Privacy Policy
1. Introduction
BeehubHR is a Human Resource Management System (HRMS) designed to help organisations manage employee information, attendance, payroll-related processes, and related HR functions. Protecting the privacy of individuals is important to us. This policy explains the types of information we collect, how we use it, who we share it with, the legal bases on which we process it, and the choices and rights available to users under applicable laws such as the GDPR, CCPA/CPRA, and India's Digital Personal Data Protection Act, 2023 (DPDP Act).
This Privacy Policy applies to the BeehubHR web application, mobile applications, and related services offered to organisations and their employees.
2. Basic Information
2.1 Legal Entity
BeehubHR (hereinafter referred to as "the Application", "the Website", or "the Platform") is owned and operated by Remitbee Incorporated, a company duly registered and existing under the laws of Canada. For the purposes of the India DPDP Act, Remitbee Incorporated acts as a Data Fiduciary to the extent that it determines the purposes and means of processing personal data through the Platform. Each client organisation using BeehubHR also acts as a Data Fiduciary for its own employees' data.
2.2 Registered Office
The registered office of Remitbee Incorporated is located at:
No. 36/1, 3rd floor, Ceebros Knowledge Tower, Little Mount,Saidapet, Chennai, Tamil Nadu 600015
India.
2.3 Data Protection Officer
For users located in the European Economic Area (EEA), the United Kingdom, and other jurisdictions where a Data Protection Officer (DPO) is required or recommended, Remitbee Incorporated has designated the following contact for data protection matters:
2.4 Contact Information
For any questions, concerns, or requests regarding this Privacy Policy or your personal data, please contact us via email at:
We will make every effort to respond to all privacy-related inquiries within a reasonable time frame, and in any case within the timelines required by applicable law.
3. Information We Collect
3.1 Overview
To provide an efficient and personalized Human Resource Management experience, BeehubHR collects and processes certain types of information from users. The categories of information we collect depend on how you use the Platform, whether as an organisation administrator, employee, or HR manager.
3.2 Personal Information Provided by Users
When you or your organisation use the Platform, we may collect the following categories of personal information:
- Identity and Contact Information: Name, email address, phone number, physical address, and other basic identity details.
- Employment and Organisational Information: Job title, employee identification number, reporting manager details, employment status, department, and associated organisation.
- Attendance and Work-Related Data: Work attendance records, leave details, shift information, and payroll-related data. This includes automatically tracked work hours based on system clock-in/clock-out activity and automatic clock-out when pre-defined maximum working hours are exceeded.
- Compensation and Financial Information: Salary details, allowances, deductions, and other payroll information necessary for organisational HR and payroll management.
Currently, BeehubHR allows organisations to store certain documents or files related to HR and employee management. These files are securely stored with reputable cloud storage providers under strict access control and encryption policies.
3.3 Sensitive Information
In certain circumstances, we may process sensitive personal information necessary for HR and compliance purposes, including:
- Government-issued identification details such as PAN or Aadhaar numbers, where required by law or for payroll and statutory compliance.
- Salary information as part of payroll management.
- Basic health-related information such as age and blood group, solely for internal HR recordkeeping or emergency purposes.
BeehubHR ensures that such data is handled with appropriate security safeguards and in compliance with applicable data protection laws. Where required by law, additional protections and safeguards are applied to sensitive data.
3.4 Automatically Collected Information
When you access the Platform through the website or mobile applications, certain information is automatically collected to ensure service performance, analytics, and compatibility. This includes:
- Platform usage data such as the device type (web, Android, iOS), operating system, and version.
- Technical information including browser type, application logs, error logs, and timestamps of activity.
- Login and logout times, as well as automatic clock-out events for attendance and time-tracking purposes.
We do not collect continuous activity monitoring or GPS location data. This information helps us optimize user experience, improve performance, and maintain security.
3.5 Cookies and Local Storage
BeehubHR uses local storage mechanisms and session management tools to ensure secure, seamless, and persistent access to the Platform. These include:
- Session Storage
- Redux State Storage
- Local Async Storage
- Shared Preferences
- Local Storage for web, Android, and iOS applications
These technologies help in storing user preferences, maintaining active sessions, and enabling certain offline or state-preserving functionality. We do not use third-party advertising cookies or cross-site tracking technologies at this time.
