RevoHR

    Privacy Notice

    RevoHR (BETTER ME S.R.L.)

    Version 1.0, last updated: 15 July 2026

    This Privacy Notice explains how BETTER ME S.R.L., operating the RevoHR platform and the website https://revohr.com (together, "RevoHR", "we", "us"), processes personal data, and describes your rights under the General Data Protection Regulation (Regulation (EU) 2016/679, "GDPR") and Romanian data-protection law (Law No. 190/2018).

    RevoHR acts in two different GDPR roles depending on the processing activity: as a data controller for some activities and as a data processor for others. Section 2 explains this distinction, which is important for understanding which parts of this notice apply to you.

    1. Who We Are (Data Controller)

    The controller responsible for processing your personal data, for the activities where RevoHR acts as a controller (see Section 2), is:

    BETTER ME S.R.L.

    Șoseaua Pantelimon Nr. 283, Camera 2, Bl. 12, Scara B, Etaj 2, Ap. 46, Sector 2, Bucharest, Romania

    Sole registration code (CUI): 54829360

    Trade Register order number: J2026036699007

    Data-protection contact: contact@better-me.tech

    2. Our Two Roles: Controller and Processor

    Under the GDPR, a data controller is the party that determines the purposes and means of processing personal data, the "why" and the "how". A data processor processes personal data on behalf of, and only on the documented instructions of, a controller. The two roles carry different responsibilities, and it matters for your rights: you exercise your rights against the controller, and where we act only as a processor we act for another organisation that is the controller.

    RevoHR takes both roles, depending on the activity:

    Processing contextRevoHR's roleWho is the controller
    Our website (revohr.com): visitors, contact / demo / waitlist forms, and our business-development and prospecting activitiesControllerRevoHR (BETTER ME S.R.L.)
    Our SaaS application: identity and account management, security, application-usage information and user management for the people who log in to operate the platform (e.g. HR and platform administrators)ControllerRevoHR (BETTER ME S.R.L.)
    Our SaaS application: employee / worker personal data that a client company records and manages through RevoHR to run its own HR activitiesProcessorThe client company (the employer)

    This notice covers in full the processing for which we are the controller (Sections 3-4). Section 5 explains, at a high level, the personal data we process as a processor on behalf of our clients. If you are a worker or employee whose data is managed by your employer through RevoHR, your employer is the controller of that data: please refer to your employer's own privacy notice and address rights requests to them. We will support your employer in responding, as required by Art. 28 GDPR.

    3. Personal Data We Process as Controller

    In connection with our website, our business-development and prospecting activities, and the administration of platform accounts, we process the following categories of personal data:

    a) Website visitors and prospects

    • Contact and enquiry data: name, work email, company name, phone number, and the free-text content of any message you send us through a contact, demo-request or waitlist form. Provided directly by you; providing it is voluntary, but it is necessary for us to respond to your enquiry.
    • Technical and usage data: IP address, device and browser information, and interaction data collected through cookies and similar technologies when you visit our website (see Section 9). Collected automatically.
    • Prospecting data: professional contact details of potential business customers, obtained from you or from public professional sources, used for B2B outreach.

    b) Platform account users (operators)

    • Identity and account data: name and email address of the individuals who log in to operate the platform (roles such as HR administrator and platform administrator), together with their assigned role and permissions.
    • Authentication and security data: login credentials (passwords are never stored in readable form, but they are kept as one-way cryptographic hashes), password-reset tokens (also stored hashed), and last-login information.
    • Account activity and security logs: records of certain actions performed in the application and related security/audit information, which may include identifiers such as user ID and, where applicable, technical data (e.g. IP address).

    4. Purposes, Legal Bases, and Retention (Controller)

    The following table sets out, for our controller-role processing, the purpose of each activity, the personal data involved, the legal basis under Art. 6 GDPR, and how long we keep the data.

    PurposeData categoriesLegal basisRetention
    Responding to contact, demo and waitlist enquiriesContact and enquiry dataArt. 6(1)(f): our legitimate interest in responding to enquiries; Art. 6(1)(b) where responding is a pre-contractual step at your requestDuration of the enquiry and, if no business relationship follows, up to 3 years from last contact
    Business development and B2B prospectingContact and prospecting dataArt. 6(1)(f): legitimate interest in promoting our services to businesses; Art. 6(1)(a): consent, for electronic marketing where requiredUntil you object or withdraw consent, and in any event reviewed at most every 3 years
    Operating our website and keeping it secureTechnical and usage dataArt. 6(1)(f): legitimate interest in a functional, secure websiteServer logs kept for a limited period (typically up to 12 months); cookie lifespans per Section 9
    Providing, administering and securing platform accounts (identity, security, user management)Identity, authentication, account activity and security dataArt. 6(1)(b): performance of our contract with the client; Art. 6(1)(f): legitimate interest in securing and administering the serviceFor the duration of the account, then deleted or anonymised (typically within 3 years after account closure); security logs kept for a shorter, defined period
    Complying with legal, accounting and tax obligationsBilling and contact data appearing in accounting recordsArt. 6(1)(c): legal obligation (Romanian accounting and tax legislation)Statutory retention period (generally 5-10 years)

