Privacy policy (GDPR)

Document version: 2026-08-14

1. Controller

The controller is iTY s.r.o. The controller's full identification details (registered office, company ID, registry entry) are available on request at the contact address below.
Data protection contact: turniket@ity.sk

2. What data we process

  • Identification data: first name, last name, academic titles, gender
  • Contact data: email address, phone number (if provided)
  • Person-type data: private person / sole trader / company / employee, with the related business identifiers (IČO, DIČ, VAT ID, trade name, business address) or employer
  • Application data: attendance records (check-in/out, breaks, time), monthly payroll statements (hours by category — night, weekend, holiday, overtime), GPS position at check-in/out on a site when required — including location checks during an open shift — work notes, voice notes and their automatic transcripts
  • Absence data: absence type (vacation, sick leave, doctor visit, family care, unpaid leave), period and approval status. Sick leave, doctor visits and family care are health-related — we store only the absence type and period,never a diagnosis or medical records
  • Technical data: IP address, login times, change audit logs

3. Purpose and legal basis

PurposeLegal basis
Operating the user account and the applicationcontract performance (Art. 6(1)(b) GDPR)
Attendance, breaks and work records (§ 99 Labour Code)contract / employer's legitimate interest, legal obligations (Art. 6(1)(b), (c), (f))
Absence and vacation records (incl. sick leave, doctor, family care)employer's legal obligations in labour and payroll matters (Art. 6(1)(c)); for health-related data, Art. 9(2)(b) GDPR (employment and social-security law)
Billing data (sole traders, companies)legal obligations (accounting, tax)
GPS presence verification on sitelegitimate interest (workplace attendance control); position is captured at check-in/out and, during an open shift, only confirmed geofence deviations or worker-initiated pings are stored
Voice notes and transcriptscontract performance (project diary)
“QVinto” AI assistant — analytical queries over operational data (available only to authorized users: owner/administrator)controller's legitimate interest in evaluating attendance, statements and costs (Art. 6(1)(f)); for health-related data, Art. 9(2)(b) GDPR
Security and audit logslegitimate interest (system security)

4. Retention

  • Account data: for the account's lifetime; erased or anonymized within 30 days of closure
  • Attendance and payroll records (incl. breaks and monthly statements): statutory retention periods
  • Absence records (vacation, sick leave, family care): statutory labour and payroll retention periods
  • Location records (GPS points at check-in/out and during a shift): max. 12 months, deleted automatically afterwards; the geofence verdict (on-site / off-site) stays part of the attendance record
  • Audit logs: max. 24 months, deleted automatically afterwards
  • Consent records: retained as evidence of consent after erasure (anonymized)

5. Recipients

Data is never shared with third parties for marketing. Processors act strictly under Art. 28 GDPR contracts:

  • OVHcloud — application and database hosting (EU)
  • Email provider (mail.ity.sk) — system email delivery
  • OpenRouter(AI model provider; may process outside the EU – USA) — (a) automatic AI summarization of diary and work notes (note text); (b) the optional “QVinto” AI assistant, available to administrators only: to answer questions it may send further organizational operational data to the AI model — attendance and payroll statements, absence types (including health-related data under Art. 9), GPS location and employee identifiers. The assistant is off by default (enabled by the operator), admin-only; login secrets are redacted before sending and conversation history is deleted automatically.
  • Groq — voice note transcription (processes recordings)

For transfers outside the EU (AI providers in the USA) the controller ensures appropriate safeguards under Art. 46 GDPR (e.g. standard contractual clauses).

6. Your rights

You have the right to access, rectification, erasure (“right to be forgotten”), restriction, portability, objection to legitimate-interest processing, and to lodge a complaint with the Slovak DPA (dataprotection.gov.sk).

Requests: turniket@ity.sk. We respond within 30 days.

7. Consent at registration

By completing registration you confirm you have read this policy. We record the consent with the document version, timestamp and IP address. When the policy changes, we ask you to confirm again.

8. Updates

This document is reviewed regularly (at least quarterly or when application features change). Version history is available from the controller.