Back to Staatus

CHAIDLA OÜ · Staatus

Privacy policy

Last updated: 29 September 2026

How CHAIDLA OÜ handles personal data when you visit Staatus or use its business automation services.

Who is responsible

Staatus is operated by CHAIDLA OÜ. Contact us at hello@olek.app about this policy or your personal data. We are responsible for information used to operate our website, customer accounts, billing and service security. Your employer or workspace business decides why employee information is used in its workspace; Staatus processes that information to provide the service on its instructions.

Information we use

Account and contact details include names, email addresses, password hashes, account roles and correspondence. Workspace information can include employee contact details, locations, working-hour limits, availability, leave, published and draft shifts, attendance records and corrections. We also process session identifiers, technical request and security logs, subscription status and payment references. Information comes from you, your workspace administrators, service activity and integrations you choose to connect.

Why we use it

We use this information to provide accounts, scheduling, attendance, notifications, support and billing; protect the service; and meet legal obligations. For our own processing, the bases are performance of our customer contract, legitimate interests in operating and securing the service, and applicable legal obligations. Where consent is required for an optional integration, you may withdraw it by disconnecting that integration. Your employer determines the legal basis for its employee records. Required account and workspace information is needed to provide the corresponding service.

Google sign-in and Calendar

If you choose Google sign-in, Staatus receives your Google account identifier and email address to identify your account. If a workspace owner connects Google Calendar, Staatus also stores the connected identity, encrypted authorization credentials, calendar identifiers and synchronization records. Offline access allows published schedules to synchronize in the background. Staatus creates location and private employee work calendars and creates, updates or removes shift events as schedules change. Events can contain employee names, shift times, roles and locations. Employees choose whether to share their private work calendar or access their locations’ team calendars using their Google email address. The connected business Google account owns these calendars and can access them.

Google permissions and Limited Use

Calendar access requests permission to create and manage calendars created by Staatus and permission to manage calendar sharing. The sharing permission is broader than Staatus-created calendars; Staatus uses it for the location calendars managed by the integration. Google data is used to provide the connected features, not for advertising, sale, credit decisions or training general-purpose AI models. Staatus complies with the Google API Services User Data Policy, including its Limited Use requirements. Human access to Google data is limited to your explicit consent, necessary security investigation, legal requirements or other uses permitted by that policy.

Disconnecting Google

Disconnect Calendar in workspace Settings to remove locally stored connection credentials and stop future work using that connection. Requests already in progress may finish. Disconnecting does not delete calendars or events already in Google and does not revoke your Google-wide authorization, which may also serve another workspace. You can remove Staatus access in your Google Account connections settings and delete calendars or events in Google Calendar. Contact us to request deletion of remaining personal information, subject to applicable retention requirements.

Who receives information

Authorized people in your workspace can access information according to their role and location permissions. Hosting, database, backup, email and security service providers process information needed to run Staatus. Stripe handles checkout, payment details and subscription processing; Staatus receives billing references and status rather than storing your full card number. Google receives data for enabled Google features. Telegram receives notifications only when that integration is used. We may disclose information when legally required or necessary to protect rights and service security. We do not sell personal data.

Storage, security and international processing

Access controls, tenant isolation, password hashing and encryption of Google connection credentials help protect your information. Service providers may process information outside your country, including outside the European Economic Area. Where required, transfers must rely on an applicable adequacy decision or appropriate safeguards, such as standard contractual clauses. Contact us for information about the providers and safeguards relevant to your workspace.

How long information is kept

Workspace records follow the business’s configured retention period and applicable employment or recordkeeping requirements. On employee erasure, personal fields are anonymized while historical records may remain. Account, billing, correspondence and security records are kept for as long as needed to provide the service, meet legal obligations, resolve disputes and protect the service. Backup copies expire through backup rotation and may remain after removal from active systems. Ask your workspace administrator or contact us about the retention period applicable to your information.

Cookies and choices

Staatus uses cookies for sign-in sessions, security and preferences such as language and theme. These support the service; we do not use personal data for advertising or profiling. You can control cookies in your browser, but blocking essential cookies can prevent sign-in. Optional Calendar and notification integrations can be left disconnected.

Your rights

Depending on the applicable law, you may request access, correction, erasure, restriction or a portable copy of your information, and object to processing based on legitimate interests. You can withdraw consent without affecting earlier lawful processing. For employee records, contact your employer or workspace administrator first; we can help direct your request. For information controlled by CHAIDLA OÜ, email hello@olek.app. We may need to verify your identity. You may complain to your local supervisory authority, including the Estonian Data Protection Inspectorate (Andmekaitse Inspektsioon).

Changes to this policy

We update this page when our practices change and show the revision date above. Material changes will be communicated through the service or another appropriate channel.