1. Who We Are and Scope of This Policy
Formation HR B.V. (“Provider”, “we”, “us”, “our”), registered address Bosruiter 54, 5658CM Eindhoven, the Netherlands, Chamber of Commerce (KVK) No. 99067978, operates Construct, a software-as-a-service HR modelling, workforce analytics, and decision-support platform (the “Platform”), currently made available to customers on an individually contracted pilot or early-access basis.
This Privacy Policy explains how we collect, use, share, and protect personal data in connection with the Platform, our website, and our “Sign in with Google” authentication integration. It applies to:
-
Authorised Users — individuals who access the Platform on behalf of a business customer (“Customer”);
-
Individuals whose data is contained within Customer Data uploaded to the Platform by a Customer (“Workforce Data Subjects”);
-
Visitors to our website and individuals who contact us directly.
If you are a Workforce Data Subject: your employer or the organisation that uses Construct (the “Customer”) is the Data Controller of your personal data processed through the Platform. Please contact your employer's HR or data protection team for information about how and why your data is processed. We process such data strictly on the Customer's instructions, under a Data Processing Agreement (“DPA”) with the Customer.
2. Contact and Data Protection Officer
Data Controller (for Platform account administration, authentication, and our own direct relationships):
Formation HR B.V., Bosruiter 54, 5658CM Eindhoven, the Netherlands. Email: dpo@formation.hr.
Where required by Article 37 GDPR, we will appoint a Data Protection Officer; until then, the above contact functions as our designated privacy contact for all data protection enquiries.
3. Our Role: Controller and Processor
3.1 As Processor. For Customer Data uploaded to the Platform by a Customer (including any personal data of that Customer's workforce), we act as a Data Processor, processing such data only on the Customer's documented instructions under the applicable DPA. We are not the Data Controller of that data.
3.2 As independent Controller. For account and authentication data (Section 5), website data, billing contacts, and other data we process for our own business purposes (security, service communications, legal compliance), we act as an independent Data Controller, and this Policy describes that processing directly.
4. Legal Bases for Processing (Where We Act as Controller)
| Processing activity | Legal basis (Art. 6 GDPR) |
|---|---|
| Authenticating Authorised Users via Google Sign-In and managing accounts | (b) performance of a contract; (f) legitimate interests — securing access to the Platform |
| Providing and administering the Platform to Customers | (b) performance of a contract |
| Security monitoring, fraud and abuse prevention | (f) legitimate interests |
| Compliance with legal obligations | (c) legal obligation |
| Responding to enquiries and support requests | (b) contract / (f) legitimate interests |
5. Google Sign-In — Authentication Data
5.1 What we collect. When an Authorised User signs in to Construct using “Sign in with Google”, we receive, via Google OAuth 2.0, the following basic profile information: the user's name, email address, Google account identifier, and profile picture (openid, .../auth/userinfo.email, .../auth/userinfo.profile scopes only).
5.2 What we do not collect. We do not request or receive Gmail, Google Calendar, Google Drive, Google Contacts, Google Directory, Google Admin Reports, or any other Google Workspace content or metadata through this integration.
5.3 Purpose. We use this information solely to create and authenticate the Authorised User's Construct account, maintain login sessions, and apply access controls. We do not use it for advertising, do not sell it, and do not use it to train AI or machine-learning models.
5.4 Google API Services User Data Policy. Our use and transfer of information received from Google APIs complies with the Google API Services User Data Policy, including the Limited Use requirements.
5.5 Our role. We act as an independent Data Controller with respect to this authentication data — not as a Processor on behalf of the Customer. This data is kept separate from Customer Data (see Section 6).
5.6 Retention. Authentication data is retained for as long as the Authorised User's account remains active, plus a limited period thereafter for security and audit purposes, and is deleted within seven (7) days of the Authorised User or Customer revoking Construct's Google access.
5.7 Revocation. You may revoke Construct's access to your Google account at any time at https://myaccount.google.com/permissions, or via the Platform's account settings.
