Frequently Asked Questions

Everything you need to know about the Proteco360 verification layer.

General

What is Proteco360?

Proteco360 is an independent workforce verification layer designed to identify potentially conflicting professional commitments across participating organizations and staffing providers.

It compares limited-scope contractual information using transformed identifiers, allowing relevant overlap patterns to be detected without creating a conventional centralized HR database containing raw workforce records.

What problem does Proteco360 solve?

Most organizations only have visibility into contracts and assignments recorded in their own systems.

They cannot normally determine whether the same individual has made overlapping commitments to another staffing provider, client or employer.

Proteco360 provides a neutral verification mechanism that can identify these cross-organizational patterns and give authorized teams an opportunity to investigate them responsibly.

Who is Proteco360 designed for?

Proteco360 is primarily designed for:

  • staffing and recruitment agencies,
  • outsourcing and consulting providers,
  • organizations working with external contractors,
  • companies managing distributed vendor ecosystems,
  • compliance, procurement, HR and workforce-risk teams.

It is particularly relevant where organizations depend on declared availability, exclusive allocation, confidentiality or predictable delivery capacity.

Is Proteco360 an HR system?

No.

Proteco360 does not recruit people, manage employee records, administer payroll, issue contracts or replace an ATS, HRIS, VMS or contractor-management platform.

It operates as an additional verification layer focused on risks that may exist between separate organizations and their workforce systems.

Is Proteco360 a background-screening service?

No.

Proteco360 does not verify education, criminal records, professional qualifications, identity documents or employment history through public registers.

It analyzes defined identifiers and contractual parameters submitted by participating organizations to determine whether relevant commitments may overlap.

Is Proteco360 an employee-monitoring platform?

No.

Proteco360 does not monitor screens, communications, application usage, logins, keyboard activity, location, GPS data or real-time productivity.

It does not observe how an individual performs their work. It analyzes defined contractual and availability parameters for the purpose of identifying potential conflicts.

Detection and results

What does Proteco360 detect?

Proteco360 is designed to identify patterns such as:

  • overlapping contract periods,
  • overlapping declared working availability,
  • the same individual appearing in records submitted by different organizations,
  • potentially excessive allocation across concurrent engagements,
  • assignments that may require conflict-of-interest review.

The presence of one of these patterns does not automatically mean that a contractual breach or misconduct has occurred.

How does Proteco360 determine that records may relate to the same person?

Identifying information is normalized and transformed before it is used for central comparison.

Proteco360 compares transformed identifiers together with relevant contractual attributes, such as engagement periods, declared working hours, time zones and contract types.

The exact matching method depends on the information available and the confidence level required.

What is a high-confidence match?

A high-confidence match occurs when a sufficiently specific transformed identifier appears in records submitted by different organizations and the related contract periods overlap.

This indicates that the same person may be committed to more than one participating organization during the same period.

It remains a signal for review, not an automatic legal conclusion.

What is a potential match?

A potential match is generated when some relevant attributes correspond, but the available evidence is not strong enough to classify the result as high-confidence.

Potential matches may consider combinations of:

  • less specific transformed identifiers,
  • declared work schedules,
  • contract types,
  • birth-related attributes,
  • other permitted matching parameters.

These cases are intended for controlled internal review rather than automatic external notification.

Does every second job create a conflict?

No.

A person may legitimately hold several jobs, contracts or business activities. Additional work may be disclosed, permitted and performed outside the availability committed to another organization.

Proteco360 focuses on potentially conflicting commitments - not on the mere existence of another source of income.

Does a Proteco360 alert prove misconduct?

No.

An alert indicates that defined records or commitments may overlap. It does not prove fraud, intentional concealment, poor performance or breach of contract.

The organization receiving the alert should verify the underlying circumstances and assess the result under its own contracts, policies and legal obligations.

Can Proteco360 produce false positives or miss a conflict?

No verification system can eliminate both risks completely.

Results depend on:

  • the quality and consistency of source data,
  • the scope of submitted information,
  • the precision of the identifiers,
  • the number of participating organizations,
  • the matching rules applied.

Proteco360 uses different confidence levels so that less certain results can be reviewed before any consequential action is taken.

What happens when a conflict is detected?

For a high-confidence match, Proteco360 can notify designated contacts according to the agreed alert workflow.

Lower-confidence matches can be directed to an internal review process.

