The controller for the processing of personal data is Eurobest-Holding (Laszlo Demeter Demeter) (Tax ID 32991314E), with registered address at C/ Sierra de las Nieves, nº 1, 1ºB, 41440 - Lora del Río, España.
You can contact us at: [email protected].
For matters relating to data protection you may contact our Data Protection Officer (DPO) at: [email protected].
We process personal data in Jornadapp to:
Workplace geolocation and AEPD criteria in Spain. The AEPD guide on data protection in employment relationships and Article 90 of the LOPDGDD allow data obtained through geolocation systems to be processed for employment control functions within the legal framework of Article 20.3 of the Workers’ Statute, subject to limits of dignity, proportionality, minimisation and prior information. For this reason, Jornadapp live tracking is designed as an optional tool for activities in mobility or fleets and not as general surveillance: it only accepts positions when the extra is subscribed, the company has enabled it and the employee is clocked in as working; the employee keeps the location notice/service on the device where applicable; and live location must not be sent outside working hours. The customer company must inform workers and, where applicable, their representatives in advance in an express, clear and unequivocal manner; justify the purpose (for example route coordination, safety, planning or verification of services outside the workplace); limit access and retention; assess whether a data protection impact assessment is appropriate; and not require the use of personal devices where work equipment should legally be provided.
Workplace geolocation and CNPD criteria in Portugal. The CNPD Deliberation no. 7680/2014 on geolocation in the employment context, Article 17 of the Portuguese Labour Code (remote monitoring) and Law no. 58/2019 (GDPR) require a defined purpose, proportionality, minimisation and prior written information to workers and, where applicable, their representatives; geolocation is only admissible for specific legitimate purposes (for example safety, fleet management or coordination of external services), not as permanent surveillance or indiscriminate performance monitoring. Jornadapp live tracking is optional: it only accepts positions with the extra subscribed, the company activated and the worker registered as working; no live location is sent outside working hours; and the customer company must justify the purpose, limit access and retention, assess a data protection impact assessment where appropriate and not impose personal devices where work equipment should be provided.
Workplace geolocation and ICO guidance in the United Kingdom. Under the UK GDPR and the Data Protection Act 2018, and in accordance with the ICO guidance on monitoring workers (including location data), the controller must identify a lawful basis, inform with transparency, ensure that monitoring is proportionate and avoid blanket surveillance; real-time location requires documented necessity and must not continue outside working hours without justification. Jornadapp live tracking is designed as an optional tool for mobility or fleets: only with the extra subscribed, activation by the company and the worker in a working state; no transmission outside working hours; with a duty of prior notice, limitation of access and retention, and a data protection impact assessment where appropriate.
Location accuracy in field operations. The optional field safety and routes/mileage modules use the position provided by the device (GPS, network or system estimates). Accuracy may vary by handset, permissions, coverage, battery use or background operation. Routes and distances shown are indicative estimates for work coordination; minor errors in mileage calculation or map display may occur without this alone constituting a breach of service. The customer company should critically assess such data before taking employment, financial or disciplinary decisions based solely on them.
In addition to the channels available within the platform for registered business customers, we provide contact means for commercial or technical enquiries prior to signing a contract and for existing customers who prefer telephone, WhatsApp or email.
You may write to us at [email protected]. We process the data you include in your message (name, email, phone, company, subject, etc.) only to handle your enquiry. Legal basis: legitimate interest or pre-contractual measures (Art. 6(1)(f) or 6(1)(b) GDPR).
You may call us on +34 854 94 30 00 (extension 2), including if you are already a customer. If you provide personal data during the call (for example your name or email so we can return your call), we use it only to handle your request. Legal basis: legitimate interest or pre-contractual measures (Art. 6(1)(f) or 6(1)(b) GDPR).
You may write to us on WhatsApp at +34 854 94 30 00, including if you are already a customer. Processing of messages and associated metadata (including your telephone number) is also governed by Meta/WhatsApp terms as the messaging provider, in addition to our purpose of handling your enquiry. Legal basis: legitimate interest or pre-contractual measures (Art. 6(1)(f) or 6(1)(b) GDPR). We recommend not sending especially sensitive personal data through this channel unless strictly necessary.
Commercial support hours: Monday to Friday, from 10:00 to 18:00 (Spanish mainland time), except on public holidays.
You may exercise your rights of access, rectification, erasure and others with Eurobest-Holding (Laszlo Demeter Demeter) — complete privacy policy or write to [email protected].
