SprintHR Privacy Policy
Effective Date: October 1, 2026
Last Updated: September 30, 2026
Gleent, Inc. ("Gleent," "we," "us," or "our") owns and operates SprintHR, including the SprintHR website, web and mobile applications, APIs, integrations, AI-assisted features, and related services (collectively, the "Services").
This Privacy Policy explains how we collect, use, disclose, retain, and protect personal data in connection with SprintHR.
We process personal data in accordance with Republic Act No. 10173, or the Data Privacy Act of 2012 ("DPA"), its Implementing Rules and Regulations, applicable issuances of the National Privacy Commission ("NPC"), and other applicable laws.
This Privacy Policy applies to:
- visitors to the SprintHR website;
- representatives of customers and prospective customers;
- authorized SprintHR users;
- employees, applicants, contractors, dependents, and other individuals whose personal data is processed through SprintHR;
- people who contact us, attend our events, or interact with our support, sales, or marketing teams; and
- individuals whose personal data is processed through SprintHR integrations or AI-assisted features.
1. Our Role in Processing Personal Data
Gleent may act in different capacities depending on the processing activity.
1.1 When Gleent acts as a Personal Information Controller
Gleent generally acts as a Personal Information Controller ("PIC") when we determine the purpose and means of processing personal data, such as when we process data relating to:
- website visitors;
- customer and prospective-customer representatives;
- account administration;
- billing and commercial relationships;
- support and service communications;
- security, fraud prevention, and service administration;
- events, inquiries, and permitted marketing activities; and
- our own legal and regulatory obligations.
1.2 When Gleent acts as a Personal Information Processor
When a customer uses SprintHR to process personal data relating to its employees, applicants, contractors, dependents, or other individuals, the customer generally determines why and how that data is processed.
In those circumstances, the customer generally acts as the PIC and Gleent acts as its Personal Information Processor ("PIP"), processing personal data on the customer's documented instructions and subject to the applicable agreement and Data Processing Addendum.
If your personal data was submitted to SprintHR by your employer or another SprintHR customer, you may need to contact that organization directly regarding requests concerning your employment or applicant records. We will assist our customers in responding to data-subject requests as required by applicable law and our contractual obligations.
2. Personal Data We Collect
The personal data we process depends on how you interact with SprintHR and which features your organization uses.
2.1 Website, Inquiry, Sales, and Event Data
We may collect:
- name;
- email address;
- telephone or mobile number;
- job title;
- employer or organization;
- business address;
- inquiry, correspondence, or support content;
- event registration information; and
- marketing and communication preferences.
2.2 Account and Service Data
When you use SprintHR, we may process:
- name and contact information;
- username and account identifiers;
- authentication and security information;
- organization or tenant membership;
- roles and permissions;
- account settings and preferences;
- login and access history;
- IP address;
- device and browser information;
- activity and audit logs; and
- support requests and related communications.
2.3 Employee, Workforce, and HR Data
Depending on the modules enabled by a customer, SprintHR may process information such as:
- employee identifiers and personnel numbers;
- name, contact details, address, date of birth, and other profile information;
- employment status, position, department, work location, and reporting relationships;
- attendance, schedules, time records, leave, and overtime;
- compensation, payroll, allowances, deductions, commissions, and benefits;
- tax, statutory, government-issued identification, and other compliance information;
- bank or payment details used for payroll or reimbursements;
- employment contracts, notices, memoranda, certificates, permits, and other employment documents;
- performance, goals, evaluations, training, and related records; and
- other information entered, uploaded, or generated by the customer through the Services.
Some of this information may constitute sensitive personal information under applicable law.
2.4 Applicant and Recruitment Data
SprintHR recruitment features may process:
- resumes and curriculum vitae;
- contact information;
- employment and education history;
- skills and qualifications;
- interview notes and assessments;
- application status;
- references and supporting documents; and
- other information provided during recruitment.
2.5 Dependent and Beneficiary Data
Where a customer uses SprintHR for benefits, payroll, statutory compliance, or related HR administration, the customer may provide information about dependents, beneficiaries, emergency contacts, or other related individuals.