3.6 Data Accuracy
Organisations using BeehubHR are responsible for ensuring that the data entered into the Platform is accurate and up to date. Users are encouraged to verify their information regularly and report any inaccuracies to their HR department or system administrator.
4. Legal Basis for Processing (GDPR and Similar Laws)
Where the General Data Protection Regulation (GDPR), the UK GDPR, or similar laws apply, BeehubHR relies on specific legal bases for processing personal data:
- Contractual Necessity: Processing is necessary to perform a contract or to take steps at the request of the data subject prior to entering into a contract. This includes the creation and maintenance of user accounts, employee records, attendance tracking, and access to HR functionality.
- Legal Obligation: Processing is necessary to comply with legal obligations, such as maintaining payroll records, tax-related records, and statutory reporting obligations, including the use of PAN and similar identifiers where required.
- Contractual Necessity and Legal Obligation (Combined): Payroll and compensation data are processed both to fulfil employment-related arrangements and to comply with statutory obligations.
- Legitimate Interests: In limited cases, we may process data to support our legitimate interests or those of an organisation using BeehubHR, such as improving the Platform, maintaining security, preventing misuse, and performing internal analytics, provided these interests are not outweighed by the rights and freedoms of individuals.
- Vital Interests: Basic health-related information such as blood group may be processed when necessary to protect the vital interests of an individual in emergency situations.
BeehubHR does not rely on consent as the primary legal basis for HR-related data processing, as employees may not be in a position to freely give or withhold consent without consequences.
5. How We Use Information
5.1 Purpose of Processing
BeehubHR collects and processes personal information strictly for legitimate business purposes related to human resource and payroll management within an organisation. The information is used solely to facilitate HR operations and ensure smooth functioning of the Platform. We do not sell, rent, or share personal data with third parties for marketing or unrelated commercial purposes.
5.2 Primary Uses of Information
The personal data collected through the Platform may be used for the following purposes:
- Employee Management: To maintain employee profiles, manage attendance, leaves, performance-related records, and HR workflows.
- Payroll Processing: To calculate and process employee salaries, deductions, benefits, and statutory payments in accordance with company policies and legal requirements.
- Communication and Notifications: To send system-generated notifications or alerts regarding leave approvals, attendance regularisations, policy updates, or other HR-related actions.
- Access Control and Authentication: To verify user identity, maintain secure login sessions, and manage user roles and permissions within the Platform.
- System Maintenance and Support: To monitor, maintain, and improve the functionality, reliability, and security of the Platform for authorized users.
- Security and Misuse Prevention: To detect and prevent unauthorized access, abuse, or misuse of the Platform and to protect the rights, property, and safety of users and the organisation.
5.3 Internal Use Only
All personal data processed by BeehubHR remains accessible only to authorized personnel within the respective organisation and to system administrators of Remitbee Incorporated as required for technical maintenance, support, and troubleshooting. Data is never sold to external third parties.
5.4 Legal Compliance and Safety
Where necessary, BeehubHR may use or disclose personal information to comply with legal obligations, respond to lawful requests from public authorities, resolve disputes, or enforce applicable terms of service. Such disclosures will only occur in compliance with applicable laws and with adequate safeguards in place to protect user privacy.
5.5 Automated Processes and Decision-Making
BeehubHR uses certain automated processes to improve operational efficiency, such as automatically marking attendance status based on clock-in activity, scheduled shifts, or automatic clock-out when configured maximum working hours are exceeded. This includes automatically tracking work hours based on the time of system log-in and log-out.
These automated actions are administrative in nature and are used to support HR and payroll operations. BeehubHR does not use automated decision-making systems to make employment decisions with legal or similarly significant effects on users (such as automated hiring, termination, or promotion decisions). Any HR decisions based on attendance or performance data remain subject to organisational policies and human review.
If BeehubHR introduces automated decision-making tools in the future that have such effects, affected users will be provided with appropriate information and rights, including the right to obtain human review where required by law.
