Effective Date: 30th of October 2019
Helvia Technologies IKE is a private company registered under Greek law, seated in Athens at Evristheos 2, 11854 ("Helvia" "we" "us") and is the creator, developer, legal owner and supplier of HRwiz.
The terms Personal Data, Data Subject, Data Controller, Data Processor, Processing, Supervisory Authority, Third Party and Recipients shall have the meaning(s) given to such terms in EU Regulation 679/2016 (GDPR) on the protection of natural persons with regard to the processing of personal data. Furthermore, as used in this Security Policy each term used with Capital initial letter shall have the meaning assigned to such term in the applicable HRwiz Terms of Service.
The organization (e.g., your employer or another entity or person) that entered into the Customer Agreement ("Customer") controls their instance of the Services (their "Microsoft Teams" or Other) and any associated Customer Data. If you have any questions about specific Microsoft Team settings and privacy practices, please contact the Customer whose Microsoft Team(s) you have joined and use. If you have received an invitation to join a Microsoft Team but have not yet created an account, you should request assistance from the Customer that sent the invitation.
In the coming sections we set out:
I. The general categories of information that we may process
II. The purposes for which me may process this information
III. How we share and disclose information
IV. How we retain this information
V. The applicable HRwiz security standards
VII. Your rights as an Authorized User
I. Information We Collect and Receive
HRwiz may collect and receive Customer Data, and other information and data ("Other Information") from a variety of sources:
- 1. Customer Data. Customers or individuals invited to join a Microsoft Team by a Customer ("Authorized Users") routinely feed HRwiz with Customer Data when using the Services.
- 2. Personal Data. For the purposes of applicable data protection law, HRwiz is primarily a Data Processor for your Personal Data provided by the Customer, who qualifies as a Data Controller. In order to use HRwiz Services, Personal Data provided by the Customer directly or indirectly are accessible by HRwiz in order to generate and/or operate in a due and compliant manner within the Microsoft Teams environment. Authorized Users are further required to provide HRwiz with additional Personal Data, such as their profile picture, name and surname, e-mail address and phone number. Furthermore, Authorized Users may provide HRwiz with their Personal Data directly at instances, for example when they provide feedback on their own initiative and at their own discretion, request client support, or in any way establish contact with HRwiz. Helvia shall not collect, use or otherwise process any special categories of Personal Data, unless we have received an explicit consent for processing these personal data, or if so required by applicable EU and national data protection law.
- 3. Other Information. HRwiz also collects, generates and/or receives Other Information:
- 3.1 Microsoft Team, Workspace and Account Information. Customers use HRwiz services and its capabilities to achieve efficient collaboration, better results and communication among members. To use, create or update a Microsoft Team, you or your Customer (e.g., your employer) supply HRwiz with information that may include an email address, profile picture, phone number, password and/or similar account details.
- 3.2 Usage Information.
- - Services Metadata. When an Authorized User interacts with the Services, metadata is generated that provides additional context about the way Authorized Users work. For example, HRwiz may log the Microsoft Teams, channels, people, features, content and links you interact with, the types of files shared and what Third Party Services are used (if any).
- - Log data. As with most websites and technology services delivered over the Internet, our servers automatically collect information when you access or use our Websites or Services and record it in log files. This log data may include the Internet Protocol (IP) address, the address of the web page visited before using the Website or Services, browser type and settings, the date and time the Services were used, information about browser configuration and plugins, language preferences and cookie data.
- - Report data. When you or Customer participates and/or generates a Microsoft Team, HRwiz collects all supplied or relative information in view to produce and supply you and/or customer with results in form of a Report. Reports are archived and are retrievable by Customer. Reports may also be used for research, statistical purposes in order to improve HRwiz efficiency, update our App, as well as feedback in order to create and launch marketing campaigns.
- - Device information. HRwiz may collect information about devices accessing the Services, including type of device, what operating system is used, device settings, application IDs, unique device identifiers and crash data. Whether we collect some or all of this Other Information often depends on the type of device used and its settings.
- - Location information. We may receive information from you, your Customer and other third-parties that helps us approximate your location. We may, for example, use a business address submitted by your employer, or an IP address received from your browser or device to determine approximate location in order to inline our Services with your current time-zone. HRwiz may also collect location information from devices in accordance with the consent process provided by your device.
