Emplyr

Legal

Privacy Policy

This Privacy Policy explains how personal information is handled when you use Emplyr through the web application, Android application, and related services.

Effective date
14 July 2026
Last updated
14 July 2026

1. Who we are and when this policy applies

Emplyr is a business platform that provides tenant-isolated workspaces, embedded Microsoft Fabric and Power BI reporting, user and role management, Process Hub workflows, notifications, and related administration tools. This policy applies to the Emplyr web application, the Emplyr Android application (package namecom.emplyr.clienthub), and the supporting services that operate them (together, the Service).

The Service is provided by RPR TECH HOLDINGS (PTY) LTD, trading as or operating the Emplyr product (Emplyr, we, us, orour).

2. Our role and your organisation's role

Emplyr is primarily a business-to-business service. The customer organisation that provides your account usually decides why and how business content is processed in its Emplyr instance. For that content, the customer is generally the responsible party or data controller and Emplyr acts as its operator or processor. Please contact your organisation first if your question concerns content, permissions, records, or workflows it controls.

Emplyr acts as a responsible party or controller for information we use for our own purposes, such as operating accounts, securing and monitoring the Service, managing customer relationships, complying with law, and improving reliability. The precise role depends on the processing activity and applicable law.

3. Personal information we process

CategoryExamples
Account and identity informationName, email address, organisation or instance, profile membership, role, permissions, authentication source, and identifiers associated with your account or a connected identity provider.
Authentication and security informationPassword hashes, session and refresh-token records, sign-in activity, IP address, request identifiers, audit events, access changes, and security or error records. We do not store your password in readable form.
Customer and business contentProfile and workspace information, report metadata and saved report state, Process Hub forms and responses, workflow assignments and approvals, comments, signatures, attachments, photographs, filenames, and any other information you or your organisation submits to the Service.
Integration and configuration informationMicrosoft tenant, Fabric workspace, Power BI report and semantic-model identifiers; partner single sign-on details; configuration for customer storage and data sources; and secret references used to connect authorised services. Credentials and secrets are subject to additional access controls.
Device and mobile informationA generated device identifier, device name, platform, manufacturer, model, operating-system and app versions, push-notification token and status, network state, sync timestamps and outcomes, and redacted diagnostic details.
Communications and notificationsInvitations, password-reset communications, service notifications, notification-delivery status, support requests, and correspondence with us or your organisation's administrators.
Service telemetryServer requests, dependencies, exceptions, performance measurements, capacity and workspace usage metrics, timestamps, and related technical metadata. Application Insights telemetry is collected only when it is enabled for the relevant environment.

Customer-configured forms and workflows may collect additional categories of personal or sensitive information. Your organisation is responsible for ensuring that its collection is lawful, necessary, transparent, and limited to authorised purposes. Do not submit sensitive information unless your organisation has instructed you to do so and is authorised to collect it.

4. How we obtain information

We obtain personal information:

  • directly from you when you sign in, complete forms, upload files, or contact support;
  • from your employer, customer organisation, administrators, or authorised partners when they create or manage your account and access;
  • from connected services such as Microsoft Entra ID, Fabric, Power BI, partner single sign-on systems, and customer-configured data sources; and
  • automatically from the web application, Android application, device, and supporting infrastructure when you use the Service.

5. How and why we use information

We use personal information to:

  • provide, authenticate, administer, support, and maintain the Service;
  • enforce instance, profile, role, module, report, workflow, and record-level access;
  • display authorised Fabric and Power BI content and connect customer-configured systems;
  • save, synchronise, and submit Process Hub records and attachments, including authorised offline work;
  • send invitations, security messages, workflow notices, and push notifications;
  • detect, investigate, and prevent misuse, fraud, security incidents, and technical failures;
  • monitor performance, troubleshoot, and improve the reliability of the Service;
  • comply with contractual, legal, regulatory, and audit obligations; and
  • establish, exercise, or defend legal claims.

Where applicable law requires a legal basis, we rely on performance of a contract, steps requested before entering a contract, compliance with legal obligations, our or a customer's legitimate interests in providing and securing a business service, and consent where consent is required. You may withdraw consent for optional processing, such as device permissions, without affecting processing that occurred before withdrawal or processing supported by another lawful basis.

Emplyr does not use your personal information for third-party advertising and does not make decisions about you that have legal or similarly significant effects using solely automated processing. Customer-configured workflow rules may automate routing, calculations, assignments, or approvals under that customer's control.

6. Cookies and information stored on your device

The web application uses strictly necessary session cookies to keep you signed in, remember the active tenant or profile, and enforce security requirements. These cookies are required for the Service to function. Emplyr does not currently use the Service's cookies for advertising or cross-site behavioural tracking.

