WeERM Privacy Policy

Version 2.1 · Effective July 13, 2026 · Last updated July 13, 2026

This Privacy Policy explains how Mutor Biz, operator of the WeERM Service, handles personal information. It should be read together with our Terms and Conditions. By accessing or using the Service, you acknowledge the practices described in this Policy.

1. Scope; Our Dual Role as Processor and Controller

This Privacy Policy (the "Policy") describes how Mutor Biz ("Mutor Biz," "we," "us," or "our"), the operator of the WeERM platform and its websites, web applications, mobile applications, and shared-device kiosk applications (the "Service"), collects, uses, discloses, retains, and safeguards personal information, and describes the rights and choices available to individuals. Capitalized terms not defined herein have the meanings given in the Terms and Conditions.

The manner in which we handle personal information depends upon the context. With respect to information that an employer, enterprise, or other organization (a "Company") and its authorized users submit to or process through the Service concerning the Company's personnel and operations ("Workforce Data"), the Company is the controller (or "business") that determines the purposes and means of processing, and Mutor Biz acts as a service provider and processor that processes such information on the Company's behalf and on its documented instructions. With respect to information we collect directly for our own purposes - such as account registration, billing, security, support, marketing to prospective customers, and operation and improvement of the Service - we act as a controller (or "business"). Where we act as a processor, individuals should direct privacy inquiries and rights requests to the relevant Company, and we will provide reasonable assistance to that Company as required by applicable law.

2. Categories of Personal Information We Collect

Depending upon your role and use of the Service, we and our subprocessors may collect and process the following categories of personal information, some of which may be sensitive:

  • Identifiers and contact information - such as name, legal and display names, employee identifier, electronic-mail address, telephone number, postal and worksite address, and account credentials and authentication tokens.
  • Employment and organizational information - such as role, employment classification and status, compensation-related inputs, worksite and organizational assignments, supervisor and approval relationships, hire and status dates, and schedule information.
  • Sensitive identifiers and financial information - such as government-issued and taxpayer-identification numbers, images of identity and eligibility documents, and financial-account details submitted for payroll or verification purposes.
  • Time, attendance, and leave information - such as clock, break, and exception entries, computed hours, leave and time-off requests and dispositions, and accrual, carryover, and payout records.
  • Precise geolocation - device location captured at the discrete moment an authorized user affirmatively initiates a clock, break, or exception action, and, where the optional perimeter-reminder feature is enabled by the user, limited background geofence-transition signals.
  • Communications and content - such as messages, "Ask HR" inquiries, notices, comments, feedback and opinions, and documents and images uploaded to the Service.
  • Commercial and transactional information - such as subscription plan, seat counts, billing and invoice records, referral and promotional-credit activity, and, in tokenized form handled by our payment processor, payment-instrument metadata (we do not store full payment-card numbers).
  • Device, usage, and technical information - such as device and operating-system identifiers, application version, log and diagnostic data, network information, push-notification tokens, and interaction and access records generated as you use the Service.

Provision of certain information is necessary to use corresponding features of the Service; failure to provide it may limit functionality. We do not knowingly collect information beyond what is reasonably necessary for the purposes described herein.

3. Sources of Information

We obtain personal information: (a) directly from you, when you register, authenticate, complete onboarding, submit inputs, communicate, or otherwise use the Service; (b) from your Company and its authorized users, who provision your account, assign roles, and submit Workforce Data concerning you; (c) automatically, through your interaction with and use of the Service and your devices; and (d) from third-party providers that support authentication, payment processing, mapping and geolocation, communications delivery, and infrastructure.

4. Location Data - How and When It Is Collected

Location data is collected only at the discrete moment an authorized user affirmatively initiates a clock-in, clock-out, break, or attendance-exception action, in order to validate the action against a Company-designated worksite or home perimeter. Except as described in the next sentence, the Service does not engage in continuous, passive, or background location tracking. Where, and only where, an authorized user expressly and separately opts in to the optional perimeter-reminder feature, the operating system may deliver limited background geofence-transition events to the Service solely to generate local reminders; this optional feature is disabled by default, is subject to device-level permissions, and may be disabled by the user at any time through device settings or in-application controls.

