In brief
- We collect only what we need to run asDayOne for you and your team, and we never sell your personal data.
- Much of the data inside asDayOne — your employees, contacts and files — belongs to your organization. You control it, and we process it on your instructions.
- We protect data with encryption and role-based access controls, and store it with reputable cloud providers.
- You can access, correct or delete your data, opt out of marketing, and contact us with any privacy question at any time.
1. Introduction
asDayOne is an all-in-one business operating system that helps organizations manage their people, projects, customers, documents and more in one connected platform. This Privacy Policy explains how [Visible One Limited] ("asDayOne", "we", "us" or "our") collects, uses, shares and protects personal data when you visit our website, create an account, or use the asDayOne platform and related services (together, the "Service").
We are committed to handling personal data in accordance with the Personal Data (Privacy) Ordinance (Cap. 486) of Hong Kong (the "PDPO") and its six Data Protection Principles and, where applicable, the Personal Data Protection Act 2012 of Singapore (the "PDPA"). Please read this policy carefully. If you do not agree with it, please do not use the Service.
2. Who we are and how to contact us
The Service is operated by [Visible One Limited], a company established in Hong Kong with operations in Hong Kong and Singapore. Our registered office is [company registered address, Hong Kong].
If you have any questions about this policy or how we handle personal data, you can contact our privacy team at [privacy@asdayone.com], or by post at the address above, marked for the attention of the "Data Protection / Privacy Officer". Full contact details are set out in Section 18.
3. Our role: when we are a controller and when we are a processor
asDayOne handles personal data in two different roles:
- As a data user (controller). For personal data about our customers, their administrators, website visitors and prospects, we decide how and why the data is used. This policy describes those practices.
- As a data processor. For personal data that a customer uploads or enters into the platform about its own employees, contacts, clients and other individuals ("Workspace Data"), the customer is the data user and decides why the data is processed. We process Workspace Data on the customer's behalf and under its instructions, as set out in our customer agreement.
If you are an employee or contact of an organization that uses asDayOne and you want to know how that organization uses your data, please contact them directly (see Section 13).
4. Personal data we collect
4.1 Information you provide to us
- Account and profile data — such as your name, work email address, phone number, job title, company name, username and password.
- Billing data — such as your billing contact, company and billing address, and payment information. Card payments are handled by our payment provider; we do not store full payment-card numbers.
- Communications — information you include when you contact us for support, sales or feedback.
4.2 Information you and your team put into the platform (Workspace Data)
Depending on the modules your organization uses, Workspace Data may include:
- HR and people data — employee profiles (name, employee ID, contact details, department, designation, branch and location), attendance and clock-in/out records (including working hours and, where your organization enables it, the location recorded at clock-in), leave, overtime, claims, timesheets, daily reports, payroll data and offboarding records.
- Documents — files your team uploads and their metadata (file name, tags, owner, path and dates).
- CRM data — contacts, companies, deals and related notes about your customers and prospects.
- Passwords — credentials your team chooses to store in the built-in password manager, which are held using encryption.
- Performance data — goals, KPIs, reviews and survey responses.
- Other workspace content — announcements, calendar events, tasks and member presence within your workspace.
Your organization decides what data to enter and is responsible for having a proper basis to do so and for informing the individuals concerned.
4.3 Information we collect automatically
- Usage and log data — the pages and features you use, actions you take, dates and times, and referring pages.
- Device and connection data — IP address, browser type, device and operating system, and language settings.
- Approximate location — we may infer your approximate location from your IP address or a location you set, to provide features such as local time, weather and language, and to help keep the Service secure.
- Cookies and similar technologies — see Section 7.
5. How and why we use personal data
We use personal data to:
- provide, operate and maintain the Service and your account;
- authenticate users and keep the Service, your workspace and your data secure, including detecting and preventing fraud, abuse and unauthorized access;
- process payments and manage billing;
- provide customer support and respond to your requests;
- send service and administrative messages, such as important updates, security alerts and changes to our terms;
- understand how the Service is used so we can maintain, improve and develop features;
- with your consent where required, send you product news, offers and marketing (you can opt out at any time); and
- comply with our legal and regulatory obligations, enforce our terms, and protect our legal rights.
We do not sell your personal data. We do not use Workspace Data for our own purposes except as needed to provide and support the Service, or as instructed by the customer.
6. The basis on which we use personal data
Under the PDPO, we collect and use personal data for lawful purposes directly related to our functions and activities, as described in this policy. Depending on the situation, we rely on one or more of the following: your consent (which you may withdraw at any time); the need to perform a contract with you or your organization, or to take steps at your request before entering into one; our legitimate business interests in operating, securing and improving the Service, where these are not overridden by your interests; and compliance with legal obligations.
Where we need your consent and you choose not to provide it, or where you withdraw it, we may be unable to provide part or all of the Service.
7. Cookies and similar technologies
We and our service providers use cookies and similar technologies (such as local storage and pixels) to keep you signed in, remember your preferences, keep the Service secure, and understand and improve how it is used. In general we use strictly necessary cookies (required for the Service to work), functional cookies (to remember your settings), and analytics cookies (to measure usage).
