Loftigo

Employee Privacy Notice

Privacy information for employees and applicants pursuant to Art. 13 GDPR

This is a translation provided for your convenience. The German version of this document is the legally binding one; in case of any discrepancy, the German text prevails.

1. Who and what does this notice cover?

This notice is addressed to everyone whose data we process in connection with employment with us: applicants, employees (including temporary staff, trial workers and working students) and former employees, insofar as we still have to retain their data.

It describes which personal data we process in our internal systems – in particular in the staff cockpit –, for what purpose, on what legal basis, how long we store it and what rights you have.

This notice supplements our website privacy policy (available at /privacy-policy) and does not replace it. The privacy policy applies to you in addition, insofar as you use our website like any other visitor.

2. Controller

The controller for the processing described here is: Loftigo UG (haftungsbeschränkt), Vollmühle 24a, 52538 Selfkant, Germany, represented by Christopher Martin Müller, Vlattenstraße 10, 40223 Düsseldorf, Germany. Telephone: 02456 7059950, email: help@loftigo.com

No data protection officer has been appointed. Please direct questions about data protection and requests to exercise your rights to the address above or to help@loftigo.com.

3. Application process

What we process: If you apply through our website or by email, we process the details from the application form – first and last name, email address, telephone number, your message and your CV as a PDF file –, the position you are applying for, the time of the application, the processing status (new, reviewed, invited, rejected) and the IP address from which the application was sent.

Your CV file is stored outside the publicly accessible area of our server and can only be retrieved after logging in, by the people involved in the selection decision.

Purpose and legal basis: We process this data to carry out the application process and to decide whether to establish an employment relationship. The legal basis is section 26(1) sentence 1 of the German Federal Data Protection Act (BDSG) in conjunction with Art. 88(1) GDPR, and Art. 6(1)(b) GDPR (pre-contractual measures). We additionally store the IP address to protect the form against misuse and automated submissions on the basis of Art. 6(1)(f) GDPR.

Storage period: If we cannot offer you a position, we store your application data for a maximum of six months after the end of the application process; the period begins when the rejection is received (section 61b(1) of the German Labour Court Act in conjunction with section 15 of the General Equal Treatment Act). Longer inclusion in a talent pool only takes place with your express consent under Art. 6(1)(a) GDPR and then for a maximum of two years. If you are hired, we transfer the required data to your personnel file.

Voluntary nature: Providing your data is voluntary. Without the details marked as mandatory, however, we cannot process your application. Please do not send us special categories of personal data (e.g. information on health, religion or trade union membership) unless they are necessary for the application.

4. Personnel master data and the employment relationship

What we process: First and last name, business contact details, the link to your user account and role, department and team, type of employment, start date, your internal status (e.g. active, paused, ended) including the time and reason for a change of status, any end date, and authorisation for the entrance area.

Key events relating to the employment relationship (e.g. status changes or warnings issued) are recorded in an event list together with the time and the person who triggered them.

Purpose and legal basis: Establishing, carrying out and ending the employment relationship, staff scheduling, granting and withdrawing authorisations, and keeping records. The legal basis is section 26(1) sentence 1 BDSG in conjunction with Art. 88(1) GDPR and Art. 6(1)(b) GDPR, and additionally Art. 6(1)(c) GDPR for legally required information.

5. Working time recording and staff scheduling

What we process: When you clock in and out in the cockpit, we record the date and time of the start and end of your working time, the resulting duration, the activities you record and the properties assigned, the approval of the month by those responsible for personnel, and the assignment of a time entry to a payout. We also process planned shifts as well as the tasks and cleaning assignments allocated to you.

Purpose and legal basis: Recording and monitoring working hours, compliance with the German Working Hours Act, staff scheduling and payroll. The legal basis is Art. 6(1)(c) GDPR in conjunction with section 16(2) of the German Working Hours Act (ArbZG) and section 17(1) of the German Minimum Wage Act (MiLoG) (recording obligation in the accommodation sector), as well as section 26(1) sentence 1 BDSG.