Location readings are estimates derived from device signals and may be affected by device, network, and environmental conditions. Location data is used for attendance validation, timekeeping, and related workforce-management purposes configured by the Company, and is not used to build advertising or behavioral profiles.

5. Biometric and Device Authentication

On capable devices, and only at the user's election, the Service may support expedited sign-in via device-native biometric verification (such as fingerprint or facial recognition). Any biometric matching is performed entirely by the operating system of the user's device. The Service does not collect, receive, access, store, or retain any biometric identifier or biometric information; biometric verification functions only as a local gate to a session persisted on that device. Biometric sign-in may be disabled at any time, and an alternative authentication method remains available.

6. Communications and Messaging Content

The Service provides communication features, including direct, team, and project messaging, an "Ask HR" channel, notices, comments, and comparable functionality (collectively, the "Communication Features"). Messages, text, images, files, reactions, reports, and other material that authorized users transmit, post, or generate through the Communication Features (collectively, "Communications Content") constitute Workforce Data for which the relevant Company is the controller. Mutor Biz processes Communications Content as a processor, on the Company's behalf and on its documented instructions, in order to transmit, store, display, deliver, and otherwise operate the Communication Features.

Mutor Biz does not monitor, pre-screen, review, or analyze Communications Content for its own purposes, and does not use Communications Content for advertising or profiling. Mutor Biz may, however, access, process, retain, and disclose Communications Content to the limited extent reasonably necessary to provide, maintain, secure, and support the Communication Features; to prevent, detect, investigate, or respond to fraud, abuse, security incidents, and violations of the Terms; to review and act upon a report submitted through the Service; and to comply with applicable law, legal process, or an enforceable governmental or regulatory request.

Communications Content is workplace communication and is not private personal correspondence. Depending upon the Company's configuration and the applicable role-and-scope model, a Company and its authorized users (such as administrators, human-resources personnel, and applicable supervisors) may be able to access, retain, review, moderate, or export Communications Content, and content that is flagged or reported may be reviewed by an administrator or, where applicable, by Mutor Biz. Accordingly, authorized users should have no expectation that Communications Content is private as against their Company or its authorized personnel.

Communications Content is retained for as long as necessary to provide the Communication Features and in accordance with the Company's configuration, instructions, and applicable law, and thereafter may be deleted, de-identified, or retained as described in the Data Retention section. Further provisions regarding permitted use, prohibited conduct, moderation, and the neutral-intermediary status of Mutor Biz with respect to the Communication Features are set out in the Terms and Conditions.

7. How We Use Personal Information

We use personal information for the following purposes, in each case consistent with our role as processor or controller: to provide, operate, maintain, secure, and support the Service and its features; to authenticate users and administer accounts, roles, and multi-company access; to process subscriptions, seats, billing, invoices, referral credits, and promotional codes; to capture, validate, compute, and display time, attendance, leave, accrual, and informational payroll outputs as configured by the Company; to deliver transactional, administrative, security, and service-related communications and notifications; to prevent, detect, investigate, and respond to fraud, abuse, security incidents, and violations of our Terms or applicable law; to maintain audit and recordkeeping information; to comply with legal obligations and lawful requests; to perform analytics and to operate, improve, develop, and troubleshoot the Service, including through the use of de-identified or aggregated data; and, with respect to prospective customers, to market the Service in accordance with applicable law and available choices. To the extent applicable data-protection law requires a lawful basis, we rely, as applicable, upon the performance of a contract, our and our customers' legitimate interests, compliance with legal obligations, and consent where required.

8. How We Disclose Personal Information; Subprocessors

We do not sell personal information, and we do not disclose it except as described herein. We may disclose personal information: (a) to the Company that controls the relevant Workforce Data and to its authorized users, in accordance with the Company's configuration and role model; (b) to service providers and subprocessors that perform functions on our behalf, subject to contractual obligations to protect the information and to process it only as instructed, including providers of cloud hosting and database services, authentication and identity, payment processing, electronic-mail and messaging delivery, mapping and geolocation, and mobile-application and push-notification platforms; (c) to professional advisors and, in connection with a merger, acquisition, financing, reorganization, or sale of assets, to counterparties and their advisors, subject to appropriate confidentiality protections; (d) to comply with applicable law, regulation, legal process, or enforceable governmental or regulatory request, and to establish, exercise, or defend legal claims; and (e) to protect the rights, property, safety, and security of Mutor Biz, our customers, users, and the public, and to enforce our Terms. We may use and disclose Aggregated or de-identified data, which is not personal information, for any lawful purpose.

