Last updated: July 23, 2026
This Privacy Policy describes how HRMGridSystem ("we", "us", or "our") collects, uses, stores, and protects personal information when you access or use the HRMGridSystem platform at https://hrmgridsys.com and related services (collectively, the "Service").
By using the Service, you acknowledge this Privacy Policy. If you do not agree, please do not use the Service.
1. Who We Are
HRMGridSystem is a cloud-based human resource management platform that helps organizations manage employees, attendance, leave, payroll-related workflows, recruitment, performance, and related HR operations across multi-tenant workspaces.
Operator: HRMGridSystem
Website: https://hrmgridsys.com
Support: support@hrmgridsys.com
2. Scope of This Policy
This Policy applies to:
- Organization administrators and authorized users who manage a tenant workspace
- Employees and other end users invited to use the Service by their organization
- Visitors to our public pages (including this Privacy Policy and Terms of Service)
For employee data stored inside a customer organization’s workspace, that organization is typically the data controller. HRMGridSystem acts as a service provider / data processor on behalf of that organization, except where we process data for our own business operations (for example billing, security, and product analytics).
3. Information We Collect
3.1 Information you or your organization provide
- Account and profile data: name, email address, phone number, job title, department, role, profile photo, and login identifiers
- Organization data: company name, subdomain/tenant identifiers, billing contacts, and configuration settings
- HR and workforce data entered into the Service, which may include employment records, contracts, attendance and timesheets, leave requests, payroll inputs, payslips, loans/advances, documents, performance records, recruitment and onboarding information, and similar HR content
- Support and communication data: messages, tickets, and attachments you send to support
3.2 Information collected automatically
- Device and browser information, IP address, approximate location derived from IP, timestamps, and pages or features accessed
- Authentication and security logs (including SSO / identity events where configured)
- Cookies and similar technologies used for session management, security, and preferences
3.3 Information from third parties
Where your organization enables integrations (for example identity providers, email delivery, payment, or other connected tools), we may receive information from those services as needed to operate the integration.
4. How We Use Information
We use personal information to:
- Provide, maintain, and improve the Service
- Authenticate users, manage sessions, and protect accounts
- Enable HR workflows configured by your organization (attendance, leave, payroll support features, recruitment, and related modules)
- Process subscriptions, invoices, and account administration
- Send important service notices (security alerts, downtime, policy updates)
- Provide customer support and investigate abuse or security incidents
- Comply with applicable laws and enforce our Terms of Service
- Generate aggregated or de-identified insights to improve product performance (not used to identify individuals where reasonably avoidable)
We do not sell personal information.
5. Legal Bases for Processing
Where required by applicable law, we process personal information on one or more of the following bases:
- Performance of a contract (to provide the Service)
- Legitimate interests (security, service improvement, fraud prevention), balanced against your rights
- Consent, where consent is required
- Legal obligation
6. How We Share Information
We may share information only as follows:
- Within your organization: with administrators and users who have been granted access in your tenant
- Service providers: hosting, email, monitoring, payment, identity, and support vendors who process data under contractual confidentiality and security obligations
- Legal and safety: when required by law, regulation, court order, or to protect rights, safety, and security
- Business transfers: in connection with a merger, acquisition, financing, or sale of assets, subject to continued protection of personal information
We do not share Customer Data with other tenants.
7. Roles and Responsibilities (Multi-Tenant HR Data)
- Your organization decides what employee/HR data to upload, how long to retain it inside the workspace, and which users can access it.
- Your organization is responsible for providing required notices to employees and obtaining any consents required under local employment and privacy laws.
- Employees seeking access, correction, or deletion of workplace HR records should first contact their employer’s administrator. We will reasonably assist organizations with such requests where contractually and legally appropriate.
8. Data Security
We implement technical and organizational measures designed to protect personal information, which may include encryption in transit, access controls, authentication safeguards, logging, and tenant isolation practices.
No method of electronic storage or transmission is 100% secure. You are responsible for protecting account credentials and configuring user permissions carefully.
9. Data Retention
We retain personal information for as long as necessary to:
- Provide the Service to your organization
- Meet contractual and accounting requirements
- Resolve disputes and enforce agreements
- Comply with legal obligations
When an organization account is closed, we will delete or de-identify Customer Data within a commercially reasonable period, unless longer retention is required by law or legitimate security/audit needs.
10. International Data Transfers
The Service may be hosted or supported from facilities in more than one country. Where personal information is transferred across borders, we take steps intended to provide an appropriate level of protection consistent with this Policy and applicable law.
11. Cookies and Similar Technologies
We use cookies and similar technologies to:
- Keep you signed in and maintain secure sessions
- Remember preferences
- Protect against fraud and abuse
- Understand product usage at an aggregate level
You can control cookies through your browser settings. Disabling certain cookies may affect login and core functionality.
12. Your Privacy Rights
Depending on your location and role, you may have rights to:
- Access personal information we hold about you
- Request correction of inaccurate information
- Request deletion or restriction of processing
- Object to certain processing
- Request data portability
- Withdraw consent where processing is based on consent
To exercise rights relating to workplace HR data stored by your employer in HRMGridSystem, contact your organization administrator first. For privacy questions about our own processing, email support@hrmgridsys.com.
We may need to verify your identity and, where applicable, confirm that your employer authorizes the request.
13. Children’s Privacy
HRMGridSystem is a business HR platform and is not directed to children under 16. We do not knowingly collect personal information from children.
14. Third-Party Links and Services
The Service may contain links to or integrations with third-party services. Their privacy practices are governed by their own policies. We are not responsible for third-party services we do not control.
15. Changes to This Privacy Policy
We may update this Privacy Policy from time to time. The “Last updated” date at the top of this page will be revised when changes are posted. Where required, we may provide additional notice. Continued use of the Service after an update becomes effective constitutes acceptance of the revised Policy.
16. Contact Us
For privacy questions or requests related to HRMGridSystem:
Email: support@hrmgridsys.com
Website: https://hrmgridsys.com
If you are an employee of a customer organization, please also contact your employer’s HR or system administrator for records held in that organization’s workspace.