Staffarmor™ Customer and Administrator Terms
Controller, employment-law and liability principles governing the relationship between SBSA Laboratory OÜ and the Customer.
1. Purpose
These terms set out core responsibility, data-protection and system-use principles between SBSA Laboratory OÜ and the Customer. They do not replace the service agreement, proposal, data-processing agreement, SLA or other contractual schedules.
2. Customer declarations
- the Customer is authorised to use Staffarmor™ and invite users
- it has a lawful basis for employee and other personal data
- it provides required privacy information and supports data-subject rights
- administrators are duly authorised
- only lawful, accurate and necessary data and documents are uploaded
3. Exclusive employment-law responsibility
The Customer is solely responsible for employment terms, daily and weekly hours, schedules, weekend and holiday work, breaks, overtime, leave, night work, site rules, payroll, tax, social-security obligations and every employment decision.
Staffarmor™ provides configurable tools and records but does not certify compliance with any country, region, collective agreement or sector rule.
4. Country, language and legal compliance
The Customer must account for the country of operation, work location, employment relationship, mandatory language rules, national and regional labour law, collective agreements, sector rules and internal policies. Multilingual interfaces and templates are not legal advice.
5. Controller and processor roles
For employee and employment data, the Customer is controller, SBSA Laboratory OÜ is processor acting on instructions, and the infrastructure provider may be a sub-processor. The Customer is responsible for legal basis, minimisation, retention, access permissions and data-subject requests.
6. Administrator access
Administrator access may be granted only to authorised individuals through personal accounts and only to the extent required for their duties. Shared administrator accounts are prohibited. Administrator actions are deemed Customer actions unless unauthorised access is proven.
7. Business continuity
The Customer must maintain a fallback procedure for temporary service unavailability, including temporary time recording, continuation of work, later corrections and compliance records. A Staffarmor™ outage alone is not a reason to suspend work unless the Customer or mandatory safety rules require otherwise.
8. Limitation of liability
To the fullest extent permitted by law, SBSA Laboratory OÜ is not liable for unlawful or incorrect Customer settings, employment or payroll decisions, unlawful schedules, Customer documents, incorrect permissions, misuse of exports, missing fallback procedures, or external network, device or provider failures.
Subject to mandatory law, SBSA Laboratory OÜ’s aggregate contractual liability is limited to the Staffarmor™ service fees actually paid by the Customer during the 12 months preceding the event giving rise to the claim.
The limitation does not apply where mandatory law prohibits it, including intentional misconduct, gross negligence, personal injury or mandatory data-protection liability.
9. Customer-caused claims
The Customer is responsible for authority, employee or third-party claims arising from its unlawful processing, employment settings, documents, unauthorised uploads, administrator omissions or breach of applicable labour law. This does not exclude SBSA Laboratory OÜ’s liability for its own breach.
10. Audit evidence
The system may record the accepting user, role, tenant, language, version, time, content SHA-256 hash, session, IP security fingerprint and administrative actions for security, accountability and dispute reconstruction.
11. User information and training
The Customer must ensure that users receive appropriate privacy information, usage rules, employment contacts, fallback procedures and necessary training.
12. Authority to accept
Only a legal representative, duly authorised person or administrator authorised under the Customer’s internal rules may accept these terms. If authority is lacking, acceptance must be stopped.
13. Retention principles
Default retention and deletion principles follow relevant EU rules and requirements of competent Estonian authorities. Specific employment retention periods are determined by the Customer under applicable local law.
