Document version: 2026-08-14
The controller is iTY s.r.o. The controller's full identification details (registered office, company ID, registry entry) are available on request at the contact address below.
Data protection contact: turniket@ity.sk
| Purpose | Legal basis |
|---|---|
| Operating the user account and the application | contract performance (Art. 6(1)(b) GDPR) |
| Attendance, breaks and work records (§ 99 Labour Code) | contract / employer's legitimate interest, legal obligations (Art. 6(1)(b), (c), (f)) |
| Absence and vacation records (incl. sick leave, doctor, family care) | employer's legal obligations in labour and payroll matters (Art. 6(1)(c)); for health-related data, Art. 9(2)(b) GDPR (employment and social-security law) |
| Billing data (sole traders, companies) | legal obligations (accounting, tax) |
| GPS presence verification on site | legitimate interest (workplace attendance control); position is captured at check-in/out and, during an open shift, only confirmed geofence deviations or worker-initiated pings are stored |
| Voice notes and transcripts | contract performance (project diary) |
| “QVinto” AI assistant — analytical queries over operational data (available only to authorized users: owner/administrator) | controller's legitimate interest in evaluating attendance, statements and costs (Art. 6(1)(f)); for health-related data, Art. 9(2)(b) GDPR |
| Security and audit logs | legitimate interest (system security) |
Data is never shared with third parties for marketing. Processors act strictly under Art. 28 GDPR contracts:
For transfers outside the EU (AI providers in the USA) the controller ensures appropriate safeguards under Art. 46 GDPR (e.g. standard contractual clauses).
You have the right to access, rectification, erasure (“right to be forgotten”), restriction, portability, objection to legitimate-interest processing, and to lodge a complaint with the Slovak DPA (dataprotection.gov.sk).
Requests: turniket@ity.sk. We respond within 30 days.
By completing registration you confirm you have read this policy. We record the consent with the document version, timestamp and IP address. When the policy changes, we ask you to confirm again.
This document is reviewed regularly (at least quarterly or when application features change). Version history is available from the controller.