Privacy Policy

How Horara processes personal data on its website and platform

This page has been drafted with the current state of the web application as a reference. It summarizes what data Horara processes, when it acts as a controller, when it acts on behalf of its clients, and which providers or technical functions are currently involved in the service.

Last update: 02/05/2026

Responsible

HORARA CONTROL S.L.U.

CIF B22542260

C/ Isabel la Católica number 57, 47400 Medina del Campo (Valladolid), Spain

Contact and links

admin@horara.es

+34 625 91 21 37

See also the cookie policy and the terms of service.

Summary

Horara combines own treatments with treatments on behalf of the client company

In the current state of the product, Horara processes its own data for account, authentication, licenses, support, billing and public website, and processes labor and shift data on behalf of client companies that use the platform to control clockings, shifts, centers, calendars, shifts and notifications.

1. Person responsible for treatment and contact

The person responsible for the treatments described in this policy is HORARA CONTROL S.L.U., with CIF B22542260 and address at C/ Isabel la Católica number 57, 47400 Medina del Campo (Valladolid), Spain.

You can contact Horara at admin@horara.es or by phone at +34 625 91 21 37 for general questions of privacy, support or exercise of rights.

2. Scope and Horara's role in each processing activity

This policy describes the processing of data on the public website, the registration and login pages, the private routes of the platform, the PWA, the kiosk and the contact or support forms currently active on horara.es.

Horara acts as the controller when it processes data specific to the commercial or pre-contractual relationship, for example data on leads, administrators, billing, licenses, support and own communications.

horara acts as data processor when it processes, on behalf of the client company, the data of employees and other internal users necessary for time control, days, calendars, notifications, centers, shifts and associated evidence.

3. Data that Horara processes as responsible

  • Identification and contact data of those who request a demo, write for support or create a company account: module of interest, name, surname, email, company, position, telephone number, number of employees, sector, message and commercial consent when the corresponding box is checked.
  • Company and administrative person registration data: name, surname, company name, NIF/CIF, email, optional telephone number, affiliate token if it exists and commercial consent when the corresponding box is checked.
  • Authentication and account data: email or username, hashed password, verification tokens, recovery tokens, image/avatar and minimum session data.
  • Licensing and contractual relationship data: company, licensing status, customer and subscription references in Stripe and payment event records required to operate the subscription.
  • Support and operation data: communications sent through forms, incidents, responses and technical metadata associated with the request.
  • Technical and security data that the platform needs to operate, such as browser information, language, platform, session state, local preferences, and technical security credentials when a company activates device restriction.

4. Purposes and legal bases of the personal treatments

  • Manage requests for information, demos and support, based on the application of pre-contractual measures, the execution of the requested relationship or the legitimate interest in responding to the request.
  • Create and maintain company accounts, authenticate users, send verification or recovery emails and operate the platform, based on the execution of the contract or pre-contractual measures.
  • Manage licenses, billing, subscriptions and administrative or fiscal obligations, based on the execution of the contract and applicable legal obligations.
  • Send your own commercial communications by email when the management company has marked the corresponding acceptance, based on the consent granted.
  • Apply security controls, prevent unauthorized access, protect sessions and operate device restriction when the client company activates it, based on legitimate security interest and the correct execution of the service.

5. Data that HR processes as a manager on behalf of each client company

For these processing activities, the client company decides the purpose and scope of Horara's use with respect to its workforce. If you are an employee of a company that uses Horara, your employer is normally the main controller of your work-time data.

For this reason, requests regarding access, rectification, deletion, opposition, limitation or portability related to employment or employment data must first be addressed to your company. Horara will assist the client company within the applicable contractual framework.

  • Identification and employment data that the client company enters for its employees and managers, such as name, surname, email, role, centers, licenses, calendars and internal service configurations.
  • Clocking and day data: entries, exits, breaks, observations, statuses, correction requests, reports and exports generated from the platform.
  • Geolocation data obtained when clocking in only when the company has activated that functionality. The application does not continuously track the device.
  • Internal and push notification data, including subscription endpoint, technical keys, platform, installed PWA indicator, and basic browser metadata when the user activates notifications.
  • Image data when a user uploads an avatar to their profile.
  • Technical data linked to device restriction when enabled by the company, such as device tag, browser, operating system, platform, device type, language, time zone and last activity, along with the technical credential necessary to recognize authorized browsers.

