Effective from 28 August 2026. Version 2.
1. Purpose and scope
This notice explains how personal data is processed in connection with the use of the Worklines business management system (the “System”), in accordance with Articles 13–14 of Regulation (EU) 2016/679 (“GDPR”) and Hungarian Act CXII of 2011 on informational self-determination and freedom of information.
It applies to everyone who uses the System: employees and contractors of subscribing organisations, contact persons of those organisations, and the individuals whose data is recorded in the System.
2. The provider and its role in the processing
2.1. Provider details
- Company: Business Software Solutions Kft.
- Registered seat: Apor Vilmos tér 25-26., 1124 Budapest, Hungary
- Company registration number: 01-09-356890
- VAT number: 25420113-2-43
- E-mail: info@bssolution.hu
- Phone: +36 30 120 2255
The provider has not appointed a Data Protection Officer, as it is not required to do so under Article 37 GDPR. Data protection enquiries can be addressed to the contact details above.
2.2. Dual role — worth reading
The System serves several organisations (each a “Subscriber”) on separated data areas. As a result the provider acts in two distinct capacities, and your rights depend on which body of data is concerned:
| Category of data | Who is the controller? | The provider’s role |
| Data of the Subscriber’s employees and contractors (HR, vehicles, devices, attendance, performance, etc.) and documents and contracts uploaded by the Subscriber |
The Subscriber (your employer) |
Processor — the provider processes this data solely on the Subscriber’s documented instructions and under a data processing agreement, and does not use it for its own purposes |
| Data of the business relationship with the Subscriber, authentication data of service accounts, operational and security logs, support requests |
The provider |
Controller — processed on its own legal basis, for its own purposes |
What does this mean in practice? If you are an employee of the Subscriber and wish to exercise your rights over your own data held in the System (access, rectification, erasure), please address your request to your employer first. The provider cannot fulfil such a request directly, because it does not decide the fate of that data — it will forward the request to the Subscriber and assist in answering it.
3. What data does the System process?
The list below covers the full functionality of the System. Which modules are in use at your employer is the Subscriber’s decision.
3.1. Account and authentication data
- username, e-mail address, display name
- a one-way, salted hash of the password (the password itself cannot be recovered or read)
- where two-factor authentication is used, the authenticator application’s secret key
- last sign-in time, security stamp, language preference, active/inactive status
3.2. Employment-related data (HR module)
- master data: name, contact details, organisational unit, job title, start date, engagement type (employee or contractor), employee code
- leave and overtime requests, attendance records, annual leave entitlement
- competence records, training and knowledge-transfer entries
- onboarding and offboarding checklists, onboarding plans, mentor assignment
- performance feedback
- reporting-line (supervisor) relationships
- documents uploaded in connection with the employment (attachments)
3.3. Data relating to company resources
- Vehicles: driver assignment, driving licence number and expiry, fuel and mileage entries, service and odometer records
- IT and mobile devices: device assignment, asset tag, handover confirmation, device requests, access reviews
- Contracts and documents: who recorded and who approved an item, signatory capacity, access and download log
3.4. Communication and reports
- content of tickets and reports, comments, attached files
- feedback submitted through the System: subject, description, the page it was sent from (URL), browser identifier, attachments
- system notifications and their read status
3.5. Logging and security data
- audit log: which user performed which operation, when, on which record, at which location
- sign-in and authorisation events, refused operations
- application error logs
4. Purposes and legal bases
| Purpose | Legal basis |
| Operating the System, providing access, maintaining employer records | The legal basis determined by the Subscriber (typically performance of the employment contract, or a legal obligation of the Subscriber). Here the provider is a processor. |
| Managing user accounts, authentication, two-factor protection | Performance of a contract (Art. 6(1)(b) GDPR) and the provider’s legitimate interest in maintaining system security (Art. 6(1)(f)) |
| Logging, traceability, detection of unauthorised access | Legitimate interest (Art. 6(1)(f)) — protecting the System and the data held in it. The provider has balanced this interest against the rights of data subjects; logging is limited to the data strictly necessary. |
| Handling support requests and fault reports | Performance of a contract, and legitimate interest in improving the service |
| Invoicing, accounting, tax obligations | Compliance with a legal obligation (Art. 6(1)(c)) |
5. How long is data retained?
- The Subscriber’s data set: for the term of the service agreement. On termination of the agreement the Subscriber’s entire data set is deleted from the live system without delay and without a separate request.
- Backups: deletion extends to backup copies, but for technical reasons these cannot be erased instantly — they are overwritten as the hosting provider’s automatic backup cycle rotates. During that period backups are accessed only for restore purposes and in a logged manner, and no data is disclosed from them.
- Audit log: 2 years in the live table, after which entries are moved to an archive table. The archive remains searchable within the statutory limitation period.
- Data recorded in individual modules: according to the retention period configured by the Subscriber. The System warns separately when a record’s retention period has expired, and supports anonymisation of the affected data.
- Accounting records: 8 years under Section 169 of Hungarian Act C of 2000 on accounting.
