Privacy Policy

Version 1.0 · Effective 2025-07-01

Privacy Policy

BERLi Technologies OÜ

⚠️ Limited Availability

BERLi is currently in development. Access is limited to authorized personnel for testing purposes. Full commercial availability will be announced separately.

Version: 1.0
Estimated Effective Date: July 1, 2025
Last Updated: February 27, 2025


This Privacy Policy explains how BERLi Technologies OÜ (“we”, “us”, “our”) collects, uses, discloses, and protects your personal data when you use our HR management platform (“Services”). We are committed to protecting your privacy and complying with the General Data Protection Regulation (GDPR).

We act as Data Controller for customer account data and as Data Processor for employee personal data processed on behalf of our customers.

1. Who We Are

FieldValue
CompanyBERLi Technologies OÜ
JurisdictionEstonia
Registration12345678
DPO Contactdpo@berli.io
Privacy Contactprivacy@berli.io
AddressTallinn, Estonia

2. Data We Collect

2.1 Categories of Personal Data

CategoryExamplesSensitivity
IdentityName, date of birth, nationality, ID numbersStandard
ContactEmail, phone, addressStandard
FinancialIBAN, salary, tax IDHigh
EmploymentJob title, department, contract details, work hoursStandard
PerformanceReviews, goals, feedbackStandard
AccessIP address, user agent, login times, device infoStandard
DocumentsUploaded files, contracts, certificatesStandard

2.2 Special Category Data

We may process health data under Article 9(2)(b) GDPR for employment law compliance:

  • Sick leave records
  • Medical certificates for absence
  • Disability accommodations

This data is processed only when necessary and with appropriate safeguards.

2.3 Data Sources

SourceData TypesPurpose
Directly from youIdentity, Contact, EmploymentAccount creation, profile updates
From your organizationEmployment, Financial, PerformanceHR management
Automatically collectedAccess, DeviceSecurity, analytics
Third partiesIdentity verificationCompliance checks

2.4 Data We Do NOT Collect

We do not collect:

  • Biometric data (fingerprints, facial recognition)
  • Genetic data
  • Political opinions
  • Religious beliefs
  • Sexual orientation
  • Trade union membership

3. How We Use Your Data

PurposeLegal BasisData CategoriesRetention
Account managementContractIdentity, ContactDuration + 30 days
Service deliveryContractAll relevantDuration + retention
Payroll processingLegal obligationFinancial, Employment5 years
Employment complianceLegal obligationEmployment, Health5 years post-termination
SecurityLegitimate interestAccess, Device3 years
AnalyticsLegitimate interestAnonymizedAggregated only
Product improvementLegitimate interestUsage patternsAnonymized
MarketingConsent (optional)ContactUntil withdrawal

3.2 Legitimate Interests

We rely on legitimate interest for:

  • Security monitoring and fraud prevention
  • Improving our Services
  • Direct marketing (with opt-out)
  • Internal research and analytics

3.3 Automated Decision-Making

We do not use automated decision-making with legal or significant effects. Our AI features:

  • OCR for receipts: Extracts data for expense reports (human review required)
  • Document processing: Assists with categorization (user confirms)
  • Search: Powers search functionality (no profiling)

All AI-assisted features require human confirmation before final actions.

4. Data Sharing

4.1 Within BERLi

Data is accessible to:

RoleAccess LevelPurpose
Support staffAs neededCustomer support
System administratorsTechnical accessMaintenance, security
EngineersLimited, loggedDevelopment, debugging
ManagementAggregatedBusiness oversight

All personnel are bound by confidentiality agreements and access is logged.

4.2 With Customers

Data SubjectData Shared WithVisibility
EmployeesCustomer organizationAs configured by permissions
StaffCustomer administratorsFull visibility
ClientsCustomerProject-related only

4.3 Subprocessors

We use the following subprocessors:

ProcessorLocationPurposeTransfer Mechanism
OVHCloudGermanyInfrastructure hostingNo transfer (EU)
Self-hosted MinIOItalyObject storageNo transfer (EU)
Self-hosted OllamaItalyAI processingNo transfer (EU)
Google FirebaseUSAPush notificationsSCCs
Google WorkspaceUSATransactional emailSCCs

We may disclose data when:

  • Required by law, court order, or government request
  • Necessary to protect our rights, privacy, safety, or property
  • Necessary to enforce our agreements
  • Necessary to detect, prevent, or address fraud or security issues

We will notify you unless prohibited by law.

5. International Data Transfers

5.1 Within the EU

All primary data storage is within the European Union:

  • Germany (OVHCloud): Primary infrastructure
  • Italy (Self-hosted): Object storage, AI processing

5.2 Transfers to the US

Limited data is transferred to US providers (Google) under Standard Contractual Clauses (SCCs) approved by the European Commission.

5.3 Supplementary Measures

For transfers to third countries, we implement:

  • Encryption: All data encrypted in transit and at rest
  • Data minimization: Only necessary data transferred
  • Access controls: Strict role-based access
  • Contractual protections: Equivalent obligations in contracts

5.4 No Transfers to Inadequate Countries

We do not transfer personal data to countries without an adequacy decision unless SCCs are in place.

