Speybl processes employee personal data in accordance with the GDPR (EU) 2016/679. Below are the specific technical and procedural measures implemented in the application.
Data transmission encryption
All communication between the browser and the server is done exclusively via HTTPS (TLS). Unencrypted connections are not supported.
Data access control
Each user has access only to data corresponding to their role. An employee can only see their own profile. A team leader can only see their team. HR managers and administrators have the scope of access defined by role permissions. Role Settings and permissions are managed by the organization administrator in Settings → Users and Roles.
Anonymization in forms
Forms support anonymous mode — responses are not linked to the respondent's identity and cannot be traced back to a specific person. Anonymity cannot be changed after the Forms is created.
Data backup
Data is backed up regularly. In the event of a technical failure, restoration from a backup is possible.
Processing agreement
Inove, as a data processor, concludes a data processing agreement (DPA) with customers in accordance with Article 28 of the GDPR. The agreement is part of the contractual documentation during onboarding.
Contact
Please direct any questions regarding the processing of personal data or requests for data deletion to support@speybl.com .