Privacy Policy

Safeguarding your team and workforce data

Last updated: July 23, 2026

Covers the marketing site, Admin Panel, and Staff Portal—including remote attendance and location data where enabled by your organisation.

1. Overview

This Privacy Policy explains how Nugo.lk (“HR360”, “we”, “us”, or “our”) collects, uses, stores, shares, and protects information when you visit hr360.lk or use HR360 products—including the Admin Panel, Staff / Self-Service Portal, APIs, integrations, and related services (the “Services”). By accessing or using the Services, you acknowledge the practices described here. Our Terms of Service are incorporated by reference.

2. Who This Policy Covers

  • Website visitors and prospective customers who submit demo or contact forms.
  • Customer organisation administrators and authorised users of the Admin Panel.
  • Employees, contractors, managers, and other individuals invited to the Staff Portal (“End Users”).
  • Where a Customer uploads or syncs workforce data, that Customer typically determines why and how personal data is processed for HR purposes (controller). HR360 processes that data to provide the Services on the Customer’s instructions (processor / service provider), except for data we collect for our own business operations (accounts, billing, security, product analytics, marketing where permitted).

3. Information We Collect

We collect information in the following categories, depending on how the Services are used:

  • Account & organisation data: company name, billing details, admin name, email, phone, role, authentication credentials, and subscription metadata.
  • Workforce / HR data (Customer Content): employee identifiers, names, NIC or other ID numbers, contact details, job titles, departments, bank details (where provided for payroll), salary structures, leave balances and requests, attendance and overtime records, documents and attachments you upload, and related configuration.
  • Staff Portal activity: login events, leave applications and approvals, attendance correction requests, payslip views, remote punches, and in-app actions tied to your user account.
  • Remote check-in & location data: when remote attendance is enabled and used, we may process punch timestamps (including server-generated times), device or account identifiers, IP address, and—where the client or Customer configuration supplies it—geolocation such as latitude, longitude, accuracy, and optional address text. Location is collected to support attendance verification for the Customer.
  • Biometric / device integration data: punch logs, device IDs, card numbers, person mappings, auth type/result, and related metadata received from Customer-connected biometric or ADMS systems (e.g., Hikvision, ZKTeco). Raw biometric templates often remain on devices or vendor systems; we process the attendance events and identifiers delivered to HR360.
  • Technical & usage data: browser/OS type, device type, approximate region derived from IP, diagnostics, crash logs, performance metrics, and feature-usage analytics.
  • Communications: emails, support tickets, call notes, and WhatsApp or form submissions.
  • Cookies and similar technologies on our marketing site and, where applicable, product surfaces—for session management, preferences, security, and analytics (see Section 10).

4. How We Use Information

  • Provide, operate, authenticate, and secure the Admin Panel, Staff Portal, and integrations.
  • Process attendance (including remote check-in and biometric punches), leave, overtime, payroll preparation, payslips, approvals, and reporting as configured by the Customer.
  • Display location and punch metadata to authorised Customer users for attendance, compliance, and payroll workflows.
  • Configure and troubleshoot device integrations and data syncs at Customer request.
  • Send service notices (security, downtime, billing, material policy changes) and—where permitted—product updates or marketing (you may opt out of non-essential marketing).
  • Monitor abuse, prevent fraud (including suspected proxy punching or credential sharing), enforce Terms, and protect rights and safety.
  • Improve reliability and UX through aggregated or de-identified analytics and product research.
  • Comply with law, respond to lawful requests, and establish or defend legal claims.

5. Legal Bases & Customer Instructions

  • Where we act as a processor, we process Customer Content under the Customer’s instructions and applicable agreement (including these Terms and this Policy).
  • Customers are responsible for having a lawful basis to collect and instruct us to process End User data—including workplace monitoring, location for remote attendance, biometric-related punches, and payroll data—and for providing required notices and obtaining consents under Sri Lankan and other applicable privacy or employment laws.
  • Where we act as a controller (e.g., our website leads, billing contacts, security logs), we rely on performance of contract, legitimate interests (securing and improving Services, B2B marketing where appropriate), consent where required, and legal obligation.

6. Location & Remote Attendance — Important Notice

  • Remote check-in is an optional Customer-controlled feature. If your employer enables it and you punch remotely, location and related telemetry may be transmitted to HR360 and made visible to your employer’s authorised administrators and managers.
  • You can typically control OS-level location permissions on your device; refusing permission may prevent remote punch features from working as configured by your employer.
  • HR360 does not guarantee GPS accuracy and is not responsible for employment decisions your employer makes based on location or attendance data.
  • Do not use remote check-in to misrepresent your location or identity. Misuse may be visible in audit logs and handled under your employer’s policies and our Terms.

