PeopleCoral
Philosophy Platform Architecture AI Roadmap ROI Resources Careers Blog Demo Webinar FAQ
Request a Demo
Legal

Application Privacy Policy. For everyone who logs in.

Effective date: 8 October 2026 · Applies to the PeopleCoral web and mobile applications (GDPR)

This Privacy Policy describes how HR Rebels B.V. (KvK: 65493486), operating the PeopleCoral product, processes personal data in connection with the PeopleCoral web and mobile applications and related services (the "Application" and "Services").

The Application is an enterprise business-to-business ("B2B") application intended for use by employees and authorized users of PeopleCoral customers. It functions primarily as an interface connecting to the PeopleCoral backend environment of the relevant customer (tenant). For visitors to our marketing website, see our Website Privacy Policy.

Controller (where applicable): HR Rebels B.V. Keurenplein 4, Unit A6271, 1069 CD Amsterdam, The Netherlands Email (privacy requests and complaints): info@peoplecoral.com

1. Roles under the GDPR (Controller / Processor)

1.1 Customer-managed use (employment/organizational context)

Where the Services are provided to you by an organization (e.g., an employer or customer entity), that organization typically determines the purposes and means of processing and is therefore the Controller (Article 4(7) GDPR).

  • In such cases, HR Rebels B.V. acts as Processor (Article 4(8) GDPR) and processes personal data solely on the Controller's documented instructions, pursuant to a data processing agreement ("DPA").
  • The Controller is responsible for determining which employee data fields are required and uploaded to PeopleCoral, and for informing employees about employment-related processing.

1.2 HR Rebels B.V. as Controller

HR Rebels B.V. acts as Controller for certain processing activities conducted for its own legitimate business purposes, including service security (such as SMS verification codes, see section 3.3), integrity monitoring, account administration for customer administrators, compliance, and contractual and billing administration (where applicable).

1.3 No consumer sign-up; access depends on an employee record

The Application does not offer consumer account creation.

  • Login to the Application requires access to PeopleCoral authentication and an existing user/employee record in the relevant customer tenant.
  • If a person does not have a valid employee/user record provisioned in PeopleCoral by the Controller, login is not possible.

2. Categories of personal data processed

Depending on the configuration chosen by the Controller and the features enabled, the Services may process:

  • Identity and account data: salutation, first name, last name, work email address, user ID, authentication tokens, user role/permissions, organization/tenant identifiers.
  • Employee master data (controller-configured): date of birth, place of birth, nationality, country of residence, address (if configured), work location, internal identifiers, organizational function, department, job title, reporting line.
  • Employer and employment context (controller-configured): employer/entity information, contract-related identifiers, employment status, payroll group and country configuration (as applicable).
  • Payroll-related data (where applicable and controller-configured): payroll inputs and employment compensation elements, tax-related data and statutory identifiers (including BSN numbers for the Netherlands where applicable), and (if configured) bank/payment details (e.g., IBAN/bank account). These data types may be required to fulfil payroll processing and statutory reporting requirements.
  • Operational HR data (controller-configured): leave/absence requests and approvals, time and attendance records (including QR-based time registration where enabled), workflow history and approvals.
  • Expense and document data (controller-configured): expense claims, receipt images, attachments and related structured expense fields entered by the user.
  • Profile data (optional): profile picture (if the user uploads one).
  • Communications and support data: support requests, correspondence, and related diagnostic information.
  • Technical, usage, and security data: IP address, device/Application version, log-in events, audit logs, error logs, device identifiers necessary for session/security, push-notification device tokens (where enabled), and — where SMS verification is enabled — your mobile phone number and SMS delivery records (time and delivery status).

Special category data (Article 9 GDPR): the Services are not designed to require special category data by default. If the Controller configures workflows that include such data, the Controller determines the lawful basis and appropriate safeguards. HR Rebels B.V. processes such data only under the Controller's instructions.

3. Purposes of processing and legal bases

3.1 Where HR Rebels B.V. acts as Processor

HR Rebels B.V. processes personal data solely to provide and operate the Services on behalf of and under the instructions of the Controller (including data storage, organization, reporting, compliance support, payroll operations, expense processing, time tracking including QR-based time registration, and related HR/payroll operations, as configured).

3.2 Where HR Rebels B.V. acts as Controller

  • Provision and administration of the Services (including account administration for customer administrators): Article 6(1)(b) and/or 6(1)(f) GDPR.
  • Security, integrity, monitoring, and fraud prevention (including audit logs, access controls, and SMS verification codes): Article 6(1)(f) GDPR and, where applicable, Article 6(1)(c) GDPR.
  • Support and incident handling: Article 6(1)(b) and/or 6(1)(f) GDPR.
  • Legal compliance and claims (including statutory retention and responding to lawful requests): Article 6(1)(c) and/or 6(1)(f) GDPR.