Windows application and Microsoft. If you use the Windows desktop application, part of the local operation depends on operating-system components. If native notifications are enabled, Microsoft Windows Push Notification Services (WNS) may be involved to deliver operating-system notifications; in that case, a technical notification channel or token is registered and Microsoft may process metadata necessary for delivery under its own terms. If the app is distributed through Microsoft Store or other Microsoft channels, download, updates, review, aggregated statistics or store security may be handled by Microsoft independently. More information: Microsoft Privacy Statement.
Google Calendar and Google user data. If an employee chooses to connect a Google Calendar account, Jornadapp uses only the authorised permission to create, update and delete published-shift and approved-absence events in that employee’s primary calendar. For this purpose, Jornadapp discloses to Google LLC and its affiliates, through the Google Calendar API, the minimum event data required: title, dates/times, time zone, operational description and the technical identifier needed to keep the event in sync. The integration does not list, read or import the user’s pre-existing calendar events. From Google, we receive and process OAuth access and refresh tokens, their expiry, and identifiers and technical responses for events created by Jornadapp. We keep OAuth tokens and technical synchronisation identifiers encrypted only while the connection remains active. When Google Calendar is disconnected, we delete the tokens and synchronisation references from Jornadapp and stop accessing the account; the user may also revoke access from their Google Account. Google processes data it receives under its own policy: Google Privacy Policy.
Who we share, transfer or disclose Google user data to. Jornadapp does not share, transfer or disclose data obtained from Google Workspace APIs to third parties except: (i) to Google LLC and its affiliates, to complete OAuth and perform the Google Calendar operations requested by the user; (ii) to authorised infrastructure, security and backup providers —Cloudflare, Inc. and Backblaze, Inc.— that may process limited integration data, such as OAuth codes in transit, encrypted tokens or technical identifiers, solely as processors to operate, protect and back up Jornadapp; and (iii) when strictly necessary to investigate a security incident or comply with a legal obligation. We do not disclose this data to the employer, other users, advertisers, advertising platforms, data brokers or information resellers. We also do not sell, rent or use it for advertising, profiling, creditworthiness, lending or any purpose unrelated to the requested synchronisation. Personnel, agents and contractors may access it only when indispensable to provide support with the user’s consent, protect security or comply with law, and they are bound by confidentiality and these same limitations.
Google Workspace Limited Use. Jornadapp’s use of information received from Google Workspace APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements. Jornadapp does not use data obtained from Google Workspace APIs to develop, improve or train generalized or non-personalized artificial intelligence or machine-learning models.
To provide the service, Jornadapp may use specialised technology providers for hosting, backups, secure storage, communications, monitoring and maintenance of the Platform.
Reverse geocoding (OpenStreetMap Nominatim). To display an approximate address from coordinates (latitude/longitude) when the device does not provide an address (for example on certain watches or integrations), the Platform may query the Nominatim service from OpenStreetMap. In that case, the coordinates required to obtain a textual response (address or place) are sent to this third-party service. More information: Nominatim (OpenStreetMap).
Road map matching (Geoapify Map Matching). If the company enables the routes and mileage module and the Platform has the integration configured, the server may send Geoapify (Map Matching API) a sample of route coordinates (latitude/longitude) and, when available, timestamps linked to those points, in order to snap the GPS trace to the road network and calculate a more realistic road distance. That call does not include the worker’s name, national ID or other direct identifiers; processing is limited to the technical data needed for the service. According to the Geoapify privacy policy, Geoapify is an EU business subject to the GDPR, hosts its services in EU data centres and, for API requests, may temporarily retain the request body, headers, IP address and timestamp for access control, usage counting, issue detection and performance improvement; it states that successful request data is generally kept for no longer than 24 hours to generate aggregated usage statistics. Geoapify states that it uses providers such as Cloudflare, Bunny CDN (for .eu API calls) and Hetzner when providing its API. More information: Geoapify Privacy Policy · Geoapify.
If you install the mobile application from Google Play, distribution through that store and certain processing linked to the Google ecosystem (for example application review, aggregated store statistics, malware protection or associated services such as Google Play Services where applicable) may be carried out by entities of the Google LLC group and affiliated companies, independently of the controller for the Jornadapp service. Applicable information: Google Play Developer Programme Policies · Google Privacy Policy.
