Privacy Policy
This policy explains what information the HR Management System (the “Service”) handles, why, and the choices people have. The Service is operated by AMDSoft (“we”, “us”) for schools and organisations that use it to manage their own staff.
1. Who is responsible for the data
Each school or organisation that uses the Service decides which staff records are entered and why. AMDSoft provides and secures the software and the database it runs on. For questions about a particular person’s record, please contact that person’s school or organisation first.
2. Information we handle
- Sign-in information. When you sign in with Google we receive your name and email address, and nothing else from your Google account. We use them only to recognise you and to check that you are an approved user. We never receive or store your Google password.
- Staff and HR records entered by authorised users of a school: staff details, attendance, leave, overtime, salary and related documents such as leave chits and reports.
- Technical information needed to keep the Service working and secure, such as sign-in session cookies and server logs.
3. How the information is used
- To let approved users sign in and use the Service.
- To provide HR functions for the school or organisation that entered the data.
- To keep the Service secure, prevent misuse and fix problems.
We do not sell personal information, use it for advertising, or share it with other schools or organisations. Each school’s data is kept separate from every other school’s.
4. Sharing
Information is shared only with the service providers we need to run the Service (for example, our hosting and database provider and, if the school turns it on, an email provider for notifications), and where the law requires it. These providers may process data only to provide their service to us.
5. Cookies
The Service uses only the cookies it needs to keep you signed in and to protect forms against forgery. It does not use advertising or tracking cookies.
6. Security
Data is stored in a managed database reachable only by the application, connections are encrypted in transit, access is limited by role and by school, and secrets are kept out of the source code. No system is perfectly secure, but we work to protect the data entrusted to us.
7. Retention
Records are kept for as long as the school or organisation subscribes to the Service, or for as long as its contract with AMDSoft or the law requires. After that, they are deleted or anonymised at the request of the school or organisation, or within 30 days after the contract ends, unless the law requires us to keep them longer.
8. Your choices
You may ask to see, correct or delete personal information about you by contacting your school or organisation, or us at the address below. Signing in with Google can be stopped at any time by removing the Service’s access in your Google Account settings.
9. Changes
We may update this policy. The date at the top shows when it last changed.
10. Contact
AMDSoft · [email protected]