Annex I — Treatment Order — WorkLogTracker
Developed and operated by RMTracker S.L.
This document is the Annex I to the Terms of Use of WorkLogTracker and forms an inseparable part of them. It regulates the processing of personal data that RMTracker is carried out on behalf of the employer who hires the service, in accordance with Article 28 of Regulation (EU) 2016/679 (GDPR).
1. Who is who
Data controller: the employer who hires the service. Decides for what and how the data is processed, and is accountable to the affected individuals and to the supervisory authority.
Data processor:
- Data processor: RMTracker S.L. («RMTracker»)
- Tax ID: B88803085
- Address: Avenida de Andalucía n.º 36, Local 2, 29793 Torrox, Málaga (Spain)
- Email for data protection purposes:
legal@rmtrackersolutions.com
RMTracker processes the data only to provide the service. It does not use them for own purposes, it does not pass them on to third parties unless legally required, it does not sell them and it does not use them to train artificial intelligence systems.
2. Object, nature and purpose
To record the employee's attendance, manage schedules and work centers, document working hours, process incidents and requests for correction, and generate the reports and exports that the responsible party requires. The operations include collection, registration, structuring, storage, consultation, communication to the responsible party, deletion and destruction. No other purpose is pursued: the data is not used to create profiles, for advertising or to train models.
3. Duration
This annex comes into effect when accepted and lasts as long as the service contract is in force. Upon termination, section 9 applies.
4. Data Categories
| Category | What it includes |
|---|---|
| Identification | Name and surname, email, phone if provided |
| Employment Relationship | Employee code, position, role, workplace, assigned schedule |
| Work Identifiers | NIF or NIE and social security affiliation number |
| Shift | Entries, breaks and exits with date and time, associated center and observations |
| Location | Coordinates and precision at the exact moment of each check-in |
| Work Tasks | Tasks, materials, expenses, mileage, photographs and customer signature with name and document |
| Incidents and Corrections | Generated notices, submitted requests and their resolution |
| Traceability | Record of relevant actions on the previous data |
5. Categories of stakeholders
- Employees of the responsible person who have been registered in the application.
- Contact details of the client's representative who signs a work order.
5 bis. Specific features of this service
The service It is not intended for handling special categories. according to Article 9 of the GDPR. Biometric data is not used for identification purposes. The controller undertakes not to enter health or other special category data into free text fields.
The The location is only checked at the time of check-in., to verify the distance to the assigned center, and is not continuously monitored. It is incumbent upon the responsible person to inform the staff and their representatives expressly and in advance, in accordance with article 90 of the LOPDGDDIf location permission is denied, the record is still created without coordinates.
The payment gateway is not listed as a subcontractor because I cannot access the template data.: it only intervenes in invoicing to the customer, in the process of RMTracker acts as a responsible person, not as a female person.
6. Obligations of RMTracker as manager
In accordance with Article 28.3 of the GDPR, RMTracker it obligates to:
- Process data only according to documented instructions of the responsible party, including those relating to international transfers. The normal use of the service constitutes that instruction. If RMTracker understands that an instruction violates data protection regulations, will immediately notify you.
- Ensure confidentiality of those who access the data, through express agreement or legal obligation, which continues after the end of the relationship.
- Apply the measures of article 32, described in section 7.
- Do not use another person as an agent without authorization. The responsible person authorizes: the deputies listed in section 8. Any new appointment or replacement will be communicated with thirty days in advance, and the responsible party may object; if they object and the change is necessary to provide the service, they may terminate the contract without penalty.
- Attend the supervisor in order to be able to exercise the rights of access, rectification, deletion, limitation, portability and objection. If an affected person contacts us directly RMTracker, será redirigido al responsable y éste será informado de inmediato.
- Attend the supervisor in compliance with articles 32 to 36: security, breach notification and impact assessment.
- Report security breaches without undue delay and, in any case, within forty-eight hours those who need to be informed about them, with the information provided in article 33.3. Forty-eight and not seventy-two because the responsible party needs a margin to meet their own deadline.
- Delete or return the data upon completion, according to section 9.
- Make available to the responsible party the information necessary to demonstrate compliance with this annex, and allow and facilitate audits, according to section 10.
