Privacy Policy
Effective Date: January 1, 2025 Last Updated: January 1, 2025
Eranis LLC ("Eranis," "we," "us," or "our") is committed to protecting the privacy of individuals who visit our website, register for our services, or whose data is processed through our platform. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our HR management platform and related services (collectively, the "Service").
By accessing or using the Service, you acknowledge that you have read, understood, and agree to be bound by this Privacy Policy. If you do not agree, please discontinue use of the Service immediately.
1. Information We Collect
1.1 Information You Provide Directly
Account Information: When you register for an account, we collect your name, email address, company name, and password.
Employer Data: Organizations using Eranis ("Customers") may input employee information including:
- Personal identifiers (name, email, phone number, address)
- Employment details (job title, department, hire date, employment type)
- Compensation data (salary, bonuses, allowances)
- Leave and attendance records
- Performance goals and reviews
- Documents (contracts, certifications, identification documents)
- Emergency contact information
- Education and training history
Communications: When you contact us for support or inquiries, we collect your name, email, and the content of your communications.
1.2 Information Collected Automatically
Usage Data: We automatically collect information about how you interact with the Service, including:
- IP address and approximate location
- Browser type and version
- Device information
- Pages visited and features used
- Date and time of access
- Referring URLs
Cookies and Similar Technologies: We use cookies, local storage, and similar technologies to maintain session state, remember preferences, and analyze Service usage. See Section 8 for more details.
1.3 Information from Third Parties
We may receive information from third-party authentication providers (such as Google or Microsoft) if you choose to sign in using those services, limited to your name, email address, and profile picture.
2. How We Use Your Information
We use the information we collect for the following purposes:
Service Delivery:
- Providing, maintaining, and improving the Service
- Processing leave requests, managing employee records, and generating reports
- Authenticating users and maintaining account security
Communications:
- Responding to inquiries and support requests
- Sending service-related notifications (e.g., password resets, system updates)
- Providing product updates and announcements (with opt-out available)
Analytics and Improvement:
- Analyzing usage patterns to improve features and user experience
- Identifying and fixing technical issues
- Conducting research and development for new features
Legal and Compliance:
- Complying with applicable laws and regulations
- Enforcing our Terms of Service
- Protecting against fraud, abuse, and security threats
3. Data Processing Roles
3.1 Eranis as Data Controller
For account holders and website visitors, Eranis acts as the data controller. We determine the purposes and means of processing your personal data in relation to account management, billing, and Service analytics.
3.2 Eranis as Data Processor
For employee data entered by Customers, Eranis acts as a data processor. Our Customers (employers) are the data controllers who determine what employee data to input and how it is used. We process this data solely according to our Customers' instructions and our Data Processing Agreement.
If you are an employee whose data is managed through Eranis, please contact your employer for information about how your data is processed. Your employer's privacy policies govern their collection and use of your information.
4. Data Sharing and Disclosure
We do not sell personal information. We may share information in the following circumstances:
With Customer Organizations: Employee data is accessible to authorized users within the Customer's organization according to their configured permissions and roles.
Service Providers: We engage trusted third-party providers to assist with:
- Cloud hosting and infrastructure (data centers)
- Email delivery services
- Payment processing
- Analytics services
- Customer support tools
These providers are contractually obligated to protect your data and may only process it for specified purposes.
Legal Requirements: We may disclose information if required by law, court order, or government request, or when we believe disclosure is necessary to:
- Comply with legal obligations
- Protect our rights, property, or safety
- Prevent fraud or security threats
- Protect the rights of others
Business Transfers: In the event of a merger, acquisition, or sale of assets, your information may be transferred to the acquiring entity. We will provide notice before your information becomes subject to a different privacy policy.
With Consent: We may share information for other purposes with your explicit consent.
5. Data Retention
Account Data: We retain account information for as long as your account is active. Upon account termination, we retain data for up to 90 days to allow for reactivation, after which it is deleted or anonymized.
Employee Data: Customer employee data is retained according to the Customer's instructions. Upon Customer request or contract termination, we delete employee data within 30 days, unless retention is required by law.
