Privacy Policy

Effective date: July 1, 2026

Hafinen Limited (“Hafinen”, “we”, “us”, or “our”) respects your privacy and is committed to protecting personal data entrusted to us.

This Privacy Policy explains how we collect, use, disclose, process, transfer, and safeguard personal data in connection with the Hafinen platform, websites, APIs, mobile applications, integrations, communication tools, analytics systems, and related services (collectively, the “Services”).

Hafinen is a global Human Capital Management (HCM) platform supporting workforce administration, recruitment, payroll, attendance, compliance, productivity, and related business operations.

By using our Services, you acknowledge that your personal data may be processed as described in this Privacy Policy.

1. Scope

This Privacy Policy applies to organization administrators, employees, contractors, candidates, job applicants, recruiters, staffing agencies, website visitors, API users, and integration users.

This Privacy Policy does not govern personal data processed by our customers where Hafinen acts solely as a processor on behalf of that customer except as required by applicable law or our contractual obligations.

2. Data Controller and Processor Roles

Depending on the context:

  • Customer Organizations are typically the Data Controllers for workforce, employee, payroll, candidate, and operational data uploaded into Hafinen.
  • Hafinen acts as a Data Processor when processing such data on behalf of customers.
  • Hafinen acts as an independent Data Controller for account registration data, billing information, support communications, website analytics, marketing communications, and platform security logs.

Customers are solely responsible for establishing lawful grounds for collecting and uploading personal data into Hafinen.

3. Information We Collect

A. Account and Organization Data

We collect names, email addresses, phone numbers, company names, business registration details, billing addresses, and subscription records.

B. Workforce Data

Customers may upload employee records, organizational hierarchies, departments, job titles, compensation records, leave records, attendance records, shift schedules, disciplinary records, performance reviews, training history, resignation and termination records, internal meeting records, and workflow approvals.

C. Recruitment Data

This may include CVs/resumes, cover letters, interview notes, candidate assessments, reference information, recruitment pipeline data, and hiring decisions.

Where staffing agencies use Hafinen, candidate data may relate to third-party employment placements.

D. Payroll and Financial Data

This may include salary information, tax records, deductions, allowances, statutory contributions, payroll history, and banking details where provided by customers.

E. Biometric Attendance Data

Hafinen supports fingerprint and facial attendance systems.

Hafinen does not store raw biometric images.

Biometric devices integrated with Hafinen store encrypted biometric templates or tokens. Hafinen may process attendance events, timestamps, and authentication outcomes associated with those templates.

Customers are responsible for obtaining all legally required employee notices, consents, or authorizations.

F. Compliance and Document Data

This includes contracts, policy acknowledgements, compliance certifications, licenses, disciplinary documentation, and employee documents.

G. Technical Data

We collect IP addresses, browser information, device information, operating system data, API logs, webhook logs, usage analytics, crash logs, and security logs.

H. AI-Assisted Workflow Data

Where enabled, Hafinen may process data for CV screening, document summarization, policy drafting, internal knowledge search, regulatory intelligence, and analytics recommendations.

AI outputs are generated for assistance purposes and should be independently reviewed by customers.

Additional governance for AI features is outlined in Hafinen’s AI Usage Policy.

4. How We Collect Information

We collect data directly from users, from customer organizations, through integrations, via APIs, through webhooks, through cookies, from connected biometric systems and through support interactions.

5. Lawful Basis for Processing

Where applicable, Hafinen relies on contract performance, legitimate interests, legal obligations, consent, employment obligations, and customer instructions as processor.

6. How We Use Information

We use personal data to deliver the Services, maintain accounts, process payroll, manage attendance, support recruitment workflows, manage assets, manage training programs, support compliance obligations, enable analytics, improve service reliability, secure the platform, prevent fraud, provide customer support, process payments, send product communications, and comply with laws.

7. Cookies and Tracking Technologies

Hafinen uses cookies and similar technologies to operate, secure, and improve the Services.

These technologies may support authentication, analytics, performance optimization, user preferences, and security monitoring.

For more detailed information, including the types of cookies used and how to manage them, please review our Cookie Policy at:

https://www.hafinen.com/cookies

8. Sharing and Disclosure

We may disclose personal data to infrastructure providers, payment processors, email service providers, SMS providers, analytics providers, support providers, legal authorities, auditors, professional advisors, and authorized Subprocessors listed in our Subprocessor Disclosure Page.

9. Subprocessors

Hafinen engages carefully selected third-party service providers (“Subprocessors”) to support the delivery, security, infrastructure, communications, and payment processing functions of the Services.

These Subprocessors may process Personal Data only as necessary to perform services on Hafinen’s behalf and under contractual obligations requiring confidentiality, security, and applicable data protection compliance.

Hafinen maintains an up-to-date public list of its authorized Subprocessors, including their service roles and processing regions, at:

https://www.hafinen.com/subprocessors

Hafinen may update its Subprocessors from time to time to improve service reliability, performance, compliance, or operational efficiency.

