Last updated: 31/08/2026
This notice describes how personal data is processed in connection with GRADO HR, the multi-tenant cloud platform for human resources management (employee records, time clock, shifts and absences, digital payslips) operated by GRADO TECH Srls. It is issued pursuant to Arts. 13 and 14 of EU Regulation 2016/679 (GDPR) and supplements the general privacy notice published on the GRADO Tech website.
GRADO HR is SaaS software: the client company manages data in its own workspace. The role of GRADO TECH Srls varies depending on context:
This section applies to personal data that the client company (or a party authorised by it) enters, uploads or generates on GRADO HR in connection with its workers and organisation. Such data remains under the control and responsibility of the controller; GRADO TECH Srls only hosts, stores and makes it available according to the contract and received instructions.
For the data described in this Part A:
The controller must provide workers and data subjects with a GDPR-compliant privacy notice (Arts. 13–14) and have a valid legal basis for each processing activity, including those relating to the employment relationship, time clock/geolocation and payroll documents.
GRADO HR is organised into modules activated by the controller. Depending on workspace configuration, data may be processed in relation to:
GRADO HR does not include individual performance evaluation, OKR or employee ranking modules.
Depending on activated modules, the platform may process, among others, the following data entered or generated by the controller:
GRADO TECH Srls processes Part A data exclusively on behalf of the controller and limited to the following technical purposes:
For worker and organisation data processed via GRADO HR, determining the purposes and the relevant legal basis is the responsibility of the client company as data controller.
Depending on the features used and the specific context, the controller may rely, among others, on performance of the employment relationship, compliance with legal obligations, exercise of rights and obligations in employment law or, where the requirements are actually met, legitimate interest.
Worker consent is not the ordinary legal basis for processing necessary to manage the employment relationship and is used only where it can genuinely be free, specific, informed and revocable without negative consequences for the data subject.
For processing carried out on behalf of the client company, GRADO TECH Srls acts as processor under Art. 28 GDPR and processes data exclusively on the basis of the controller's documented instructions, the service contract and the data processing agreement. Any processing by GRADO TECH Srls for its own independent purposes, such as security of its infrastructure, contract management, billing or protection of its own rights, is governed separately in Part C of this notice and is based on the legal basis applicable in each case.
Retention periods for Part A data are determined by the controller, in compliance with employment, social security, tax and safety law. GRADO TECH Srls retains data for the duration of the contract and thereafter for the period strictly necessary for orderly service termination, recovery at the controller's request or legal obligations. Upon termination, data is returned or deleted as provided in the contract and Art. 28 agreement, unless otherwise documented or required by law.
GRADO TECH Srls does not freely access, consult or use content in the HR workspace without a lawful and documented basis. Access by authorised personnel is permitted only in the following cases:
Any access is limited to authorised staff, subject to confidentiality, logged where technically possible and limited to the duration of the intervention. GRADO TECH Srls does not sell data and does not disclose it to third parties for its own marketing or profiling purposes.
The platform records relevant operations (audit logs, user access, changes, stamping errors) to enable the controller to monitor activities. Technical assistance logs are retained for the time necessary for the contractual relationship, security and traceability, generally no longer than 12 months unless disputes or legal obligations require otherwise.
This section applies to personal data collected directly by GRADO TECH Srls in connection with registration, subscription, billing, commercial and contractual communications and management of platform administrative accounts.
The data controller for Part C data is GRADO TECH Srls, registered office Corso Umberto I, 7 — 66050 San Salvo (CH), Italy. VAT IT02868240694. Email: info@gradotech.it — Phone: +39 378 421 3717.
Performance of contract or pre-contractual measures (Art. 6(1)(b) GDPR); compliance with legal obligations (Art. 6(1)(c) GDPR); legitimate interest in security and relationship management (Art. 6(1)(f) GDPR); consent for optional marketing activities (Art. 6(1)(a) GDPR), revocable at any time.
Data relating to workers and other parties entered by the company on GRADO HR is processed by the data controller (the client company). Therefore:
The controller is responsible for providing workers with a complete and up-to-date privacy notice on processing carried out via GRADO HR, including any geolocation of stampings and, if enabled, AI photo check.
Workers may contact their employer, as data controller, to obtain information on personal data processing carried out through artificial intelligence features and to exercise the rights under Arts. 15–22 GDPR.
Where a result produced by an artificial intelligence feature has been used as part of a human assessment, the worker may ask the controller for information on the processing of their data and, within the limits of applicable law, rectification of inaccurate data and verification of the outcome.
