1. Data controller
The controller for the processing of personal data is Eurobest-Holding (Laszlo Demeter Demeter) (Tax ID 32991314E), with registered address at C/ Sierra de las Nieves, nº 1, 1ºB, 41440 - Lora del Río, España.
You can contact us at: [email protected].
For matters relating to data protection you may contact our Data Protection Officer (DPO) at: [email protected].
2. Purpose and legal basis
We process personal data in Jornadapp to:
- Platform and contractual relationship management: registration of companies and users; authentication (including sign-in with Google or Microsoft (OAuth) and, where applicable, with digital certificate); employee management (onboarding, editing, sending credentials by email, assignment of schedules and geofence zones, optional employee photo); working time records with geolocation (clock-in, clock-out and breaks); management of absences and holidays (requests, approvals, balances and company absence policies); generation of reports (CSV, PDF, payroll, SAGE); billing and subscriptions (Stripe, PayPal) and, where applicable, integration with external billing or accounting systems; clock-in reminders by email; configuration of mandatory breaks, projects and two-factor authentication (2FA). Legal basis: contract performance (Art. 6(1)(b) GDPR).
- Live tracking (where the customer has subscribed to this paid extra): map view of workers’ location for mobile teams, fleets, delivery or field services outside the workplace when the company enables it and the employee is clocked in as working. Sending stops when that condition no longer applies (for example, break or clock-out), and the live position is deleted when the employee clocks out. Service legal basis: contract performance (Art. 6(1)(b) GDPR); the customer company, as controller in respect of its workforce, must determine and document its own legal basis and specific employment purpose.
- Push communications and notifications: sending reminders and notifications in the mobile application (via Firebase Cloud Messaging or other technical means). Legal basis: contract performance or legitimate interest (Art. 6(1)(b) or 6(1)(f) GDPR).
- Legal compliance: retention of working time control records and data necessary for applicable employment legislation. Legal basis: legal obligation (Art. 6(1)(c) GDPR).
- Time-record corrections and worker confirmation: management of missed-clock incidents, worker requests and correction proposals created by the company, including worker confirmation, rejection or alternative proposal, with traceability of user, date, time, IP address, device/browser where applicable, reason and comments. Legal basis: contract performance, legal obligations in employment matters and legitimate interest in resolving working-time incidents and disputes (Article 6.1.b, 6.1.c and 6.1.f GDPR/UK GDPR as applicable).
- Clock-in integrity evidence: generation of technical integrity events for each clock-in, cryptographic fingerprints, per-company hash chaining, daily or batched manifests, sealing to external storage with immutable retention, operational audit records and consistency checks. Legal basis: contract performance, legal obligation and/or legitimate interest in service security and integrity.
- Field safety (if enabled by the company): recording help alerts during an active work session, with time, employee, location where available, accuracy, note, battery level where available and basic device details, for operational coordination, incident response and safety of mobile teams. Legal basis: contract performance and/or legitimate interest documented by the customer company (Art. 6(1)(b) and/or 6(1)(f) GDPR).
- Routes and mileage (if enabled by the company): recording start, intermediate points and end of work routes to calculate mileage, justify business travel, coordinate field services and, where applicable, handle allowances or expenses. Background location may be used while a route is active and a work session is open. Legal basis: contract performance and/or legitimate interest or applicable employment/tax obligation as determined by the customer company (Art. 6(1)(b), 6(1)(f) and/or 6(1)(c) GDPR).
- Windows application: desktop access to the Platform through a native Windows application, with secure session handling, server synchronisation, local queueing of operations where applicable and operational notifications from the company or the system. Legal basis: contract performance and legitimate interest in service security and continuity (Art. 6(1)(b) and 6(1)(f) GDPR).
- Commercial communications and service improvement: sending information about the service, updates or surveys, if you have given us your consent or we have a legitimate interest. Legal basis: consent or legitimate interest (Art. 6(1)(a) or 6(1)(f) GDPR).
