Legal
Privacy Policy
Last updated: [DATE]
1. Introduction
This Privacy Policy explains how [LEGAL ENTITY NAME] (“StaffiX,” “we,” “us,” or “our”) collects, uses, stores, and protects personal information when you use the StaffiX bot, website, and related services (the “Services”). StaffiX is a workforce-automation assistant that operates inside chat platforms such as Slack and LINE WORKS (and Microsoft Teams when available) to handle attendance, breaks, leave, daily reports, and payroll-related tasks.
By installing StaffiX or using our Services, you agree to the practices described here. If you do not agree, please do not use the Services.
This policy is written to comply with the EU/UK General Data Protection Regulation (GDPR), the California Consumer Privacy Act as amended by the CPRA (CCPA/CPRA), and Japan's Act on the Protection of Personal Information (APPI).
2. Who we are (Data Controller / Processor)
For the personal data of your employees that we process to deliver the Services, your organization (the customer) is the data controller and StaffiX acts as a data processor, processing data on your documented instructions.
For data we collect directly about website visitors and account administrators (for example, marketing and billing data), StaffiX is the data controller.
- Legal entity: [LEGAL ENTITY NAME]
- Address: [REGISTERED ADDRESS]
- Data Protection contact: [PRIVACY/DPO EMAIL]
3. Information we collect
3.1 Information you provide
- Account and billing details: name, work email, company name, role, and payment information when you register or subscribe.
- Support communications: any message, attachment, or detail you share with our support team.
3.2 Information from your chat platform
When StaffiX is installed in Slack or LINE WORKS, we receive — based on the permissions granted at installation — information needed to operate the bot, which may include:
- User identifiers (such as your platform user ID, name, and workspace/team ID).
- Profile information made available by the workspace (such as display name and email).
- The content of messages and commands you send to the StaffiX bot(for example, “checkin,” “break,” “leave Friday”) and the bot's responses.
StaffiX reads only the messages directed to it or posted in channels it is invited to. We do not read your team's general private conversations.
3.3 Information StaffiX generates
- Attendance, check-in/out, break, and leave records.
- Daily progress reports submitted through the bot.
- Work-hours data used for payroll-related exports.
- Usage and diagnostic logs that help us keep the Services reliable and secure.
3.4 Information collected automatically on our website
Cookies and similar technologies, IP address, browser type, device information, and pages visited. See Section 10 (Cookies).
4. How we use information
We use personal information to:
- Provide, operate, and maintain the Services (record attendance, manage leave, generate reports and payroll exports).
- Authenticate users and secure accounts.
- Respond to support requests — with your permission, our team may review your interaction logs with the bot to diagnose an issue.
- Send service-related communications (system updates, security notices, billing).
- Send product and best-practice emails, where permitted, which you can opt out of at any time.
- Improve and develop the Services, including aggregated and de-identified analytics.
- Comply with legal obligations and enforce our Terms.
We do not sell your personal information, and we do not use the content of your bot conversations to train third-party advertising models.
5. Legal bases for processing (GDPR)
Where GDPR applies, we rely on:
- Contractual necessity — to deliver the Services you signed up for.
- Legitimate interests — to secure, maintain, and improve the Services, balanced against your rights.
- Consent — for optional marketing communications and non-essential cookies, which you may withdraw at any time.
- Legal obligation — where we must retain or disclose data to comply with the law.
6. How we share information
We share personal information only as needed to run the Services:
- Sub-processors — vetted third parties that provide hosting, payment processing, analytics, and support tooling, under contracts requiring them to protect your data. A current list of sub-processors, including their role and location, is available at [SUB-PROCESSOR LIST URL] or on request.
- Your chat platform — Slack or LINE WORKS, as required to deliver bot functionality.
- Legal and safety — where required by law, court order, or to protect rights and safety.
- Business transfers — in connection with a merger, acquisition, or asset sale, with notice to you.
We do not sell or rent personal information to third parties.
7. International data transfers
We may process data in countries other than your own, including the United States and Japan. Where we transfer personal data internationally, we use appropriate safeguards such as Standard Contractual Clauses (for GDPR) and equivalent protections required under APPI.
8. Data retention
We retain personal data for as long as StaffiX is installed on your workspace and your account is active, plus any period required to meet legal, accounting, or reporting obligations. Specific retention periods by data type are set out at [RETENTION SCHEDULE URL].
When you uninstall StaffiX or request deletion, we will delete or de-identify your data within [NUMBER] days, except where retention is legally required.
9. Your privacy rights
Depending on where you live, you have rights over your personal information.
Under GDPR/UK GDPR, you have the right to: access; rectification; erasure; restriction of processing; objection to processing; data portability; withdraw consent; and lodge a complaint with a supervisory authority.
Under CCPA/CPRA (California), you have the right to: know what we collect; access and delete; correct; opt out of sale/sharing (note: we do not sell data); and not be discriminated against for exercising your rights.
Under APPI (Japan), you have the right to: request disclosure, correction, addition, deletion, and cessation of use of your retained personal data.
Because your employer is usually the controller of your workforce data, employee requests may be directed to your employer first. To exercise any right, contact us at [PRIVACY EMAIL]. We will respond within the timeframe required by applicable law.
10. Cookies
Our website uses cookies for essential functionality, analytics, and (with consent) marketing. You can control cookies through your browser settings or our cookie banner. Disabling some cookies may affect site functionality. For details, see our Cookie Policy at [COOKIE POLICY URL].
11. Security
We protect your data with technical and organizational measures, including encryption in transit and at rest, role-based access controls, restricted internal access, and regular security reviews. Data is hosted on reputable cloud infrastructure. No method of transmission or storage is 100% secure, but we work continuously to protect your information and will notify you and any regulator of a qualifying data breach as required by law.
12. Children's privacy
The Services are intended for use by businesses and their employees. They are not directed to children, and we do not knowingly collect personal data from anyone under [16/18].
13. Changes to this policy
We may update this Privacy Policy from time to time. We will post the updated version with a new “Last updated” date and, where required, notify you. Continued use of the Services after changes take effect constitutes acceptance.
14. Contact us
Questions about this policy or your data? Contact:
- Email: [PRIVACY/DPO EMAIL]
- Address: [REGISTERED ADDRESS]
- EU/UK representative (if applicable): [REPRESENTATIVE]
Pre-publication checklist
- Lawyer review of both documents
- Fill all [BRACKETED] placeholders
- Confirm legal entity name and registered address
- Publish sub-processor list and link it
- Define and publish data retention schedule
- Finalize refund policy with counsel
- Add Data Processing Agreement (DPA) for enterprise customers
- Link Privacy ↔ Terms ↔ Cookie Policy in the footer (Terms)
- Add cookie consent banner if serving EU/UK visitors
- Provide Japanese-language versions if targeting Japan (APPI best practice)
