OnePassERPby SuperInk

OnePassERP Privacy Policy

Last updated: 29 July 2026

1. About This Privacy Policy

OnePassERP is a software-as-a-service platform operated by SuperInk Pte Ltd, a company incorporated in Singapore (“SuperInk”, “OnePassERP”, “we”, “us” or “our”).

This Privacy Policy explains how we collect, use, disclose, store, transfer, protect and otherwise process Personal Data when individuals:

  • access or use the OnePassERP platform, mobile applications, websites or related services;
  • act as an administrator, authorised user, employee, contractor or representative of a OnePassERP customer;
  • communicate with our sales, support, implementation or technical teams; or
  • otherwise interact with OnePassERP or SuperInk in connection with the services.

This Privacy Policy is intended to comply with applicable data protection laws, including:

  • the Singapore Personal Data Protection Act 2012 (“Singapore PDPA”);
  • the Malaysia Personal Data Protection Act 2010, including its amendments (“Malaysia PDPA”); and
  • Indonesia Law No. 27 of 2022 concerning Personal Data Protection (“Indonesia PDP Law”).

Where local law provides greater protection or additional rights, the applicable local law will prevail.

2. Scope

This Privacy Policy applies to OnePassERP and related services provided by SuperInk, including modules and functions for:

  • human resources and employee management;
  • attendance and timesheets;
  • leave and claims management;
  • payroll and compensation;
  • recruitment and onboarding;
  • project and task management;
  • training and learning management;
  • procurement and operational workflows;
  • reporting and analytics;
  • system administration and audit logging; and
  • other modules, integrations and services made available through OnePassERP.

The particular categories of Personal Data processed will depend on the modules and features selected by the subscribing organisation.

This Privacy Policy does not replace the privacy notice that an employer or subscribing organisation may be required to provide to its employees, contractors, applicants or other individuals.

3. Definitions

For this Privacy Policy:

“Customer” means an organisation or person that subscribes to, purchases or administers OnePassERP.

“Customer Data” means information, documents and Personal Data submitted to or processed through OnePassERP by or on behalf of a Customer.

“Personal Data” means information relating to an identified or reasonably identifiable individual, whether directly or indirectly, and includes equivalent terms such as “personal information” under applicable laws.

“Sensitive Personal Data” includes information requiring additional protection under applicable law, such as identification numbers, financial information, health information, biometric data, religious beliefs, marital information, criminal records and other legally protected categories.

“User” means any individual authorised to access or use OnePassERP.

4. Our Role and the Customer’s Role

4.1 Customer Data

For Personal Data that a Customer submits to OnePassERP, the Customer generally determines why and how that Personal Data is processed.

Accordingly, the Customer will normally act as the:

  • organisation under the Singapore PDPA;
  • data controller under the Malaysia PDPA; or
  • Personal Data Controller under the Indonesia PDP Law.

SuperInk generally processes such Customer Data on the Customer’s documented instructions and acts as the Customer’s data intermediary, data processor or Personal Data Processor, as applicable.

Individuals seeking to exercise their rights concerning Customer Data should normally contact their employer or the relevant Customer first. We will reasonably assist Customers in responding to valid requests as required by applicable law and our agreement with the Customer.

4.2 Data Controlled by SuperInk

SuperInk acts as the controller or organisation for Personal Data that we determine the purposes and methods of processing, including:

  • Customer account and administrator information;
  • subscription, billing and payment information;
  • sales and marketing contacts;
  • support and service communications;
  • platform usage, diagnostic and security information; and
  • information collected through our websites.

5. Personal Data We Collect

Depending on how OnePassERP is used, we may process the following categories of Personal Data.

5.1 Account and Contact Information

  • name;
  • business email address;
  • telephone number;
  • job title;
  • department and organisation;
  • username and account identifiers;
  • authentication and account recovery information; and
  • communication preferences.

5.2 Employment and Human Resources Information

Where entered by a Customer, this may include:

  • employee or contractor identification numbers;
  • employment status and employment history;
  • job title, department and reporting structure;
  • work location and employment dates;
  • attendance, timesheets and working hours;
  • leave, absence and overtime records;
  • performance, training and disciplinary records;
  • salary, payroll, allowances, bonuses and claims;
  • bank account and payment information;
  • tax, pension, social security or statutory contribution information;
  • qualifications, licences and certifications;
  • emergency contacts and dependant information; and
  • documents uploaded by the Customer or User.

