1. Roles
You are the controller of the personal data you and your people put into
HRMZY — employee records, attendance, leave, payroll inputs, documents
and anything else you choose to store. We are your processor: we act on your
documented instructions and we do not use your data for our own purposes.
Using the platform as intended constitutes your instructions.
We are the controller for a narrow, separate set of data: the account and
billing details of the person who subscribes, and the operational logs we
need to run and secure the service. That is covered by our
Privacy Policy, not by this agreement.
2. Subject matter and duration
We process personal data for as long as your subscription is active, and for
the short wind-down period described in section 9. The subject matter is the
provision of the HRMZY platform: human-resources administration, attendance
and leave, payroll records, projects, and the related reporting.
3. Categories of data and data subjects
- Data subjects
- Your employees and contractors; your administrators; where you use the
CRM and client features, your own clients and leads; where you use
recruitment, your candidates.
- Categories of data
- Identity and contact details; employment details such as role, salary,
contract and dates; attendance and leave records; payroll inputs and
payslip figures; documents you upload; and any custom fields you create.
- Special categories
- HRMZY does not require special-category data. If you choose to store it
— for example health information in a sick-leave note or a
document you upload — you remain responsible for having a lawful
basis for doing so.
4. Our obligations
- Process personal data only on your documented instructions, including for transfers.
- Ensure the people who handle your data are bound by confidentiality.
- Apply the technical and organisational measures in section 7.
- Assist you, so far as we reasonably can, with data-subject requests, impact assessments and consultations with a supervisory authority.
- Tell you without undue delay if we become aware of a personal-data breach affecting your data, with what we know at the time.
- Make available the information you need to demonstrate compliance with Article 28, and allow an audit as set out in section 10.
5. Sub-processors
You give us general authorisation to engage sub-processors. The current list,
what each receives and where it processes, is published and kept current at
hrmzy.com/sub-processors. Each is engaged under
a written agreement imposing data-protection obligations no less protective
than those in this agreement, and we remain responsible to you for their
performance.
We will update that page when the list changes. If you would like advance
notice of additions, ask us and we will add you to the notification list; if
you reasonably object to a new sub-processor on data-protection grounds, tell
us and we will work with you to find a solution or you may terminate.
6. Where your data is processed
The application and its database are hosted in the European Union. Some
sub-processors listed in section 5 process data outside Switzerland and the
EEA — in particular the AI features send the text you submit to a
provider in the United States. Those transfers are made under the European
Commission’s Standard Contractual Clauses, or another transfer mechanism
recognised under the GDPR and the Swiss revised Federal Act on Data
Protection, as incorporated into our agreement with that sub-processor.
AI features can be switched off for your entire company by an administrator,
from the AI & Data Protection page in settings. With AI off, no content is
sent to the AI provider.
7. Security measures
The measures below are in place today. They are stated because they are true,
not as aspirations.
- Transport encryption (HTTPS/TLS) on every request, with HSTS enforced.
- Strict separation of customer data: every record is scoped to your company and that scoping is enforced at the data layer, not just in the interface.
- Role-based permissions, so an administrator decides what each person can see.
- Optional two-factor authentication, and rate limiting on sign-in and other public endpoints.
- Sensitive documents — payslips, passports, contracts, invoices — stored on a private path that is not readable over the web.
- Upload validation that rejects executable file types and double-extension filenames.
- Credentials and third-party keys encrypted at rest.
- A content-security policy and related hardening headers on every response.
8. Assisting you with data-subject rights
HRMZY includes tools that let you answer most requests yourself: you can
export an individual’s data, correct records directly, and anonymise a
person who asks to be erased. Where a request needs something the product does
not cover, contact us and we will help within the time the law allows.
9. Return and deletion
You can export your data at any time while your subscription is active. When
it ends, you may ask us to return or delete your personal data; unless you
ask us to keep it, or the law requires us to, we delete it within 90 days of
the subscription ending. Backups are overwritten on their normal cycle.
10. Audit
On reasonable written notice, and no more than once a year unless a
supervisory authority requires otherwise, we will provide the information
needed to demonstrate compliance with this agreement and respond to a
reasonable security questionnaire. Audits must respect confidentiality and
must not compromise other customers’ data.
11. Liability and governing law
This agreement is governed by Swiss law, and the courts of Zürich,
Switzerland have exclusive jurisdiction, in each case as set out in the
Terms & Conditions. Liability under this agreement is
subject to the limitations in those Terms. Nothing in this agreement limits
a data subject’s rights under applicable data-protection law.
12. Contact
Data-protection queries, breach notifications and audit requests:
contact@hrmzy.com, or Tech Gipfel,
Seefeldstrasse 69, 8008 Zürich, Switzerland.