staffer.space

Privacy policy

Translation provided for convenience. The Spanish version is the legally binding one — in case of any discrepancy, it prevails.
Read in Spanish

1. Data controller

  • Controller: DREAMS COME TRUE BCN, S.L.
  • Tax ID (NIF): B44788875
  • Address: c/ Muntaner 339, 3-2, 08021 Barcelona, España
  • Data protection contact: hello@staffer.space

2. Our two roles

Staffer.Space processes personal data in two distinct capacities, and it is worth telling them apart.

As controller, we process the data of people who create an account and contract the service, of those who write to us, and the technical browsing data of this website.

As processor, we handle the data each client company enters into its workspace about its own team — shifts, check-ins, absences, pay, professional development. In these cases the controller is the client company, which decides what data is processed and for what purpose; we process it only on their instructions and under the article 28 GDPR processing agreement that forms part of the Terms of Service.

If you work at a company that uses Staffer and want to exercise your rights over that data, you should contact your company. We will help route the request, but we cannot decide on it.

3. What data we process and why

PurposeDataLegal basis
Creating and maintaining your account and workspaceName, email, phone, name of the business and its venuesPerformance of a contract (art. 6.1.b GDPR)
Verifying your identity at sign-up and sign-in through one-time codes sent by SMS or emailPhone, emailPerformance of a contract (art. 6.1.b)
Billing the service and meeting tax and accounting obligationsBilling details, recorded hours in aggregate, invoice historyLegal obligation (art. 6.1.c) and performance of a contract
Answering your enquiries and providing supportThe data you provide in the communicationPerformance of a contract and legitimate interest (art. 6.1.f)
Informing you of service changes that affect youEmailPerformance of a contract
Sending you commercial communications about StafferEmailLegitimate interest with respect to customers (art. 6.1.f), with objection at any time; consent in all other cases (art. 6.1.a)
Measuring use of the website in order to improve itBrowsing data collected through analytics cookies (page views, source of the visit, device type)Consent (art. 6.1.a) — see the Cookie Policy
Keeping the service secure and preventing fraudulent useAccess logs, IP addressLegitimate interest (art. 6.1.f)

We do not use advertising cookies and do not share data with advertising networks. We do use an analytics tool, whose use depends on your consent (see the Cookie Policy).

We do not make automated decisions with legal or similarly significant effects on people. The product’s intelligence features explain and suggest; decisions about people are made by people.

We do not build employability profiles or overall scores of people.

4. Third-party data you provide to us

If, while using Staffer, you enter data about other people — your team, your collaborators — it is up to you to inform them that their data will be processed in the platform and for what purposes, and to have a legal basis for doing so.

5. How long we keep data

We keep your account data while the relationship is in force. Once it ends:

  • Workspace data is kept for 30 days so that it can be recovered, and after that period is deleted or irreversibly anonymised.
  • Billing data is kept for the periods required by tax and commercial law (generally six years under the Commercial Code and four years for tax purposes).
  • Records needed to demonstrate compliance with legal obligations are kept for as long as liability may arise.

6. Who else has access to the data

We do not sell personal data and do not transfer it to third parties for commercial purposes.

To provide the service we rely on suppliers acting as processors, under a contract compliant with article 28 GDPR:

SupplierServicePlace of processing
Railway Corp. (USA)Hosting of the application and the databaseEuropean Union (Amsterdam)
GcoreContent delivery networkEuropean Union
Namecheap, Inc. (USA)Corporate emailUnited States
Twilio Inc. (USA)Sending SMS verification messagesUnited States
Google Ireland Ltd. / Google LLCWebsite usage analytics (Google Analytics 4)European Union and United States

We also disclose data to public authorities where there is a legal obligation to do so.

6.1 Optional integrations

Staffer lets the client company enable an integration with Telegram to receive notifications about its team. This integration is off by default: it only works if the company decides to enable it.

When it is active, the data contained in those notifications is sent to Telegram, a service provided by an entity located outside the European Economic Area which does not act as a processor on behalf of Staffer, but as a messaging service chosen by the client company. The decision to enable it, and informing the people affected, are the responsibility of the client company as controller.

7. International transfers

Some of our suppliers are entities established in the United States. Each transfer relies on appropriate safeguards under Chapter V of the GDPR:

  • Railway Corp. — standard contractual clauses approved by the European Commission, incorporated in its data processing addendum. The application and the database are hosted in the European Union region (Amsterdam).
  • Twilio Inc. — self-certification under the EU-US Data Privacy Framework, approved binding corporate rules (BCR) and, subsidiarily, standard contractual clauses.
  • Namecheap, Inc. — standard contractual clauses (Module Two, controller to processor) incorporated in full in its data processing addendum.
  • Google LLC — certified under the EU-US Data Privacy Framework and, additionally, standard contractual clauses incorporated in the Google Analytics data processing terms.

Gcore provides its service from the European Union, so no international transfer takes place.

You can ask us for further information about these safeguards by writing to hello@staffer.space.

8. Your rights

You may at any time exercise your rights of access, rectification, erasure, objection, restriction of processing and portability, as well as withdraw any consent given, without affecting the lawfulness of processing before withdrawal.

To do so, write to hello@staffer.space stating which right you wish to exercise. We may ask you to prove your identity.

If you believe we have not handled your request properly, you may lodge a complaint with the Spanish Data Protection Agency (www.aepd.es, c/ Jorge Juan 6, 28001 Madrid).

9. Security

We apply appropriate technical and organisational measures to protect data against destruction, loss, alteration and unauthorised access. Access to information inside each workspace is limited by a permissions system: each person sees only what their company has given them access to.

10. Changes to this policy

We may update this policy to reflect changes in law or in the service. We publish the version in force on this page, stating the date of the last update, and communicate material changes through our usual contact channels.

Last updated: 4 September 2026