1. Who we are and what this covers
Humio is a cloud service for leave, expense claims and attendance, provided by [Company legal name] Sdn. Bhd. (registration no. [SSM registration no.]), [Registered business address], Malaysia (“we”, “us”).
This policy explains how we handle personal data when you visit our website, sign up, or use Humio, and your rights under Malaysia's Personal Data Protection Act 2010 as amended (“PDPA”).
2. Our role: your employer decides, we process
Humio is used by companies (“Customers”) to manage their own employees. For the personal data a Customer puts into Humio about its people — employee records, leave, claims, receipts, attendance and face scans — the Customer is the data controller and decides why and how that data is processed. We process it on the Customer's behalf, only to provide the service and as described in our Terms of Service.
If you are an employee and have a question about your data in Humio, or want to exercise a right over it, please contact your employer first. We will help your employer respond.
We are the data controller for our own data: the accounts of people who sign up for Humio, billing contacts, support conversations, and visitors to our website.
3. Personal data we process
Accounts
Name, work email address, company name and country, and the roles a person holds (Admin, HR, Manager, Employee). Passwords are handled by our authentication provider and stored only in hashed form; we never see them.
Employee records
What a Customer enters: employee number, job title, department, reporting manager, employment type and status, hire and exit dates, work location, phone number and which public holiday calendar applies.
Leave
Leave type, dates, reason, contact details during leave, approval decisions and notes, and supporting documents such as medical certificates, which are health data.
Expense claims
Receipt images and the details on them — merchant, date, amounts, tax and currency — including the values our receipt reader extracted, whether the employee changed them, and approval and reimbursement history.
Attendance and face scans
Clock-in and clock-out times, a face reference photo each employee registers, the photos taken at each scan, and a similarity score from comparing the two. Face images used for recognition are biometric data.
Billing
Plan, billing period, number of active employees, invoices and payment status. Card details are entered on and held by our payment processor, Stripe; we never receive full card numbers.
Technical and security data
Sign-in session data, IP addresses and request information in server logs, usage counts for features with fair-use limits, and audit records of administrative actions.
Communications
What you send us when you contact support or billing.
4. Sensitive personal data: health and biometrics
Medical certificates and face scans are sensitive personal data under the PDPA and need the explicit consent of the person concerned.
- Customers must obtain that consent from each employee before they upload medical documents or use face attendance, tell employees how the data is used, and offer a reasonable alternative to anyone who does not consent.
- A face scan is compared only with that same employee's own reference photo, to confirm who is clocking in. It is not used to identify anyone else, not shared between companies, and not used for any other purpose.
- Scan photos are deleted automatically after 90 days. A reference photo is kept until HR resets it or the employee's record is deleted.
- Medical certificates can be opened only by the employee, their reporting manager and the Customer's HR.
5. How we use personal data
We use personal data to:
- provide Humio: sign-in, routing requests to the right approver, calculating leave balances, recording attendance, and keeping approval histories;
- read receipts automatically and suggest values for the employee to confirm, and compare face scans to confirm attendance;
- run subscriptions and billing, including counting active employees and applying fair-use limits;
- keep the service secure: enforcing separation between companies, preventing abuse, investigating incidents, and keeping audit records;
- provide support and send service messages such as invitations, trial reminders and billing notices;
- meet our legal, tax and accounting obligations.
We do not sell personal data, use it for advertising, or use Customer data to train our own models.
Automated processing
Receipt reading only suggests values, which the employee confirms before submitting, and approvers can see where a scanned amount was changed. Face matching decides whether a scan counts as a clock-in; if it fails, HR can record attendance another way. Neither makes a decision about pay, leave or employment on its own.
6. Who we share it with
Within a Customer
People in the same company see what their role allows: approvers see the requests routed to them, HR and Admins see their company's records. No one sees another company's data.
Service providers (sub-processors)
| Provider | What they do | Location |
|---|---|---|
| Amazon Web Services | Hosting, database, file storage, sign-in and email (Amazon Cognito), receipt reading (Amazon Textract) and face comparison (Amazon Rekognition) | [AWS region, e.g. Asia Pacific (Singapore)] |
| Stripe | Subscription payments, invoices and card details | Stripe's global infrastructure |
Each is bound by data protection terms and processes data only to provide their service to us. Under AWS's service terms, AWS may store content processed by Textract and Rekognition, possibly in another region, to improve those services.
Our own staff
A small number of authorised staff can see account-level information — company, plan, and each user's name, email, role and sign-in status — to run billing and provide support. Every such view is logged. We access other Customer data only when needed to resolve an issue you have raised, or as required by law.
Legal requirements and business transfers
We may disclose data where required by law or a lawful request from authorities, to protect rights and safety, or to a successor if our business is sold or reorganised, who must honour this policy.
7. Transfers outside Malaysia
Data is stored with Amazon Web Services in [AWS region, e.g. Asia Pacific (Singapore)], and payment data is processed by Stripe, which may be outside Malaysia. We transfer data only where the destination has substantially similar data protection laws or adequate safeguards are in place, such as our providers' data processing terms, as the PDPA requires.
8. How long we keep it
| Data | Kept |
|---|---|
| Employee records, leave, claims, receipts and leave attachments | For as long as the Customer's account exists. Businesses generally must keep financial records for seven years, so we never delete receipts automatically while an account is active. After an account ends, kept for at least 90 days so the Customer can export them, then may be deleted. |
| Clock-in and clock-out scan photos | 90 days, then deleted automatically. |
| Face reference photos | Until HR resets them or the employee's record is deleted. |
| Record exports | 7 days after they are prepared, then deleted. |
| Server logs | One month; audit records of administrative and billing actions, one year. |
| Our billing and invoice records | Seven years, for our own tax and accounting obligations. |
A Customer can export its expense records at any time, including after its subscription has ended.
9. How we protect it
- Data is encrypted in transit and at rest.
- Every company's data is kept separate, and each request is checked on our servers against the company and role of the person making it.
- Receipts, medical certificates and face photos are never publicly accessible; they open only through short-lived links issued to people allowed to see them.
- Approval histories cannot be edited, and administrative actions are logged.
No system is perfectly secure. If a data breach affects personal data we process for a Customer, we will tell that Customer promptly and help it meet its obligations. Where we are responsible, we will notify the Personal Data Protection Commissioner within 72 hours and affected individuals where the law requires.
10. Your rights
Under the PDPA you may:
- ask for access to, and a copy of, your personal data;
- ask for inaccurate or incomplete data to be corrected;
- withdraw consent, including for biometric or health data;
- ask us to stop direct marketing;
- ask for your data to be transferred to another provider;
- complain to the Personal Data Protection Commissioner.
For data in your employer's Humio account, please ask your employer. For anything else, email [privacy@your-domain]. We respond within 21 days and may need to verify your identity first. Withdrawing consent for face scans means you will need another way to record attendance with your employer.
11. Cookies and similar technology
We use only what the service needs to work: cookies and browser storage that keep you signed in, and remember your theme and sidebar preferences. We do not use analytics or advertising cookies.
Stripe's checkout and billing pages, which open on Stripe's own website, set their own cookies under Stripe's privacy policy.
12. Children
Humio is a workplace service and is not intended for anyone under 18.
13. Changes to this policy
We will post any change here with a new effective date. For material changes we will also notify Customer Admins by email or in the app before the change takes effect.
14. Contact us
[Company legal name] Sdn. Bhd.
[Registered business address], Malaysia
Data Protection Officer: [Name or role of your Data Protection Officer]
Email: [privacy@your-domain]
See also our Terms of Service.