6. Who has access to the data?
6.1. Within the System
Only those users have access whom the Subscriber’s administrator has authorised. The System separates the data areas of individual Subscribers technically: every query filters on the location identifier, and write operations pass through a separate authorisation gate.
6.2. Processors
| Processor | Activity | Location of data |
| Microsoft Ireland Operations Limited (Microsoft Azure) |
Hosting and database services |
European Union — West Europe region (Netherlands) |
| Twilio Inc. / SendGrid |
Sending transactional e-mail (password reset, invitations, notifications) |
United States — see section 6.3 |
The provider uses no other processors. Subscribers are notified in advance of any change to the list of processors.
6.3. Transfers to third countries
Use of the e-mail delivery service involves a transfer of data to the United States. The transferred data is limited to what is necessary for delivery: the recipient’s e-mail address, name and the content of the message. The transfer relies on the European Commission’s adequacy decision of 10 July 2023 on the EU–US Data Privacy Framework or, should that decision cease to apply, on the European Commission’s Standard Contractual Clauses (SCCs).
6.4. Authorities
The provider discloses personal data to authorities only where legally compelled, and only to the exact extent of that compulsion. Unless prohibited by law, the affected Subscriber is informed of such requests.
7. Security measures
The provider applies technical and organisational measures proportionate to the risk, as required by Article 32 GDPR. The more significant protections built into the System are:
- Authentication: passwords are stored only as one-way hashes; two-factor authentication (time-based one-time codes) is supported and can be made mandatory per location
- Password strength: minimum length and complexity rules, with stricter requirements for administrator accounts
- Sessions: encrypted transport (HTTPS) and a security stamp — deactivating an account or changing a password immediately invalidates existing sessions
- Tenant separation: every query and write operation filters on the location identifier; requests arriving from another location’s subdomain are refused and logged
- Encryption of confidential documents: documents classified as confidential or secret are stored encrypted; if encryption fails the upload is refused rather than proceeding unencrypted
- Integrity: a SHA-256 checksum is generated for uploaded files; on mismatch the download is refused
- Logging: sensitive operations — permission changes, document downloads, exports, deletions, refused access — are written to the audit log
- Browser-side protection: Content Security Policy, and encoding of text rendered to the interface to prevent script injection
8. Logging and impersonation — transparent disclosure
Two operational characteristics deserve particular attention because they matter to data subjects:
- Operations in the System are logged. The log records which user did what, and when. Administrators of the Subscriber and — for operational purposes — the provider can view it. The purpose is traceability and detection of unauthorised access, not continuous automated evaluation of employee performance.
- The System supports impersonation: for troubleshooting, a global administrator can temporarily use the interface in the name of another user. When this happens a persistent warning bar is shown at the top of the screen and the action is logged. Impersonation cannot be used to learn a password.
9. Cookies
The System uses strictly necessary cookies only; it sets no analytics, profiling or advertising cookies.
- authentication cookie: maintains the signed-in state — for the session, or for the configured period if “remember me” is selected
- session cookie: preserves the state of forms being filled in — until the browser is closed
- language cookie: remembers the selected interface language
Under the GDPR and applicable electronic communications rules, consent is not required for these cookies, as they are essential to providing the service.
10. Your rights
Under the GDPR you have the following rights:
- Right to information and access (Art. 15): to learn whether we process data about you and to obtain a copy
- Right to rectification (Art. 16): to have inaccurate data corrected and incomplete data completed
- Right to erasure (Art. 17): to have your data deleted where the purpose has ceased or the legal basis has fallen away. This right does not apply where processing is required by law (e.g. accounting retention).
- Right to restriction of processing (Art. 18)
- Right to data portability (Art. 20): for automated processing based on contract or consent
- Right to object (Art. 21): against processing based on legitimate interest
- Right to withdraw consent (Art. 7(3)): where processing is based on consent
Where should you turn?
- If your request concerns data processed in the System by your employer: to your employer. The provider cannot fulfil such a request on its own; any request received will be forwarded to the Subscriber without delay and you will be informed.
- If your request concerns the provider’s own processing (account data, support correspondence, operational logs): directly to the provider at info@bssolution.hu. We will respond within one month of receipt; in complex cases this may be extended by two months, of which you will be informed.
11. Remedies
If you believe your data is being processed unlawfully, you may lodge a complaint with the supervisory authority:
- Hungarian National Authority for Data Protection and Freedom of Information (NAIH)
Falk Miksa utca 9-11., 1055 Budapest — postal address: 1363 Budapest, Pf. 9., Hungary
Phone: +36 1 391 1400 — E-mail: ugyfelszolgalat@naih.hu — Web: naih.hu
You may also bring proceedings before a court. At your choice, the action may be brought before the regional court of your place of residence or stay.
If it suits you, please contact us first — most questions are resolved fastest that way.
12. Changes to this notice
The provider reserves the right to amend this notice. The System stores legal documents in versioned form: each release receives its own version number and effective date, so it can be established retrospectively which text was in force at any given time. Material changes are communicated before they take effect, through an in-system notification or by e-mail.
This English text is a translation provided for convenience. In the event of any discrepancy, the Hungarian version prevails.