Privacy
Privacy
What the system holds, why it holds it, and what this website collects. Written from the schema rather than from a template, so every statement about stored data is checkable.
This website collects nothing
No analytics, no tracking pixels, no advertising tags, no third-party scripts, and no cookies set by us. Fonts are served from this domain, so displaying a page here makes no request to any other party.
There is no form on this site that submits anywhere. Every call to action, including the newsletter pill in the footer, opens your own mail client — so you can see exactly what would be sent before you send it, and nothing is transmitted if you close it.
If you do mail us, we hold that message in an ordinary mailbox for as long as it is useful, and we do not add you to anything you did not ask for.
Who controls employee data
When an employer runs payroll on PEOPLE, the employer decides what is collected about its own employees and why. We hold and process that data on the employer's instructions, and we do not decide what to collect or use it for our own purposes.
In practice this means an employee's request to see, correct or erase their data goes to their employer, who can act on it in the system. If you write to us directly about your own data, we will tell you which employer holds it rather than acting on it ourselves.
Where an accountant or payroll bureau operates PEOPLE on behalf of its clients, each client company remains separate in the system and the bureau acts for it.
What the system stores
Payroll needs a specific and fairly small set of things. The system holds:
- Who the employer is. The company, and the partner firm operating on its behalf where there is one.
- Who is employed. An employee record and the dated events that begin and end the employment.
- Facts a calculation needs. Only the facts the country pack declares it requires — for a Malaysian payroll, things like citizenship, date of birth, and which statutory schemes apply. The pack declares these explicitly, so the list of what is asked for is a property of the code rather than an open-ended form.
- What someone is standingly paid, effective-dated, and one-off pay items for a particular run.
- What a previous provider paid, where an employer imports an opening balance at changeover — because a year-to-date figure cannot be derived without it.
- Computed results. Payslips, the wage bases and contribution lines behind them, journal lines, and the reasons a run was blocked.
Identity references a filing needs — a tax reference, an identity card number, a bank account number — are declared as facts the employer supplies when a filing requires them, and the relevant documents refuse to generate rather than guess.
Records are append-only, and what that means for you
This deserves stating clearly because it is unusual and it cuts both ways. The system does not overwrite records. A correction is a new dated entry, and the earlier one remains — which is what makes a payslip recomputable years later to the figure somebody was actually paid, and what makes a dispute answerable.
The consequence is that correcting a value does not remove the old value, and erasure is a deliberate deletion rather than an overwrite. Payroll records also carry statutory retention obligations that sit with the employer, so erasure requests are decided by the employer against those obligations rather than applied automatically.
We have not set a retention period here, because it is the employer's to set within what Malaysian law requires of them, and stating a number we invented would be worse than saying so.
Malaysian data protection
The system is built for Malaysian payroll and designed with the Personal Data Protection Act in mind: data minimisation is structural, because the country pack declares exactly which facts a calculation needs and nothing collects more than that; and tenant separation is enforced in the database rather than only in application code.
We are not claiming a compliance assessment. No audit has been performed and we hold no certification of any kind — see the security page, which lists what is not done.
Asking us something
Mail hello@flightworkly.com. It reaches the person who wrote the code, who can tell you exactly what a table holds rather than paraphrasing a policy.