This notice explains how Employee Central GmbH handles personal data through our website and our service. We act as a controller for personal data we collect directly through this website, and as a processor under our customers' instructions for personal data they upload to the platform.

Data we collect

Why we process it

Lawful bases (GDPR)

Consent (marketing where required), contract performance, legitimate interest (security, fraud prevention, product improvement), legal obligation.

Sub-processors

We don't sell personal data. We share it only with sub-processors under contract, professional advisors, and authorities where legally required. International transfers governed by SCCs.

Retention

Marketing-form: 24 months. Customer platform data: per the customer's contractual schedule and applicable law. Audit logs: 7 years.

Your rights

Contact privacy@employee-central.com. Lead supervisory authority: Berliner Beauftragte für Datenschutz und Informationsfreiheit.

Security

SOC 2 Type II and ISO 27001 controls. Suspected compromise: security@employee-central.com.

Contact

Employee Central GmbH · Torstraße 35, 10119 Berlin · DPO: dpo@employee-central.com