6. Data Sharing and Disclosure
6.1 Overview
BeehubHR respects the privacy of all users and organisations using the Platform. We do not sell, rent, or trade personal information to any third parties. All data collected through the Platform is used strictly for internal HR and payroll management purposes within the respective organisation and for the operation and improvement of the Platform.
6.2 Trusted Third-Party Service Providers
To operate the Platform effectively and ensure reliable performance, BeehubHR relies on certain trusted third-party service providers. These providers assist in delivering specific functionalities essential to the Platform's operation and maintenance, including:
- Email Communication Services: For sending system-generated communications such as account notifications, leave approvals, and password resets.
- File and Document Storage Services: For securely storing documents and attachments uploaded by users or organisations with enterprise-grade encryption and redundancy.
- Hosting and Cloud Infrastructure Providers: For running the BeehubHR Platform on secure, cloud-based infrastructure that supports data hosting, backup, and infrastructure monitoring.
All such third parties act solely as data processors on behalf of BeehubHR and are contractually bound to maintain the confidentiality, integrity, and security of the data. They are not authorized to access or use personal information for any purpose other than performing their designated service functions.
6.3 Internal Access Control
Access to personal data within BeehubHR is strictly limited to authorized personnel who require it to perform operational or technical duties such as customer support, troubleshooting, and maintenance. All such personnel are subject to confidentiality obligations and data protection standards consistent with company policy.
6.4 Legal Obligations
BeehubHR may disclose personal information only where required by applicable law, regulation, or legal process, or in response to valid governmental or judicial requests. Such disclosures will always be carried out in a manner that ensures the protection of user privacy and complies with relevant data protection legislation.
6.5 Aggregated and Non-Personal Information
BeehubHR may use aggregated or anonymized data for internal research, analytics, and service enhancement. This information does not personally identify any individual user and falls outside the scope of personal data under applicable laws.
7. Data Retention
7.1 Retention Policy
BeehubHR retains personal and organisational data only for as long as it is necessary to fulfil the purposes described in this Privacy Policy, including HR operations, payroll processing, security, and legal compliance.
7.2 Retention Duration and Anonymization
In general, personal data is retained for:
- The duration of an individual's employment and active use of the Platform, and
- An additional period as required or permitted by law for recordkeeping, audit, and compliance purposes.
After the applicable retention period, personal data may be:
- Permanently deleted, or
- Irreversibly anonymized so that it no longer identifies any individual.
BeehubHR may retain non-identifiable, anonymized HR data indefinitely for analytics, reporting, trend analysis, and service improvement, provided such data cannot be used to re-identify individuals.
7.3 Administrative Control and Deletion Rights
Organisations and authorized administrators using the BeehubHR Platform have full control over the data they manage. They may at any time:
- Permanently delete individual employee records ("hard delete") from their organisation's database within the Platform.
- Remove user accounts or entire organisational datasets as needed for compliance, restructuring, or internal policy requirements.
Once data is hard deleted by an administrator, it is permanently erased from the active systems and cannot be restored by BeehubHR. Certain anonymized or aggregated data may remain for statistical purposes, but will no longer be linked to any identifiable individual.
7.4 Backup and Archival Copies
System backups may temporarily retain deleted data for technical and recovery purposes. Such data remains securely encrypted and is automatically overwritten or purged in accordance with BeehubHR's data management and security protocols.
7.5 Legal and Regulatory Compliance
In certain cases, BeehubHR or the organisation may be required to retain specific records to comply with applicable laws, audit requirements, or regulatory obligations. These exceptions will always align with lawful retention requirements and data minimization principles.
8. Data Security
8.1 Commitment to Security
BeehubHR takes the protection of personal and organisational data seriously. We implement robust technical and organisational measures designed to maintain the confidentiality, integrity, and availability of all information processed through the Platform.
8.2 Data Encryption
All data transmitted between users and the BeehubHR servers is protected using Secure Socket Layer (SSL) and Transport Layer Security (TLS) protocols via HTTPS. This ensures that sensitive information such as login credentials and employee data remains secure during transmission. Data stored within the Platform is safeguarded using encryption and hashing mechanisms. Passwords and other sensitive information are stored in encrypted form and are not accessible in plain text at any point.