What we do not do: Clocking in and out records neither your location nor GPS data. No performance or behaviour monitoring takes place beyond what is required for payroll and the statutory records.

6. Breaks and break violations

What we process: When you clock out, we ask which break you actually took. We store the break times and your confirmation. If a legally required break is not taken, this is recorded as a violation. From the fifth violation onwards, the system generates a one-off warning; you and those responsible for personnel are informed by email, and the warning is stored.

Purpose and legal basis: Compliance with the statutory rest breaks under section 4 ArbZG, health and safety at work, and evidence towards the supervisory authorities. The legal basis is Art. 6(1)(c) GDPR in conjunction with sections 4 and 16 ArbZG and section 26(1) sentence 1 BDSG.

Note on automation: The counting of violations and the notification are automated. No employment-law measure is derived from this automatically; such measures are always decided by a person after reviewing the individual case.

7. Leave, absences and incapacity for work

What we process: The type of absence (holiday or sickness), the start and end or the expected end, the number of working days affected, the status of your request, your note on it, the decision including the deciding person, the time and the reasons given, as well as your leave entitlement for the respective year and how much of it you have used.

For sickness notifications we only record the fact of the incapacity for work and its duration – no diagnoses and no information about the nature of the illness. From the second day of sickness, a medical certificate must be submitted; if you submit it as a document, it is filed under the category "sick note" (see section 8).

Purpose and legal basis: Granting leave, continued payment of remuneration in the event of illness, staff scheduling, and fulfilling our obligations under employment and social security law. Information on incapacity for work constitutes health data and therefore a special category of personal data. The legal basis is Art. 9(2)(b) GDPR in conjunction with section 26(3) BDSG, section 5 of the German Continued Remuneration Act and the German Federal Leave Act; otherwise section 26(1) sentence 1 BDSG.

Access: Only the people who have to process the request or carry out payroll have access to absence and health data.

8. Personnel documents

What we process: We file documents relating to your employment in the categories contract, sick note, identity document, reference or certificate, and other. In addition to the file itself, we store the title, the original file name, the file type and size, the time of upload and the person who uploaded it.

The files are stored outside the publicly accessible area of our server; they can only be retrieved after logging in and only by authorised persons.

Purpose and legal basis: Carrying out the employment relationship and fulfilling statutory documentation and retention obligations. The legal basis is section 26(1) sentence 1 BDSG and Art. 6(1)(c) GDPR, and for health data Art. 9(2)(b) GDPR in conjunction with section 26(3) BDSG. Identity checks are based on the obligation to carry and check identity documents in the accommodation sector under section 2a of the German Act to Combat Illicit Work.

9. Remuneration and payouts

What we process: For each payout we store the amount and currency, the payment method (cash or bank transfer), the underlying working time in minutes and the number of time entries taken into account, the settlement period, the payout date, a note and the person who recorded the payout.

Payroll accounting itself (this includes, for example, tax identification number, social security number, bank details, tax class and religious affiliation) takes place outside this application and is carried out by the tax consultancy we have engaged for payroll, KSL3 Steuerberater | Kott & Schnitter – Steuerberater PartG mbB, Girardetstraße 4, 45131 Essen, Germany.

Purpose and legal basis: Fulfilling our payment obligations under the employment relationship as well as obligations under tax and social security law. The legal basis is Art. 6(1)(b) and (c) GDPR and section 26(1) sentence 1 BDSG.

10. Internal team chat

What we process: In the internal chat we process the content of your messages, the sender, the time, the members of the respective conversation, the time you last read it, reactions to messages and your setting as to whether you have muted a conversation. So that you notice a message outside the cockpit as well, we send throttled email notifications.

Message content is stored encrypted in the database (AES-256-GCM) and is only decrypted when displayed to the members of the respective conversation.

Purpose and legal basis: Organising day-to-day work and internal communication. The legal basis is section 26(1) sentence 1 BDSG and Art. 6(1)(f) GDPR (legitimate interest in functioning internal communication).