6. Customer Data (Processed as Data Processor)
Customer Data may include workforce or HR-related information that a Customer uploads to or generates within the Platform, such as employee identifiers, role and organisational data, compensation-related data, and analytical outputs. The specific categories, purposes, and retention of Customer Data are determined by the Customer and set out in the DPA between the Provider and that Customer. We process Customer Data strictly on the Customer's documented instructions and do not use it for our own purposes, including AI model training, without the Customer's prior written consent.
6.1 Special category data. We do not actively seek to collect special category data (Article 9 GDPR). Where such data may be present in Customer-provided data, the Customer is responsible for ensuring a valid Article 9(2) basis and appropriate safeguards, as set out in the DPA.
7. AI Processing — Bring Your Own Model (“BYOM”)
7.1 Standard architecture. Construct's standard architecture is Bring-Your-Own-Model: each Customer connects its own contracted AI model or API to the Platform. Where AI Processing occurs, Customer Data (or the relevant excerpt) is transmitted to that Connected AI Model, which is selected, licensed, and controlled by the Customer, not by us. We act as a technical conduit for that transmission and do not operate, host, or control the Connected AI Model.
7.2 Pilot exception. In specific pilot engagements, we may exceptionally make available our own integrated AI service. Where this applies, the specific data-handling and anonymisation controls for that arrangement (for example, exclusion of identifiable personal data from transmission to the AI provider) are set out in the applicable DPA for that engagement.
7.3 No training on Customer Data. We do not use Customer Data to train, fine-tune, or improve generalised or commercially available AI or machine-learning models, whether ours or a third party's, without the Customer's prior written consent.
8. AI Outputs and Automated Decision-Making
8.1 Decision-support only. The Platform generates Outputs — insights, scores, predictions, and recommendations — for review by the Customer's administrators or HR professionals. The Platform does not itself make decisions with legal or similarly significant effects on individuals, and the Customer is contractually required to apply meaningful human review before acting on Outputs (see our Terms of Service, Section 7).
8.2 Article 22 GDPR. Where a Customer uses Outputs in a way that may constitute profiling or automated decision-making under Article 22 GDPR, the Customer, as Data Controller, is responsible for ensuring compliance with Article 22, including providing required disclosures and review rights to affected individuals.
8.3 EU AI Act. Where Platform functionality is used in a context in scope of the EU AI Act, the Customer is responsible for determining the applicable classification of its specific use case (including any Annex III high-risk employment use) and for meeting its resulting obligations as deployer (and, where applicable, provider). We support Customers' compliance by providing available technical documentation and information about the Platform's logging and human-oversight design on reasonable request. We do not permit use of the Platform for prohibited AI practices under Article 5 of the EU AI Act, including workplace emotion recognition (other than as narrowly permitted by law), social scoring, or covert disproportionate employee surveillance.
9. Categories of Personal Data We Process as Controller
| Category | Examples | Purpose |
|---|---|---|
| Account & authentication | Name, email address, Google account ID, profile picture | Account creation, login, access control |
| Usage data | Login timestamps, features accessed, session data | Security, audit, service operation |
| Communications | Support requests, emails, feedback | Support and service improvement |
| Technical data | IP address, browser/device type, access logs, error logs | Security, fraud prevention, debugging |
10. How We Share Personal Data
We do not sell personal data. We share it only as follows:
-
With the relevant Customer, where the individual is an Authorised User acting on that Customer's behalf, or where Customer Data reveals information about a Workforce Data Subject;
-
With sub-processors engaged to help us operate the Platform (Section 11);
-
With law enforcement, courts, or regulators where required by applicable law;
-
In connection with a merger, acquisition, or sale of assets, subject to equivalent data-protection obligations and prior notice where required.
