0
Privacy Policy
Human Solutions+ · Effective date: July 18, 2026

1. Who We Are and Scope

This Privacy Policy explains how Human Solutions Plus LLC ("Human Solutions+," "we," "us") collects, uses, and protects information in connection with the Human Solutions+ platform and websites (the "Service").

For information about the businesses that subscribe to the Service (our "Customers"), we generally act as a controller. For the employee and personnel information that a Customer submits about its own workforce, we generally act as a processor acting on the Customer's instructions; that Customer is responsible as the controller of its employees' information.

2. Information We Collect

Account and business information

•Account details such as name, email address, and password (passwords are stored in hashed form by our authentication provider).
•Company information such as company name, size, industry, and billing contact.
•Billing information processed by our payment provider (we do not store full card numbers).

Workforce information submitted by Customers

Customers may submit personnel information about their Authorized Users and employees. Depending on how a Customer uses the Service, this may include:

•Employee profiles, names, and contact details; emergency contacts; job title, department, and manager;
•Employment status and dates; compensation and paid-time-off information; time-off requests;
•Uploaded personnel files and onboarding documents; signed acknowledgements and handbook acknowledgements; documents generated in the Service;
•Performance reviews, coaching notes, disciplinary records, and performance improvement plans (PIPs);
•Organizational charts, custom forms, and role/permission assignments; and
•Workplace concerns or complaints (including submissions a Customer chooses to allow anonymously) and voluntary self-identification information where a Customer enables it.

The Service is not designed to collect Social Security numbers, and we instruct Customers not to submit them.

Usage, analytics, and technical information

•Log and device information, such as IP address, browser type, and actions taken in the Service, used for security, troubleshooting, audit history, and improving the Service.

We may analyze Customer Data to generate dashboards, reports, metrics, trends, forecasts, and AI-generated insights — for example, turnover trends, hiring and onboarding metrics, engagement and burnout indicators, manager workload, meeting analytics, and workforce planning — solely for the benefit of the Customer whose data it is. As described in our Terms, these outputs are informational estimates, not factual predictions.

3. How We Use Information

•To provide, maintain, secure, and improve the Service.
•To process subscriptions and payments.
•To communicate with you about your account, security, and support.
•To provide AI Features (see Section 5).
•To comply with legal obligations and enforce our Terms.

We do not sell personal information.

4. Sub-Processors and Service Providers

We rely on the following third-party providers to operate the Service. They process information on our behalf under agreements intended to protect that information:

•Supabase — database, authentication, and file storage (data hosting).
•Vercel — application hosting and content delivery.
•Resend — transactional email delivery (e.g., invitations, notifications).
•Square — payment processing (handles card data; we do not store full card numbers).
•Anthropic — AI processing that powers AI Features such as document drafting and the "Ask Toby" assistant.

5. AI Features and How Data Is Used With Them

When you use AI Features, information needed to fulfill your request is sent to our AI provider to generate a response. Depending on the feature, this may include text from your prompts, selected employee records, uploaded documents, and templates — only as necessary to generate the requested output. AI output is informational only, may be inaccurate, and is not legal or professional advice.

Human Solutions+ does not use Customer Data to train its own AI models. Our AI providers are configured not to use Customer prompts or responses to train their foundation models.

We instruct users not to submit unnecessary sensitive information to AI Features. As described in our Terms, we may change AI providers or underlying AI models.

6. How We Store and Protect Information

We take reasonable technical and organizational measures designed to protect information, including:

•Authentication via our identity provider, with two-factor authentication available for administrators;
•Tenant isolation using row-level security, so each Customer's data is logically separated from others';
•Role-based permissions, so users see only the information appropriate to their role;
•Encryption of data in transit (HTTPS/TLS) and at rest;
•Data minimization, including not storing Social Security numbers; and
•Activity logging of certain actions for security, troubleshooting, and audit history.

We (through our infrastructure providers) maintain encrypted backups and disaster-recovery measures intended to support business continuity.

If we become aware of a security incident affecting Customer Data, we will notify affected Customers as required by applicable law and our contractual obligations.

No method of transmission or storage is completely secure, and we cannot guarantee absolute security.

7. Data Location

The Service is operated in the United States, and Customer Data is primarily stored in the United States.

8. Data Retention and Deletion

We retain information for as long as needed to provide the Service and for legitimate business or legal purposes. When a Customer's subscription ends, we make Customer Data available for export for a limited period and then delete or de-identify it, subject to legal retention requirements.

Our retention timelines are:

•Customer Data available for export for 30 days after cancellation;
•Active Customer Data deleted or de-identified within 60 days after cancellation; and
•Residual copies in encrypted backups expiring within 90 days.

Customers may request deletion of their account and associated Customer Data, subject to applicable legal retention requirements and to the timelines described above.

9. Aggregated and De-Identified Data

We may create and use aggregated and de-identified information to operate, improve, and secure the Service, to develop analytics and benchmarks, and to understand overall product usage. Aggregated and de-identified information does not identify, and cannot reasonably be used to identify, any Customer, employee, or individual, and we do not attempt to re-identify it.

10. Cookies and Similar Technologies

We use cookies and similar technologies that are necessary to operate the Service — for example, authentication and session cookies that keep you signed in — and we may use limited analytics technologies to understand and improve how the Service is used.

11. How Information Is Shared

We share information only: (a) with the sub-processors listed above to operate the Service; (b) as directed by the Customer that controls the data; (c) to comply with law, legal process, or lawful government requests; (d) to protect the rights, safety, and security of users, the public, or Human Solutions+; and (e) in connection with a merger, acquisition, or sale of assets, subject to this Policy. We do not sell personal information.

12. Integrations You Authorize

The Service may offer optional integrations with third-party providers (for example, payroll, productivity, calendar, messaging, or workforce tools). If you choose to connect an integration, you are directing us to exchange information with that provider as needed to enable the integration, and that provider's handling of information is governed by its own terms and privacy policy. You may disconnect integrations as provided in the Service.

13. Customer Choices and Responsibilities

Customers control important aspects of how information is handled in the Service, including what employee information to upload, which managers and other users have access, how roles and permissions are configured, and applicable retention settings. Customers are responsible for these choices. Employees and other Authorized Users should direct questions about their information to their employer (the Customer).

14. Your Choices and Rights

Depending on your role and applicable law, you may have rights to access, correct, delete, or export certain personal information. Employees of a Customer should generally direct such requests to their employer (the controller of their information); we will support our Customers in responding to those requests. Account holders may contact us using the details below.

Because we may serve Customers nationwide, various U.S. state privacy laws may apply.

15. Anonymous Submissions

Where a Customer enables anonymous workplace-concern submissions, the Service is designed not to store the identity of the submitter for those submissions. Please note that the content of a submission may still reveal or suggest identity, particularly in small organizations.

16. Children's Information

The Service is intended for use by businesses and their adult workforce and is not directed to children. We do not knowingly collect personal information from children.

17. International Users

The Service is operated in the United States and intended for U.S. businesses. If you access it from outside the United States, you understand information will be processed and stored in the United States.

18. Changes to This Policy

We may update this Privacy Policy from time to time. If we make material changes, we will provide reasonable notice. The "Effective date" above indicates when this Policy was last updated.

19. Contact

For privacy questions or requests, contact privacy@humansolutionsplus.com or Human Solutions Plus LLC, 7901 4th St N, STE 300, St. Petersburg, FL 33702.