Privacy Policy

Privacy Policy

HRPanorama Sp. z o.o., owner of the hrpanorama.com website, makes every effort to protect the privacy of persons using this website.

This Privacy Policy sets out how we take care of your personal data and ensure the exercise of your rights in connection with your personal data that we collect in the situations described in this Privacy Policy. It is also intended to fulfil our obligation to process data in a lawful, fair, and transparent manner.


Definitions Used in the Privacy Policy

HR Panorama or Administrator – HRPanorama Sp. z o.o., with its registered office in Kraków, ul. Feliksa Wrobela 13, 30-798 Kraków.

Account – a set of data and settings created for the User within the System, used to manage services provided with the help of the System.

Profile – an Account functionality that allows the User to collect selected information, including details about their employment history, qualifications, educational background, and other skills.

Newsletter – a service provided via email, whereby HR Panorama sends information in the form of an electronic message (email) to the email address provided by the User.

Privacy Policy – this document.

Terms of Service – the Terms and Conditions for the provision of electronic services within the System belonging to HRPanorama Sp. z o.o., in the currently applicable version.

GDPR – Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (General Data Protection Regulation).

Website – the website belonging to HRPanorama Sp. z o.o., through which HR Panorama provides its services, including the ability to sign up for the Newsletter, access blog content, learn about the System offered by HR Panorama, or proceed to registration or login to that System. The Website is available at the following addresses: www.hrpanorama.com, www.hrpanorama.pl, hrpanorama.no.

System – the IT system under the name HR Panorama, made available to the Service Recipient electronically in a SaaS model using a web browser, enabling the management of HR processes.

User – an adult natural person who holds an Account or otherwise uses services offered by HR Panorama through the Website.

You, Your – the User, as applicable.

In this Privacy Policy we also use the names of individual services and Account functionalities that have been defined and described in detail in the Terms of Service.


I. Data Controller

  1. The controller of personal data within the meaning of Article 4(7) of the GDPR is HRPanorama Spółka z ograniczoną odpowiedzialnością, with its registered office in Kraków, at ul. Feliksa Wrobela 13, 30-798 Kraków, entered in the register of entrepreneurs of the National Court Register by the District Court for Kraków-Śródmieście in Kraków, 11th Commercial Division of the National Court Register, under KRS number: 0000827108, NIP: 6793196738, REGON: 385580424, share capital: PLN 50,000.
  2. Contact details of the Data Controller. Email address: [email protected].
  3. The Administrator, pursuant to Article 32(1) of the GDPR, observes the principles of personal data protection and applies appropriate technical and organisational measures to prevent the accidental or unlawful destruction, loss, modification, unauthorised disclosure, or unauthorised access to personal data processed in connection with its activities.
  4. The provision of personal data is, as a rule, voluntary. In certain cases, however, providing certain categories of data may be necessary, including for the creation of an Account in the System and the use of services provided by HR Panorama through the System, as well as for ordering the Newsletter service in order to have it delivered to the User.
  5. The Data Controller processes personal data only to the extent required for the proper fulfilment of the purposes set out in this Privacy Policy.

II. Purposes and Legal Bases for Processing Personal Data

  1. The Administrator processes personal data for the following purposes: a) preparing and sending a commercial offer in response to the User’s interest, which is our legitimate interest as the data controller (Article 6(1)(f) GDPR); b) entering into a contract with HR Panorama and providing services through the Website in performance of that contract (Article 6(1)(b) GDPR); c) handling the complaints process, based on our obligation as the data controller under applicable law (Article 6(1)(c) GDPR); d) fulfilling accounting obligations, including those related to issuing and receiving settlement documents and their processing, based on tax law provisions (Article 6(1)(c) GDPR); e) archiving data and creating backups, in connection with our obligation as the data controller to properly secure data and based on our legitimate interest as the personal data controller (Article 6(1)(f) GDPR); f) pursuing or defending against claims directed at HR Panorama, which is our legitimate interest as the data controller (Article 6(1)(f) GDPR); g) contact by telephone or email, in particular in response to enquiries addressed to the Data Controller, which is our legitimate interest as the data controller (Article 6(1)(f) GDPR); h) sending technical information regarding the functioning of the System and services used by the User, which is our legitimate interest as the data controller (Article 6(1)(f) GDPR); i) marketing of the Data Controller’s own products, including the delivery of commercial information, conversion analysis, and optimisation of marketing activities for specific recipients, which is our legitimate interest (Article 6(1)(f) GDPR) or is carried out on the basis of previously given consent (Article 6(1)(a) GDPR); j) analysing User behaviour on the Website, analysing how Users arrived at our site, and analysing the System’s operation in order to improve its functioning, security, and fix errors, which is our legitimate interest (Article 6(1)(f) GDPR); k) where HR Panorama is a party to a contract with an entity that employs the User, HR Panorama may also process the User’s personal data in order to perform that contract, in which case it will act as a data processor on behalf of that third party (the entity with which HR Panorama has a contract).

