App privacy — employees
Privacy notice for end users of the platform
This page explains how Onwork processes the personal data of employees, contractors and end users («Users») of the organisations using the platform. It is intentionally written in plain language.
- Version
- v1.0
- Effective
- 2026-04-25
Who processes your data and in what role
When your employer or principal uses Onwork to manage shifts, attendance, projects, billing and HR data, the GDPR roles are:
- Data Controller — your organisation. Decides why and how data is processed.
- Data Processor— Oncode S.r.l. Processes data exclusively to provide the platform on the controller's documented instructions, never for its own purposes.
To exercise your data subject rights (access, rectification, erasure, portability, objection, restriction) please contact your employer first, as data controller. Onwork assists the controller in handling your request.
Categories of data processed
Depending on the configuration chosen by your employer, the platform may process:
- Identification and professional contact data
- Attendance, clock-ins, shifts, leave, business trips
- Geolocation data (only if enabled by the employer in compliance with Italian Workers' Statute, Art. 4)
- Project, activity, progress and labour-cost data
- E-invoicing and accounting data
- Uploaded documents and attachments
- Application logs (logins, IP, user agent, audit trail)
- AI-assistant insights
How we protect your data
Onwork implements technical and organisational measures consistent with GDPR Art. 32, leveraging Oncode S.r.l.'s ISO/IEC 27001 certification. Key measures include:
- Encryption in transit (TLS 1.3) and at rest
- Cloud hosting within the European Union
- Strong authentication and granular role-based access
- Immutable audit log of operations
- Regular backups and disaster recovery procedures
- Vulnerability management and periodic penetration tests
For more detail, see the Security page.
Sub-processors
To deliver the platform, Onwork relies on qualified vendors (cloud, email, observability, AI). The current list is available at Sub-processors. All vendors operate within the EU or under adequate safeguards (Standard Contractual Clauses 2021/914, Data Privacy Framework).
Your rights
You may exercise the rights provided by GDPR Articles 15–22 (access, rectification, erasure, portability, restriction, objection) by contacting your employer as data controller.
If you believe your rights have been violated, you may lodge a complaint with the Italian Data Protection Authority (Piazza Venezia 11, 00187 Rome).
Onwork DPO contact
For questions about Onwork acting as Processor, write to [email protected] or [email protected].