- 3.4 Third Party Services. Typically, Third Party Services are software that integrates with our Services, and Customer can permit its Authorized Users to enable and disable certain integrations, while other (e.g. invoicing, billing, payments' integrations) are required for the operation of HRwiz therefore Customer or Authorized Users are required to use if they intend to use HRwiz. Once enabled, the provider of a Third Party Service may share certain information with HRwiz. Authorized Users should check the privacy settings and notices in these Third Party Services to understand what data may be disclosed to HRwiz. When a Third-Party Service is enabled, HRwiz is authorized to connect and access Other Information made available to HRwiz in accordance with our agreement with the Third Party Provider. We do not, however, receive or store passwords or means of payment/ transaction details (for example credit-card numbers) for any of these Third Party Services when connecting them to the Services. Furthermore, for purposes of Due Diligence, Analytics, Client Support, Quality Control and Communication we may employ Third Party Services in view to acquire information and data, as well as Personal Data, in order to comply with our legal, contractual or client service and support obligations as well as improve our product. Such services may include (list non-exhaustive) Google Analytics, Stripe, etc.
- 3.5 Contact Information. In accordance with the consent process provided by your device, any information that an Authorized User chooses to import may be collected when using the Services.
- 3.6 Third Party Data. HRwiz may receive data as stated above, as well as about organizations, industries, Website visitors, marketing campaigns and other matters related to our business from parent corporation(s), affiliates and subsidiaries, our partners or others that we use to make our own information better or more useful. This data may be combined with Other Information we collect and might include aggregate level data, such as which IP addresses correspond to zip codes or countries. Or it might be more specific: for example, how well an online marketing or email campaign performed.
- 3.7 Additional Information Provided to HRwiz. We receive Other Information when submitted to our Websites or if you request support, interact with our social media accounts or otherwise communicate with HRwiz.
Generally, no one is under a statutory or contractual obligation to provide any Customer Data or Other Information (collectively, "Information"). However, certain Information is collected automatically and, if some Information, such as setup details, is not provided, we may be unable to provide the Services.
II. How We Use Information
Customer Data will be used by HRwiz in accordance with Customer's instructions, including any applicable terms in the Customer Agreement and Customer's use of Services functionality, and as required by applicable law. HRwiz is a processor of Customer Data and Customer is the controller. Customer may, for example, use the Services to grant and remove access to an Authorized User, assign roles and configure settings, access, modify, export, share and remove Customer Data and otherwise apply its policies to the Services.
HRwiz uses Other Information in furtherance of our legitimate interests in operating our Services, Websites and business. More specifically, HRwiz uses Other Information:
- • To provide, update, maintain and protect our Services, Websites and business. This includes use of Other Information to support delivery of the Services under a Customer Agreement, prevent or address service errors, security or technical issues, analyze and monitor usage, trends and other activities or at an Authorized User's request.
- • As required by applicable law, legal process or regulation.
- • To communicate with you by responding to your requests, comments and questions. If you contact us, we may use your Other Information to respond.
- • To develop and provide search, learning and productivity tools and additional features. HRwiz tries to make the Services as useful as possible for Customers and Authorized Users. For example, we may improve configuration functionality by using Other Information to help determine and rank the relevance of content, series and hierarchy of questions to an Authorized User, make Services suggestions based on historical use and predictive models, identify organizational trends and insights, to customize a Services experience, create new productivity features and products and apply machine learning capabilities in view to further improve and integrate HRwiz Reports.
- • For billing, account management and other administrative matters. HRwiz may need to contact you for invoicing, account management and similar reasons and we use account data to administer accounts and keep track of billing and payments. Such data and information will be furthermore retained and used as may be required by applicable law.
- • To investigate and help prevent security issues and abuse.
- • To provide HRwiz Reports.
III. How We Store Information
IV. How We Share & Disclose Information
This section describes how HRwiz may share and disclose Information. Customers determine their own policies and practices for the sharing and disclosure of Information, and HRwiz does not control how they or any other third parties choose to share or disclose Information. Furthermore, as Microsoft Teams, Reports or Data input may be visible or accessible by Authorized Users, HRwiz does not control how they or any other parties chose to share or disclose such Information.
- • Customer's Instructions. HRwiz may share and disclose Customer Data in accordance with a Customer's instructions, including any applicable terms in the Customer Agreement and Customer's use of Services functionality, and in compliance with applicable law and legal process.
- • Displaying the Services. When an Authorized User submits Other Information, it may be displayed to other Authorized Users. Please consult the FAQ for more information on Services functionality.
- • Collaborating with Others. The Services provide different ways for Authorized Users to collaborate. Other Information, such as an Authorized User's profile Information, may be shared, subject to the policies and practices.
- • Customer Access. Owners, administrators, Authorized Users and other Customer representatives and personnel may be able to access, modify or restrict access to Other Information. This may include, for example, your employer using Service features to export activity logs and reports.
- • Third Party Service Providers and Partners. We may engage third party companies or individuals as service providers or business partners to process Other Information and support our business. These third parties may, for example, provide virtual computing and storage services. Additional information about the sub-processors we use to support delivery of our Services is set forth at HRwiz Sub-processors.
