Legal

Service Privacy Policy

This Service Privacy Policy covers the privacy practices employed by Rostero when Rostero customers ("Customer", "You") use our Cloud-Based Application (the "Cloud Service") or On-Premise application (the "On-Premise Service") or both ("Cloud Service and On-Premise Service", "Service"). This Privacy Policy does not apply to any information or data obtained by Rostero for any other purpose, such as marketing purposes. Please refer to the Rostero Privacy Policy.

Effective date: 1 June 2026

Who We Are

When we use the terms "Rostero", or "us" or "we" in this policy, we are referring to OrangeHRM Inc.

Data Protection Officer

Our Data Protection Officer oversees how we collect, use, distribute and secure your information to ensure your rights are respected. Our Data Protection Officer can be contacted at dpo@orangehrm.com.

How We Collect Information

In the normal course of using the Rostero Cloud or On-Premise Service, Customers will enter electronic data into the Rostero systems ("Customer Data").

Customers may input Customer Data into data templates and submit these to Rostero through secure channels. Rostero implementation consultants will assist with the import of such data into the Rostero Cloud or On-Premise Service.

What Information Do We Collect

Customer may submit Personal Data to the Services, the extent of which is determined and controlled by Customer in its sole discretion, and which may include, but is not limited to the categories of Personal Data listed below based on the Rostero modules used:

Employee Management: Personal contact details, including name, title, addresses, telephone numbers, and personal email addresses. Date of birth, gender, marital status and dependants, emergency contact information, National Insurance/Social Security number, bank account details, payroll records and tax status information, salary, annual leave, pension and benefits information, location of employment or workplace, driving license, employment records (including job titles, work history, working hours, training records and professional memberships), photographs, qualifications (work experience, educational qualifications, skills, languages, professional and social license details), passport and visa details, memberships (membership details and subscriptions), assets (asset details tracking with assignment).

Leave: Employee leave information, including the type of leave and any relevant medical reports, should be attached as necessary.

Time and Attendance: Employee attendance information (Punch In/Out, attendance reports, working hours).

Rosters: Work patterns, including punctuality data.

Any other information applicable to workers, contractors, and employees.

How We Keep Your Information Safe

We have a comprehensive, written information security program in place that includes industry-standard, administrative, technical, and physical safeguards to protect Customer Data from unauthorized access.

Our infrastructure service providers are Rackspace Inc and Amazon Web Services, Inc. They maintain various certifications that help us validate our security policies and processes as well as comply with applicable legislation such as GDPR, Jamaican Data Protection Act, Singapore Personal Data Protection Act, and international standards. The following compliance frameworks have been examined and validated:

Rostero Advanced Cloud Service

Our infrastructure service provider is Rackspace Inc.

ISO 27001 — Rackspace Information Security Management System (ISMS) with ISO 27001 is an iterative management system that ensures security policies and processes are effective in mitigating identified risks. Rackspace's ISMS validates the management of information security in its data center operations.

SSAE 18 and ISAE 3402 — Rackspace SOC (1,2,3) reports can be used to satisfy requirements under both the SSAE 18 and ISAE 3402 standards. This report includes a description of the controls in place as well as the auditor's informed assessment of their effectiveness throughout the audit period.

PCI DSS — Rackspace's status as a PCI DSS Level 1 service provider has been verified by a qualified security assessor (QSA). It covers:

  • Physical security for data centers.

  • Network infrastructure.

  • Rackspace employee access to network devices.

Your Personal Information Rights

We process customer data at the request of our customers and do not have direct control or ownership of the personal data processed by the system. Prior to sending data to Rostero for processing purposes, you are responsible for complying with any regulations or laws that require you to provide notice, disclosure, and/or obtain consent.

We offer a comprehensive set of data protection capabilities ranging from role-based access control to data encryption; from corporate policy publishing tools to data management with extensive audit logs. It enables Customers to gain access to, correct, and limit the processing of their personal data.

Rostero allows you to purge terminated employees from the entire system, including audit trails. This is to help you to practice data subject requests such as the right to be forgotten.

Any data subject request that is directed to us will be forwarded to the customer and we will assist the customer in meeting any obligation to respond to such data subject requests. If the customer requests help from Rostero to comply with data protection regulations, Rostero will respond to their request within 30 business days.

Data Retention Period

In the Rostero Cloud Service, if you have a valid SAAS agreement with Rostero, your data will be retained in our servers. Should you purge any specific employee records, this data will be immediately purged from the system. Such information will then be completely removed from Rostero backups after 4 weeks.

Between 10 and 30 days after the agreement between Rostero and the Customer is terminated, Rostero will remove the customer's personal data from the Rostero servers, and all customer personal data will be fully purged from Rostero backups after a further 4 weeks.

For On-Premise service, we will ensure that any temporary data such as customer data templates, is purged between 10 and 30 days after the termination of the agreement between Rostero and the Customer.

Note: Under Rostero standard agreements, the aforementioned data retention periods will be valid. Customers who have subscribed to Rostero extended services will have their data retained for longer than the above mentioned periods (can go up to 12 weeks).

Meeting Our Legal and Regulatory Obligations

Rostero may, where it concludes that it is legally obligated to do so, disclose personal data to law enforcement or other government authorities. Rostero will notify customers of such requests unless prohibited by law.

Consent

Prior to using sensitive personal information about you for any service improvements, we will first request your consent. Before you give your consent, we will tell you what information we collect and how we use it. You have the right to withdraw your consent at any time by contacting us.

How We Use Your Information

Per the relevant agreement between the Customer and Rostero, we may access customer data within Rostero to provide the service, prevent or address service or technical problems, respond to support issues, respond to the customer's instructions, or as may be required by law.

We may process anonymized data to troubleshoot customer-specific issues and for quality control purposes.

We may process anonymized data to track how the Service's various components are used. This information is used to drive feature development and service enhancements as well as to provide recommendations on how our products and services can add value for you. Rostero does not sell your information to any party under any circumstances and Rostero is not responsible for any PII data sold by the data controller.

How You Access the Rostero Service

Customers and their authorized users may access the Service directly via a URL that is unique to their tenant or may elect to use internal launch pages for single sign-on or other purposes. As they utilize the service, customers provide information for processing and storage. Customers may also configure the Service to allow end users to input information directly into the Service.

Your Information and Third Parties (Sub-processors)

To comply with applicable law, regulation or authorized requests, we may share your information with third parties. We will notify you of such incidents unless prohibited by law.

Sub-processors processing personal data as part of the Services: See the complete Sub-Processor list here.

International Transfer of Data

In Cloud Service, we store customer data in the nearest data center used by Rostero to provide your specific service, e.g.: European client data is stored in European centers.

In Cloud Service and On-Premises Service, we may transfer anonymized data from European region Data Centers to North American Rackspace Data Centers and Asian technical support centers for the purposes of providing the Service, preventing or addressing service or technical problems, responding to support issues, and responding to the Customer's instructions.

Right to Fair Treatment

Rostero will not discriminate against you for exercising your privacy rights. Regardless of your privacy preferences, Rostero will provide the products and services you require.

Making a Complaint

If you have a complaint about the use of your personal information, please contact your application admin within the organization. If you have a complaint about the Rostero service privacy policy or security, please contact our DPO at dpo@orangehrm.com.

Updates to This Notice

We may update this privacy statement to reflect changes in our information practices. If we make any material changes, we will notify you by means of a notice on this site prior to the change taking effect. We encourage you to periodically review this page for the latest information on our privacy standards.