10. International Data Transfers

Your data may be processed in multiple jurisdictions.

Where required, Hafinen uses appropriate safeguards including contractual protections and equivalent lawful transfer mechanisms.

11. Data Retention

We retain data:

  • for active accounts during subscription
  • up to ninety (90) days after account termination
  • longer where required for legal compliance, dispute resolution, security, or backups

After retention periods expire, data may be deleted, anonymized, or aggregated.

12. Security

We implement technical and organizational safeguards including encryption in transit, access controls, audit logging, infrastructure segmentation, DDoS protection, and authentication controls.

13. Data Breach Notification

Where legally required, Hafinen will notify affected customers of confirmed security incidents without undue delay.

14. Your Rights

Depending on your jurisdiction, you may have rights to access, correction, deletion, objection, restriction, portability, and withdrawal of consent.

Requests involving customer-controlled workforce data must generally be directed to the relevant employer or organization.

15. Children

Hafinen is not intended for individuals under 18.

16. Changes

We may update this Privacy Policy periodically.

17. Contact

Hafinen Limited 107 Lower Kabete Road Westlands, Nairobi, Kenya Email: [email protected]

O le yan iru kukisi iyan Hafinen le lo lati mu iriri rẹ pọ si. Ni pataki pataki ati awọn kuki aabo nigbagbogbo ṣiṣẹ nitori wọn ṣe pataki fun ijẹrisi, aabo pẹpẹ, idena jibiti, ati iṣẹ igbẹkẹle ti Awọn iṣẹ naa. O le ṣe imudojuiwọn awọn ayanfẹ rẹ nigbakugba.

Muna Pataki Cookies

Awọn kuki wọnyi ṣe pataki fun Hafinen lati ṣiṣẹ ni aabo ati igbẹkẹle. Wọn ṣe atilẹyin ijẹrisi akọọlẹ, awọn akoko iwọle, aabo CSRF, ilọsiwaju igba to ni aabo, iwọntunwọnsi fifuye, ati iṣẹ ṣiṣe ipilẹ ipilẹ miiran. Nitoripe awọn kuki wọnyi nilo fun Awọn iṣẹ lati ṣiṣẹ, wọn ko le ṣe alaabo.

Awọn kuki aabo

Awọn kuki wọnyi ṣe iranlọwọ lati daabobo akọọlẹ rẹ ati Awọn iṣẹ nipasẹ wiwa iṣẹ ifura, idilọwọ iraye si laigba aṣẹ, idinku ilokulo, ifẹsẹmulẹ awọn ibeere API, didiwọn oṣuwọn atilẹyin, ati mimu iduroṣinṣin pẹpẹ mu. Awọn kuki wọnyi nilo fun aabo ati pe ko le ṣe alaabo.

Awọn kuki iṣẹ ṣiṣe

Awọn kuki iṣẹ-ṣiṣe ranti awọn ayanfẹ rẹ ati ṣe akanṣe iriri rẹ. Wọn le tọju ede, agbegbe aago, akori, awọn eto iraye si, awọn isọdi wiwo, ati awọn ayanfẹ dasibodu nitorina o ko nilo lati tunto wọn nigbakugba ti o ba lo Awọn iṣẹ naa.

Awọn kuki atupale

Awọn kuki atupale ṣe iranlọwọ fun wa lati loye bi a ṣe lo Awọn iṣẹ naa ki a le mu ilọsiwaju lilo, iṣẹ ṣiṣe, ati igbẹkẹle pọ si. Wọn gba alaye gẹgẹbi isọdọmọ ẹya, awọn ibaraẹnisọrọ oju-iwe, awọn ilana lilọ kiri, ibaramu ẹrọ aṣawakiri, awọn ijabọ jamba, ati awọn metiriki iṣẹ. Nibiti o ti ṣeeṣe, alaye yii jẹ akojọpọ tabi aimọ.

Awọn kuki iṣẹ ṣiṣe

Awọn kuki iṣẹ ṣiṣe ni ilọsiwaju iyara, iduroṣinṣin, ati idahun ti Awọn iṣẹ naa. Wọn ṣe atilẹyin caching, iṣapeye ifijiṣẹ akoonu, iwọntunwọnsi ijabọ, ikojọpọ dukia, ati awọn imọ-ẹrọ miiran ti o ṣe iranlọwọ lati fi iriri olumulo deede ati igbẹkẹle han.

Awọn kuki ibaraẹnisọrọ

Awọn kuki ibaraẹnisọrọ ṣe atilẹyin awọn ibaraẹnisọrọ ti o ni ibatan iṣẹ gẹgẹbi ifijiṣẹ iwifunni, ipasẹ iṣẹlẹ imeeli, awọn iṣeduro SMS, ati awọn iṣan-iṣẹ ibaraẹnisọrọ iṣẹ miiran ti o mu bi a ṣe jẹ ki o sọ fun nigba lilo Awọn iṣẹ naa.