    We do not make decisions that produce legal or similarly significant effects about website visitors, prospects or account users based solely on automated processing (Art. 22 GDPR). See Section 10 on our use of AI.

    5. Personal Data We Process as Processor (on behalf of clients)

    When a client company uses RevoHR to manage its workforce, that company is the controller of its workers' personal data and decides why and how the data is processed. We act as its processor, processing the data only on the client's documented instructions and under a data-processing agreement that meets the requirements of Art. 28 GDPR. The legal basis for this processing is determined by the client, not by us.

    On our clients' behalf, the platform may process the following categories of worker personal data:

    • Identity and contact: first and last name, phone number (used as the worker's WhatsApp identity), email.
    • Demographic: date of birth, gender, nationality and preferred language.
    • National identifier: national ID number, including the Romanian CNP, which encodes date of birth and sex and is subject to specific safeguards under Romanian law.
    • Address and emergency contact: home address, and the name and phone number of a worker's emergency contact.
    • Employment: job title, department, role, manager, and hire / termination dates.
    • Worker documents: employment contracts, ID-card scans and certificates.
    • Attendance and location: check-in / check-out records including GPS location, working hours and overtime.
    • Training and communications: responses to training questions (and AI-assisted analysis of them), and WhatsApp conversation content, including messages, images and voice notes.
    • Special-category data (Art. 9 GDPR): medical-leave information and medical certificates (health data); facial photographs; and free-text or voice content that may incidentally reveal special-category data. This data is processed on the client's instructions and legal basis, which for employment-related health data is typically Art. 9(2)(b) or (h) GDPR combined with an Art. 6 basis.

    Retention of worker data is determined by the client controller. We retain it for the duration of our service agreement and delete or return it on the client's instruction or on termination, subject to any legal retention obligations. If you are a worker, please direct access, correction, deletion and other rights requests to your employer; we will assist the employer as required under Art. 28(3) GDPR.

    6. Recipients and Sub-Processors

    We use carefully selected service providers ("processors" / "sub-processors") to operate RevoHR. They process personal data only on our instructions (or, for worker data, on our clients' instructions passed on to them) under GDPR-compliant agreements. The main categories are:

    ProviderPurposeData categories
    Microsoft Azure (cloud hosting, Blob Storage, Cognitive Services)Application hosting and compute; document and file storage; speech synthesis for training videos; image moderation of uploaded contentAll platform data in transit and at rest; documents (contracts, ID scans, certificates, medical certificates, photos); caption/script text; uploaded images
    Meta Platforms (WhatsApp Business Cloud API)Two-way worker messaging and media transportPhone numbers, message content, worker and company names, images, voice notes
    OpenAIIntent detection, translation, retrieval-augmented answers, and text embeddings for the AI assistant and document searchWorker message text, conversation history, company-document text, query text
    SendGrid (Twilio)Transactional and notification emailRecipient email addresses, names, password-reset links
    SIEL AI SRL (SIEL.AI)Service ProviderAccess to all platform data in transit and at rest; documents (contracts, ID scans, certificates, medical certificates, photos); caption/script text; uploaded images

    We also operate internal search components (Qdrant, and a legacy ChromaDB store) hosted within our own cloud environment; these are not independent third parties. Where a company document contains worker data, that data may also be held within this search store.

    7. International Data Transfers

    Some of our sub-processors (in particular Meta, OpenAI and SendGrid, and depending on the configured cloud region, certain Microsoft Azure services) may process personal data outside the European Economic Area (EEA), including in the United States.

    Where personal data is transferred outside the EEA, we ensure appropriate safeguards under Chapter V GDPR, namely:

    • European Commission adequacy decisions (Art. 45 GDPR), including the EU, U.S. Data Privacy Framework where the recipient is certified; and/or
    • Standard Contractual Clauses (Art. 46(2)(c) GDPR), supplemented by additional technical and organisational measures where necessary.

    You can request further information about the specific transfer mechanism applied to a given provider, and a copy of the relevant safeguards, by contacting us at contact@better-me.tech.

