Zum Inhalt springen
FuzeWork
StartseiteAnleitungenSo funktioniert es
StartseiteAnleitungenSo funktioniert esKontakt
FuzeWork · Version 2026-04

Personal Data Processing Notice

How FuzeWork and your company handle personal and work data.

Version
2026-04
Effective from
13 August 2026
Last updated
10 October 2026
LEGAL REVIEW

Draft for legal and operational review

The legal identity, contacts, governing law, retention periods and principal processors are now stated. Before production release, a qualified Czech lawyer must still review the text and it must be checked against the actual production configuration.

Contents

1. Who is responsible for processing2. Data that may be processed3. Purposes and legal bases4. Sources5. Camera, photos and location6. Recipients and service providers7. Transfers outside the EEA8. Retention9. Security10. Individual rights11. Consent in employment12. Automated decision-making13. Children14. Changes and versions15. Controller, DPO and contact16. Sources used for this draft
Permanent link to this version →

1. Who is responsible for processing

For work data placed in a company workspace, your company or employer is normally the controller: it decides why data is used, who may access it and how long it is retained. The FuzeWork operator processes that data as a processor on the company’s instructions.

For data needed to operate its own accounts, secure the service, invoice, provide support and meet legal duties, the FuzeWork operator may be an independent controller. Its exact legal identity must be added in section 15 before publication.

2. Data that may be processed

  • identity and contact data, account UID, company, role, language and settings;
  • team and project assignments, permissions and join requests;
  • check-ins, checkouts, work intervals, corrections, comments and audit records;
  • photos, captions, file metadata and location where enabled and permitted;
  • quality issues, status, comments, photos and linked attendance adjustments;
  • receipts, expenses, attachments and optional automated extraction results;
  • technical and security data, device type, app version, diagnostics and error records;
  • version, time, source and state of consent or acknowledgement.

3. Purposes and legal bases

  • account and requested functions: performance of a contract or pre-contract steps;
  • attendance and workforce/project management: the company determines the basis, typically employment contract, legal obligation or legitimate interests;
  • security, abuse prevention, audit and stability: legitimate interests or legal obligation;
  • billing, accounting and legal claims: contract and legal obligations;
  • optional marketing: separate, withdrawable consent;
  • camera, library and location: device permission enables technical access; the company must determine the legal basis for workplace use.

4. Sources

Data comes from the user, company administrators and team leads, device functions, work records created in the service and automatic technical operation. The company may add or correct information within its permissions.

5. Camera, photos and location

FuzeWork does not continuously track a worker’s location or access it in the background. Precise location may be stored once only during a specific user action: when taking a check-in or check-out photo, a photo of completed work, or project-issue documentation. Use requires the relevant special module in a supported plan (currently PRO), company and project configuration, the worker’s recorded consent, and the device’s system permission.

The owner may choose not to use photo attendance, make it optional, or exempt a particular worker. An authorised team lead may record attendance without a photo and without obtaining the worker’s location. Individual photo or GPS functions can also be disabled in project settings.

System permission and in-app acknowledgement do not by themselves determine the lawful basis for workplace processing. The company must assess necessity, proportionality, worker information and local employment-law requirements.

6. Recipients and service providers

Authorised users of the relevant company have role-based access. Google Cloud and Firebase technically provide authentication, Firestore, Cloud Storage, Cloud Functions, App Check and operational security logging. Optional receipt analysis sends the relevant document to Google Gemini API only when that function is expressly started.

Apple, Google and Meta may process authentication data under their own terms when the user selects their sign-in service. Cloudflare Pages hosts the public website and legal pages. Firebase Analytics, Crashlytics and Performance Monitoring are not used in the current Android build. This list is updated before a new provider or purpose is deployed.

7. Transfers outside the EEA

Some providers may process data outside the European Economic Area. Such transfers must rely on an adequacy decision, Standard Contractual Clauses or another lawful safeguard. Information about the specific safeguard can be requested.

8. Retention

After completion, only a minimised request status needed to demonstrate secure handling is retained. Any exception must record its specific legal reason, scope and next review date.

  • active account, profile and company work data: while the service is used and under the controller company’s instructions;
  • verified deletion request: a 30-day safety period followed by no more than 30 days to remove direct identifiers and complete the approved scope;
  • pre-deletion export: the protected link remains available for 14 days and the export is deleted no later than 30 days after request completion;
  • backups containing deleted data: securely overwritten within 90 days and not restored to the active service except for incident recovery;
  • security, audit and operational records: up to 12 months unless anonymised earlier or longer retention is necessary for a specific ongoing legal dispute;
  • company documents and work records: FuzeWork does not impose its own ten-year archive; the company exports them before closure and determines any further statutory retention as controller.

9. Security

Risk-appropriate technical and organisational measures include authentication, tenant separation, role controls, encrypted transfer, access rules, audit records and restricted support access. No system can guarantee absolute security.

10. Individual rights

For work data, contact your company or employer first. FuzeWork will reasonably assist it as processor. For data where the operator is controller, use section 15.

  • information and access;
  • rectification of inaccurate data;
  • erasure or restriction where legal conditions apply;
  • portability for relevant processing;
  • objection to legitimate-interest processing;
  • withdrawal of consent at any time without affecting earlier lawfulness;
  • complaint to the competent supervisory authority.

11. Consent in employment

The required in-app acknowledgement primarily records that the user received this information. It does not itself determine the legal basis for all employee attendance and monitoring.

Because of the employer–worker power imbalance, consent may not be freely given. The company must identify a suitable basis for each processing activity and must not make work conditional on optional consent unless necessary and lawful. Marketing consent remains separate and withdrawable.

12. Automated decision-making

FuzeWork is not intended to make decisions with legal or similarly significant effects based solely on automated processing. Automatic totals, filters, alerts or receipt extraction are supporting outputs and must be reviewed by a person where material.

13. Children

The service is intended for organisations and people legally entitled to work under local law. A company must not create an account without a lawful basis and any required authorisation.

14. Changes and versions

Each notice has a version and permanent URL. Material changes to purposes, bases, recipients or rights will be communicated and may require renewed acknowledgement. Earlier notices remain archived.

15. Controller, DPO and contact

The FuzeWork operator and contact for rights concerning data for which the operator is an independent controller is Pavel Majer, Ortenovo náměstí 14, Prague 7, Czech Republic, pavel.majer@fuzenest.io. No company registration number has been assigned. No data protection officer has been appointed.

For work data, the primary contact is the company or employer shown in the user profile. A complaint may be made to the authority for the place of residence, work or alleged infringement.

16. Sources used for this draft

  • European Commission: information that must be provided ↗
  • European Commission: individual rights under GDPR ↗
  • EUR-Lex: Regulation (EU) 2016/679 ↗
Version 2026-04·Permanent link to this version
FuzeWork

Ein Arbeitsbereich für Teams, Projekte und jeden Arbeitstag.

NutzungsbedingungenDatenschutzAccount deletionKontakt
© 2026 FuzeWork. Alle Rechte vorbehalten.Entwurf · W1