Proteco360 itself does not terminate contracts, block accounts, contact the individual or take enforcement action. The final interpretation and response remain with the authorized organizations.

Does Proteco360 notify the contractor or employee?

Not automatically.

Proteco360 communicates results to authorized organizational contacts. Any communication with the individual should be handled by the relevant employer, client or staffing provider in accordance with its procedures and legal obligations.

Does Proteco360 use artificial intelligence to judge workers?

No.

The current matching model is deterministic and rules-based. Results are generated from defined identifiers, dates, schedules and matching conditions.

This makes the process more explainable and auditable and avoids automated behavioural profiling.

Privacy and data protection

Does Proteco360 store names and surnames centrally?

Proteco360 is designed so that raw identifying information used for matching is transformed on the client side before central processing.

The central service works with transformed identifiers rather than using a conventional database of readable names and complete personnel files.

The precise dataset and transformation process are agreed during implementation.

Does Proteco360 store PESEL numbers, identity documents or complete HR files?

Proteco360 is not designed to centrally store identity documents, complete employee files or unrestricted HR datasets.

Where an identity-related value is required to create a sufficiently specific identifier, it should be processed according to the agreed privacy-preserving transformation model rather than retained centrally in raw form.

Does Proteco360 process personal data?

Proteco360 uses pseudonymized or transformed identifiers. Under GDPR, pseudonymized information may still qualify as personal data where it can be related to an individual using additional information.

For that reason, Proteco360 treats the processing as subject to appropriate data-protection, security, contractual and governance controls rather than claiming that hashing automatically removes every data-protection obligation.

Can Proteco360 reverse a hash and reveal a person's identity?

Proteco360 is not designed to reverse transformed identifiers.

Raw source records remain under the control of the participating organization. Where an alert is generated, that organization can reconcile its own reference with its internal records.

The central service does not need to reconstruct the original name in order to identify that two submitted records correspond.

Can other participating organizations see our workforce database?

No.

Organizations do not receive unrestricted access to another participant's source records, workforce lists or HR systems.

Alerts should disclose only the information necessary for the agreed verification and resolution process. The exact scope of information exchanged is determined through contractual, privacy and compliance rules.

Why is hashing performed before the data is submitted?

Client-side transformation limits the exposure of raw identifying information outside the organization that originally collected it.

The technical model can then apply an additional server-side cryptographic transformation, with protected secrets managed separately from the database. This reduces the usefulness of database records in the event of unauthorized access.

Is hashed data completely anonymous?

Not necessarily.

Hashing and pseudonymization significantly reduce exposure, but they should not automatically be described as anonymization.

Whether information is considered anonymous depends on the full technical and organizational context, including the possibility of linking it back to an individual. Proteco360 therefore uses the more accurate concepts of pseudonymization, data minimization and limited-scope processing.

How long is information retained?

The intended model is to retain information only for as long as it is relevant to active verification and agreed operational or legal requirements.

The MVP specification assumes that active contract information may be removed after the engagement ends and that deletion or anonymization procedures can be initiated following a valid request.

Final retention periods should be defined in the customer agreement, data-processing documentation and applicable retention policy.

Where is the data stored?

The production hosting region, data residency requirements and infrastructure configuration are defined as part of the deployment and contractual process.

The current technical architecture anticipates secure cloud infrastructure, encrypted communication, protected key management, centralized monitoring and audit logging.

Compliance and governance

Is Proteco360 GDPR compliant?

Proteco360 is designed around GDPR-relevant principles, including:

  • privacy by design,
  • data minimization,
  • pseudonymization,
  • restricted access,
  • limited retention,
  • auditable processing.

However, GDPR compliance cannot be guaranteed by a product in isolation. It also depends on the customer's purpose, lawful basis, transparency obligations, contracts, internal procedures, configuration and use of the results.

Proteco360 should therefore be described as designed to support GDPR-aligned processing, subject to legal and operational assessment - not as automatically compliant in every deployment.

Who is the data controller and who is the processor?

The allocation of GDPR roles depends on the commercial and operational model used in a particular deployment.

The relevant roles, purposes of processing, instructions, responsibilities and rights-handling procedures should be documented contractually, including in an appropriate data-processing or joint-controller arrangement where required.

What legal basis can be used for verification?

The appropriate lawful basis depends on:

  • the relationship with the individual,
  • the purpose of the verification,
  • the jurisdiction,
  • applicable employment or contractual rules,
  • the categories of information processed,
  • the legitimate interests and rights involved.

