Privacy Policy — GDPR, ePrivacy & CCPA Compliant
How Chegatta collects, uses and protects your data. Data controller, legal bases, cookies, retention (PT 5y / ES 4y), 90-day anonymization, international transfers, subprocessors and your GDPR/CCPA rights.
Privacy Policy
Last updated: September 22, 2026 — Effective: September 22, 2026
Data Controller: Chegatta Technologies Inc., privacy@chegatta.com — DPO: dpo@chegatta.com
EU Representative (Art. 27): Chegatta EU Rep, Lisbon, PT — eudata@chegatta.com
Not legal advice. This policy is a transparent summary of how we operate. For binding obligations, see the Data Processing Agreement (DPA) in your subscription contract. If you are a staffing agency, your company is the Controller for employee attendance data; Chegatta is the Processor.
1. Who we are and who controls what
- Website visitor: Chegatta is Controller for
chegatta.comanalytics and contact forms. - Customer account (HR manager / owner): Chegatta is Controller for account data (name, work email, company).
- Employee attendance records: Your organization is Controller, Chegatta is Processor (Art. 28). We process only on your documented instructions, plus the DPA (available on request).
2. What we collect
| Category | Examples | Source |
|---|---|---|
| Account | Name, work email, company name, hashed password, plan, billing contact | You type it |
| Attendance | Clock-in/out times, site polygon, break logs, device_fingerprint (hashed), Shift/KioskSession | Employee tap/scan |
| Hiring & HR | NIF/NISS/employee_code, contract dates, LeaveRequest, PerformanceReview | You enter / employee onboarding |
| Technical | IP (truncated), User-Agent, device model, app version, crash logs (ErrorLog) | Automatic at request |
| Support | Messages to privacy@ / support, Lead/Trial form | You send |
We do not collect: biometric templates, contacts, photos from gallery, or browsing history.
3. How we collect it
- Directly from you (forms, dashboard, mobile browser/PWA or native iOS/Android apps).
- Automatically: IP + device at clock-in, and cookieless analytics via Umami Cloud (no third-party advertising cookies — see §8).
- From subprocessors (hosting, email) under Art. 28 contracts.
4. Why we use it — legal bases (GDPR Art. 6)
| Purpose | Basis |
|---|---|
Provide the service (account, clock-in, rosters, payroll calc, SEPA pain.001, Recibo) | Contract (Art.6(1)(b)) |
| Keep attendance for labour law (PT Art.334 5y / ES Art.34.9 4y / 11h rest) | Legal obligation (Art.6(1)(c)) |
Security (TLS, SHA-256 device check, hash-chained audit, rate limiting) | Legitimate interest + Legal obligation |
| Improve the product (aggregate, not personal) | Legitimate interest (balanced) |
| Marketing emails only if you opt in | Consent (Art.6(1)(a)) — withdraw anytime |
| Cookie analytics (non-essential) | Consent (ePrivacy) — blocked until you Accept |
5. Cookies & tracking — your choice on first visit
On your first visit we show a cookie banner (see bottom of every page). You can Accept all / Reject all / Customize.
| Type | Name / Provider | Purpose | Duration | Needs consent? |
|---|---|---|---|---|
| Necessary | chegatta-cookie-consent, NEXT_LOCALE | Remember consent choice + language | 12 months | No (strictly necessary) |
| Functional | device_fingerprint (hashed) | Prevent buddy punching (Shift/KioskSession) | Per shift | No — service operation |
| Analytics | Umami Cloud (cookieless by default, no cross-site tracking) | Pages visited, time on site, referrer (aggregate) | Session — only if you Accept analytics | Yes |
| No advertising | — | We use no third-party ad cookies, no data-broker sharing | — | — |
Withdraw or change at any time: footer Cookie Preferences or clear chegatta-cookie-consent in your browser.
6. How we share — subprocessors (Art. 28)
We do not sell personal data. Sharing only with:
- Hosting & infra: AWS EU (eu-west-1, Ireland) — TLS in transit + encryption at rest,
s3:GetObjectfor deploys. - Email: Amazon SES (Art.28 DPA).
- Analytics (if you consent): Umami Cloud EU (cookieless, DPA).
- Legal / safety: when required by law or to protect rights.
Full subprocessor list on request: privacy@chegatta.com. We sign DPAs with each.
7. International transfers
Primary storage EU (Ireland). If support accesses from outside EEA, we use SCCs (Art.46) + encryption. No transfer of attendance data outside EEA without your instruction.
8. Retention — how long we keep it
| Data | Retention | Legal note |
|---|---|---|
| Account | While active + 12 months after deletion (to handle disputes) | Then deleted or anonymized |
| Attendance / Shifts / KioskSessions | Per your setting, or PT 5 years / ES 4 years (labour law) | Art. 334 PT, Art.34.9 ES |
| Payslips / SEPA runs / Audit chain | Same as attendance — locked runs immutable, new version on edit | Hash-chain re-verifiable |
| IP / raw device fingerprint / User-Agent | Anonymized after 90 days (truncated, hashed) — kept as anomaly stats only | GDPR minimization |
| Support tickets / Leads | 24 months | |
| Backups | Daily, retained 14 days, encrypted | Then overwritten |
9. Security
- TLS 1.2+ in transit, encryption at rest, SHA-256 device + document hashing, hash-chained
ContractAuditEvent(tamper-evident), daily encrypted backups,role-basedaccess (KioskPolicy,SiteManagerGrants), rate limiting (clock-by-id 10/min).
See Security page /en/security.
10. Your rights (GDPR Art.15-22 + CCPA)
For EEA/UK (GDPR) and California (CCPA — “Do Not Sell” — we don’t sell), you can:
- Access — copy of data we hold about you
- Rectification — correct inaccurate data
- Erasure — delete (subject to 5y/4y labour retention)
- Restriction — limit processing
- Portability — CSV/JSON of your data
- Object — to legitimate-interest processing
- Withdraw consent — for marketing/analytics (doesn’t affect prior lawfulness)
- Complain — to your DPA (PT: CNPD, ES: AEPD, EU) or AG in California
Exercise: email privacy@chegatta.com (or dpo@chegatta.com for DPO) — we reply within 30 days. For ATTENDANCE data where you are the Controller, we forward the request to your HR admin as Processor.
No automated decision-making with legal/significant effects (Art.22) — managers approve overtime/anomalies.
11. Children
Service not directed to children under 16. We do not knowingly collect their data. If you believe a child’s data was provided, contact us for deletion.
12. Changes to this policy
Material changes posted here with new Last updated date + banner in dashboard. Continued use after changes = acceptance. For major changes we email account owners.
13. Contact — Controller, DPO, EU Rep
- Controller / DPO: Chegatta Technologies Inc.,
privacy@chegatta.com—dpo@chegatta.com - EU Representative: Chegatta EU Rep, Lisbon, PT —
eudata@chegatta.com - Postal: on request via
privacy@ - Contact form:
/en/contact
14. Consent banner — how to manage
Your choice is stored as chegatta-cookie-consent = {necessary:true, analytics:false/true, marketing:false/true} in localStorage. Change anytime:
- Click Cookie Preferences in the footer, or
- Clear site data in browser → banner reappears.
Analytics and marketing cookies/scripts are blocked until you click Accept.
If you are a customer, this policy is supplemented by your Subscription Agreement + DPA. For the staffing-agency Controller/Processor split, see Multi-Company docs.
Start free — no credit card
GPS + QR kiosk clock-in, geofencing & SEPA payroll in one place. Setup in 2 minutes.