Legal

Privacy Policy

This policy explains how WorkforceMS collects, uses, and protects personal data when you use our platform.

Version: 1.0Effective Date: September 2, 2026

1. Introduction

WorkforceMS ("we", "us", "our") operates an enterprise Human Resource Management platform — including the core WorkforceMS product, the BlindHire recruitment module, the Workforcely Learning Management and HMO Benefits module, and the HRMS Attrition Prediction module (collectively, the "Platform"). The Platform is provided to organisations ("Clients") that use it to manage their workforce, and to the individual employees, line managers, and HR administrators of those organisations ("End Users").

This Privacy Policy explains what personal data we collect when you use the Platform, why we collect it, how we use and protect it, who we may share it with, and what rights you have under applicable law. Please read it carefully.

By accessing or using WorkforceMS — whether as a Client or an End User — you acknowledge that you have read, understood, and agree to the practices described in this Policy.

2. Who This Policy Applies To

2.1 Clients (Organisations)

An organisation that subscribes to WorkforceMS and uses it to manage its employees. Clients are independent Data Controllers in respect of their employees' personal data. WorkforceMS acts as a Data Processor on behalf of Clients when processing employee data.

2.2 End Users (Employees & HR Personnel)

Individuals whose data is processed through the Platform because their employer is a Client — including employees, line managers, payroll administrators, and HR managers. This Policy primarily describes how WorkforceMS handles your data as a Processor on behalf of your employer.

2.3 Visitors

Anyone who visits our marketing website or contacts us directly. This Policy also applies to any personal data collected in those contexts.

3. Personal Data We Collect

The data we collect depends on which modules your organisation has enabled. Below is a comprehensive list by category:

3.1 Identity & Contact Information

  • Full name, staff ID, email address, phone number
  • Profile photo (optional, uploaded by the employee or HR)
  • Job title, department, employment type, and role within the Platform
  • Date of birth (used by the BlindHire recruitment module for age verification)

3.2 Employment & Payroll Data

  • Start date, probation end date, contract end date
  • Base salary, allowances, deductions, net pay, and payslip history
  • Leave records (type, dates, status, and approval history)
  • Attendance records (clock-in/clock-out timestamps, late arrivals, shift details)
  • Performance appraisal scores, grades, and reviewer comments
  • Training assignments, completion status, and certificates (Workforcely module)
  • HMO plan enrolment and out-of-pocket reimbursement claims (Workforcely module)

3.3 Recruitment Data (BlindHire Module)

  • Candidate name, email, phone number, gender, and school (collected at application)
  • CV text, skills, years of experience, and AI-generated match score
  • Application stage and hiring decisions
  • Blind screening flags — personally identifiable fields can be hidden from recruiters until manually revealed by an authorised HR administrator

3.4 Workforce Analytics Data (HRMS Module)

  • Attrition prediction inputs: derived numeric attributes such as tenure, job level, overtime history, salary progression, and training frequency — computed from employment records already held on the Platform
  • Survey responses: job satisfaction, work-life balance, and environmental satisfaction scores, entered directly by the employee or HR
  • Attrition risk scores and model predictions — these are analytical outputs, not raw personal data, and are accessible only to authorised HR administrators

3.5 Wellbeing Data

  • Mood check-in scores and optional free-text notes submitted through the Wellness module
  • Anonymous counselling requests — where a request is marked anonymous, the employee's identity cannot be recovered even with direct database access

3.6 Disciplinary & Governance Records

  • Disciplinary queries, written warnings, suspension records, and outcome notes
  • Staff misconduct reports — which may be submitted anonymously

3.7 Technical & Usage Data

  • IP address, device type, browser or app version, and operating system
  • Session timestamps, pages visited, and features used (for security and product improvement)
  • Audit log entries — a timestamped record of every significant action taken on the Platform (e.g. profile updates, role changes, payroll approvals) — retained for compliance and security purposes

4. How We Use Your Data

We use personal data for the following purposes:

4.1 Platform Operation

  • Authenticating users and managing access control (JWT-based single sign-on across all modules)
  • Displaying employee profiles, dashboards, and records to authorised personnel
  • Processing payroll runs and generating payslips
  • Managing attendance, leave, and appraisal workflows

4.2 Recruitment (BlindHire)

  • Processing job applications and running AI-assisted blind screening
  • Supporting hiring decisions through a structured recruitment pipeline
  • Anonymising candidate data to reduce unconscious bias during shortlisting

4.3 Learning & Benefits (Workforcely)

  • Tracking course enrolment, progress, and quiz completion
  • Issuing verified learning certificates
  • Processing HMO enrolments and claims

4.4 Attrition Prediction (HRMS)

  • Computing derived metrics from employment records to generate an attrition risk score per employee
  • Presenting risk labels and actionable recommendations to HR administrators
  • Improving the prediction model using historical employment and exit data

4.5 Compliance & Security

  • Maintaining audit logs for accountability and regulatory compliance
  • Investigating security incidents or policy violations
  • Fulfilling legal obligations under Nigerian law, including the NDPA 2023 and NDPR 2019

4.6 Product Improvement

  • Analysing aggregated, de-identified usage patterns to improve Platform features
  • We do not use personal data for advertising purposes, and WorkforceMS products are ad-free

5. Legal Basis for Processing

Under the Nigeria Data Protection Act 2023 and NDPR 2019, we rely on the following lawful bases:

6. Who We Share Your Data With

We do not sell personal data. We share data only in the circumstances described below:

6.1 Within the WorkforceMS Ecosystem

WorkforceMS, BlindHire, Workforcely, and HRMS share a common Supabase backend. Data flows between modules only to the extent necessary to deliver the integrated service — for example, employment records are passed to the HRMS module via a narrow, JWT-authenticated API to generate attrition predictions. Each module enforces row-level security so that only authorised roles can read data relevant to their function.

6.2 Client Organisations

Your employer (the Client) has access to your employment data within the Platform through the HR console and, where applicable, the line manager portal. WorkforceMS does not control how Clients use that data within their own HR processes; Clients are independently responsible for compliance with applicable data protection law in relation to their employees.

6.3 Service Providers (Sub-processors)

We engage trusted third-party sub-processors to operate the Platform:

  • Supabase — cloud database and file storage (data may be hosted in the EU or US; Supabase is SOC 2 certified)
  • Paystack — payment processing for payroll disbursements (where enabled)
  • Netlify / Vercel — web application hosting
  • Groq / OpenAI — AI inference for BlindHire CV screening and HRMS attrition modelling (data is processed transiently and not used to train third-party models)

All sub-processors are contractually bound to process data only as instructed and to maintain appropriate security standards.

6.4 Legal Disclosure

We may disclose personal data if required to do so by law, court order, or in response to a lawful request by a regulatory authority, including the Nigeria Data Protection Commission (NDPC).

6.5 Business Transfers

If WorkforceMS is involved in a merger, acquisition, or asset sale, personal data may be transferred as part of that transaction. Affected users will be notified before data becomes subject to a different privacy policy.

7. Data Retention

We retain personal data for as long as necessary to fulfil the purposes described in this Policy, or as required by law:

  • Active employee records — retained for the duration of the employment relationship and for 6 years after termination (in line with Nigerian labour and tax record-keeping requirements).
  • Payroll and payslip data — 7 years from the date of payment, in compliance with FIRS requirements.
  • Recruitment data (BlindHire) — 12 months from the close of a hiring round, after which unsuccessful candidate data is deleted unless the candidate consents to a longer retention period.
  • Wellness check-in data — 12 months from submission; anonymised aggregate data may be retained indefinitely.
  • Audit logs — 3 years from the date of the logged event.
  • Attrition model data — retained for as long as the HRMS module is active for the Client; de-identified training data used to improve the model may be retained indefinitely.

When data is no longer required, it is securely deleted or irreversibly anonymised.

8. Data Security

We implement appropriate technical and organisational measures to protect personal data against unauthorised access, loss, destruction, or alteration:

  • All data is transmitted over TLS 1.2 or higher.
  • Data at rest is encrypted using AES-256 (Supabase default).
  • Row-Level Security (RLS) is enforced at the database level — each row of data is accessible only to authenticated users whose role authorises it, within their employer's company context.
  • JWT-based authentication with short-lived tokens is used for all API access and cross-module communication.
  • Sensitive fields (e.g. bank account numbers, anonymous report identities) are designed to be non-recoverable even with direct database access.
  • All significant platform actions are recorded in an immutable audit log.
  • Access to production infrastructure is restricted to authorised WorkforceMS engineers and is subject to multi-factor authentication.

