myHR
Funcionalidades Sobre Nós
  • English
  • Français
  • Deutsch
  • Português
Teste Gratuito Pedir demonstração
Contacte-nos Sobre nós Workshops Acordos e políticas legais Acesso de colaboradores
Proteção de Dados Política de Privacidade Termos de Serviço Acordo SLA Acordo de GDPR Cookies Documentação

Acordo de GDPR

Pode contar connosco - o myHR está em conformidade com o GDPR de ponta a ponta. Este Acordo de Tratamento de Dados (DPA) estabelece os termos contratuais ao abrigo dos quais tratamos dados pessoais em seu nome.

Última atualização: 02/09/2024

Mantém-se como responsável pelo tratamento

O cliente mantém-se responsável pelo tratamento dos dados pessoais dos seus colaboradores. Atuamos como seu subcontratante, seguindo as suas instruções documentadas.

  • Cliente = responsável pelo tratamento
  • myHR = subcontratante
  • Tratamento segundo as suas instruções

Salvaguardas técnicas robustas

Encriptação, controlos de acesso, registos de auditoria, cópias de segurança regulares, diligência devida sobre subcontratantes - todas as salvaguardas exigidas pelo Artigo 32.º do GDPR estão em vigor.

  • Encriptação em repouso e em trânsito
  • Subcontratantes auditados
  • Revisões de segurança anuais

Os seus direitos enquanto titular dos dados

Ajudamo-lo a responder aos pedidos de acesso, retificação, eliminação e portabilidade dos seus colaboradores - dentro dos prazos definidos pelo GDPR.

  • Acesso e retificação (Art. 15-16)
  • Eliminação e limitação (Art. 17-18)
  • Portabilidade (Art. 20)

The myHR Data Processing Agreement (“DPA”) governs the processing of personal data when using myHR Services under the myHR Terms of Service. Unless otherwise agreed, myHR acts as a data processor (“Processor”) on behalf of the customer (“you”), the data controller (“Controller”). The Processor and Controller are collectively referred to as the “Parties.”

Considering that:

  • The Controller has access to personal data of various clients (hereinafter: “Data Subjects”);
  • The Controller requires the Processor to perform specific processing tasks as per the SaaS Agreement;
  • The Controller determines the purpose and means of processing personal data governed by this DPA;
  • The Processor agrees to comply with this DPA and Luxembourg legislation on data protection and privacy, including GDPR.

The Parties agree as follows:

1. Processing Objectives

  1. The Processor agrees to process personal data on behalf of the Controller per the conditions laid out in this DPA.
  2. Processing will be performed exclusively within the scope of the SaaS Agreement and for purposes agreed upon thereafter.
  3. The Processor shall not use personal data for any purpose other than those specified by the Controller.
  4. All personal data processed on behalf of the Controller remains the property of the Controller and/or the relevant Data Subjects.
  5. The Processor shall not make unilateral decisions regarding data processing, including sharing data with third parties or data retention.

2. Processor's Obligations

  1. The Processor shall comply with all applicable laws and regulations, including those related to data protection, such as GDPR.
  2. The Processor shall provide the Controller, upon request, with details regarding the measures taken to comply with this DPA and GDPR.
  3. The Processor's obligations under this DPA apply equally to any third party processing personal data under the Processor's instructions.

3. Transmission of Personal Data

  1. The Processor will not process or transfer personal data to countries outside the EU.

4. Allocation of Responsibility

  1. The Processor is responsible for processing personal data under this DPA, according to the Controller's instructions.
  2. The Processor is not responsible for any other processing, including processing not reported by the Controller or by third parties.
  3. The Controller warrants it has legal grounds to process the relevant personal data and indemnifies the Processor against related claims.

5. Engaging Third Parties or Subcontractors

  1. The Processor may engage third parties for processing within the framework of the agreement, without prior approval from the Controller.
  2. The Processor shall inform the Controller of any engaged third parties upon request.
  3. The Processor shall ensure that such third parties agree in writing to the same obligations between the Controller and the Processor.

