e-HR

Privacy Policy

Last Updated: 28.07.2026

This Privacy Policy explains how e-HR collects, uses, discloses, and protects personal data when you use the e-HR platform. We recommend reading it together with the Terms and Conditions and the GDPR Compliance page.

1. Introduction

e-HR ("we", "our", "Platform") respects your privacy and is committed to protecting your personal data. This Privacy Policy ("Policy") explains what data we collect, for what purpose and on what legal basis we process it, to whom we may disclose it, how long we keep it, and what rights you have, when you use our SaaS platform for HR management, time tracking, leave, and payroll available at e-hr.ro, including the web application, the kiosk time-tracking terminal, and the public blog and help center sections.

2. Data Controller

The data controller, within the meaning of Regulation (EU) 2016/679 ("GDPR"), for the data described in this Policy (account data, billing data, Platform usage data) is e-HR, located in Romania. For Employee Data uploaded to the Platform by a Client Company, that Company is the data controller, and e-HR acts as data processor, as described in Section 7 below. For any question about the processing of your data, you can contact us at: [email protected].

3. Scope

This Policy applies to personal data processed through the Platform, whether you are an account owner, administrator, manager, or employee of a Client Company, a visitor of our public website, blog, or help center, or a contact person in a sales or support process. This Policy does not apply to the data processing practices of other websites or services that the Platform may link to, which have their own privacy policies.

4. Data We Collect

Account and Billing Data

  • Full name and job title
  • Email address and phone number (optional)
  • Company name, tax identification number, registered address
  • Billing information and payment history (processed through Stripe)
  • Authentication credentials (encrypted password, kiosk PIN codes)

Technical and Usage Data

  • IP address, browser type and version, operating system, device type
  • Pages visited, actions taken, access dates and times, system logs
  • Cookies and similar technologies, as described in Section 13
  • Approximate location (derived from IP address), for security purposes

Client Company Employee Data

  • Identification data (name, national ID number, identity document, contact details) entered by the Company
  • Employment contract details, job title, department, and organizational structure
  • Attendance and time-tracking data, including records made via the kiosk terminal
  • Leave data (annual, medical, and other leave types) and related requests
  • Payroll data, including salary calculation elements and payslips
  • Documents and files uploaded to the Platform (for example contracts, certificates, medical leave documents)

Communications Data

  • Correspondence with our support, sales, or other e-HR teams
  • Feedback, suggestions, or survey responses submitted voluntarily

5. How We Collect Data

Directly from you – when you create an account, fill in forms, upload documents, contact support, or use Platform features.

Automatically – through cookies, server logs, and similar technologies, when you access the Platform or our public website.

From your employer – if you are an employee of a Client Company, part of your data (for example identification, payroll, or attendance data) is entered into the Platform by the Company, acting as data controller, rather than by you directly.

From third parties – for example from our payment processor (Stripe), regarding the status of a transaction, or from publicly available sources, to the extent permitted by law.

7. e-HR's Role: Controller or Processor

For the account, billing, and usage data described in Section 4, relating to representatives and Users of the Client Company, e-HR acts as data controller, independently determining the purposes and means of processing, as described in this Policy.

For Employee Data entered by a Client Company into the Platform (for example identification, attendance, payroll, or leave data of its employees), e-HR acts solely as data processor, processing such data based on the documented instructions of that Company, in accordance with the Terms and Conditions and, where applicable, a separately executed Data Processing Agreement (DPA).

If you are an employee of a Client Company and have questions about how your data is used within the Platform, please contact your employer directly, as the data controller responsible for such processing; e-HR will support your employer in addressing such requests, in accordance with its contractual obligations.

8. Data Sharing and Disclosure

We share data with trusted third-party service providers who help us operate the Platform — for example cloud hosting and infrastructure providers (Amazon Web Services/S3), our payment processor (Stripe), email and notification service providers, and monitoring and technical support providers — under contractual arrangements that impose confidentiality and security obligations similar to those undertaken by e-HR.

We may disclose data if necessary to comply with a legal obligation, subpoena, or court order, to respond to requests from competent public authorities, or to protect the rights, property, or safety of e-HR, our Clients, or our Users.

In case of a merger, acquisition, reorganization, or sale of a substantial part of e-HR's assets, personal data may be transferred to the new entity, subject to confidentiality and, where required by law, prior notice to data subjects.

e-HR does not sell or rent your personal data to third parties for their own marketing purposes.

The updated list of sub-processors used by e-HR to process Employee Data is available upon request at [email protected].

9. International Data Transfers

Some of our service providers may process data outside the European Economic Area (EEA), including in countries for which the European Commission has not issued an adequacy decision. In such cases, we ensure the transfer relies on appropriate safeguards recognized by the GDPR, such as Standard Contractual Clauses approved by the European Commission, applicable adequacy decisions, or other equivalent legal mechanisms. You may request further information about the safeguards applied to a specific transfer at [email protected].

10. Data Retention

We retain your personal data for as long as necessary to fulfill the purposes described in this Policy, generally for the duration of your account and active Subscription.

Certain categories of data (for example accounting records, payslips) must be retained for minimum periods required by applicable Romanian law (tax, accounting, archiving, and labor law), even after account closure.

