Privacy Policy
Product: Open HR
Operated by: Angle Open Source Ltd
Company number: 17066367
Registered address: 71–75 Shelton Street, London, England, WC2H 9JQ
Effective date: 21 July 2026
Version: 1.0
1. Who We Are
Open HR is an HR and hiring platform built for founders and small business operators. It’s developed and operated by Angle Open Source Ltd, a company registered in England and Wales (company number 17066367), based at 71–75 Shelton Street, London, England, WC2H 9JQ.
We currently operate in the UK, the EU (including Germany), the US, Nigeria, India, and Kenya. If you’re based somewhere else, please get in touch before creating an account, we may not yet have the right setup in place to handle your data properly.
For any privacy question, email us at [email protected].
2. What This Policy Covers
This policy covers personal data we handle through the Open HR website, waitlist, account sign-up, and the hosted platform.
If you’re an employee: if your employer uses Open HR to manage your HR records, we process your data on your employer’s behalf, not as an independent party. Your employer decides how your data is used and is the one responsible for it. If you want to access, correct, or delete your data, please contact your employer directly, we support them in handling these requests, but we can’t act on them ourselves.
3. Our Two Roles: Controller and Processor
3.1 When we are the data controller
We are the data controller for:
- Personal data you provide when joining our waitlist (email address, consent record)
- Personal data you provide when creating an account (name, email, company details, and for EU business customers, VAT registration details)
- Data generated by your use of our website and platform (login logs, session data, usage analytics)
As controller, we determine the purposes and means of processing and are directly accountable to you and to regulators for that processing.
3.2 When we are the data processor
When you (as an employer) use Open HR to store and manage employee records, applicant data, or team information, you are the data controller and we are the data processor. We process that data only:
- On your documented instructions
- For the purpose of providing the Open HR platform to you
- Not for any other commercial purpose of our own, including AI model training, benchmarking, or resale, without your explicit prior written authorisation
This relationship is governed by our Data Processing Agreement, which you must accept as a mandatory step during account creation. No employee data can be entered into the platform until the DPA is executed.
A note on employee consent:Across every market we operate in, employee consent is not treated as a reliable basis for routine HR processing because of the power imbalance in the employment relationship. If you are an employer using Open HR, please rely on contractual necessity or legal obligation as your lawful basis for standard HR activities (payroll, records, onboarding), rather than asking employees to “consent” to being managed on the platform.
3.3 If you are an employee
If your employer uses Open HR and has entered your personal data into the platform, contact your employer directly to:
- Access a copy of your data
- Request corrections or deletions
- Exercise any other data subject rights
Your employer is responsible for responding to your request. We contractually require employers to support employee rights requests and will assist them in doing so, including by providing a full export of the relevant records on request.
3.4 Business (VAT/VIES) data for EU customers
Where a business customer in the European Union signs up for a paid subscription, we may collect and validate a VAT registration number using the EU’s VAT Information Exchange System (VIES) to determine whether the reverse-charge mechanism applies to your invoice. This is processed as part of the contract with you (Art. 6(1)(b) GDPR) and for compliance with our own EU VAT obligations (Art. 6(1)(c) GDPR). VIES validation involves submitting your VAT number to the European Commission’s VIES service; no other personal data is shared in that exchange. We retain VAT validation records for the statutory period required for tax compliance (currently a minimum of 6 years, consistent with the retention basis applied to comparable financial records).
4. Personal Data We Collect and Why
4.1 Joining the waitlist.
When you join our waitlist, we ask for your name, email address, and country. We use this to manage the list and send you an invite when we launch. We collect this simply because you’ve asked us to, it’s necessary to provide the waitlist service you’re requesting. There’s no separate marketing consent checkbox on the waitlist form; by submitting the form, you’re agreeing to our Terms & Conditions, as shown at the point of sign-up. We also briefly collect your IP address to prevent spam and bot abuse, which we delete after 30 days. If you don’t create an account within 90 days of getting your launch invite, we delete your waitlist details entirely. If you do create an account, we keep this record for 3 years.
