Privacy Policy & GDPR
Last Updated: January 18, 2025
Central Station (CS) is an ERP Suite for employment agencies, developed by bayata. We respect your privacy and are committed to protecting your personal data in accordance with the General Data Protection Regulation (GDPR).
Data Controller
bayata is the data controller for the processing of your personal data. For questions about this privacy policy, please contact:
Herengracht 320, 1016 CE Amsterdam, Netherlands
Data Collected
We collect and process the following categories of personal data:
- Identification data: name, email address, username, BSN number (for Dutch workers)
- Employment data: contract information, skills, availability, work history
- Financial data: salary information, payslips, billing information
- Technical data: IP address, browser type, device information, user activity
- Communication data: correspondence, notes, documents
Purpose of Processing
Your personal data is processed for the following purposes:
- Provision of employment agency services and workforce management
- Processing of payroll administration and invoicing
- Compliance with legal obligations (CAO, tax legislation)
- Improvement of our services and user experience
- Communication with users and customers
- Security and fraud prevention
Legal Basis
The processing of your data is based on:
- Performance of a contract (Article 6(1)(b) GDPR)
- Compliance with a legal obligation (Article 6(1)(c) GDPR)
- Legitimate interest (Article 6(1)(f) GDPR) for service improvement and security
- Consent (Article 6(1)(a) GDPR) where applicable
Data Retention
We retain your personal data no longer than necessary for the purposes for which they were collected, or as required by law. Employment data is retained in accordance with Dutch labor and tax legislation (typically 7 years after termination of employment relationship).
Your Rights
Under the GDPR, you have the following rights:
- Right of access: you can request what data we process about you
- Right to rectification: you can request correction of inaccurate data
- Right to erasure: you can request deletion of your data
- Right to restriction of processing: you can request restriction of processing
- Right to data portability: you can receive your data in a structured format
- Right to object: you can object to processing based on legitimate interest
- Right to withdraw consent: where processing is based on consent
To exercise your rights, please contact privacy@bayata.nl
Data Security
We implement appropriate technical and organizational measures to protect your personal data against unauthorized access, loss, destruction, or alteration, including:
- Encryption of data in transit and at rest
- Access controls and authentication
- Regular security audits and updates
- Limited access to data based on role
- Backup and disaster recovery procedures
Data Sharing
We only share your data with:
- Authorized users within your organization
- Service providers working on our behalf (under strict contractual obligations)
- Legal authorities when legally required
- We do not share your data with third parties for marketing purposes
International Transfers
Your data is primarily processed within the European Economic Area (EEA). If data is transferred outside the EEA, we ensure appropriate safeguards in accordance with GDPR.
Cookies and Tracking
We use essential cookies for application functionality. We do not use tracking cookies or analytics without your consent.
Complaints
If you believe we are not processing your data correctly, you have the right to lodge a complaint with the Dutch Data Protection Authority:
Changes to this Policy
We may update this privacy policy from time to time. We will notify you of significant changes via the application or by email.
Contact
For questions about this privacy policy or your data, please contact: