Updated 19 December 2017
Air HR (“This Application”, “We”, “Our”) collects some Personal Data from its Users for the sole purpose of operating the Air HR platform and improving it. Air HR is fully committed to the protection of our users’ privacy at all times. We will never sell User data to anyone nor share data for any reasons that are not strictly for running and improving the Air HR platform.
This policy is intended to inform you of the way in which any personal data you provide us with or we collect from you will be used.
Data Controller
Air HR Ltd.
31 Lionel Street
Birmingham
B3 1AP
Contact: [email protected]
Types of Data collected
Among the types of Personal Data that this Application collects, by itself or through services used by Air HR, includes: Cookies, Usage Data, contact information and HR data.
Complete details on each type of Personal Data collected are provided in the dedicated sections of this privacy policy or by specific explanation texts displayed prior to the Data collection.
The Personal Data may be freely provided by the User, or, in case of Usage Data, collected automatically when using this Application.
All Data requested by this Application is mandatory and failure to provide this Data may make it impossible for this Application to provide its services. In cases where this Application specifically states that some Data is not mandatory, Users are free not to communicate this Data without any consequences on the availability or the functioning of the service.
Any use of Cookies – or of other tracking tools – by this Application or the applications it uses serves the purpose of providing the Air HR service and improving it, in addition to any other purposes described in this policy.
Users are responsible for any third party Personal Data obtained, published or shared through this Application and confirm that they have consent to provide the Data to Air HR.
Personal data we may collect about you
We may obtain and use the following data about you and your Users:
- Any correspondence we have with you and your Users should you or your Users contact us. This data will be used only for providing support through our support help desk solution and for improving the Air HR service.
- Contact Data like Name, Email address and phone number. This data will be used for running the Air HR service, providing customer support and internal Air analytics regarding use of Air HR overall.
- Personal Data you or your employees submit or upload to Air HR which may include, among other things, dates of birth, residential addresses, National Insurance numbers, bank details, passport details, payroll numbers, salary and pension details, a record of holidays and sick days, certain medical information. This data will be used for the sole purpose of providing the Air HR service to you.
- Details of transactions made by Administrators and Account owners through Air HR
- Responses to optional research surveys we ask users on our platform to complete. This data will be used only to improve the Air HR service.
- Details of you or your users’ visits to our website, which includes without limitation location and traffic data, weblogs, resources you access and other communication data. This data will be used only to improve the Air HR service.
Mode and place of processing the Data
Methods of processing
The Data Controller processes the Data of Users in a proper manner and shall take appropriate security measures to prevent unauthorized access, disclosure, modification, or unauthorized destruction of the Data.
The Data processing is carried out using computers and/or IT enabled tools, following organisational procedures and modes strictly related to the purposes indicated. In addition to the Data Controller, in some cases, the Data may be accessible to certain types of persons in charge, involved with the operation of Air HR (administration, sales, marketing, legal, system administration) or external parties (such as third party technical service providers, mail carriers, hosting providers, IT companies, communications agencies) appointed, if necessary, as Data Processors by the Air HR. Air will never use employee data for sales and marketing, and will only use Administrator and Account Owner details for sales and marketing messages regarding Air HR (and never any third party applications or services).
Place
Data obtained from you and your Users may be moved to and stored at a destination within the European Economic Area (“EEA”). Staff members who work for or on behalf of us may process this information. Such staff members may, among other things, be involved in the processing of payment details, the provision of support services and the delivery of your and your Users’ request(s) for us to provide services. When submitting your and your Users’ personal data, you are agreeing to such processing, transfer or storage as outlined above.
Without limiting the foregoing, you agree that the information we obtain from you and your Users may be also processed by our service providers based in countries outside of the EEA for the purposes of providing you with the Service. See our Security Policy for more information.
Retention time
The Data is kept for the time necessary to provide the service requested by the User, or stated by the purposes outlined in this document, and the User can always request that the Data Controller suspend or remove the data.
The use of the collected Data
The Data concerning the users is collected to allow the Air HR to provide its services and for improving it’s services through Analytics and feature testing (A/B testing), Handling payments, Hosting and backend infrastructure, Infrastructure monitoring, Managing contacts and sending messages, Traffic optimisation and distribution, and User database management.
The Personal Data used for each purpose is outlined in the specific sections of this document.
