Privacy Policy

Last updated: August 23, 2026

1. Overview

Sira Solutions LLC, doing business as Sira HRM ("we", "us", "our"), is committed to protecting the privacy of your data. This Privacy Policy explains how we collect, use, store, and protect information when you use our human resource management platform (the "Service"). By using Sira HRM, you agree to the practices described in this policy. This policy should be read together with our Terms & Conditions.

2. Information We Collect

We collect the following categories of information:

Account Information

  • Name, email address, and password for account holders
  • Organization name and team details
  • SMTP configuration (stored securely, used only to send your transactional emails)

Employee Data

  • Personal details: name, date of birth, address, contact information
  • Employment information: hire date, discipline, employment status
  • Documents: licenses, certifications, and identification documents uploaded by your organization
  • Sensitive identifiers: Social Security Numbers (SSN), stored encrypted at rest
  • Work history, education background, and skills

Payment & Billing Information

  • Billing contact name, email, and business address
  • Subscription plan, billable employee count, and billing history
  • A tokenized reference to your payment method (e.g. card brand and last four digits) - see Section 6 for how full payment card data is handled

Usage Data

  • IP addresses logged when sensitive data (e.g. SSN) is accessed
  • Actions performed within the platform (audit logs)
  • Contact form submissions from our website

3. How We Use Your Information

  • To provide and operate the Sira HRM platform
  • To process subscription payments and manage your billing account
  • To send transactional emails (onboarding invitations, orientation documents, reference questionnaires, billing receipts and payment notices) on your behalf
  • To respond to contact inquiries submitted through our website
  • To maintain audit logs of sensitive data access for compliance purposes
  • To improve and maintain the security and reliability of the Service
  • To comply with applicable legal obligations

4. Sensitive Data Handling

Sira HRM handles highly sensitive employee data including Social Security Numbers and identity documents. We apply the following protections:

  • Encryption at rest: SSNs are encrypted using AES-256-CBC before storage. Plain-text values are never stored in the database.
  • Access control: Sensitive fields are hidden from API responses by default. Only users with the FullControl role can reveal sensitive data, and only after password verification.
  • Audit logging: Every reveal of an SSN or sensitive document is logged with the user's identity, IP address, and timestamp.
  • Rate limiting: Access to sensitive reveal endpoints is rate-limited to prevent abuse.

5. Health Information; No HIPAA Business Associate Relationship

Sira HRM is not a "Covered Entity" or "Business Associate" under the Health Insurance Portability and Accountability Act ("HIPAA"), and we do not sign Business Associate Agreements. The Service is not designed or certified to store Protected Health Information ("PHI").

Employers may incidentally upload employment-related records about their own workforce, such as licenses, certifications, or proof of required training. If your organization uploads any document containing health information about your employees (for example, immunization records, physical clearance forms, or drug screening results), you - not Sira HRM - are solely responsible for determining whether that data is regulated health information and for ensuring your own use of the Service complies with HIPAA and any other applicable health-privacy law. Do not upload patient records or PHI of any kind.

6. Payment Processing and Card Data

Subscription payments are processed by Stripe, Inc. ("Stripe"), a PCI-DSS Level 1 certified payment processor. When you enter a card number, it is transmitted directly from your browser to Stripe using Stripe's tokenization technology (Stripe Elements); Sira HRM never receives, transmits, or stores your full card number, CVV, or other full payment card data on our own servers. We only store a tokenized reference (such as card brand and last four digits) and your resulting subscription and invoice history. Stripe's use of your payment information is governed by Stripe's Privacy Policy.

We retain invoice and billing transaction records (excluding full card data, which we never hold) for as long as required for accounting, tax, and legal purposes, generally up to seven years after the transaction, even if you later delete your account.

7. Regulatory and Medicare-Adjacent Data

Many of our customers operate in regulated industries, including healthcare staffing and Medicare-participating providers subject to government audit. Sira HRM does not review, verify, or certify the accuracy or regulatory sufficiency of any document or record you store in the Service, including for purposes of a Medicare, Medicaid, state licensing, or other regulatory audit. You remain solely responsible for the accuracy and completeness of the records you maintain and for your own compliance obligations.

8. Data Sharing

We do not sell your data. We may share data only in the following circumstances:

  • Service providers: We use Resend (email delivery) to send transactional emails, and Stripe to process subscription payments. These providers access only the data necessary to perform their function, under their own privacy and security obligations.
  • Legal requirements: We may disclose data if required by law, court order, subpoena, or government/regulatory authority, including in connection with an audit or investigation of one of our customers.
  • Business transfer: In the event of a merger or acquisition, data may be transferred to the successor entity, with notice provided to users.

9. Data Retention

We retain your data for as long as your account is active or as needed to provide the Service. Employee records, documents, and audit logs are retained in accordance with your organization's requirements. If you request deletion of your account, we will remove your data within 30 days, except where retention is required by law or for billing/tax records as described in Section 6.

10. Security

We implement industry-standard security measures including encrypted data storage, HTTPS-only access, role-based access controls, and audit logging. However, no system is completely secure, and we cannot guarantee absolute security. We encourage you to use strong, unique passwords and to report any suspected security issues to us immediately at the contact below.

11. Your Rights

Depending on your jurisdiction, you may have the right to:

  • Access the personal data we hold about you
  • Request correction of inaccurate data
  • Request deletion of your data
  • Object to or restrict certain processing of your data
  • Data portability (receive your data in a structured format)

To exercise any of these rights, contact us at info@siratms.com.

12. Cookies

Sira HRM uses session cookies to maintain your authenticated state within the application. When you manage billing, Stripe's own scripts (Stripe.js/Elements) may set cookies (such as __stripe_mid and __stripe_sid) used for fraud prevention, subject to Stripe's privacy policy. We do not use tracking cookies or third-party advertising cookies of our own. You can disable cookies in your browser settings, but this may prevent you from accessing authenticated areas of the platform or completing a payment.

13. Children's Privacy

The Service is intended for business use by adults and is not directed at, nor knowingly used to collect information from, individuals under 18 years of age.

14. Changes to This Policy

We may update this Privacy Policy periodically. We will notify users of material changes via email or a notice within the platform at least 15 days before the change takes effect, except where a shorter period is required by law or security necessity. Your continued use of the Service after changes take effect constitutes your acceptance of the updated policy.

15. Contact Us

For any privacy-related questions or requests, please contact:

Sira Solutions LLC, d/b/a Sira HRM

733 E Dublin Granville RD Suite 100, Columbus, OH 43229

Email: info@siratms.com

Phone: (614) 859 6063