Skip to content
LEGAL

PRIVACY POLICY

Privacy Policy

How Humaneti collects, uses, protects, and isolates information across our public website and our multi-tenant HR, payroll, and NGO project platform.

Effective: July 22, 2026Last updated: July 22, 2026

1. Scope & definitions

This policy explains how Humaneti handles information across two different contexts, and the role we play in each:

  • Website visitors — people who browse this website or submit contact, demo, or subscription-request forms. For this information, Humaneti is the data controller (we decide why and how it is used).
  • Platform users — tenant administrators and employees of a subscribing organization who use the Humaneti platform. The subscribing organization is the data controller of the employee and business records it enters; Humaneti is the data processor that handles those records only on the organization’s documented instructions and to deliver the service.

2. Information we collect

Account credentials & profile. Name, work email, role/permissions, and (for website forms) company, phone, and message content.

Tenant content. Business and personal records that a subscribing organization enters — for example payroll figures, National ID / passport numbers, bank and NSSF details, expense receipts, attendance and leave records, and project or grant budgets. Humaneti processes this content on the organization’s behalf and does not use it for its own purposes.

Device & usage data. Mobile device model and operating system, IP address, browser type, login and activity timestamps, and — only with your permission on your device — camera access used to capture receipts and documents.

3. How we use information

  • Operating HR, payroll, procurement, finance, and NGO project workflows that the platform provides.
  • Authenticating users, enforcing role-based access, and keeping audit logs for accountability and fraud prevention.
  • Responding to website inquiries, scheduling demos, and processing subscription requests.
  • Maintaining security, service reliability, and legal or regulatory compliance where applicable.

4. Data isolation & security

  • Multi-tenant segregation: each organization’s data is logically isolated and scoped to its own tenant, and access is enforced server-side so one organization cannot read another’s records.
  • Encryption in transit: all traffic is protected with TLS/HTTPS.
  • Encryption at rest: databases, backups, and uploaded documents are stored encrypted.
  • Storage location & provider standards: data is hosted with reputable cloud infrastructure providers operating to recognized security standards. Where feasible, hosting favors regions appropriate for our Cambodian customers.

5. Sub-processors & data sharing

To run the service we rely on a limited set of vetted sub-processors — for example cloud infrastructure hosting and transactional email delivery. Each is bound by contract to protect data and to process it only for the purpose of providing their service to us.

Humaneti does not sell, rent, or monetize tenant data, and does not use it for advertising. Data may be disclosed to authorities only where required by law.

6. International data transfers

Some sub-processors may store or process data outside Cambodia. Where that happens, we take reasonable steps to ensure the data remains protected to a standard consistent with this policy through contractual and technical safeguards.

7. Cookies & website analytics

The website uses essential cookies and similar technologies to keep the site working, remember your language preference, and understand basic, aggregated usage. We do not use cookies for cross-site advertising. You can control cookies through your browser settings.

8. Data retention & tenant offboarding

  • Employee and business records are retained for as long as the subscribing organization’s agreement remains active, and thereafter as governed by that agreement and applicable law.
  • On termination, the organization may export its data. We keep it for a deletion grace period of thirty (30) days so records can be retrieved, after which tenant data is securely deleted from active systems (backups age out on their normal cycle).
  • Website contact records are kept only as long as needed for follow-up, compliance, and security, then deleted or anonymized.

9. Data breach notification

We maintain safeguards to prevent unauthorized access. If a security incident affects tenant personal data, we will investigate, take steps to contain it, and notify the affected organization (the controller) without undue delay, so it can meet its own notification obligations.

10. Your rights

Depending on your jurisdiction, you may request access, correction, or deletion of your personal information. If you are an employee of a subscribing organization, requests about your work records are directed first to that organization (the controller); Humaneti supports the request as processor. Website-visitor requests can be sent to us directly.

11. Contact

Privacy inquiries: privacy@humaneti.com

General inquiries: Contact form