If you install the mobile application from Huawei AppGallery, distribution through that store and certain processing linked to the Huawei ecosystem (such as application review, aggregated store statistics or associated services as applicable) may be carried out by entities of the Huawei group, independently of the controller for the Jornadapp service. Huawei provides information on data protection requirements and policies applicable to developers and users in its official documentation; you may consult it here: Application review guidelines and compliance (Huawei documentation) · Data protection in applications — frequently asked questions (Huawei). According to AppGallery Connect documentation, some services may process user data as data processors; the developer must indicate a data processing location so that those services process data in the chosen region, and if no location is specified for a particular service the default processing location for that service will apply. For Huawei/AppGallery Connect services configured for Jornadapp, the indicated data processing location is Germany. More information: Data storage and processing location (Huawei).
Among these providers is Backblaze, Inc., used for secure storage, backups, platform documents and clock-record integrity manifests or evidence with immutable retention or Object Lock policies. Data is hosted in a European region where the service allows it, transmitted via secure encrypted connections and stored with security measures such as encryption at rest, access control, audit logging and configurable retention policies. Relevant vendor documentation: data processing agreement — DPA (EEA/EU) · privacy policy (Backblaze).
These providers do not use the data for their own purposes, but solely to deliver the service contracted by Jornadapp, in accordance with applicable data processing or sub-processing agreements.
We retain data for as long as necessary for the purposes stated above and to comply with legal obligations (for example, working time and employment law). Clock-in and absence data is kept in accordance with applicable legislation. When you cancel your account, we will delete or anonymise data within the periods legally permitted.
Data processing agreement. Where a client company uses the Platform to manage workforce data, the client company normally acts as controller and Jornadapp as processor. The Article 28 GDPR data processing agreement and the current list of sub-processors are available to the client company on request at [email protected].
When the service ends, the client company may export its data during the contracted period. After closure, data will be deleted or anonymised, except where retention is required by law, to deal with liabilities or to preserve integrity evidence. Backups are purged in line with their technical cycles.
Contractual acceptance evidence relating to the immediate start of the service and withdrawal information will be retained for six years in order to evidence the contract and deal with legal liabilities.
You may exercise your rights against Eurobest-Holding (Laszlo Demeter Demeter):
You may send your request to [email protected]. You have the right to lodge a complaint with the competent supervisory authority (for example in Spain, AEPD).
If you are an employee of a customer company of the Platform, you may also exercise your rights through your employer (data controller for your employment data), so that they can handle the request with us where necessary.
The Platform is intended for professional use and is not directed at users under 18 years of age. We do not deliberately process minors’ data outside legally permitted scenarios. If we detect unauthorised processing, we will block it and delete it as soon as reasonably practicable.
We do not make automated decisions with legal or similarly significant effects for the data subject based solely on automated processing. Technical indicators (for example anti-fraud signals) are support tools for human review by the customer company.
We use cookies and local storage necessary for the operation of the Platform (session, language and theme preferences). We do not use third-party advertising cookies in restricted access areas.
On the first visit to public pages, if you have not yet chosen a language and no preference cookie exists (landing_lang or dashboard_lang), we may display content according to the language indicated by your browser (Accept-Language header). That data is used only for that response and is not saved in a cookie until you explicitly select a language (for example with ?lang= or the site language selector) or access the dashboard with your preference already saved.
On public pages we may use Umami, an open-source, privacy-oriented web analytics tool, for aggregated statistics (for example visit volume, pages viewed, referrer source or device type in general, non-identifying terms). According to the project documentation, it does not use measurement cookies in the browser for that purpose and does not sell visitor data for advertising; processing may take place on self-hosted or third-party infrastructure depending on the data controller’s configuration. Privacy and data information from the project: Privacy policy (Umami).
The installable web application (PWA) may use a service worker, browser cache and persistent storage (for example IndexedDB, localStorage) for performance, preferences and an offline clock-in queue. You can delete this data from your browser settings (site data).
Native mobile applications may use the system’s local storage for the same offline queue of pending clock-ins until a network connection is available; managing or deleting app data depends on the operating system and the application settings.
Depending on the features your company and you use, the Platform may request or use system capabilities. Denying permission may prevent or limit GPS, QR or NFC clock-in, notifications or capturing photos for expenses, per diem claims or internal requests with attachments.
Permissions are managed from the operating system settings (Android, iOS, etc.) or from the browser settings (site, camera, location, notifications).
We apply appropriate technical and organisational measures to protect your personal data, including restricted access controls, encryption in transit and at rest where applicable, passwords protected with a one-way hash and two-factor authentication (2FA) where that feature has been enabled on your account.
We may update this privacy policy from time to time for legal, technical or operational reasons. Relevant changes will be communicated by means of a notice on the Platform or by email to registered users. The date of the last update is indicated at the bottom of this page.
Last updated: 13/08/2026