- QR or NFC clock-in (where the company enables it): validation of the terminal or tag and recording of the clock event; on the web, the camera may be used solely to read the QR code. Legal basis: contract performance (Art. 6(1)(b) GDPR).
- Employment documents: custody of files uploaded by the company, assignment to employees and, where applicable, capture of signature (handwritten or similar) and recording of the signing date. Legal basis: contract performance or legal obligation (Art. 6(1)(b) or 6(1)(c) GDPR).
- External calendar (optional): synchronisation or display of absences/events via OAuth with Google or Microsoft and/or an iCal-style subscription link, with processing of the necessary tokens. Legal basis: contract performance (Art. 6(1)(b) GDPR).
- Webhooks and HTTP integrations (configured by the business customer): automatic sending of events (for example creation of clock-in records) to the URLs indicated by the customer data controller. Legal basis: contract performance (Art. 6(1)(b) GDPR).
- Technical anti-fraud signals: storing scores or flags derived from the device or clock-in context (for example location accuracy, consistency between records, clock skew) to support auditing; they are technical indicators and do not by themselves constitute proof of fraud. Legal basis: legitimate interest or contract performance (Art. 6(1)(f) or 6(1)(b) GDPR).
- Wellbeing / emotional pulse check-in (if the company enables it): collection of a mood or wellbeing rating; the employer dashboard shows aggregated statistics; at a technical level the response may be associated with the employee to prevent duplicate submissions on the same day. Legal basis: contract performance or legitimate interest as applicable (Art. 6(1)(b) or 6(1)(f) GDPR).
- Cryptographic device binding (native app): where the company configures or requires stronger clock-in security, the application may create on the phone or compatible watch a key pair protected by the operating system (Android Keystore on Android/Wear OS or Apple’s secure keychain on iOS). The system may issue a digital certificate associated with that key on the device itself; on the server only the public key (and derived data such as a fingerprint of the same) is stored—not the private key—to recognise that installation reliably versus other accounts or terminals. Clock events may be accompanied by a digital signature generated on the device over information agreed with the platform (including a one-time nonce provided by the server), for integrity and to reduce impersonation. Legal basis: contract performance and legitimate interest in the security of processing (Art. 6(1)(b) and 6(1)(f) GDPR).
- Offline operation: the installable web application (PWA) and native mobile applications (Android/Wear OS/iOS) may temporarily store clock-ins or pending operations on the device until connectivity is restored and they can synchronise with the server. Legal basis: contract performance (Art. 6(1)(b) GDPR).
- Public contact and commercial support: handling enquiries by email, telephone and WhatsApp, including from existing customers who use those channels. Legal basis: legitimate interest or pre-contractual measures (Art. 6(1)(f) or 6(1)(b) GDPR).
Workplace geolocation and AEPD criteria in Spain. The AEPD guide on data protection in employment relationships and Article 90 of the LOPDGDD allow data obtained through geolocation systems to be processed for employment control functions within the legal framework of Article 20.3 of the Workers’ Statute, subject to limits of dignity, proportionality, minimisation and prior information. For this reason, Jornadapp live tracking is designed as an optional tool for activities in mobility or fleets and not as general surveillance: it only accepts positions when the extra is subscribed, the company has enabled it and the employee is clocked in as working; the employee keeps the location notice/service on the device where applicable; and live location must not be sent outside working hours. The customer company must inform workers and, where applicable, their representatives in advance in an express, clear and unequivocal manner; justify the purpose (for example route coordination, safety, planning or verification of services outside the workplace); limit access and retention; assess whether a data protection impact assessment is appropriate; and not require the use of personal devices where work equipment should legally be provided.
Workplace geolocation and CNPD criteria in Portugal. The CNPD Deliberation no. 7680/2014 on geolocation in the employment context, Article 17 of the Portuguese Labour Code (remote monitoring) and Law no. 58/2019 (GDPR) require a defined purpose, proportionality, minimisation and prior written information to workers and, where applicable, their representatives; geolocation is only admissible for specific legitimate purposes (for example safety, fleet management or coordination of external services), not as permanent surveillance or indiscriminate performance monitoring. Jornadapp live tracking is optional: it only accepts positions with the extra subscribed, the company activated and the worker registered as working; no live location is sent outside working hours; and the customer company must justify the purpose, limit access and retention, assess a data protection impact assessment where appropriate and not impose personal devices where work equipment should be provided.
