Privacy policy
This policy explains which data OOUR processes when you use the OOUR mobile app, the OOUR web application or the website oour.app, why it processes it, who it is shared with, how long it is kept, and what rights you have. It is written for workers who use the mobile app and for coordinators and managers who use the web application.
1. Who processes your data
OOUR is a product of KYUBIX DOO BEOGRAD, Bulevar kralja Aleksandra 314, Belgrade, Republic of Serbia, registration number 22188933, tax ID 115653879 (“OOUR” or “we”).
When you use OOUR as a worker, coordinator or manager, you do so because a company that uses OOUR has engaged or employed you (the “Company”). You do not create the account yourself: the Company creates it and sends you an invitation to your phone number. The code you receive by message serves only to confirm that the number is yours. For data about your work, schedule, presence and hours, the Company is the data controller: it decides why and how that data is processed. OOUR is the processor, handling that data on the Company’s instructions under a data processing agreement it has with every Company.
For data required for the platform to work independently of any single Company (your sign-in profile, your phone number and its history, devices and sessions, security records) OOUR is the controller. The same profile lets another Company engage you later without re-entering your data.
Contact for all data questions: privacy@oour.app.
2. Which data we process
Worker (mobile app)
| Data | Source | Purpose | Retention |
|---|---|---|---|
| Name, phone number, nationality, national ID or passport number | Entered by the Company at engagement | Worker identification, invitation, payroll | While the profile exists; a copy in the Company’s payroll records for the periods in section 7 |
| Phone number history | Created when the number changes | One worker has one active number; preventing duplicate profiles | While the profile exists |
| Number verification code, stored as a hash | Sent by message (WhatsApp, then SMS) at sign-in | Confirming that the phone number is yours; passwordless sign-in | The code is valid for 10 minutes; the hash is kept in the security record for 90 days |
| Device: platform (Android or iOS), push notification token, last sign-in time | The app at sign-in | One active session per worker, delivering notifications | Until sign-out or sign-in on another device |
| Schedule: tasks, sites, working hours | Entered by the Company in the planner | Showing the schedule and notifications | As the Company’s payroll records |
| Location during a shift (coordinates, time, accuracy), every 10 minutes | The app, only in the window in section 3 | Checking whether you are inside the site zone, from which hours are calculated | 6 months from the day of the task, then automatic deletion |
| Check-in and check-out: time, location at that moment, reason for an early check-out | Your tap in the app | Record and audit trail | As the Company’s payroll records |
| Check-in photo | Camera, at check-in | Visual confirmation that you are on site | 6 months from the day of the task; see section 4 |
| Profile picture | The first check-in photo | Recognition in the worker list | While the profile exists or until you request removal |
| Task cancellation and reason | Your input in the app | Notifying the coordinator, record | As the Company’s payroll records |
| App language and settings | Your choice | Display in Serbian or English | While the profile exists |
Coordinator and manager (web application)
| Data | Source | Purpose | Retention |
|---|---|---|---|
| Name, work e-mail, password as a hash, role | Entered by the Company’s manager | Sign-in and access rights | While the account exists in the Company |
| Actions in the system: hour corrections, schedule changes, exports, with time and reason | Your work in the application | Audit trail the Company must keep for payroll | As the Company’s payroll records |
What we do not collect. We do not read contacts, calendar, photo library or other apps on the device. We do not use facial recognition. We do not collect location outside the window in section 3. We do not use advertising or behavioural analytics tools. A worker never sees their hourly rate or amounts anywhere in the app.
3. Location: when it is tracked and when it is not
This is the text the app shows before it requests the system location permission, repeated here verbatim:
In detail:
- Before the shift. From 60 minutes before the scheduled start, every 10 minutes, to detect arrival early.
- During the shift. From the scheduled start to the scheduled end, every 10 minutes. Actual hours worked are calculated from this data.
- After the shift. Only if you did not check out yourself: every 30 minutes, until the first check finds you outside the zone, at which point the system records the check-out itself.
- Hard limit. At the latest 16 hours after the scheduled start, tracking stops unconditionally.
- As soon as you check out tracking stops.
- Between shifts, on weekends, on leave and when you have no task location is not collected.
The Company can change the intervals (10 and 30 minutes) and the hard limit (16 hours) in its settings. The values that apply to you are shown in the app on the “Privacy and data” screen.
Tracking runs as a foreground service that the app starts at the moment you check in, while the screen is open. On Android this is visible as a persistent notification during the shift. The app requests “while using the app” location permission, with continued operation in the background solely while a shift is open. It does not request “always” permission.