7. How We Share Information

  • We do not sell personal data. We do not rent Customer Content for unrelated third-party advertising.
  • Service providers / subprocessors: hosting, database, email delivery, error monitoring, analytics, maps/geocoding (if used), and similar vendors bound by confidentiality and data-processing obligations.
  • Integrations you enable: biometric device vendors, ADMS bridges, and other systems the Customer connects; data flows according to that configuration.
  • Within the Customer tenant: administrators, managers, and other roles the Customer authorises may access workforce and attendance data (including remote location where collected).
  • Corporate events: merger, acquisition, or asset transfer, subject to continued protection consistent with this Policy.
  • Legal: if required by law, regulation, court order, or to protect rights, safety, or security—disclosing only what we reasonably believe is necessary.

8. Data Security

  • We use administrative, technical, and organisational measures appropriate to the nature of the data, including encryption in transit (TLS), access controls, least-privilege practices, and monitoring of operational logs.
  • No method of transmission or storage is 100% secure. You acknowledge residual risk. Customers must also secure their admin accounts, End User credentials, devices, and on-premise biometric hardware.
  • Promptly notify us of suspected unauthorised access to your HR360 accounts.

9. Retention & Deletion

  • Customer Content is generally retained for the life of the Customer relationship and any post-termination export or wind-down period, unless earlier deletion is requested and legally permissible.
  • We may retain subsets of data as required by law, for dispute resolution, security auditing, backup integrity, or enforcement of agreements—then delete or anonymise when no longer needed.
  • Location and remote-punch records are retained as part of attendance history according to Customer retention needs and our backup cycles.
  • On verified Customer request after contract end and fee settlement, we will delete or return Customer Content within a commercially reasonable period, except where retention is required or backups are not yet rotated.

10. Cookies, Analytics & Marketing Site

  • Our website may use cookies, pixels, or similar tools (including analytics and advertising tags such as Google Tag Manager / Meta-related events where configured) to understand traffic, measure campaigns, and improve the site.
  • You can control cookies via browser settings; disabling some cookies may limit site functionality.
  • Product authentication cookies/tokens are necessary to keep you signed in and are not used to sell your personal data.

11. International Transfers

We may process and store information on servers or through subprocessors located in Sri Lanka or other countries. Where data is transferred across borders, we take steps designed to protect it appropriately (contractual safeguards, reputable providers, and access controls). By using the Services, you understand that processing may occur outside your province or country.

12. Your Rights & Choices

  • End Users: For HR records, leave, pay, or attendance data held in your employer’s tenant, please contact your employer (the Customer) first—they control that data. We will assist the Customer with verified requests as required by contract and law.
  • Customers / admins: You may request access, correction, export, or deletion of organisation data subject to contract, backups, and legal retention.
  • Marketing opt-out: Unsubscribe links or email privacy@hr360.lk / info@hr360.lk for non-essential marketing. Service and security messages may still be sent.
  • We respond to verified requests within a reasonable period (typically within 30 days) unless a longer period is permitted or required.

13. Children’s Data

HR360 is a business / workplace service and is not directed at children. We do not knowingly collect personal data from children for the Services. If you believe a child’s data was provided in error, contact us and we will take appropriate steps with the Customer.

14. Third-Party Links & Services

The Services may link to third-party sites or depend on third-party device/cloud vendors. Their privacy practices are governed by their own policies. We are not responsible for those practices.

15. Limitation of Responsibility for Customer Monitoring

Workplace monitoring choices (including whether to require location for remote punches, how long to keep attendance history, and how to use that data in employment decisions) are made by the Customer. To the fullest extent permitted by law, HR360 is not liable for Customer misuse of personal data, failure to provide employee notices, or employment claims arising from attendance or location data the Customer elects to collect through the Services.

16. Updates to This Policy

We may update this Privacy Policy to reflect legal, technical, or business changes. The “Last updated” date will change when we post revisions at hr360.lk/privacy. Material updates may also be communicated via email or in-product notices to administrators (and where appropriate, End Users). Continued use after the effective date constitutes acknowledgement of the updated Policy.

17. Contact

For privacy requests or questions, email privacy@hr360.lk or info@hr360.lk, or reach our contact team. Please include enough detail for us to verify and route your request (including your employer/organisation name for Staff Portal matters).