Privacy Policy Details - v0.0.0 Outdated
Privacy Policy for HRaaS.io
Effective Date: [Insert Date]
At HRaaS.io (“we”, “our”, “the Service”), we are committed to protecting the privacy of our users and ensuring transparency in how we handle personal and company data. This Privacy Policy explains what data we collect, how we use it, how it is stored, and your rights under the General Data Protection Regulation (GDPR) and other applicable laws.
1. Data Controller
The data controller responsible for your information is:
- [Your Company Legal Name]
- [Company Address]
- Contact: [[email protected]]
2. Data We Collect
We collect and process the following categories of information:
- Employee Information: full name, surname, email, phone number, attendance records, time-off, working schedules, positions, levels, and other HR-related information provided by employers.
- Company Information: company name, department, position, salaries (if disclosed), and internal HR structures.
- Technical Data: IP addresses, browser type, device information, access logs.
- Cookies & Analytics: we use cookies and Google Analytics to understand usage patterns. Cloudflare may temporarily process IP addresses for security and performance.
We do not knowingly collect data from children. The Service is intended only for companies and individuals of legal working age.
3. Purposes of Processing
We process personal data only for legitimate purposes:
- To provide, operate, and maintain the HRaaS.io service.
- To manage user accounts and authenticate access.
- To enable employers to track and manage attendance and HR data.
- To ensure system security, prevent fraud, and maintain service reliability.
- To improve our platform, including through aggregated analytics.
We do not use your data for marketing purposes without your consent.
4. Legal Basis
Under GDPR, we rely on the following legal bases:
- Contractual necessity – to deliver the Service you subscribed to.
- Legitimate interests – for service improvement, fraud prevention, and security.
- Legal obligations – where required by law.
- Consent – where applicable (e.g., cookies).
5. Data Retention
We retain data as follows:
- Employee & company data: retained for up to 5 years unless deleted earlier at your request.
- System & access logs: retained for 6 months to 1 year.
- Cookies & analytics data: retained as per Google’s policies.
When data is no longer needed, it will be securely deleted or anonymized.
6. Data Sharing
We may share data only with trusted third parties necessary to provide the Service:
- Cloud providers (e.g., Huawei Cloud and other providers we may use).
- Analytics providers (e.g., Google Analytics).
- Security & infrastructure providers (e.g., Cloudflare).
- Payment processors if applicable.
We never sell personal data.
7. Data Storage & Security
We implement the following security measures:
- All customer data resides in secure cloud environments.
- Databases are encrypted at the disk level (data at rest).
- All communications are encrypted in transit via SSL/HTTPS.
- Strong role-based access controls protect data access.
- Administrative access is limited to authorized personnel.
8. International Data Transfers
Your data may be stored or processed in different regions depending on our cloud provider. We ensure all transfers comply with GDPR, either by adequacy decisions or by using Standard Contractual Clauses (SCCs).
9. Your Rights under GDPR
You have the following rights regarding your personal data:
- Right of access – obtain a copy of your data.
- Right to rectification – correct inaccurate or incomplete data.
- Right to erasure – request deletion of your data.
- Right to restriction – limit how your data is processed.
- Right to portability – receive your data in a machine-readable format.
- Right to object – object to certain processing activities.
- Right to withdraw consent – where processing is based on consent.
Requests can be made by contacting us at [[email protected]]. We will respond within statutory deadlines.
10. Cookies
We use cookies to:
- Maintain login sessions.
- Enable essential platform functionality.
- Measure usage with Google Analytics.
You may manage or reject cookies via our Cookie Consent tool or your browser settings.
11. diff
We may update this Privacy Policy from time to time. The latest version will always be published here.
12. Contact
For any questions or to exercise your rights, contact us at:
- Email: [[email protected]]
- Address: [Company Address]