Documento legale
Accordo sul trattamento dei dati
Termini titolare-responsabile per clienti Company e Training Provider quando Enkronos tratta dati su istruzioni documentate.
Per questa lingua è pubblicata la versione master inglese; la traduzione approvata sarà aggiunta nel flusso di localizzazione legale.
1. Roles and subject matter
For customer-provided learner and organisation data, the customer is the controller and Enkronos OÜ is the processor. The subject matter is the provision of Workforce OS learning, administration, evidence, support and related services for the term of the order.
2. Data and data subjects
Data may include identity, contact, organisation membership, assignments, learning progress, assessment results, certificates, support records and audit events. Data subjects may include employees, contractors, learners, administrators and Training Provider users. The customer must not send special-category or HR data unless the service configuration and documented instructions authorise it.
3. Instructions and confidentiality
Enkronos processes personal data only on documented customer instructions, including the order, configuration and support request. Personnel with access are bound by confidentiality. Enkronos will notify the customer of an instruction that would breach applicable data-protection law.
4. Security and assistance
Enkronos maintains appropriate technical and organisational measures including tenant isolation, access control, authentication security, audit trails, signed webhook handling, backup and incident procedures proportionate to the configured service. Enkronos assists with data-subject requests, security incidents, impact assessments and regulator communications to the extent reasonably possible.
5. Subprocessors
The application repository currently identifies Stripe for payment processing and Resend for transactional email. No analytics tracker or external AI provider is embedded in the current application. A current subprocessor list and change process must be maintained with the production provider configuration before customer HR data is accepted.
6. Return, deletion and audits
At the end of the service, Enkronos returns or deletes customer data according to the configured export and deletion workflow, except records that must be retained for legal, accounting, security or defence purposes. The customer may request reasonable information needed to demonstrate compliance, subject to confidentiality and security limits.
7. International transfers and governing law
Any international transfer uses a lawful mechanism applicable to the relevant provider and data flow. This DPA is governed by Estonian law, subject to mandatory data-protection law and the governing terms of the order.