1. Purpose
This document describes the high-level GDPR and data processing framework used by Diriqo when providing its SaaS service to business customers. A separate DPA or enterprise addendum may be agreed with individual customers.
2. Roles of the parties
For customer content entered into the service, the customer is usually the controller and Diriqo is usually the processor. For account administration, billing, support, website operation and security, Diriqo may act as an independent controller.
3. Data categories
Depending on customer use, Diriqo may process worker, customer, job, shift, attendance, photo, offer, invoice, communication, audit log and technical metadata.
4. Security
Diriqo applies reasonable technical and organisational measures, including access controls, encrypted communication, logging, monitoring, backups and incident response processes appropriate for a modern B2B SaaS service.
5. Contact
For GDPR or DPA questions, contact support@diriqo.com.