If you decline location. The app still works in “schedule only” mode: you see your tasks and notifications, but the system cannot calculate hours automatically, so the Company records them manually. You can withdraw consent at any time on the “Privacy and data” screen or in your phone settings.
Location is not used for advertising, profiling or anything other than verifying presence on site and calculating hours.
4. Check-in photo
If the Company enables the mandatory photo, you take a photo with the camera at check-in. The photo serves visual verification by a coordinator. We do not use facial recognition or any automated biometric processing.
Before upload the app strips all metadata from the photo (device model, camera GPS, camera time). The time and location of the check-in are stored separately, from the check-in itself.
Photos are stored encrypted and deleted automatically 6 months from the day of the task. Only the coordinators and managers of your Company can access a photo, through temporary links valid for 5 minutes.
The first check-in photo becomes your profile picture in the app and in the Company’s web application, so that the coordinator can recognise you in the worker list. You can request removal of the profile picture by e-mail to privacy@oour.app; it is then replaced by your initials.
5. Why we process data and on what basis
| Purpose | What it covers | Legal basis |
|---|---|---|
| Working time records and payroll | Schedule, check-ins, hours, corrections, payroll | Performance of your employment or engagement contract with the Company and the Company’s legal duty to keep records of work and wages |
| Verifying presence on site | Location during a shift, check-in photo | Your consent, given in the app before your first check-in and withdrawable at any time |
| Scheduling and notifications | Showing the schedule, push notifications about a task, a change, a cancellation and a reminder before a shift | Performance of the contract |
| Account security | Sign-in by code, one active session, protection against misuse | Legitimate interest of OOUR and the Company in preventing falsified records |
| Audit and dispute resolution | Record of who entered a correction, when, and why | The Company’s legal duty and legitimate interest in reconstructing every calculated hour |
| Operating and maintaining the platform | Technical error logs and protection against attacks | Legitimate interest of OOUR |
Withdrawing consent for location and photos has no consequence for your account. The app then works in “schedule only” mode and the Company records hours manually.
We do not use data for any other purpose. Events such as a check-in outside the zone or a task cancellation are recorded solely as part of the records of the Company you work for and are not used outside that Company.
Technical logs never contain coordinates, phone numbers, names or the text of reasons, only technical identifiers.
6. Who we share data with
The Company that engaged you. Its coordinators see the schedule, location during a shift, check-ins, photos, hours and corrections. Its managers also see the hourly rate and amounts. You can see the list of Companies with access to your data on the “Privacy and data” screen in the app.
Sub-processors. These are companies that technically enable the platform to run. They process data exclusively on our instructions and are contractually bound to the same level of protection this policy describes:
| Who | What | Where |
|---|---|---|
| Amazon Web Services EMEA SARL | Hosting of the database, photos and application | Frankfurt, Germany; backups in Dublin, Ireland |
| Infobip d.o.o. | Sending the sign-in code and invitation by message (WhatsApp, then SMS) | European Union |
| Meta Platforms Ireland Ltd (WhatsApp Business) | Message delivery if you have WhatsApp; sees only your number and the message content | Ireland |
| Google Ireland Ltd (Firebase Cloud Messaging) | Delivery of push notifications to your phone; the notification contains only the site and time | Ireland |
| MapTiler AG | Map tiles in the app; sees only which parts of the map the app loads | Switzerland |
| Functional Software Inc. (Sentry), EU instance | Technical error logs of the web and server applications, without personal data | Frankfurt, Germany |
We do not sell data to anyone. We do not share it with advertisers. We do not use cross-app tracking tools.
Public authorities. We disclose data only where the law requires it, on the basis of a valid request from a competent authority, and we inform the Company.
Transfers outside the EU/EEA. All data is stored in the European Union. Transfers to a sub-processor headquartered outside the EU/EEA (Switzerland, United States) rely on an adequacy decision or on standard contractual clauses recognised by the Serbian Personal Data Protection Act and the GDPR.