III. Recipients of Data. Transfer of Data to Third Countries

  1. Recipients of personal data processed by the Data Controller may include entities processing personal data on behalf of HR Panorama, including entities whose services HR Panorama uses where necessary to fulfil the purposes set out in this Privacy Policy, including entities providing services such as: a) hosting and storage of data and applications in the cloud, b) sending email and SMS messages, c) document conversion, d) online payments, e) error handling, f) additional functionalities, such as live chat, g) analysis and monitoring of User behaviour, h) support of marketing activities, i) other services, including IT and accounting services.
  2. Recipients of personal data processed by the Data Controller may also include entities that pursue their own purposes in relation to the processing of personal data — including, for example, entities handling payments for HR Panorama services, accounting firms, law firms, and entities to which the Data Controller may be required to disclose personal data under applicable law (in particular, authorised public authorities or institutions).
  3. Data may also be transferred to entities outside the European Economic Area (EEA). Whenever your personal data is transferred outside the European Economic Area or to countries that do not provide the same or an adequate level of personal data protection, we will ensure that this takes place on a valid legal basis and with the legally required safeguards.
  4. The Website may contain links to third-party websites. Different rules than those described in this Privacy Policy apply to visitors of those websites with regard to the processing of personal data, and a different entity acts as the data controller for data processed there. We recommend familiarising yourself with the personal data processing rules published by the controllers of those websites.
  5. The Website may also contain social media plugins. When using the Website, the IP address of your device and the identifier of the browser you are using are transmitted to the providers of those social media platforms. Through this integration, the providers of those platforms receive information that your browser has displayed a page of our Website, even if you do not have a profile on the given social media platform or are not currently logged in. Clicking on a social media plugin button (e.g. “Like” or “Share”) additionally establishes a direct connection with the servers of those media providers, who may collect other data from your device. Please note that we have no control over what data is collected by social media platforms after you click their button. More information on the purposes and scope of data collected by these entities, as well as how your personal data is processed, used, and protected, including your rights and available privacy options, can be found on the Facebook Ireland Ltd., Ireland page: https://pl-pl.facebook.com/privacy/explanation. We note that, together with Facebook Ireland Limited, HR Panorama acts as a joint controller for the processing of data for statistical purposes. Information on the principles of joint data controlling by HR Panorama and Facebook can be found at: https://www.facebook.com/legal/terms/page_controller_addendum. Information about how Facebook processes personal data for statistical purposes is available here: https://www.facebook.com/legal/terms/information_about_page_insights_data.

IV. Retention Period for Personal Data

  1. The Data Controller retains personal data related to the conclusion, performance, and settlement of contracts for the duration of the contract concluded with the data subject, and after its expiry for purposes related to pursuing claims under the contract or fulfilling obligations arising from applicable law (including tax law), but for no longer than the limitation period under the Civil Code or tax law provisions.
  2. The Data Controller retains personal data contained in archival and backup copies for the period determined in accordance with the documentation of the security measures applied by the Administrator.
  3. The Data Controller retains personal data processed for marketing purposes, data of persons who used the Website but did not enter into a contract with the Administrator, and data collected for the purposes of analysing the behaviour of Website Users, for a period of up to 3 years counted from the end of the year in which the data was collected, but no longer than until the withdrawal of consent to data processing or the lodging of an objection to data processing.
  4. Where HR Panorama acts as a processor of your personal data on behalf of another controller, HR Panorama will process your personal data for the period arising from the data processing agreement or other legal instrument governing data processing on behalf of that entity.
  5. The Data Controller will delete personal data upon the expiry of the period indicated above, unless processing can be continued on a different legal basis.

