1. Who We Are
StreamHCM (“we”, “us”, “our”) provides cloud-based HR management software to organisations across Pakistan. This Privacy Policy applies to our website and all associated services.
2. Data We Collect
We collect the following categories of personal data through the StreamHCM platform:
- Account data: Name, email address, company name, job title, and phone number provided during signup and login.
- Employee records (processed on behalf of client companies): Names, CNIC/national ID, contact details, designations, departments, branches, salary structures, bank details, and employment lifecycle events (joining, transfer, promotion, resignation, termination).
- Attendance & biometric data: Check-in/out timestamps, GPS location for field check-ins, and biometric identifiers (face recognition templates and fingerprint data) synced from connected biometric devices (e.g. ZKTeco, eSSL, Suprema, Fingertec) for attendance verification.
- Payroll & financial data: Salary components, allowances, deductions, overtime, loans/advances, EOBI and tax contributions, and payslip records.
- Documents: Contracts, certificates, and other files employees or admins upload, stored in encrypted cloud object storage.
- Device & session data: IP address, browser/device type, and authentication tokens used to keep you securely signed in.
- Communication data: In-app notifications, push notification tokens, and emails sent via our transactional email provider.
- Billing data: Subscription plan, invoice, and payment status. We do not store full card numbers on our servers.
3. How We Use Your Data
We use personal data to:
- Provide core HRMS functionality: attendance tracking, leave management, shift scheduling, payroll processing, and reporting.
- Match and verify biometric check-ins against enrolled templates for accurate, fraud-resistant attendance.
- Calculate and process payroll, EOBI contributions, and tax deductions on behalf of client companies.
- Send transactional emails and push notifications (approvals, payslips, policy updates, system alerts).
- Maintain audit and activity logs for security, compliance, and dispute resolution.
- Detect and prevent fraudulent, abusive, or unauthorised use of the platform.
- Comply with legal and regulatory obligations, including labour and tax law in Pakistan.
4. Biometric Data
Where a client company enables biometric attendance (face recognition or fingerprint devices), StreamHCM processes biometric templates strictly to verify employee identity for check-in/check-out. Biometric templates are stored securely, are never sold, and are only used for the attendance and access-control purposes configured by the client company. Client companies are responsible for obtaining any consent required from their employees under applicable law before enabling biometric attendance.
5. Data Sharing & Disclosure
We do not sell your personal data. We share data only with sub-processors who help us operate the Service, under contractual confidentiality and security obligations:
- Cloud database hosting (PostgreSQL) for structured HR, payroll, and attendance data.
- Encrypted cloud object storage (Cloudflare R2) for uploaded documents and files.
- Email delivery provider (SMTP) for transactional emails such as payslips and approvals.
- Push notification service (Firebase Cloud Messaging) for mobile and web alerts.
- Biometric device manufacturers' local sync protocols (ZKTeco, eSSL, Suprema, Fingertec), device data stays within the client's configured environment.
6. Data Retention
We retain account and employee data for the duration of your subscription and for a further 90 days after termination to allow data export. Employee and biometric data processed on behalf of client companies is retained per the client's instructions and deleted or anonymised on request, subject to legal retention requirements (e.g. payroll and tax records). Audit and activity logs are retained for security and compliance purposes.
7. Security
StreamHCM uses industry-standard security measures to protect your data, including:
- TLS/HTTPS encryption for all data in transit.
- Encrypted cloud object storage for uploaded documents and files.
- JWT-based authentication with short-lived access tokens and separate refresh tokens.
- Role-based access controls (RBAC) limiting who can view salaries, biometric data, or admin settings.
- Rate limiting and multi-tenant data isolation, each client company's data is logically separated.
- Full audit logs and activity logs tracking every sensitive change.
8. Your Rights
Depending on applicable law, you may have the right to access, correct, or request deletion of your personal data, restrict or object to processing, receive your data in a portable format, and withdraw consent at any time. To exercise any right, contact us at hello@streamhcm.com. We will respond within 30 days.
9. Changes to This Policy
We may update this Privacy Policy periodically. We will notify you of material changes by email or by displaying a notice in the platform. Your continued use of the Service after changes take effect constitutes acceptance of the updated policy.
