Privacy Policy
Last updated: January 15, 2026
Introduction
AlanHR ("we", "our", or "us") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our HR management platform.
This policy applies to information we collect through our website and services. Please read this privacy policy carefully. If you do not agree with the terms of this privacy policy, please do not access the site or use our services.
Information We Collect
Personal Information
We collect information that you provide directly to us, including:
- Name and contact information (email address)
- Account credentials (username, password)
- Company information (company name, size)
- Payment information (processed securely through Stripe)
- Employee data that you input into the system
- Communication data when you contact us for support
Automatically Collected Information
When you access our services, we automatically collect certain information:
- Device information (browser type, operating system)
- Usage data (pages viewed, features used, time spent)
- IP address and general location information
- Cookies and similar tracking technologies (see our Cookie Policy)
How We Use Your Information
We use the information we collect for the following purposes:
- Service Delivery: To provide, maintain, and improve our HR management platform
- Authentication: To verify your identity and manage your account
- Payment Processing: To process subscriptions and payments through our payment processor, Stripe
- Communication: To send you service updates, security alerts, and support messages
- Security: To protect against fraud, abuse, and security threats
- Compliance: To comply with legal obligations and enforce our terms
- Analytics: To understand how our services are used and improve user experience (only with your consent)
Legal Basis for Processing (GDPR)
If you are located in the European Economic Area (EEA) or United Kingdom, we process your personal information based on the following legal grounds:
- Contract Performance: Processing necessary to provide our services under our agreement with you
- Consent: Where you have given explicit consent for specific processing activities
- Legitimate Interests: For fraud prevention, security, and service improvement
- Legal Obligation: To comply with applicable laws and regulations
Information Sharing and Disclosure
We do not sell your personal information. We may share your information in the following circumstances:
- Service Providers: With trusted third-party vendors who assist in operating our platform (e.g., Stripe for payments, hosting providers)
- Legal Requirements: When required by law or to respond to legal process
- Business Transfers: In connection with a merger, acquisition, or sale of assets
- With Your Consent: When you explicitly authorize us to share your information
Data Security
We implement appropriate technical and organizational measures to protect your personal information against unauthorized access, alteration, disclosure, or destruction. These measures include:
- Encryption of data in transit and at rest
- Secure authentication mechanisms
- Regular security assessments
- Access controls and monitoring
- Employee training on data protection
However, no method of transmission over the internet or electronic storage is 100% secure. While we strive to protect your information, we cannot guarantee absolute security.
Data Retention
We retain your personal information for as long as necessary to fulfill the purposes outlined in this Privacy Policy, unless a longer retention period is required or permitted by law. When you delete your account, we will delete or anonymize your personal information within 90 days, except where we are required to retain it for legal or regulatory purposes.
Your Rights
Depending on your location, you may have the following rights regarding your personal information:
- Access: Request access to your personal information
- Correction: Request correction of inaccurate or incomplete data
- Deletion: Request deletion of your personal information
- Portability: Request a copy of your data in a portable format
- Objection: Object to certain processing of your information
- Restriction: Request restriction of processing
- Withdraw Consent: Withdraw consent at any time where processing is based on consent
To exercise these rights, please contact us at privacy@alanhr.com. We will respond to your request within 30 days.
If you are located in the EEA or UK, you also have the right to lodge a complaint with your local data protection authority.
International Data Transfers
Your information may be transferred to and processed in countries other than your country of residence. These countries may have data protection laws that are different from the laws of your country. When we transfer your information internationally, we implement appropriate safeguards to protect your information in accordance with this Privacy Policy.
Children's Privacy
Our services are not intended for individuals under the age of 18. We do not knowingly collect personal information from children. If we become aware that we have collected personal information from a child without parental consent, we will take steps to delete that information.
Changes to This Privacy Policy
We may update this Privacy Policy from time to time. We will notify you of any material changes by posting the new Privacy Policy on this page and updating the "Last updated" date. Your continued use of our services after such changes constitutes your acceptance of the updated policy.
Contact Us
If you have any questions about this Privacy Policy or our privacy practices, please contact us at:
Email: privacy@alanhr.com
Data Protection Officer: For GDPR-related inquiries, contact our DPO at dpo@alanhr.com