Version 2026.2 · in effect from September 9, 2026
Draft document: the company details are not filled in yet. Do not treat it as in force.
This is an information notice, not a document you have to sign. Your consent is not requested, and it matters that you understand why: the processing described below is not based on your consent but on your employment contract and the laboratory's legitimate interest. Consent asked for within a relationship of subordination would not be freely given, and so would not be valid.
Instead, we tell you exactly what the laboratory sees about you.
The laboratory that invited you is the controller. It decides what is recorded about your work and how long it is kept.
We, [DENUMIRE SOCIETATE], are the processor: we host the platform and process the data on the laboratory's instructions.
For any question about your employee data, contact the laboratory first.
| What | Details |
|---|---|
| Identity | First and last name, email address, profile picture from your Google account |
| Assigned tasks | Which stages you have to carry out, on which cases, with which deadlines |
| Activity | When you started and finished a stage, in what order |
| Review notes | Observations about your work, including rework reasons |
| Reworks | When a case is redone and who the cause is attributed to |
| Barcode scans | Which boxes you scanned and when |
| Earnings | Amounts accrued per stage, payslips and payments |
| Sessions | IP address and browser type at sign-in |
This information is visible to the laboratory owner. It is not public and is not visible to other laboratories.
We do not track your location. We do not record your screen, keyboard or camera. We do not measure time spent in the application as a productivity metric. We take no automated decisions about you — no evaluation, promotion or sanction is generated by the platform.
| Purpose | Basis |
|---|---|
| Assigning and tracking work | Performance of the contract between you and the laboratory |
| Calculating earnings and payslips | Legal and contractual obligation of the laboratory |
| Account security and session logs | Legitimate interest — protecting patient data |
| Task notifications | Performance of the contract |
Data related to cases and payroll is kept for as long as accounting and employment law require — the period is set by the laboratory, as controller. Notifications are deleted after 90 days. Barcode scans after 12 months. Audit logs after 24 months. Sessions are deleted on expiry, and revoked ones 30 days after revocation.
You have the right of access, rectification, restriction, objection and, within the limits below, erasure. You can contact the laboratory or us at [EMAIL PROTECȚIA DATELOR].
One limit we prefer to state plainly: deleting an account does not remove everything. Your name is tied to completed tasks and payslips the laboratory is legally required to keep. In those cases we anonymise the account — severing the identity from the records — and keep only what the law requires.
How to exercise them, concretely. Data export and account closure are requested from your account settings. The technician profile, however, cannot be edited in the app: to correct your name or other account data, write to the laboratory or to us and we correct it for you. The same goes for restriction of processing and objection. The email address cannot be changed — it is the identifier of the Google account you sign in with.
You also have the right to lodge a complaint with the supervisory authority. In the Republic of Moldova this is the National Center for Personal Data Protection (CNPDCP), www.datepersonale.md. If you are in the European Union, you may go to the authority in your own state.
The laboratory can revoke your access at any time. It cannot read your password — there are no passwords, authentication is through Google — and it cannot sign in as you.
A platform administrator, however, can. There is a support feature that lets them open the app as you, in order to reproduce a problem you report. Here is exactly how it is limited: only a platform administrator can use it, only with a written reason, and never against another administrator; the resulting session lasts 30 minutes, not 14 days; it is marked as such, so the app shows a banner and every action stays attributed to the administrator rather than to you; and opening it is written to the audit log before it can be used.
Our staff can access accounts only for technical support, incident investigation, or a legal obligation. Each such access requires a recorded reason and is written to a log that cannot be altered.