2.6 Files and Documents
Users and authorized customer administrators may upload files to SprintHR, including resumes, contracts, notices, government documents, certificates, identification documents, and other records.
The customer is responsible for determining what files may lawfully be uploaded and who within its organization is authorized to access them.
2.7 Billing and Transaction Data
We may process customer billing contacts, invoices, subscription information, transaction references, and related financial records.
If payment-card processing is provided through a third-party payment provider, payment-card information may be processed directly by that provider in accordance with its own terms and privacy practices.
2.8 Device, Log, Cookie, and Usage Data
We may automatically collect technical information such as:
- IP address;
- browser and device type;
- operating system;
- access times;
- referring pages;
- pages and features used;
- session and diagnostic information;
- application logs;
- security events; and
- cookie or similar technology identifiers.
We use this information for security, authentication, troubleshooting, analytics, service operation, and improvement.
2.9 Information from Integrations and Third Parties
If a customer enables an integration, SprintHR may receive information from or send information to third-party services according to the customer's configuration and instructions.
Examples may include authentication providers, communication tools, calendar services, storage services, payroll or banking services, and other business systems.
3. AI-Assisted Features
SprintHR may provide artificial-intelligence-assisted features for functions such as:
- summarization;
- drafting;
- classification;
- search and retrieval;
- recommendations;
- anomaly or pattern detection;
- workflow assistance;
- applicant or employee-related analysis; and
- other productivity or decision-support functions.
Depending on the feature used, AI processing may involve prompts, documents, employee or applicant records, retrieved context, metadata, and generated outputs.
Where third-party AI providers are used to provide an AI feature, relevant data may be transmitted to those providers as necessary to deliver the requested functionality and subject to applicable contractual, privacy, and security safeguards.
AI-generated output may be incomplete, inaccurate, or inappropriate for a particular decision. Customers are responsible for determining how AI-assisted outputs are used in their employment and business processes and for complying with applicable requirements concerning transparency, fairness, human review, profiling, and automated decision-making.
Additional rules governing SprintHR AI features may be provided in the SprintHR AI Terms and the Gleent Subprocessor List.
4. Why We Process Personal Data
4.1 Lawful Bases for Processing
Depending on the processing activity, Gleent may process personal information where:
- you have given consent;
- processing is necessary to perform a contract with you or to take steps at your request before entering into a contract;
- processing is necessary to comply with a legal obligation;
- processing is necessary to protect vitally important interests, including life or health;
- processing is necessary for legitimate interests pursued by Gleent or another party, provided those interests are not overridden by the data subject's fundamental rights and freedoms; or
- another lawful basis permitted by applicable law applies.
Where sensitive personal information or privileged information is involved, Gleent processes such information only where a lawful ground permitted under the Data Privacy Act or other applicable law applies.
Where Gleent acts as a Personal Information Processor on behalf of a SprintHR customer, the customer is generally responsible for determining the lawful basis for processing the personal data it controls.
4.2 Purposes of Processing
Depending on the context and applicable lawful basis, we may process personal data to:
- provide, operate, maintain, and support SprintHR;
- create, authenticate, and administer user accounts;
- perform our contractual obligations to customers;
- process payroll, HR, recruitment, attendance, performance, and other functions configured by customers;
- provide customer support and respond to inquiries;
- maintain security and prevent unauthorized access, fraud, abuse, or misuse;
- troubleshoot, monitor, and improve the reliability and performance of the Services;
- maintain audit trails and system records;
- provide integrations and customer-requested features;
- provide AI-assisted functionality requested or enabled by customers;
- comply with legal, regulatory, tax, accounting, employment, or other applicable obligations;
- establish, exercise, or defend legal claims;
- communicate material service, security, administrative, or contractual information;
- perform analytics and research using information that is appropriately aggregated or de-identified where practicable; and
- conduct marketing activities where permitted by law and subject to applicable consent or opt-out requirements.