Detailed information on the processing of Personal Data
The information we hold about you and your Users may be used in any of the following ways:
- To provide and to improve our services to you, including administration and management of your account, allowing you to upload, store and access data and allowing users to access data relevant to themselves
- To send Administrators and Company Owners further information about our Air HR services for which we think you may have an interest. This information will be used only where you have given consent.
- To send you further information about our services based on a request we have received from you
- To fulfil our obligations to you
- To provide you with notification about any changes to our services
We use the following services to collect data for the following purposes:
Analytics
The services contained in this section enable the Owner to monitor and analyze web traffic and can be used to keep track of User behaviour.
Google Analytics (Google Inc.)
Google Analytics is a web analysis service provided by Google Inc. (“Google”). Google utilizes the Data collected to track and examine the use of this Application, to prepare reports on its activities and share them with other Google services.
Personal Data collected: Cookies and Usage Data.
Place of processing: US – Privacy Policy – Opt Out
Content performance and features testing (A/B testing)
The services contained in this section allow the Owner to track and analyze the User response concerning web traffic or behaviour regarding changes to the structure, text or any other component of this Application.
Google Website Optimizer (Google Inc.)
Google Website Optimizer is an A/B testing service provided by Google Inc.
Google may use Personal Data to contextualize and personalize the ads of its own advertising network.
Personal Data collected: Cookies and Usage Data.
Place of processing: US – Privacy Policy
Handling payments
Payment processing services enable this Application to process payments by credit card, bank transfer or other means. To ensure greater security, this Application shares only the information necessary to execute the transaction with the financial intermediaries handling the transaction.
Some of these services may also enable the sending of timed messages to the User, such as emails containing invoices or notifications concerning the payment.
Stripe (Stripe Inc)
Stripe is a payment service provided by Stripe Inc.
Personal Data collected: various types of Data as specified in the privacy policy of the service.
Place of processing: US – Privacy Policy
Hosting and backend infrastructure
This type of service has the purpose of hosting data and files that enable this Application to run and be distributed as well as to provide a ready-made infrastructure to run specific features or parts of this Application. Some of the services that hold less sensitive data (such as but not limited to Usage Data and Cookies) work through geographically distributed servers, making it difficult to determine the actual location where the data is stored. We store sensitive personal data (e.g. date of birth, bank details, salary details) within the EEA.
Google Cloud Storage (Google Inc.)
Google Cloud Storage is a hosting service provided by Google Inc.
Personal Data collected: various types of Data as specified in the privacy policy of the service.
Place of processing: US – Privacy Policy
Infrastructure monitoring
This type of service allows this Application to monitor the use and behavior of its components so its performance, operation, maintenance and troubleshooting can be improved.
Which Personal Data are processed depends on the characteristics and mode of implementation of these services, whose function is to filter the activities of this Application.
Sentry (GetSentry, LLC)
Sentry is a monitoring service provided by GetSentry, LLC.
Personal Data collected: various types of Data as specified in the privacy policy of the service.
Place of processing: US – Privacy Policy
Managing contacts and sending messages
This type of service makes it possible to manage a database of contact information to communicate with the User.
These services may also collect data concerning the date and time when the message was viewed by the User, as well as when the User interacted with it, such as by clicking on links included in the message.
Sendgrid (Sendgrid)
Sendgrid is an email address management and message sending service provided by Sendgrid Inc.
Personal Data collected: email address.
Place of processing: US – Privacy Policy
Traffic optimization and distribution
This type of service allows this Application to distribute their content using servers located across different countries and to optimize their performance.
Which Personal Data are processed depends on the characteristics and the way these services are implemented. Their function is to filter communications between this Application and the User’s browser.
Considering the widespread distribution of this system, it is difficult to determine the locations to which the contents that may contain Personal Information User are transferred.
CloudFlare (Cloudflare)
CloudFlare is a traffic optimization and distribution service provided by CloudFlare Inc. The way CloudFlare is integrated means that it filters all the traffic through this Application, i.e., communication between this Application and the User’s browser, while also allowing analytical data from this Application to be collected.
Personal Data collected: Cookies and various types of Data as specified in the privacy policy of the service.
