LunaHR Privacy Policy

LunaHR – moonsoft HR Solutions GmbH
Status: August 2026 · Version 1.0

This Privacy Policy explains how personal data is processed when you use LunaHR (the "App"), the mobile HR application provided by moonsoft HR Solutions GmbH ("moonsoft", "we", "us"). It supplements the LunaHR Terms of Use and applies specifically to the App. Processing on our website is described separately at www.moonsoft.at/en/privacypolicy.

We process personal data exclusively in accordance with the EU General Data Protection Regulation (GDPR) and the Austrian Data Protection Act (DSG).

1. Scope and audience

LunaHR is a business (B2B) application. It is made available to the employees and authorised users of companies that have a valid contract with moonsoft. The App enables mobile handling of HR processes such as time tracking, absence management, access to the digital personnel file, travel and expense reporting, and workflow approvals.

The App is not directed at children and is not intended for private consumers or use outside an employment relationship.

2. Controller and roles (who is responsible)

Because the App is used in a B2B context, responsibility is split as follows:

  • Your employer is the controller. For the HR data processed through the App (e.g. your master data, working times, absences, documents, travel and expense data), your employer – the company that gave you access to the App – is the data controller within the meaning of Art. 4(7) GDPR. moonsoft acts as a processor on your employer's behalf pursuant to Art. 28 GDPR, on the basis of a Data Processing Agreement (DPA) that forms part of the contract with your employer. Requests concerning this HR data (access, correction, deletion, etc.) should be directed to your employer.
  • moonsoft is the controller for limited technical data. For a small set of data required to operate, secure, and stabilise the App – in particular crash diagnostics, technical device and log information, and push-notification delivery – moonsoft is the controller. This Policy describes that processing directly.

3. Provider and contact details

Companymoonsoft HR Solutions GmbH
AddressGuglgasse 15–17, BT 3B, 1st floor, A-1110 Vienna, Austria
Commercial registerFN 440640a, Commercial Court Vienna
VAT IDATU69911848
Emailinfo@moonsoft.at
Phone+43 676 / 711 99 25
Websitewww.moonsoft.at

For any privacy-related question about the App, please contact us at info@moonsoft.at.

4. What data we process, why, and on what legal basis

4.1 HR and business data (processed on behalf of your employer)

Depending on the modules your employer has enabled, the following categories may be processed:

  • Master data – name, personnel number, contact details, organisational assignment.
  • Time and attendance data – clock-in/clock-out times, working hours, absences, leave and sick-leave requests (including supporting documents you upload).
  • Personnel file documents – documents and records made available to you in the digital personnel file.
  • Travel and expense data – travel requests, routes and distances, receipts, mileage/odometer photos, expense settlements.
  • Workflow data – requests, approvals, incoming invoices, and related tasks assigned to you.

Purpose: to provide the HR functions of the App to you and your employer.
Legal basis: the processing is carried out for your employer as controller; the legal basis is determined by your employer (typically Art. 6(1)(b) and/or (f) GDPR, and Art. 88 GDPR / § 96 ArbVG in the employment context). moonsoft processes this data only on documented instructions from your employer under the DPA.

4.2 Account, authentication and session data

  • Login credentials (user name and, if you enable biometric login, credentials stored only in the device's secure storage – see section 6), and a session/context token used to keep you signed in.

Purpose: to authenticate you and maintain a secure session.
Legal basis: Art. 6(1)(b) GDPR (performance of the contract / provision of the service) and our and your employer's legitimate interest in secure access, Art. 6(1)(f) GDPR.

4.3 Technical, device and diagnostic data (moonsoft as controller)

  • Device and app information – device model, operating system name and version, and app version.
  • Application log data – records of requests made by the App to the backend, including endpoint, timestamp, status code, and request/response content, together with your user ID, company number, and session context. These logs are used to diagnose errors and support requests.
  • Crash diagnostics – automatically generated crash and stability reports via Firebase Crashlytics (see section 7), which may include device state and technical identifiers at the time of a crash.
  • Push notification token – a device token (Firebase Cloud Messaging) used to deliver notifications about tasks and approvals.

Purpose: operation, security, error diagnosis, stability, and delivery of notifications.
Legal basis: Art. 6(1)(f) GDPR (legitimate interest in a functioning, secure, and reliable App); for push notifications also Art. 6(1)(b) GDPR where notifications are part of the service.

4.4 Location data

If you use GPS-based route recording in travel management, the App accesses your device location to record travel distances and to convert coordinates into an address. Location is accessed only while you use this feature.

Purpose: recording travel routes and distances for expense reporting.
Legal basis: Art. 6(1)(b)/(f) GDPR as determined by your employer; access to the device sensor requires your permission at the operating-system level (see section 6).

5. On-device processing (no upload)

Some processing happens entirely on your device and the underlying content is not transmitted to moonsoft for this purpose:

  • Receipt, odometer, and QR scanning uses on-device text and entity recognition (Google ML Kit). The image is analysed locally; only the data you confirm (e.g. an amount or a reading) is added to your entry. The ML Kit language model may be downloaded once from Google's servers.
  • Biometric authentication (Face ID / Touch ID / fingerprint) is handled by your device's operating system. moonsoft does not receive or store your biometric data.

