Staffarmor™ Privacy Notice
Information about personal data processed in Staffarmor™, controller and processor roles, infrastructure and data subject rights.
1. Purpose of this notice
This notice explains which personal data may be processed when Staffarmor™ is used, why it is processed, who may access it and which rights are available to the data subject. Staffarmor™ is developed and technically operated by SBSA Laboratory OÜ. The employer or organisation providing access is referred to as the Customer.
2. Roles of the parties
For employee, working-time, attendance, scheduling, leave, document and employment-related data, the Customer is normally the controller because it determines the purposes, legal basis, access rules and retention periods.
SBSA Laboratory OÜ processes such data on the documented instructions of the Customer and acts as processor. For its own account-security, access-log, support, abuse-prevention and legal-claims data, SBSA Laboratory OÜ may act as an independent controller.
3. SBSA Laboratory OÜ details
Company: SBSA Laboratory OÜ
Registry code: 16863186
EU VAT number: EE102684175
Registered office: Harju maakond, Kuusalu vald, Pudisoo küla, Männimäe/1, 74626, Estonia
Privacy, complaint and deletion requests: office@sbsalaboratory.tech
4. Infrastructure and sub-processor
Hosting and server infrastructure provider: A2 Hosting LLC, 1201 North Market Street, Suite 111-N73, Wilmington, DE 19801, United States.
Primary Staffarmor™ server region: Frankfurt am Main, Germany.
SBSA Laboratory OÜ uses sub-processors only under appropriate confidentiality, data-protection and security obligations.
5. Categories of personal data
- identity, employee number, work e-mail, phone number, language and user role
- company, site, department, team, job position and employment information
- planned and actual working time, clock-in/out, breaks, schedules, variances and corrections
- leave and absence requests, balances, approvals and comments
- documents, electronic declarations, signatures and acceptance audit records
- IP security fingerprint, device, browser, session, access and diagnostic logs
6. Purposes of processing
- workforce and organisational records
- working-time, attendance, breaks, scheduling and leave administration
- site and user identification
- approval, correction, document and declaration workflows
- auditable event history, security and abuse prevention
- service operation, support, troubleshooting and assistance with legal obligations
7. Legal basis
The Customer determines the legal basis under applicable EU, national, employment and sector-specific law. It may include legal obligation, performance of the employment relationship, legitimate interests or the establishment, exercise or defence of legal claims.
Acknowledging this notice is not consent to every processing operation. The Customer must independently determine and demonstrate the applicable legal basis.
8. Access and transfers
Access is limited to authorised Customer administrators, HR staff, managers and, where technically necessary, authorised SBSA Laboratory OÜ personnel and infrastructure providers.
Any transfer outside the EEA is performed only with an applicable legal mechanism and safeguards.
9. Retention and deletion
The Customer determines employment-data retention periods under applicable employment, tax, accounting and other law.
Default retention and deletion principles follow relevant EU rules and requirements of the competent Estonian authorities. On termination, data may be exported, returned, restricted or securely deleted in accordance with the Customer’s instructions and the contract.
10. Security
- encrypted connections and secure server region
- role-based access and tenant separation
- short-lived access tokens and session controls
- audit logging, access revocation and incident investigation
- backups and regular technical review
11. Data subject rights
Subject to applicable conditions, a person may request access, rectification, erasure, restriction, portability, object to processing and lodge a complaint with a competent supervisory authority.
Employment-related requests should first be addressed to the Customer. Requests may also be sent to office@sbsalaboratory.tech; SBSA Laboratory OÜ will assist the Customer as processor.
12. Automated decision-making
Staffarmor™ may generate alerts, variances and statistics, but it does not itself make employment, disciplinary, payroll or dismissal decisions. Those decisions remain the responsibility of the Customer.
13. Versioning
The system may record the document version, language, content hash, viewing and acknowledgement time. Material changes may require renewed acknowledgement.
