Draft: company details in this document are not filled in yet, and it has not been reviewed. It is not yet in effect.

Privacy Policy

Effective [Effective date, e.g. 1 November 2026]

In short: your employer controls the HR data it puts into Humio, and we process it to run the service. We collect only what the service needs, including sensitive data — medical certificates and face scans — that your employer must have your consent for.

We don't sell data or use it for advertising, face scan photos are deleted after 90 days, and you can ask to access or correct your data at any time.

1. Who we are and what this covers

Humio is a cloud service for leave, expense claims and attendance, provided by [Company legal name] Sdn. Bhd. (registration no. [SSM registration no.]), [Registered business address], Malaysia (“we”, “us”).

This policy explains how we handle personal data when you visit our website, sign up, or use Humio, and your rights under Malaysia's Personal Data Protection Act 2010 as amended (“PDPA”).

2. Our role: your employer decides, we process

Humio is used by companies (“Customers”) to manage their own employees. For the personal data a Customer puts into Humio about its people — employee records, leave, claims, receipts, attendance and face scans — the Customer is the data controller and decides why and how that data is processed. We process it on the Customer's behalf, only to provide the service and as described in our Terms of Service.

If you are an employee and have a question about your data in Humio, or want to exercise a right over it, please contact your employer first. We will help your employer respond.

We are the data controller for our own data: the accounts of people who sign up for Humio, billing contacts, support conversations, and visitors to our website.

3. Personal data we process

Accounts

Name, work email address, company name and country, and the roles a person holds (Admin, HR, Manager, Employee). Passwords are handled by our authentication provider and stored only in hashed form; we never see them.

Employee records

What a Customer enters: employee number, job title, department, reporting manager, employment type and status, hire and exit dates, work location, phone number and which public holiday calendar applies.

Leave

Leave type, dates, reason, contact details during leave, approval decisions and notes, and supporting documents such as medical certificates, which are health data.

Expense claims

Receipt images and the details on them — merchant, date, amounts, tax and currency — including the values our receipt reader extracted, whether the employee changed them, and approval and reimbursement history.

Attendance and face scans

Clock-in and clock-out times, a face reference photo each employee registers, the photos taken at each scan, and a similarity score from comparing the two. Face images used for recognition are biometric data.

Billing

Plan, billing period, number of active employees, invoices and payment status. Card details are entered on and held by our payment processor, Stripe; we never receive full card numbers.

Technical and security data

Sign-in session data, IP addresses and request information in server logs, usage counts for features with fair-use limits, and audit records of administrative actions.

Communications

What you send us when you contact support or billing.

4. Sensitive personal data: health and biometrics

Medical certificates and face scans are sensitive personal data under the PDPA and need the explicit consent of the person concerned.

  • Customers must obtain that consent from each employee before they upload medical documents or use face attendance, tell employees how the data is used, and offer a reasonable alternative to anyone who does not consent.
  • A face scan is compared only with that same employee's own reference photo, to confirm who is clocking in. It is not used to identify anyone else, not shared between companies, and not used for any other purpose.
  • Scan photos are deleted automatically after 90 days. A reference photo is kept until HR resets it or the employee's record is deleted.
  • Medical certificates can be opened only by the employee, their reporting manager and the Customer's HR.

5. How we use personal data

We use personal data to:

  • provide Humio: sign-in, routing requests to the right approver, calculating leave balances, recording attendance, and keeping approval histories;
  • read receipts automatically and suggest values for the employee to confirm, and compare face scans to confirm attendance;
  • run subscriptions and billing, including counting active employees and applying fair-use limits;
  • keep the service secure: enforcing separation between companies, preventing abuse, investigating incidents, and keeping audit records;
  • provide support and send service messages such as invitations, trial reminders and billing notices;
  • meet our legal, tax and accounting obligations.

We do not sell personal data, use it for advertising, or use Customer data to train our own models.

Automated processing

Receipt reading only suggests values, which the employee confirms before submitting, and approvers can see where a scanned amount was changed. Face matching decides whether a scan counts as a clock-in; if it fails, HR can record attendance another way. Neither makes a decision about pay, leave or employment on its own.