4.2 Creating an account.
When you sign up, we collect your name, email address, password, company name, industry, team size, and country. Your password is hashed and never stored in plain text. We use this information to set up your workspace and provide the service, this is necessary to fulfil our contract with you. Your country also helps us route you to the right legal requirements for your market. If you’re an EU business signing up for a paid plan, we may also ask for your VAT number, which we check against the EU’s VIES system so we can invoice you correctly. We keep your account details for as long as you have an account, plus 30 days. The exceptions are your DPA acceptance record, which we keep for 7 years for legal reasons, and VAT records, kept for 6 years for tax purposes.
4.3 Using the platform.
We use short-lived session tokens to keep you logged in, generally for up to 30 days. We keep a record of logins for 90 days and failed login attempts for 30 days, both to help keep your account secure. Password reset links expire after 15 minutes, and invitations to join a workspace as a co-admin expire after 7 days.
4.4 Product analytics.
We collect anonymised or pseudonymised information about how people use Open HR, which features get used, where people get stuck during setup, and where errors happen, so we can improve the product. We don’t build profiles of individual people from this, and we don’t use it for advertising. If we ever introduce tools that track individual behaviour in more detail, such as session recordings, we’ll update this policy and ask for your consent first.
5. Our Legal Basis for Using Your Data
Data protection law requires us to have a valid reason for every way we use your personal data. In the UK, EU, Nigeria, and Kenya, this generally comes down to one of four things: you’ve given us consent, we need the data to provide something you’ve asked for (a contract), we’re legally required to collect or keep it (a legal obligation), or we have a legitimate business reason that doesn’t unfairly override your rights (a legitimate interest). The US doesn’t require us to label a legal basis in the same way, but we only ever use your data for the purposes described in this policy.
In practice: joining the waitlist and creating an account happen because you’ve asked us to, so our basis is contract. Security monitoring, fraud prevention, and product analytics rely on our legitimate interest in keeping the platform safe and useful. Keeping your DPA acceptance record and VAT details is a legal obligation. Any marketing emails we send are based on your consent, which you can withdraw at any time using the unsubscribe link or by emailing us.
If you’re an employer processing employee data through Open HR, the basis for that processing is yours to determine, but as noted above, please rely on contractual necessity or a legal obligation for routine HR tasks rather than employee consent. In India, standard HR activities like recruitment, onboarding, payroll, and benefits are covered by a specific employment exception in Indian law and don’t need separate employee consent at all.
6. Who We Share Data With
We don't sell your personal data, and we don't share it with advertisers.
We use AWS and Cloudflare to host the platform and store data. We also use a transactional email provider to send account, verification, and waitlist emails, and, for EU users, an EU representative who acts as a point of contact for regulators and individuals, as required under EU law when a company isn’t based in the EU.
We'll publish an up-to-date list of everyone we share data with before launch, and we'll tell account holders before adding anyone new who would affect their data, so there's a chance to raise concerns.
If you're a co-admin invited into a workspace, the employer running that workspace can see your name and email, and can manage or remove your access.
We’ll disclose personal data to law enforcement, courts, or regulators if we’re legally required to, and we’ll tell you beforehand if we’re allowed to. If Angle Open Source Ltd is ever acquired or merged with another company, personal data may transfer to the new owner, we’ll notify you before that happens and make sure the new owner is bound by protections at least as strong as this policy.
7. Where We Store Data and International Transfers
We host Open HR on AWS and store data in the region closest to your market wherever we can. UK data is stored in the UK. EU data is kept within the EU as a firm requirement, not just a preference. US data is stored in the US. For Nigeria, India, and Kenya, we don’t yet have dedicated in-region hosting, so data from those markets is currently stored in the nearest suitable regional infrastructure while we finish setting up dedicated hosting, we’ll update this policy once that’s in place.
Whenever data does need to cross borders for example, between our infrastructure and a service provider, we put appropriate legal safeguards in place. For the UK and EU, this means standard contractual clauses or the UK’s equivalent. For Nigeria, Kenya, and India, we’re finalising the specific mechanisms required under each country’s law and will publish the details here before we accept a meaningful volume of data from those markets.