You can control cookies through your browser settings, although disabling some may affect how the Service works. For more detail, see our [Cookie Policy].
8. How we share personal data
We share personal data only as described below, and we never sell it:
- Within your organization — Workspace Data is accessible to authorized users in your organization's account, according to the roles and permissions it sets.
- Service providers and sub-processors — we use trusted third parties to help us run the Service, for example cloud hosting and infrastructure, data storage and backup, payment processing, email and communications, and analytics. They may process personal data only on our instructions and under contractual confidentiality and security obligations. A current list of key sub-processors is available on request at [privacy@asdayone.com].
- Legal and safety reasons — we may disclose personal data where required by law, regulation, legal process or a governmental request, or where necessary to protect the rights, property or safety of asDayOne, our users or others.
- Business transfers — if we are involved in a merger, acquisition, financing or sale of assets, personal data may be transferred as part of that transaction, subject to this policy.
- With your consent — we may share personal data with other parties where you have asked us to or agreed that we may.
9. Data storage and international transfers
We host the Service and store personal data with reputable cloud providers, primarily in [Hong Kong / your chosen data region]. Some of our service providers may store or process personal data in other locations.
Where personal data is transferred outside the place in which it was collected, we take reasonable steps to ensure it continues to receive a level of protection consistent with this policy and applicable law, including through appropriate contractual safeguards.
10. How we protect your data
We take the protection of personal data seriously and use appropriate technical and organizational measures designed to protect it against unauthorized access, loss, misuse or alteration. These include encryption of data in transit and of sensitive data such as stored passwords, role-based access controls, network and application security controls, and regular review of our practices.
No method of transmission or storage is completely secure, so while we work hard to protect your data we cannot guarantee absolute security. Please keep your account credentials confidential and notify us promptly at [privacy@asdayone.com] if you believe your account has been compromised.
11. How long we keep your data
We keep personal data for as long as needed to provide the Service, maintain your account and fulfil the purposes described in this policy, unless a longer retention period is required or permitted by law (for example, for tax, accounting or legal reasons).
For Workspace Data, your organization controls retention within the Service. When your organization's account ends, we delete or return Workspace Data in accordance with our customer agreement, after which it may remain in secure backups for a limited period before being deleted.
12. Your privacy rights
Under the PDPO, you have the right to:
- ask whether we hold your personal data and request access to it (a "data access request");
- request correction of personal data that is inaccurate;
- ask about our personal data policies and practices and the kinds of data we hold;
- withdraw any consent you have given; and
- opt out of direct marketing at any time.
Depending on where you are, you may have additional rights. To exercise any of these, please contact us at [privacy@asdayone.com]. We may need to verify your identity before responding and, as permitted by the PDPO, we may charge a reasonable fee for complying with a data access request. If your personal data is held by us on behalf of an organization that uses asDayOne, please make your request to that organization (see Section 13). You also have the right to complain to a data protection authority (see Section 18).
13. If your data was added by your employer or organization
If you are an employee, contractor, customer or contact of an organization that uses asDayOne, that organization — not asDayOne — decides why and how your personal data is processed in its workspace. We process such data on the organization's behalf and under its instructions.
If you want to access, correct or delete your data, or have questions about how it is used, please contact your organization directly. We will refer requests we receive about Workspace Data to the relevant organization.
14. Children's privacy
The Service is intended for use by organizations and their workforce and is not directed to children. We do not knowingly collect personal data directly from anyone under the age of 16. If you believe we have inadvertently collected such data, please contact us so we can delete it.
15. Third-party links and services
The Service and our website may contain links to third-party websites, products or services that we do not operate. This policy does not apply to those third parties, and we are not responsible for their content or privacy practices. We encourage you to review the privacy policies of any third-party services you use.
16. Notice to users in Singapore
If you are in Singapore, we handle personal data in accordance with the PDPA. Among other things, we will obtain your consent (or rely on another lawful basis) before collecting, using or disclosing your personal data for the purposes described in this policy; we will make reasonable efforts to keep it accurate and protected; and you may request access to, or correction of, your personal data, or withdraw consent, by contacting us at [privacy@asdayone.com]. Our data protection contact for Singapore matters is [name / email].
17. Changes to this Privacy Policy
We may update this Privacy Policy from time to time to reflect changes to the Service, our practices or legal requirements. When we do, we will revise the "Last updated" date at the top of this page and, if the changes are material, we will provide additional notice (for example, by email or an in-product notice). Your continued use of the Service after an update means you accept the revised policy.
18. How to contact us and make a complaint
If you have any questions, concerns or requests about this Privacy Policy or your personal data, please contact us:
If you are not satisfied with our response, you may lodge a complaint with the Office of the Privacy Commissioner for Personal Data, Hong Kong (PCPD) at pcpd.org.hk or, if you are in Singapore, with the Personal Data Protection Commission (PDPC) at pdpc.gov.sg.