Privacy policy

This policy explains, in plain language, what personal data we process, why, and what your rights are.

Who we are

This website (chris.hr) and the CHRIS application (app.chris.hr) are operated by Web rješenja d.o.o., Markuševečka cesta 115, 10040 Zagreb, Croatia, OIB (tax ID): 97669668809. For any privacy questions, contact us at hello@chris.hr.

This website (chris.hr)

The chris.hr marketing site uses no cookies, no analytics tools and does not track visitors. We do not collect personal data when you simply browse the site.

If you contact us by email, we use your address and the content of your message solely to reply to you.

The application (app.chris.hr): who is responsible for what

CHRIS is an HR and leave-management tool used by organizations (employers). For its employees' personal data, the data controller is the organization using CHRIS — it decides which data it enters and how it is used. Web rješenja d.o.o. processes that data on the organization's behalf, as a data processor.

Accounting firms and their people

An organization may approve in CHRIS an engagement with an accounting firm that does its accounting and payroll. The firm is then a recipient of employee data in the areas of access the organization's administrator approved, and while the engagement lasts an employee sees the firm's name on their profile in CHRIS. The firm processes the data as the organization's processor, under their data processing agreement. Instead of a firm, the organization may authorise its own employees as in-house accountants.

The people of an accounting firm (firm managers and accountants) use CHRIS as users. Web rješenja d.o.o. is the controller of their account data: their name, e-mail address, sign-in data and security records, their place in the firm and the clients they are assigned to, and their notification settings. We process it to provide them the service under the Terms for accounting firm people (GDPR Art. 6(1)(b)) and to protect the accounts and data in CHRIS (legitimate interest, GDPR Art. 6(1)(f)).

The organization is the controller of what a firm's person opens, enters or downloads at that client. The Terms for accounting firm people are published at chris.hr/en/accounting-firm-terms/.

What data the application processes

Depending on what the organization enters, the application processes the following categories of employee data:

  • name and work email address,
  • employment details: start date, contract type and leave quotas,
  • leave requests, including the leave type (which may indicate health-related leave),
  • optionally: HR notes, an emergency contact and a CV.

Payroll data

If the organization uses payroll support, the following data is also processed. The disabled-worker flag is health data; it is processed to meet the employer's obligations in employment and social-security law (GDPR Art. 9(2)(b)), only to split sick-leave compensation between the employer and HZZO.

  • OIB (personal identification number), date of birth and address,
  • the IBAN the salary is paid to, and the municipality or town of residence,
  • whether the person is a disabled worker (invalid rada), with no degree of disability, diagnosis or documents,
  • payslips,
  • non-taxable receipts paid to the employee and, for receipts related to a child, the child's first name and birth year.

Lawful basis for processing

Data in the application is processed to perform the contract with the organization (Art. 6(1)(b) GDPR) and on the basis of the employer's legitimate interest in keeping orderly employee and leave records.

Sub-processors and data location

We use the following sub-processors to provide the service. The database, documents and email are located in the European Union. Two services process data outside the EU under the European Commission's standard contractual clauses: sign-in (email address and sign-in events) and mobile push delivery (notification title and body, which may contain an employee's name).

If the organization turns on the assistant, the sub-processors listed in the “Assistant (Ask CHRIS)” section further down this page are also involved.

  • Supabase — database and authentication (EU region),
  • WorkOS — sign-in and account management (USA; standard contractual clauses),
  • Stripe — payment processing,
  • Mailgun EU — email delivery,
  • Expo — push notification delivery to mobile devices (USA; standard contractual clauses),
  • Hetzner (via Nebion) — hosting in the EU.

Assistant (Ask CHRIS)

CHRIS includes an assistant powered by artificial intelligence (“Ask CHRIS”) that answers employees' questions about leave, working time and the organization's rules. The module is off until the organization's administrator turns it on and confirms the consent. While it is off, no data is sent to the sub-processors in this section.

When the assistant is on, the employee's question is sent together with only the data that employee may already see in CHRIS (their own leave, the team's records for a team lead, and so on). HR notes, pay data, personal identification numbers, addresses, emergency contacts and documents are never sent, except the one document an employee hands to the assistant. The data sent is not used to train models.

We will notify organizations of a change of sub-processor or of processing location. The processing is carried out by one of the named sub-processors, in the EU or the US:

  • OpenAI — generating the assistant's answers (USA; standard contractual clauses; EU processing on request),
  • Anthropic PBC — generating the assistant's answers (USA; standard contractual clauses),
  • Amazon Web Services EMEA — generating the assistant's answers (EU processing).

How long we keep data

We delete data at the organization's request or no later than 30 days after the contract ends. Before deletion, the organization can request an export of its data.

Employees' conversations with the assistant are kept for 12 months. The assistant's sub-processor retains inputs for at most 30 days for abuse monitoring and does not use them to train models.

Your rights

You have the right of access, rectification, erasure, restriction of processing, data portability and objection. If you are an employee of an organization using CHRIS, the simplest route is to contact your employer as the data controller — we will gladly help them fulfil your rights. You can also lodge a complaint with a supervisory authority; in Croatia, that is the Personal Data Protection Agency (AZOP).

Changes to this policy

We may update this policy from time to time. The new version applies from its publication on this page, and we will notify organizations using CHRIS about material changes.

Version 1.1 — 30 September 2026.

Changes in version 1.1: payroll data, and accounting firms and their people as users of CHRIS.