6. Duty to Report

  1. In case of a security breach or data leak, the Processor shall notify the Controller without undue delay.
  2. The Controller will determine whether to inform the Data Subjects or relevant regulatory authorities.
  3. The Processor will ensure the information provided about the breach is complete, correct, and accurate.
  4. If required by law, the Processor shall cooperate in notifying the relevant authorities and/or Data Subjects.
  5. The Controller remains responsible for statutory obligations in this regard.
  6. The duty to report includes the obligation to report the breach's occurrence, including:
    • The (suspected) cause of the breach;
    • The (currently known and/or anticipated) consequences;
    • The (proposed) solution;
    • The measures already taken.

7. Security

  1. The Processor shall implement adequate technical and organizational measures to protect personal data against unlawful processing.
  2. The Processor will ensure that security measures are reasonable, considering the data's sensitivity and associated costs.
  3. The Controller shall only provide personal data to the Processor once assured that necessary security measures are in place.
  4. The Controller is responsible for ensuring compliance with the security measures agreed upon by the Parties.

8. Handling Requests from Data Subjects

  1. If a Data Subject submits a request to the Processor regarding their personal data, the Processor will forward the request to the Controller.
  2. The Controller will handle the request, and the Processor may notify the Data Subject that their request has been forwarded.

9. Non-disclosure and Confidentiality

  1. All personal data received by the Processor from the Controller under this DPA is subject to confidentiality obligations.
  2. This confidentiality obligation does not apply if the Controller authorizes the disclosure or if there is a legal obligation to disclose.

10. Audit

  1. The Controller may conduct an audit to confirm compliance with this DPA by appointing an independent third party.
  2. Any audit must adhere to the Processor's security requirements and must not unreasonably interfere with the Processor's business activities.
  3. The audit may only be conducted when there are specific grounds for suspecting misuse of personal data.
  4. The audit can only be conducted after the Controller provides written notice to the Processor at least two weeks in advance.
  5. The audit findings will be discussed and evaluated by the Parties, and any necessary actions will be implemented accordingly.
  6. The Controller will bear the costs of the audit.

11. Duration and Termination

  1. This DPA is valid for the duration specified in the SaaS Agreement or for the duration of the cooperation between the Parties.
  2. This DPA may not be terminated mid-term.
  3. Any amendments to this DPA must be mutually agreed upon by the Parties.
  4. The Processor shall cooperate in amending this DPA in the event of new privacy legislation or regulations.

12. Miscellaneous

  1. This DPA and its implementation will be governed by and interpreted in accordance with the laws of Luxembourg.
  2. Any legal action arising under this DPA will be brought exclusively in courts located in Luxembourg, and the Parties consent to this jurisdiction.
  3. In case of any inconsistency between documents, the following order of priority will apply:
    1. The contract signed between Processor and Controller;
    2. This Data Processing Agreement;
    3. Additional conditions, if applicable.
  4. Logs and measurements taken by the Processor shall be considered authentic unless the Controller provides convincing evidence to the contrary.

Precisa de um DPA assinado?

Teremos todo o gosto em enviar-lhe uma cópia contra-assinada do nosso DPA padrão ou em negociar uma versão personalizada com a sua equipa jurídica.

Solicitar um DPA assinado → Leia a nossa Proteção de Dados
myHR SARL
17, rue Léon Laval
L-3372 Leudelange
Luxemburgo
  • +352 27 72 03 09
  • support@myhr.lu
  • Seg-Sex, 9:00-17:30
Empresa
  • Sobre nós
  • Contacte-nos
  • Proteção de dados
  • Participe nos nossos workshops
Aspetos legais
  • Política de Privacidade
  • Termos de serviço
  • Acordo de SLA
  • Acordo de GDPR
  • Política de cookies
Funcionalidades
  • Ausências e Faltas
  • Terminais de ponto
  • Convenções coletivas
  • Assistente de IA Pixie
  • Planeamento de turnos para equipas
  • Avaliações de desempenho
  • Relatórios de Despesas
  • Autosserviço do colaborador
  • Base de dados de RH centralizada
  • Todas as funcionalidades
© 2026 myHR SARL
RCS B204620 · VAT LU28504264
EN FR DE PT