Workplace geolocation and ICO guidance in the United Kingdom. Under the UK GDPR and the Data Protection Act 2018, and in accordance with the ICO guidance on monitoring workers (including location data), the controller must identify a lawful basis, inform with transparency, ensure that monitoring is proportionate and avoid blanket surveillance; real-time location requires documented necessity and must not continue outside working hours without justification. Jornadapp live tracking is designed as an optional tool for mobility or fleets: only with the extra subscribed, activation by the company and the worker in a working state; no transmission outside working hours; with a duty of prior notice, limitation of access and retention, and a data protection impact assessment where appropriate.
Location accuracy in field operations. The optional field safety and routes/mileage modules use the position provided by the device (GPS, network or system estimates). Accuracy may vary by handset, permissions, coverage, battery use or background operation. Routes and distances shown are indicative estimates for work coordination; minor errors in mileage calculation or map display may occur without this alone constituting a breach of service. The customer company should critically assess such data before taking employment, financial or disciplinary decisions based solely on them.
3. Data we collect
- Manager/company accounts: name, email, password protected with a one-way hash, company name, tax ID, address; payment data where applicable (managed by providers such as Stripe/PayPal).
- Employees: name, surname, email, password (hashed), national ID/tax number, social security number, company to which they belong; where applicable employee photo, geofence data (centre and radius of the permitted zone) and schedules; theme preferences (light/dark).
- Clock-in/out records: date and time of clock-in, clock-out and breaks; location (latitude, longitude and address) at the moment of the clock event.
- Live tracking: if the company subscribes to and enables it, the employee’s latest live position while clocked in as working, including latitude, longitude, address where available, accuracy, estimated speed, time of last update and, in compatible native apps, technical metadata about the device or installation sending the position. The live-position table is updated with the latest available location and is deleted when the employee clocks out.
- Time-record corrections: existing or empty original value, proposed value, affected worker, manager proposing or reviewing it, worker response (confirmation, rejection or alternative proposal), timestamps, IP address, browser/device where applicable, reason and comments.
- Field safety: I need help alert, date and time, employee, company, location and accuracy where provided by the device, note, battery level where available, alert status and basic device details.
- Routes and mileage: active or completed route, start and end date/time, employee, company, start/end location, intermediate points with accuracy, accumulated distance and optional notes.
- Windows app: technical installation or device identifiers, application version, Windows platform, notification registration status, Windows Push Notification Services (WNS) channel or token when the user allows notifications, technical error or synchronisation messages, local preferences and data temporarily stored in the app itself for session, performance and offline queue purposes. The Windows app does not request or use the microphone.
- Absence and holiday requests: dates, type of absence, status (pending, approved, rejected) and data associated with the company’s absence policies.
- Reports and exports: generated reports (CSV, PDF) may contain employee and clock-in data; where digital signature is used for PDFs, certificate configuration data is stored on the Provider’s server according to the settings configured by the administrator.
- Technical use and security: IP addresses, browser type, sessions and cookies necessary for operation and security (session, language and theme preferences); on the mobile application, tokens for push notifications (Firebase Cloud Messaging on Android and Apple Push Notification service (APNs) on iOS where applicable); when enabled, tokens or results of environment integrity validation (Play Integrity API on Android devices with Google Play Services installed from Google Play; in other environments a different policy may apply according to server configuration); and the device’s public key associated with the certificate generated on the phone, plus digital signatures verified on the server on clock-in payloads where the company enables this measure (the private key remains only on the device). We do not use third-party advertising cookies in restricted access areas.
- QR, NFC and terminals: QR terminal tokens or codes, NFC tag identifiers and technical data associated with the clock-in mode chosen by the company.
