Legal
Privacy policy
Ergonicx privacy policy: processor vs. controller, personal data, sub-processors, EEA transfers, retention periods and GDPR rights.
Last updated: 9 June 2026
1. Introduction
This privacy policy describes how ReinartzBranding, trading as Ergonicx (ergonicx.com), processes personal data in connection with our B2B SaaS platform for workforce management. The platform serves Dutch SMB organisations in operational sectors, including logistics and warehouse operations.
Ergonicx processes time tracking, scheduling, leave and related employment data. We do not process payroll; we only provide payroll-ready timesheets and export files to the customer or their payroll administrator.
2. Controller and processor
In the relationship between Ergonicx and our business customers (organisations that create an account), the following applies:
- Data controller: the business customer. The customer determines which personal data of employees is processed in Ergonicx and is responsible for a lawful basis towards those employees (for example performance of the employment contract or legitimate interest).
- Data processor: ReinartzBranding / Ergonicx. We process personal data solely on behalf of and in accordance with the instructions of the customer, for the purpose of delivering the service.
- Data subjects: employees and other users of the platform within the customer’s organisation (managers, HR, etc.).
For data relating to the customer account itself (contact person, organisation billing details), ReinartzBranding acts as data controller where necessary to enter into and perform the agreement with the customer.
A Data Processing Agreement (DPA) is available on request via privacy@ergonicx.com.
3. Categories of personal data
Depending on how the customer uses the platform, the following categories of personal data may be processed:
- Identity and contact data: name, email address, username, role (manager/employee), organisation.
- Employment and contract data: contract type, contracted hours, employment start and end dates, employment status.
- Attendance and hours data: clock-in/out times, breaks, corrected hours, week closures, timesheets.
- Scheduling and leave: shift assignments, rosters, leave requests, sick reports, leave balances.
- Location data (optional): GPS coordinates when clocking in/out, only when the customer has enabled geofencing. No continuous location tracking.
- Technical and usage data: IP address, browser type, device information, session logs, audit logs of actions in the system.
- Billing data (organisation): company name, Chamber of Commerce (KVK) number, VAT number, billing address, payment details via Stripe (we do not store full card numbers).
4. Purposes and legal bases
We process personal data for the following purposes:
- Performance of contract (Art. 6(1)(b) GDPR): delivering, maintaining and supporting the Ergonicx platform; processing hours, scheduling and leave; generating timesheets and export files; account management and billing.
- Legitimate interest (Art. 6(1)(f) GDPR): platform security, fraud prevention, error analysis, improving reliability and protecting our systems and users. For analytics (PostHog) we ask for consent in advance; see section 11.
- Legal obligation (Art. 6(1)(c) GDPR): where applicable, for example statutory retention for certain records.
As data controller, the customer is responsible for informing employees and having an appropriate legal basis for processing personal data in Ergonicx, including any use of location data with geofencing.
5. Retention periods
We apply the following retention periods, unless the customer has different settings within the platform’s capabilities or the law requires a longer period:
- Employment and hours data: up to 7 years after the relevant financial year, in line with Dutch statutory retention for payroll administration and related records.
- Account data: for as long as the subscription is active, plus 30 days after termination of the contract, unless statutory retention requires a longer period.
- Technical and audit logs: up to 90 days, unless needed for incident investigation or legal obligation.
- Back-ups: are overwritten within a reasonable time after deletion from production environments; remaining backup data is deleted within 90 days of account termination at the latest.
