Legal

Privacy Policy

This policy explains how we handle personal data in compliance with Singapore's Personal Data Protection Act 2012 (PDPA).

Last updated: 30 May 2026

This Privacy Policy describes how Slota Technologies Pte. Ltd. (“Slota”, “we”, “us”, or “our”) collects, uses, discloses, and protects personal data when you use the Slota staff-scheduling platform, our websites, and related services (collectively, the “Service”). We are committed to handling personal data in accordance with the Personal Data Protection Act 2012 of Singapore (the “PDPA”).

By using the Service, you acknowledge that you have read and understood this policy. Where the PDPA requires your consent, we will obtain it before collecting, using, or disclosing your personal data, except where the PDPA permits otherwise.

1. Who is responsible for your data

Slota acts in two distinct capacities:

  • As a data controller for the account, billing, and usage information of the managers and administrators who sign up for and operate the Service.
  • As a data intermediary (processor) for the employee and workforce data that our customers (employers) upload or generate while using the Service. In that role, the employer is the controller and determines the purposes for which that data is processed; we process it on the employer’s behalf and under our agreement with them.

2. Personal data we collect

2.1 Account & contact data

  • Name, email address, and (optionally) phone number;
  • Organisation name, role, position, location assignments, and wage information;
  • Authentication credentials and single sign-on identifiers (e.g. Google account ID).

2.2 Workforce & scheduling data

  • Shifts, availability, time-off requests, timesheets, and break records;
  • Messages and announcements sent within the Service;
  • Employee identifiers entered by the employer (e.g. staff/NRIC numbers, where provided).

2.3 Time-clock data (location & biometric)

  • Location data: when geofenced clock-in is enabled by your employer, we process the device’s GPS coordinates at the moment of clock-in/clock-out solely to verify presence within an approved location.
  • Biometric data: where facial-recognition clock-in is enabled, we process a mathematical representation (a face descriptor) of an image captured at clock-in. This is sensitive personal data; it is used only to match an employee at clock-in and is never used for any other purpose. Facial clock-in is optional and is configured by the employer; affected employees should be informed and give consent before it is enabled.

2.4 Usage & device data

  • Log data such as IP address, browser type, pages viewed, and timestamps;
  • Cookies and similar technologies used to keep you signed in and to operate the Service.

3. How we use personal data

We use personal data for the following purposes:

  • To create and administer accounts and authenticate users;
  • To provide scheduling, time-tracking, messaging, reporting, and related features;
  • To verify attendance and prevent time-clock fraud (location and, where enabled, biometric matching);
  • To process subscriptions, billing, and payments;
  • To send service-related notifications (e.g. shift reminders, approvals);
  • To maintain security, prevent abuse, and debug and improve the Service;
  • To comply with legal and regulatory obligations.

4. Consent and its withdrawal

Where we rely on consent, you may withdraw it at any time by contacting our Data Protection Officer (see below). Withdrawing consent may mean we can no longer provide certain features — for example, withdrawing consent to biometric processing disables facial clock-in for you, and your employer may require an alternative method (PIN or QR). We will inform you of the likely consequences before giving effect to a withdrawal request.

5. Disclosure of personal data

We do not sell personal data. We disclose it only as follows:

  • Service providers (sub-processors) who host and operate the Service on our behalf — including our cloud database and authentication provider, email/notification delivery providers, and our payment processor — under contractual obligations of confidentiality and data protection;
  • Your employer / organisation, who controls the workforce data within their account;
  • Authorities or third parties where required by law, court order, or to protect our rights, users, or the public.

6. International transfers

Some of our service providers may store or process data outside Singapore. Where personal data is transferred overseas, we take reasonable steps to ensure it is afforded a standard of protection comparable to that under the PDPA, including through contractual safeguards with the receiving party.

7. Retention

We retain personal data only for as long as is necessary to fulfil the purposes for which it was collected, or as required by law (for example, employment, tax, and accounting records). When data is no longer required, we will delete or anonymise it. Workforce data is retained according to the employer’s instructions and is deleted following account closure, subject to our backup-rotation and legal-retention periods.

8. Security

We implement reasonable administrative, technical, and physical safeguards to protect personal data against unauthorised access, collection, use, disclosure, copying, modification, or disposal — including encryption in transit, access controls, row-level data isolation between organisations, and audit logging. No method of transmission or storage is completely secure, and we cannot guarantee absolute security.

9. Your rights under the PDPA

Subject to the PDPA, you may:

  • Access the personal data we hold about you and information on how it has been used or disclosed;
  • Correct any personal data that is inaccurate or incomplete;
  • Withdraw consent to the collection, use, or disclosure of your personal data.

If you are an employee of an organisation using Slota, access and correction requests are often best directed to your employer, who controls your workforce data. We will otherwise respond to verified requests within a reasonable time as required by the PDPA. A reasonable fee may apply to an access request, as permitted by law.

10. Cookies

We use strictly necessary cookies to keep you signed in and to operate the Service. We do not use advertising cookies. You can control cookies through your browser settings, but disabling necessary cookies will prevent you from signing in.

11. Children

The Service is intended for use by businesses and their staff. It is not directed at children under 13, and we do not knowingly collect their personal data.

12. Data Protection Officer & contact

We have designated a Data Protection Officer (DPO) responsible for overseeing our compliance with the PDPA. To exercise your rights, ask questions, or make a complaint, contact:

  • Data Protection Officer, Slota Technologies Pte. Ltd.
  • Email: dpo@slota.tech
  • Singapore

If you are not satisfied with our response, you may lodge a complaint with the Personal Data Protection Commission (PDPC) of Singapore.

13. Changes to this policy

We may update this policy from time to time. Material changes will be notified through the Service or by email. The “Last updated” date above indicates when this policy was last revised.