Privacy Policy

Last updated: 11 August 2026

This is placeholder template text, not reviewed legal advice. Replace it with copy approved by your legal counsel before relying on it.

1. What this policy covers

This policy describes how this HRM system ("the Service") collects, uses and stores personal data belonging to registered companies and their employees.

2. Data we collect

  • Account data: staff ID, name, email, role and password (stored as a salted hash, never in plain text).
  • Employee records: department, position, employment dates, compensation, and documents uploaded for onboarding or payroll (e.g. IDs, bank details) where your organization chooses to store them.
  • Operational data: leave and overtime requests, attendance/shift records, and payroll history entered or generated within the Service.
  • Technical data: login timestamps and source IP address, used for security purposes such as rate-limiting failed login attempts.

3. How data is used

Data is used solely to provide HR functionality to your organization: managing employees, processing leave/overtime, running payroll, generating payslips and reports, and (where enabled) Telegram or SSO/LDAP sign-in integration.

4. Data storage and security

Data is stored in a database dedicated to the Service. Passwords are hashed, not stored in plain text. Payslip documents sent by email or Telegram are transmitted using the delivery channel your administrator configures.

5. Data sharing

Data is not sold or shared with third parties, except where your organization enables an integration (e.g. SSO/LDAP identity provider, Telegram bot, SMTP email delivery) that necessarily involves sending data to that third-party service to perform its function.

6. Data retention

Data is retained for as long as your company account is active, plus any period required for legitimate business, tax or legal record-keeping purposes. An organization administrator may request deletion of specific records, subject to those requirements.

7. Employee rights

Employees seeking to access, correct or request deletion of their personal data should contact their organization's HR administrator, who controls the data entered into the Service.

8. Changes to this policy

This policy may be updated from time to time. Material changes will be reflected by updating the "Last updated" date above.

9. Contact

Questions about this policy can be directed to your system administrator or to admin@example.com.

Terms & Conditions · Back to login

Terms & Conditions · Privacy Policy