Privacy Policy
Last updated
What personal data openbranchhq collects, why, who it is shared with and for how long — on our website, in your account, and in the employee records your organization keeps with us.
1. Who we are and what this policy covers
PAP SOFTWARE SOLUTIONS L.P., a limited partnership (Ε.Ε.) registered in Greece ("openbranchhq", "we", "us"), runs the website at openbranchhq.com and the hosted openbranchhq service. As we are established in the European Union, the EU General Data Protection Regulation (GDPR) and Greek Law 4624/2019 apply to our processing of personal data.
We are the controller of the personal data described in this policy: data about visitors to our website, people who hold an openbranchhq account, and our customers' billing contacts.
Organizations use openbranchhq to keep records about their employees. For those records we act as a processor on the organization's behalf, under our Data Processing Agreement. The organization, usually your employer, decides what is recorded and why, and its own privacy notice applies. The section on employee records below summarizes what that data includes.
This policy does not cover self-hosted installations of openbranchhq. Their operators run them independently, and they send no data to us.
2. Information we collect
- Account information: your name, email address, password (stored only as a salted hash), a profile picture if you upload one, and two-factor authentication secrets and backup codes if you turn it on.
- Sign in with Google: if you choose it, Google shares your name, email address and profile picture with us, and we store the tokens Google issues for the sign-in.
- Organization information: the organization's name, logo and settings, and your role in it.
- Security data: the IP address and browser user agent of each signed-in session, which you can see and revoke from your account page, and server logs of requests to the Service, in which email addresses are masked.
- Billing information: Polar, our merchant of record, collects payment details and billing addresses directly. We receive the subscription's plan, status and seat count, never full card numbers.
- Communications: what you send us when you write to us.
- Website: our marketing website uses no analytics, advertising or tracking tools. Our hosting provider processes your IP address to serve pages and to protect against abuse.
3. How we use it, and our legal bases
We use personal data only to:
- provide the Service and your account, including sign-in, invitations, notifications and the features you use (performance of our contract with you or your organization);
- keep the Service secure and reliable by detecting abuse, investigating incidents and fixing errors (our legitimate interest in protecting our customers and the Service);
- process payments and keep accounting records (contract and legal obligation);
- answer your requests and tell you about changes to the Service or these policies (contract and legitimate interest);
- comply with the law and enforce our terms (legal obligation and legitimate interest).
We do not sell personal data, share it for cross-context behavioral advertising, or use it to train AI models. We do not send marketing email unless you have opted in.
4. Employee records we process for customers
When an organization uses openbranchhq, its owners, admins and HR staff may record information about its employees, including:
- names, work email addresses, profile pictures, job titles, departments, locations, managers and working hours;
- employment dates, probation periods, role history, offboarding and rehire records, and notes added to them;
- leave requests, approvals, balances and comments, and attachments such as medical certificates, which can contain health data;
- with the Documents add-on, documents such as contracts, payslips, performance reviews, certifications and ID documents, and a record of who viewed or downloaded them;
- with the Assets add-on, the equipment assigned to each person and its condition;
- an activity log of the changes made in the organization.
We process this data only on the organization's instructions, as set out in our Data Processing Agreement. If you are an employee and want to access, correct or delete it, contact your employer. If you contact us instead, we will forward your request to them.
7. International transfers
We are established in Greece, but the service providers that host and run the Service are in the United States, so your personal data is transferred there. We protect these transfers with the European Commission's Standard Contractual Clauses and, where a provider is certified, the EU-U.S. Data Privacy Framework. For personal data from the United Kingdom or Switzerland, the UK Addendum and the Swiss amendments to those clauses apply.
8. How long we keep it
- Account and organization data: for as long as the account or organization exists.
- Employee records: until the organization deletes them. Deleting an employee removes their records and their personal documents.
- Session records, including IP address and user agent: while your account exists.
- Activity and document-access logs: for the life of the organization, so its owners keep a complete audit trail.
- Files uploaded but never attached to a record: 24 hours.
- Server logs: for a limited period, after which they are deleted.
- Billing records: for as long as tax and accounting law requires.
Deleting an organization removes its records from our database immediately and its uploaded files from storage shortly after.
To delete your account, email [email protected] from the address on the account. We will confirm the request and complete it within 30 days.
9. Security
We protect personal data with measures suited to its sensitivity, including:
- TLS encryption for all traffic to the Service;
- salted password hashes, required email verification, and optional two-factor authentication;
- tenant isolation, with every organization-scoped query taking the organization from the signed-in session;
- role-based permissions, and an append-only activity log of changes;
- a private file store, encrypted at rest, reachable only through signed links that expire within minutes;
- calendar feed links stored only as hashes.
No system is perfectly secure. If we become aware of a breach affecting your personal data, we will notify you and, where required, the authorities. To report a vulnerability, follow our security policy.
10. Your rights
Depending on where you live, you may have the right to access the personal data we hold about you, correct it, delete it, receive a portable copy, restrict or object to our processing of it, and withdraw consent you have given.
You can also complain to our lead supervisory authority, the Hellenic Data Protection Authority, or to the data protection authority where you live or work.
If you live in California or another U.S. state with a comprehensive privacy law, you have the right to know what personal data we collect and how we use and disclose it, to correct and delete it, and not to be discriminated against for exercising these rights. We do not sell or share personal data as those laws define it.
To exercise any of these rights, email [email protected]. We will verify your request and respond within 30 days. You may also make a request through an authorized agent.
11. Children
The Service is for businesses and is not directed at children. We do not knowingly collect personal data from anyone under 16. If you believe we have, contact us and we will delete it.
12. Changes to this policy
We post changes on this page with a new "Last updated" date. If a change is material, we will also email account holders before it takes effect.
13. Contact
PAP SOFTWARE SOLUTIONS L.P., 2nd km Kalampaka–Trikala Road, 42200 Kalampaka, Greece. GEMI 172897553000, VAT EL802245732.
Email: [email protected]