V. Rights of the Data Subject

  1. Every data subject has the right to: a) access – to obtain from the Administrator confirmation as to whether their personal data is being processed. If data about a person is being processed, they are entitled to obtain access to it and to the following information: the purposes of processing, the categories of personal data, information about the recipients or categories of recipients to whom the data has been or will be disclosed, the retention period or the criteria used to determine it, the right to request rectification, erasure, or restriction of processing of personal data, and the right to object to such processing (Article 15 GDPR); b) to receive a copy of the data – to obtain a copy of the data undergoing processing, with the first copy being free of charge and the Administrator being able to charge a reasonable fee for subsequent copies based on administrative costs (Article 15(3) GDPR); c) to rectification – to request rectification of inaccurate personal data concerning them or completion of incomplete data (Article 16 GDPR); d) to erasure – to request erasure of their personal data where the Administrator no longer has a legal basis for processing it or the data is no longer necessary for the purposes of processing (Article 17 GDPR); e) to restriction of processing – to request restriction of the processing of personal data (Article 18 GDPR), where:
    • the data subject contests the accuracy of the personal data — for a period enabling the Administrator to verify the accuracy of the data,
    • the processing is unlawful and the data subject opposes erasure, requesting restriction of use instead,
    • the Administrator no longer needs the data, but it is required by the data subject for the establishment, exercise, or defence of legal claims,
    • the data subject has lodged an objection to processing — pending verification of whether the legitimate grounds of the Administrator override those of the data subject;
    f) to data portability – to receive, in a structured, commonly used, and machine-readable format, the personal data concerning them that they have provided to the Administrator, and to request that such data be transmitted to another controller, where the data is processed on the basis of the data subject’s consent or a contract concluded with them, and where the data is processed by automated means (Article 20 GDPR); g) to object – to object to the processing of their personal data for the legitimate purposes of the Administrator, on grounds relating to their particular situation, including in relation to profiling. The Administrator will then assess whether compelling legitimate grounds for processing exist that override the interests, rights, and freedoms of the data subject, or grounds for the establishment, exercise, or defence of legal claims. If, based on that assessment, the interests of the data subject outweigh those of the Administrator, the Administrator will be required to cease processing the data for those purposes (Article 21 GDPR).
  2. To exercise the above rights, the data subject should contact the Administrator using the contact details provided and inform them which right they wish to exercise and to what extent.
  3. The data subject has the right to lodge a complaint with the supervisory authority, which is the President of the Personal Data Protection Office in Warsaw. A complaint may be lodged in writing (to the address: ul. Stawki 2, 00-193 Warszawa) or electronically via the Electronic Inbox of the President of the Office.

VI. Profiling and Automated Decision-Making

In certain situations, the Administrator or a third party used by the Administrator may be able to link information collected via cookies and similar technologies to a specific, identifiable individual. Personal data in such cases may be subject to profiling using tools for analysing User behaviour on the website. The User profile created with the help of this data may be used to display advertisements tailored to that profile. However, this data and any such profile will not be used for automated decision-making in relation to the User.


VII. How We Ensure Security

We make every effort to ensure the security of your personal data. The System uses encrypted data transmission (SSL) during registration and login, which protects your identifying data and significantly hinders unauthorised systems or individuals from gaining access to your Account. We also enable two-factor authentication for System Users. Documents and certain data processed through the System are subject to encryption. We also ensure appropriate separation of the databases used by the System, and we regularly perform database backups.


VIII. How We Use Cookies

Details about how we use cookies can be found in the Cookie Policy.


IX. User Data Obtained Through Google Services (Google Sign-In, Google Calendar)

HR Panorama offers optional integrations with Google services, including Single Sign-On (Google Sign-In / SSO) and Google Calendar integration. Below we describe in detail what Google data we process, how we use it, and how we protect it. HR Panorama’s use of Google data complies with the Google API Services User Data Policy, including the Limited Use requirements for data obtained through sensitive scopes.