6. Device permissions

The App requests the following permissions. You can grant or revoke them at any time in your device settings; some features will not work without the relevant permission.

PermissionWhy it is used
CameraScanning receipts, odometer readings, and QR codes.
MicrophoneThe App does not record or transmit audio. No feature of the App uses the microphone. Where a platform component requires this permission to be present, it is requested only at the moment you explicitly start a feature that captures audio or video – never in the background – and no audio is stored or sent to moonsoft.
Photo library / mediaAttaching existing images or documents (e.g. receipts) and saving files where applicable.
LocationGPS-based route and distance recording in travel management.
Biometrics (Face ID / fingerprint)Optional convenient and secure login; credentials are stored in the device's secure keychain and unlocked by the OS biometric check.
NotificationsPush notifications for new tasks, approvals, and reminders.

7. Recipients and processors

We do not sell personal data and do not use it for advertising or cross-app tracking. Data is shared only with the following recipients:

  • moonsoft RS2 backend – the HR data you enter or view is processed on the moonsoft backend, hosted in Google Cloud within the EU. Subprocessor: Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland. Data transmission uses SSL/TLS encryption.
  • Google / FirebaseFirebase Cloud Messaging (delivery of push notifications) and Firebase Crashlytics (crash and stability diagnostics), provided by Google Ireland Limited / Google LLC. Google Maps is used to display maps within travel features. Google ML Kit may download on-device recognition models (see section 5).
  • Geocoding (address lookup) – address search and the conversion of coordinates into addresses are performed via moonsoft's own servers. No location data is shared with third-party geocoding providers for this purpose.

All processors act on the basis of data processing agreements. All subprocessors that process HR data (section 4.1) – including Google Ireland Limited – are engaged under, and covered by, the Data Processing Agreement (DPA) between moonsoft and your employer, which also governs the approval and notification of any changes to subprocessors.

8. International data transfers

The App is intended for use within the EU/EEA, and HR data is hosted on servers within the EU. Where a processor with a US parent company (e.g. Google) may involve processing outside the EEA, such transfers are safeguarded by the EU-U.S. Data Privacy Framework adequacy decision (Art. 45 GDPR) for DPF-certified recipients such as Google LLC, and/or by the EU Standard Contractual Clauses (Art. 46 GDPR). We do not otherwise transfer personal data to third countries.

9. Storage and retention

  • HR and business data is retained for as long as necessary for the HR processes and according to the retention periods defined by your employer (the controller) and applicable law. moonsoft stores it as instructed under the DPA and deletes or returns it at the end of the contract.
  • Technical, log, and diagnostic data is retained only as long as needed for operation, security, and error analysis, and then deleted or aggregated.
  • Data stored on your device – credentials in the secure keychain, session token, configuration, and local drafts/log entries remain on your device until you log out, clear them, or uninstall the App. Logging out and uninstalling removes locally stored data.

Account deletion and revocation. LunaHR does not offer self-service account registration – accounts are provisioned and managed by your employer. To delete your account or revoke your access, please contact your employer (the controller), who can disable or remove your account in the HR system; moonsoft will action such deletion on the employer's instruction under the DPA. Independently, you can remove all locally stored app data at any time by logging out and uninstalling the App.

10. Data security

Data transmission between the App and the backend takes place exclusively over SSL/TLS-encrypted connections. Credentials are stored in the operating system's secure storage (Keychain / Keystore). moonsoft applies appropriate technical and organisational measures to protect personal data against unauthorised access, loss, or misuse, as further detailed in the DPA with your employer.

11. Your rights

Under the GDPR you have the right to access, rectification, erasure, restriction of processing, data portability, and to object to processing, as well as the right to lodge a complaint with a supervisory authority.

  • For HR and business data (section 4.1), your employer is the controller – please direct these requests to your employer. We will support your employer in responding.
  • For data for which moonsoft is the controller (section 4.3), you may contact us directly at info@moonsoft.at.
  • For account deletion, see the "Account deletion and revocation" note in section 9.

You have the right to lodge a complaint with the Austrian Data Protection Authority:

Österreichische Datenschutzbehörde
Barichgasse 40–42, 1030 Vienna, Austria
dsb@dsb.gv.at · www.dsb.gv.at

12. Changes to this Privacy Policy

We may update this Privacy Policy to reflect changes to the App or legal requirements. The current version is always available at the link provided in the App and in the app stores. Material changes will be communicated appropriately.

13. Contact

moonsoft HR Solutions GmbH
Guglgasse 15–17, BT 3B, 1st floor, A-1110 Vienna, Austria
Email: info@moonsoft.at
Phone: +43 676 / 711 99 25
Web: www.moonsoft.at

Contact

LunaHR Privacy Policy - moonsoft HR Solutions | moonsoft HR Solutions GmbH