No method of transmission or storage is 100% secure. If you believe your data has been compromised, please contact us immediately at security@workforcems.com.

9. Your Rights

Under the Nigeria Data Protection Act 2023, you have the following rights in relation to your personal data:

  • Right of access — you may request a copy of the personal data we hold about you.
  • Right to rectification — you may request that inaccurate or incomplete data be corrected.
  • Right to erasure — you may request deletion of your data where it is no longer necessary for the purposes for which it was collected, subject to legal retention obligations.
  • Right to restrict processing — you may ask us to pause processing of your data in certain circumstances.
  • Right to data portability — you may request a machine-readable copy of data you have provided to us.
  • Right to object — you may object to processing based on legitimate interests.
  • Right to withdraw consent — where processing is based on consent (e.g. wellness check-ins), you may withdraw consent at any time without affecting the lawfulness of prior processing.

To exercise any of these rights, contact your employer's HR administrator (who acts as the Data Controller for your employment data) or contact WorkforceMS directly at privacy@workforcems.com. We will respond within 30 days. Note that some requests may need to be directed to your employer, as they control certain decisions about your employment data.

If you are dissatisfied with our response, you have the right to lodge a complaint with the Nigeria Data Protection Commission (NDPC) at ndpc.gov.ng.

10. International Data Transfers

WorkforceMS is a Nigerian platform and we aim to keep data within Nigeria wherever possible. However, some of our sub-processors (Supabase, Groq) may process data outside Nigeria. Where this occurs, we ensure that appropriate safeguards are in place — including contractual clauses that meet the transfer conditions under the NDPA 2023 — to ensure your data receives an equivalent level of protection.

11. Children's Data

WorkforceMS is an enterprise platform intended for use by organisations and their adult employees. We do not knowingly collect personal data from individuals under the age of 18. If you believe a minor's data has been submitted to the Platform, please contact us at privacy@workforcems.com and we will promptly delete it.

12. Anonymous Features

Certain features of the Platform are designed to be genuinely anonymous:

  • Anonymous staff misconduct reports — where a report is submitted anonymously, no reporter identity is stored. The anonymous report cannot be linked back to the submitter even by WorkforceMS engineers with direct database access.
  • Anonymous wellness check-ins — where the anonymous option is selected, the check-in is not linked to an employee record.
  • Anonymous counselling requests — as above, the submitter's identity is not recoverable.

Non-anonymous reports and check-ins are linked to your profile and are visible to authorised HR administrators within your organisation.

13. Cookies and Tracking

The WorkforceMS web application uses essential session cookies for authentication and security. We do not use advertising cookies, third-party tracking pixels, or behavioural profiling technologies.

The WorkforceMS mobile application (Flutter) does not use cookies. Authentication state is managed using secure local storage of JWT tokens on the device.

14. Client Responsibilities (Data Controllers)

When your organisation subscribes to WorkforceMS, it acts as the Data Controller for its employees' personal data. As the Data Controller, your organisation is responsible for:

  • Ensuring there is a lawful basis for processing employee data through the Platform.
  • Informing employees about the use of WorkforceMS and directing them to this Privacy Policy.
  • Responding to employee data rights requests that relate to employment data.
  • Ensuring that HR administrators and line managers use the Platform in compliance with applicable data protection law.

WorkforceMS acts as a Data Processor on behalf of Clients and processes employee data only in accordance with Client instructions and this Policy.

15. Changes to This Policy

We may update this Privacy Policy from time to time to reflect changes in the Platform, applicable law, or our practices. When we make material changes, we will:

  • Update the "Effective Date" at the top of this document.
  • Notify Client HR administrators via the Platform dashboard.
  • Where required by law, seek fresh consent for any new processing.

Continued use of the Platform after the effective date of a revised Policy constitutes acceptance of the updated terms.

See the whole platform, one login.

Book a walkthrough of WorkforceMS running as a single platform for your team.

Request a demo