1. Scope of Google Data Processed (Data Accessed)

Through the Google services integration, HR Panorama gains access to the following Google account data, within the OAuth 2.0 scopes to which the User has consented:

a) Google Sign-In (scopes: openid, email, profile)

  • email address (email),
  • email address verification status (email_verified),
  • first and last name (name, given_name, family_name),
  • unique Google account identifier (sub),
  • profile picture URL (picture),
  • preferred language (locale).

b) Google Calendar (scope: https://www.googleapis.com/auth/calendar.events)

  • reading events from the User’s calendar (title, description, start date and time, end date and time, attendee list, attendee status, location, busy/free status for that time slot),
  • creating new events in the User’s calendar,
  • modifying and deleting only events created by the HR Panorama application,
  • reading free/busy availability information in order to suggest meeting times.

HR Panorama uses the minimal calendar.events scope (rather than the full calendar scope) to restrict access exclusively to events, and not to calendar settings or metadata.

HR Panorama does not request or obtain access to Gmail messages and attachments, Google Drive files, contacts, Google Docs/Sheets documents, or any other Google Workspace services beyond those listed above.

2. Purpose and Manner of Using Google Data (Data Usage)

Data obtained from a Google account is used exclusively for the following purposes:

a) Google Sign-In:

  • authenticating the User in the HR Panorama System,
  • matching the Google account to an existing System Account by comparing the verified email address,
  • displaying basic profile data (first name, last name, profile picture) in the System interface.

b) Google Calendar:

  • adding to the User’s calendar events created within the HR Panorama System, in particular: recruitment meetings, performance reviews, 1:1 meetings, training sessions, and onboarding events,
  • automatic synchronisation of approved leave requests and absences as events in the User’s calendar,
  • reading the User’s availability information in order to suggest or book optimal times for HR meetings,
  • updating and cancelling events created by HR Panorama when changes occur in the System (e.g. rescheduling a meeting, cancelling a leave request).

HR Panorama does not use data obtained from Google (including Google Calendar data) for:

  • marketing, advertising, or advertising profiling purposes,
  • training artificial intelligence models or machine learning,
  • analysing the content of calendar events beyond what is necessary to carry out a specific function requested by the User,
  • sharing calendar data with other System Users beyond the scope necessary to perform the function (e.g. displaying free/busy status to someone proposing a meeting),
  • any purposes other than those listed in point 2 above.

HR Panorama’s use of Google data complies with the Google API Services User Data Policy, including the Limited Use requirements.

3. Sharing Google Data with Third Parties (Data Sharing)

HR Panorama does not share, sell, rent, or transfer data obtained from a User’s Google account (including Google Calendar data) to any third parties for marketing, advertising, or commercial purposes.

Google data may be processed exclusively by:

a) providers of technical infrastructure used by HR Panorama to deliver the service (DigitalOcean, Amazon Web Services, Cloudflare) — solely as data processors acting on behalf of HR Panorama, under data processing agreements compliant with Article 28 of the GDPR;

b) the Client (employer), who acts as the data controller for End Users within their System instance — to the extent necessary to perform HR functions (e.g. displaying an approved leave event in the calendar);

c) authorised public authorities — only where a legal obligation exists under applicable law.

HR Panorama does not transfer Google Calendar data to any AI model providers, analytics tools, or third parties not listed above.

4. Storage and Protection of Google Data (Data Storage & Protection)

a) Google Sign-In tokens. Access tokens and ID tokens issued during the login process are not stored in HR Panorama’s databases. They are processed exclusively in server memory (in-memory) during the authentication process.

b) Google Calendar tokens. To enable continuous access to Google Calendar (including background access when the User is not actively logged in), HR Panorama stores refresh tokens issued by Google. These tokens are:

  • encrypted before being written to the database using the AES-256-GCM algorithm,
  • stored in the Client’s isolated database schema (schema-per-tenant architecture),
  • associated exclusively with a specific User Account in the System,
  • never transmitted outside HR Panorama’s infrastructure or logged in plaintext.

