Privacy Policy
Last updated: 4 Aug 2026
1. Who we are
CirroPeople provides human resources software to businesses. This policy explains how we handle personal data in two distinct roles, which matters for your rights and for who you should contact.
- As a controller for the people who deal with us directly: account holders, billing contacts and website visitors.
- As a processor for the HR data our customers put into the platform about their own employees, interns, contractors and candidates. There, the employing organization is the controller and decides what is collected and why.
If you are an employee of a company that uses CirroPeople and want to access or correct your data, contact your employer's HR team first — they control that record. We will help them respond.
2. Data we handle as a controller
- Account data: name, work email, password (stored hashed), language, time zone and profile photograph.
- Organization data: business name, address, industry, size, contact and billing email.
- Billing data: plan, subscription status and invoices. Card details are handled by our payment provider and never reach our servers.
- Usage and security data: sign-in events, audit entries, a hashed form of your IP address and a truncated browser identifier.
- Support data: messages you send us and our replies.
3. Data we process for customers
Customers decide what to record, and the platform supports HR data including contact and employment details, leave and attendance, skills and training, performance reviews, assets, recruitment records, documents and payroll records. Some of this may be sensitive — for example health-related absence information.
We process it only on the customer's documented instructions, to provide and secure the service. We do not sell it, and we do not use it to train models.
4. Why we process data
- To perform our contract: providing the service, authentication, billing and support.
- Legitimate interests: keeping the service secure, preventing abuse, maintaining an audit trail and improving the product.
- Legal obligations: tax, accounting and responding to lawful requests.
- Consent: where we ask for it, such as optional product emails. You may withdraw it at any time.
5. Separation between customers
Every business-owned record carries the organization that owns it, all data access is scoped to a single organization, and the database rejects any access that is not made by the application's service account. We test this with automated checks that attempt cross-organization access and must fail. See our security page for detail.
6. Sharing
We share personal data only with:
- Infrastructure and hosting providers that run the service on our behalf.
- Payment providers, where a customer pays by card or mobile money.
- Email delivery providers, for transactional messages.
- Professional advisers, or authorities where the law requires it.
Each is bound by contract to process data only on our instructions. We do not sell personal data or share it for third-party advertising.
7. Retention
Customer HR data is retained for as long as the customer's account is active, and is deleted after the organization is deleted and its cooling-off period has passed — during which the customer can cancel the deletion and export their data. Audit entries are kept longer where needed for security and legal reasons. Billing records are kept as long as tax law requires.
8. Your rights
Depending on where you live, you may have the right to access, correct, delete, restrict or object to processing, to data portability, and to complain to a supervisory authority. For HR records held by an employer, direct these requests to that employer.
9. International transfers
Data may be processed in countries other than your own. Where that happens we rely on appropriate safeguards, such as standard contractual clauses. Customers with specific data-residency requirements should contact us before subscribing.
10. Cookies
We use strictly necessary cookies only: a signed, HTTP-only session cookie to keep you signed in, a token used to protect against cross-site request forgery, and a cookie recording your chosen display language. We do not use advertising or third-party tracking cookies.
11. Children
CirroPeople is a workplace tool and is not directed at children. We do not knowingly collect data from anyone under 16 other than where an employer records a lawfully engaged young worker.
12. Changes and contact
We will post any changes to this policy on this page and update the date above. For material changes affecting customers we will also give notice in the product. Questions can go to support@cirropeople.com.