Munus+

Notice on the processing of personal data

Courtesy translation — version 5. This text is a faithful translation of the Italian original, which is the only binding version. In the event of any discrepancy, the Italian text prevails. The version number is the same as the Italian one: a translation is not a new version, it is the same version in another language.

W.F.B. Srl — Via Romolo Gessi 13, 20146 Milan (MI), Italy — VAT no. 04724770237

This notice concerns two categories of people. Read the part that applies to you: they are separate because the data processed and the reasons why we process them are different.


PART A — Employees and collaborators


In brief (first level)

Who: W.F.B. Srl, your employer, is the data controller. What: the data needed to manage the employment relationship: personal details, documents, shifts and hours, communications with the office. Why: to perform the employment contract and comply with legal obligations — we do not ask you for consent for these activities, because they are required. Where: all data remain on servers within the European Union. Your rights: access, rectification, erasure and the other rights provided by the GDPR; you can exercise them by writing to the contacts indicated below and you will receive a reply within 30 days.

The full text below explains every point.


1. Who processes your data?

The data controller is W.F.B. Srl, Via Romolo Gessi 13, 20146 Milan (MI), Italy, VAT no. IT04724770237, contact email: privacy@wfbservice.it.

W.F.B. Srl uses the MUNUS+ software platform to manage staff, shifts and documents. The platform is the tool; the decisions about which data to process and why are taken by W.F.B. Srl as your employer.

W.F.B. Srl has not appointed a Data Protection Officer (DPO): for a company of this size and with these processing activities the appointment is not mandatory. For any matter concerning your data you can write to the address indicated above.

2. What data do we process, why, and what happens if you do not provide it?

Data categoryWhat it is forProvisionLegal basis
Personal details: first and last name, sex, date and place of birth, tax code, staff numberTo identify you uniquely and to comply with tax, social security and insurance obligationsRequired: without this data the employment relationship cannot be managedContract (art. 6.1.b) and legal obligations (art. 6.1.c)
Contact details: mobile phone, email, residence and domicileWork communications (shifts, expiring documents) and administrative fulfilmentsRequired for mandatory communications; the email also serves as the app usernameContract (art. 6.1.b)
Documents: copy of the identity document and professional certificates (e.g. food hygiene, fire safety) with expiry datesTo verify identity and eligibility for job roles: an expired mandatory certificate makes the shifts of that role unassignable, for your protection and that of othersRequired for the roles that call for them; the platform warns you before expiryLegal obligations on employment and safety (art. 6.1.c); contract (art. 6.1.b)
Photograph of the faceThe identification badge and your recognisability at workplaces where it is required (e.g. site regulations)Required where the work context imposes visual identification. The photo is never shown to W.F.B. Srl's clientsSafety obligations (art. 6.1.c) and contract (art. 6.1.b). Any further use of the photo, if ever proposed, will require your separate and revocable consent
Shifts and hours: assigned and confirmed shifts, planned and actual hours, absences (leave, time off, sickness, injury)To organise work, count hours for pay purposes and for invoicing services to clientsDerives from the employment relationshipContract (art. 6.1.b); legitimate organisational interest (art. 6.1.f)
Messages: the chat between you and the office inside the appOperational coordination and the ability to reconstruct the arrangements made (who said what, when)Use of the chat is the working tool for operational communicationsLegitimate interest (art. 6.1.f). We do not use the chat to assess your performance
Account data: login email, password (stored only in non-reversible encrypted form), any second authentication factor, date of last login, notification subscriptionsTo let you log in securely and protect your accountNecessary to use the appContract (art. 6.1.b); legitimate interest in security (art. 6.1.f)
Operations log: who created or modified data and when, with the reason for significant operationsSecurity, data correctness and the ability to reconstruct events in the event of disputes or incidentsGenerated automatically by the systemLegitimate interest (art. 6.1.f). It is not a tool for monitoring work performance

Data not necessary to managing the relationship is not requested from you. If in future the platform were to collect optional data (e.g. bank details for new services), you will receive an update to this notice before activation.