- Documents: metadata (title, type, recipients), uploaded files, signature image or data where applicable, and timestamps of signing or consultation.
- Calendar: OAuth or refresh tokens for Google/Microsoft and, if used, per-employee iCal feed subscription token.
- Webhooks: destination URL, HMAC signing secret, subscribed event types and technical delivery information (attempts, response codes, error messages) for operation and support.
- Anti-fraud: score, technical flags and reference to the related clock-in record.
- Wellbeing: mood or wellbeing score, date and link to company (and technically to the employee for the daily limit).
- Offline queue: pending clock-ins or operations stored locally in the browser/PWA or in the native application until synchronisation with the server.
- Commercial contact: name, email, phone number, company or subject of the message and any other data you voluntarily provide when writing to us, calling +34 854 94 30 00 (extension 2) or contacting us on WhatsApp at the same number; messaging metadata where applicable.
Commercial contact
In addition to the channels available within the platform for registered business customers, we provide contact means for commercial or technical enquiries prior to signing a contract and for existing customers who prefer telephone, WhatsApp or email.
Email
You may write to us at [email protected]. We process the data you include in your message (name, email, phone, company, subject, etc.) only to handle your enquiry. Legal basis: legitimate interest or pre-contractual measures (Art. 6(1)(f) or 6(1)(b) GDPR).
Telephone
You may call us on +34 854 94 30 00 (extension 2), including if you are already a customer. If you provide personal data during the call (for example your name or email so we can return your call), we use it only to handle your request. Legal basis: legitimate interest or pre-contractual measures (Art. 6(1)(f) or 6(1)(b) GDPR).
WhatsApp
You may write to us on WhatsApp at +34 854 94 30 00, including if you are already a customer. Processing of messages and associated metadata (including your telephone number) is also governed by Meta/WhatsApp terms as the messaging provider, in addition to our purpose of handling your enquiry. Legal basis: legitimate interest or pre-contractual measures (Art. 6(1)(f) or 6(1)(b) GDPR). We recommend not sending especially sensitive personal data through this channel unless strictly necessary.
Commercial support hours: Monday to Friday, from 10:00 to 18:00 (Spanish mainland time), except on public holidays.
You may exercise your rights of access, rectification, erasure and others with Eurobest-Holding (Laszlo Demeter Demeter) — complete privacy policy or write to [email protected].
4. Recipients and transfers
Windows application and Microsoft. If you use the Windows desktop application, part of the local operation depends on operating-system components. If native notifications are enabled, Microsoft Windows Push Notification Services (WNS) may be involved to deliver operating-system notifications; in that case, a technical notification channel or token is registered and Microsoft may process metadata necessary for delivery under its own terms. If the app is distributed through Microsoft Store or other Microsoft channels, download, updates, review, aggregated statistics or store security may be handled by Microsoft independently. More information: Microsoft Privacy Statement.
To provide the service, Jornadapp may use specialised technology providers for hosting, backups, secure storage, communications, monitoring and maintenance of the Platform.
Reverse geocoding (OpenStreetMap Nominatim). To display an approximate address from coordinates (latitude/longitude) when the device does not provide an address (for example on certain watches or integrations), the Platform may query the Nominatim service from OpenStreetMap. In that case, the coordinates required to obtain a textual response (address or place) are sent to this third-party service. More information: Nominatim (OpenStreetMap).
Road map matching (Geoapify Map Matching). If the company enables the routes and mileage module and the Platform has the integration configured, the server may send Geoapify (Map Matching API) a sample of route coordinates (latitude/longitude) and, when available, timestamps linked to those points, in order to snap the GPS trace to the road network and calculate a more realistic road distance. That call does not include the worker’s name, national ID or other direct identifiers; processing is limited to the technical data needed for the service. According to the Geoapify privacy policy, Geoapify is an EU business subject to the GDPR, hosts its services in EU data centres and, for API requests, may temporarily retain the request body, headers, IP address and timestamp for access control, usage counting, issue detection and performance improvement; it states that successful request data is generally kept for no longer than 24 hours to generate aggregated usage statistics. Geoapify states that it uses providers such as Cloudflare, Bunny CDN (for .eu API calls) and Hetzner when providing its API. More information: Geoapify Privacy Policy · Geoapify.
