Data Policy

Data Retention Policy:

What kind of data will be stored in this application?

The basic identity information such as first name, last name, email address, and web data such as IP address and cookies of the users will be stored. It is stored so as to identify the specific users whenever they log in/sign in to our application. 

Besides the above-mentioned data, no other kind of data will be stored in our application under any such circumstances. 

Data Archival/Removal Policy:

How long will the data be kept?

Both the basic identity information and the web data will be deleted either upon the concerned user’s request or on the set time limit, i.e. 5 years once. However, there’s one exception to the above criteria; the email address of the registered users alone will be archived for an indefinite period purely for the sole reason of identifying our old users – wherever they tried to sign in/log in to our application in future. 

What will be done with the data that is no longer required?

In compliance with General Data Protection Regulation (GDPR), we delete the data that is classified as no longer required for every 5 years once except the user’s email address purely for the reasons stated earlier. Apart from this set time limit, the data will be deleted whenever and however required if the concerned user wants us to. 

Data Storage Policy:

Where will the data be stored/kept?

At Hoursheets, we respect and commit to safeguarding our users’ information. For us, data security is a non-compromisable factor that in turn makes us continuously ensure that  all the measures are in place to avoid any kind of data leakage and security breaches. Both the basic identity and web data will be stored in our highly protected cloud servers (US) and Amazon S3 buckets. 

Sub-processors

To offer the best out of our products & services, we make use of third-party vendors which helps in the effective running of the application with timely enhancements. To ensure data protection is in place, we sign up vendors that process personal data only with GDPR-compliant data processing agreements.

The list of third-party vendors to whom we share personal or sensitive data with:

  • Stripe – Billing
  • DigitalOcean – Server
  • Amazon S3 –  Storage
  • Google Analytics – Analytics
  • Amazon SES – Communication