Staffarmor Executive← Back to Executive
STAFFARMOR EXECUTIVE™ / Legal documents

Privacy notice

1. Scope and provider

This notice covers the standalone Staffarmor Executive matter, document and management decision system. Provider: SBSA Laboratory OÜ; registration 16863186; EU VAT EE102684175; registered office: Harju maakond, Kuusalu vald, Pudisoo küla, Männimäe/1, 74626, Estonia. Privacy, support and deletion requests: office@sbsalaboratory.tech.

2. Data protection roles

For company matters, uploaded documents, contacts and client data, the company determining the purposes and means of processing is the controller. SBSA acts as a processor on documented client instructions, under a separate processing agreement. A management service provider or other partner's role depends on its actual tasks and agreement with the company. A sales relationship alone does not grant access to client documents. SBSA is a separate controller for its own account security, business communications, billing, support and legal claims.

3. Data, purposes and legal bases

The system may process names, email addresses, languages, memberships, roles, invitation and access records; matters, participants, documents and versions, deadlines, decisions, approvals and sharing; subscription and billing records, security and audit data. The company controller determines the legal basis and necessity of company content processing. SBSA's own processing relies on contract performance where the individual is a contracting party, legal obligations for mandatory records, and legitimate interests in security, business communications and legal claims. This notice does not request marketing consent.

4. Recipients and infrastructure

Company roles, matter permissions, delegated access and sharing rules limit access. The sender must verify invitation and sharing recipients. Authorised technical staff may access necessary information for justified support or security purposes. Infrastructure includes Hosting.com hosting and Backblaze B2 document storage; email delivery and security providers may also be involved. Current subprocessor and region information is available from SBSA. Transfers outside the EEA require an appropriate EU legal mechanism and safeguards; information and access to copies of those safeguards may be requested at the contact address above.

5. Retention and termination

Company document retention follows the controller's applicable legal requirements and documented instructions. Our own account, support and security records are retained as needed for their purpose; disputed matters until resolution and expiry of the applicable claims period; mandatory business records for statutory periods. Acceptance evidence is kept as necessary to establish the service relationship and related legal claims. Suspension of access does not mean data deletion. Return, export, deletion and backup expiry follow the contract and lawful client instructions.

6. Your rights

Subject to applicable conditions, you may request access, correction, erasure, restriction and portability, and object to processing based on legitimate interests. Contact the company controller for company content and the email address above for SBSA's own processing. We normally respond within one month and explain any lawful extension. You may complain to the supervisory authority where you live, work or believe an infringement occurred, or to Estonia's Andmekaitse Inspektsioon (aki.ee).

7. Security and decisions

The system uses encrypted connections, separate company workspaces, roles, revocable access and audit records. Matter alerts and statuses support decisions; they are not themselves grant, financing or legal decisions. Upload only necessary personal data. Before uploading special-category or criminal-offence data, the controller must establish the appropriate legal basis and protections.

8. Local storage and acknowledgement

The browser may store necessary session and language information. This acceptance process does not authorise marketing or analytics tracking. Executive separately records the user ID, document bundle version, language, SHA-256 hashes of both documents, server timestamp and session ID. Acknowledging this notice is not blanket consent to processing. Processing needed to create an account and display this screen occurs beforehand; the notice is also available before sign-in.