GRADO HR does not provide, for the features described in this notice, exclusively automated decisions producing legal effects or similarly significant effects on the worker.
GRADO HR may interact with the following services only if activated or used by the controller:
mfa_remember.openid, email, profile). After that, “Sign in with Google” opens that same account. An unlinked Google account cannot sign in and does not create a new user. The Google identifier and associated email are stored; the user can unlink Google at any time. Google LLC processes sign-in data under its own privacy notice, on Google’s domain.Access to GRADO HR is named and is limited to accounts already created by the controller in the workspace. In short:
The hr.gradotech.it platform uses first-party technical cookies only, needed for sign-in and security. It does not use profiling or marketing cookies. Google (third-party) cookies appear only if the user chooses “Sign in with Google”, and are set on Google’s domain, not on the HR domain.
| Name | Purpose | Duration | Type |
|---|---|---|---|
grado_hr_session |
Authenticated session cookie. Keeps the user signed in and the active workspace after login. | Session / idle timeout about 120 minutes | Technical — first party (HttpOnly) |
XSRF-TOKEN |
CSRF protection: lets the browser send authenticated requests securely (e.g. payslip upload). | Aligned with the session | Technical — first party |
mfa_remember |
If the user has enabled MFA and chose to remember the device, skips the TOTP code at each sign-in for the period set (1, 7, 30 or 90 days). Absent if “At every sign-in” is selected. | 1 / 7 / 30 / 90 days, or absent | Technical — first party |
remember_web_* |
“Remember me” cookie for identifier-and-password login, if the user ticks the box. Not set unless that option is chosen. | Until expiry or logout | Technical — first party (HttpOnly) |
Google cookies (accounts.google.com) |
Set by Google only during “Sign in with Google” / account linking. They serve Google authentication, not profiling on HR. The user can refuse Google and sign in with local credentials only. | According to Google’s settings | Technical — third party (Google LLC), only if Google is used |
Disabling technical cookies prevents sign-in and use of the platform. Google cookies can be avoided by not using “Sign in with Google”. For browser instructions, see the GRADO Tech website Cookie Policy.
GRADO HR may make features assisted by generative and vision artificial intelligence systems available to the client company. Such features remain off until at least one API key is configured in the workspace (the controller's own or one supplied by GRADO TECH Srls) and are enabled according to the configuration chosen by the client company.
Artificial intelligence is used as a support tool and does not replace the responsibilities and assessments of people authorised by the company.
GRADO HR artificial intelligence features are designed so that:
Where activated by the company, the photo check feature allows a service evidence photograph to be submitted to an artificial intelligence model in order to carry out technical or procedural checks defined in advance.
By way of example, the system may verify:
Before processing, the image may be resized and subject to data minimisation measures.
Photo check does not perform facial recognition, biometric identification, emotion recognition, worker rankings, individual productivity scoring or automatic disciplinary decisions. It checks only technical aspects of the image and required elements (for example subject visibility, sharpness, presence of configured PPE where applicable).
The AI outcome relates exclusively to the check requested on the photograph and may indicate, for example, that the image is usable or must be retaken.
Where the outcome may have further consequences for the worker, it must be reviewed by a person authorised by the company and cannot be used as the sole automated basis for a decision with legal or similarly significant effects.
The client company determines, under its own responsibility, whether and how outcomes may subsequently be used in the employment relationship, in compliance with the GDPR, employment law and, where applicable, Art. 4 of Italian Law No. 300 of 20 May 1970.
In short, AI photo check verifies the technical usability of the photographic evidence and does not assess the person, their productivity or the employment relationship.
Images may contain personal data relating to the worker or other people accidentally captured.
GRADO HR applies minimisation measures to reduce data sent to the AI system to what is strictly necessary for the requested check. Where technically possible and compatible with the purpose of the feature, unnecessary information may be excluded, obscured or reduced before processing.
Photographs are not used by GRADO TECH Srls to create biometric databases, recognise people's identity or autonomously train facial recognition models.
The presence of special categories of personal data in the image does not lead to their use to deduce or classify sensitive characteristics of the person.
Authorised administrators may use an optional feature to analyse a limited number of sample documents in order to configure the technical rules needed to import payslips. Only sampled text extracted from the PDFs is sent to the AI, not the full files.