If you install the mobile application from Google Play, distribution through that store and certain processing linked to the Google ecosystem (for example application review, aggregated store statistics, malware protection or associated services such as Google Play Services where applicable) may be carried out by entities of the Google LLC group and affiliated companies, independently of the controller for the Jornadapp service. Applicable information: Google Play Developer Programme Policies · Google Privacy Policy.
If you install the mobile application from Huawei AppGallery, distribution through that store and certain processing linked to the Huawei ecosystem (such as application review, aggregated store statistics or associated services as applicable) may be carried out by entities of the Huawei group, independently of the controller for the Jornadapp service. Huawei provides information on data protection requirements and policies applicable to developers and users in its official documentation; you may consult it here: Application review guidelines and compliance (Huawei documentation) · Data protection in applications — frequently asked questions (Huawei). According to AppGallery Connect documentation, some services may process user data as data processors; the developer must indicate a data processing location so that those services process data in the chosen region, and if no location is specified for a particular service the default processing location for that service will apply. For Huawei/AppGallery Connect services configured for Jornadapp, the indicated data processing location is Germany. More information: Data storage and processing location (Huawei).
Among these providers is Backblaze, Inc., used for secure storage, backups, platform documents and clock-record integrity manifests or evidence with immutable retention or Object Lock policies. Data is hosted in a European region where the service allows it, transmitted via secure encrypted connections and stored with security measures such as encryption at rest, access control, audit logging and configurable retention policies. Relevant vendor documentation: data processing agreement — DPA (EEA/EU) · privacy policy (Backblaze).
These providers do not use the data for their own purposes, but solely to deliver the service contracted by Jornadapp, in accordance with applicable data processing or sub-processing agreements.
5. Retention
We retain data for as long as necessary for the purposes stated above and to comply with legal obligations (for example, working time and employment law). Clock-in and absence data is kept in accordance with applicable legislation. When you cancel your account, we will delete or anonymise data within the periods legally permitted.
Data processing agreement. Where a client company uses the Platform to manage workforce data, the client company normally acts as controller and Jornadapp as processor. The Article 28 GDPR data processing agreement and the current list of sub-processors are available to the client company on request at [email protected].
When the service ends, the client company may export its data during the contracted period. After closure, data will be deleted or anonymised, except where retention is required by law, to deal with liabilities or to preserve integrity evidence. Backups are purged in line with their technical cycles.
Contractual acceptance evidence relating to the immediate start of the service and withdrawal information will be retained for six years in order to evidence the contract and deal with legal liabilities.
Clock-in integrity: events, manifests, audit records and sealed evidence are retained for the periods needed for employment, tax, audit, claims-defence and service-security purposes. Sealed copies with immutable retention cannot be modified until their technical retention period expires.
6. Your rights
You may exercise your rights against Eurobest-Holding (Laszlo Demeter Demeter):
- Access: obtain information on whether we process your data and a copy of it.
- Rectification: correct inaccurate or incomplete data.
- Erasure: request deletion where data is no longer necessary, you withdraw consent or object to processing, unless we must retain it due to a legal obligation.
- Restriction: request that processing be restricted in the cases provided for by law.
- Portability: receive your data in a structured, commonly used and machine-readable format where processing is based on contract or consent.
- Objection: object to processing that is based on legitimate interest.
You may send your request to [email protected]. You have the right to lodge a complaint with the competent supervisory authority (for example in Spain, AEPD).
If you are an employee of a customer company of the Platform, you may also exercise your rights through your employer (data controller for your employment data), so that they can handle the request with us where necessary.
7. Minors
The Platform is intended for professional use and is not directed at users under 18 years of age. We do not deliberately process minors’ data outside legally permitted scenarios. If we detect unauthorised processing, we will block it and delete it as soon as reasonably practicable.
