GDPR Compliance

Last updated: January 2026

Our Commitment

Qrew is built with privacy by design. We comply with the EU General Data Protection Regulation (GDPR 2016/679) and the Italian Personal Data Protection Code (D.Lgs. 196/2003 as amended by D.Lgs. 101/2018).

Data Controller

Qrew S.r.l. is the data controller. Contact our DPO at [email protected].

Lawful Basis for Processing

PurposeLegal Basis
Time-tracking service deliveryContract performance (Art. 6(1)(b))
Payroll calculationsContract performance + legal obligation
GPS geofencingLegitimate interest — fraud prevention (Art. 6(1)(f))
Photo verificationConsent (Art. 6(1)(a))
Push notificationsConsent (Art. 6(1)(a))
Audit loggingLegitimate interest — compliance evidence
Device fingerprintingLegitimate interest — anti-spoofing

Data Subject Rights

You have the following rights under the GDPR:

Submit requests to [email protected]. We respond within 30 days.

Data Retention

Time-tracking records are retained for 10 years as required by Italian employment law (Art. 2949 Codice Civile). Audit logs are retained for 10 years for tribunal-ready compliance. Other personal data is deleted within 30 days of account closure.

International Transfers

All data is stored in EU data centres. We do not transfer personal data to third countries. Stripe (payment processor) maintains EU Standard Contractual Clauses for any sub-processing outside the EEA.

Data Breach Notification

In the event of a personal data breach, we will notify the supervisory authority (Garante per la protezione dei dati personali) within 72 hours and notify affected individuals without undue delay where the breach is likely to result in a high risk to their rights and freedoms.

Records of Processing Activities

We maintain detailed records of all processing activities as required by Art. 30 GDPR. These records are available to the supervisory authority upon request.

← Back to home