    8. Your Rights

    Under the GDPR, you have the following rights regarding your personal data:

    • Access (Art. 15 GDPR): obtain confirmation of whether your data is processed and receive a copy.
    • Rectification (Art. 16 GDPR): have inaccurate or incomplete data corrected without undue delay.
    • Erasure (Art. 17 GDPR): request deletion of your data where legally permissible.
    • Restriction (Art. 18 GDPR): request temporary restriction of processing under certain conditions.
    • Data portability (Art. 20 GDPR): receive your data in a structured, commonly used, machine-readable format.
    • Object (Art. 21 GDPR): object to processing based on legitimate interests.
    • Withdraw consent (Art. 7(3) GDPR): at any time, without affecting the lawfulness of prior processing.
    • Lodge a complaint (Art. 77 GDPR): file a complaint with the competent supervisory authority.

    To exercise your rights, please contact us at contact@better-me.tech. We will respond within one month (extendable by a further two months for complex or numerous requests). Exercising your rights is free of charge unless a request is manifestly unfounded or excessive. If your data is processed by RevoHR as a processor on behalf of your employer, please address your request to your employer as the controller.

    You also have the right to lodge a complaint with the Romanian supervisory authority:

    The National Supervisory Authority for Personal Data Processing (ANSPDCP)

    B-dul General Gheorghe Magheru 28-30, Sector 1, 010336 Bucharest, Romania

    Phone: +40 31 805 9211 · Email: anspdcp@dataprotection.ro · www.dataprotection.ro

    9. Cookies and Tracking Technologies

    Our website uses cookies and similar technologies. We use strictly necessary cookies to make the site work; these do not require consent. Any functional, analytics or marketing cookies are only set with your consent, which you can give or refuse and later change at any time through the on our website.

    CategoryPurposeConsent
    Strictly necessaryCore site functionality, load balancing and securityNot required (Art. 6(1)(f))
    FunctionalRemembering preferences and settingsConsent (Art. 6(1)(a))
    Analytics / performanceUnderstanding aggregated site usage to improve the serviceConsent (Art. 6(1)(a))

    The specific, up-to-date list of cookies, their providers and their lifespans is available in the cookie-preference centre on our website. See also our Cookie Policy.

    10. AI Processing and Automated Decision-Making

    We use automated processing technologies, including artificial intelligence (AI), mainly within the RevoHR application. In this context we generally act as a processor on behalf of our clients; the client controller determines the purpose and legal basis. The main uses are:

    AI system / technologyPurposeDecision type
    AI assistant (OpenAI)Understanding worker messages, translating, and generating conversational answers over WhatsAppAssistive (no solely-automated decision with legal or similarly significant effect)
    Document search (OpenAI embeddings)Semantic search over company documents to support answersAssistive
    Speech and content-safety services (Azure)Speech synthesis for training videos; moderation of uploaded imagesAssistive

    In line with the EU AI Act (Regulation (EU) 2024/1689), workers who interact with the AI assistant are informed that they are communicating with an automated system. Where an automated decision would produce legal effects or similarly significantly affect a person (Art. 22 GDPR), that person has the right to obtain human intervention, express their point of view, and contest the decision; in the processor context these rights are handled by the client controller. In our controller-role processing, we do not carry out such solely-automated decision-making.

    11. Data Security

    We implement appropriate technical and organisational measures pursuant to Art. 32 GDPR to protect personal data against unauthorised access, loss, destruction or alteration. These include encryption of data in transit (TLS), one-way hashing of operator passwords, role-based access controls, strict separation of each client's data within the multi-tenant application, and access to stored documents only through short-lived, restricted links rather than public URLs. Our infrastructure is hosted on Microsoft Azure. These measures are regularly reviewed and adapted to the state of the art.

    12. Children's Data

    Our website and our SaaS accounts are intended for businesses and their professional users, and are not directed at children (in Romania, the age of digital consent is 16). Where worker data processed on behalf of a client controller may relate to persons below the applicable age threshold, ensuring a valid legal basis is the responsibility of the client controller as the employer.

    13. Changes to This Notice

    We reserve the right to update this notice to reflect changes in legislation or in our practices. The current version is always available on our website. We will notify you of material changes in an appropriate manner.

    14. Contact

    If you have any questions about the processing of your personal data or wish to exercise your rights, you can reach us at:

    BETTER ME S.R.L. (RevoHR)

    Șoseaua Pantelimon Nr. 283, Camera 2, Bl. 12, Scara B, Etaj 2, Ap. 46, Sector 2, Bucharest, Romania

    Email: contact@better-me.tech · Website: https://revohr.com