This Privacy Policy explains how Webzbolt HRMS ("we", "us", "the platform") collects, uses, stores, and protects information when an organization ("customer", "you") and its employees use our HR management software. It applies to every organization's tenant on the platform and to the platform's own public pages.
1. Information We Collect
Depending on how the platform is used, we process:
- Account information — name, email, and login credentials for every user your organization creates.
- Employee records — the data your organization chooses to store: contact details, employment history, attendance, leave, payroll, performance, and documents you upload.
- Usage data — login times, IP address, and a security audit trail of sensitive actions (who changed what, and when), used to keep accounts and organization data secure.
- Communications — messages sent through the platform's internal chat and notifications, scoped strictly within your own organization.
2. How We Use Information
- To provide, operate, and maintain the HR functions your organization has subscribed to.
- To send transactional notifications — leave decisions, expense claim updates, published HR policies, payslip availability, and account security codes.
- To secure accounts (password hashing, optional two-factor authentication, session management) and detect misuse.
- To improve platform reliability and troubleshoot issues reported by your organization.
3. Multi-Tenant Data Isolation
Webzbolt HRMS is multi-tenant: many organizations share the same platform, but every record is scoped to its owning organization. Employees, managers, and administrators can only see data that belongs to their own organization — a super admin's platform-level access exists solely for account provisioning and support, not day-to-day visibility into your data.
4. Data Sharing
We do not sell organization or employee data. Information is shared only:
- Within your own organization, per the roles and permissions your administrators configure.
- With service providers strictly necessary to operate the platform (e.g. email delivery for notifications), bound to protect the data they process.
- Where required by law, or to protect the rights, safety, or property of the platform or its users.
5. Data Retention
Data is retained for as long as an organization's account remains active, plus a reasonable period afterward for legal, audit, and backup purposes. An organization administrator may request deletion or export of their organization's data at any time (see Data Export in Settings).
6. Security
Passwords are stored using industry-standard one-way hashing, never in plain text. Optional two-factor authentication adds a one-time email code to the login flow. Every sensitive administrative action is recorded in a searchable audit log. Access to each module and action is enforced by role-based permissions on every request, not just hidden from the menu.
7. Your Rights
Depending on your organization's policies and applicable law, individuals may have the right to access, correct, or request deletion of their personal data. Requests should go through your organization's HR administrator, who manages the underlying records.
8. Cookies & Sessions
The platform uses a session cookie to keep you signed in and a security (CSRF) cookie to protect form submissions. Neither is used for advertising or cross-site tracking.
9. Changes to This Policy
We may update this policy as the platform evolves. Material changes will be reflected by updating the "Last updated" date above.
10. Contact
Questions about this policy or how your organization's data is handled should be directed to your organization's administrator, or to the platform's support contact provided at signup.