If you're an employer, you and your team may be able to view your workspace data from anywhere you operate, even across borders. This kind of access is covered separately in your Data Processing Agreement with us.
A note for German employers: if your organisation has a works council (Betriebsrat), German law requires you to get their agreement before switching on any Open HR feature that could be used to monitor employees, things like attendance tracking or activity logs. This sits alongside your GDPR obligations, not instead of them, and it’s something we can’t handle on your behalf.
8. How Long We Keep Your Data
We only keep personal data for as long as we actually need it. Waitlist details are deleted after 90 days if you don’t go on to create an account, or kept for 3 years if you do. Account information is kept for as long as you have an account, plus 30 days, then deleted or anonymised, except your DPA acceptance record (kept 7 years) and VAT records for EU business customers (kept 6 years), both for legal reasons. Login and security logs are kept on a rolling basis for 30 to 90 days. Password reset links expire in 15 minutes, and workspace invitations expire after 7 days. If we ever have a security incident, we keep records of it for at least 3 years for regulatory purposes.
If we delete something from our main systems, it’s also removed from backups during our normal backup cycle, until that happens, it isn’t considered fully deleted under the law.
If you’re an employer, the retention of your employees’ records is set out in your Data Processing Agreement with us. We recommend keeping employee records for as long as someone works for you, plus at least 6 years, then deleting them securely rather than archiving them. When your account closes, we delete or return all employee data to you, as agreed in the DPA.
9. Your Rights
Wherever you’re based, you have the right to see a copy of the personal data we hold about you, correct anything that’s wrong, ask us to delete it (subject to anything we’re legally required to keep), object to processing based on our legitimate interest, and withdraw consent at any time where consent is the basis. You can also complain to us directly, or to your local regulator, see Section 15. We respond to requests within 30 days; if a request is complex, we may need a further 30 days (45 days in the US), and we’ll let you know if that’s the case.
To exercise any of these rights, email [email protected]and let us know what you’d like.
If you’re in the UK or EU, you also have the right to ask us to pause processing in certain situations, receive your data in a portable format, and be told if we’ve made any decision about you using automated tools alone, see Section 11. In Germany specifically, you can also raise concerns about workplace monitoring features with your works council.
If you’re in the US, you have the right to know what we collect, correct it, delete it, and opt out of any sale or sharing of your data, though we don’t sell or share personal data. We also honour the Global Privacy Control browser signal as a valid opt-out. If you’re a California-based employee or job applicant of a company using Open HR, you have the same rights as any other California resident, the old exemption for employee data ended in 2023.
If you’re in Nigeria, you can ask us to restrict processing, request a portable copy of your data where relevant, and object to being subject to a fully automated decision.
If you’re in India, you can access, correct, and erase your data, raise concerns with us directly, and nominate someone else to exercise your rights on your behalf if something happens to you. India’s rights framework is still being rolled out and will be complete by May 2027, until then, some requests go through our general process rather than a dedicated legal mechanism.
If you’re in Kenya, you can object to processing, ask for corrections or deletion, and request a portable copy of your data. We’ll respond within 30 days, or explain within 7 days if we’re unable to fulfil the request.
If you’re an employee and your employer has entered your data into Open HR, please contact your employer first, they’re responsible for your records, and we help them respond to you.
10. Cookies and Tracking
We use cookies on the Open HR website and platform.
Some cookies are strictly necessary, they keep you logged in and keep the platform secure, and we don’t ask for consent to use these. Any cookies used for analytics or marketing need your consent first, and you can manage your preferences at any time from the cookie settings link in the footer. We don’t currently use marketing or advertising cookies; if that changes, we’ll update this notice and ask for your consent.
If you visit our website with the Global Privacy Control browser signal turned on, we treat that as a valid request to opt out of any sale or sharing of your data. In Nigeria, we get your opt-in consent before placing any non-essential cookies, in line with local requirements.
11. Automated Decision-Making
Open HR’s job creation tool includes built-in prompts that flag legal requirements based on where a job is posted, for example, reminding an EU employer to disclose a salary range, or a Nigerian employer to check their registration status. This helps employers meet their own obligations; it doesn’t make or influence any decision about a candidate or employee under GDPR or similar laws.