6. Sub-processors
We use the following sub-processors. They process personal data solely on behalf of Ergonicx and under appropriate contractual safeguards:
- Supabase Inc. (United States / EU region) — database, authentication and storage of application data. Privacy policy: https://supabase.com/privacy
- Vercel Inc. (United States / EU region) — hosting and content delivery for the web application. Privacy policy: https://vercel.com/legal/privacy-policy
- Stripe Inc. (United States / Ireland) — payments, SEPA direct debit and fraud prevention. Privacy policy: https://stripe.com/privacy
- Resend Inc. (United States) — transactional email (invitations, notifications, billing). Privacy policy: https://resend.com/legal/privacy-policy
- Functional Software Inc. / Sentry (United States / EU) — error monitoring and application performance. Privacy policy: https://sentry.io/privacy/
- PostHog Inc. (United States / EU data centre) — product analytics, only after user consent. Privacy policy: https://posthog.com/privacy
- Upstash Inc. (United States / EU region) — Redis caching for performance (optional). Privacy policy: https://upstash.com/trust/privacy.pdf
- OpenRouter Inc. (United States) — AI features (manager assistant and marketing chatbot); only prompt context necessary for the query is processed. Privacy policy: https://openrouter.ai/privacy
Changes to sub-processors are communicated to customers in accordance with the data processing agreement or this privacy policy.
7. Transfers outside the European Economic Area (EEA)
We aim to process personal data within the EEA. Where sub-processors are established outside the EEA, or transfers otherwise occur, we apply appropriate safeguards:
- Supabase, Vercel, PostHog, Upstash: production environments are configured in EU data centres where available. Any transfer to the United States is based on Standard Contractual Clauses (SCCs) and additional measures where required.
- Stripe, Resend, Sentry, OpenRouter: processing may (partly) take place in the United States. Transfers are based on SCCs, the EU–US Data Privacy Framework (where applicable) and/or the sub-processor’s data processing terms.
Copies of relevant safeguards or information about transfers are available on request via privacy@ergonicx.com.
8. Rights of data subjects
Data subjects (employees and other users) have the following rights under the GDPR, where applicable:
- Access to personal data processed about them.
- Rectification of inaccurate or incomplete data.
- Erasure (“right to be forgotten”), where legally permitted.
- Restriction of processing.
- Data portability in a structured, commonly used format.
- Objection to processing based on legitimate interest.
- Withdrawal of consent where processing is based on consent (analytics), without affecting prior lawful processing.
Requests can be sent to privacy@ergonicx.com. We respond within 30 days. Because we generally act as processor for employee data, we may refer data subjects to their employer (the controller) where appropriate. We support customers in honouring requests as far as contractually and technically possible.
9. Data breaches
In the event of a personal data breach, we follow an internal notification procedure. If the breach is likely to pose a risk to the rights and freedoms of data subjects, we report it to the Dutch Data Protection Authority (Autoriteit Persoonsgegevens) within 72 hours.
As processor, we inform the relevant customer (controller) without undue delay after discovering a breach, so the customer can fulfil any notification and information obligations towards data subjects.
10. Security
We take appropriate technical and organisational measures to protect personal data, including:
- Encryption of data in transit (TLS 1.2 or higher).
- Encryption of data at rest in our database environment (Supabase).
- Role-based access control and organisation isolation (Row Level Security).
- Limited access to production systems for authorised personnel.
- Monitoring and error detection via Sentry.
- Regular security updates to the platform and dependencies.
11. Cookies and analytics
We use essential cookies and similar technologies for authentication, session management, security and language preference. These are necessary for the service to function.
For product analytics we use PostHog, hosted in the EU (eu.i.posthog.com). PostHog is only activated after the user has given consent via our cookie preferences. Without consent, no analytics cookies are placed and no tracking events are sent.
Stripe may place cookies for payments and fraud prevention when you use checkout or the customer portal. See Stripe’s privacy policy for details.
12. Contact details
ReinartzBranding (Ergonicx) Grensstraat 10 6374 CS Landgraaf Netherlands KVK: 94174946 VAT: NL005069113B66 Email: privacy@ergonicx.com
13. Complaints
If you believe we are not handling personal data correctly, contact us at privacy@ergonicx.com. You also have the right to lodge a complaint with the Dutch Data Protection Authority: https://autoriteitpersoonsgegevens.nl
14. Changes
We may amend this privacy policy. Material changes will be communicated to customers by email or via an in-app notice. The “Last updated” date at the top of this document indicates when the policy was last revised.
Changelog: 9 June 2026 — first production version of this privacy policy published.