After account termination, the Client Company has a reasonable period (typically 30 days, per the Terms and Conditions) to export its data. Afterwards, data not subject to a legal retention obligation is deleted or irreversibly anonymized, in accordance with our internal retention policy.

11. Data Security

We implement appropriate technical and organizational measures to protect your data against unauthorized access, loss, destruction, or accidental or unlawful alteration, including:

  • Encryption of data in transit (TLS/HTTPS) and, where applicable, at rest
  • Role-based access control and the principle of least privilege
  • Logical isolation of each Client Company's data (multi-tenant architecture)
  • Periodic backups and disaster recovery procedures
  • Monitoring of activity and security incidents
  • Hosting through recognized cloud infrastructure providers with their own security certifications

No method of transmission over the internet or electronic storage is 100% secure. While we make reasonable efforts to protect your data, we cannot guarantee its absolute security, and we recommend that you follow good security practices (strong, unique passwords, confidentiality of kiosk PIN codes).

In the event of a personal data breach that poses a risk to your rights and freedoms, we will act in accordance with our obligations under the GDPR, including, where applicable, notifying the National Supervisory Authority for Personal Data Processing (ANSPDCP) and affected individuals, as further described in the GDPR Compliance page.

12. Your Rights

As a data subject, you have, subject to the conditions and limitations set out in the GDPR, the following rights regarding your personal data:

Right of access

The right to obtain confirmation that we process your data and to receive a copy of that data, together with information about how it is processed.

Right to rectification

The right to request correction of inaccurate data or completion of incomplete data.

Right to erasure ("right to be forgotten")

The right to request deletion of your data in certain circumstances, for example when it is no longer necessary for the purposes for which it was collected.

Right to restriction of processing

The right to request that we limit how we process your data in certain situations, for example while a dispute over the accuracy of the data is being verified.

Right to data portability

The right to receive the data you provided to us in a structured, commonly used, machine-readable format, and to transmit it to another controller.

Right to object

The right to object to processing based on our legitimate interest, as well as to processing of your data for direct marketing purposes, at any time.

Right to withdraw consent

Where processing is based on consent, you have the right to withdraw it at any time, without affecting the lawfulness of processing carried out before the withdrawal.

Right not to be subject to automated decision-making

e-HR does not use automated decision-making processes, including profiling, that produce legal effects concerning you or similarly significantly affect you, without human intervention.

You may exercise these rights by contacting us at [email protected]. We will respond to your request within one month of receipt, a period that may be extended by up to two further months, taking into account the complexity and number of requests, in which case we will inform you of the extension. If you are an employee of a Client Company, we may direct you to your employer, as the data controller for Employee Data.

If you believe that the processing of your data infringes the GDPR, you have the right to lodge a complaint with the National Supervisory Authority for Personal Data Processing (ANSPDCP), as described in Section 17 below, without prejudice to your right to bring proceedings before a court.

13. Cookies and Similar Technologies

We use cookies and similar technologies (for example local storage) to ensure the Platform functions correctly, keep you signed in, improve the user experience, analyze how the Platform is used, and, where applicable, personalize content.

We primarily use the following categories of cookies:

  • Strictly necessary cookies – essential for the Platform to function and for authentication; these cannot be disabled;
  • Performance/analytics cookies – help us understand how the Platform is used, so we can improve it;
  • Functional cookies – remember your preferences (for example the selected language);

You can manage your cookie preferences through the consent banner displayed on your first visit to the website, as well as through your browser settings, which allow you to block or delete cookies. Disabling strictly necessary cookies may affect the proper functioning of the Platform.

14. Marketing Communications

We may occasionally send you communications about new features, Platform updates, or content from our blog, but only where you have given your consent or in other cases permitted by applicable commercial communications legislation. You may unsubscribe at any time using the unsubscribe link included in each message or by contacting us at [email protected]. Transactional communications necessary for providing the Service (for example system notifications, invoices, security alerts) are not affected by unsubscribing from marketing communications.

15. Children's Privacy

The Platform is intended exclusively for use by persons with full legal capacity, in the context of employment relationships or company administration, and is not intended for persons under 18 years of age. We do not knowingly collect personal data directly from children. If you believe we may have inadvertently collected data about a child, please contact us at [email protected] so we can take appropriate action.

17. Supervisory Authority

The authority competent to oversee compliance with personal data protection legislation in Romania is the National Supervisory Authority for Personal Data Processing (ANSPDCP), located at Bd. G-ral. Gheorghe Magheru no. 28-30, Sector 1, Bucharest. You have the right to lodge a complaint with the ANSPDCP or with the supervisory authority of the EU member state where you have your habitual residence, place of work, or where the alleged infringement occurred.

18. Changes to This Policy

We reserve the right to periodically update this Privacy Policy to reflect changes in our data processing practices or applicable legislation. Material changes will be communicated by email or through a visible notice on the Platform at least 15 days before taking effect. The date of the last update is shown at the top of this page; we recommend checking it periodically.

19. Contact

For questions, requests, or complaints regarding this Privacy Policy, or to exercise the rights described in Section 12, you may contact us at any time at: [email protected].

Have questions about data privacy?

For questions or to exercise your rights, contact us at [email protected]

Contact us