Before sending to the artificial intelligence system, the controller or authorised administrator must apply minimisation and redaction of unnecessary data. In particular, unless strictly necessary for the technical purpose, names, tax codes, bank details, health information, trade union membership information and other data not essential to determine the document structure must not be transmitted. The platform may automatically replace monetary amounts with generic placeholders; redaction of other personal data remains the controller's responsibility.
The feature does not calculate pay, does not determine payslip content and does not make decisions concerning the worker.
Use of AI is optional for the administrator: configuration can also be done through manual rules and presets.
AI analysis of payslip samples is an administrative configuration tool and does not involve pay assessments or employment decisions.
Administrators may use artificial intelligence tools to improve or structure the text of criteria used in photo checks.
Unless the administrator independently enters unnecessary personal information, this feature does not require identity, payroll or other personal information relating to workers.
The artificial intelligence features described in this notice are not intended to make decisions based solely on automated processing that produce legal effects on the worker or similarly significantly affect them under Art. 22 GDPR.
If features with such characteristics are introduced in future, they will be subject to prior regulatory and impact assessment and will not be activated without the information, safeguards and legal bases required by applicable law, including, where provided, the right to human intervention, to contest and to express one's point of view.
When an artificial intelligence feature directly concerns a worker, the platform interface may show specific information before the feature is used.
Any acknowledgement or confirmation of reading recorded by the platform serves exclusively to document that information was provided and does not constitute worker consent nor replace the legal basis the controller must identify for the processing.
Further information obligations under employment and data protection law remain the responsibility of the client company.
The client company must identify authorised persons able to understand the nature and limits of outputs produced by AI features.
Authorised users must be able to critically assess outcomes and, when necessary, ignore, correct or submit them for further review.
AI outputs must not be considered automatically correct and must be interpreted in relation to the context in which they were produced.
Before activating artificial intelligence features that process worker data, and in particular where such features may involve monitoring of work activity, assessment of behaviour, systematic processing of images or other operations likely to present a high risk to people's rights and freedoms, the client company must verify necessity and, where required by applicable law, carry out a data protection impact assessment under Art. 35 GDPR in advance.
The company must also verify in advance the applicability of rules on remote monitoring of workers, including Art. 4 of Italian Law No. 300 of 20 May 1970, as well as further information obligations under employment law.
Technical activation of the feature by GRADO HR does not constitute an assessment of the lawfulness of its use in the client's specific organisational context.
Artificial intelligence features remain off until at least one API key (or equivalent gateway) toward a supported provider is configured in the workspace: OpenAI, Anthropic (Claude), Google Gemini / Vertex AI or Amazon Bedrock.
The client company may enter its own API keys for its accounts with those providers, or use keys supplied by GRADO TECH Srls when the service is activated or configured by authorised GRADO staff. In the latter case the key may be “locked” by the administrator and then changed or replaced only by that administrator.
Keys are stored encrypted at rest. After saving, the interface shows only a mask (last digits) and not the full value. GRADO TECH Srls does not consult, copy or use the customer's keys for its own purposes, nor to access workspace content outside the cases in Part B. The platform decrypts the key in memory only, at the moment of the call to the provider, on the controller's instructions.
GRADO TECH Srls does not consult content sent to the model (photographs, text, prompts) for its own purposes, nor to train models. Usage metadata is recorded (provider, model, feature, token counts, estimated cost) so the controller can monitor consumption; such metadata does not include request content or the key in the clear. Any access by GRADO staff to workspace content remains limited to the cases in Part B.
If the controller uses its own keys, data for the requested function (for example the service photo or sampled text) is sent to the controller's account with that provider. In that case the AI provider is chosen and contracted by the controller: retention, training, location and any transfers outside the EU under that account remain the controller's responsibility. GRADO TECH Srls only forwards the technical request.
If the key is supplied and managed by GRADO TECH Srls, the AI provider acts as a sub-processor of GRADO TECH Srls within the limits of the contract and DPA. In that case GRADO TECH Srls favours, where available, processing in the European Economic Area, limited retention at the provider and no use of data for general model training.
Model providers (OpenAI, Google, Anthropic, Amazon Web Services / Bedrock) receive the data of each request according to the key and model configured in the workspace, as described in the “API keys” section.
Such parties process data to the extent necessary to deliver the requested function and under the applicable agreements: with the controller, if the key belongs to the customer; with GRADO TECH Srls, if the key is supplied by GRADO TECH Srls.
When the key is managed by GRADO TECH Srls and it is technically and contractually available, configurations providing processing in European Economic Area regions, limited retention at the provider and no use of client data for general model training are favoured.
