PRIVACY POLICY
Privacy Policy
How we process personal data, your rights under the GDPR, and how to exercise them.
If your employer set you up in PersoHR
Your employer is the controller of your HR data in PersoHR. To exercise your rights under Articles 15 to 22 GDPR — access, rectification, erasure, restriction, portability, objection — contact your employer or your HR administrator. PersoHR processes that data on your employer's behalf under a Data Processing Agreement. PersoHR is the controller only for your direct interactions with us — billing if you are the account owner, support correspondence, and the public website.
1. Introduction
Labb Holding Ltd ("we", "us", "our") operates the PersoHR HR-management service. This privacy policy explains how we collect, use, share and protect personal data in connection with PersoHR and our public website, in accordance with Regulation (EU) 2016/679 (the "GDPR") and the Cypriot Law 125(I)/2018 implementing it.
2. Who is the controller of your data
When you use PersoHR through your employer, your employer is the controller of your personal data and we act as a processor on their behalf under a Data Processing Agreement (see /legal/dpa). When you sign up for PersoHR directly (for example, as the account owner during company registration), when you contact us, or when you use our public website, the controller is Labb Holding Ltd, a Cyprus private company limited by shares with its registered office at Anthipolochagou Georgiou M.Savva 26, Shop 1-2, 8201 Paphos, Cyprus, registered under HE 424230, VAT CY 10424230D, represented by its sole director Michael Delamere. You can reach us at privacy@persohr.eu.
3. Data Protection Officer
We have not appointed a designated Data Protection Officer. We carry out a written Article 37(1) GDPR threshold assessment at least once a year and whenever the nature, scope or volume of our processing changes materially. Based on the current assessment we do not meet any of the mandatory triggers — we are not a public authority, our core activities do not consist of regular and systematic monitoring of data subjects on a large scale, and our core activities do not consist of large-scale processing of special-category data under Article 9 or criminal-conviction data under Article 10 — and Cyprus has not introduced a stricter national threshold. If the assessment changes we will appoint a DPO. Privacy enquiries should be addressed to privacy@persohr.eu and are handled by the management within the timelines required by Article 12 GDPR.
4. Categories of personal data we process
Identification and contact data: name, email, phone, postal address, profile photo. Employment data: job title, department, employment type, start and end dates, working hours, manager. Leave and absence data: leave requests, balances, public holidays. Salary and payroll-preparation data: salary records, IBAN where supplied, tax and social-security identifiers where supplied. Performance and development data: objectives, reviews, feedback, training records. Recruitment data: applications, CVs, interview notes, references. Document content: files uploaded by you or your employer. Communication and chat data within the platform. Authentication and security data: login timestamps, IP addresses, device fingerprints, two-factor authentication state. Support correspondence. Billing data when you are the account owner: name, billing address, VAT identifier, payment-method tokens (raw card data is held by Stripe, not by us). We do not process special categories of personal data within the meaning of Article 9 unless your employer chooses to upload them and is responsible under their own legal basis.
5. Lawful basis for processing
When we are the controller, our lawful bases are: (a) performance of a contract under Article 6(1)(b) for delivering the subscribed service to the account owner; (b) compliance with legal obligations under Article 6(1)(c), in particular Cypriot tax and accounting record-retention rules; (c) legitimate interests under Article 6(1)(f) for service security, abuse prevention and product improvement, balanced against your rights and freedoms. When your employer is the controller, the lawful basis is determined by your employer and is typically Article 6(1)(b) (performance of the employment contract) or Article 6(1)(c) (compliance with employment-law obligations).
6. How we use your data
Your data is used solely for HR management and the operation of the platform: maintaining employee records, managing leave and absence, organising the company structure, supporting performance and development, running recruitment, preparing payroll exports, storing documents, enabling internal communication, billing, abuse prevention and security. We do not sell your data, do not share it with advertising networks, and do not use it for marketing without your separate opt-in consent.
7. AI-assisted features
PersoHR offers optional AI-assisted features such as the in-app HR assistant, onboarding-task suggestions, document analysis and performance-review drafting. When these features are enabled, the prompts sent to the AI provider may include the personal data necessary to answer the question. AI inference is provided by Mistral AI, headquartered in Paris, France, on infrastructure within the European Union. Inputs and outputs are not used to train Mistral's foundation models. Runtime AI inference uses Mistral exclusively; no non-EU AI provider receives customer prompts or outputs.
8. Sub-processors and recipients
We engage a small set of sub-processors to deliver the service. The current list, including each sub-processor's role, location and data-protection mechanism, is published at /legal/sub-processors. We inform the account owner at least 30 days before adding or replacing a sub-processor and offer the right to object on reasonable data-protection grounds.
9. International transfers
All primary infrastructure (database, file storage, AI inference, transactional email) is hosted within the European Union. The only routine transfer outside the EU is to Stripe Payments Europe Limited (Ireland), with onward transfer to Stripe Inc. in the United States for billing and subscription processing. That transfer is made on the basis of the European Commission's Standard Contractual Clauses (Decision 2021/914/EU) supplemented by Stripe's additional safeguards. You can request a copy of the relevant SCCs by emailing privacy@persohr.eu.
