthorized access, loss, destruction, or accidental or unlawful alteration, including:
- Encryption of data in transit (TLS/HTTPS) and, where applicable, at rest
- Role-based access control and the principle of least privilege
- Logical isolation of each Client Company's data (multi-tenant architecture)
- Periodic backups and disaster recovery procedures
- Monitoring of activity and security incidents
- Hosting through recognized cloud infrastructure providers with their own security certifications
No method of transmission over the internet or electronic storage is 100% secure. While we make reasonable efforts to protect your data, we cannot guarantee its absolute security, and we recommend that you follow good security practices (strong, unique passwords, confidentiality of kiosk PIN codes).
In the event of a personal data breach that poses a risk to your rights and freedoms, we will act in accordance with our obligations under the GDPR, including, where applicable, notifying the National Supervisory Authority for Personal Data Processing (ANSPDCP) and affected individuals, as further described in the GDPR Compliance page.
12. Your Rights
As a data subject, you have, subject to the conditions and limitations set out in the GDPR, the following rights regarding your personal data:
Right of access
The right to obtain confirmation that we process your data and to receive a copy of that data, together with information about how it is processed.
Right to rectification
The right to request correction of inaccurate data or completion of incomplete data.
Right to erasure ("right to be forgotten")
The right to request deletion of your data in certain circumstances, for example when it is no longer necessary for the purposes for which it was collected.
Right to restriction of processing
The right to request that we limit how we process your data in certain situations, for example while a dispute over the accuracy of the data is being verified.
Right to data portability
The right to receive the data you provided to us in a structured, commonly used, machine-readable format, and to transmit it to another controller.
Right to object
The right to object to processing based on our legitimate interest, as well as to processing of your data for direct marketing purposes, at any time.
Right to withdraw consent
Where processing is based on consent, you have the right to withdraw it at any time, without affecting the lawfulness of processing carried out before the withdrawal.
Right not to be subject to automated decision-making
e-HR does not use automated decision-making processes, including profiling, that produce legal effects concerning you or similarly significantly affect you, without human intervention.
You may exercise these rights by contacting us at [email protected]. We will respond to your request within one month of receipt, a period that may be extended by up to two further months, taking into account the complexity and number of requests, in which case we will inform you of the extension. If you are an employee of a Client Company, we may direct you to your employer, as the data controller for Employee Data.
If you believe that the processing of your data infringes the GDPR, you have the right to lodge a complaint with the National Supervisory Authority for Personal Data Processing (ANSPDCP), as described in Section 17 below, without prejudice to your right to bring proceedings before a court.
14. Marketing Communications
We may occasionally send you communications about new features, Platform updates, or content from our blog, but only where you have given your consent or in other cases permitted by applicable commercial communications legislation. You may unsubscribe at any time using the unsubscribe link included in each message or by contacting us at [email protected]. Transactional communications necessary for providing the Service (for example system notifications, invoices, security alerts) are not affected by unsubscribing from marketing communications.
15. Children's Privacy
The Platform is intended exclusively for use by persons with full legal capacity, in the context of employment relationships or company administration, and is not intended for persons under 18 years of age. We do not knowingly collect personal data directly from children. If you believe we may have inadvertently collected data about a child, please contact us at [email protected] so we can take appropriate action.
16. Links to Third-Party Sites
The Platform and our blog may contain links to third-party websites or services that are not operated by e-HR. We are not responsible for the privacy practices or content of such third-party sites. We recommend reviewing the privacy policy of any third-party site you visit.
18. Changes to This Policy
We reserve the right to periodically update this Privacy Policy to reflect changes in our data processing practices or applicable legislation. Material changes will be communicated by email or through a visible notice on the Platform at least 15 days before taking effect. The date of the last update is shown at the top of this page; we recommend checking it periodically.
19. Contact
For questions, requests, or complaints regarding this Privacy Policy, or to exercise the rights described in Section 12, you may contact us at any time at: [email protected].
Have questions about data privacy?
For questions or to exercise your rights, contact us at [email protected]
Contact us