Roles
Your organization is the data controller for its employees' personal data entered into CHRIS. Web rješenja d.o.o., Markuševečka cesta 115, 10040 Zagreb, Croatia, OIB (tax ID): 97669668809, is the data processor and processes the data solely on the organization's documented instructions.
Subject matter, duration and purpose
Processing is carried out to provide the CHRIS service — keeping employee records and managing leave — and lasts for the duration of the service contract.
Payroll support
The purpose of processing also includes supporting the organization's payroll and accounting: CHRIS prepares and exchanges the data with which the organization and the party that does its accounting prepare the payroll. These are the tasks between them, the monthly payroll package, payslips and the record of non-taxable receipts.
CHRIS does not file the payroll, JOPPD or any other report to the authorities; the organization or its accounting firm does. The record of non-taxable receipts in CHRIS is an auxiliary record; the official record is the JOPPD and the organization's books.
Categories of data subjects and data
Data subjects are the organization's employees and members. The following categories of data are processed:
- name and work email address,
- employment details: start date, contract type and leave quotas,
- leave requests, including the leave type (which may indicate health-related leave),
- optionally: HR notes, an emergency contact and a CV.
Payroll data
For payroll support the following categories of employee data are also processed. The disabled-worker flag is health data, a special category of data, and is processed under GDPR Art. 9(2)(b) only to split sick-leave compensation between the employer and HZZO.
- OIB (personal identification number), date of birth and address,
- the IBAN the salary is paid to, and the municipality or town of residence,
- whether the person is a disabled worker (invalid rada), with no degree of disability, diagnosis or documents,
- payslips,
- non-taxable receipts paid to the employee and, for receipts related to a child, the child's first name and birth year.
Processor obligations
As the data processor, we commit to the following:
- we process data only on the organization's instructions,
- persons with access to the data are bound by confidentiality,
- we apply appropriate technical and organizational security measures (role-based access control, per-organization data isolation, two-factor sign-in available, encrypted transport, database and document storage in the EU),
- we assist the organization with data-subject rights and security obligations,
- we notify the organization of a personal-data breach without undue delay.
Sub-processors
The following sub-processors are engaged to provide the service. The database, documents and email are located in the European Union. Transfers outside the EU exist for two services — sign-in and mobile push delivery — and rely on the European Commission's standard contractual clauses (GDPR Art. 46(2)(c)).
We will notify organizations in advance of planned changes to sub-processors.
If the organization turns on the assistant, the sub-processors listed in the “Assistant (Ask CHRIS)” section are also involved.
- Supabase — database and authentication (EU region),
- WorkOS — sign-in and account management (USA; standard contractual clauses),
- Stripe — payment processing,
- Mailgun EU — email delivery,
- Expo — push notification delivery to mobile devices (USA; standard contractual clauses),
- Hetzner (via Nebion) — hosting in the EU.
Assistant (Ask CHRIS)
The “Ask CHRIS” assistant is an optional module powered by artificial intelligence. It is off until the organization's administrator turns it on and confirms the consent; that confirmation is the controller's documented instruction and is recorded with the name, the date and the version of the consent text. While the module is off, no data is sent to the sub-processors in this section.
When the assistant is on, the employee's question is sent together with only the data that employee may already see in CHRIS. HR notes, pay data, personal identification numbers, addresses, emergency contacts and documents are never sent, except the one document an employee hands to the assistant. The data sent is not used to train models.
Transfers to the US rely on the European Commission's standard contractual clauses (GDPR Art. 46(2)(c)). We will notify organizations in advance of a change of sub-processor or of processing location. The processing is carried out by one of the named sub-processors, in the EU or the US:
- OpenAI — generating the assistant's answers (USA; standard contractual clauses; EU processing on request),
- Anthropic PBC — generating the assistant's answers (USA; standard contractual clauses),
- Amazon Web Services EMEA — generating the assistant's answers (EU processing).
The accounting party the organization designates
An organization may designate in CHRIS one party that does its accounting: an accounting firm whose engagement the organization's administrator approves, or its own employees whom an administrator authorises as in-house accountants. On that documented instruction CHRIS discloses to that party the data in the areas of access the administrator switched on. CHRIS records who gave the instruction, when, with which areas of access and which version of the confirmation text.
The accounting firm is the organization's processor under a separate data processing agreement between the organization and the firm. The firm is not a sub-processor of CHRIS, and this DPA neither governs nor replaces that agreement. The firm's people are then data subjects too: the organization sees what they opened, entered and downloaded there, and those records belong to the organization.
Files the accounting firm or the in-house accountants open or upload, such as task attachments and payslips, are stored in the European Union only.
The organization may end the engagement or the authorisation at any time; access then stops at once, and what the accounting party entered stays with the organization.
Deletion and return of data
After the contract ends, we delete the data at the organization's request or no later than within 30 days. Before deletion, the organization can request an export of its data.
Conversations with the assistant are kept for 12 months. The assistant's sub-processor retains inputs for at most 30 days for abuse monitoring.
Signed DPA
This summary is for information and does not replace the agreement itself. Request the signed Data Processing Agreement at hello@chris.hr.
Version 1.1 — 30 September 2026.
Changes in version 1.1: payroll support as a purpose of processing, payroll data as new categories of data, and disclosure to the accounting party the organization designates.