8.3 Access Control
Access to data within BeehubHR is governed by a structured role-based access control (RBAC) system, which restricts information access based on user roles and responsibilities. The following access levels are defined within the Platform:
- Super Admin: Full system-level access to manage all organisations, configurations, and administrative functions.
- Admin: Organisational-level access for managing employees, payroll, attendance, and HR operations within a specific company.
- Manager: Limited access to departmental or team-level data for reviewing attendance, approving leave requests, and managing subordinate activities.
- Employee: Restricted access to their own personal, attendance, and leave information.
Each role is designed to ensure that users only access data relevant to their scope of responsibility.
8.4 Infrastructure and Monitoring
BeehubHR operates on a secure cloud infrastructure that incorporates continuous monitoring, intrusion detection, and regular security assessments. All system access is logged, and activities are audited periodically to ensure compliance with security best practices and to detect potential abuse or misuse.
8.5 Incident Management
In the unlikely event of a data breach or unauthorized access, BeehubHR has a defined incident response process. Affected organisations will be notified promptly in accordance with applicable laws and regulations, along with details of remedial actions taken to mitigate the impact.
8.6 User Responsibility
While BeehubHR implements strong safeguards, users and organisations are responsible for maintaining the confidentiality of their login credentials and ensuring appropriate use of the Platform. Unauthorized sharing of credentials or improper access management may compromise data security.
9. User Rights and Choices
9.1 Overview
BeehubHR values transparency and accountability in the way personal data is managed. We are committed to ensuring that users and organisations retain control over their information and can exercise their rights in accordance with applicable data protection laws.
9.2 Access to Information
Employees and users with authorized access can view their personal and employment-related information through the BeehubHR Platform. This includes details such as contact information, attendance, leave records, and payroll data, as provided by their organisation.
9.3 Correction and Updates
Employees do not have direct editing privileges for their personal data in most cases. If any information is inaccurate, outdated, or incomplete, users must contact their organisation's administrator to request the necessary corrections. The administrator can update the data through the administrative control panel within the Platform.
9.4 Data Deletion Requests
Users who wish to delete their account or associated personal data may do so by submitting a request to their respective organisation's administrator or by contacting BeehubHR support at:
Upon receiving a valid request, the organisation or BeehubHR team will process the deletion in accordance with internal verification procedures and applicable legal obligations. Once deleted from active systems, the data cannot be recovered.
9.5 Organisational Rights
Each organisation using BeehubHR has full administrative control over its data. Administrators may:
- Access, update, or correct employee data as required for HR operations.
- Hard delete employee records or organisation-level datasets at their discretion, subject to applicable laws.
9.6 Right to Object or Restrict Processing
Users may contact BeehubHR if they have concerns regarding the processing of their data. Requests to restrict or object to processing will be handled in coordination with the organisation's administrator and in compliance with applicable legal requirements, particularly where processing is based on legitimate interests.
9.7 Response Time
BeehubHR and the respective organisation will make reasonable efforts to respond to access, correction, or deletion requests within a reasonable period of time, typically within 30 days of receipt, or within any shorter period required by applicable law.
9.8 Additional Rights for EEA and UK Users (GDPR/UK GDPR)
Where the GDPR or UK GDPR applies, individuals may have additional rights, including:
- The right to data portability, allowing them to receive certain personal data in a structured, commonly used, and machine-readable format and to transmit it to another controller.
- The right to object to processing based on legitimate interests, on grounds relating to their particular situation.
- The right to request restriction of processing in certain circumstances.
- The right to withdraw consent where processing is based on consent (without affecting the lawfulness of processing prior to withdrawal).
- The right not to be subject to a decision based solely on automated processing, including profiling, which produces legal effects or similarly significant effects; as noted above, BeehubHR does not use such automated decision-making.
- The right to lodge a complaint with a competent supervisory authority in the EEA or UK.
Requests to exercise these rights may be submitted to beehubhr@gmail.com and will be handled in accordance with applicable law.