Google Calendar access tokens are stored exclusively in Redis cache (with a time-to-live matching the token’s TTL, maximum 1 hour) and are not persisted in the database.

c) Temporary tokens (handshake tokens used in internal Auth Hub communication) are stored in Redis cache with an automatic expiry time not exceeding 60 seconds (SET NX EX pattern) and are deleted immediately after single use.

d) Only the minimum data necessary to perform the function is stored in the Client’s database: the unique Google identifier (sub), the email address linked to the Account, the encrypted Google Calendar refresh token, and the event IDs of events created by HR Panorama in the User’s calendar — solely to enable their future update or deletion.

e) The content of Google Calendar events (titles, descriptions, attendee data) is not persisted in HR Panorama’s databases. This data is fetched from the Google API on demand, processed in memory to carry out a specific operation, and then discarded.

f) Technical security measures:

  • all communication takes place exclusively over encrypted HTTPS/TLS 1.2+ connections,
  • requests between System components are signed using an HMAC mechanism with shared secrets,
  • internal tokens are signed using the JWT HS256 algorithm,
  • encryption keys for refresh tokens are stored separately from the database, in a managed secrets store,
  • infrastructure is protected by Cloudflare (WAF, DDoS protection),
  • databases are separated using a schema-per-tenant architecture,
  • administrative access to infrastructure is secured with two-factor authentication (2FA),
  • security tests and audits are carried out regularly in accordance with ISO/IEC 27001 requirements.

g) Certification: HR Panorama holds an ISO/IEC 27001 certificate confirming the implementation of an information security management system.

h) Data location: HR Panorama’s infrastructure is located in European data centres within the European Economic Area.

5. Retention Period and Deletion of Google Data (Data Retention & Deletion)

a) Temporary tokens (handshake tokens in Redis) expire automatically within a maximum of 60 seconds.

b) Google Calendar access tokens expire in accordance with Google’s policy (typically 1 hour) and are removed from Redis cache upon expiry.

c) Google Calendar refresh tokens are stored (in encrypted form) for as long as:

  • the User holds an active Account in the HR Panorama System and has an active Google Calendar integration,
  • the Client (employer) has an active agreement with HR Panorama.

d) The association between a Google account and a System Account (the sub identifier and email address) is retained for as long as the associated User Account exists.

e) Event IDs of events created by HR Panorama in the User’s calendar are retained for the duration of the associated record in the System (e.g. a leave request, a scheduled meeting) and are deleted when that record is deleted.

f) Upon deletion of a User Account in the System, all associated Google data (refresh token, sub identifier, event IDs) is permanently deleted from HR Panorama’s databases within no more than 30 days, in accordance with the principles set out in Section IV of this Privacy Policy.

g) At any time, the User may:

  • disconnect the Google Calendar integration from their System Account via profile settings — this causes immediate deletion of the refresh token from HR Panorama’s database,
  • disconnect the Google account from SSO login in profile settings,
  • revoke all permissions granted to the HR Panorama application directly in their Google account settings at: https://myaccount.google.com/permissions — once permissions are revoked, refresh tokens stored by HR Panorama become invalid and are deleted upon the first failed attempt to use them,
  • request deletion of all data obtained from their Google account by contacting the Administrator at [email protected]. The request will be fulfilled within no more than 30 days.

Revoking permissions or disconnecting the integration does not automatically delete events previously created by HR Panorama in the User’s Google Calendar — the User may delete them manually from within Google Calendar.

6. B2B Model — HR Panorama as a Data Processor

HR Panorama is a software provider operating in the B2B SaaS model. In the context of End Users’ (Client’s employees’) integration with Google services, HR Panorama acts as a data processor within the meaning of Article 28 of the GDPR, on behalf of the Client, who serves as the data controller for their employees’ data.

The Client (employer) independently decides whether to enable the Google Calendar integration for their System instance, and each End User must individually grant OAuth consent for access to their calendar.


X. Changes to the Privacy Policy

We may amend and supplement this Privacy Policy as needed. We will inform you of any changes or additions by posting relevant information on the main page of the Website, and in the case of significant changes, we may also send you a separate notification to the email address you have provided.

This Privacy Policy does not limit any rights to which you are entitled under the Terms of Service or applicable law.

x