hours24
← Back to home

Privacy Policy

Effective from: 16.07.2026 (for existing customers from 16.08.2026). This version replaces the version of 23.09.2019.

hours24 is workforce management software (the Service) owned and operated by Hours OÜ, Estonian registry code 16434060, address Nikolai 10, 80011 Pärnu, Estonia (hours24, we, us). The Service is used through the website hours24.com and the mobile applications (iOS and Android). Data protection questions: info@hours.ee.

The most important summary

We have two distinct roles and this policy separates them clearly:

  • When you visit our website, fill in an enquiry form, subscribe to the newsletter or act as a contact person of our customer, we are the CONTROLLER of your data - the main part of this policy covers that data.
  • When your employer uses the hours24 Service and enters your data as an employee (working time, leave, pay data etc.), the controller of your data is YOUR EMPLOYER. We are the processor and process that data only on the employer's instructions. For questions about that data, please contact your employer first.

1. When we are the controller

Hours OÜ is the controller (GDPR Art 4(7)) of the following data:

  • website enquiry form data: demo booking, price quote requests, free tool material downloads, webinar and event registrations, newsletter subscription (name, e-mail, phone, company, number of employees, message content);
  • customer account administration data: names, e-mails, phone numbers, roles and login data of the Customer's contact persons;
  • billing data: invoices, payment information, contractual correspondence;
  • correspondence between you and us (e-mail, support requests);
  • website technical data: IP address, device and browser information, cookies (analytics and marketing cookies only with your consent - see the Cookie Policy).

We may also receive a contact person's data from the Customer itself (e.g. when an administrator adds a colleague as a contact person or invoice recipient). In that case the source of the data is the Customer, and we refer that person to this policy at the first reasonable opportunity (e.g. in the first e-mail).

2. When we are the processor

When a Customer (employer) uses the Service, we host and process their employees' data on their instructions (GDPR Art 28). Such data may include:

  • employee name, contact details, employee number, position, unit;
  • working time data: clock-ins, breaks, shifts, schedules, overtime;
  • absences and their types (including the fact of sickness-related absence), leave balances;
  • pay-related data (hourly rates, premiums, bonuses), contract data and documents;
  • attendance data from devices: terminal identification events, QR clock-ins, Bluetooth beacon presence events, access control door events, and vehicle location data from fleet integrations activated by the Customer;
  • mobile app location data (only if the employee has themselves enabled geofence automation - see section 6);
  • workspace content: chat messages, announcements, survey responses, uploaded files.

The purposes and legal basis for collecting this data are determined by the Customer as the controller. Our staff access the content of a Customer's environment only to provide the service, to deliver support requested by the Customer or where required by law; such access is logged. We do not use Customer employees' data for our own purposes. The detailed terms of processing (including sub-processors and deletion of data at the end of the agreement) are set out in the data processing chapter of the Terms of Service, which operates as the data processing agreement (DPA).

3. Purposes, legal bases and retention

As a controller we process data as follows:

PurposeDataLegal basis (GDPR Art 6)Retention
Responding to enquiries (demo, quotes, contact)name, e-mail, phone, company, messagepre-contractual measures (b)up to 2 years from last contact
Concluding and performing the Service agreement, account administrationcontact person data, account dataperformance of a contract (b)for the term of the agreement + 3 months after account closure
Invoicing and accountingbilling datalegal obligation (c) - Estonian Accounting Act7 years from the end of the financial year
Newsletter and marketing messagese-mail, nameconsent (a) - may be withdrawn at any timeuntil consent is withdrawn or 2 years from last contact
Webinars and eventsname, e-mail, companyconsent (a) / pre-contractual measures (b)up to 2 years from the event
Website analytics and marketing measurementcookies, usage dataconsent (a) - see the Cookie Policyas set out in the Cookie Policy
Service security, preventing misuse and fraudlogs, IP address, technical datalegitimate interest (f) - protecting the service and customersup to 1 year; in case of a security incident until the matter is resolved
Establishing and defending legal claimscontract and correspondence datalegitimate interest (f) - protection of rightsup to 10 years (limitation periods)

Where we rely on legitimate interest, we have assessed that our interest (providing a secure, functioning service and protecting rights) is not overridden by your rights and freedoms. You may object to such processing at any time (see section 10).

Providing enquiry form data is voluntary, but without contact details we cannot respond. Providing customer account data is a precondition for concluding and performing the Service agreement - without it we cannot provide the Service.

4. Cookies, analytics and marketing

The website uses necessary cookies for the Service to function. We use analytics (Google Analytics) and marketing cookies (Meta Pixel) ONLY with your prior consent, which you can change or withdraw at any time. The exact list, lifetimes and consent management are described in the Cookie Policy.

5. Recipients and sub-processors

We never sell personal data. We use carefully selected service providers (sub-processors) in the following categories:

  • cloud infrastructure and data hosting (data centres in the European Union);
  • e-mail delivery service (transactional and notification e-mails);
  • AI feature provider (only when the AI module is used, under a data processing agreement; inputs are not used to train AI models);
  • analytics and marketing services (only with consent, see the Cookie Policy);
  • demo booking calendar service (when you book a time in the calendar).

