Hecho para equipos por turnos:
Diseñado para las normas de tiempo de trabajo de la UE
|

Privacy Policy — GDPR, ePrivacy & CCPA Compliant

How Chegatta collects, uses and protects your data. Data controller, legal bases, cookies, retention (PT 5y / ES 4y), 90-day anonymization, international transfers, subprocessors and your GDPR/CCPA rights.

Privacy Policy

Last updated: September 22, 2026 — Effective: September 22, 2026
Data Controller: Chegatta Technologies Inc., privacy@chegatta.com — DPO: dpo@chegatta.com
EU Representative (Art. 27): Chegatta EU Rep, Lisbon, PT — eudata@chegatta.com

Not legal advice. This policy is a transparent summary of how we operate. For binding obligations, see the Data Processing Agreement (DPA) in your subscription contract. If you are a staffing agency, your company is the Controller for employee attendance data; Chegatta is the Processor.

1. Who we are and who controls what

  • Website visitor: Chegatta is Controller for chegatta.com analytics and contact forms.
  • Customer account (HR manager / owner): Chegatta is Controller for account data (name, work email, company).
  • Employee attendance records: Your organization is Controller, Chegatta is Processor (Art. 28). We process only on your documented instructions, plus the DPA (available on request).

2. What we collect

CategoryExamplesSource
AccountName, work email, company name, hashed password, plan, billing contactYou type it
AttendanceClock-in/out times, site polygon, break logs, device_fingerprint (hashed), Shift/KioskSessionEmployee tap/scan
Hiring & HRNIF/NISS/employee_code, contract dates, LeaveRequest, PerformanceReviewYou enter / employee onboarding
TechnicalIP (truncated), User-Agent, device model, app version, crash logs (ErrorLog)Automatic at request
SupportMessages to privacy@ / support, Lead/Trial formYou send

We do not collect: biometric templates, contacts, photos from gallery, or browsing history.

3. How we collect it

  • Directly from you (forms, dashboard, mobile browser/PWA or native iOS/Android apps).
  • Automatically: IP + device at clock-in, and cookieless analytics via Umami Cloud (no third-party advertising cookies — see §8).
  • From subprocessors (hosting, email) under Art. 28 contracts.
PurposeBasis
Provide the service (account, clock-in, rosters, payroll calc, SEPA pain.001, Recibo)Contract (Art.6(1)(b))
Keep attendance for labour law (PT Art.334 5y / ES Art.34.9 4y / 11h rest)Legal obligation (Art.6(1)(c))
Security (TLS, SHA-256 device check, hash-chained audit, rate limiting)Legitimate interest + Legal obligation
Improve the product (aggregate, not personal)Legitimate interest (balanced)
Marketing emails only if you opt inConsent (Art.6(1)(a)) — withdraw anytime
Cookie analytics (non-essential)Consent (ePrivacy) — blocked until you Accept

5. Cookies & tracking — your choice on first visit

On your first visit we show a cookie banner (see bottom of every page). You can Accept all / Reject all / Customize.

TypeName / ProviderPurposeDurationNeeds consent?
Necessarychegatta-cookie-consent, NEXT_LOCALERemember consent choice + language12 monthsNo (strictly necessary)
Functionaldevice_fingerprint (hashed)Prevent buddy punching (Shift/KioskSession)Per shiftNo — service operation
AnalyticsUmami Cloud (cookieless by default, no cross-site tracking)Pages visited, time on site, referrer (aggregate)Session — only if you Accept analyticsYes
No advertisingWe use no third-party ad cookies, no data-broker sharing

Withdraw or change at any time: footer Cookie Preferences or clear chegatta-cookie-consent in your browser.

6. How we share — subprocessors (Art. 28)

We do not sell personal data. Sharing only with:

  • Hosting & infra: AWS EU (eu-west-1, Ireland) — TLS in transit + encryption at rest, s3:GetObject for deploys.
  • Email: Amazon SES (Art.28 DPA).
  • Analytics (if you consent): Umami Cloud EU (cookieless, DPA).
  • Legal / safety: when required by law or to protect rights.

Full subprocessor list on request: privacy@chegatta.com. We sign DPAs with each.

7. International transfers

Primary storage EU (Ireland). If support accesses from outside EEA, we use SCCs (Art.46) + encryption. No transfer of attendance data outside EEA without your instruction.

8. Retention — how long we keep it

DataRetentionLegal note
AccountWhile active + 12 months after deletion (to handle disputes)Then deleted or anonymized
Attendance / Shifts / KioskSessionsPer your setting, or PT 5 years / ES 4 years (labour law)Art. 334 PT, Art.34.9 ES
Payslips / SEPA runs / Audit chainSame as attendance — locked runs immutable, new version on editHash-chain re-verifiable
IP / raw device fingerprint / User-AgentAnonymized after 90 days (truncated, hashed) — kept as anomaly stats onlyGDPR minimization
Support tickets / Leads24 months
BackupsDaily, retained 14 days, encryptedThen overwritten

9. Security

  • TLS 1.2+ in transit, encryption at rest, SHA-256 device + document hashing, hash-chained ContractAuditEvent (tamper-evident), daily encrypted backups, role-based access (KioskPolicy, SiteManagerGrants), rate limiting (clock-by-id 10/min).

See Security page /en/security.

10. Your rights (GDPR Art.15-22 + CCPA)

For EEA/UK (GDPR) and California (CCPA — “Do Not Sell” — we don’t sell), you can:

  • Access — copy of data we hold about you
  • Rectification — correct inaccurate data
  • Erasure — delete (subject to 5y/4y labour retention)
  • Restriction — limit processing
  • Portability — CSV/JSON of your data
  • Object — to legitimate-interest processing
  • Withdraw consent — for marketing/analytics (doesn’t affect prior lawfulness)
  • Complain — to your DPA (PT: CNPD, ES: AEPD, EU) or AG in California

Exercise: email privacy@chegatta.com (or dpo@chegatta.com for DPO) — we reply within 30 days. For ATTENDANCE data where you are the Controller, we forward the request to your HR admin as Processor.

No automated decision-making with legal/significant effects (Art.22) — managers approve overtime/anomalies.

11. Children

Service not directed to children under 16. We do not knowingly collect their data. If you believe a child’s data was provided, contact us for deletion.

12. Changes to this policy

Material changes posted here with new Last updated date + banner in dashboard. Continued use after changes = acceptance. For major changes we email account owners.

13. Contact — Controller, DPO, EU Rep

  • Controller / DPO: Chegatta Technologies Inc., privacy@chegatta.comdpo@chegatta.com
  • EU Representative: Chegatta EU Rep, Lisbon, PT — eudata@chegatta.com
  • Postal: on request via privacy@
  • Contact form: /en/contact

Your choice is stored as chegatta-cookie-consent = {necessary:true, analytics:false/true, marketing:false/true} in localStorage. Change anytime:

  • Click Cookie Preferences in the footer, or
  • Clear site data in browser → banner reappears.

Analytics and marketing cookies/scripts are blocked until you click Accept.


If you are a customer, this policy is supplemented by your Subscription Agreement + DPA. For the staffing-agency Controller/Processor split, see Multi-Company docs.

Start free — no credit card

GPS + QR kiosk clock-in, geofencing & SEPA payroll in one place. Setup in 2 minutes.

14 days full access Zero hardware Cancel anytime
Start Free Trial