Legal
Privacy policy
Staffora is a service of ACL GESTION. This policy explains what personal data we handle, why, and the rights people have. It covers the public website and the Staffora product.
Last updated 10 October 2026
1. Who this policy is for
It applies to people who visit the Staffora website, people who write to us, and people whose information is stored in a customer’s Staffora account. That includes employees, contractors and company administrators.
If you are an employee, your employer decides what is collected for HR and why. We process that information for them. Questions about your own HR record should go to your employer first. This policy explains our part.
2. Who is responsible
ACL GESTION is the controller for the website, contact and demo enquiries, billing contacts, and our own security logs.
For employee and other HR records entered into Staffora, the customer is the controller and ACL GESTION is the processor. We use that data only to provide the service the customer has asked for. The data processing agreement sets out that arrangement.
3. What we collect
On the website and in sales contact, we collect only what you give us and a small amount of technical data:
- Name, work email, company, team size, chosen plan and message, when you use the contact form or ask to be told about a future module
- Account details of the people a customer invites: name, work email and role
- Basic logs needed to run and protect the site, such as IP address, browser type and the time of a request
4. What customers store in Staffora
Customers decide which HR records to keep. Depending on how they use the product, that can include:
- Identity and contact details, including name, work and personal email, phone, address and date of birth
- National identity card number, stored encrypted, and employment details such as job, site, manager, contract dates and emergency contacts
- Leave, attendance, corrections and the public key of a phone enrolled for attendance
- Asset assignments and the audit record of important actions inside the account
5. Why we use it
Where we are the controller, we rely on the following reasons:
- Contract: to create an account, provide the trial or subscription, invoice, and reply to an administrator
- Legitimate interests: to keep the service secure, prevent misuse, and understand service errors. We do not use this for advertising
- Legal obligation: to keep accounting and tax records required in France
6. Where it is hosted
The website and the Staffora service, including customer HR data, are hosted in France.
Two activities can involve a provider outside France. Email that Staffora sends, such as invitations and leave notices, is delivered by Google and may be processed outside France under Google’s data-processing terms. Card payments are taken by PayHere (Private) Limited in Sri Lanka, which receives the billing details needed to charge the subscription and does not receive employee HR records.
A Sri Lankan customer that puts employee data into Staffora is sending that data to France. The customer remains responsible for any step Sri Lankan law requires before that transfer. Our data processing agreement is the contract we offer for it.
7. Who we share it with
We do not sell personal data and we do not use advertising trackers. We share data with service providers who work on our instructions, with a customer’s own administrators and the people those administrators authorise, and with authorities when the law requires it.
The providers we use today are the host of the service in France, Google for email delivery, and PayHere for card payments. Customers can ask us for the host’s name. We will tell customers before we add a provider that handles their HR data or replace one.
8. Cookies
The signed-in product uses cookies that are required to keep you signed in and to protect the session. The browser hides those cookies from page scripts. We do not set analytics or advertising cookies.
9. How long we keep it
We keep data only for as long as the purpose, or the law, requires:
- HR and account data: for the subscription. After it ends, the customer has 30 days to export. We then delete it from the live service. Copies in backups are removed in the ordinary backup cycle, within a further 30 days
- Contact and demo enquiries: for up to 24 months after our last exchange, unless they become part of a customer account
- Invoices and payment records: for 10 years, as French accounting law requires
- Security logs: for up to 12 months
10. How we protect it
Access to a customer’s records is limited by role. Companies are separated from each other. Connections are encrypted. The national identity card number is encrypted in storage, and revealing it is itself recorded. Sessions expire, and administrators are asked to use multi-factor sign-in. The security page describes these measures in product language.
11. Your rights
If we are the controller, you may ask to access, correct, delete or limit your data, or to receive a copy of what you gave us, and you may object to processing based on legitimate interests. Write to staffora.hello@gmail.com. We may need to confirm you are the person concerned. We reply within one month, or tell you if we need longer.
If your data is in an employer’s Staffora account, ask that employer to exercise your rights, including rights under Sri Lanka’s Personal Data Protection Act No. 9 of 2022. We help the customer respond. You may also contact the Data Protection Authority of Sri Lanka about your employer’s duties.
12. Children
The website is not aimed at children. A customer may store a young worker’s employment record where the law allows that employment. That decision, and the notice to the person, belong to the customer.
13. Changes
If we change this policy, we will update the date at the top. If a change materially affects customer HR data, we will also tell account administrators.