SprintHR Security & Trust
Provider: Gleent, Inc.
Product: SprintHR
Effective Date: October 1, 2026
Last Updated: September 30, 2026
Version: 1.0
SprintHR is designed to help organizations manage sensitive HR, payroll, recruitment, attendance, performance, and related business information.
Gleent, Inc. ("Gleent," "we," "us," or "our") maintains technical, organizational, and administrative safeguards designed to protect SprintHR systems and Customer Data against unauthorized access, disclosure, alteration, loss, misuse, and other security risks.
This page provides a high-level overview of SprintHR's security and trust practices. It is informational and does not replace the SprintHR Customer Agreement, Data Processing Addendum ("DPA"), Privacy Policy, AI Terms, or other binding agreements.
1. Security Principles
Our security approach is based on the following principles:
- limit access to systems and data based on legitimate business need;
- separate customer environments and permissions appropriately;
- protect data in transit and at rest using appropriate safeguards;
- monitor systems and security events;
- maintain backups and recovery processes;
- reduce unnecessary access to production systems and Customer Data;
- respond to security incidents promptly;
- use trusted infrastructure and service providers;
- maintain appropriate logging and auditability; and
- continuously improve security practices as SprintHR evolves.
2. Infrastructure and Hosting
SprintHR may use cloud infrastructure and service providers to operate the platform.
Depending on the applicable SprintHR service, deployment, or configuration, infrastructure may include providers such as:
- Google Cloud;
- DigitalOcean;
- Cloudflare; and
- other subprocessors identified in the current SprintHR Subprocessor List.
These providers may support functions such as:
- compute;
- networking;
- file and object storage;
- backups;
- content delivery;
- security services;
- disaster recovery; and
- AI-assisted processing.
The specific infrastructure used may vary based on SprintHR architecture, service requirements, Customer configuration, and operational needs.
For a current list of relevant subprocessors, see the SprintHR Subprocessor List.
3. Data Encryption
SprintHR uses appropriate technical protections for data transmission and storage.
Data in Transit
SprintHR uses encrypted network connections, such as HTTPS/TLS, for supported communications between users, SprintHR services, APIs, and connected systems.
Data at Rest
Customer Data stored through SprintHR is protected using encryption or equivalent storage protections provided by the applicable infrastructure and storage services where supported and appropriate.
Encryption practices may vary depending on the underlying storage, database, backup, or service architecture.
4. Authentication and Access Control
SprintHR uses access controls designed to restrict system and data access to authorized users.
Controls may include:
- authenticated user accounts;
- role-based access control;
- organization or tenant membership;
- user roles and permissions;
- administrator-controlled access;
- session and credential protections;
- API authentication;
- scoped service or integration credentials; and
- additional authentication controls where supported.
Customers are responsible for assigning appropriate roles and permissions to their Authorized Users.
Users should protect their credentials and report suspected unauthorized access promptly.
5. Tenant and Customer Data Isolation
SprintHR is designed to separate Customer Data according to the applicable tenant, organization, account, database, permission, or system boundary used by the relevant SprintHR service.
Access to Customer Data is restricted according to:
- tenant or organization membership;
- application permissions;
- user roles;
- system authorization rules; and
- service-level access controls.
Gleent seeks to prevent one Customer from accessing another Customer's data without authorization.
6. Logging and Auditability
SprintHR may maintain logs and audit records to support:
- authentication and account security;
- security monitoring;
- troubleshooting;
- system administration;
- incident investigation;
- compliance;
- detection of suspicious or unauthorized activity; and
- Customer audit and reporting functions where supported.
Depending on the SprintHR feature, logs may include information such as:
- login activity;
- account activity;
- system events;
- application errors;
- API requests;
- administrative actions;
- security events; and
- other technical metadata.
Access to logs is restricted according to operational need and applicable permissions.
7. Backups and Recovery
Gleent maintains backup and recovery processes designed to reduce the risk of permanent data loss and support restoration of SprintHR services following certain failures or incidents.
Depending on the applicable system or service, backup practices may include:
- database backups;
- file or object-storage backups;
- infrastructure snapshots;
- off-system or separate-storage backup copies;
- retention schedules;
- periodic recovery procedures; and
- disaster-recovery processes.
Backup architecture and retention may vary by system, service, and Customer configuration.
Backup copies may remain for a limited period after data is deleted from active systems until the applicable backup lifecycle expires.
8. Vulnerability and Patch Management
Gleent maintains processes intended to identify and address security vulnerabilities affecting SprintHR.
These processes may include:
- software and dependency updates;
- operating-system and infrastructure patching;
- vulnerability monitoring;
- security review of material changes;
- remediation of identified vulnerabilities;
- infrastructure hardening; and
- review of relevant provider security advisories.
The priority and timing of remediation may depend on factors such as:
- severity;
- likelihood of exploitation;
- affected systems;
- availability of mitigations; and
- potential impact on Customers and data subjects.
9. Secure Development and Change Management
SprintHR development and deployment processes are designed to reduce security risks introduced by software changes.
Depending on the applicable service and development workflow, practices may include:
- code review;
- source-control access restrictions;
- testing before production deployment;
- environment separation;
- controlled deployment processes;
- secrets and credential management;
- dependency management;
- logging and monitoring; and
- rollback or recovery procedures.
Security requirements are considered when designing material new features, integrations, and system changes.
10. Personnel and Internal Access
Access by Gleent personnel to production systems and Customer Data is limited according to legitimate operational need.