8. Automated decision-making and profiling
We do not make automated decisions with legal or similarly significant effects for the data subject based solely on automated processing. Technical indicators (for example anti-fraud signals) are support tools for human review by the customer company.
9. Cookies and similar technologies
We use cookies and local storage necessary for the operation of the Platform (session, language and theme preferences). We do not use third-party advertising cookies in restricted access areas.
On the first visit to public pages, if you have not yet chosen a language and no preference cookie exists (landing_lang or dashboard_lang), we may display content according to the language indicated by your browser (Accept-Language header). That data is used only for that response and is not saved in a cookie until you explicitly select a language (for example with ?lang= or the site language selector) or access the dashboard with your preference already saved.
On public pages we may use Umami, an open-source, privacy-oriented web analytics tool, for aggregated statistics (for example visit volume, pages viewed, referrer source or device type in general, non-identifying terms). According to the project documentation, it does not use measurement cookies in the browser for that purpose and does not sell visitor data for advertising; processing may take place on self-hosted or third-party infrastructure depending on the data controller’s configuration. Privacy and data information from the project: Privacy policy (Umami).
The installable web application (PWA) may use a service worker, browser cache and persistent storage (for example IndexedDB, localStorage) for performance, preferences and an offline clock-in queue. You can delete this data from your browser settings (site data).
Native mobile applications may use the system’s local storage for the same offline queue of pending clock-ins until a network connection is available; managing or deleting app data depends on the operating system and the application settings.
10. Browser and device permissions (web and app)
Depending on the features your company and you use, the Platform may request or use system capabilities. Denying permission may prevent or limit GPS, QR or NFC clock-in, notifications or capturing photos for expenses, per diem claims or internal requests with attachments.
- Location / GPS: precise position at clock-in, geofencing and, if subscribed to and enabled by the company, live tracking only while the employee is clocked in as working.
- Field safety and routes: if the company enables these modules, location may be used to send help alerts and to record mileage-route points. For active routes, the mobile app may use background location while the work session remains open and the route has not been stopped.
- Windows / desktop application: may use local storage, network access and system notifications through WNS where enabled. On compatible Windows computers or tablets, the camera may be used only for the functions already described (for example QR codes or attachments/photos if the company enables them). The application does not request or use microphone permission.
- Camera: in the browser or app, live capture to read terminal QR codes (clock-in); additionally, where the company has enabled the relevant modules, to take photos or select images when submitting expenses and per diem claims (e.g. receipts) or when creating internal requests with attachments. Images you submit are associated with those records on the Platform according to your company’s configuration.
- NFC (Android or compatible devices): reading of tags associated with clock-in on enabled terminals.
- Notifications: notices via Firebase Cloud Messaging on Android and, on iOS where applicable, Apple Push Notification service (APNs); in compatible browsers, web notifications for reminders or company messages.
- Network and internet: sending and receiving clock-ins, documents, webhooks and synchronisation of the offline queue.
- Local storage: see section 9 (cookies and similar technologies); used for session, preferences and offline queue in the browser/PWA and, in the native application, local storage for the offline queue where applicable.
- Environment integrity (Android): where applicable (for example app installed from Google Play with Google Play Services), communication with Google Play Integrity to verify that the application runs in an expected environment.
- Device certificate and keys (native Android/iOS app): where the company enables strengthened clock-in security, the app uses the system security APIs to create a non-exportable key pair and the associated certificate on the phone itself; only the public key and signatures on clock-in requests are transmitted to the server, not the private key (see section 2).
Permissions are managed from the operating system settings (Android, iOS, etc.) or from the browser settings (site, camera, location, notifications).
11. Security
We apply appropriate technical and organisational measures to protect your personal data, including restricted access controls, encryption in transit and at rest where applicable, passwords protected with a one-way hash and two-factor authentication (2FA) where that feature has been enabled on your account.
12. Changes
We may update this privacy policy from time to time for legal, technical or operational reasons. Relevant changes will be communicated by means of a notice on the Platform or by email to registered users. The date of the last update is indicated at the bottom of this page.