Privacy

Last updated 4 October 2026

Peoplume is HR software sold to employers. Almost everything in it is personal data about someone’s staff, so this page sets out exactly what is stored, who else can see it, and how it leaves again.

Who is who. Under GDPR-style terminology, the employer using Peoplume is the data controller — they decide what to record about their people. Peoplume is a processor, acting on the employer’s instructions. If you are an employee and want your record corrected or removed, ask your employer’s HR team; they hold the controls, not us.

What is stored

Only what the employer enters or the product generates. Nothing is collected from third parties, bought from data brokers, or inferred about anyone.

CategoryFields
Identity & contactName, employee number, work email, phone, address, date of birth, gender, nationality, marital status, emergency contact name and phone. Every one of these except name and employee number is optional.
EmploymentHire date, probation end, employment type, department, job title, branch, shift, reporting manager, status and termination date, free-text notes.
PayBasic salary or hourly rate, allowances and deductions, loans, bank name and IBAN, payslips, and a history of salary changes. Approved payroll runs are immutable snapshots by design.
TimeAttendance records (date, check-in and check-out as times of day), leave requests, timesheets and project hours. Portal check-ins may include browser geolocation when the employee's device allows it — the punch is never blocked if it does not.
DocumentsFiles the employer uploads: contracts, IDs, certificates, expense receipts, candidate CVs, company policies, and a company logo.
FamilyDependents the employer records for sponsorship and benefits: name, relationship, optional date of birth and nationality, whether the company sponsors them, and one identity document's type, number and expiry. These are people who are not users and cannot sign in; the employee sees the list on their own profile.
Performance & developmentGoals, reviews and ratings, self-assessments, peer feedback, training enrolments and certificates, succession plans.
RecruitmentApplicant name, email, CV, interview notes, scorecards and offers — including applications submitted through an employer's public careers page.
Account & securityLogin email, a bcrypt hash of the password (never the password), last login time, and an append-only audit log of sensitive changes recording who made them.

Engagement survey responses are deliberately anonymous. A response row carries no employee reference and no timestamp, and the record of who responded is kept in a separate table that is never joined to it. Results stay hidden until a minimum number of people have answered. The one thing we cannot anonymise is a free-text comment, and the portal says so before you type one.

Who else processes it

A short list, each with a narrow job. The current list, and what each one receives, is on the sub-processors page.

Some are optional and simply do nothing if the employer has not configured them: outbound email, the receipt-reading feature, and the AI assistant — which is also off until an administrator switches it on, since answering a question means sending the rows needed for the answer to Anthropic. Peoplume does not sell data and does not share it for advertising.

One third-party script does run on our pages: Cloudflare Web Analytics, which counts page views and referrers so we can see which parts of the site are used. It sets no cookie, builds no profile and cannot follow anyone to another site. We would rather name it than let “no tracking scripts” stand, which is what this page said until the content security policy we added caught it — Cloudflare injects the script at the edge, so it never appeared in our own source. There is no advertising or cross-site tracking of any kind.

How long it is kept

Mostly, for as long as the employer keeps it. There is one scheduled deletion, and it is off unless switched on: an employer can set a period after which rejected job applicants are deleted automatically, with their CV. Nothing else in Peoplume is removed on a timer, and no default period is assumed — how long to keep a record is a statement about the employer’s own obligations, not ours to guess.

Erasing a person. An administrator can erase a former employee’s personal data: name, contact details, date of birth, nationality, bank details and every uploaded document go, permanently, along with their portal login. What stays is the employment and payroll record — employee number, hire and termination dates, payslips, attendance and leave. That split is deliberate. A right-to-erasure request does not entitle anyone to rewrite what a company reported it paid, and a system that deleted payslips to honour one would change the accounting record months after the fact.

What else the employer can delete, and what happens when they do:

  • Deleting an employee removes their record and their portal login in the same transaction. It is refused if they have ever been paid — a payslip is an accounting record, and the answer there is to mark them terminated instead.
  • Deleting a document, receipt or CV also removes the underlying file from disk.
  • Webhook delivery logs keep only the most recent 20 per endpoint.
  • The audit log is append-only on purpose: it exists to record who changed a salary or approved a payment, and an audit trail that can be edited is not one.

Getting data out

Without asking us and without an export request: employees, attendance, leave, payroll, expenses and reports each export to CSV; a report builder lets you choose your own columns; one archive contains every table; and a read-only API serves scoped keys.

Answering a request about one person is one click. An employer can download everything held about a single employee — profile, attendance, leave, payslips, expenses, training, reviews — as one set of spreadsheets from that person’s profile. Pay is included only if the person downloading it is allowed to see salaries, and the file says so rather than leaving a silent gap.

Employees can download their own, without asking. The same bundle is on every employee’s own profile in the portal. A subject-access right that can only be exercised by asking your employer is a right with a gatekeeper, so there isn’t one — and we deliberately do not log people reading their own record.

Where it runs

Peoplume is hosted on Railway, with Cloudflare in front of it. Uploaded files — contracts, identity documents, receipts, CVs — and the off-site database backups are stored in Cloudflare R2, which encrypts them at rest; we do not add a further layer of our own before they are sent. If your organisation has a data-residency requirement, ask before you commit — the hosting region is a deployment decision and we would rather agree it up front than discover it during your review.

Who to ask

Peoplume is operated by Plumeware LLC. Data protection questions — what is held, access and erasure requests, our sub-processors — go to [email protected].

If you are an employee rather than an employer, ask your own HR team first: they decide what is recorded about you and hold the controls to change it. We act on their instructions and cannot alter their records for them.

Changes to this page

The date at the top is the last change. Because this page describes how the software behaves rather than what we intend, it changes when the software does.