GDPR Compliance
Last updated: January 2026
Our Commitment
Qrew is built with privacy by design. We comply with the EU General Data Protection Regulation (GDPR 2016/679) and the Italian Personal Data Protection Code (D.Lgs. 196/2003 as amended by D.Lgs. 101/2018).
Data Controller
Qrew S.r.l. is the data controller. Contact our DPO at [email protected].
Lawful Basis for Processing
| Purpose | Legal Basis |
|---|---|
| Time-tracking service delivery | Contract performance (Art. 6(1)(b)) |
| Payroll calculations | Contract performance + legal obligation |
| GPS geofencing | Legitimate interest — fraud prevention (Art. 6(1)(f)) |
| Photo verification | Consent (Art. 6(1)(a)) |
| Push notifications | Consent (Art. 6(1)(a)) |
| Audit logging | Legitimate interest — compliance evidence |
| Device fingerprinting | Legitimate interest — anti-spoofing |
Data Subject Rights
You have the following rights under the GDPR:
- Access (Art. 15): Request a copy of your personal data.
- Rectification (Art. 16): Correct inaccurate data.
- Erasure (Art. 17): Request deletion (“right to be forgotten”).
- Restriction (Art. 18): Limit how we use your data.
- Portability (Art. 20): Receive your data in a machine-readable format.
- Object (Art. 21): Object to processing based on legitimate interest.
Submit requests to [email protected]. We respond within 30 days.
Data Retention
Time-tracking records are retained for 10 years as required by Italian employment law (Art. 2949 Codice Civile). Audit logs are retained for 10 years for tribunal-ready compliance. Other personal data is deleted within 30 days of account closure.
International Transfers
All data is stored in EU data centres. We do not transfer personal data to third countries. Stripe (payment processor) maintains EU Standard Contractual Clauses for any sub-processing outside the EEA.
Data Breach Notification
In the event of a personal data breach, we will notify the supervisory authority (Garante per la protezione dei dati personali) within 72 hours and notify affected individuals without undue delay where the breach is likely to result in a high risk to their rights and freedoms.
Records of Processing Activities
We maintain detailed records of all processing activities as required by Art. 30 GDPR. These records are available to the supervisory authority upon request.