Data protection
Privacy policy
CALAPPA acts as controller for account, contact, billing, security and service-usage data. When a customer uses CALAPPA to manage employees or collaborators, the customer is normally the controller and CALAPPA acts as processor under documented instructions.
Last updated:
CALAPPA
- hi@calappaflow.com
- Privacy / DPO
- hi@calappaflow.com
Roles
CALAPPA acts as controller for account, contact, billing, security and service-usage data. When a customer uses CALAPPA to manage employees or collaborators, the customer is normally the controller and CALAPPA acts as processor under documented instructions.
Purposes and legal bases
Account, billing and security processing relies on contract performance, legal obligations and legitimate interests where applicable. Optional tracking relies on consent where required.
Retention
Data is kept for the contractual relationship and afterwards only for legal obligations and claims. Customer workforce data is returned or deleted under the DPA, subject to mandatory retention. Spanish daily time records must be retained for four years; other jurisdictions follow the applicable local rule.
Rights and security
Applicable GDPR rights include access, rectification, erasure, restriction, objection and portability when their legal conditions are met. A data subject may also lodge a complaint with the competent supervisory authority, especially in the Member State of habitual residence, place of work or alleged infringement. CALAPPA applies risk-based technical and organisational security measures and does not use solely automated decision-making producing legal or similarly significant effects in its ordinary account, billing or security processing.
Applicable legal framework
For EEA processing, the GDPR is the common framework. National implementing and ePrivacy rules apply according to the establishment, user location and processing context; mandatory local law always prevails where applicable.