7. How long we keep data
| Data | Period | What happens afterwards |
|---|---|---|
| Location during a shift | 6 months (183 days) from the day of the task | Automatic deletion, two independent mechanisms |
| Check-in photo | 6 months (183 days) from the day of the task | Automatic deletion from storage |
| Profile picture | While the profile exists or until you request removal | Replaced by initials |
| Check-ins and check-outs, calculated hours, corrections, audit trail | At least 5 years from the end of the year in which the task was performed, under the Serbian Accounting Act; the Company keeps analytical wage records permanently under the Serbian Act on Records in the Field of Labour | The Company must retain them; OOUR deletes at the end of the period or on the Company’s instruction |
| Sign-in profile | While the profile exists, until your deletion request | See section 9 |
| Push device token | Until sign-out or sign-in on another device | Deleted |
| Sign-in code hash and security records | 90 days | Automatic deletion |
| Technical logs (no personal data) | 90 days | Automatic deletion |
| Database backups | 30 days | Deleted by rotation |
8. Your rights
Under the Serbian Personal Data Protection Act and, where it applies, the GDPR, you have the right:
- to access and obtain a copy of your data, in a readable format;
- to rectification of inaccurate data (name and phone number are corrected by the Company, since it enters them; we forward the request to it);
- to erasure, within the retention periods for payroll records in section 7;
- to restriction of processing and to object, where processing is based on legitimate interest;
- to withdraw consent for location and photos at any time, without affecting the lawfulness of processing before withdrawal;
- to data portability for data you provided yourself;
- to lodge a complaint with the Serbian Commissioner for Information of Public Importance and Personal Data Protection (poverenik.rs), or with the supervisory authority in your EU country of residence.
How to exercise your rights. A copy of your data and withdrawal of location consent are requested in the app, on the “Privacy and data” screen. Everything else, including account deletion and removal of the profile picture, is requested by e-mail to privacy@oour.app. We respond within 30 days of receiving the request at the latest. We deliver the copy of your data in a readable form (PDF and CSV) to the phone number or e-mail address you confirm. For data controlled by the Company, we forward the request to the Company and help it fulfil it within the same period.
9. Account deletion
You do not create the account yourself; the Company creates it by invitation, so the app has no deletion option. You request deletion by e-mail to privacy@oour.app, from the phone number or e-mail address you have used, stating the phone number you sign in with. Before deletion we confirm your identity with a code sent to that number.
Deletion is completed within 30 days of identity confirmation. During that period you can cancel it by replying to our message.
What is deleted: the sign-in profile, phone number history, devices and tokens, location and photos that have not yet expired, profile picture, language and settings.
What is retained and why: check-ins and check-outs, calculated hours, corrections and the audit trail remain with the Company for the periods in section 7, because they are part of the payroll documentation it is legally required to keep. In those records your name, phone number and national ID are replaced by an internal identifier, so the Company keeps a record of hours, not your personal data.
Deactivation of your engagement by the Company is not account deletion: the profile remains so that another Company can engage you with the same phone number. You start deletion yourself.
10. How we protect data
- All communication is encrypted (TLS 1.2 or newer).
- Data in the database, photos and backups are encrypted at rest with a key we manage, rotated yearly.
- Web user passwords and sign-in codes are stored only as hashes, never in readable form.
- Production access follows least privilege, with no direct server access, and every access is logged and kept for one year.
- Photos and exports are accessed through temporary links (5 minutes for photos, 15 minutes for exports).
- Each Company’s data is strictly isolated from other Companies.
- All data is stored in the European Union.
If a data breach occurs that may put your rights at risk, we notify the Commissioner within 72 hours of becoming aware of it, and you and your Company without undue delay.
11. Age
OOUR is intended for workers engaged by a Company and is not intended for persons under 18. We do not knowingly collect data of persons under 18. If we learn that we have, we delete it and inform the Company.
12. Cookies and the website
The website oour.app uses necessary cookies to work and, only with your consent, statistics cookies to see which pages are read. Statistics cookies are off until you turn them on in the banner or in the in the footer. Which cookies we use, who sets them and how long they last is described in the Cookie Policy at oour.app/en/cookies. The web application uses no tracking cookies; it uses only technically necessary browser storage to keep you signed in, which is cleared at sign-out.
13. Changes to this policy
When we change the policy, we update the date at the top of the page. We notify you of material changes in the app at least 15 days before they take effect. Previous versions are available on request at privacy@oour.app.
14. Contact
Bulevar kralja Aleksandra 314, 11000 Belgrade, Republic of Serbia
Registration number 22188933 · Tax ID 115653879
Phone +381 69 1 360 360
privacy@oour.app
Supervisory authority: Commissioner for Information of Public Importance and Personal Data Protection, Bulevar kralja Aleksandra 15, 11120 Belgrade, Serbia, poverenik.rs