5.3 Identification and Sensitive Personal Data

Depending on the Customer’s configuration and applicable local requirements, Customer Data may include:

  • national identification, passport or work permit information;
  • date of birth, age, sex, nationality or marital status;
  • photographs or profile images;
  • health, medical or disability information;
  • religious information where required for lawful employment administration;
  • biometric or facial information where a biometric attendance feature is specifically enabled; and
  • other Sensitive Personal Data submitted by the Customer.

Customers are responsible for ensuring that they have a valid legal basis and have provided all required notices before submitting Sensitive Personal Data to OnePassERP.

5.4 Technical, Usage and Security Information

We may automatically collect:

  • IP address;
  • browser type and operating system;
  • device identifiers;
  • login dates, times and locations;
  • pages, modules and functions accessed;
  • actions performed within the platform;
  • audit trails and activity logs;
  • system performance and diagnostic information;
  • security alerts and suspected unauthorised activity; and
  • cookie and similar technology information.

5.5 Billing and Transaction Information

We may collect:

  • billing contact details;
  • subscription and plan information;
  • invoice and transaction records;
  • payment status; and
  • limited payment-related information received from payment providers.

Complete payment card information may be processed directly by our payment service providers and may not be stored by OnePassERP.

5.6 Support and Communications

We may process information contained in:

  • support tickets;
  • emails and chat messages;
  • telephone or video support sessions;
  • implementation and training records;
  • feedback, surveys and complaints; and
  • files or screenshots supplied for troubleshooting.

Users should avoid sending unnecessary Personal Data when requesting technical support.

6. How We Collect Personal Data

We may collect Personal Data:

  • directly from Customers, Users and other individuals;
  • from a User’s employer or contracting organisation;
  • through the OnePassERP platform and connected applications;
  • from integrations authorised by the Customer;
  • automatically through cookies, logs and similar technologies;
  • from payment, identity, communication or infrastructure providers; and
  • from publicly available sources where permitted by law.

If a person provides Personal Data concerning another individual, that person and the relevant Customer are responsible for ensuring that they are authorised to provide it.

7. Purposes and Legal Bases for Processing

We process Personal Data where permitted by applicable law and where necessary for purposes including:

  • creating and administering OnePassERP accounts;
  • providing, operating, maintaining and supporting the services;
  • carrying out a Customer’s documented instructions;
  • processing subscriptions, invoices and payments;
  • authenticating Users and controlling platform access;
  • configuring modules, permissions and organisational workflows;
  • providing implementation, migration, training and support;
  • maintaining audit trails and operational records;
  • detecting, investigating and preventing fraud, misuse and security incidents;
  • monitoring system availability, performance and reliability;
  • troubleshooting errors and improving service functionality;
  • communicating service, maintenance and security notices;
  • responding to enquiries, requests, complaints and disputes;
  • complying with legal, regulatory, tax and accounting obligations;
  • enforcing our agreements and protecting our legal rights;
  • conducting internal reporting and business planning; and
  • sending marketing communications where permitted by law.

Depending on the jurisdiction and circumstances, our legal basis may include:

  • performance of a contract;
  • compliance with a legal obligation;
  • consent;
  • legitimate interests or other recognised lawful interests;
  • protection of an individual’s vital interests;
  • performance of duties in the public interest, where applicable; or
  • another legal basis permitted under applicable law.

We will not rely on consent where consent is not required or is not the appropriate legal basis. Where we rely on consent, the individual may withdraw it, subject to applicable legal and contractual consequences.

8. Artificial Intelligence and Automated Processing

OnePassERP may provide reports, analytics, recommendations or AI-assisted functions where such features are enabled.

Unless specifically disclosed to the Customer, we do not use Customer Data to make solely automated decisions that produce legal or similarly significant effects on an individual.

Customers remain responsible for reviewing system-generated outputs before making employment, payroll, disciplinary, recruitment or other decisions affecting individuals.

We will not use identifiable Customer Data to train general-purpose artificial intelligence models unless the Customer has expressly agreed to this in writing.

