Legal
Privacy Policy
Last updated: September 1, 2026 · Effective date: September 1, 2026
1. Introduction
ChordHR ("ChordHR", "we", "us", or "our") is an HR management platform that helps growing companies manage their workforce, payroll, attendance, and more. We are committed to protecting your personal information and your right to privacy.
This Privacy Policy explains what information we collect, how we use and share it, and what rights you have in relation to it. It applies to all personal data we process about visitors to our website (chordhr.com) and users of the ChordHR platform (collectively, the "Services").
By using our Services, you agree to the collection and use of information in accordance with this policy. If you do not agree, please discontinue use of the Services.
3. How We Use Your Information
We use the information we collect to:
- Provide and operate our Services — process payroll, manage attendance, run onboarding workflows, and deliver every feature of the ChordHR platform.
- Manage your account — create and authenticate your account, communicate account-related notices, and respond to support requests.
- Improve and develop our Services — analyse usage patterns, conduct research, fix bugs, and build new features.
- Communicate with you — send product updates, security alerts, and, where you have opted in, marketing communications about ChordHR.
- Comply with legal obligations — meet our obligations under applicable labour, tax, and data protection laws, and respond to lawful requests from authorities.
- Prevent fraud and ensure security — detect and investigate suspicious activity, enforce our Terms of Service, and protect ChordHR and its users.
We rely on the following legal bases under applicable data protection law: contract performance, legitimate interests, legal obligation, and (where required) your consent.
4. How We Share Your Information
We do not sell your personal data. We may share it in the following limited circumstances:
- Service providers — trusted vendors who help us operate the platform (e.g. cloud hosting, payment processing, email delivery, analytics) under strict data processing agreements.
- Your organisation — HR data you enter or that is entered on your behalf is accessible to authorised administrators within your organisation according to the roles and permissions you configure.
- Integrations you enable — when you connect a third-party service (e.g. Slack, Google Calendar, biometric hardware), data is shared with that service as needed to operate the integration.
- Legal requirements — if required by law, court order, or governmental authority, or to protect the rights, property, or safety of ChordHR, our users, or the public.
- Business transfers — in connection with a merger, acquisition, or sale of assets, your information may be transferred as part of that transaction, subject to the same privacy protections.
5. Data Retention
We retain personal data for as long as necessary to fulfil the purposes described in this policy, or as required by applicable law.
- Active accounts — data is retained for the duration of your subscription and for a reasonable period thereafter to resolve disputes, enforce agreements, or comply with legal obligations.
- Deleted accounts — upon account deletion, we purge personal data within 30 days, except where retention is required by law (e.g. payroll records may be retained for up to 7 years for tax compliance purposes).
- Marketing communications — opt-out preferences are retained indefinitely so we can honour your choice.
To request early deletion of your data, see Section 6 or visit our Account Deletion page.
6. Your Rights & Choices
Depending on your location, you may have the following rights regarding your personal data:
- Access — request a copy of the personal data we hold about you.
- Correction — request correction of inaccurate or incomplete data.
- Deletion — request deletion of your personal data, subject to legal retention requirements. See our Account Deletion page for the full process.
- Portability — request your data in a structured, machine-readable format.
- Restriction — request that we restrict processing of your data in certain circumstances.
- Objection — object to processing based on legitimate interests or for direct marketing purposes.
- Withdraw consent — where processing is based on consent, withdraw it at any time without affecting the lawfulness of prior processing.
To exercise any of these rights, submit a request through your ChordHR account under Settings → Privacy. We will respond within 30 days. We may need to verify your identity before fulfilling your request.
7. Security
We implement industry-standard technical and organisational measures to protect your personal data against unauthorised access, loss, or disclosure. These include:
- Encryption of data in transit (TLS 1.2+) and at rest (AES-256).
- Role-based access controls and audit logging within the platform.
- Regular security reviews, penetration testing, and vulnerability management.
- Incident response procedures to detect, report, and address data breaches promptly.
No method of transmission over the internet is 100% secure. While we strive to protect your data, we cannot guarantee absolute security. If you suspect a security incident, please report it through your ChordHR account support channel.
8. Cookies & Tracking
We use cookies and similar tracking technologies to operate our website and platform, understand usage, and improve your experience.
- Essential cookies — required for the platform to function (e.g. session authentication). These cannot be disabled.
- Analytics cookies — help us understand how visitors use our website (e.g. page views, traffic sources). We use these only in aggregate form.
- Preference cookies — remember your settings and choices across sessions.
You can control cookie settings through your browser preferences. Disabling certain cookies may affect the functionality of our Services. We do not use cookies to serve third-party advertising or sell data to advertisers.
9. International Data Transfers
ChordHR operates globally. Your information may be transferred to and processed in countries other than your own. Where such transfers occur, we ensure appropriate safeguards are in place — such as Standard Contractual Clauses approved by relevant authorities — to protect your data in accordance with applicable law.
10. Children's Privacy
Our Services are designed for business use and are not directed to individuals under the age of 16. We do not knowingly collect personal data from children. If you believe we have inadvertently collected such data, please notify us through your account support channel and we will delete it promptly.
11. Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, technology, or legal requirements. When we make material changes, we will notify you by updating the "Last updated" date at the top of this page and, where appropriate, by sending a notice to the email address associated with your account.
We encourage you to review this policy periodically. Your continued use of the Services after the effective date of any changes constitutes your acceptance of the updated policy.