Important: The chat is a work tool; private use is not intended. Management does not read along on an ongoing basis. Chat content is only accessed on a case-by-case basis where there is a concrete suspicion of a serious breach of duty or a criminal offence, limited to what is necessary and documented.

11. Personal access codes and electronic door locks

What we process: You receive a personal numeric code for the electronic door locks. We store the display name held at the lock, the code itself, the status (active, rotated, revoked), the validity period, the time of the last rotation and the technical assignment within the locking system. The codes are changed automatically every two months and are revoked when the employment relationship ends.

Door actions that you trigger through the cockpit (e.g. opening the entrance area) are logged with your user ID, the lock concerned, the property, the action, your IP address and the time. Automatic locking operations of our system are marked as such and are not attributed to any person.

We operate the locking systems using products of Nuki Home Solutions GmbH, Münzgrabenstraße 92/4, 8010 Graz, Austria, which acts as a processor for us in this respect.

Purpose and legal basis: Securing our properties and our guests’ property, issuing individual rather than shared codes, and traceability in the event of damage or suspicion. The legal basis is Art. 6(1)(f) GDPR and section 26(1) sentence 1 BDSG. The logs are not evaluated for general behaviour or performance monitoring; they are only evaluated on a case-by-case basis in response to a concrete incident.

12. Personal calendar and calendar subscription

What we process: The personal calendar shows you your own assignments, tasks and absences. If you wish, you can subscribe to this calendar in your calendar app; for this we generate a personal, secret retrieval link (token) and store it together with the time it was created.

Please note: anyone who knows this link can retrieve your appointments. Do not pass it on. The link is not rotated automatically; we will reset it at your request.

Purpose and legal basis: Staff scheduling and your own overview of your work appointments. The legal basis is section 26(1) sentence 1 BDSG; we only set up the subscription at your request.

13. Weather notice when clocking in

What we process: When you clock in, we show you a safety notice in case of extreme heat, frost or icy conditions. To do so, our server retrieves the current weather for the region. The request uses fixed coordinates for the region, is cached jointly for all employees and contains no information about you – in particular, your IP address is not transmitted to the weather service (Open-Meteo).

Purpose and legal basis: Protecting your health when working in adverse weather conditions. The legal basis is Art. 6(1)(f) GDPR in conjunction with our duty of care under section 618 of the German Civil Code and the German Occupational Safety and Health Act.

14. Application log data

What we process: Page views and operations in the cockpit are logged. We record the time, the function called, your user ID, the booking number concerned where applicable, your IP address, the processing duration and, in the event of an error, the technical error message. Independently of this, technical log files are generated when the server is operated.

Since you access guest and booking data in the course of your work, those accesses are also covered by the logging.

Purpose and legal basis: Operational and data security, troubleshooting, detecting and investigating misuse, and traceability of security-relevant operations. The legal basis is Art. 6(1)(f) GDPR in conjunction with Art. 32 GDPR. The logs are not systematically evaluated for performance or behaviour monitoring.

Storage period: The logs are deleted automatically after a short time; they are only retained longer where a concrete security incident has to be investigated.

15. Video surveillance at our properties

At our properties we use video cameras that record exclusively the outdoor area and generally accessible hallway areas. You may also be recorded in your capacity as an employee. The scope, purpose, technology used, storage period (a maximum of 90 days) and your right to object are described in section 22 of our privacy policy at /privacy-policy; that information applies to you accordingly.

In addition, the following applies to employees: workplaces, staff rooms and break areas are not monitored. The material is not evaluated for behaviour or performance monitoring; it is only evaluated on a case-by-case basis in response to a concrete incident. The legal basis is Art. 6(1)(f) GDPR and section 26(1) sentence 1 BDSG.

16. Recipients of your data

Internally, only those people have access who need the respective data for their tasks – in particular management, those responsible for personnel, and staff scheduling. Access is restricted by roles and permissions.

