Data Protection & Privacy Governance

Privacy Policy

How PeopleCoreAI processes, safeguards, and respects personal, employee, and organizational data in full compliance with global regulations like GDPR and CCPA.

Effective: January 1, 2026•Last Updated: July 2026

Our Privacy Commitment

Your privacy and employee data confidentiality are fundamental to our architecture. PeopleCoreAI acts as a Data Processor for all employee records uploaded by your employer, processing information strictly according to your organization's administrative instructions.

1Categories of Information We Process

To deliver complete HRIS, attendance, and payroll services, PeopleCoreAI processes the following data categories on behalf of your employer:

Employee Profile Data

Full legal name, work email address, employee ID, job title, department, manager reporting lines, and contact phone number.

Time, Shift & Attendance Logs

Daily check-in and check-out timestamps, assigned work shifts, total work hours, break times, and overtime duration.

Compensation & Payroll Records

Basic wage parameters, allowances, deductions, bonus structures, bank deposit details, and monthly digital payslips.

Leave & Time-Off Requests

Paid time off, sick leave balances, request reasons, manager approvals, and annual accrual histories.

2Geo-Verification & Punch Location Privacy

When optional geo-verified attendance is enabled by your company administrator, location coordinates are captured only at the exact moment you click "Clock In" or "Clock Out" to verify office radius attendance. PeopleCoreAI does not perform background tracking or continuous location monitoring.

3Purposes of Processing & Legal Grounding

All customer data is processed under the legal grounds of:

  • Performance of Contract: Fulfilling the service agreement with your employer to administer employee payroll and shifts.
  • Legal & Statutory Obligations: Enabling employers to maintain mandatory workplace attendance registers and tax records.
  • Legitimate Interests: Securing the application against unauthorized logins and safeguarding organizational data.

4Zero Data Selling Guarantee

We never sell, rent, or trade your employee or company data. We do not monetize data for behavioral advertising or third-party profiling. Your organizational data is strictly used to power your PeopleCoreAI workspace.

5Infrastructure & Trusted Sub-processors

PeopleCoreAI utilizes enterprise cloud sub-processors bound by strict Data Processing Agreements (DPAs):

  • AWS (Amazon Web Services): Encrypted document and asset storage (S3).
  • PostgreSQL Cloud Database: Enterprise database clustering with AES-256 encryption at rest.
  • Stripe: PCI-DSS Level 1 compliant payment processing for SaaS subscriptions (billing details never touch our application servers).
  • ZeptoMail / SMTP: Transactional email distribution for password resets, shift alerts, and payslip notifications.

6GDPR, CCPA & Individual Rights

In accordance with GDPR (EU/UK) and CCPA (California), individuals have rights to:

  • Access & Inspect: View personal profile, attendance records, and historical payslips at any time via Employee Self-Service.
  • Rectification: Request correction of inaccurate personal or banking records through your company HR administrator.
  • Data Portability: Export personal records and monthly payslips in standard PDF format.
  • Right to Erasure: Employer administrators can request complete data decommissioning upon service termination.

7Data Retention & Secure Deletion

Customer data is retained for the active duration of the employer's subscription. Upon account termination, a thirty (30) day export grace period is provided, after which all customer databases, backup snapshots, and stored documents are permanently purged in accordance with DoD 5220.22-M sanitization standards.

Privacy Officer & Data Inquiries

For questions regarding our privacy practices or to exercise your data rights.