- • Third Party Services. Customer may enable or permit Authorized Users to enable Third Party Services. When enabled, HRwiz may share Other Information with Third Party Services. Third Party Services are not owned or controlled by HRwiz and third parties that have been granted access to Other Information may have their own policies and practices for its collection and use. Please check the privacy settings and notices in these Third Party Services or contact the provider for any questions. If required by our policies or law, we will ask for your consent and/or the Customer's before engaging any such service.
- • Corporate Affiliates. HRwiz may share Other Information with its corporate affiliates, parents and/or subsidiaries. During a Change to HRwiz's Business. If HRwiz engages in a merger, acquisition, bankruptcy, dissolution, reorganization, sale of some or all of HRwiz's assets or stock, financing, public offering of securities, acquisition of all or a portion of our business, a similar transaction or proceeding, or steps in contemplation of such activities (e.g. due diligence), some or all Other Information may be shared or transferred, subject to standard confidentiality arrangements.
- • Aggregated or De-identified Data. We may disclose or use aggregated or de-identified Other Information for any purpose. For example, we may share aggregated or de-identified Other Information with prospects or partners for business or research purposes, such as telling a prospective HRwiz customer the average amount of time spent within a typical Microsoft Team. To comply with Laws, enforce our rights, prevent fraud, and for safety. If we receive a request for information, we may disclose Other Information if we reasonably believe disclosure is in accordance with or required by any applicable law, regulation or legal process. We cooperate with law enforcement authorities, as well as with other third parties, to enforce laws, intellectual property rights and to prevent fraud. In response to a verified request by law enforcement or other government officials relating to a criminal investigation or alleged illegal activity, we can, and you authorize us to, disclose your name, surname, profile picture, telephone number, e-mail address and website use history, with or without a subpoena. Without limiting the above, we will not disclose your Information to any law enforcement or other governmental officials without a subpoena or court order, except when we believe in good faith that the disclosure of information is necessary to protect our rights, enforce our policies, respond to claims that your use of our Services violates Helvia's applicable policies or rights or others, or protect anyone's rights, property or safety, enforce contracts or policies. With Consent. Helvia may share Other Information with third parties when we have an explicit consent to do so.
In Helvia we take data security very seriously. Helvia works hard to protect all and Other Information you provide from loss, misuse, and unauthorized access or disclosure. Given the nature of communications and information processing technology, HRwiz cannot guarantee that Information, during transmission through the Internet or while stored on our systems or otherwise in our care, will be absolutely safe from intrusion by others.
- 1. Age Limitations. To the extent prohibited by applicable law, HRwiz does not allow use of our Services and Websites by anyone younger than 18 years old. If you learn that anyone younger than 18 has unlawfully provided us with personal data, please contact us and we will take steps to delete such information.
- 3. Identifying the Data Controller and Processor. Data protection law in certain jurisdictions differentiates between the "controller" and "processor" of information. In general, Customer is the controller of Customer Data. In general, Helvia is the processor of Customer Data and the controller of Other Information. We are the Controller of Other Information and a Processor of Customer Data relating to Authorized Users who use Microsoft Teams established for Customers.
VII. Authorized Users' Rights
Individuals located in certain countries, including the European Economic Area, have certain statutory rights in relation to their personal data. Subject to any exemptions provided by law, you may have the right to request access to Information, as well as to seek to update, delete or correct this Information. As your personal data is furnished by your company, we urge you to also contact your employer, i.e. the Customer for additional access and assistance.
To the extent that Helvia's processing of your Personal Data is subject to the General Data Protection Regulation, Helvia relies on its legitimate interests, described above, to process your data. HRwiz may also process Other Information that constitutes your Personal Data for direct marketing purposes and you have a right to object to or opt-out from HRwiz's use of your Personal Data for this purpose at any time, by contacting HRwiz at email@example.com. In this context, HRwiz may refuse to proceed with any action relative to your Personal Data stored for reasons pertaining to its legal obligations, public safety as well as any other legal obligation to keep records and/or archives unaltered. HRwiz may though keep the Information you suggest in correction or alteration in a separate file, attachment or note connected with the Other Information collected. HRwiz may also legally refrain from responding to any requests if so required by law or instructed by a law enforcement agency or so ordered by a court of law.
Data Protection Authority
Subject to applicable law, you also have the right to (i) restrict Helvia's use of Other Information that constitutes your Personal Data and (ii) lodge a complaint with your local data protection authority or the Hellenic Data Protection Authority, which is Helvia's lead Supervisory Authority in the European Union. If you are a resident of the European Economic Area and believe we maintain your Personal Data within the scope of the General Data Protection Regulation (GDPR), you may direct your questions or complaints to our lead Supervisory Authority:
Hellenic Data Protection Authority
Kifissias 1-3, 115 23 Athens, Greece
tel: +30-210 6475600
Fax: +30-210 6475628
Helvia Technologies IKE
Evristheos 2, 11854, Athens