We do not require consent where another lawful basis for processing applies. Where processing is based on consent, you may withdraw that consent subject to applicable law and without affecting processing lawfully carried out before withdrawal.
5. How We Share Personal Data
We may disclose personal data only where reasonably necessary for the purposes described in this Privacy Policy, including to the following categories of recipients.
5.1 SprintHR Customers and Authorized Users
Personal data stored in a customer's SprintHR environment may be accessible to that customer's authorized administrators, managers, HR personnel, payroll personnel, or other users according to the permissions configured by the customer.
5.2 Service Providers and Subprocessors
We may engage third parties to provide infrastructure, hosting, communications, analytics, security, customer support, payment, storage, AI, and other services.
These providers may process personal data only to the extent necessary to provide their services to us and are subject to appropriate contractual or legal obligations.
A current list of relevant subprocessors may be published at:
/legal/subprocessor-list
5.3 Integrations Selected by Customers
If a customer enables a third-party integration, personal data may be shared with that third party as directed by the customer. The third party's own privacy terms may apply to its independent processing.
5.4 Affiliates and Business Operations
We may disclose personal data within Gleent or to authorized personnel where necessary to operate, administer, secure, or support the Services.
5.5 Legal and Regulatory Disclosures
We may disclose personal data when required or permitted by applicable law, regulation, court order, lawful government request, or legal process, or where reasonably necessary to protect the rights, safety, security, or property of Gleent, our customers, users, or others.
5.6 Corporate Transactions
If Gleent is involved in a merger, acquisition, financing, restructuring, sale of assets, or similar corporate transaction, personal data may be disclosed subject to appropriate confidentiality, security, and legal safeguards.
We do not sell personal data.
6. International Processing and Transfers
SprintHR and its service providers may process or store personal data in the Philippines or in other countries where Gleent or its subprocessors operate.
Where personal data is transferred or processed outside the Philippines, we take reasonable steps to ensure that the transfer is carried out in accordance with the DPA, applicable NPC requirements, our contractual obligations, and appropriate data-protection safeguards.
Information about relevant subprocessors and processing locations may be provided in our Subprocessor List.
7. Data Retention
We retain personal data only for as long as reasonably necessary for the purposes for which it was collected or processed, including to satisfy contractual, legal, regulatory, accounting, security, dispute-resolution, and enforcement requirements.
Specific retention periods may vary depending on the category of personal data, the purpose of processing, customer instructions where Gleent acts as a PIP, contractual requirements, applicable legal and regulatory requirements, security needs, and our documented retention schedules. Where practicable, additional information about applicable retention periods or the criteria used to determine them may be provided through product-specific notices, contractual documents, or upon request.
For Customer Data processed by Gleent as a PIP, retention and deletion are governed by the customer's instructions, the Customer Agreement, the applicable Data Processing Addendum, and legal requirements.
Following termination of a SprintHR subscription, Customer Data will be returned, made available for export, retained, or deleted in accordance with the applicable agreement and our documented retention and backup procedures.
Some information may remain temporarily in backups or disaster-recovery systems after deletion from active systems and will be removed or overwritten according to the applicable backup-retention cycle, unless longer retention is legally required.
We may retain appropriately aggregated or de-identified information where it can no longer reasonably be used to identify an individual.
8. Security
We implement reasonable and appropriate organizational, physical, and technical safeguards designed to protect personal data against accidental or unlawful destruction, loss, alteration, unauthorized disclosure, unauthorized access, and other unlawful processing.
Measures may include, as appropriate:
- access controls and role-based permissions;
- authentication and account-security controls;
- encryption or other appropriate protections for data in transit and at rest;
- logging and monitoring;
- vulnerability and security-management practices;
- backups and disaster-recovery measures;
- confidentiality obligations;
- personnel access restrictions; and
- incident-response procedures.
No information system or method of transmission can be guaranteed to be completely secure. Users are responsible for protecting their credentials and using the Services in accordance with applicable security requirements.