If we ever build features that use automated tools or AI to screen, rank, or score candidates or employees, we’ll update this policy first to explain what the tool does, what data it uses, what its output means, and how you can ask for a human review. Features like that would likely count as high-risk under the EU’s AI Act from August 2026, and we’d put the required safeguards in place before switching them on for EU employers.
12. Security
We use reasonable technical and organisational measures to protect personal data, including encrypting data in transit and at rest, hashing passwords so they’re never stored in plain text, limiting access to people who need it, logging access to sensitive data, and expiring sessions and one-time tokens automatically. If you find a security vulnerability in Open HR, please report it to [email protected].
If a data breach happens, we’ll notify the relevant regulators and affected individuals in line with our legal obligations, generally within 72 hours in the UK and EU, without undue delay in Nigeria and India, and as soon as reasonably possible in Kenya. If you’re an employer, we’ll tell you about any breach affecting your workspace within 24 hours, so you have time to meet your own reporting deadlines.
13. Children's Data
Open HR is built for business operators and HR professionals, not for children. We don’t knowingly collect data from anyone under 18. If you think we’ve accidentally collected data from a child, email [email protected]and we’ll delete it promptly.
14. Changes to This Policy
We update this policy whenever we make a meaningful change to how we handle data, for example, adding a new service provider, using data for a new purpose, or entering a new market. For meaningful changes, we’ll email you at least 14 days before the change takes effect and show a notice on the platform. For small clarifications, we’ll just update the date at the top of this page.
You can request an earlier version of this policy at any time by emailing [email protected].
15. Complaints
If you have a concern about how we’ve handled your data, please contact us first at [email protected]. We’ll acknowledge your complaint within 5 working days and aim to resolve it within 30 days. From 19 June 2026, UK individuals have a legal right to complain to us directly before going to the regulator, and we’ll follow the same 30-day acknowledgement window.
If we can’t resolve things to your satisfaction, you can take your complaint to your local regulator. In the UK, that’s the Information Commissioner’s Office (ico.org.uk). In the EU, it’s your national data protection authority, you can find yours at edpb.europa.eu. In Germany specifically, it’s your regional Datenschutzbehörde. In Nigeria, it’s the Nigeria Data Protection Commission (ndpc.gov.ng), you can also use their SNAG process to try to resolve things with us first. In India, once its complaints process is fully up and running. In Kenya, it’s the Office of the Data Protection Commissioner (odpc.go.ke). And if you’re in California, it’s the California Privacy Protection Agency (cppa.ca.gov).
16. How to Contact Us
For any privacy question, rights request, or security report, email [email protected]. You can also write to us at Data Protection, Angle Open Source Ltd, 71–75 Shelton Street, London, England, WC2H 9JQ.
We’re in the process of appointing an EU representative, as required under EU law for a company based outside the EU, we’ll publish their contact details here once that’s confirmed.
Angle Open Source Ltd is registered in England and Wales, company number 17066367, registered office 71–75 Shelton Street, London, England, WC2H 9JQ.
17. Jurisdiction-Specific Notices
17.1 United Kingdom.
We’re the data controller for the processing described in Section 4. We’re registered in England and Wales, and the applicable law is UK GDPR, the Data Protection Act 2018, and the Data (Use and Access) Act 2025. The regulator is the Information Commissioner’s Office (ico.org.uk). From 19 June 2026, you can complain to us directly before the ICO, and we’ll acknowledge within 30 days. When we transfer data outside the UK, we use approved safeguards to keep it protected to UK standards. We’re not currently required to have a Data Protection Officer.
17.2 European Union, including Germany.
The applicable law is the EU GDPR. You can complain to your national regulator, find yours at edpb.europa.eu. Because we’re based in the UK, not the EU, we’re appointing an EU representative under EU law to act as a point of contact for regulators and individuals; we’ll publish their details once confirmed. If you’re an EU business customer, we may validate your VAT number through the EU’s VIES system for invoicing purposes. If you’re a German employer with a works council, please see Section 7, they’ll need their agreement before enabling any monitoring-capable features, separately from your GDPR obligations. Employers in France or the Netherlands may face similar works council requirements and should check with local counsel before rolling out employee-facing features.