6. Who we share it with

Within a Customer

People in the same company see what their role allows: approvers see the requests routed to them, HR and Admins see their company's records. No one sees another company's data.

Service providers (sub-processors)

ProviderWhat they doLocation
Amazon Web ServicesHosting, database, file storage, sign-in and email (Amazon Cognito), receipt reading (Amazon Textract) and face comparison (Amazon Rekognition)[AWS region, e.g. Asia Pacific (Singapore)]
StripeSubscription payments, invoices and card detailsStripe's global infrastructure

Each is bound by data protection terms and processes data only to provide their service to us. Under AWS's service terms, AWS may store content processed by Textract and Rekognition, possibly in another region, to improve those services.

Our own staff

A small number of authorised staff can see account-level information — company, plan, and each user's name, email, role and sign-in status — to run billing and provide support. Every such view is logged. We access other Customer data only when needed to resolve an issue you have raised, or as required by law.

Legal requirements and business transfers

We may disclose data where required by law or a lawful request from authorities, to protect rights and safety, or to a successor if our business is sold or reorganised, who must honour this policy.

7. Transfers outside Malaysia

Data is stored with Amazon Web Services in [AWS region, e.g. Asia Pacific (Singapore)], and payment data is processed by Stripe, which may be outside Malaysia. We transfer data only where the destination has substantially similar data protection laws or adequate safeguards are in place, such as our providers' data processing terms, as the PDPA requires.

8. How long we keep it

DataKept
Employee records, leave, claims, receipts and leave attachmentsFor as long as the Customer's account exists. Businesses generally must keep financial records for seven years, so we never delete receipts automatically while an account is active. After an account ends, kept for at least 90 days so the Customer can export them, then may be deleted.
Clock-in and clock-out scan photos90 days, then deleted automatically.
Face reference photosUntil HR resets them or the employee's record is deleted.
Record exports7 days after they are prepared, then deleted.
Server logsOne month; audit records of administrative and billing actions, one year.
Our billing and invoice recordsSeven years, for our own tax and accounting obligations.

A Customer can export its expense records at any time, including after its subscription has ended.

9. How we protect it

  • Data is encrypted in transit and at rest.
  • Every company's data is kept separate, and each request is checked on our servers against the company and role of the person making it.
  • Receipts, medical certificates and face photos are never publicly accessible; they open only through short-lived links issued to people allowed to see them.
  • Approval histories cannot be edited, and administrative actions are logged.

No system is perfectly secure. If a data breach affects personal data we process for a Customer, we will tell that Customer promptly and help it meet its obligations. Where we are responsible, we will notify the Personal Data Protection Commissioner within 72 hours and affected individuals where the law requires.

10. Your rights

Under the PDPA you may:

  • ask for access to, and a copy of, your personal data;
  • ask for inaccurate or incomplete data to be corrected;
  • withdraw consent, including for biometric or health data;
  • ask us to stop direct marketing;
  • ask for your data to be transferred to another provider;
  • complain to the Personal Data Protection Commissioner.

For data in your employer's Humio account, please ask your employer. For anything else, email [privacy@your-domain]. We respond within 21 days and may need to verify your identity first. Withdrawing consent for face scans means you will need another way to record attendance with your employer.

11. Cookies and similar technology

We use only what the service needs to work: cookies and browser storage that keep you signed in, and remember your theme and sidebar preferences. We do not use analytics or advertising cookies.

Stripe's checkout and billing pages, which open on Stripe's own website, set their own cookies under Stripe's privacy policy.

12. Children

Humio is a workplace service and is not intended for anyone under 18.

13. Changes to this policy

We will post any change here with a new effective date. For material changes we will also notify Customer Admins by email or in the app before the change takes effect.

14. Contact us

[Company legal name] Sdn. Bhd.
[Registered business address], Malaysia
Data Protection Officer: [Name or role of your Data Protection Officer]
Email: [privacy@your-domain]

See also our Terms of Service.