Security & Trust
MeritHRMS Legal Pack R1.1 · Last updated: 12 August 2026
Our commitment
MeritHRMS is built and operated by Adneti Technologies (Singapore) to keep your employees’ HR and payroll data private, available, and under your control. This page describes the safeguards in place today and those we are actively rolling out.
Data protection — in place today
- Encryption in transit: TLS 1.2+ for all connections between your browser and MeritHRMS.
- Access control: role-based access control, with account-lockout protection against brute-force login attempts.
- Organisation isolation: each organisation’s data is logically isolated.
- Audit logging: access and administrative events are logged.
- Backups: regular automated database backups.
Rolling out (2026 security hardening)
- Database encryption at rest.
- Multi-factor authentication (MFA) for accounts.
- Point-in-time recovery (target RPO ≤ 1 hour) and a documented disaster-recovery runbook.
- Immutable, encrypted off-site backups (object-lock, write-only key) following the 3-2-1 principle.
- A published uptime SLA.
Data residency & retention
- Cloud hosting in the Singapore region.
- Retention aligned to Singapore PDPA (s24 Protection, s25 Retention); data retained per your contract and deleted on request or termination under our DPA.
Governance & roles (PDPA)
- You are the data controller of your employees’ data; MeritHRMS is your data intermediary (processor) under a written Data Processing Agreement.
- Breach handling: we notify you without undue delay (PDPA s26C(3)(a)); you assess and notify the PDPC where required (s26D).
- Data Protection Officer: dpo@adneti.sg.
Report a concern
Security or data-protection matters: dpo@adneti.sg.