Privacy Policy

Last updated: 17 June 2026

This Privacy Policy explains how the StaffE platform ("StaffE", "we", "us", "our") collects, uses, discloses and protects personal data in accordance with the Personal Data Protection Act 2010 of Malaysia ("PDPA").

StaffE serves employers ("Customers") and their employees. For an employer's account and billing data, StaffE is the data user (controller). For personal data about a Customer's employees that the Customer processes through the Service, the Customer is the data user and StaffE acts as a data processor on the Customer's behalf. If you are an employee, please also refer to your employer's own privacy notice.

1. The PDPA principles we follow

We handle personal data in line with the seven PDPA principles: the General, Notice and Choice, Disclosure, Security, Retention, Data Integrity, and Access Principles.

2. Personal data we collect

Depending on how the Service is used, we may collect:

  • Account & contact data — name, work email, phone number, company name, business registration number, role.
  • Employee profile data — name, NRIC/passport number, contact details, date of birth, employment details, department, and emergency contacts.
  • Payroll & statutory data — salary, bank account details, EPF/SOCSO/EIS/tax (PCB) numbers and contributions, and related figures, used to operate payroll and statutory reporting.
  • Attendance & location data — clock-in/out times and, where the feature is enabled, the geolocation of a clock-in event and the work station/device used.
  • Biometric data (facial images/templates) — where facial-recognition attendance is enabled, a facial image and/or mathematical face template used to verify identity at clock-in. This is treated as sensitive personal data.
  • Device & technical data — IP address, browser/device information, and push-notification tokens (for browser/phone notifications).
  • Usage data — actions taken in the Service for security, support and improvement.

3. Sensitive personal data (biometric data)

Under the PDPA, biometric data is sensitive personal data and requires the data subject's explicit consent.

Where facial-recognition attendance is used, the Customer (employer) is responsible for obtaining each employee's explicit consent before enabling it. Facial data is used only to verify identity for attendance and is not used for any other profiling.

  • Employees may decline facial recognition and request an alternative clock-in method from their employer.
  • Facial images/templates are stored using access controls and encryption in transit, and are deleted when no longer needed for the stated purpose or on withdrawal of consent (subject to lawful retention).

4. Why we process personal data

We process personal data to:

  • provide and operate the Service (attendance, payroll, leave, documents, recruitment, reporting);
  • verify identity for attendance and prevent fraudulent clock-ins;
  • calculate salaries and statutory contributions and generate statutory forms;
  • send operational notifications (in-app, email, browser/phone push, and, where configured, WhatsApp);
  • provide support, ensure security, and comply with legal obligations.

5. Consent, notice and choice

We process personal data on the basis of consent and/or where processing is necessary for the performance of a contract or compliance with a legal obligation.

You may withdraw consent for optional processing at any time by contacting your employer (for employee data) or us. Withdrawing consent for essential processing (for example, payroll) may mean we or your employer cannot continue to provide the relevant function.

6. Disclosure of personal data

We may disclose personal data to:

  • the Customer (employer) to whom the data relates;
  • service providers (data processors) who help us run the Service — for example cloud hosting and database (Supabase), email delivery (Resend), messaging (e.g. WhatsApp Business), calendar integration (Google), and push-notification gateways — under obligations of confidentiality and security;
  • government and statutory authorities (such as LHDN, EPF/KWSP, PERKESO/SOCSO) where required to operate statutory functions or comply with law;
  • professional advisers or authorities where required by law, court order, or to protect rights and safety.

We do not sell personal data.

7. Cross-border transfer

Our cloud infrastructure and some service providers may store or process data on servers located outside Malaysia. Where personal data is transferred outside Malaysia, we take reasonable steps to ensure a comparable level of protection and to comply with the PDPA's requirements on cross-border transfer.

8. Security

We apply administrative, technical and physical safeguards appropriate to the data, including access controls, encryption in transit, and tenant data isolation. No method of transmission or storage is completely secure, and we cannot guarantee absolute security.

9. Retention

We retain personal data for as long as needed to provide the Service and to meet legal, accounting and statutory obligations (for example, Malaysian employment and tax records). When data is no longer required, we take reasonable steps to delete or anonymise it. On account termination, Customer Data may be exported within thirty (30) days and is then deleted in line with our retention obligations.

10. Your rights under the PDPA

Subject to the PDPA, you have the right to:

  • access the personal data we hold about you;
  • correct inaccurate or incomplete personal data;
  • withdraw consent to processing;
  • limit the processing of your personal data; and
  • make a complaint to us or to the Personal Data Protection Commissioner.

If you are an employee, please direct access and correction requests to your employer in the first instance, as they control your employment data. We will assist the employer as data processor.

11. Cookies and similar technologies

We use strictly necessary cookies and local storage to keep you signed in, remember preferences, and secure the Service. We do not use the Service for third-party advertising.

12. Children

The Service is intended for use by businesses and their workforce. Where data relating to individuals under 18 is processed (for example, young employees), the Customer is responsible for obtaining any consent required under Malaysian law.

13. Changes to this Policy

We may update this Policy from time to time. We will post the updated version with a new "Last updated" date and, where changes are material, provide reasonable notice.

14. Contact us

To exercise your rights or for any privacy question, contact our data protection contact at privacy@staffe.io.

You may also contact the Personal Data Protection Department (Jabatan Perlindungan Data Peribadi, JPDP) Malaysia regarding your rights under the PDPA.