Place of processing: US – Privacy Policy
User database management
This type of service allows the Owner to build user profiles by starting from an email address, a personal name, or other information that the User provides to this Application, as well as to track User activities through analytics features. This Personal Data may also be matched with publicly available information about the User (such as social networks’ profiles) and used to build private profiles that Air HR uses for customer support operations and for improving the Air HR platform.
Some of these services may also enable the sending of timed messages about Air HR to users, such as emails based on specific actions performed on this Application.
Intercom (Intercom Inc.)
Intercom is a User database management service provided by Intercom Inc. Intercom can also be used as a medium for communications, either through email, or through messages within our product(s).
Personal Data collected: email address and various types of Data as specified in the privacy policy of the service.
Place of processing: US – Privacy Policy
Further information about Personal Data:
Additional information about Data collection and processing
Legal action
The User’s Personal Data may be used for legal purposes by the Data Controller, in Court or in the stages leading to possible legal action arising from improper use of this Application or the related services.
The User declares to be aware that the Data Controller may be required to reveal personal data upon request of public authorities.
Additional information about User’s Personal Data
In addition to the information contained in this privacy policy, this Application may provide the User with additional and contextual information concerning particular services or the collection and processing of Personal Data upon request.
System logs and maintenance
For operation and maintenance purposes, this Application and any third party services may collect files that record interaction with this Application (System logs) or use for this purpose other Personal Data (such as IP Address).
Information not contained in this policy
More details concerning the collection or processing of Personal Data may be requested from the Data Controller at any time. Please see the contact information at the beginning of this document.
The rights of Users
Users have the right, at any time, to know whether their Personal Data has been stored and can consult the Data Controller to learn about their contents and origin, to verify their accuracy or to ask for them to be supplemented, cancelled, updated or corrected, or for their transformation into anonymous format or to block any data held in violation of the law, as well as to oppose their treatment for any and all legitimate reasons. Requests should be sent to the Data Controller at the contact information set out above.
This Application does not support “Do Not Track” requests.
To determine whether any of the third party services it uses honor the “Do Not Track” requests, please read their privacy policies.
Changes to this privacy policy
The Data Controller reserves the right to make changes to this privacy policy at any time by giving notice to its Users on this page. It is strongly recommended to check this page often, referring to the date of the last modification listed at the bottom. If a User objects to any of the changes to the Policy, the User must cease using this Application and can request that the Data Controller remove the Personal Data. Unless stated otherwise, the then-current privacy policy applies to all Personal Data the Data Controller has about Users.
Information about this privacy policy
The Data Controller is responsible for this privacy policy.
Definitions and legal references
Personal Data (or Data)
Any information regarding a natural person, a legal person, an institution or an association, which is, or can be, identified, even indirectly, by reference to any other information, including a personal identification number.
Usage Data
Information collected automatically from this Application (or third party services employed in this Application), which can include: the IP addresses or domain names of the computers utilized by the Users who use this Application, the URI addresses (Uniform Resource Identifier), the time of the request, the method utilized to submit the request to the server, the size of the file received in response, the numerical code indicating the status of the server’s answer (successful outcome, error, etc.), the country of origin, the features of the browser and the operating system utilized by the User, the various time details per visit (e.g., the time spent on each page within the Application) and the details about the path followed within the Application with special reference to the sequence of pages visited, and other parameters about the device operating system and/or the User’s IT environment.
User
The individual using this Application, which must coincide with or be authorized by the Data Subject, to whom the Personal Data refers.
Data Subject
The legal or natural person to whom the Personal Data refers.
Data Processor (or Data Supervisor)
The natural person, legal person, public administration or any other body, association or organization authorized by the Data Controller to process the Personal Data in compliance with this privacy policy.
Data Controller (or Owner)
The natural person, legal person, public administration or any other body, association or organization with the right, also jointly with another Data Controller, to make decisions regarding the purposes, and the methods of processing of Personal Data and the means used, including the security measures concerning the operation and use of this Application. The Data Controller, unless otherwise specified, is the Owner of this Application.
This Application
The hardware or software tool by which the Personal Data of the User is collected.
Cookies
Small piece of data stored in the User’s device.
Legal information
Notice to European Users: this privacy statement has been prepared in fulfillment of the obligations under Art. 10 of EC Directive n. 95/46/EC, and under the provisions of Directive 2002/58/EC, as revised by Directive 2009/136/EC, on the subject of Cookies.
This privacy policy relates solely to this Application.