GRADO TECH Srls does not use client data to train its own artificial intelligence models for independent purposes. An updated list of sub-processors and relevant processing locations is available as indicated in the “Sub-processors and recipients” section.
Data may be processed by appointed processors or sub-processors bound by Art. 28 GDPR agreements or equivalent contractual safeguards where applicable, including: Aruba S.p.A. (Via San Clemente 53, 24036 Ponte San Pietro (BG), Italy — VAT 01573850516), as provider of infrastructure services connected to the platform — Aruba GDPR, Aruba privacy notice; email services; any technical compromised-password checking services; Google LLC (1600 Amphitheatre Parkway, Mountain View, CA 94043, USA), limited to Google sign-in if the user enables it (OAuth: identifier and email) and, if the controller enables AI with a key managed by GRADO TECH Srls, to Gemini / Vertex AI — Google privacy notice; any AI and photo-evidence storage providers, strictly as needed: OpenAI OpCo, LLC / OpenAI Ireland Ltd (privacy), Anthropic, PBC (privacy), Amazon Web Services EMEA SARL for Bedrock and object storage in an EU region (privacy); authorities where required by law or by the controller's instructions; professional advisors where required by law. When the controller configures its own API keys, AI providers receive data on the controller's instructions and in relation to the controller's account: in that configuration they are not appointed by GRADO TECH Srls as its own sub-processors. When the key is supplied by GRADO TECH Srls, those providers act as sub-processors of GRADO TECH Srls within the limits of the contract and DPA. An updated list of relevant sub-processors is available on request at info@gradotech.it or attached to the contract.
Data is processed primarily within the European Economic Area, including through Aruba S.p.A. (Italy) and, for photo evidence and AI models under a strict EU configuration, through endpoints and storage in EU regions. More information: aruba.it/gdpr. If the user enables “Sign in with Google”, authentication data (identifier and email) is processed by Google LLC, which may transfer it to countries outside the EU on the basis of GDPR safeguards (adequacy decisions, EU-US Data Privacy Framework where applicable, Standard Contractual Clauses). Where AI features involve processing by OpenAI, Anthropic, Google or AWS and, as a result, transfers to third countries (for example the United States), such transfers occur only with appropriate GDPR safeguards, such as adequacy decisions (including, where applicable, the EU-US Data Privacy Framework), the European Commission’s Standard Contractual Clauses or other lawful instruments. If the controller uses its own keys, any transfers outside the EU depend on the account and settings the controller has with the AI provider, not on GRADO TECH Srls’ default configuration. Specific information on transfers connected to AI services is provided in the contract, the DPA or on request.
GRADO TECH Srls implements appropriate technical and organisational measures to protect data processed on GRADO HR: multi-tenant segregation, TLS encryption, irreversible password hashing, optional MFA with encrypted TOTP secrets, granular role-based access control, encryption at rest of payslip PDFs and net amounts (decryption only on request by an authenticated, authorised user), encryption at rest of AI service API keys (the full value is not shown in the interface after saving), resizing of service photos before they are sent to AI models and, in production/staging under a strict EU policy, object storage in an EU region with KMS encryption, technical cookies HttpOnly where applicable, backups, monitoring, audit logs (including net-amount reveals, AI service configuration and AI-notice acceptance) and compliance with ISO/IEC 27001:2024 standards. In the event of a personal data breach affecting data processed on behalf of the controller, GRADO TECH Srls will inform the controller without undue delay, as required by Art. 33 GDPR and the contract.
Payroll data is processed with additional measures compared with the rest of the workspace. In particular:
The controller warrants that data entered on GRADO HR is lawful, relevant, accurate and not excessive; that it has the rights and authorisations required (including for worker data, documents, IBAN, stamping geolocation, payslips and, if enabled, service photos and AI processing); that it correctly configures roles, modules, permissions and any AI deployments; and that it provides workers with the required privacy notice.
Before activating artificial intelligence features concerning workers, the controller is responsible for:
GRADO TECH Srls makes features available in accordance with the intended purpose of the product and implements the technical and organisational measures within its remit; the client company remains responsible for the lawfulness of the concrete use of the system within its organisation and in its relationship with its workers.
GRADO TECH Srls is not responsible for the controller's organisational or payroll decisions, the substantive or legal accuracy of entered content, or the privacy notice the controller must provide to data subjects. This notice does not constitute legal advice.
This notice may be updated to reflect regulatory, contractual or service changes. Any amendments will be published on this page with the date of the last update.