All sub-processors are bound by GDPR Art 28 agreements. You can request the current list of sub-processors at info@hours.ee. We give Customers advance notice of any intended addition or replacement of sub-processors (see the data processing chapter of the Terms of Service). We may also disclose data where required by law or a competent authority, and to a legal successor in the event of a merger or acquisition, provided the recipient undertakes to comply with this policy.

If the Customer activates an integration (e.g. payroll or accounting software, an e-signing service, an access control system), data is transferred to the service chosen by the Customer on the Customer's instructions. The respective provider and/or the Customer are responsible for the processing in those services.

6. Mobile app location data

The hours24 mobile app may collect and process the device's location data - both approximate and precise location (GPS) - including in the background, that is, also when the app is not open or not on screen.

Location data is used for the sole purpose of providing the automatic work-time tracking that the user chooses to enable: the app may automatically start or stop the user's own work-time measurement when the user enters or leaves a work area designated for them (geofencing). Location is processed only to record the user's own working time; the app does not display the location of other people and does not track the user in real time.

This feature is turned off by default and is entirely optional. Location-based automation works only if the user turns it on themselves in the app and grants the device-level location permission (including permission for background use). The user can turn the feature and the location permission off at any time in the app or device settings.

We do not sell location data and do not transfer it to third parties for advertising or any other purpose unrelated to work-time tracking. The app may also request camera permission (e.g. for scanning asset QR codes or taking a profile photo) and push notification permission - both are optional and managed in device settings.

7. Biometric identification in terminals

Terminals that identify employees by fingerprint, face or palm can be connected to the Service. Identification uses a mathematical template, not an image - the template is not a photo and does not allow the original fingerprint or face to be reconstructed in normal use. Such a template is nevertheless special category (biometric) personal data within the meaning of GDPR Art 9, subject to stricter requirements.

The decision to adopt biometric identification is made by the Customer (employer) as the controller. The Customer is responsible for ensuring a legal basis - in Estonian practice the employee's explicit prior consent -, offering an equivalent alternative clock-in method (e.g. RFID tag, QR code or PIN) to those who do not consent, and deleting the template when consent is withdrawn. The Service receives identification events from terminals (time, person, device), which we process on the Customer's instructions for working time records.

8. AI features and automated decisions

The optional AI features of the Service (e.g. the AI assistant, schedule drafting help) may, at the Customer's request, process data in the Customer's environment to produce answers and suggestions. To provide AI features we may use a third-party AI service provider bound by a data processing agreement; inputs and outputs are not used to train AI models.

We do not make automated decisions based on personal data that would have legal or similarly significant effects within the meaning of GDPR Art 22. AI outputs are assistive suggestions; a human always makes the decision.

9. Data location, transfers and security

Service data is hosted in data centres located in the European Union (Frankfurt, Germany). Where individual service providers (e.g. the AI feature provider, or analytics and marketing services used with your consent) process data outside the European Economic Area, we ensure the transfer is lawful either under a European Commission adequacy decision (including the EU-US Data Privacy Framework) or standard contractual clauses (SCCs). To obtain a copy of the safeguards, write to info@hours.ee.

Our security measures include:

  • encryption of data in transit (TLS) and at rest;
  • passwords stored only as hashes;
  • role-based access control and access logging;
  • regular backups and recovery procedures;
  • staff confidentiality obligations and access only for work duties.

If a personal data breach concerns data for which we are the controller, we notify the Estonian Data Protection Inspectorate and affected individuals in accordance with GDPR Art 33 and 34. If a breach concerns data in a Customer's environment, we notify the Customer without undue delay, and the Customer as controller decides on notifying the supervisory authority and the data subjects.

10. Your rights

You have the following rights regarding your personal data:

  • right of access (Art 15) - to receive confirmation of whether and which of your data we process;
  • right to rectification (Art 16);
  • right to erasure (Art 17), unless the law requires retention (e.g. accounting data for 7 years);
  • right to restriction of processing (Art 18);
  • right to data portability (Art 20);
  • right to withdraw consent at any time - as easy as giving it (e.g. via the newsletter link), without affecting the lawfulness of prior processing.

Right to object (Art 21): you have the right to object at any time to processing based on legitimate interest, and always to processing for direct marketing purposes. To object, write to info@hours.ee.

To exercise your rights, write to info@hours.ee. We respond within one month at the latest; for complex requests we may extend the deadline and will inform you. We may ask for additional identity verification (e.g. a digitally signed request). If your data is processed through us by your employer, we will forward the request to them or direct you to them - the employer as the controller decides on that data.

If you believe your rights have been violated, you have the right to lodge a complaint with the Estonian Data Protection Inspectorate (aki.ee, info@aki.ee, Tatari 39, 10134 Tallinn, Estonia) or the supervisory authority of your country of residence, and to go to court.

11. Minors

The Service is intended for companies and their employees. We do not direct the Service at children under 13 and do not knowingly collect their data.

12. Changes to this policy

If we make material changes to this policy, we will notify Customers by e-mail or through the Service a reasonable time in advance. The current version with its effective date is always published on this page.

13. Contact

Hours OÜ (registry code 16434060)
Nikolai 10, 80011 Pärnu, Estonia
E-mail: info@hours.ee