Matrics HR

Privacy Policy

Last updated: 3 August 2026

1. Who we are

Matrics HR is a human-resources management platform operated by Matrics (“Matrics”, “we”, “us”). The platform is sold to employers, who use it to manage their own employee records, time off, recruitment, performance reviews and related HR processes.

For the personal data of an employer’s staff and job applicants, the employer is the data controller and Matrics acts as a data processor on their instructions. For data about our own visitors and prospective customers, Matrics is the controller.

2. Data we process

Depending on what an employer configures, the platform stores:

  • Identity and contact data — name, work email address, phone number, profile photo.
  • Employment data — job title, department, office, reporting line, start and end dates, employment status, contract details.
  • HR process data — time-off requests and balances, performance reviews and feedback, onboarding and offboarding checklists, assigned assets, daily priorities and project assignments.
  • Recruitment data — applications, CVs and supporting documents submitted through our careers pages.
  • Documents — files uploaded to an employee record by the employer or the employee.
  • Technical data — authentication events, IP address and audit logs needed to operate and secure the service.

3. How we use it

We process this data solely to provide the platform to the employer: authenticating users, showing each user the records they are authorised to see, running the HR workflows the employer has enabled, sending service notifications by email, and keeping the service secure and available.

We do not sell personal data. We do not use it for advertising or ad profiling, and we do not use it to train generalised artificial-intelligence or machine-learning models.

4. Google user data

Matrics HR offers optional integrations with Google services. They are off unless an employer or user connects them, and each requires your explicit consent through Google’s own permission screen. Google Drive is available today; Google Calendar is described below as planned and is not enabled yet.

  • Google Drive (drive.readonly) — used only to let you attach a file from your own Drive to an employee or recruitment record. We read a file only at the moment you pick it in the Google file picker, and we store only that file and its name. We do not browse, index or otherwise read the rest of your Drive.
  • Google Calendar — not enabled today. We are building calendar scheduling for interviews and onboarding sessions. When it is released it will read availability and create, update or cancel events for that scheduling only, accessing only the calendars you grant and only the event fields needed. It will require your explicit consent through Google’s permission screen, and this policy will be updated before it is switched on.

Matrics HR’s use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

Concretely, that means data obtained from Google APIs is used only to provide or improve the user-facing features described above; it is never transferred to others except as necessary to provide those features, to comply with applicable law, or as part of a merger or acquisition; it is never used for advertising; and no human reads it unless you have given explicit consent for specific messages, it is necessary for security or to comply with applicable law, or the data is aggregated and de-identified.

You can revoke our access at any time from your Google account permissions page, or by disconnecting the integration in Matrics HR settings.

5. Sharing and sub-processors

We share data only with service providers who help us run the platform, under contract and only for that purpose. These are:

  • Google Cloud Platform — application hosting, managed database, file storage.
  • Our transactional email provider — delivery of service notification emails.

We also disclose data where we are legally required to do so. We do not otherwise share personal data with third parties.

6. Retention

We keep employer data for as long as the employer’s account is active. When an account is closed, we delete or irreversibly anonymise the data within 90 days, unless a longer period is required by law. Employers can delete individual records at any time from within the platform. Audit logs are kept for up to 12 months for security purposes.

7. Security

Data is encrypted in transit (TLS) and at rest. Access is authenticated through Keycloak with role-based permissions, and each customer’s data is isolated by tenant. Administrative access to production systems is restricted to named engineers, logged, and granted on a least-privilege basis.

8. Your rights

Subject to applicable law, you may request access to your personal data, correction of inaccurate data, deletion, restriction of processing, portability, or object to processing. If your data is held in the platform by your employer, please contact your employer’s HR team first, as they control that data — we will assist them in responding. You can also contact us directly using the details below.

9. International transfers

Our infrastructure runs in Google Cloud. Where data is transferred outside your jurisdiction, we rely on the safeguards offered by our providers, including the European Commission’s Standard Contractual Clauses where applicable.

10. Changes to this policy

We may update this policy as the platform evolves. Material changes will be announced in the application or by email to account administrators, and the “last updated” date above will change.

11. Contact

For any privacy question or request, contact us at privacy@matrics.hr.

This policy covers the Matrics HR application and the personal data processed within it.

powered by Matrics HR