9. How We Disclose Personal Data

We may disclose Personal Data only where reasonably necessary and permitted by law, including to:

  • the Customer that controls the relevant Customer Data;
  • authorised Customer administrators and Users;
  • SuperInk personnel who require access to perform their duties;
  • cloud hosting, data storage and infrastructure providers;
  • email, SMS, authentication and communication providers;
  • payment processors and financial institutions;
  • implementation, migration and technical support providers;
  • professional advisers, auditors and insurers;
  • government authorities, regulators, courts or law enforcement agencies;
  • parties involved in a merger, acquisition, financing, restructuring or sale of business assets, subject to appropriate confidentiality protections; and
  • other parties authorised by the Customer or the relevant individual.

Service providers and subprocessors are required to process Personal Data only for authorised purposes and to apply appropriate confidentiality and security measures.

We do not sell Personal Data.

10. International Transfers

OnePassERP may process or store Personal Data in Singapore, Malaysia, Indonesia or other countries in which SuperInk or its approved service providers operate.

Where Personal Data is transferred outside its originating country, we will take reasonable and legally required steps to ensure that it receives a standard of protection comparable to that required by applicable law. These steps may include:

  • contractual data protection obligations;
  • transfer agreements or approved contractual clauses;
  • assessments of the recipient and destination country;
  • consent where legally required;
  • technical and organisational safeguards; and
  • other recognised transfer mechanisms.

The locations used for a particular Customer may depend on its subscription, selected hosting region, integrations and contracted service configuration.

11. Data Retention and Deletion

We retain Personal Data only for as long as reasonably necessary to:

  • provide the services;
  • fulfil the purposes described in this Privacy Policy;
  • comply with Customer instructions;
  • meet legal, tax, accounting and regulatory requirements;
  • establish, exercise or defend legal claims;
  • maintain security and audit records; and
  • resolve disputes and enforce agreements.

Customer Data will generally be retained for the duration of the Customer’s subscription and subsequently deleted or returned in accordance with the Customer’s agreement and configured retention settings.

Deleted information may remain in encrypted or access-restricted backups until it is overwritten or deleted through our normal backup cycle.

Customers are responsible for exporting any required Customer Data before their access or subscription ends.

12. Security of Personal Data

We use reasonable administrative, physical and technical measures designed to protect Personal Data against:

  • unauthorised or accidental access;
  • collection, use or disclosure;
  • copying, modification or deletion;
  • loss or misuse; and
  • other similar risks.

These measures may include, where appropriate:

  • role-based access controls;
  • authentication and access management;
  • audit and activity logging;
  • network and infrastructure protections;
  • encryption during transmission;
  • backup and recovery procedures;
  • vulnerability and security monitoring;
  • employee confidentiality obligations;
  • access reviews; and
  • incident response procedures.

No internet-based service or storage system can be guaranteed to be completely secure. Customers and Users are responsible for maintaining the confidentiality of their login credentials, enabling available security controls and promptly reporting suspected unauthorised access.

13. Personal Data Breaches

We maintain procedures for identifying, assessing, containing and responding to Personal Data breaches.

Where SuperInk processes Customer Data on behalf of a Customer, we will notify the affected Customer without undue delay after becoming aware of a confirmed Personal Data breach, in accordance with our agreement and applicable law.

Where SuperInk is responsible for notifying a regulator or affected individual, we will make the notification within the legally required period and provide the information required by applicable law.

14. Individual Rights

Subject to applicable law, an individual may have the right to:

  • request access to their Personal Data;
  • obtain information about how their Personal Data has been processed;
  • request correction or completion of inaccurate Personal Data;
  • withdraw consent;
  • object to or restrict certain processing;
  • request deletion, erasure or destruction;
  • request a copy of their Personal Data;
  • request data portability in a technically feasible format;
  • object to certain automated decision-making;
  • complain about the processing of their Personal Data; and
  • nominate or authorise another person to exercise rights where permitted by law.

These rights are not absolute. We may need to verify the requester’s identity and may refuse or limit a request where permitted or required by law.

For Customer Data, individuals should first submit their request to their employer or the relevant Customer. If a request is submitted directly to us, we may refer it to the Customer and assist the Customer in responding.

For Personal Data controlled directly by SuperInk, requests may be submitted to our Data Protection Officer using the contact details below.

We will respond within the period required by applicable law. A reasonable fee may be charged for an access request where permitted by law, and the requester will be informed before the request is processed.

15. Withdrawal of Consent

Where processing is based on consent, an individual may withdraw that consent by providing reasonable written notice.

Withdrawal will not affect processing already lawfully carried out before the withdrawal. Depending on the information and services involved, withdrawal may affect our ability or the Customer’s ability to continue providing certain services, features or employment-related administration.

