Personal Data Protection Notice
MeritHRMS Legal Pack R1.1 · Last updated: 12 August 2026
Abridged notice — an executed DPA prevails. Published at merithrms.com/privacy.html and linked from the sign-in footer and the Merit Me “About” page.
Operator
MeritHRMS and the Merit Platform are operated by Adneti Technologies Pte Ltd (AT), part of the Eusen Group, under licence from the platform’s owner. AT provides commercial contracting, implementation, and maintenance for this service interface.
1. Scope & Singapore PDPA Compliance
This Notice describes how personal data is collected, used, and disclosed within Merit Pay and related MeritHRMS interfaces. All data processing activities are strictly aligned with the Singapore Personal Data Protection Act 2012 (PDPA).
2. Data Collection & Processing Scope
We collect and process personal data strictly required to execute core HR functions, including but not limited to: payroll runs, Central Provident Fund (CPF) submission workflows, and Merit auditing metadata. This encompasses attendance, employment status, and compensation metadata as configured by your organisation.
Location & device data (Merit Me app): Where your organisation enables geofenced or field-visit attendance, the app collects device location (GPS) only at the moment you clock in/out — not continuously or in the background — together with the resolved address. If you enable notifications, a device push token is collected to deliver reminders.
3. Purposes of Processing
Data processing is conducted on a strict need-to-know basis to support statutory and contractual HR obligations. Processing also facilitates internal risk controls within the Eusen Group ecosystem, including automated fraud detection, anomaly flagging, and policy compliance checks.
4. Data Sovereignty & Insight Vault Analytics
Operational data is logically isolated per organisation to ensure absolute organisation privacy. Any cross-entity aggregation for Insight Vault analytics follows strict compliance checklists, data minimisation principles, and rigid access controls approved specifically for group-risk workflows.
5. Retention, Security & Cross-Border Transfers
Personal data is retained in accordance with statutory minimum retention periods, or your organisation’s internal policies where stricter (PDPA s25). Cross-border data transfers occur only under appropriate legal safeguards or explicit consent as required under the PDPA.
Security measures. We protect your data with layered technical and organisational safeguards: encryption in transit (TLS 1.2+); role-based access control with account-lockout protection against brute-force attempts; per-organisation logical isolation; access and administrative event logging; and regular automated database backups. Additional measures — encryption at rest, multi-factor authentication, point-in-time recovery, and immutable off-site backups — are being rolled out as part of our 2026 security hardening. No system is perfectly secure, but we work continuously to protect your data and to detect and respond to incidents.
Service providers: We use a limited set of sub-processors to deliver the Service, including cloud hosting (Singapore region), the Singapore OneMap geocoding service (to convert coordinates to a readable address), and a mobile push service (e.g., Firebase Cloud Messaging) for notifications. Each processes data only as needed for its function.
6. Our Role & Data Breaches
For employee personal data uploaded by your organisation, your organisation is the data controller and MeritHRMS (Adneti Technologies) acts as its data intermediary (processor) under a written agreement, bound by PDPA sections 24 (Protection) and 25 (Retention). If we become aware of a data breach affecting your data, we will notify your organisation without undue delay (PDPA s26C(3)(a)) and provide reasonable information to support assessment. Your organisation, as controller, is responsible for notifying the PDPC and affected individuals within the timelines under PDPA s26D where the breach is notifiable.
7. Your Rights & Data Protection Officer (DPO)
Individuals may contact our Data Protection Officer (DPO) to request access, correction, or to exercise any other rights available under the PDPA. We will verify the requester’s identity and respond within reasonable statutory timelines.
Inquiries & Requests: dpo@adneti.sg
8. AI Assistant (MeritAI)
Our website offers an optional AI chat assistant, MeritAI, to answer questions and help you reach our team. If you use it, we process the messages you type and any contact details you choose to submit (e.g., name, work email) to respond and follow up. MeritAI currently runs on our own website and does not send your messages to any third-party AI model. We do not sell this information and do not use it to train third-party AI models. If we later introduce AI models to power MeritAI, we will update this notice and our AI Trust Center before processing your data through them. Questions: dpo@adneti.sg.
This page constitutes the MeritHRMS abridged Personal Data Protection Notice. Sector-specific or enterprise Data Protection Addenda (DPA) schedules executed between your organisation and AT may provide further binding details.