Privacy Policy

Last updated: January 2025

Summary: MakeSpire collects only the data needed to provide the HR platform. We do not sell personal data. Employee data is processed on behalf of the employer (who is the data controller). Monitoring features are always disclosed to employees and configurable by administrators.

1. Who We Are

MakeSpire ("MakeSpire", "we", "us") operates the HR management platform at makespire.com. For personal data processed in the course of providing the platform to businesses, the business customer is the data controller and MakeSpire is the data processor.

2. Data We Collect

2.1 Account and Billing Data

When you create an account or subscribe to a paid plan, we collect: your name, email address, company name, billing address, and payment method details (handled by our payment processor — we do not store full card numbers).

2.2 Employee Data (Processed on Behalf of Customers)

When you use MakeSpire to manage your workforce, you provide us with personal data about your employees, including: names, contact details, job titles, employment dates, salary information, attendance records, performance data, and (if monitoring is enabled) productivity activity data. This data is processed under your instructions as your data processor.

2.3 Usage and Technical Data

We collect standard server logs (IP addresses, browser type, pages visited) to maintain service availability and diagnose technical issues. We use session cookies essential to the platform's operation. We do not use third-party analytics cookies without consent.

3. How We Use Your Data

  • To provide, maintain, and improve the MakeSpire platform
  • To process billing and send invoices
  • To respond to support requests
  • To send service notifications and important product updates
  • To detect and prevent fraud and security incidents
  • To comply with legal obligations

We do not sell personal data. We do not use employee data for training machine learning models without explicit consent.

4. Productivity Monitoring

Productivity monitoring is an opt-in feature available to Professional plan customers. It must be explicitly enabled by an account administrator. Before monitoring begins, employees are notified of what is captured, how it is stored, and how long it is retained. Monitoring data is accessible only to authorised managers and administrators — not to other employees.

Monitoring captures: application usage, website categories, keyboard/mouse activity frequency (not keystroke content), and optional screenshots at configurable intervals. GPS location data is captured on mobile only during active clock-in sessions, with employee consent.

5. Data Retention

Account data is retained for the duration of your subscription and for 90 days after cancellation, after which it is deleted. Monitoring data retention is configurable by the administrator (default: 30 days). On written request, we will delete specific data records within 30 days in accordance with GDPR Article 17 (right to erasure).

6. Data Storage and Security

Data is stored on servers within the European Union by default. Professional plan customers can request EU-only data residency with additional contractual guarantees. We use encryption in transit (TLS 1.2+) and encryption at rest. Access to production systems is restricted to authorised personnel and logged.

7. Third-Party Processors

We use a limited number of third-party sub-processors to operate the platform, including cloud infrastructure providers and payment processors. A current list of sub-processors is available on request. We ensure all sub-processors have appropriate data processing agreements in place.

8. Your Rights (GDPR)

If you are in the European Economic Area or UK, you have the right to: access your personal data, correct inaccurate data, request deletion, object to processing, request restriction of processing, and data portability. To exercise these rights, contact us at privacy@makespire.com. We will respond within 30 days.

For requests relating to employee data processed on behalf of an employer customer, we will direct requests to that customer as the data controller.

9. Cookies

MakeSpire uses strictly necessary cookies for session management and authentication. These cannot be disabled as they are required for the platform to function. We do not use advertising cookies. If you access our public marketing website, we may use analytics cookies with your consent.

10. Changes to This Policy

We will notify account administrators by email at least 30 days before making material changes to this privacy policy. The current version is always available at https://makespire.com/privacy-policy.

11. Contact

Privacy-related enquiries: privacy@makespire.com
General enquiries: Contact form