Usage Logs: Aggregated and anonymized usage data may be retained indefinitely for analytics and service improvement.
Backups: Backup copies may persist for up to 30 days after deletion from production systems.
6. Data Security
We implement industry-standard security measures to protect your information:
Technical Safeguards:
- Encryption in transit (TLS 1.2+) and at rest (AES-256)
- Row-level security ensuring tenant data isolation
- Regular security assessments and penetration testing
- Secure data centers with physical access controls
Organizational Safeguards:
- Employee background checks and security training
- Access controls based on principle of least privilege
- Incident response procedures
- Regular security audits
For more details, please see our Security page.
Despite our efforts, no method of transmission or storage is 100% secure. We cannot guarantee absolute security but will notify affected parties promptly in the event of a data breach as required by applicable law.
7. Your Rights and Choices
Depending on your location, you may have the following rights regarding your personal information:
Access: Request a copy of the personal data we hold about you.
Correction: Request correction of inaccurate or incomplete data.
Deletion: Request deletion of your personal data, subject to legal retention requirements.
Portability: Request your data in a structured, machine-readable format.
Restriction: Request restriction of processing in certain circumstances.
Objection: Object to processing based on legitimate interests.
Withdraw Consent: Where processing is based on consent, withdraw consent at any time.
For Account Holders: Exercise these rights by contacting us at privacy@eranis.com or through your account settings.
For Employees: If your employer uses Eranis, please contact your employer to exercise these rights. We will assist your employer in responding to verified requests.
8. Cookies and Tracking
We use the following types of cookies:
Essential Cookies: Required for the Service to function (authentication, security, preferences). Cannot be disabled.
Analytics Cookies: Help us understand how visitors interact with the Service. You may opt out via browser settings or our cookie preferences panel.
Marketing Cookies: Used to deliver relevant advertisements. We currently do not use marketing cookies but may in the future with appropriate notice.
Managing Cookies: Most browsers allow you to refuse or delete cookies. Note that disabling essential cookies may affect Service functionality.
9. International Data Transfers
Eranis is based in the United States. If you access the Service from outside the United States, your information may be transferred to, stored, and processed in the United States or other countries where our service providers operate.
For transfers from the European Economic Area (EEA), United Kingdom, or Switzerland, we rely on:
- Standard Contractual Clauses approved by the European Commission
- Adequacy decisions where applicable
- Your explicit consent where appropriate
10. Children's Privacy
The Service is not directed to individuals under 16 years of age. We do not knowingly collect personal information from children. If we become aware that we have collected data from a child, we will delete it promptly. If you believe we have collected information from a child, please contact us at privacy@eranis.com.
11. California Privacy Rights
If you are a California resident, you have additional rights under the California Consumer Privacy Act (CCPA):
- Right to Know: Request information about the categories and specific pieces of personal information we have collected.
- Right to Delete: Request deletion of your personal information.
- Right to Opt-Out: Opt out of the sale of personal information. Note: We do not sell personal information.
- Non-Discrimination: We will not discriminate against you for exercising your rights.
To exercise these rights, contact us at privacy@eranis.com or call [phone number to be added].
12. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of material changes by:
- Posting the updated policy on our website with a new "Last Updated" date
- Sending email notification to account holders for significant changes
- Displaying an in-app notification
Your continued use of the Service after changes take effect constitutes acceptance of the revised policy.
13. Contact Us
If you have questions or concerns about this Privacy Policy or our data practices, please contact us:
Eranis LLC Email: privacy@eranis.com Address: [Address to be added upon incorporation]
For data protection inquiries in the EU, you may also contact our designated representative at: [To be designated if required]
14. Regulatory Information
Supervisory Authority: If you are in the EEA and believe we have not adequately addressed your concerns, you have the right to lodge a complaint with your local data protection authority.
Wyoming Consumer Protection: Eranis LLC is organized under the laws of Wyoming, USA. Wyoming residents may contact the Wyoming Attorney General's Consumer Protection Unit for consumer protection matters.