6. Data Retention

6.1 Retention Periods

Data CategoryRetention PeriodLegal Basis
Account dataDuration + 30 daysContract
Employment records5 years post-terminationApplicable employment law
Payroll data5 yearsTax/audit requirements
Financial records5 yearsAccounting requirements
Access logs3 yearsSecurity (Art. 32 GDPR)
Backups90 daysRecovery
Marketing consentUntil withdrawal + 1 yearDocumentation
Deleted data30 days (soft delete)Recovery window

6.2 Deletion

After retention periods:

  • Data is securely deleted
  • Backups are overwritten
  • Deletion is logged
  • Certificates available upon request

Retention periods may be extended for:

  • Pending litigation
  • Regulatory investigations
  • Contractual disputes

7. Your Rights

7.1 GDPR Rights

RightArticleDescriptionHow to Exercise
AccessArt. 15Copy of your dataApp → Settings → Export
RectificationArt. 16Correct inaccurate dataEdit profile or contact support
ErasureArt. 17Delete your dataApp → Settings → Delete Account
RestrictionArt. 18Limit processingContact privacy@berli.io
PortabilityArt. 20Data in machine-readable formatExport feature (JSON/CSV)
ObjectArt. 21Object to processingOpt-out or contact us
Automated decisionsArt. 22Human reviewContact us

7.2 Response Timeline

Request TypeStandard TimelineExtension
Simple access14 daysUp to 30 days
Complex requests30 daysUp to 90 days (with notice)
Urgent requests7 daysAs applicable

7.3 Verification

To protect your data, we may:

  • Verify identity before fulfilling requests
  • Request additional information
  • Use secure communication channels

7.4 Exemptions

Rights may be limited when:

  • Processing is necessary for legal claims
  • Data must be retained by law
  • Disclosure would adversely affect others’ rights
  • Request is manifestly unfounded or excessive

7.5 Complaints

You have the right to lodge a complaint with a supervisory authority:

8. Security Measures

8.1 Technical Measures

CategoryMeasures
EncryptionAES-256 at rest, TLS 1.3 in transit
Access controlRole-based, principle of least privilege
AuthenticationMagic link + secure session management
Monitoring24/7 system monitoring, intrusion detection
BackupsDaily backups, 90-day retention, encrypted
NetworkFirewall, VPN for admin access, DDoS protection
AuditComprehensive audit logging

8.2 Organizational Measures

CategoryMeasures
TrainingRegular data protection training for all staff
Access reviewsQuarterly access audits
PoliciesDocumented security and data protection policies
Incident responseDocumented breach response procedures
Vendor managementDue diligence on all subprocessors
Background checksFor personnel with access to sensitive data

8.3 Certifications

We are working toward:

  • ISO 27001 (Information Security)
  • SOC 2 Type II

8.4 Breach Notification

In case of a personal data breach affecting your data:

RecipientTimelineMethod
Supervisory authorityWithin 72 hoursOfficial notification
Affected individualsWithout undue delayEmail (if high risk)
Affected customersWithin 48 hoursEmail + phone

Notification includes:

  • Nature of the breach
  • Categories and approximate number of individuals affected
  • Likely consequences
  • Measures taken or proposed
  • Contact point for more information

9. Children’s Privacy

9.1 Age Restrictions

  • Under 16: Not permitted to use BERLi
  • 16-18: May use with parental or guardian consent
  • 18+: Full access

9.2 Data from Children

We do not knowingly collect personal data from children under 16. If we discover we have collected such data, we will:

  • Delete it immediately
  • Notify the parent/guardian if identifiable
  • Document the deletion

9.3 Reporting

If you believe a child under 16 has provided us with personal data, contact: privacy@berli.io

10. Cookies and Tracking

10.1 Essential Cookies

CookiePurposeDurationType
supAccess tokenSessionEssential
entRefresh token7 daysEssential
preferencesUser preferences1 yearFunctional

10.2 Analytics

We use self-hosted analytics with:

  • Anonymized IP addresses
  • No cross-site tracking
  • No third-party cookies
  • No profiling

10.3 No Third-Party Tracking

We do not use:

  • Google Analytics
  • Facebook Pixel
  • Third-party advertising cookies
  • Cross-site tracking

You can manage cookies through:

  • Browser settings
  • App preferences
  • Opt-out mechanisms

11. Changes to This Policy

11.1 Notification

We will notify you of material changes via:

  • Email to your registered address
  • In-app notification with countdown
  • Banner notice in application

11.2 Notice Period

We provide at least 30 days notice before material changes take effect.

11.3 Acceptance

  • Continued use after effective date constitutes acceptance
  • You may reject changes and terminate without penalty

11.4 Version History

All versions are archived and available upon request.

12. Contact Information

12.1 General Privacy Inquiries

12.2 Data Protection Officer

12.4 Postal Address

BERLi Technologies OÜ
Data Protection Officer
[Address]
Tallinn, Estonia


Policy History

VersionEffective DateChanges
1.0July 1, 2025 (est.)Initial version

Last updated: February 27, 2025