GamHR Privacy Policy
This page gives the public operational summary for the current Privacy Policy. The immutable workspace agreement remains the authoritative accepted text. It describes how GamHR collects, uses, stores, and protects personal information in alignment with the Protection of Personal Information Act 4 of 2013 (POPIA).
1. Information We Collect
GamHR processes the following categories of personal information:
- Identity: Full name, SA ID number/passport, date of birth, gender, nationality
- Contact: Email address, phone number, physical address
- Employment: Job title, department, employment dates, contracts
- Financial: Bank account details, tax reference number, salary information
- Leave & Attendance: Leave balances, clock-in/out records, timesheets
- System Usage: Login timestamps, IP addresses, user agent strings
- Trial registration notifications: Name, work email, company name, company size, reopening-notice request, and an optional product-updates choice
- Optional marketing measurement: Consent choice, public page viewed, advertising click identifiers, and a completed-trial event
2. Purpose of Processing
Personal information is processed for the following lawful purposes (POPIA Section 11):
- Contract performance: Administering employment contracts, calculating and paying salaries
- Legal obligation: Payroll and statutory review preparation (including EMP201, EMP501, and IRP5 artifacts), recordkeeping, and BCEA-related administration
- Legitimate interest: Workforce analytics, risk management, audit compliance
- Requested notification: Contacting prospective customers once trial registration reopens
- Optional marketing consent: Sending product updates only when the person separately chooses to receive them
3. Data Storage and Security
- Data is stored in Google Cloud Firestore (africa-south1 region) within South Africa
- Application hosted on Azure Container Apps (South Africa North)
- Sensitive fields (SA ID, tax reference, bank account) are encrypted with AES-256-GCM
- Access controlled via Firebase Authentication with MFA on privileged operations
- Hash-chained audit trail ensures tamper-evident record keeping
4. Data Sharing
- Customer-controlled statutory use: GamHR prepares review artifacts for authorised users; it does not submit these artifacts directly to SARS
- Service providers: Google Cloud (hosting), Microsoft Azure (hosting) - bound by Data Processing Agreements
- Optional connections: OpenAI, Google Calendar, Microsoft Calendar, and Xero receive only the limited data described below, and only after the relevant feature is enabled and an authorised user chooses to connect or use it
- Google Ads measurement: Used only after you allow optional measurement. GamHR does not send employee, payroll, or workspace data to Google Ads.
- No third-party sale: Personal information is never sold to third parties
5. Optional Connections and Mish
GamHR keeps these services off unless the relevant feature has passed its release checks and an authorised user chooses to use it. Availability in the policy does not mean a feature is enabled for a workspace.
- Mish, the AI Experience Guide: When a signed-in user asks Mish a question, GamHR may send OpenAI the redacted question, current page, effective system role, a broad setup state, and short excerpts from reviewed GamHR guidance. GamHR does not send tenant identifiers, employee records, payroll values, leave records, names, email addresses, identity or bank details, free-text leave reasons, or audit entries. Requests use
store:false, and GamHR does not retain persistent AI conversations. OpenAI's standard abuse-monitoring retention may still apply unless a different data-control arrangement is approved. - Google Calendar: When a user connects Google Calendar, GamHR receives delegated permission limited to calendars created by GamHR. GamHR creates a dedicated leave calendar and sends approved-leave dates. A personal calendar uses the title “Approved leave”; a team calendar also uses the employee's display name. GamHR does not import other calendar events and does not send leave reasons, employee IDs, medical information, attachments, hours, or payroll data. GamHR's use and transfer of information received from Google APIs complies with the Google API Services User Data Policy, including its Limited Use requirements.
- Microsoft Calendar: When a user connects Microsoft Calendar, GamHR receives delegated
Calendars.ReadWritepermission and uses it only for a dedicated GamHR leave calendar. The same minimum-data and no-import rules used for Google Calendar apply. GamHR does not request tenant-wide application permission. - Xero: When a Workspace Administrator connects a selected Xero organisation and separately confirms draft-journal access, GamHR may receive organisation and account references and may send payroll-period details, narration, approved account references, and aggregate debit and credit totals. GamHR does not send employee names or identifiers, bank details, tax numbers, payslip lines, or leave information. GamHR creates only a reviewed draft; posting and corrections remain in Xero.
These optional providers operate global services and may process the limited information described above outside South Africa. The workspace employer must confirm its authority, purpose, and cross-border basis before enabling a workspace-owned connection. Personal connections require the individual user's provider consent.
OAuth credentials are encrypted in a private Azure Key Vault in South Africa North. GamHR stores only opaque credential references and minimum connection and audit metadata in its database. A user or authorised Workspace Administrator can disconnect a calendar connection. Google revocation is also requested at the provider, and Microsoft users may remove consent in their Microsoft account or tenant. Disconnecting Xero stops future GamHR access but does not remove accounting records already created in Xero.
GamHR does not sell provider-derived data, use Google or Xero data to train AI, import unrelated calendar events, or use optional provider access for advertising.
6. Cookies and Advertising Measurement
Essential storage: GamHR uses limited browser storage for authentication, security, theme preferences, and your privacy choice. This storage is necessary to provide the requested service and does not enable advertising personalisation.
Optional Google Ads cookies: GamHR keeps Google Ads storage and measurement disabled by default and does not load the Google tag until you allow optional cookies. If you allow them and a new trial workspace is successfully created, GamHR may use an advertising click identifier and send one completed-trial event without employee, payroll, or workspace details. Advertising personalisation and automatic page-view reporting remain disabled. You can withdraw or change this choice at any time by selecting Cookie choices on a public page.
Declining optional cookies does not affect pricing, signup, login, tutorials, or use of a GamHR workspace.
7. Your Rights Under POPIA
As a data subject, you have the right to:
- Access your personal information (Section 23)
- Correct inaccurate information (Section 24)
- Object to processing in certain circumstances (Section 11(3))
- Lodge a complaint with the Information Regulator
To exercise these rights, submit a request through the System or contact your employer's HR administrator.
8. Data Retention
Retention depends on the processing purpose, employer policy, applicable employment and tax law, legal holds, and POPIA's no-longer-than-necessary principle.
- Workspace records: the subscribing employer determines applicable retention requirements and must review them against its lawful purposes and obligations
- Billing recovery: normal access, export, and retained-workspace recovery follow the time-bounded subscription states described in the Terms
- Security, audit, and support evidence: retained only for the bounded operational, legal, and security purposes that apply to the record
- Trial notification details: retained until the reopening notice is sent and for a limited follow-up period, or removed earlier on request
- Records are deleted or anonymised after the applicable purpose, obligation, hold, recovery state, and deletion review have ended
9. Breach Notification
When POPIA Section 22 applies, the responsible party will notify the Information Regulator and identifiable affected data subjects as soon as reasonably possible, subject to any lawful delay directed by the authorities.
10. Data Processing Consent
By explicitly accepting the workspace Data Processing Consent, you acknowledge that your employer may process your personal information for employment administration, payroll, tax, leave, timekeeping, compliance, security, and audit purposes described in this policy.
You also acknowledge the optional-provider disclosures above. Provider access is separate, purpose-limited, and revocable. Accepting this policy does not itself connect an account, enable a provider, or replace the provider's own consent screen.
You understand that you may request access to or correction of your information and may object to or withdraw consent where applicable. Processing required by employment, tax, recordkeeping, or other legal obligations may continue on another lawful basis.
11. Contact
Information Officer: your employer's designated privacy or HR contact
Information Regulator: POPIAComplaints@inforegulator.org.za
GamHR control and provider boundaries: Trust Centre