peoplBook a walkthroughTalk to us

Privacy

Privacy

What the system holds, why it holds it, and what this website collects. Written from the schema rather than from a template, so every statement about stored data is checkable.

This website collects nothing

No analytics, no tracking pixels, no advertising tags, no third-party scripts, and no cookies set by us. Fonts are served from this domain, so displaying a page here makes no request to any other party.

There is no form on this site that submits anywhere. Every call to action, including the newsletter pill in the footer, opens your own mail client — so you can see exactly what would be sent before you send it, and nothing is transmitted if you close it.

If you do mail us, we hold that message in an ordinary mailbox for as long as it is useful, and we do not add you to anything you did not ask for.

Who controls employee data

When an employer runs payroll on PEOPLE, the employer decides what is collected about its own employees and why. We hold and process that data on the employer's instructions, and we do not decide what to collect or use it for our own purposes.

In practice this means an employee's request to see, correct or erase their data goes to their employer, who can act on it in the system. If you write to us directly about your own data, we will tell you which employer holds it rather than acting on it ourselves.

Where an accountant or payroll bureau operates PEOPLE on behalf of its clients, each client company remains separate in the system and the bureau acts for it.

What the system stores

Payroll needs a specific and fairly small set of things. The system holds:

  • Who the employer is. The company, and the partner firm operating on its behalf where there is one.
  • Who is employed. An employee record and the dated events that begin and end the employment.
  • Facts a calculation needs. Only the facts the country pack declares it requires — for a Malaysian payroll, things like citizenship, date of birth, and which statutory schemes apply. The pack declares these explicitly, so the list of what is asked for is a property of the code rather than an open-ended form.
  • What someone is standingly paid, effective-dated, and one-off pay items for a particular run.
  • What a previous provider paid, where an employer imports an opening balance at changeover — because a year-to-date figure cannot be derived without it.
  • Computed results. Payslips, the wage bases and contribution lines behind them, journal lines, and the reasons a run was blocked.

Identity references a filing needs — a tax reference, an identity card number, a bank account number — are declared as facts the employer supplies when a filing requires them, and the relevant documents refuse to generate rather than guess.

Records are append-only, and what that means for you

This deserves stating clearly because it is unusual and it cuts both ways. The system does not overwrite records. A correction is a new dated entry, and the earlier one remains — which is what makes a payslip recomputable years later to the figure somebody was actually paid, and what makes a dispute answerable.

The consequence is that correcting a value does not remove the old value, and erasure is a deliberate deletion rather than an overwrite. Payroll records also carry statutory retention obligations that sit with the employer, so erasure requests are decided by the employer against those obligations rather than applied automatically.

We have not set a retention period here, because it is the employer's to set within what Malaysian law requires of them, and stating a number we invented would be worse than saying so.

Who else sees it

We do not sell data, and we do not share it for advertising or profiling. There is no third-party analytics in the product or on this site.

Statutory filings and payment instructions are, by their nature, sent to the bodies the employer is filing to and to the employer's bank — that is the point of them, and the employer initiates each one.

The product is not deployed yet, so there is no hosting provider processing anyone's data today. When there is, this section will name it. That is a commitment about this page, not a placeholder.

Malaysian data protection

The system is built for Malaysian payroll and designed with the Personal Data Protection Act in mind: data minimisation is structural, because the country pack declares exactly which facts a calculation needs and nothing collects more than that; and tenant separation is enforced in the database rather than only in application code.

We are not claiming a compliance assessment. No audit has been performed and we hold no certification of any kind — see the security page, which lists what is not done.

Asking us something

Mail hello@flightworkly.com. It reaches the person who wrote the code, who can tell you exactly what a table holds rather than paraphrasing a policy.