Skip to content

Legal

Data processing agreement

This agreement is part of the Staffora terms of service. It applies when a customer stores personal data in Staffora. The customer is the controller. ACL GESTION, the company that operates Staffora, is the processor. If this agreement and the terms conflict on a point of data protection, this agreement prevails.

Last updated 10 October 2026

1. What we process

We process personal data only to provide Staffora: to host the customer’s account, to let authorised users work with it, to send the notices the product is configured to send, to support the customer, and to keep the service secure.

The people concerned are the customer’s employees and contractors, their emergency contacts, and the users the customer invites. The data is the HR information the customer enters or that the product generates from it, including identity and contact details, employment records, national identity card numbers, leave, attendance, device keys used for attendance, asset assignments and audit events.

Processing lasts for the subscription and for the deletion period in the section on return and deletion.

2. Instructions

We act on the customer’s documented instructions. These terms, this agreement, and the customer’s use of the product’s settings are those instructions. We will tell the customer if we believe an instruction breaks European Union data-protection law, unless the law forbids us to say so.

We do not use customer HR data to advertise, to train public models, or for any purpose of our own.

3. Confidentiality

People who can access customer HR data are limited to those who need it to operate the service, and they are bound by confidentiality. Access is controlled by role and is recorded when it concerns sensitive actions, including revealing a national identity card number.

4. Security

We apply measures appropriate to HR data, including encryption in transit, encryption of the national identity card number at rest, separation between customers, multi-factor sign-in for administrative access, session expiry, and an audit trail of important actions. We review these measures as the service changes.

5. Sub-processors

The customer authorises the providers below. Each is bound by a written contract that requires protection of the data consistent with this agreement.

  • The infrastructure host that stores the application and customer data, located in France. We give the host’s name to the customer on request
  • Google, for delivery of product email such as invitations and leave notices
  • PayHere (Private) Limited, Sri Lanka, for card payments. PayHere receives billing details for the subscription, not employee HR records

6. Changes to sub-processors

We will tell account administrators before we appoint a new sub-processor that handles customer HR data, or before we replace one. The customer may object on reasonable data-protection grounds within 30 days. If we cannot offer a reasonable alternative, the customer may end the subscription before that provider starts work, and we will refund any fees already paid for the unused part of the period.

7. Location and transfers

Customer HR data is hosted in France. Where a sub-processor processes personal data outside the European Economic Area, we use a transfer tool recognised by European Union law, such as the provider’s standard contractual clauses, together with any extra measure that transfer requires.

The customer is responsible for the basis on which it is allowed, under Sri Lankan law, to send its employees’ data to a processor in France. This agreement is the written safeguard we provide for that arrangement.

8. Requests from people

We will help the customer respond to requests from people to access, correct, delete, restrict or receive their data, taking into account how the product works. If someone contacts us directly about a customer’s HR record, we will refer them to the customer unless the customer asks us to reply or the law requires us to act.

9. Personal data breaches

We will tell the customer without undue delay after we become aware of a personal data breach affecting its data, and where we can, within 48 hours. The notice will describe what happened, the data affected, the likely consequences, and the measures taken or proposed. We will cooperate with the customer so it can meet its own duty to notify an authority or the people concerned.

10. Audits

We will make available the information the customer reasonably needs to show that we meet this agreement. Once a year, the customer may ask written questions or, on reasonable notice, a review conducted so that it does not compromise other customers’ data. The customer bears its own cost unless the review shows a material breach of this agreement.

11. Return and deletion

During the subscription and for 30 days after it ends, the customer may export its data. At the end of that period we delete the live records, unless European Union or French law requires us to keep a particular record. Backup copies are removed in the ordinary backup cycle, within 30 days after the live records are deleted. Invoices are kept for the legal retention period and are not part of the HR export.

12. Law

This agreement is governed by French law, including Regulation (EU) 2016/679 where it applies to ACL GESTION as a processor established in France. The courts of Bobigny have jurisdiction, on the same terms as the terms of service.