17.3 United States.
We assess our obligations mainly under California’s privacy law (CCPA/CPRA), given it’s the most comprehensive framework among the states. The regulator is the California Privacy Protection Agency (cppa.ca.gov). If you’re a California-based employee or job applicant of a company using Open HR, you have the same rights as any other California resident, the old exemption for employee data ended in 2023. If your organisation has people in other states with their own privacy laws, those may apply too; Texas’s law, for example, applies to any business serving Texas residents regardless of size. We honour the Global Privacy Control signal as a valid opt-out. As an employer, you remain responsible for your own compliance with US employment law, including any state rules on automated hiring tools.
17.4 Nigeria.
The applicable law is the Nigeria Data Protection Act 2023 and its implementing directive (GAID 2025). The regulator is the Nigeria Data Protection Commission (ndpc.gov.ng). Any organisation processing data for more than 200 Nigerian individuals within 6 months is generally required to register with the NDPC, appoint a data protection officer, and file periodic compliance reports, we expect to meet this threshold and will confirm our registration status here before accepting Nigerian data at scale. When we transfer Nigerian data across borders, we put in place the safeguards Nigerian law requires; we’re finalising exactly which mechanism applies to our current AWS setup and will update this section once confirmed. If you’re a Nigerian employer, remember that employee consent generally isn’t a valid basis for routine HR processing, use contractual necessity or a legal obligation instead. You can also use the NDPC’s SNAG process to resolve complaints with us first before involving the regulator.
17.5 India.
The applicable law is the Digital Personal Data Protection Act 2023 and its Rules, which are being rolled out in stages. The regulator is the Data Protection Board of India, established in late 2025. Full compliance with the Act’s notice and consent requirements is required by 13 May 2027, until then, the older IT Act rules on sensitive personal data continue to apply. Standard HR activities like recruitment, onboarding, payroll, and benefits are covered by a specific employment exception and don’t require separate employee consent. India doesn’t use an approved-country list for international transfers, transfers are generally allowed unless the Indian government has specifically restricted a country, and we monitor that list. If you’re an Indian employer, you remain responsible for any sector-specific rules that might apply to particular types of data you process.
17.6 Kenya.
The applicable law is the Data Protection Act 2019. The regulator is the Office of the Data Protection Commissioner (odpc.go.ke). We’re registering with the ODPC both as a controller (for our own account data) and as a processor (for employer-customer employee data), these are separate registrations under Kenyan law, renewed every 24 months. Kenyan law also requires at least one copy of certain personal data to be kept within Kenya; we’re reviewing how this applies to our current setup and will confirm our position before accepting Kenyan data at scale. If you’re a Kenyan employer, remember that an employment contract alone doesn’t give you blanket permission to process all employee data, you need a specific reason for each category you collect. Biometric data needs explicit consent. We recommend keeping employee records for the length of employment plus 6 years, then deleting them securely. The ODPC actively enforces these rules, so please take them seriously.
18. Legal Disclaimer
This policy was prepared by Angle Open Source Ltd and reflects our current understanding of the law as of 21 July 2026. It isn’t legal advice. If you’re an employer using Open HR, we recommend getting independent legal advice in each country where you operate before processing employee data, especially given that India’s rules are still being phased in and some details for Nigeria and Kenya are still being finalised.
A few items in this policy are still being worked on: our EU representative’s contact details, dedicated hosting for Nigeria, India, and Kenya, our NDPC and ODPC registration numbers, and confirmation of how we’ll meet Kenya’s local data storage requirement. We’ll update this policy as each of these is resolved, and we won’t make Open HR generally available in a market before the relevant legal requirements are in place.
This is version 1.0, effective 21 July 2026.
Angle Open Source Ltd
Company number 17066367, 71–75 Shelton Street, London, England, WC2H 9JQ.