DestraForce

Privacy policy

Last updated 19 August 2026

This policy explains what personal data DestraForce handles, why, and what you can do about it. It covers both this website and the DestraForce web and mobile applications. It is written to match what the software actually does rather than to describe every practice a company of this kind might have.

Two different roles, and which one applies to you

DestraForce is a product of Destratech. Which data-protection role we hold depends on how you came to be here, and the difference decides who you ask about your data.

Where you are an employee or contractor using DestraForce because your employer bought it, your employer is the controller: they decide what is recorded about you and for how long. We are their processor, acting on their instructions. Ask them first — this policy tells you what we do on their behalf, and they can tell you what they have chosen.

Where you contact us directly — visiting this website, asking for a demonstration, or holding an account with us as a customer — we are the controller of that data ourselves.

If you visit this site or ask for a demonstration

If you request a demonstration we collect the details you give us, which is how we reply. The lawful basis is our legitimate interest in responding to a business enquiry, and taking steps at your request before entering a contract.

This site sets one cookie, to remember whether you are reading it in English or Portuguese. It carries no identifier and is not used to profile you. There is no advertising network and no cross-site tracking on this site.

If you use DestraForce at work

The applications hold your account details (name, email address, phone number, profile photograph and language), your work (the jobs assigned to you, your check-ins and check-outs, worked time, leave requests, completed checklists, issues you report and messages you send), and your HR record (job title, hire date, employment type, department, and — where your employer records them — date of birth, tax number, identification document number, home address and emergency contact).

This is processed to run the service you are employed to deliver, to record worked time, and to meet your employer's obligations under labour, tax and social-security law. The lawful bases are performance of your contract of employment and compliance with a legal obligation.

It is deliberately not based on your consent. Consent given by an employee to an employer is not freely given in any meaningful sense, and treating it as though it were would misrepresent the position you are actually in. Confirming a notice inside the app records that you were informed; it is not permission, and it waives nothing.

Location

The mobile app records your position at the moment you check in to a job and again when you check out. That is the whole of what is stored.

It does not track you in the background. Background location is switched off in the app's configuration on both iOS and Android, so the app cannot read your position when it is not open. While a job is open your position may be shown live to your manager, but that live position is not written to any database — close the job and there is nothing to look back at.

Your employer sets how long the stored check-in positions are kept. The platform default is one year, after which the position is removed from the visit while the visit itself remains, because the visit is part of the working-time record and the coordinates are not.

Photographs

The app takes photographs as evidence of work carried out, attached to a specific job. The camera is only used when you choose to attach one, and audio recording is blocked outright.

Photographs are kept for as long as your employer specifies — one year by default — and then deleted, images included, not merely hidden from view.

Please avoid photographing people who are not part of the work. If you appear in a photograph taken on site and want it removed, contact the organization that took it.

Who else sees this data

We do not sell personal data, and we do not share it for advertising. Data is never shared between customer organizations: each organization's data is isolated from every other one.

We rely on a small number of service providers to run the product: Railway for hosting and databases, Stripe for subscription billing, and Sentry for error monitoring, which is configured not to attach personal data to reports.

Where the web console shows a map, the map tiles and any address suggestions are requested by your browser directly from Google Maps, which means Google sees those requests. That happens in the browser rather than through our servers.

We will also disclose data where the law requires it of us.

Where the data is stored

Application data is hosted in the European Union, in the Amsterdam region, and that includes the databases rather than only the application servers.

Some of the providers above are established outside the EU. Where that involves a transfer, it relies on the safeguards those providers offer for it, such as standard contractual clauses.

How long it is kept

Records that the law requires an employer to retain are kept for the statutory period, which for most employment records runs for years after the employment ends. Invoices and their supporting documents are kept for ten years under Portuguese tax law.

Everything else is kept only as long as it is needed. Each customer organization sets its own periods, starting from platform defaults: one year for check-in positions and photographs, ninety days for delivered notifications, one year for the record of who accessed personal data, and three years for a sales contact nobody has been in touch with.

Your rights

You may ask for a copy of your data, ask for it to be corrected, object to how it is used, and ask for it to be erased. The applications can produce a copy of everything held about a person as a downloadable file, and can carry out an erasure.

Erasure has a real limit worth stating plainly: where the law requires a record to be kept, we remove the identifying details as far as the law allows instead of deleting the record. Where that applies you will be told the date the rest can follow, rather than simply refused.

If you use DestraForce through an employer, ask them first — they decide these questions and we act on their instructions. If you are not satisfied, you may complain to the Comissão Nacional de Proteção de Dados (CNPD), Portugal's supervisory authority.

Children

DestraForce is a tool for managing work and is not directed at children. We do not knowingly collect data about anyone below the minimum working age.

Changes to this policy

If this policy changes we update the date at the top. Where a change affects people using the applications at work, the notices inside the app are versioned separately and re-issued, so a change to the wording asks everyone to read it again rather than passing unnoticed.

Contact

For anything in this policy, write to info@destratech.com.

If you use DestraForce through your employer, they remain your first point of contact for questions about your own data.