Proteco360 does not prescribe one universal lawful basis. Customers should validate their intended use with qualified data-protection and employment-law advisors before deployment.

Do workers need to be informed about participation in Proteco360?

Transparency obligations should be assessed as part of each implementation.

Depending on the legal and operational model, organizations may need to update privacy notices, contractor policies, engagement terms, vendor agreements or internal procedures.

Proteco360 should not be used as a hidden surveillance mechanism.

Can an organization terminate a contract based solely on an alert?

Proteco360 does not make employment, legal or contractual decisions.

An alert should be reviewed against the underlying facts, contractual terms, applicable law and the individual's opportunity to explain the circumstances.

Any action remains the responsibility of the relevant organization and its legal or compliance advisors.

Is Proteco360 intended to prevent people from having side jobs?

No.

The purpose is not to restrict legitimate additional work.

Proteco360 is intended to help organizations identify situations in which separate commitments may compete for the same capacity or create a relevant contractual, security, confidentiality or conflict-of-interest concern.

Implementation and operation

What information does an organization need to provide?

The required dataset is defined during onboarding and kept as narrow as reasonably possible.

Depending on the verification model, it may include:

  • attributes used locally to create transformed identifiers,
  • contract start and end dates,
  • declared working hours or availability,
  • time zone,
  • contract type,
  • limited role or assignment metadata.

Not every field is required in every implementation.

How is information submitted?

The MVP workflow supports structured file submission through a local client application.

The application can:

  • read an XLSX file,
  • map the customer's columns to required fields,
  • validate and normalize the information,
  • generate transformed identifiers,
  • securely submit the resulting package for processing.

Proteco360's server-side processing is API-based, while direct system-to-system client integrations can be considered separately from the standard MVP workflow.

Does Proteco360 require access to our HR system?

Not for the standard file-based onboarding model.

An organization can prepare an agreed structured export and process it locally through the Proteco360 client application.

Direct access to the organization's complete HR environment is neither necessary nor desirable for the core verification process.

Does Proteco360 change our source data?

No.

Proteco360 does not edit or correct the customer's source records. Validation can identify formatting or consistency issues, but responsibility for the accuracy and quality of the original information remains with the submitting organization.

How does onboarding work?

A typical onboarding process includes:

  • establishing the organization's account and authorized contacts,
  • agreeing on the scope and legal framework,
  • configuring authentication and security credentials,
  • mapping the organization's data fields,
  • conducting a limited test submission,
  • verifying processing and alert workflows,
  • enabling production submissions.

The duration depends on data readiness, security requirements and the complexity of the customer environment.

Is the verification performed in real time?

The current model is based on periodic submission and processing of contract information.

It is not a real-time employee-tracking system and does not continuously observe activity or daily timesheets.

The submission frequency can be agreed according to the organization's workforce volume and risk requirements.

Can Proteco360 operate across countries and time zones?

The technical design supports contract dates and declared work periods with time-zone information.

Where schedule comparison is required, relevant time ranges can be normalized to a common time standard before overlap analysis.

Legal, employment and data-protection requirements must still be assessed for each jurisdiction involved.

Does Proteco360 offer a dashboard?

A public or customer-facing dashboard is not part of the documented MVP.

The initial process is focused on secure submission, automated matching, email alerts and controlled internal reporting.

Dashboards and broader analytics may be considered as later product capabilities and should not be promised as currently available until their scope is confirmed.

Does Proteco360 provide PDF reports?

The current technical MVP explicitly assumes text-based email reporting rather than automatically generated PDF files.

More advanced reporting formats may be introduced later, but they should be presented as roadmap items rather than existing functionality.

Participation and coverage

Does Proteco360 work if only one organization participates?

Proteco360 can process an organization's records, but cross-organizational detection depends on there being relevant comparison data from other participating organizations.

The practical value and coverage of the verification network increase as more staffing providers and organizations participate.

Can Proteco360 detect every external engagement?

No.

Proteco360 can only compare information available within the participating ecosystem and the agreed processing scope.

It cannot detect an engagement that has not been submitted by any participating organization or infer complete employment history from external sources.

Will participating organizations know that we use Proteco360?

The participation and disclosure model should be defined contractually.

Proteco360 can operate as a transparent workforce-integrity programme in which vendors and contractors are informed that relevant commitments may be independently verified.

This preventive model may strengthen accountability without requiring intrusive employee monitoring.