The Android application stores settings, a generated device identifier, secure session information, diagnostics, and authorised offline records on your device. It may store files or photographs you select for later upload. Offline database storage is configured to use encryption, and session credentials use protected device storage where the platform supports it. Local information is cleared or updated through app actions such as sign-out, record submission, or removal, but some app preferences may remain until you clear app data or uninstall the application.

Camera or file access occurs only when you choose to capture or attach content. Notification access controls whether the device displays push notifications. You can manage these permissions in your device settings, although disabling them may prevent the related feature from working.

7. When we disclose information

We may disclose personal information to:

  • your customer organisation and its authorised administrators, users, assignees, approvers, and service providers according to configured permissions;
  • Microsoft services used to host and operate the Service or provide connected features, which may include Azure, Entra ID, Fabric, Power BI, Azure Storage, Key Vault, and Application Insights;
  • Google services used for Android distribution and push notifications, including Google Play and Firebase Cloud Messaging;
  • email-delivery providers and other vendors that help us authenticate, host, monitor, secure, support, or communicate about the Service;
  • customer-selected data stores, identity providers, partner single sign-on systems, and other integrations when instructed or configured by the customer;
  • professional advisers, auditors, insurers, regulators, courts, law-enforcement bodies, or other parties when reasonably necessary to comply with law or protect rights, safety, and security; and
  • a buyer, investor, successor, or adviser in connection with a proposed or completed corporate transaction, subject to appropriate confidentiality protections.

We require service providers acting for us to handle information for authorised purposes and with appropriate safeguards. Some connected providers may process information as independent responsible parties or controllers under their own terms. We do not sell personal information or share it for third-party targeted advertising.

8. International processing

Emplyr, our providers, a customer, or its connected systems may process information outside the country where you are located. The location can depend on the Azure or Microsoft Fabric region selected for an environment, the customer's systems, and where service providers operate. Where required, we use contractual protections and other lawful transfer mechanisms intended to provide an appropriate level of protection for international transfers.

9. Retention and deletion

We retain personal information only for as long as reasonably necessary for the purposes described in this policy, including to provide the Service, follow customer instructions and contractual retention requirements, maintain security and audit records, resolve disputes, and comply with law. Retention periods vary by data type, customer configuration, contractual requirements, and whether an account or customer relationship remains active.

Your customer organisation generally controls retention and deletion of its business content. Ask your organisation's administrator to correct or delete that content. To request deletion of an Emplyr account or information controlled by Emplyr, use the contact details in section 15. We may need to verify your identity and consult the customer that provided your account before acting.

Removing access or soft-deleting a membership may be the first step needed to protect tenant integrity and audit history, and is not necessarily immediate erasure. After a valid deletion request, information will be deleted or de-identified where required, unless it must be retained for contractual, security, fraud-prevention, legal, or regulatory reasons. Residual copies in protected backups are isolated from normal use and removed as those backups expire under the applicable backup schedule.

10. Security

We use technical and organisational measures designed to protect personal information. Depending on the feature and environment, these measures include encrypted network connections, password hashing, protected or hashed session tokens, role-based access controls, instance and profile isolation, restricted secret storage, audit logging, mobile storage protections, secure development practices, and monitoring. No system can guarantee absolute security. Please protect your credentials and promptly report suspected unauthorised access.

11. Your privacy rights

Depending on where you live and the circumstances, you may have rights to be informed about processing; access personal information; request correction, deletion, or restriction; object to certain processing; receive portable information; withdraw consent; and complain to a privacy or data-protection regulator. These rights can be subject to legal exceptions.

If your organisation provided your account, submit requests concerning customer content to that organisation first. You may also contact Emplyr using section 15. We may verify your identity, ask for information needed to locate the relevant records, and forward a request to the customer when it is the responsible party or controller. We will not discriminate against you for exercising a privacy right.

12. Children

The Service is a workplace and business application and is not directed to children under 18. We do not knowingly invite children to create their own accounts. If you believe a child's information has been submitted without appropriate authority, please contact us so the responsible organisation and Emplyr can investigate.

13. Third-party services and links

The Service may display or link to content and services controlled by your organisation or third parties. Their privacy practices are governed by their own notices and agreements. This policy does not replace a customer's employee, client, or other privacy notice.

14. Changes to this policy

We may update this policy when the Service, our providers, or applicable requirements change. We will publish the revised policy with a new "Last updated" date and provide additional notice when required by law or when a change is material.

15. Contact us

For privacy questions, requests, or complaints, contact:

RPR TECH HOLDINGS (PTY) LTD
Emplyr Privacy
70 BIZWENI AVE, SOMERSET WEST, 7130, SOUTH AFRICA
Email: accounts@bfipro.com

South African data subjects may also contact the Information Regulator (South Africa) through its official website at inforegulator.org.za. Individuals elsewhere may contact the privacy regulator or supervisory authority for their location.

Privacy Policy | Emplyr