Where appropriate, controls may include:
- role-based internal access;
- least-privilege access;
- confidentiality obligations;
- restricted administrative access;
- account and credential controls;
- logging of privileged activity; and
- removal or adjustment of access when responsibilities change.
Gleent personnel are not permitted to access Customer Data for unrelated personal purposes.
11. Incident Response
Gleent maintains processes for responding to suspected or confirmed security incidents.
Incident-response activities may include:
- detection;
- triage;
- containment;
- investigation;
- mitigation;
- recovery;
- preservation of relevant evidence;
- Customer communication;
- regulatory or data-subject notification where required; and
- post-incident corrective actions.
Where a personal data breach affects Customer Personal Data processed by Gleent as a Personal Information Processor, Gleent will handle notification and assistance in accordance with the SprintHR DPA and applicable law.
12. Privacy and Data Protection
SprintHR security practices operate together with Gleent's privacy and data-protection obligations.
Where Gleent processes Customer Personal Data on behalf of a Customer, the SprintHR Data Processing Addendum governs the applicable processing relationship.
Privacy-related safeguards may include:
- purpose limitation;
- data minimization;
- access restrictions;
- confidentiality obligations;
- subprocessor controls;
- retention and deletion practices;
- assistance with data-subject requests; and
- incident and breach-response obligations.
For more information, see:
- SprintHR Privacy Policy;
- SprintHR Data Processing Addendum; and
- SprintHR Subprocessor List.
13. Subprocessors and Third-Party Services
Gleent uses third-party service providers where necessary to operate SprintHR.
These providers may support:
- cloud infrastructure;
- storage;
- backups;
- network security;
- email delivery;
- AI-assisted functionality;
- payment processing; and
- other technical services.
Where a third party processes Customer Personal Data on Gleent's behalf, Gleent applies appropriate contractual, privacy, confidentiality, and security requirements in accordance with the SprintHR DPA and applicable law.
The current list of relevant providers is available in the SprintHR Subprocessor List.
14. AI Security and Data Protection
SprintHR may provide AI-assisted features through Gleent-operated systems or third-party AI providers.
Security and privacy controls for AI Features may include:
- limiting access to AI Features based on user permissions;
- sending only information necessary for the requested AI function where practicable;
- applying Customer-configured permissions and data access boundaries;
- using subprocessors subject to appropriate contractual protections;
- logging or monitoring AI-related system activity where appropriate;
- requiring human review for significant decisions where appropriate; and
- preventing AI Features from independently exercising permissions beyond those granted through SprintHR.
Customer Personal Data processed through AI Features remains subject to the SprintHR DPA and AI Terms where applicable.
15. API and Integration Security
SprintHR may provide APIs, webhooks, integrations, and connected-service functionality.
Security controls may include:
- authentication tokens or API credentials;
- scoped permissions;
- authorization checks;
- tenant and application boundaries;
- request validation;
- usage and rate controls;
- logging;
- revocation of compromised credentials; and
- Customer-controlled configuration.
Customers are responsible for protecting Customer-controlled API credentials, integration secrets, and connected accounts.
16. Business Continuity and Disaster Recovery
Gleent maintains operational measures intended to support service continuity and recovery from major disruptions.
Depending on the affected system, these measures may include:
- backups;
- infrastructure redundancy;
- service restoration procedures;
- alternative infrastructure or recovery paths;
- incident escalation;
- recovery prioritization; and
- communication procedures.
No cloud or software service can guarantee uninterrupted availability. Where a formal availability commitment applies, it is governed by the applicable SprintHR Service Level Agreement or Customer Order.
17. Security Responsibilities of Customers
Security is a shared responsibility.
Customers are responsible for:
- assigning appropriate user roles and permissions;
- removing access when users no longer require it;
- protecting administrator and user credentials;
- securing Customer-controlled devices and networks;
- configuring integrations appropriately;
- protecting API keys, tokens, and secrets;
- ensuring users follow Customer security policies;
- reporting suspected compromise promptly; and
- using SprintHR in accordance with the Acceptable Use Policy.
Gleent is not responsible for security failures caused solely by Customer-controlled systems, credentials, configurations, or unauthorized actions outside Gleent's reasonable control.
18. Responsible Security Reporting
If you believe you have discovered a security vulnerability affecting SprintHR, please report it responsibly and avoid accessing, altering, downloading, or disclosing data beyond what is reasonably necessary to identify the issue.
Security reports should include, where possible:
- a description of the issue;
- affected feature or endpoint;
- steps to reproduce;
- potential impact; and
- relevant screenshots or technical details.
Do not publicly disclose an unremediated vulnerability without providing Gleent a reasonable opportunity to investigate and address the issue.
19. Security and Privacy Contacts
Security, privacy, and legal concerns may be directed to:
Gleent, Inc.
Unit 18, 2nd Floor, Sundrel Bldg.
Brgy. Sala, City of Cabuyao
Laguna, Philippines
Privacy / Data Protection: [email protected]
Legal: [email protected]
Security-related reports may also be submitted through SprintHR's authorized support channels.
20. Changes to this Security & Trust Page
Gleent may update this page from time to time to reflect:
- changes to SprintHR architecture;
- new security controls;
- changes to infrastructure or subprocessors;
- changes to privacy or security requirements;
- new integrations or AI Features; or
- improvements to operational security practices.
Material contractual commitments remain governed by the applicable SprintHR Customer Agreement, DPA, SLA, Order, or other binding agreement.
