Staffer.Space processes personal data in two distinct capacities, and it is worth telling them apart.
As controller, we process the data of people who create an account and contract the service, of those who write to us, and the technical browsing data of this website.
As processor, we handle the data each client company enters into its workspace about its own team — shifts, check-ins, absences, pay, professional development. In these cases the controller is the client company, which decides what data is processed and for what purpose; we process it only on their instructions and under the article 28 GDPR processing agreement that forms part of the Terms of Service.
If you work at a company that uses Staffer and want to exercise your rights over that data, you should contact your company. We will help route the request, but we cannot decide on it.
| Purpose | Data | Legal basis |
|---|---|---|
| Creating and maintaining your account and workspace | Name, email, phone, name of the business and its venues | Performance of a contract (art. 6.1.b GDPR) |
| Verifying your identity at sign-up and sign-in through one-time codes sent by SMS or email | Phone, email | Performance of a contract (art. 6.1.b) |
| Billing the service and meeting tax and accounting obligations | Billing details, recorded hours in aggregate, invoice history | Legal obligation (art. 6.1.c) and performance of a contract |
| Answering your enquiries and providing support | The data you provide in the communication | Performance of a contract and legitimate interest (art. 6.1.f) |
| Informing you of service changes that affect you | Performance of a contract | |
| Sending you commercial communications about Staffer | Legitimate interest with respect to customers (art. 6.1.f), with objection at any time; consent in all other cases (art. 6.1.a) | |
| Measuring use of the website in order to improve it | Browsing data collected through analytics cookies (page views, source of the visit, device type) | Consent (art. 6.1.a) — see the Cookie Policy |
| Keeping the service secure and preventing fraudulent use | Access logs, IP address | Legitimate interest (art. 6.1.f) |
We do not use advertising cookies and do not share data with advertising networks. We do use an analytics tool, whose use depends on your consent (see the Cookie Policy).
We do not make automated decisions with legal or similarly significant effects on people. The product’s intelligence features explain and suggest; decisions about people are made by people.
We do not build employability profiles or overall scores of people.
If, while using Staffer, you enter data about other people — your team, your collaborators — it is up to you to inform them that their data will be processed in the platform and for what purposes, and to have a legal basis for doing so.
We keep your account data while the relationship is in force. Once it ends:
We do not sell personal data and do not transfer it to third parties for commercial purposes.
To provide the service we rely on suppliers acting as processors, under a contract compliant with article 28 GDPR:
| Supplier | Service | Place of processing |
|---|---|---|
| Railway Corp. (USA) | Hosting of the application and the database | European Union (Amsterdam) |
| Gcore | Content delivery network | European Union |
| Namecheap, Inc. (USA) | Corporate email | United States |
| Twilio Inc. (USA) | Sending SMS verification messages | United States |
| Google Ireland Ltd. / Google LLC | Website usage analytics (Google Analytics 4) | European Union and United States |
We also disclose data to public authorities where there is a legal obligation to do so.
Staffer lets the client company enable an integration with Telegram to receive notifications about its team. This integration is off by default: it only works if the company decides to enable it.
When it is active, the data contained in those notifications is sent to Telegram, a service provided by an entity located outside the European Economic Area which does not act as a processor on behalf of Staffer, but as a messaging service chosen by the client company. The decision to enable it, and informing the people affected, are the responsibility of the client company as controller.
Some of our suppliers are entities established in the United States. Each transfer relies on appropriate safeguards under Chapter V of the GDPR:
Gcore provides its service from the European Union, so no international transfer takes place.
You can ask us for further information about these safeguards by writing to hello@staffer.space.
You may at any time exercise your rights of access, rectification, erasure, objection, restriction of processing and portability, as well as withdraw any consent given, without affecting the lawfulness of processing before withdrawal.
To do so, write to hello@staffer.space stating which right you wish to exercise. We may ask you to prove your identity.
If you believe we have not handled your request properly, you may lodge a complaint with the Spanish Data Protection Agency (www.aepd.es, c/ Jorge Juan 6, 28001 Madrid).
We apply appropriate technical and organisational measures to protect data against destruction, loss, alteration and unauthorised access. Access to information inside each workspace is limited by a permissions system: each person sees only what their company has given them access to.
We may update this policy to reflect changes in law or in the service. We publish the version in force on this page, stating the date of the last update, and communicate material changes through our usual contact channels.