Privacy Policy
Last updated: 31 August 2026 · Applies to BIMHR and all regional brands operated by the platform.
This Privacy Policy explains how BIMHR collects, uses, discloses, and protects personal data when you visit our website, register your company, or use the platform as an employee of a customer organisation. For employee data stored by our customers, the customer is the data controller and BIMHR acts as a data processor acting only on their instructions.
1. Who we are
BIMHR is a cloud HR and payroll platform for Caribbean employers, operated from Barbados. For data we collect directly (website visitors, customer administrators, billing contacts), BIMHR is the data controller. For workplace data our customers store about their employees, the customer is the controller and we are the processor; employees should first raise requests with their employer.
2. Data we collect
- Account data — name, work email, password (hashed), role, company details, employer tax IDs.
- Workplace data (on behalf of customers) — employment records, schedules, timesheets, GPS location at clock-in/out, leave, pay and statutory deduction figures, documents, and audit events.
- Usage data — pages viewed, actions taken, device/browser type, IP address, and security events used for access control and abuse prevention.
- Support data — messages you send to our support channels.
3. How we use data
We use personal data to: provide and secure the Service (including GPS/geofence validation of clock-ins and anti-spoofing checks); process subscriptions and invoices; send transactional email such as payslip notifications; provide support; meet legal, tax, and audit obligations; and improve the product on an aggregated basis. We do not sell personal data and we do not use customer workplace data for advertising.
4. Lawful bases and employee monitoring
We process data under performance of a contract, legitimate interests (security, abuse prevention, product improvement), consent where required, and legal obligation. GPS clock-in verification is a security feature controlled by the employer: employers are responsible for notifying employees about location monitoring and for having a lawful basis to use it. Location is captured only around clock-in/clock-out actions and is not continuously tracked.
5. Sharing and subprocessors
We share personal data only with: cloud infrastructure and database providers (hosting the Service), transactional email providers, payment/invoicing providers where applicable, and professional advisers under confidentiality — each bound by written agreements and only processing as needed to deliver the Service. We disclose data to authorities where legally compelled, with notice to the affected customer unless prohibited.
6. International transfers
The Service is hosted on cloud infrastructure that may be located outside the Caribbean. Where personal data crosses borders, we rely on provider safeguards (such as standard contractual clauses) and encrypt data in transit and at rest.
7. Retention
Account and workplace data are retained while a subscription is active. After a trial ends without purchase, provisioned data is retained for 90 days and then deleted. After termination, Tenant Data can be exported for 30 days and is deleted within 90 days thereafter, except records we must keep by law (statutory payroll and audit records follow the customer’s statutory retention schedule). Backup copies age out within a further 35 days.
8. Security
We apply defence-in-depth: TLS in transit, encryption at rest, row-level security isolating every tenant, strict signed session cookies, role-based access control, rate limiting, immutable audit logs, and least-privilege staff access. No system is perfectly secure; we will notify affected customers of confirmed personal-data breaches without undue delay and within the timeframes required by applicable law.
9. Your rights
Subject to applicable law (including Barbados’ Data Protection Act and, where applicable, GDPR or similar regimes), you may request access, correction, deletion, restriction, portability, and objection to processing of your personal data, and you may withdraw consent where processing is based on consent. Customer administrators: use in-app exports or contact us. Employees: contact your employer first — we will support them in fulfilling valid requests. You may also complain to your local data-protection authority.
10. Cookies
The Service uses strictly necessary cookies for authentication and session security. The marketing site uses a minimal set of functional preferences (such as theme and region). We do not run third-party advertising trackers.
11. Changes and contact
We will post any changes to this policy on this page and update the “Last updated” date; material changes affecting customer data will be announced in-app or by email. Contact our data-protection point of contact at privacy@bimhr.com.