Privacy Policy
Last updated: 18 August 2026
TechHive HRMS is a human resources system used by employers to manage their own staff records. This policy explains what personal data the system holds, why it holds it, who can see it, and what rights you have over it.
1. Data we collect
The system holds only what an employer enters into it, or what is generated by using it. Nothing is bought from third parties and nothing is collected from you outside the product.
| Category | What it includes | Why |
|---|---|---|
| Identity | Name, date of birth, government identity number, passport or travel document number, citizenship, marital status, home address, personal contact details, profile photo | To maintain an employment record and meet statutory reporting duties |
| Employment | Staff number, job title, department, designation, reporting line, hire date, employment status, work location, shift assignment | To operate the employment relationship |
| Attendance | Clock-in and clock-out times, breaks, late minutes, overtime, the source of each punch (web, mobile or biometric device) and the device identifier where one is used | To record hours worked and calculate pay |
| Time off | Leave requests and balances, work-from-home days, shift swaps, timesheets, and any reason you give when raising one | To administer absence and remote working |
| Pay | Salary, allowances, deductions, tax and statutory contributions, payslips, loans and advances, expense claims | To run payroll and meet tax and social-security obligations |
| Documents | Files uploaded by you or your employer — contracts, certificates, identity documents — and their expiry dates | To evidence eligibility to work and keep qualifications current |
| Performance | Reviews, goals, probation records, promotions, training enrolments | To manage development and progression |
| Security | Sign-in events, IP address, browser and device description, session references, and push-notification tokens if you use the mobile app | To keep accounts secure, show you your active sessions, and send notifications you have opted into |
What we do not collect
- We do not track your location. Attendance records the time of a punch and which device it came from, never where you were.
- We do not store biometric images or templates. Where an employer uses a biometric terminal, that device performs the match itself and sends only a punch event and a device identifier.
- We do not use advertising or analytics trackers, and we do not build advertising profiles.
- We do not read the contents of your personal device beyond what you explicitly upload.
2. How your data is used
Personal data is used only to provide the service to your employer: maintaining employment records, recording attendance, processing time off, running payroll, routing approvals to the right people, and securing accounts. It is not used to make automated decisions that produce legal effects without a person reviewing them.
Legal basis
- Contract — most processing is necessary to perform your contract of employment.
- Legal obligation — payroll, tax and statutory contribution records.
- Legitimate interests — securing accounts and preventing misuse, balanced against your rights.
- Consent — optional features such as push notifications, which you can withdraw at any time.
3. Who can see it
Visibility inside the system is governed by role and by permission, not by seniority:
- You can always see your own record, attendance, payslips and requests.
- Your manager can see their team's attendance and the requests they are asked to approve. Pay and identity data are not included.
- HR and administrators can see what their assigned permissions allow. An employer decides who holds which role.
- Colleagues see only what is published company-wide — the holiday calendar, company events, birthdays and work anniversaries.
Reasons given on leave requests are treated as confidential and are not shown to colleagues.
Third parties
We share data only where it is necessary to run the service:
- Hosting and infrastructure providers who store the data on our behalf.
- Email and push-notification providers, to deliver messages the system sends you.
- Authorities, where the law requires it.
We do not sell personal data, and we do not share it for advertising.
4. How long it is kept
Records are retained for as long as your employer needs them and for as long as the law requires — commonly several years after employment ends for payroll and tax records. Your employer sets the retention period; when they delete a record from the system, it is removed from our active databases and falls out of encrypted backups on the normal backup cycle.
5. Security
- All traffic is encrypted in transit over HTTPS.
- Passwords are stored as salted one-way hashes and are never readable by us.
- Access is controlled by role-based permissions, and each employer's data is isolated from every other employer's.
- Uploaded documents are served through access-checked endpoints, never public links, so permission is re-checked on every download.
- Sign-in activity is logged, and you can review and end your own active sessions from your profile.
No system is perfectly secure. If a breach affects your data, we will notify your employer without undue delay so they can inform you as the law requires.
6. Your rights
Depending on where you live, you may have the right to:
- Ask what personal data is held about you, and get a copy.
- Have inaccurate data corrected.
- Ask for data to be erased, where no legal duty requires it to be kept.
- Object to or restrict certain processing.
- Receive your data in a portable format.
- Withdraw consent for anything you consented to, such as push notifications.
Because your employer is the controller, please raise these with their HR team first. If you cannot reach a resolution, contact us at privacy@techhive.ai and we will help. You also have the right to complain to your local data protection authority.
Deleting your account
You can ask for your account and the personal data attached to it to be deleted at any time, from Profile → Security in the app or at https://hr.techhive.ai/account-deletion. That page sets out exactly what is erased and what your employer is legally required to keep.
7. Mobile app
The mobile app accesses only what you grant it:
- Notifications — optional, to tell you about approvals and requests. Declining does not limit any other feature.
- Camera and photo library — only when you choose to upload a profile photo or a document, and only for the file you pick.
The app does not access your location, contacts, calendar, messages or call history. Signing out removes the notification token registered for that device.
8. Children
The service is for employment administration and is not intended for anyone under the minimum legal working age in their jurisdiction.
9. International transfers
Data is hosted in the region your employer's account is provisioned in. Where data is transferred across borders, it is protected by appropriate safeguards.
10. Changes
We may update this policy as the product changes. The date at the top always reflects the current version, and material changes will be notified to employers before they take effect.
11. Contact
TechHive AI
Privacy enquiries: privacy@techhive.ai