3. Who sees your data inside the platform?

Access is profiled by role: only authorised W.F.B. Srl staff (administration and operators) see your data, and operators only for the sites within their remit.

W.F.B. Srl's clients where you work, as a rule, do not see your name: they see that a shift is covered, not by whom. The name appears only to clients expressly enabled by W.F.B. Srl and only for confirmed shifts. They never see your photo, your contact details, your documents or your overall hours; the summaries they receive never contain names.

4. To whom is the data disclosed? (technical suppliers)

To run the platform, W.F.B. Srl relies on suppliers that process data on its behalf, on the basis of contracts compliant with art. 28 GDPR:

CompanyFunctionData involvedCountry
Hetzner Online GmbHservers, database and document storageall platform dataGermany (EU)
Backblaze Inc.external backup copybackup copies encrypted before sending: the supplier cannot read themNetherlands (EU)
Brevo (Sendinblue SAS)email sending (invitations, password recovery, alerts)email address and content of the communicationsFrance (EU)

All suppliers process the data within the European Union.

Push notifications: if you enable notifications on your device, delivery goes through the service of your operating system or browser (Apple, Google or Mozilla, depending on the device you choose). These services receive an identification code of the device and an encrypted message they cannot read (Web Push standard). For Google, the transmission is covered by the EU-US adequacy decision (Data Privacy Framework). You can disable notifications at any time without consequences for the employment relationship.

The data may also be disclosed, where the law so provides, to labour consultants, social security and insurance bodies and public authorities, which act as independent controllers. No data is transferred to third parties for marketing, profiling or the training of artificial intelligence systems.

5. How long do we keep the data?

DataRetention
Personal details and employment relationship data (shifts, hours, absences)duration of the relationship + 10 years (civil and accounting time limits)
Copy of the identity documentduration of the relationship + 5 years
Professional certificatesduration of the relationship + 5 years (the renewal history documents eligibility over time)
Photographremoved on termination of the relationship within 30 days, save for specific obligations
Chat messagesfor the entire duration of the employment relationship. ⚠️ The chat is append-only by design: messages cannot be edited or deleted — not even by their author, the office included — because they serve to reconstruct the arrangements made about a shift. On termination of the relationship they are removed together with the other data not subject to retention obligations
Operations log5 years, for security and accountability
Deactivated accountthe minimum identifying data remain associated with the historical operations for the integrity of the log; the rest is removed or anonymised after 10 years
Closed shifts10 years: closed hours become the basis for pay and for invoicing the client, so they follow accounting time limits and cannot be erased on request
Backup copiesautomatic rotation: copies expire within 30 days

On expiry, the data is deleted or anonymised. Deletion propagates to the backup copies with their natural rotation (maximum 30 days).

6. What are your rights?

You have the right to obtain access to your data, the rectification of inaccurate data (many you can correct directly from your record in the app), erasure in the cases provided by art. 17 GDPR, the restriction of processing, the portability of the data you have provided, and to object to processing based on legitimate interest.

To exercise them write to privacy@wfbservice.it: you will receive a reply within 30 days. Exercising your rights cannot entail any negative consequence for the employment relationship.

If you believe that a processing operation infringes the law, you may lodge a complaint with the Italian Data Protection Authority (www.garanteprivacy.it).

Transparency note: some data cannot be erased as long as the law requires it to be kept (e.g. data needed for tax and social security fulfilments). In that case you will receive a reasoned reply indicating what has been erased and what has not, and why.

7. How do we protect your data?

We adopt technical and organisational measures appropriate to the risk, as required by art. 32 GDPR: always encrypted connections; passwords stored only in non-reversible encrypted form and mandatory two-factor authentication for W.F.B. Srl staff; access profiled by role and by site; each company's data isolated from the others; automatic block after a few failed login attempts; daily backups, verified and also kept at an external supplier in encrypted form; logging of significant operations; continuous system monitoring.

The complete and up-to-date list of measures is collected in a technical document that you can request at any time by writing to privacy@wfbservice.it.

