Data practices

Privacy Policy

HRIS Central handles workforce and applicant information on behalf of organizations, so this notice explains what categories of data the service uses, why it uses them, and how access, retention, and privacy rights are managed in a business setting.

Last updated

May 6, 2026

Data handled

Account, workforce, applicant, attendance, scheduling, filing, payroll, and support records

Primary use

Delivering HR workflows, securing access, maintaining audit trails, and supporting operations

Control model

Your organization typically controls workforce records while HRIS Central provides the service layer

01

Who this notice covers

This privacy policy explains how information is handled when people use HRIS Central.

This Privacy Policy describes how HRIS Central handles personal information when organizations, administrators, managers, employees, applicants, contractors, and other authorized users access the service.

Because HRIS Central is primarily used as a business platform, some personal information is provided directly by users and some is provided by the organization that invited or manages them in the system.

If your employer or client organization gives you access to HRIS Central, that organization may control many decisions about your account, your role, and the data stored about you in the platform.

02

Information we collect

The service needs workforce and operational information to deliver HR workflows safely and accurately.

The information handled in HRIS Central depends on which modules your organization uses. Common categories include account details, employee profile information, applicant details, attendance and schedule records, filings, payroll context, uploaded documents, and support communications.

  • Identity and account data such as name, email address, role, department, and login activity
  • Employment and applicant records such as job history, documents, evaluations, offers, and profile changes
  • Operational records such as schedules, attendance, leave, reimbursement, case, and payroll workflow data
  • Technical data such as device, browser, IP-derived security signals, timestamps, and audit logs used to protect the service
03

How we use information

We use information to provide the service, secure it, and help organizations operate HR processes correctly.

HRIS Central uses information to authenticate users, enforce role-based access, process workflow actions, generate reports, maintain audit trails, troubleshoot incidents, and improve reliability and usability.

  • To create and administer user accounts and permissions
  • To support attendance, payroll, leave, scheduling, recruitment, filing, and case workflows
  • To monitor security events, detect suspicious activity, and respond to abuse or incidents
  • To provide customer support, product maintenance, and operational analytics
04

Your organization's role and our role

Workforce data in HRIS Central is typically managed on behalf of an employer or client organization.

When your organization configures and uses HRIS Central for workforce operations, your organization is generally responsible for deciding what data is collected, why it is used, who may access it, and how long it should be kept.

In that scenario, HRIS Central acts as a service provider or processor that helps your organization host, organize, secure, and present data according to the permissions and workflows it configures.

If you have questions about an employment record, a leave decision, a payroll record, or a recruiting action, you should usually contact your HR or system administrator first because they control the underlying business decision.

05

How information may be shared

Information is not sold. It is shared only where needed to operate the service, follow instructions, or meet legal obligations.

HRIS Central does not sell personal information. Information may be disclosed to authorized users within your organization, trusted service providers, hosting partners, security providers, or professional advisers when reasonably necessary to operate the service or meet legal obligations.

  • Within your organization according to the role, module, and approval permissions it configures
  • With infrastructure and support providers that help host, secure, monitor, or maintain the service
  • When required to comply with law, court order, audit obligation, or a valid government request
  • As part of a merger, restructuring, financing, or asset transfer, subject to appropriate confidentiality protections
06

Retention and deletion

Retention is shaped by product configuration, legal requirements, payroll obligations, and audit needs.

We keep information for as long as it is reasonably needed to provide the service, support legitimate workforce operations, comply with legal obligations, resolve disputes, or enforce agreements.

Different modules may have different retention periods because HR, payroll, recruitment, attendance, and case management records often carry different business and legal requirements.

  • Account, audit, and security logs may be retained longer than front-end profile edits when needed for fraud prevention or incident investigation.
  • Your organization may request deletion or export of data, subject to its own retention obligations and our operational backup cycles.
  • Archived or backed-up copies may persist for a limited period before secure deletion processes complete.
07

Security and access controls

We use layered safeguards designed to reduce risk, but every organization still needs good internal access hygiene.

HRIS Central uses administrative, technical, and organizational safeguards designed to protect personal information against unauthorized access, disclosure, alteration, and misuse. Examples may include authentication controls, role-based permissions, audit logging, rate limiting, and operational monitoring.

No system can guarantee absolute security, so organizations should still use strong password practices, appropriate access reviews, secure endpoints, and internal approval controls.

If your organization uses this service in a regulated environment, review your own legal, security, and records-management requirements before launch.
08

Cookies, sessions, and browser storage

Some browser-side storage is required to keep the service secure and functional.

HRIS Central may use essential cookies, session tokens, and browser storage to keep users signed in, protect sessions, remember preferences, and support security controls.

If optional analytics, marketing, or tracking tools are enabled in your deployment, your organization should update this policy and its consent flows so users receive accurate notice.

09

User rights and choices

Users may have rights over personal information depending on applicable law and the organization that controls the record.

Depending on your location and the nature of your relationship with the organization using HRIS Central, you may have rights to request access, correction, deletion, restriction, portability, or objection regarding certain personal information.

Because many records are controlled by the employer or organization using the service, those requests should usually be directed to your HR team or system administrator first. We will support reasonable requests as required by law and our contractual obligations.

  • You may update some profile details directly through self-service features where available.
  • You may request help from your administrator if you believe a role, record, or access decision is inaccurate.
  • Certain information may still need to be retained to comply with law, payroll obligations, dispute handling, or audit requirements.
10

Policy updates and contact path

Privacy practices can change as the product, laws, or deployment choices evolve.

We may update this Privacy Policy from time to time and will publish the latest version with an updated effective date. Material changes may also be highlighted in-product or through another reasonable notice channel.

For day-to-day questions about records inside your workspace, contact your HRIS Central administrator or HR team first. For platform-level privacy concerns, use the support channel configured by your organization.

Review before production launch

This document is strong product copy for launch, onboarding, and internal review, but it should still be reviewed by your legal counsel before you rely on it as a final legal agreement.