11. Sub-processors
We engage a limited number of sub-processors, listed at formation.hr/sub-processors and notified to Customers in accordance with the DPA. As of the effective date of this Policy, the following sub-processors are used for hosting and infrastructure:
| Sub-processor | Purpose | Location | Transfer safeguard |
|---|---|---|---|
| Upcloud | Database hosting, compute, object storage, backups, network infrastructure | EU/EEA | EEA — no transfer mechanism required |
| Functional Software, Inc. (Sentry.io) | Application performance monitoring and error tracking (pseudonymised technical data only) | USA | EU Standard Contractual Clauses (Module 2) |
A Connected AI Model that a Customer connects under the BYOM architecture (Section 7) is contracted directly by the Customer and is not our sub-processor.
11.1 Google. Google LLC processes authentication tokens and identity data as part of the Sign-In flow described in Section 5. For that specific processing, we act as an independent Controller and Google LLC processes such data under its own privacy policy and terms; Google is not our sub-processor for Customer Data.
12. International Data Transfers
The Provider is established in the Netherlands. Where personal data we control is transferred outside the European Economic Area (for example, to Sentry.io in the United States, per Section 11), such transfers are made under appropriate safeguards, including EU Standard Contractual Clauses adopted by the European Commission, supplemented by a Transfer Impact Assessment where required. Transfers of Customer Data are addressed in the applicable DPA.
13. Data Retention
| Data category | Retention period |
|---|---|
| Authentication data (Google Sign-In) | Duration of active account; deleted within 7 days of access revocation |
| Customer Data (processed as Processor) | As instructed by the Customer; per the applicable DPA, generally deleted within 30 days of engagement termination or Customer request |
| Account and usage data | Duration of the Customer relationship, plus a limited period thereafter for legal and security purposes |
| Security and audit logs | Up to 12 months (rolling) |
| Support communications | Up to 3 years from last interaction |
14. Your Rights
Where we act as Data Controller (Authorised Users' account/authentication data, website visitors, direct contacts), you may exercise the following rights under the GDPR by emailing dpo@formation.hr: access (Art. 15); rectification (Art. 16); erasure (Art. 17); restriction of processing (Art. 18); data portability (Art. 20); and objection to processing based on legitimate interests (Art. 21). We will respond within one month of a valid request and do not charge a fee unless a request is manifestly unfounded or excessive.
Workforce Data Subjects: if your employer uses Construct to process your data, please direct rights requests to your employer in the first instance, as they are the Data Controller of that data. We will assist the Customer in responding to valid requests as required by the DPA.
You also have the right to lodge a complaint with a supervisory authority. In the Netherlands, the competent authority is the Autoriteit Persoonsgegevens (www.autoriteitpersoonsgegevens.nl). You may also find your national authority via https://edpb.europa.eu/about-edpb/about-edpb/members_en.
15. Security
We implement appropriate technical and organisational measures to protect personal data, including: encryption in transit and at rest; role-based access controls and multi-factor authentication; logical isolation of Customer environments hosted on shared infrastructure; audit logging; vulnerability management and periodic security testing; and an incident-response process, including breach notification in accordance with Articles 33-34 GDPR. Full details applicable to a given engagement are set out in the DPA.
16. Cookies and Similar Technologies
The Platform uses only strictly necessary cookies for authentication (including maintaining your Google Sign-In session) and core platform functionality. We do not use third-party advertising cookies, tracking pixels, or cross-site tracking technologies.
17. Children's Data
The Platform is designed exclusively for business use by individuals aged 18 and over. We do not knowingly collect personal data of individuals under 18. If we become aware that such data has been submitted, we will delete it promptly.
18. Changes to This Policy
We may update this Privacy Policy from time to time. Where changes are material, we will provide at least thirty (30) days' advance notice via email or Platform notification. The “Effective Date” above reflects the date of the most recent revision.
19. Contact
Formation HR B.V., Bosruiter 54, 5658CM Eindhoven, the Netherlands. Email: dpo@formation.hr. We aim to acknowledge privacy requests within 5 business days and respond in full within one month.
This Privacy Policy is provided in compliance with Regulation (EU) 2016/679 (GDPR) and applicable Netherlands implementing legislation (UAVG), and is intended to serve as the publicly accessible privacy policy required for Google API/OAuth verification of Construct's “Sign in with Google” integration.