Where a personal data breach occurs, Gleent will take reasonable and appropriate steps to contain, investigate, mitigate, and respond to the incident. Gleent will provide or assist with notifications to affected customers, data subjects, the National Privacy Commission, or other competent authorities where required by applicable law and our contractual obligations.
9. Your Rights as a Data Subject
Subject to the DPA and applicable law, data subjects may have rights including the right to:
- be informed about the processing of their personal data;
- access personal data concerning them;
- object to certain processing;
- correct or rectify inaccurate or incomplete personal data;
- request erasure or blocking where legally applicable;
- withdraw consent where consent is the lawful basis for processing;
- obtain data portability where applicable;
- lodge a complaint with the National Privacy Commission; and
- seek damages where provided by law.
These rights may be subject to lawful exceptions and limitations.
If your information is controlled by your employer or another SprintHR customer, that organization is generally the appropriate party to handle your request. You may contact that organization directly, or contact Gleent and we will route or assist with the request as appropriate under our contractual and legal obligations.
If Gleent is the PIC for the relevant processing activity, you may contact our Data Protection Officer using the details in Section 15.
10. Automated Processing and Profiling
Certain SprintHR functions may involve automated processing, analytics, scoring, classification, recommendations, or AI-assisted analysis.
Where required by applicable law, SprintHR or the relevant SprintHR customer will provide appropriate information regarding the nature and purpose of automated processing or profiling, the categories of information used, meaningful information regarding the logic involved where applicable, and the significance and reasonably foreseeable consequences for the data subject. Such information may be provided through this Privacy Policy, product-specific notices, in-product disclosures, the SprintHR AI Terms, or notices provided by the relevant SprintHR customer.
Customers remain responsible for determining the lawful basis and appropriate use of automated or AI-assisted processing they configure through SprintHR, including whether human review or additional notice is required for employment-related decisions. Gleent will provide customers with information reasonably necessary to understand and administer the relevant SprintHR features and to support their applicable transparency obligations.
11. Cookies and Similar Technologies
SprintHR may use cookies and similar technologies that are necessary for authentication, security, preferences, performance, analytics, and operation of the Website and Services.
Where required by law, we will request consent before using non-essential cookies or similar technologies.
You may be able to control cookies through your browser or device settings. Disabling certain cookies may affect the functionality of the Services.
12. Marketing Communications
Where permitted by law, we may send information about SprintHR, Gleent products, events, updates, or related services to customer representatives, prospective customers, or individuals who have provided appropriate permission.
You may opt out of promotional email communications using the unsubscribe mechanism provided in the communication or by contacting us.
Opting out of marketing messages will not prevent us from sending necessary transactional, contractual, security, billing, account, or service-related communications.
13. Children's and Dependent Data
The public SprintHR website is not directed to children for independent use.
However, a SprintHR customer may lawfully process information about dependents, beneficiaries, interns, or other minors where necessary for employment, benefits, statutory, or other legitimate purposes.
When such information is provided by a customer, Gleent processes it according to the customer's instructions, the applicable agreement, and applicable law.
14. Changes to This Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in our Services, processing activities, technologies, legal requirements, or business practices.
The updated policy will state its effective date and last-updated date.
Where required by law or where changes materially affect how we process personal data, we will provide appropriate notice through the Website, the Services, email, or another reasonable method.
15. Contact Us and Our Data Protection Officer
For questions about this Privacy Policy, requests relating to personal data for which Gleent acts as PIC, or inquiries for our Data Protection Officer, contact:
Gleent, Inc.
Unit 18, 2nd Floor, Sundrel Bldg.
Brgy. Sala, City of Cabuyao
Laguna, Philippines
Data Protection Officer / Privacy Email: [email protected]
If your request concerns employee, applicant, payroll, attendance, performance, or other records controlled by your employer or another SprintHR customer, that organization is generally the appropriate party to handle your request. You may contact that organization directly, or contact Gleent and we will route or assist with the request as appropriate under our contractual and legal obligations.
You may also raise concerns with the National Privacy Commission in accordance with applicable law.