7. Security measures
The measures are described by what the system does, not by what is usually said in a contract. They are verifiable:
- Isolation between companies. Access to the data is restricted within the database itself through row-level security: a person only has access to the data of the company to which they belong.
- Role-based access control. Within each company, what each person can see and do depends on their role, also applied on the server and not just in the interface.
- Separation of work identifiers. The NIF and the social security number are stored separately from the rest of the record and are only accessible to the individual themselves and to those who manage payroll or attend an inspection.
- Encryption. Communications travel encrypted and passwords are stored with robust hashing functions.
- Record integrity. Records cannot be altered or deleted: an error is corrected by an approved correction that is recorded along with the original record.
- Traceability. Relevant actions on the data are logged with their author and time.
- Backups managed by the hosting manager, with recovery to a previous point in time.
- Minimization. The location is only queried at the time of check-in and not continuously tracked.
The measures can evolve. RMTracker it will not degrade: any change will maintain an equivalent or higher level of protection.
8. Authorized Sub-managers
| Sub-manager | For what | Where |
|---|---|---|
| Supabase | Database hosting, authentication and attachment storage | European Union (Ireland region) |
With each sub-manager RMTracker maintains a contract that imposes the same obligations as this annex, and is liable to the responsible for their actions as well as the own.
9. End of assignment
When the contract ends, RMTracker will delete the personal data processed by the responsible, or will return them return in a common format and mechanical reading if requested before deletion, and will delete existing copies.
When subscription ends, the responsible has thirty days to export their data using the functions of the own application. After that period, RMTracker will delete the personal data processed by your account, including copies, unless it must retain them for legal reasons, in which case they will be blocked for the corresponding period. The controller may request their return in a structured and common format, or their immediate deletion, which will be confirmed in writing if requested. It is worth remembering that labor regulations oblige the controller to keep the record of working hours for four years: exporting before deletion is not recommended, it is what allows them to continue complying with this obligation.
10. Audit
The controller may request, once a year and with fifteen days' notice, the information necessary to prove compliance with this annex. It can also carry out an audit, either itself or through an independent third party that is not a competitor of RMTracker, prior agreement on date, scope and confidentiality, and without interrupting the service.
Additional audits arising from a security breach, a request from the regulatory authority or a proven non-compliance are not subject to this annual limit.
11. Confidentiality Commitment
This section replaces a separate confidentiality agreement, so that no separate document needs to be signed.
Both parties agree to keep the other party's confidential information secret to which they have access in connection with this relationship, to use it only for its execution and not to disclose it to third parties without written authorization. Confidential information is considered technical, commercial, financial and organizational information that is not publicly available, and in particular, personal data processed under the terms of this annex.
The following information is not confidential:
- , if it was already public before receipt, or becomes so without breaching this commitment;
- , if it legitimately existed in the possession of the receiving party without a duty of secrecy;
- , if it has been developed independently without using the other party's information; or
- , if it must be disclosed by legal obligation or by a competent authority, in which case prior notice will be given to the other party if possible.
This commitment remains in effect three years after the relationship ends. For personal data there is no deadline: the confidentiality obligation of Article 28.3.b of the GDPR does not expire.
12. Liability
Each party is liable for damages caused by breaching the obligations imposed on them by this annex and the GDPR, in accordance with Article 82 of the Regulation. RMTracker they are not liable for the controller's instructions or for the legality of the treatments that they decide to implement.
13. Acceptance without signature
This annex is accepted electronically when creating the account, in the form that is supported by article 28.9 of the GDPR, and does not require a handwritten signature. A record is kept of who made each acceptance, when, and which version of the text was in effect. The responsible party can request a certificate of their acceptances at any time.
If this annex changes, it will be notified in advance with reasonable notice and a new acceptance will be obtained. The previous ones are retained: they represent the history of what was in effect at each moment.
14. Applicable law
This annex is governed by the GDPR, Law 3/2018 on the Protection of Personal Data and Digital Rights Guarantee, and Spanish legislation. In cases not covered here, the Terms of Use of WorkLogTracker, which it forms part of.
legal@rmtrackersolutions.com.