9.9 Additional Rights for California Residents (CCPA/CPRA)
For residents of California, BeehubHR provides the following rights under the California Consumer Privacy Act (CCPA) as amended by the California Privacy Rights Act (CPRA):
- Right to Know: You may request information about the categories of personal information collected, the purposes for which it is used, and the categories of third parties to whom it is disclosed.
- Right to Access: You may request copies of specific pieces of personal information that we hold about you, subject to verification and applicable exceptions.
- Right to Delete: You may request deletion of personal information, subject to certain exceptions (for example, where data is required for legal or HR purposes).
- Right to Correct: You may request correction of inaccurate personal information.
- Right to Non-Discrimination: You will not be discriminated against for exercising your CCPA/CPRA rights.
Do Not Sell or Share My Personal Information: BeehubHR does not sell or share personal information as "sell" or "share" are defined under the CCPA/CPRA. Accordingly, we do not offer a separate mechanism to opt out of the sale or sharing of personal information. If this changes in the future, this Privacy Policy will be updated and appropriate opt-out mechanisms will be provided.
California residents may exercise their rights or submit questions by contacting:
9.10 Additional Rights for Users in India (DPDP Act)
Under the Digital Personal Data Protection Act, 2023, users in India may have the right to:
- Access personal data processed about them.
- Request correction or updating of inaccurate or incomplete data.
- Request erasure of personal data in accordance with applicable law and organisational requirements.
- Register grievances regarding the processing of personal data.
BeehubHR aims to address grievances and requests from users in India within 30 days from the date of receipt, in line with DPDP requirements.
10. International Data Transfers
10.1 Overview
BeehubHR is a global platform operated by Remitbee Incorporated, headquartered in Canada. While the Platform is accessible to organisations and users across multiple countries, personal and organisational data processed through BeehubHR is primarily stored and managed on secure cloud servers located in Canada or other jurisdictions with appropriate safeguards.
10.2 Cross-Border Data Access
Users and organisations from various regions, including but not limited to Canada, India, Europe, and Ukraine, may access the Platform remotely. Such access may involve the transfer of limited personal data across borders as part of normal Platform usage, such as authentication, communication, and HR-related transactions.
10.3 Data Protection Standards
All data stored and processed by BeehubHR is subject to privacy and data protection standards consistent with applicable laws. We ensure that international data transfers occur with appropriate safeguards, including:
- Secure and encrypted data transmission using HTTPS (SSL/TLS) protocols.
- Strict access controls and role-based permissions for authorized personnel only.
- Contractual and technical measures consistent with global data protection norms, including GDPR-equivalent protections where required.
10.4 User Consent for International Access
By using the BeehubHR Platform and services, users and organisations acknowledge and consent that their information may be transferred to and processed in Canada and other jurisdictions, regardless of their country of origin. These transfers are carried out solely for the purpose of providing the HR and payroll services described in this Policy.
11. Updates to This Policy
11.1 Policy Review and Modification
BeehubHR may update or modify this Privacy Policy from time to time to reflect changes in operational practices, legal requirements, or service enhancements. Any revisions will maintain our commitment to protecting user privacy and ensuring transparent data processing.
11.2 User Notification
When significant updates are made to this Privacy Policy, BeehubHR will notify users and organisations through appropriate channels, which may include email communications, in-application alerts, or website notifications. Continued use of the Platform following such updates constitutes acknowledgment and acceptance of the revised Policy.
11.3 Access to the Latest Version
The latest version of this Privacy Policy will always be available on the official BeehubHR website at:
Users are encouraged to review this Policy periodically to stay informed about how their information is protected and processed.
11.4 Commitment to Transparency
BeehubHR remains committed to maintaining transparency in all privacy-related matters. Any updates will be made with clear communication and without compromising user data rights or protection standards.
12. Contact Information
For any questions or concerns regarding this Privacy Policy or the handling of personal data on the BeehubHR Platform, you may contact us at:
No. 36/1, 3rd floor, Ceebros Knowledge Tower, Little Mount,Saidapet, Chennai, Tamil Nadu 600015
India.
Email: beehubhr@gmail.com