As processors under Art. 28 GDPR we use service providers in the areas of hosting and server operation, email delivery, the locking system, the camera system and building technology. They are contractually obliged to process data on our instructions and confidentially.

Further recipients may be: the tax consultancy engaged for payroll, KSL3 Steuerberater | Kott & Schnitter – Steuerberater PartG mbB, Girardetstraße 4, 45131 Essen, Germany, the tax office, social security institutions and health insurance funds, the employers’ liability insurance association, the customs authority’s unit for combating illicit work, other authorities and courts, and our legal advisers – in each case only insofar as we are legally obliged or entitled to do so.

Your data is generally processed within the European Union or the European Economic Area. Where a transfer to a third country exceptionally takes place (for example for secure access to the camera system), it is safeguarded by EU standard contractual clauses pursuant to Art. 46(2)(c) GDPR.

17. Storage period and deletion

As a matter of principle, we store your data for as long as it is required for the purposes stated, and beyond that for as long as statutory retention obligations exist or claims can be asserted. In particular, the following applies:

• Application documents: six months after the end of the process; up to two years where you consent to inclusion in the talent pool. • Working time records: at least two years (section 16(2) ArbZG, section 17(2) MiLoG). • Remuneration and accounting records: six or ten years (section 257 of the German Commercial Code, section 147 of the German Fiscal Code); payroll accounts until the end of the sixth calendar year following the last entry (section 41(1) sentence 9 of the German Income Tax Act). • Social security records: until the end of the calendar year following the last audit (section 28f of the German Social Code, Book IV). • Video recordings: a maximum of 90 days. • Access codes: rotated every two months, revoked when the employment relationship ends. • Application log data: deleted automatically after a short time.

After the employment relationship ends, we delete or anonymise the data we no longer need and that is not subject to a retention obligation. We record the time of anonymisation so that it remains verifiable that the personal reference was removed. Records subject to retention obligations are kept until the respective period expires and are deleted afterwards.

18. Are you obliged to provide your data?

Providing the data we need to initiate, carry out and end the employment relationship and to fulfil our statutory obligations is necessary. Without this information we cannot conclude or perform an employment contract.

Voluntary, by contrast, are for example the calendar subscription, a profile picture and any information you provide beyond what is necessary. Not providing these has no disadvantages for you.

19. No automated decision-making in individual cases

No decision based solely on automated processing which produces legal effects concerning you within the meaning of Art. 22 GDPR takes place. Automatically generated notices – for example about break violations or the rotation of access codes – are always assessed by a person before any consequences are drawn from them.

20. Your rights

You have the following rights with regard to your personal data:

• access to the data processed under Art. 15 GDPR, • rectification of inaccurate data and completion of incomplete data under Art. 16 GDPR, • erasure under Art. 17 GDPR, unless a retention obligation prevents it, • restriction of processing under Art. 18 GDPR, • data portability under Art. 20 GDPR, • objection to processing based on Art. 6(1)(f) GDPR on grounds relating to your particular situation (Art. 21 GDPR), • withdrawal of any consent given, with effect for the future, under Art. 7(3) GDPR; the lawfulness of processing carried out until then remains unaffected.

To exercise your rights, a message to help@loftigo.com or to the address given in section 2 is sufficient. Exercising your rights has no adverse consequences for your employment relationship.

21. Right to lodge a complaint with a supervisory authority

Irrespective of the above, you may lodge a complaint with a data protection supervisory authority at any time under Art. 77 GDPR if you believe that the processing of your data is unlawful.

The authority responsible for us is the State Commissioner for Data Protection and Freedom of Information of North Rhine-Westphalia (LDI NRW), Kavalleriestraße 2–4, 40213 Düsseldorf, Germany. You may also contact the supervisory authority at your place of residence or place of work.

22. Changes to this notice

We update this notice when the processing described here changes – for example because a new function is added to the cockpit. The current version is always available at /employee-privacy; the version date is shown at the end of this page.

Fassung 2.0 vom 11.08.2026

Domů

Objevit

Účet