6. Recipients, suppliers and access by third parties

Horara does not communicate data to third parties for purposes unrelated to the service unless there is a legal basis, a user request or the corresponding integration requires it to provide the contracted functionality.

  • Infrastructure, hosting, CDN and deployment providers of the environment where the application runs.
  • Stripe, when the client company uses checkout, client portal, billing or subscription collections.
  • LinkedIn, when the user accepts marketing cookies on the public website and the LinkedIn Insight Tag is loaded for campaign measurement, audiences and conversion attribution.
  • Mail or SMTP provider configured to send operational messages, such as account verification, password recovery, or support responses.
  • Configured file storage provider for avatars; The application supports Vercel Blob when enabled in the environment.
  • Public administrations, courts, security forces and bodies or other third parties when there is a legal obligation or valid requirement.

7. International transfers

Some providers used by the application or the public website may process data outside the European Economic Area or allow remote access from third countries, especially in payment, hosting, mail or storage services, depending on the actual configuration of the environment.

When that happens, the treatment must be supported by the corresponding legal mechanism in accordance with the applicable regulations and the conditions of the provider involved. If you need more details about a specific supplier, you can request additional information through the contact channels indicated on this page.

8. Conservation periods

  • Account, company and administration data are kept as long as there is a contractual or pre-contractual relationship and, afterwards, during the periods required by legal obligations or to defend claims.
  • Billing and payment data are kept for the applicable accounting, tax and commercial periods.
  • Contact or support requests are retained as long as necessary to manage the request and associated follow-up.
  • Session, security, push notifications, avatars or device restriction data is maintained as long as it is necessary for functionality, until revocation, replacement, technical expiration or deletion of browser data.
  • The employment and time-tracking data processed on behalf of the client are kept according to the instructions of the client company and the legal obligations that fall on it as the person responsible.

9. Cookies and similar technologies

horara uses cookies, localStorage, sessionStorage, service workers, PWA caches and other similar technologies. Some are technical and required for session, security, visual theme, push notifications, or device restriction.

On public acquisition pages, Horara can load the LinkedIn Insight Tag for marketing purposes only when the user accepts that use from the cookie notice.

10. Security

Horara applies reasonable technical and organizational measures to protect the information processed on the platform, including authentication, access control by role, session protection, server validations and security measures in accordance with the deployment environment and the providers used.

No system connected to the Internet can guarantee absolute security. That is why access, sessions and configurations are reviewed and response mechanisms are applied when errors or incidents are detected.

11. Rights of data subjects

You can request access, rectification, deletion, opposition, limitation of processing or portability when applicable, by writing to admin@horara.es and clearly indicating your request and the relationship you have with Horara.

If Horara acts only as a processor on behalf of your employer, we may first refer you to the client company responsible for the treatment to manage the request through the appropriate channel.

You can also file a claim with the Spanish Data Protection Agency if you consider that the treatment does not comply with the applicable regulations.

12. Minors

horara is a service aimed at companies and professionals. It is not intended for minors or to deliberately collect data from minors for its own purposes.

13. Changes to this policy

This policy may be updated when the application, its providers, the scope of service or applicable legal obligations change. The last update date indicates the version published at any given time.

14. Internal Information System

When a company uses Horara SII to operate its Internal Information System, the data is processed to receive, analyze, manage and document communications included in the scope of Law 2/2023.

Access is limited to the System Controller, to the people who directly manage the communication, to human resources when disciplinary measures may be taken, to legal services when legal measures are appropriate, to the Data Protection Officer, if any, and to the designated data processors.

The data are kept only for the time necessary to decide whether to initiate an investigation and, where appropriate, for the time necessary to process it. If actions are not initiated within three months, they will be deleted except for anonymized preservation to leave evidence of the system's operation. In no case will they be kept for more than ten years.

Privacy Policy | Horara