StackHR

StackHR

Manage your people, payroll, and business spending in one place

← Back to StackHR

Data Processing Overview

Last updated: July 6, 2026

Beta notice: StackHR is currently in limited beta. This policy will be expanded as we move toward general availability.

What We Process

StackHR processes personal data on behalf of our customers, who are the data controllers. We act as a data processor for the personal data of your employees and other individuals whose data you upload to the platform.

We process the following categories of personal data:

  • Employee identifiers: full names, National Identification Numbers (NIN), Bank Verification Numbers (BVN), contact details, job roles, and employment dates.
  • Payroll data: salary amounts, bank account details, tax records, pension contribution amounts, and deduction records.
  • Expense and spend data: claim amounts, receipts, approval records, and budget allocations.
  • Account and audit data: login records, action logs, and session metadata used for security and audit trail purposes.

Where Data Is Stored

StackHR stores customer data using managed cloud database infrastructure hosted in Africa. We prioritise regional data residency so that personal data belonging to African employees remains within the region by default.

Our infrastructure provides redundancy, automated backups, and point-in-time recovery to protect against data loss. Backup data is stored in the same region as primary data unless a specific exception is required for disaster recovery.

Multi-Tenant Data Isolation

StackHR is a multi-tenant platform — multiple customer organisations share the same underlying infrastructure. We isolate each organisation's data using row-level security enforced at the database layer.

This means that even if two organisations share the same database infrastructure, a query executing in the context of one organisation cannot read or modify another organisation's data. This isolation is enforced at the database layer, not solely at the application layer, which provides a stronger guarantee than application-only access controls.

StackHR staff access to customer data is restricted to what is necessary to provide support and operate the service. Access is logged and subject to internal review.

Data Retention

Customer data is retained while your account is active. On account closure or upon written request, we delete or anonymise personal data within a reasonable period. Specific timeframes for deletion will be communicated at the time of closure.

Some data may be retained for longer periods where required by law — for example, payroll records that must be kept under Nigerian tax or labour regulations. In such cases, we retain only the minimum data required to meet the legal obligation, and delete it once the obligation period has passed.

To request deletion of your data, contact privacy@stackhr.app.

Sub-Processors

We use the following categories of third-party sub-processors to operate the service. We maintain data processing agreements with sub-processors where required by applicable law.

  • Cloud infrastructure providers: provide database hosting, object storage, and computing resources. Data processed by these providers is subject to the same regional data residency requirements as described above.
  • Payment processors: process salary disbursements and subscription payments. We use Paystack for payment processing within Nigeria; Paystack's own privacy and data processing policies apply to data they receive.

Specific vendor names for cloud infrastructure can be provided on request to organisations with a legitimate compliance need. Contact privacy@stackhr.app.

Related Documents

Contact

Data processing questions: privacy@stackhr.app