3.3 Account security messages (SMS)

If you add and confirm a mobile phone number in your security settings, we use it to send one-time passcodes by text message when you reset your password or when a sign-in needs to be verified. Messages are sent only when you request them, and message and data rates may apply. We never use your mobile number for marketing. Reply STOP to opt out, or switch off SMS verification in your settings; you can then reset your password by email or through your HR administrator. Messages are delivered by our SMS provider Twilio. Full program terms are in our SMS Terms.

No mobile information will be shared with third parties or affiliates for marketing or promotional purposes. Text messaging originator opt-in data and consent will not be shared with any third parties.

3.4 Camera and device permissions (no tracking; functionality only)

The mobile Application may request access to certain device functions solely to enable Application features:

  • Camera access: to capture receipts for expense reports, to scan QR codes for time registration, and (if used) to upload a profile picture.
  • Photo/file access (if enabled on the device): to select and upload attachments (e.g., receipts, profile picture).
  • Push notifications (if enabled): to deliver workflow, approval, and operational notifications.

If metadata is generated (e.g., file properties needed for upload handling), it is used only for functionality and security of the Application and the Services. The Application does not access other phone content, sensors, or data for unrelated purposes. HR Rebels B.V. does not use the Application for advertising, data brokerage, or cross-application tracking.

4. Hosting location and international transfers

4.1 PeopleCoral is hosted on EU-based Microsoft Azure servers

PeopleCoral is operated using a single-tenant architecture: each customer environment is deployed on a separate, dedicated server environment and is not shared with other customers. This architectural segregation is designed to reduce the risk of cross-customer access, strengthen confidentiality controls, and support customer-specific security configuration and access governance. Customer data is stored and processed within the European Economic Area ("EEA"), subject to the customer's contractual configuration and support requirements.

4.2 Limited third-party processing

Certain technical service providers necessary to deliver specific functionality may process limited data: push notification services such as Apple Push Notification service (APNs) and/or Firebase Cloud Messaging (FCM) process device tokens and notification routing data, and our SMS provider Twilio processes your mobile phone number and the content of verification messages. Where such processing involves transfers outside the EEA, including to the United States, HR Rebels B.V. applies appropriate safeguards as required under the GDPR, such as an adequacy decision (including, where applicable, the EU-U.S. Data Privacy Framework) or Standard Contractual Clauses.

4.3 Tenant isolation as a privacy and security measure

PeopleCoral's default operating model is single tenant per customer, including dedicated server resources for each customer environment. This reduces dependency on logical separation controls typically required in multi-tenant deployments and is intended to provide enhanced data isolation, improved auditability, and reduced blast radius in the event of a security incident within any single customer environment.

5. Recipients and sub-processors

Personal data may be disclosed to:

  • The Controller and authorized users of the Controller's organization, subject to role-based access controls configured by the Controller.
  • Sub-processors engaged to provide the Services: Microsoft Azure for cloud hosting and storage in the Netherlands/EU, and Twilio for delivery of SMS verification codes. Sub-processor obligations and change-notification commitments are set out in the DPA.
  • Platform notification services (APNs/FCM) for push notifications, as described in section 4.2.
  • Authorities or professional advisors where required by law, or where necessary to establish, exercise, or defend legal claims.

HR Rebels B.V. does not sell personal data and does not use personal data for advertising or tracking purposes.

6. Data retention

Retention depends on whether HR Rebels B.V. acts as Processor or Controller:

  • Processor data (customer content): retained and deleted/returned in accordance with the Controller's instructions and the DPA, unless retention is required under EU or Member State law.
  • Controller-side records (typical retention targets):
    • Payroll and tax-related records: up to 7 years where applicable under Dutch tax or other applicable legislation.
    • Customer account administration data: up to 2 years after service termination.
    • Support tickets/communications: up to 1 year, unless longer is required for dispute handling or compliance.
    • SMS security logs (mobile number, time and delivery status): up to 12 months. One-time passcodes expire within minutes.

7. Security and confidentiality

HR Rebels B.V. maintains appropriate technical and organizational measures ("TOMs") to protect personal data against unauthorized or unlawful processing and against accidental loss, destruction, or damage.

  • Measures include: encryption in transit and at rest, role-based access control, multi-factor authentication, monitoring and alerting, secure development practices, and audit logging.
  • Standards: security controls are designed in line with recognized standards referenced in customer documentation (e.g., ISO 27001/27018 and NEN 7510 alignment as described in the DPA).

