Política de privacidad

Versión: 1.0Fecha de vigencia: 2026-04-05

Este documento se publica en inglés. El texto en inglés es la versión vinculante.

PRIVACY POLICY FOR WIZSCHEDULER Effective Date: April 5, 2026 1. INTRODUCTION WizScheduler ("we", "our", "us") is a multi-tenant employee scheduling platform. This Privacy Policy explains how we collect, use, disclose, and safeguard your personal data when you use our service. We are committed to protecting your privacy in compliance with the General Data Protection Regulation (GDPR), the California Consumer Privacy Act (CCPA), and other applicable data protection laws. 2. DATA WE COLLECT We collect the following categories of personal data: - Account Information: full name, email address, hashed password. - Employee Profile Data: full name, email, assigned roles, skill levels, work location assignments. - Availability Data: weekly availability windows (day, start time, end time). - Work Preference Data: interpersonal affinity scores between employees (used to optimize team composition). - Shift & Schedule Data: assigned shifts, schedule history, role-based working minutes. - Technical Data: IP addresses (recorded with consent actions), JWT authentication tokens (not stored server-side beyond session). - Usage Data: API request logs for error monitoring and service improvement. 3. HOW WE USE YOUR DATA We process your personal data for the following purposes: - Schedule Generation: Your availability, roles, skill levels, and affinity data are sent to Anthropic's Claude AI to generate optimized weekly shift schedules. Data is transmitted via encrypted API calls and is not retained by Anthropic beyond the API request lifecycle. - Account Management: To create and maintain your user account, authenticate sessions via JWT, and manage multi-tenant company access. - Communication: To send transactional emails (e.g., welcome emails, employee invitations) via our email service provider, Resend. - Data Import/Export: To facilitate integration with 7shifts for importing and exporting employee and schedule data at your manager's request. - Service Improvement: To monitor errors, analyze usage patterns, and improve scheduling algorithms. 4. LEGAL BASIS FOR PROCESSING (GDPR) We process your data based on: - Consent: You provide explicit consent during registration for data processing and AI-powered scheduling. - Contractual Necessity: Processing is necessary to provide the scheduling service you have requested. - Legitimate Interest: For security, fraud prevention, and service improvement. 5. DATA SHARING AND THIRD-PARTY PROCESSORS We share your data with the following third-party processors: - Anthropic (Claude AI): Employee availability, roles, and preferences are sent for AI-powered schedule generation. Anthropic processes data per their data processing terms and does not use API inputs for model training. - 7shifts: Employee and schedule data may be imported from or exported to 7shifts at your organization's discretion. - Resend: Email addresses and names are shared to deliver transactional emails. - Cloud Infrastructure Provider: All data is hosted on secured cloud infrastructure with encryption at rest and in transit. 6. DATA RETENTION We retain your personal data for as long as your account is active or as needed to provide services. Upon account deletion (right to erasure), all personal data is permanently deleted, including employee profiles, availability, affinities, shift history, and consent records. 7. YOUR RIGHTS Under GDPR and applicable laws, you have the right to: - Access: Request a copy of all personal data we hold about you (GET /api/v1/gdpr/export). - Rectification: Update or correct your personal data. - Erasure: Request deletion of your account and all associated data (DELETE /api/v1/gdpr/delete-account). - Data Portability: Receive your data in a structured, machine-readable JSON format. - Withdraw Consent: You may withdraw consent at any time, though this may limit your ability to use the service. - Restriction of Processing: Request that we limit how we use your data. - Object: Object to processing based on legitimate interests. 8. DATA SECURITY We implement appropriate technical and organizational measures to protect your data, including: - Passwords are hashed using bcrypt and never stored in plaintext. - Authentication via signed JWT tokens with configurable expiration. - Multi-tenant data isolation ensures company data is strictly separated. - All API communications are encrypted via TLS. - Security headers (X-Content-Type-Options, X-Frame-Options, HSTS) are enforced. 9. INTERNATIONAL DATA TRANSFERS Your data may be transferred to and processed in countries outside your jurisdiction. We ensure appropriate safeguards are in place, including Standard Contractual Clauses where required. 10. CHILDREN'S PRIVACY Our service is not directed to individuals under 16. We do not knowingly collect personal data from children. 11. CHANGES TO THIS POLICY We may update this Privacy Policy from time to time. We will notify you of material changes via email or in-app notification. Continued use of the service after changes constitutes acceptance. 12. CONTACT For privacy inquiries, data subject requests, or complaints, contact us at privacy@wizscheduler.com.