Privacy policy

Status: draft, published for review. This document is prepared from how the platform actually behaves, but it has not yet been reviewed by an NZ employment and privacy lawyer and is not yet in force. It is published here so it can be read and corrected — please treat it as a statement of intent, not a contract.

It carries the sign-off already pending on the trust documents in docs/ — this policy, the data processing addendum and the biometric privacy impact assessment, now joined by the terms of service.

Last updated: 4 September 2026.

Who we are, and whose data this is

AskHR360 is HR software used by New Zealand employers. It is operated by ASK YOUR HR LIMITED, a New Zealand company (NZBN 9429051538712, company number 8864748), registered office 15 Bremner Ridge Street, Flat Bush, Auckland 2019 — “we” and “us” in this policy mean that company.

For almost all personal information in the platform, your employer is the agency under the Privacy Act 2020 — they decide what is collected and why; we process it on their behalf. Questions about your record start with your employer; this policy explains what the platform itself does.

What the platform holds

Employment records your employer keeps about you: identity and contact details, position and salary history, tax code, KiwiSaver election and bank account (entered by you), leave and time records, documents (agreements, certificates, visas), training, health & safety reports, performance reviews, and — only if you choose to enrol — a numeric face template for the attendance clock (never a photo; see the biometric privacy impact assessment).

How it is protected

  • Encryption: sensitive fields (IRD number, address, bank account, tax code, salary, visa numbers, narratives, 2FA secrets) are encrypted at rest with AES-256-GCM, over an encrypted database.
  • Access control: four roles with least-privilege defaults; managers never see your IRD number, date of birth, address, bank details or salary; every access rule is enforced server-side and covered by automated tests.
  • Tenant isolation: every database query is confined to your employer's organisation by a mandatory scoping layer; cross-tenant access is technically blocked, not just forbidden.
  • Audit: every change to an HR record is written to an append-only audit log (who, what, when) that cannot be edited or deleted, by anyone.
  • Sign-in: passwords are argon2id-hashed; two-factor authentication is available to every account and employers can require it org-wide.
  • Backups: encrypted backups with a tested restore procedure.

Where data lives

Application, database and uploaded files: Australia (Sydney). Documents you upload are held in Tigris object storage pinned to the Sydney region, so they stay in Australia. If your employer enables the optional liveness check on the clock, that check alone is processed by Amazon Web Services in Japan and only the pass/fail result is kept.

Email is the other exception, and it is worth being plain about. Notifications we send you — invitations, password resets, compliance reminders — are delivered by Resend, which processes them in Japan. Your name, your email address and the contents of those messages therefore pass through Japan, even though the records they are drawn from stay in Australia.

Sub-processors current at publication: Fly.io (hosting — Sydney), Tigris (file storage — Sydney), Resend (email delivery — Japan), Amazon Web Services (liveness check when enabled — Japan), Stripe (employer billing only — never employee data), and Anthropic (AI assistant, only when enabled, no training on your data).

Your rights (IPPs 6 and 7)

You can see the information the platform holds about you — most of it is already visible in your own profile — and ask for corrections. Requests go to your employer; the platform gives them a full-record export to answer with. Biometric templates are deleted when you leave, and earlier on request.

What we never do

Sell personal information; use it to train AI models; move employee data through the billing system; keep biometric imagery; or let platform staff read tenant data outside an audited, super-admin support path.

Retention

Employment records are retained by your employer per their legal obligations (e.g. six years for wage and time records; five years for notifiable health & safety events). “Deleting” an employee archives the record and destroys the biometric template and clock PIN immediately.

Complaints and contact

Raise it with your employer’s privacy officer first. Unresolved complaints can go to the Office of the Privacy Commissioner — privacy.org.nz, 0800 803 909.

To reach us about this policy or the platform itself, email support@askhr360.com, or use askyourhr.co.nz/contact.

See also our terms of service.