9. No Sale or Sharing; No Targeted Advertising

We do not sell personal information, and we do not share personal information for cross-context behavioral advertising, in each case as those terms are defined under applicable law. We do not use sensitive personal information for purposes other than those permitted under applicable law and reasonably necessary to provide the Service.

10. Data Retention

We retain personal information for as long as reasonably necessary to fulfill the purposes described in this Policy, including to provide the Service, to maintain business, security, audit, and backup records, to comply with legal, tax, and recordkeeping obligations, to resolve disputes, and to enforce our agreements. Retention of Workforce Data is ordinarily determined by the Company as controller and by its configuration and instructions. Following termination, account closure, or deactivation, we may retain, delete, de-identify, or anonymize information in accordance with our retention practices, the Company's instructions, and applicable law, and we may thereafter permanently delete such information without further obligation. Residual copies may persist in backups for a limited period before routine deletion.

11. Security

We maintain administrative, technical, and organizational safeguards designed to protect personal information against unauthorized access, use, disclosure, alteration, and destruction, appropriate to the nature of the information and the risks involved. These measures include encryption of data in transit, encryption at rest of designated sensitive data fields (including government and taxpayer identifiers, financial-account details, and identity documents) using industry-standard cryptographic methods, logical tenancy isolation and access controls that restrict access according to role and scope, credential protection, audit logging of sensitive operations, and the retention of platform-level secrets outside of client applications. No method of transmission or storage, however, is perfectly secure, and we cannot and do not guarantee absolute security. You are responsible for maintaining the confidentiality of your credentials and the security of your devices, and for promptly notifying us of any suspected compromise.

12. Your Privacy Rights and Choices

Depending upon your jurisdiction and applicable law, you may have rights with respect to your personal information, which may include: the right to know or access the personal information we hold about you and information about our processing; the right to request correction of inaccurate information; the right to request deletion; the right to restrict or object to certain processing; the right to data portability; the right to opt out of any sale or sharing (which, as stated, we do not conduct) and of certain profiling; and the right not to receive discriminatory treatment for exercising your rights. Where we rely upon consent, you may withdraw it prospectively.

Because much of the information processed through the Service is Workforce Data for which the Company is the controller, requests concerning such information should ordinarily be directed to the relevant Company, and we will assist the Company as required by applicable law. Where we are the controller, you may submit a request to us using the contact details below. We will verify requests as required by law, may decline requests to the extent permitted, and will not discriminate against you for exercising your rights. You may also manage certain communication and notification preferences within the Service, subject to the fact that some categories of communication are integral to the Service and cannot be disabled.

13. Cookies, Analytics, and Tracking Technologies

The Service uses cookies, local storage, and similar technologies that are strictly necessary to authenticate sessions, remember preferences, secure the Service, and enable core functionality, and may use limited analytics to understand and improve usage. We do not use these technologies for cross-context behavioral advertising. You may control certain technologies through your browser or device settings, although disabling strictly necessary technologies may impair the Service.

14. International Data Transfers and Data Location

The Service is operated from, and personal information may be processed and stored in, the United States and in such other jurisdictions in which we or our subprocessors operate. If you access the Service from outside such jurisdictions, you understand that your information may be transferred to, processed in, and stored in a jurisdiction whose data-protection laws may differ from those of your own, and, where required, such transfers are conducted subject to appropriate safeguards.

15. Children's Privacy

The Service is intended for use by businesses and their adult personnel and is not directed to, or intended for use by, children under the age of majority. We do not knowingly collect personal information from children. If we become aware that we have collected personal information from a child in a manner inconsistent with applicable law, we will take appropriate steps to delete it.

16. Changes to This Policy; Contact

We may update this Policy from time to time. When we do, we will revise the version identifier and effective date above and, where required by applicable law or where changes are material, may provide additional notice. Your continued use of the Service after the effective date of a revised Policy constitutes your acknowledgment of the revised Policy. Questions, requests, or concerns regarding this Policy or our privacy practices may be directed to Mutor Biz at info@weerm.com.