Personal data breach notification (Processor role): HR Rebels B.V. will notify the Controller without undue delay and in any event within 48 hours of becoming aware of a personal data breach, in accordance with the DPA.

8. Business continuity and disaster recovery

HR Rebels B.V. maintains business continuity and disaster recovery measures leveraging Azure resilience features, including automated backups, geo-redundant storage, monitoring, and periodic testing. Target recovery objectives include an RPO of 15 minutes for critical systems and an RTO of 4 hours for essential services (and up to 24 hours for less critical data), subject to incident type and scope.

9. Data subject rights

Subject to applicable law, you may have rights to access, rectify, erase, restrict, object to processing, and data portability, and to withdraw consent where processing is based on consent.

  • For most data processed within PeopleCoral in an employment/organizational context, requests should be directed to the relevant Controller (your employer/organization).
  • You may also contact HR Rebels B.V. at info@peoplecoral.com.

Where HR Rebels B.V. acts as Processor, it will support the Controller in responding in accordance with the DPA. You may lodge a complaint with a competent supervisory authority, including the Dutch supervisory authority (Autoriteit Persoonsgegevens).

9.1 Account deletion requests within the Application (enterprise context)

Where the Application supports user access to personal data, the Application provides a method within the Application to initiate a request for account and associated data deletion (or deactivation), subject to the Controller's instructions, legal retention obligations, and the DPA.

Because the Application is provided in an employment/organizational context, the Controller (your employer/organization) controls whether an account can be deleted, must be retained (e.g., payroll/tax retention), or should be deactivated while retaining statutory records.

10. Children

The Services are intended for business use and are not directed to children. HR Rebels B.V. does not knowingly collect personal data from children in violation of applicable law.

11. Amendments

HR Rebels B.V. may update this Privacy Policy from time to time. The effective date will be revised accordingly, and material changes will be made available via the Application and/or Services.

11.1 App Store disclosures and policy access within the Application

HR Rebels B.V. maintains App Store listing disclosures (App Privacy Details / "Privacy Label") in App Store Connect to declare the categories of data processed by the Application, whether data is linked to a user, and to confirm that the Application is not used for tracking, in line with this policy and the Application's functionality. The Privacy Policy link is provided in the App Store listing and is also accessible from within the Application (e.g., via Settings/About/Legal or an equivalent menu in the Application).

11.2 Consent and permissions; purpose strings; data minimization

Where the Application requests access to protected device resources (such as the camera), the Application provides clear permission usage descriptions explaining the specific purpose (e.g., receipt capture, QR scanning for time registration, profile picture upload). The Application is designed to request permissions only when a user initiates the relevant feature ("just-in-time" permission requests), and not for unrelated purposes.

12. Contact

HR Rebels B.V. (KvK: 65493486) Keurenplein 4, Unit A6271, 1069 CD Amsterdam, The Netherlands Email (privacy requests and complaints): info@peoplecoral.com

See also our Terms of Use and SMS Terms.

PeopleCoral
One database. Every tool. Every country.

The premium HR and payroll platform for ambitious organisations. Single-tenant. Native payroll per country. Every HR tool built in — dedicated AI, zero integrations, fully supported and fully customisable.

Platform
Core HR Native Payroll OrgStudio Talent & Performance Budgeting Process Dedicated AI
Company
About Resources Implementation Careers Blog
Get in touch Contact Book a Demo Download E-Book info@peoplecoral.com Privacy Policy
HR Rebels B.V. Keurenplein 4 Unit A6271 1069 CD Amsterdam +31 (0)72 707 4182 CoC: 65493486
© 2026 HR Rebels B.V. All rights reserved. GDPR · AVG · Single-tenant · Dedicated AI · SSL
PeopleCoral
One database. Every tool. Every country.

The premium HR and payroll platform for ambitious organisations. Single-tenant. Native payroll per country. Every HR tool built in — dedicated AI, zero integrations, fully supported and fully customisable.

Platform
Core HR Native Payroll OrgStudio Talent & Performance Budgeting Process Dedicated AI
Company
About Resources Implementation Careers Blog
Get in touch Contact Book a Demo Download E-Book info@peoplecoral.com
HR Rebels B.V. Keurenplein 4 Unit A6271 1069 CD Amsterdam +31 (0)72 707 4182 CoC: 65493486
© 2026 HR Rebels B.V. All rights reserved.
Privacy Policy Application Privacy Policy Terms of Use SMS Terms
GDPR · AVG · Single-tenant · Dedicated AI · SSL