Effective date: 8 October 2026 · Applies to the PeopleCoral web and mobile applications (GDPR)
This Privacy Policy describes how HR Rebels B.V. (KvK: 65493486), operating the PeopleCoral product, processes personal data in connection with the PeopleCoral web and mobile applications and related services (the "Application" and "Services").
The Application is an enterprise business-to-business ("B2B") application intended for use by employees and authorized users of PeopleCoral customers. It functions primarily as an interface connecting to the PeopleCoral backend environment of the relevant customer (tenant). For visitors to our marketing website, see our Website Privacy Policy.
Controller (where applicable): HR Rebels B.V. Keurenplein 4, Unit A6271, 1069 CD Amsterdam, The Netherlands Email (privacy requests and complaints): info@peoplecoral.comWhere the Services are provided to you by an organization (e.g., an employer or customer entity), that organization typically determines the purposes and means of processing and is therefore the Controller (Article 4(7) GDPR).
HR Rebels B.V. acts as Controller for certain processing activities conducted for its own legitimate business purposes, including service security (such as SMS verification codes, see section 3.3), integrity monitoring, account administration for customer administrators, compliance, and contractual and billing administration (where applicable).
The Application does not offer consumer account creation.
Depending on the configuration chosen by the Controller and the features enabled, the Services may process:
Special category data (Article 9 GDPR): the Services are not designed to require special category data by default. If the Controller configures workflows that include such data, the Controller determines the lawful basis and appropriate safeguards. HR Rebels B.V. processes such data only under the Controller's instructions.
HR Rebels B.V. processes personal data solely to provide and operate the Services on behalf of and under the instructions of the Controller (including data storage, organization, reporting, compliance support, payroll operations, expense processing, time tracking including QR-based time registration, and related HR/payroll operations, as configured).
If you add and confirm a mobile phone number in your security settings, we use it to send one-time passcodes by text message when you reset your password or when a sign-in needs to be verified. Messages are sent only when you request them, and message and data rates may apply. We never use your mobile number for marketing. Reply STOP to opt out, or switch off SMS verification in your settings; you can then reset your password by email or through your HR administrator. Messages are delivered by our SMS provider Twilio. Full program terms are in our SMS Terms.
No mobile information will be shared with third parties or affiliates for marketing or promotional purposes. Text messaging originator opt-in data and consent will not be shared with any third parties.
The mobile Application may request access to certain device functions solely to enable Application features:
If metadata is generated (e.g., file properties needed for upload handling), it is used only for functionality and security of the Application and the Services. The Application does not access other phone content, sensors, or data for unrelated purposes. HR Rebels B.V. does not use the Application for advertising, data brokerage, or cross-application tracking.
PeopleCoral is operated using a single-tenant architecture: each customer environment is deployed on a separate, dedicated server environment and is not shared with other customers. This architectural segregation is designed to reduce the risk of cross-customer access, strengthen confidentiality controls, and support customer-specific security configuration and access governance. Customer data is stored and processed within the European Economic Area ("EEA"), subject to the customer's contractual configuration and support requirements.
Certain technical service providers necessary to deliver specific functionality may process limited data: push notification services such as Apple Push Notification service (APNs) and/or Firebase Cloud Messaging (FCM) process device tokens and notification routing data, and our SMS provider Twilio processes your mobile phone number and the content of verification messages. Where such processing involves transfers outside the EEA, including to the United States, HR Rebels B.V. applies appropriate safeguards as required under the GDPR, such as an adequacy decision (including, where applicable, the EU-U.S. Data Privacy Framework) or Standard Contractual Clauses.
PeopleCoral's default operating model is single tenant per customer, including dedicated server resources for each customer environment. This reduces dependency on logical separation controls typically required in multi-tenant deployments and is intended to provide enhanced data isolation, improved auditability, and reduced blast radius in the event of a security incident within any single customer environment.
Personal data may be disclosed to:
HR Rebels B.V. does not sell personal data and does not use personal data for advertising or tracking purposes.
Retention depends on whether HR Rebels B.V. acts as Processor or Controller:
HR Rebels B.V. maintains appropriate technical and organizational measures ("TOMs") to protect personal data against unauthorized or unlawful processing and against accidental loss, destruction, or damage.
Personal data breach notification (Processor role): HR Rebels B.V. will notify the Controller without undue delay and in any event within 48 hours of becoming aware of a personal data breach, in accordance with the DPA.
HR Rebels B.V. maintains business continuity and disaster recovery measures leveraging Azure resilience features, including automated backups, geo-redundant storage, monitoring, and periodic testing. Target recovery objectives include an RPO of 15 minutes for critical systems and an RTO of 4 hours for essential services (and up to 24 hours for less critical data), subject to incident type and scope.
Subject to applicable law, you may have rights to access, rectify, erase, restrict, object to processing, and data portability, and to withdraw consent where processing is based on consent.
Where HR Rebels B.V. acts as Processor, it will support the Controller in responding in accordance with the DPA. You may lodge a complaint with a competent supervisory authority, including the Dutch supervisory authority (Autoriteit Persoonsgegevens).
Where the Application supports user access to personal data, the Application provides a method within the Application to initiate a request for account and associated data deletion (or deactivation), subject to the Controller's instructions, legal retention obligations, and the DPA.
Because the Application is provided in an employment/organizational context, the Controller (your employer/organization) controls whether an account can be deleted, must be retained (e.g., payroll/tax retention), or should be deactivated while retaining statutory records.
The Services are intended for business use and are not directed to children. HR Rebels B.V. does not knowingly collect personal data from children in violation of applicable law.
HR Rebels B.V. may update this Privacy Policy from time to time. The effective date will be revised accordingly, and material changes will be made available via the Application and/or Services.
HR Rebels B.V. maintains App Store listing disclosures (App Privacy Details / "Privacy Label") in App Store Connect to declare the categories of data processed by the Application, whether data is linked to a user, and to confirm that the Application is not used for tracking, in line with this policy and the Application's functionality. The Privacy Policy link is provided in the App Store listing and is also accessible from within the Application (e.g., via Settings/About/Legal or an equivalent menu in the Application).
Where the Application requests access to protected device resources (such as the camera), the Application provides clear permission usage descriptions explaining the specific purpose (e.g., receipt capture, QR scanning for time registration, profile picture upload). The Application is designed to request permissions only when a user initiates the relevant feature ("just-in-time" permission requests), and not for unrelated purposes.
See also our Terms of Use and SMS Terms.