This policy describes how employees' personal data is processed in the Eskadia employee portal ("/my"), available as a web and mobile application. It applies to the use of the attendance, payroll, absences, fleet trips and expenses, and performance objectives features.
Data controller
The data controller is the employing organization that contracts Eskadia and makes the portal available to its employees. Eskadia Solutions acts as a data processor, providing the technology service on behalf of that organization. Each organization manages its own data in isolation.
What data is collected
Depending on the features you use in the portal, the following categories of data may be processed:
Identification and account data
First name, last name, corporate email and profile data needed to authenticate you and use the portal.
Attendance and clock-in
Clock-in and clock-out stamps, hours worked and, when the organization requires it, the location or geolocation at the time of clocking in to verify the workplace.
Payroll
Payslip documents, compensation amounts and payment history associated with your employment.
Absences and vacation
Vacation and absence requests, dates, leave types and their approval status.
Fleet trips and expenses
Recorded trips, assigned vehicles, expenses and transactions related to fleet usage.
Objectives and performance
Assigned objectives, development plans and performance evaluation data.
Purpose of processing
Data is processed to manage the employment relationship: time and attendance tracking, payroll management, handling vacation and absences, fleet trip and expense control, objective tracking and secure delivery of the portal. It is not used for advertising profiling nor sold to third parties.
Legal basis
Processing is based on the performance of the employment contract, compliance with the employer's legal obligations (for example, working-time records) and, where applicable, the organization's legitimate interest or your consent for specific features such as geolocation when clocking in.
Storage and security
Data is stored on managed Supabase infrastructure (PostgreSQL) hosted in the United States (us-east-2 region), with per-organization isolation via row-level security (RLS) policies. This involves an international transfer of data outside the European Economic Area. Technical and organizational measures are applied to protect information against unauthorized access.
Who it is shared with
Only your employing organization and the technology providers that make the service possible (such as the database and hosting provider), acting under a data-processing agreement, can access your data. It is not shared with third parties for commercial purposes.
Your rights
You may exercise your rights of access, rectification, erasure, restriction, objection and portability over your personal data. To do so, contact your employing organization or Eskadia at the email address below. You may also lodge a complaint with the competent supervisory authority.
Contact
For any questions about this policy or the processing of your data, write to us at:
privacy@eskadia.com