Privacy Policy
Effective from 2026-09-12
This policy describes what personal data we process in connection with the tivero.app website and the Tivero application, in which role we do so, and what rights data subjects have.
1. Who the data controller is
The controller of personal data processed in connection with the tivero.app website and the Tivero application is Convertin OÜ, a company registered in Estonia — register: Estonian Commercial Register (Äriregister), registry code 14814025, VAT number EE102244560, registered address Harju maakond, Tallinn, Kesklinna linnaosa, Tornimäe tn 3 // 5 // 7, 10145, Estonia.
Contact for data protection matters: hello@tivero.app.
2. What this document covers — and two different roles
This policy covers two cases in which our role differs, and that distinction decides who a request should go to.
First: data about people visiting the website, and about people who create an account and manage a subscription. Here we are the controller.
Second: data a customer enters into their workspace — employee and contractor records, requests, absences, balances. Here the customer is the controller and we process that data solely on their instructions, as a processor, on the terms set out in the DPA.
3. What data we process
Depending on how Tivero is used, we process:
- account data: first and last name, email address, authentication credentials,
- workspace and team data: team structure, roles, assignments,
- HR-adjacent data entered by the customer: absence requests, dates, balances, absence types,
- billing data: company name, address, VAT number, invoicing email address, payment history,
- support correspondence, conducted by email,
- contract evidence: which version of the Terms, the DPA and this notice was accepted or presented, by which user and when,
- technical data: IP address, browser and device information, operational logs,
- analytics data — only where the visitor has given consent.
4. Where the data comes from
Account data is provided by the person creating the account, or by the workspace administrator who invites them.
HR-adjacent data is entered by the customer as employer or principal. We do not collect it from the people it concerns and we do not buy data from third parties.
5. Why we process data, and on what legal basis
Providing the service, running the account and handling the subscription — performance of a contract (GDPR Art. 6(1)(b)).
Billing, invoicing and tax obligations — a legal obligation of the controller (Art. 6(1)(c)).
Service security, abuse prevention, operational logs and legal claims — the controller’s legitimate interest (Art. 6(1)(f)). This includes keeping evidence of which contract version was accepted; that record is not consent to anything.
Website usage analytics — consent (Art. 6(1)(a)), which can be withdrawn at any time.
For data entered into a workspace, the customer determines the legal basis as its controller; we act on their instructions.
6. Special categories of data
A health-related absence is a distinct type in Tivero whose details are not shown to the whole team.
Notifications sent outside the application — including email and messenger cards — do not name such an absence type; a neutral word (“Absence”) is used instead.
Tivero is not intended for storing medical documentation or descriptions of a person’s health.
7. Authentication
Sign-in is handled by Clerk, Inc. as a processor. This involves a user identifier, email address, first and last name, and authentication metadata. Where Clerk signs in a customer’s users or delivers a workspace invitation, it does so as a subprocessor under the DPA.
As at the date of this policy, sign-in uses an email address; no external identity provider sign-in is enabled.
8. Billing
Payments and invoices are handled by Stripe. We pass it billing data: company name, address, VAT number, email address and subscription status.
For obligations arising from payment services and fraud prevention law, Stripe acts as a separate controller.
We do not store full payment card numbers.
9. Email
Service-related messages are sent by Resend, Inc. as a processor, from an address in the notify.tivero.app domain. Notifications about requests and approvals in a customer’s workspace are sent on the customer’s behalf, with Resend acting as a subprocessor under the DPA.
Correspondence sent to our contact address is received in Microsoft 365 mail; Microsoft processes it as a processor.
10. Analytics
Website usage analytics is provided by PostHog, on its European cloud (eu.i.posthog.com), as a processor.
Analytics loads only after consent is given, and consent can be withdrawn at any time. Before consent no identifier is created and no event is sent.
The analytics identifier is pseudonymous, not anonymous: it contains no name or email address, but it persists between visits and allows events from the same browser to be linked.
Session recording is not used in customer workspaces.
11. Marketing technologies
A tag manager may load on tivero.app, only after marketing consent is given.
As at the date of this policy the tag manager container holds no tags and loads no vendor. If that changes, the vendors will be listed in the Cookie Policy before they are enabled.
12. Customer-enabled integrations
Tivero provides for integrations with third-party services, enabled by a customer’s own decision.
As at the date of this policy no such integration is configured in the production environment, and consequently no integration provider receives any data. A customer enabling one changes that, and it is subject to the customer’s own assessment.
13. Telemetry and monitoring
Service monitoring relies on logs and telemetry collected within Microsoft Azure infrastructure, in the European Union.
We do not use a third-party error monitoring service.
14. Providers that do not receive personal data
Tivero uses an external public-holiday calendar source. We send it only a country code, a year and a day type — no personal data and no customer data.
We state this explicitly, because the presence of an integration does not mean a provider receives personal data.
15. List of processors
The current list is published at /subprocessors in two parts: subprocessors that process data a customer enters into its workspace on the customer’s behalf, under the DPA; and other processors and recipients we use for our own processing as controller, described in this policy.
16. Transfers outside the European Economic Area
Tivero’s production environment — application, database and backups — runs in the Poland Central region in the European Union.
Some providers are established outside the EEA. Where that is the case, transfers rely on the mechanisms provided for in the GDPR, in particular standard contractual clauses in our data processing agreements with those providers.
Per-provider detail is in the list at /subprocessors.
17. How long we keep data
Account and workspace data is kept for the duration of the agreement.
Ordinary termination. When a subscription ends without a switching request, the workspace remains available in read-only mode, with export, until the customer requests its deletion. Deletion is then staged: a deletion request, a 30-day grace period with access cut off, and then permanent deletion.
Switching provider. When a customer requests a switch under the Data Act, its data is kept through the transitional period and a retrieval period of at least 30 days, as set out in the Terms of Service, and is erased after the retrieval period has expired and the switch has been successfully completed, subject to retention required by law.
Database backups are retained for 14 days and then expire automatically.
Billing and accounting records are kept for the period required by tax and accounting law.
Demo workspaces, which run on synthetic data, are deleted automatically.
Operational logs are kept for as long as needed for security and diagnostics.
18. Security
We apply technical and organisational measures appropriate to the risk, including data isolation between workspaces, role-based access control, and logging of administrative actions.
Access to production data is restricted and recorded. The measures are described in detail in Annex 2 to the DPA.
19. Your rights
Data subjects have:
- the right of access and to obtain a copy,
- the right to rectification,
- the right to erasure,
- the right to restriction of processing,
- the right to data portability,
- the right to object to processing based on legitimate interest,
- the right to withdraw consent — without affecting the lawfulness of processing before withdrawal,
- the right to lodge a complaint with a supervisory authority.
20. How requests are handled
Requests about account and subscription data should be sent to us, at the contact address above.
Requests about data held in an employer’s workspace should go to that employer — they are its controller. If we receive such a request directly, we pass it to the relevant customer and assist them in handling it.
Tivero gives customers data export and real deletion of an account and a workspace.
21. Automated decision-making
We do not take decisions based solely on automated processing that produce legal effects concerning data subjects, and we do not profile for that purpose.
22. Children
The service is aimed at businesses and is not intended for people under 16.
23. Changes to this policy
This policy may be updated. We announce material changes, and the date of the last update is shown at the top of the document.
24. Contact
For data protection matters: hello@tivero.app.
Controller: Convertin OÜ, a company registered in Estonia — register: Estonian Commercial Register (Äriregister), registry code 14814025, VAT number EE102244560, registered address Harju maakond, Tallinn, Kesklinna linnaosa, Tornimäe tn 3 // 5 // 7, 10145, Estonia.