How CloudHR collects, uses and protects personal data — for the organisations that use our platform, and for the people whose records it holds.
Last updated: 13 September 2026
Cloud HR Limited, a company registered in Ireland and trading as CloudHR, provides human-resources, payroll and workforce management software to organisations, mainly in Ireland.
This policy explains what we do with personal data when you visit this website, create an account, or use the platform.
Address: 39 Dominick Street Lower, Dublin 1, Ireland
Email: info@cloudhr.ie
WhatsApp: +353 89 467 8033
Data protection questions, and requests to exercise the rights set out below, should go to info@cloudhr.ie. We answer within one month, as the GDPR requires.
The platform and its databases are hosted in the European Union. Each customer organisation has its own separate database, described in section 5.
Tell us first and we will try to put it right. You also have the right to complain to the Irish supervisory authority at any time:
Data Protection Commission
21 Fitzwilliam Square South, Dublin 2, D02 RD28, Ireland
www.dataprotection.ie
If you are an employee of an organisation that uses CloudHR, your employer decides how your records are used. Ask them first — section 2 explains why.
This determines who you should contact, so it matters.
| Situation | Our role | Who to contact |
|---|---|---|
| You visit this site, request a trial, or manage a subscription | Controller — we decide why and how data is used | Us, at info@cloudhr.ie |
| Your employer uses CloudHR and your employee record is held in it | Processor — we act only on your employer’s instructions | Your employer, who is the controller |
If you are an employee asking us directly to change or delete your record, we will refer you to your employer. We are not permitted to alter their records on our own initiative.
Card details are entered directly with our payment processor and never reach our servers.
Depending on the modules an organisation enables, its workspace can hold:
Some of this is sensitive, and some may be special category data — sickness absence, for example. The employer decides what to record and must have a lawful basis for it.
We do not use analytics, advertising or session-recording tools, and we do not track visitors across other websites.
| Purpose | Lawful basis |
|---|---|
| Providing the platform under our agreement with the customer | Performance of a contract |
| Billing, invoicing and collecting payment | Performance of a contract |
| Keeping the service secure and investigating misuse | Legitimate interests |
| Support and service notices | Performance of a contract |
| Marketing to business contacts | Consent, or legitimate interests where permitted |
| Meeting legal, tax and accounting obligations | Legal obligation |
For data held on an employer’s behalf, the lawful basis is theirs to determine. We process it only on their documented instructions.
Each organisation’s data is held in its own dedicated database, not pooled with other customers. Access within a workspace is governed by the roles and permissions that organisation configures, and each signed-in session is bound to the workspace it authenticated against, so a session cannot be used to reach another organisation’s data.
Uploaded documents are stored outside the public web root and are served only through an authenticated request that checks the file belongs to the requesting organisation.
To sign in on the mobile app, the app has to know which organisation's workspace you belong to before it can check your password — your account lives inside that organisation's own database, so the right one has to be opened first. To make that possible without asking you to remember a workspace code, we keep a single central index: a one-way SHA-256 hash of your email address and the name of the workspace it belongs to. Nothing else.
We hold the hash rather than the address itself because the lookup only ever needs to compare, never to read or display. The index contains no names, no employment details and no other personal data, and it is not used for marketing or analytics. It is updated when an account is created, its address changes, or the account is removed, and an organisation's entries are deleted with its workspace.
We do not sell personal data and we do not share it for advertising. We use a small number of providers to run the service, each under contract:
| Provider | What they process | Where |
|---|---|---|
| Our hosting provider | The platform, its databases and backups | European Union |
| Stripe | Subscription payments and card details | EU and United States |
| Our email provider | Outbound email — account, notification and system messages | European Union |
| Google Fonts, CDN providers | Serve fonts and scripts on public pages; your IP address is visible to them | Global |
Workspace data stays in the EU. Two exceptions are worth naming plainly. Stripe processes payment data in the United States as well as the EU, and the content delivery networks that serve fonts and scripts on our public pages operate globally. Where data reaches a country without an EU adequacy decision, the transfer is covered by the European Commission's Standard Contractual Clauses, and in Stripe's case also by its certification under the EU–US Data Privacy Framework.
We may also disclose data where the law requires it — for example to Revenue, a court, or An Garda Síochána under a valid order. We will tell the affected customer unless we are legally prohibited from doing so.
If we add or replace a provider that processes customer data, we will update this page. Customers on a paid subscription are notified by email at least 30 days beforehand and may object; if we cannot resolve an objection, the customer may cancel without penalty.
We would rather state this accurately than reassuringly.
One thing to be clear about: for the employee records inside a workspace, the customer decides retention, not us. Irish employers have their own statutory duties — working-time records must be kept for 3 years under the Organisation of Working Time Act 1997, and payroll records for 6 years under Revenue rules. We keep the data available for as long as the customer's subscription runs and delete it when they tell us to, or on the schedule above.
Under the GDPR you may:
For your employer’s records, contact your employer. For data we hold as controller, email info@cloudhr.ie and we will respond within one month.
You can also complain to the Data Protection Commission (dataprotection.ie), or to the supervisory authority where you live.
HttpOnlyNo system is perfectly secure, but we treat these obligations seriously and review them.
CloudHR is a workplace product, not directed at children. We do not knowingly collect data from anyone under 16 other than employment records an employer lawfully maintains.
We update this page when our practices change and revise the date above. Where a change materially affects customers, we tell them directly.
Email info@cloudhr.ie, message us on WhatsApp, or write to 39 Dominick Street Lower, Dublin 1, Ireland. See also our contact page.