16. Marketing Communications

We may send information about OnePassERP products, services, events and updates where permitted by applicable law.

Recipients may unsubscribe by using the link in a marketing email or by contacting us. Administrative, billing, transactional, maintenance and security communications are not marketing communications and may continue where necessary to provide the services.

We will comply with applicable direct-marketing and communications requirements, including Singapore’s Do Not Call provisions where applicable.

17. Cookies and Similar Technologies

Our websites and applications may use cookies, local storage and similar technologies to:

  • enable essential platform functions;
  • maintain sessions and authentication;
  • remember preferences;
  • protect accounts and prevent fraud;
  • understand platform usage and performance; and
  • measure the effectiveness of our communications.

Where required, non-essential cookies will be used only after appropriate consent has been obtained.

Users can manage cookies through their browser or available cookie settings. Disabling essential cookies may prevent parts of OnePassERP from functioning properly.

18. Children and Minors

OnePassERP is intended primarily for use by businesses and organisations and is not directed at children for their personal use.

Where a Customer uses OnePassERP to process Personal Data relating to a minor, the Customer is responsible for ensuring that the processing is lawful and that any required consent from a parent, guardian or authorised representative has been obtained.

19. Customer Responsibilities

Customers are responsible for:

  • providing appropriate privacy notices to their employees, contractors, applicants and other individuals;
  • establishing a valid legal basis for processing Customer Data;
  • limiting Customer Data to what is necessary;
  • maintaining accurate and up-to-date information;
  • configuring access permissions appropriately;
  • managing User accounts and removing unnecessary access;
  • responding to individual rights requests;
  • complying with employment, tax, payroll and data protection laws;
  • obtaining any required consent for biometric or Sensitive Personal Data; and
  • notifying SuperInk promptly of suspected misuse or unauthorised access.

20. Third-Party Services and Integrations

Customers may connect OnePassERP with third-party services. The Customer is responsible for selecting and authorising those integrations.

Third-party services may process Personal Data under their own privacy policies and terms. SuperInk is not responsible for a third party’s independent privacy practices unless that third party has been engaged by SuperInk as a subprocessor.

21. Regional Provisions

21.1 Singapore

Where the Singapore PDPA applies, SuperInk will process Personal Data in accordance with the applicable consent, purpose limitation, notification, access, correction, accuracy, protection, retention limitation, transfer limitation, accountability and data breach notification obligations.

SuperInk has designated a Data Protection Officer whose contact details are provided below.

21.2 Malaysia

Where the Malaysia PDPA applies, Personal Data will be processed in accordance with the applicable General, Notice and Choice, Disclosure, Security, Retention, Data Integrity and Access Principles.

Applicable rights may include access, correction, withdrawal of consent, prevention of certain processing, direct-marketing objections and data portability, subject to the Malaysia PDPA.

Where legally required, SuperInk or the relevant Customer will appoint and register a Data Protection Officer and comply with applicable Personal Data breach notification requirements.

A Bahasa Malaysia version of the relevant privacy notice should be made available for Malaysian data subjects.

21.3 Indonesia

Where the Indonesia PDP Law applies, Personal Data will be processed based on a lawful basis recognised under Indonesian law.

Applicable rights may include the right to information, access, correction, completion, withdrawal of consent, restriction, objection, deletion or destruction, data portability and objection to decisions based solely on automated processing, subject to applicable limitations.

Where required, SuperInk or the relevant Customer will appoint a Personal Data protection officer or official and comply with applicable breach notification and cross-border transfer requirements.

A Bahasa Indonesia version of the relevant privacy notice should be made available for Indonesian Personal Data Subjects.

22. Changes to This Privacy Policy

We may update this Privacy Policy to reflect changes to OnePassERP, our processing practices or applicable laws.

The latest version will be published through our website or platform with the revised “Last updated” date. Where changes are material, we may also notify Customers or Users through email, account notification or another appropriate method.

23. Contacting Us

For privacy questions, requests or complaints, please contact:

Data Protection Officer — SuperInk Pte Ltd (OnePassERP)

Email: dpo@superink.com.sg

Address: 120 Hillview #04-06 Singapore 669594

Please include sufficient details for us to understand the request. We may request additional information to verify identity before disclosing or changing Personal Data.

If the request concerns information entered into OnePassERP by an employer or another Customer, please contact that organisation first.