No IT system can be said to be 100% secure, and the law does not demand it: the obligation is to adopt measures appropriate to the risk and to be able to demonstrate them, not to guarantee an absolute result. If, despite the measures, a breach of your data were to occur:

8. Updates to this notice

This notice is versioned: every change produces a new version, with a date, and the platform asks you to take note of it at the first subsequent login. Previous versions remain recorded: you can always know which text you saw and when, from the "Consents" section of your profile.



PART B — Contact persons of client companies


In brief (first level)

Who: W.F.B. Srl is the controller of the data of contact persons and portal users. What: professional contact details and portal account data. Why: to manage the service relationship between W.F.B. Srl and the company you work for. Where: all data remain on servers within the European Union. Rights: access, rectification, erasure and the other GDPR rights, with a reply within 30 days.


1. Who processes your data?

The controller is W.F.B. Srl, Via Romolo Gessi 13, 20146 Milan (MI), Italy, VAT no. IT04724770237, contact email: privacy@wfbservice.it.

W.F.B. Srl uses the MUNUS+ platform to manage service requests, shifts and reporting towards its clients. You access the portal as the contact person of the client company you work for.

2. What data do we process and why?

CategoryWhat it is forLegal basis
Professional contact details: first name, last name, company role, email, telephoneTo maintain operational and commercial relations with the company you represent (service requests, statements, communications)Performance of the contract with the client company (art. 6.1.b) and legitimate interest in ordinary commercial relations (art. 6.1.f)
Portal account data: login email, password (stored only in non-reversible encrypted form), any second factor, date of last loginTo let you access the portal securelyContract (art. 6.1.b); legitimate interest in security (art. 6.1.f)
Portal activity: service requests created, statement confirmations (recording who confirms and when), acknowledgements of legal documentsTo deliver the service and document approvals with evidential valueContract (art. 6.1.b)

Providing contact details is necessary in order to operate on the portal: without them, the company you represent can still receive the services through traditional channels.

We do not process your data for marketing or profiling.

3. What you see, and what we see

The portal shows only the data of the company you work for: its requests, its sites, its statements. Out of confidentiality towards the staff, as a rule the names of the personnel employed on the shifts are not visible and the summaries never contain names.

4. To whom is the data disclosed?

The same technical suppliers of the platform, bound by contracts under art. 28 GDPR:

CompanyFunctionCountry
Hetzner Online GmbHservers, database, storageGermany (EU)
Backblaze Inc.backup copies encrypted before sendingNetherlands (EU)
Brevo (Sendinblue SAS)email sending (portal invitations, statements, alerts)France (EU)

All suppliers process the data within the European Union. For push notifications, what is described in the general notice applies: delivery through your device's service (Apple/Google/Mozilla) with encrypted content that the service cannot read.

5. How long do we keep the data?

DataRetention
Contact detailsduration of the relationship with the client company + 2 years
Portal accountuntil access is revoked by W.F.B. Srl or by the company + 2 years
Confirmed statements and records of approvals10 years (accounting and tax relevance)
Backup copiesautomatic rotation within 30 days

6. What are your rights?

Access, rectification, erasure, restriction, portability, objection to processing based on legitimate interest. Write to privacy@wfbservice.it: reply within 30 days. You may lodge a complaint with the Italian Data Protection Authority (www.garanteprivacy.it).

If you are no longer the contact person of the client company, let us know: we will deactivate the account and keep only what is necessary to document the operations already carried out.

7. Security and updates

The same measures described in Part A apply: encrypted connections, profiled access, mandatory two-factor authentication for W.F.B. Srl staff, isolation of data by company, encrypted backups at an external supplier, logging of operations. The complete list is collected in a technical document that you can request by writing to privacy@wfbservice.it.

No IT system can be said to be 100% secure: the law imposes measures appropriate to the risk and the ability to demonstrate them, not an absolute result. In the event of a data breach we notify the Authority within 72 hours in the cases provided (art. 33 GDPR) and we communicate it directly to the data subjects when it entails a high risk to their rights (art. 34 GDPR).

This notice is versioned: every change produces a new version and the portal asks you to take note of it at the first subsequent login.


Document updated on 30 August 2026.