10. Retention periods
We retain personal data only for as long as necessary for the purposes set out in this policy. Active employee records: for the duration of employment as configured by your employer. Terminated employee records: retained by your employer for the period required by local employment, tax and social-security law, typically 6 to 10 years; we delete or anonymise data within 30 days of receiving instruction from your employer to do so. Leave and time-tracking records: retained alongside the employee record. Payroll-preparation records: retained alongside the employee record and subject to the statutory accounting retention period of your country. Authentication logs and audit logs: retained for 24 months for security and accountability purposes, or longer if subject to a legal hold. Support correspondence: 12 months after the request is closed. Billing records (invoices, payment metadata): 7 years from the end of the relevant tax year, in line with Cypriot accounting law. Tenant data after subscription cancellation: 30 days for export under Article 20, then deletion. After the applicable period, data is deleted or irreversibly anonymised in line with Article 17.
11. Your rights
Under Articles 15–22 GDPR you have the right to: (a) access your personal data; (b) rectify inaccurate data; (c) request erasure (the "right to be forgotten"); (d) restrict processing; (e) data portability — receive your data in a structured, commonly used and machine-readable format; (f) object to processing based on legitimate interests; (g) withdraw consent at any time, where processing is based on consent; (h) not be subject to a decision based solely on automated processing that produces legal or similarly significant effects (see section 12). You can exercise rights (a), (b), (c) and (e) self-service via the in-app GDPR tools (Profile → Download my data; Settings → Erase data). For all other rights, email privacy@persohr.eu or contact your account administrator. We will respond within one month, extendable by a further two months for complex requests, in line with Article 12(3).
12. Automated decision-making
We do not make decisions producing legal or similarly significant effects on you based solely on automated processing. AI-assisted features generate suggestions that are always reviewed and accepted, edited or rejected by a human user before any action is taken.
13. Security of processing
We implement technical and organisational measures appropriate to the risk: TLS 1.2 or higher in transit, encryption at rest, role-based access control with the principle of least privilege, comprehensive audit logging, regular vulnerability scanning, EU-only data residency for primary processing, time-limited access tokens, mandatory two-factor authentication for privileged roles, and tested backup and restore procedures.
14. Data breach notification
In the event of a personal data breach affecting your data, we notify the competent supervisory authority without undue delay and, where feasible, within 72 hours of becoming aware of the breach (Article 33 GDPR). Where the breach is likely to result in a high risk to your rights and freedoms, we also notify you directly without undue delay (Article 34 GDPR).
15. Cookies and similar technologies
We use only strictly necessary cookies and equivalent local-storage entries, all on a same-site basis from the persohr.eu domain. Specifically: a `persohr_rt` HttpOnly Secure SameSite=Strict refresh-token cookie that keeps you signed in for up to 7 days — your browser sends it back automatically but JavaScript on the page cannot read it, which closes the XSS-refresh-token vector; a `persohr-locale` localStorage entry that remembers your language preference; a small number of UI-state localStorage entries (sidebar collapsed, dismissed banners). Authentication is handled in-process by the PersoHR backend (passwordless magic link plus optional TOTP); no external identity provider sets cookies on your device. Stripe sets its own strictly-necessary cookies during checkout when you upgrade your subscription. We use Plausible Analytics (hosted in Estonia, EU) to count visits and conversion events on the marketing site and the public sign-up flow only. Plausible is cookieless and does not store IP addresses in raw form, so no advertising, retargeting or social-media tracking cookies are set on your device. Logged-in app pages are not tracked. Because we do not set any non-essential cookies, no consent banner is required under the ePrivacy Directive and Cypriot Law 112(I)/2004. If we ever introduce optional cookies, we will publish an opt-in consent banner before any non-essential cookie is set.
16. Support requests
When you reach out through the in-app contact form or write to support@persohr.eu, your message and any attached screenshot reach our support team so we can reply. We attach context that helps us answer faster: the company you're with, your plan, your name and email, and the page you were on. We keep the request long enough to resolve the issue plus a short follow-up window, then delete it within 12 months.
17. Right to lodge a complaint
Without prejudice to any other remedy, you have the right to lodge a complaint with a supervisory authority, in particular in the EU member state of your habitual residence, place of work or place of the alleged infringement, if you consider that our processing of your personal data infringes the GDPR. The lead supervisory authority for Labb Holding Ltd is the Office of the Commissioner for Personal Data Protection in Cyprus (www.dataprotection.gov.cy). A list of all national supervisory authorities is published by the European Data Protection Board at edpb.europa.eu.
18. Changes to this policy
We may update this policy to reflect changes in the service, applicable law or our processing activities. Material changes are notified to the account owner by email at least 30 days before they take effect. The current version and effective date are shown at the top of this document. The previous version remains accessible on request to privacy@persohr.eu.
19. Contact
For privacy-related enquiries, please email privacy@persohr.eu or write to Labb Holding Ltd, Anthipolochagou Georgiou M.Savva 26, Shop 1-2, 8201 Paphos, Cyprus. You may also contact your company administrator for matters relating to data your employer controls. We aim to respond within one month of receiving the request, in line with Article 12(3) GDPR.